GDPR Data Processing Agreement (Article 28)
Version 1.0 · 6 August 2026 · Contact: privacy@canoanumis.org
For schools subject to the GDPR or the UK GDPR, the school is the controller and CANOA is the processor. The page below sets out the Article 28(3) terms as we apply them; a signable document with these terms is sent on request within two business days.
Subject matter, duration, nature and purpose
We process personal data solely to deliver Canoa // edu assignments to the school's students, record and check their answers, return scores to the school's LMS, and enable teacher review. Processing lasts for the duration of the school's use of the service, with the retention periods below applying automatically regardless of contract length.
Categories of data and data subjects
| Data subjects | Categories of data | Retention |
|---|---|---|
| Students | Pseudonymous LTI identifier, course context id, assignment answers, scores. No names, emails, photographs, or special-category data. | School year + 90 days (455-day rolling window), or earlier on instruction |
| Teachers (optional, by consent) | Email address; for pilot requests also name, role, school, LMS. | Until withdrawal of consent; one-click unsubscribe, immediate |
No special categories of personal data under Article 9 are processed, and no automated decision-making with legal or similarly significant effects under Article 22 takes place — scoring an assignment is reviewable and correctable by the teacher.
Our obligations as processor
- Documented instructions (Art. 28(3)(a)). We process only on the controller's documented instructions, which include these terms and the configuration of the LTI deployment.
- Confidentiality (b). Staff with access are bound by confidentiality obligations; access is limited and logged.
- Security (c, Art. 32). TLS 1.2+ in transit, encryption at rest, pseudonymisation by design, per-deployment isolation, cryptographic validation of every launch, backups rotating out within 35 days.
- Subprocessors (d). Engaged under written terms no weaker than these, listed publicly at subprocessors, with at least 30 days' notice and a right to object before any change.
- Data subject rights (e). We assist the controller with access, rectification, erasure, and portability requests. In practice the school must identify the record: we hold no name and cannot map an identifier to a person.
- Breach and DPIA assistance (f). We notify the controller without undue delay after becoming aware of a personal data breach, and assist with DPIAs and prior consultations.
- Deletion or return (g). On termination, data is deleted and deletion is confirmed in writing; see the deletion procedure.
- Audit (h). We make available the information needed to demonstrate compliance and allow for audits, including inspections, by the controller or an auditor it mandates.
International transfers — read this before signing
Our infrastructure is operated in the Russian Federation, which the European Commission has not recognised as providing an adequate level of protection. Any processing of EU or UK personal data therefore relies on a transfer mechanism and a transfer impact assessment by the controller.
We state this at the top of the section rather than in a footnote because it is the single most consequential fact for a European school's DPO. If your assessment concludes the transfer cannot be justified, tell us — for EU and UK schools we would rather discuss hosting arrangements openly than have you discover the issue at the end of a procurement. Write to privacy@canoanumis.org.
Request the signable DPA
Email privacy@canoanumis.org with your institution and jurisdiction. If your school has its own DPA template, send that instead — we review and return it within two business days.