Agreement Overview
This Data Processing Agreement ("DPA") forms part of the service agreement between Blacklink
Education, Inc. ("Processor") and the educational institution ("Controller") for the processing of
personal data in accordance with applicable data protection laws, including GDPR, CCPA, and
educational privacy regulations.
Key Definitions
- Controller: The educational institution that determines purposes and means
of processing
- Processor: Blacklink, Inc., which processes data on behalf of the
Controller
- Personal Data: Any information relating to identified or identifiable
individuals
- Processing: Any operation performed on personal data
Data Processing Details
Categories of Data Subjects
- Students enrolled in the educational institution
- Teaching and administrative staff
- Parents and guardians (where applicable)
- Other authorized users of the educational platform
Categories of Personal Data
- Identity Data: Name, student ID, email address
- Educational Data: Academic records, assignments, assessments
- Usage Data: Platform interactions, learning progress
- Technical Data: IP addresses, device information, cookies
Processing Purposes
- Provision of educational technology services
- User authentication and access management
- Educational progress tracking and reporting
- Platform security and fraud prevention
- Technical support and troubleshooting
Processor Obligations
Data Protection Measures
- Process data only on documented instructions from Controller
- Ensure confidentiality of processing staff
- Implement appropriate technical and organizational security measures
- Engage sub-processors only with prior written authorization
- Assist Controller with data subject rights requests
- Maintain records of processing activities
Security Measures
- Encryption: Data encrypted in transit and at rest using industry-standard
protocols
- Access Controls: Role-based access with multi-factor authentication
- Monitoring: Continuous security monitoring and logging
- Incident Response: 24/7 incident response and breach notification procedures
- Regular Audits: Annual security assessments and compliance reviews
Sub-Processing
Current authorized sub-processors include:
- Google Cloud Platform: Cloud hosting and infrastructure
- SendGrid: Email delivery services
Data Subject Rights
Blacklink, Inc. will assist the Controller in responding to data subject requests for:
- Access to personal data
- Rectification of inaccurate data
- Erasure of personal data
- Restriction of processing
- Data portability
- Objection to processing
Data Retention and Deletion
- Data retained only as long as necessary for educational purposes
- Automatic deletion based on Controller's retention policies
- Secure deletion using industry-standard methods
- Certificate of deletion provided upon request
International Transfers
Where personal data is transferred outside the EEA/UK:
- Transfers based on adequacy decisions or appropriate safeguards
- Standard Contractual Clauses implemented where required
- Regular review of transfer mechanisms and legal basis
Liability and Indemnification
- Each party liable for damages caused by its own data protection violations
- Processor indemnifies Controller for breaches of this DPA
- Liability limitations as specified in main service agreement
Contact Information
For DPA-related inquiries: