Skip to main content

Data Processing Agreement

The Article 28 GDPR processor agreement that governs the personal data your organisation entrusts to us when your people learn here. It is written to be read by your legal team, printed, and signed — not to reassure you in the abstract. Where the honest answer is a commitment rather than a certificate, it says so.

Version 1.0 · Effective 24 August 2026 · Last updated: August 24, 2026

How to execute this agreement

Email [email protected] with the subject line "DPA request", naming your organisation’s legal entity, its registered address, and the person who will sign. We return a PDF of this agreement, completed with both parties’ details and counter-signed by us. Signing by email, including an electronic signature, is sufficient; we do not require a wet-ink original.

If your procurement process requires your own DPA template or the EU Standard Contractual Clauses attached as an appendix, say so in that email. We will read it and tell you plainly what we can and cannot accept rather than sending it back marked up weeks later.

This agreement also applies automatically, without signature, to every team subscription: it is incorporated into our Terms of Service by reference and takes effect when your order does. A counter-signed copy changes nothing about your rights; it exists because your auditors will ask for one.

1. Parties

This agreement is between ISO 26262 Academy (the "Processor", "we", "us"), established in Germany and operating the platform at iso26262.academy, and the organisation that holds a team subscription to that platform (the "Customer", the "Controller", "you").

Our registered legal name and address are stated on the counter-signed copy described above, and we provide them in advance on request if your procurement process needs them before you sign.

We have not appointed a formal Data Protection Officer, because our processing does not currently meet the thresholds in Article 37 GDPR. Every data protection question, including everything arising under this agreement, goes to [email protected].

2. Roles, and what this agreement does not cover

Where you buy team seats, you are the controller of the personal data of the people you enrol and of what they do in your workspace, and we are your processor for that data. That is the relationship this agreement governs.

Two things sit outside it, and we would rather name them than let you discover them later. First, an individual who signs up here directly, on their own account and with their own card, is not your data subject under this agreement: for those people we are the controller and our privacy policy governs. Second, we act as an independent controller for the commercial record of your own account — your billing contact, your billing address, your VAT or tax identifier, your invoices and the accounting records we are required to keep — because we determine those purposes ourselves and cannot process them on your instruction.

Everything else your people generate here — their accounts, their progress, their exam attempts and answers, the documents they author, the files they upload, the audit trail of your workspace, and the operational telemetry described in Annex I — is processed on your behalf under this agreement.

3. Subject matter, duration, nature and purpose

Subject matter. Provision of the ISO 26262 Academy online training platform to your team workspace, as described in the Terms of Service and your order.

Duration. For the term of your subscription, and thereafter only for as long as the retention periods in section 12 require.

Nature and purpose. Hosting user accounts; delivering training content; recording learning progress, exam attempts and results; grading open-text exam answers with the assistance of a large language model; issuing and verifying certificates; storing the work-product documents and files your people author or upload; workspace administration, competence reporting and training records; supporting your users; securing and operating the service; and, where you have configured them, delivering activity data to the systems you nominate.

The categories of data subjects and the types of personal data are set out in Annex I. We do not ask for, and the service is not designed to hold, the special categories of data in Article 9 GDPR or data relating to criminal convictions.

4. Processing on documented instructions

We process personal data only on your documented instructions, including on transfers to a third country, unless we are required to do otherwise by Union or Member State law — in which case we will tell you of that requirement before processing, unless that law prohibits it on important grounds of public interest.

Your documented instructions are: this agreement, the Terms of Service, your order, and the configuration choices your administrators make inside the workspace — who is invited, which curricula are assigned, which integrations are connected and where they point, and which retention and reporting options are selected. Any further instruction must be in writing to the address in section 1.

We will inform you immediately if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection law.

5. Confidentiality

We ensure that every person authorised to process personal data under this agreement has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, that access is limited to those who need it to perform the service, and that the obligation survives the end of their engagement with us.

6. Security of processing

We implement the technical and organisational measures set out in Annex II, which are the measures actually running in production, described in the same terms as our public compliance page. Annex II may be updated as the platform evolves, but never in a way that materially reduces the overall level of security.

We assist you, taking into account the nature of processing and the information available to us, in complying with your own obligations under Articles 32 to 36 GDPR — security of processing, breach notification to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation.

7. Sub-processors

You give us general written authorisation under Article 28(2) GDPR to engage the sub-processors listed in Annex III. That list is the same list published on our privacy policy, kept in one place so the two can never drift apart.

Changes. We will notify customers on a team plan before we add a sub-processor of our own, by email to your billing and administrative contacts, at least 30 days before the new provider begins processing. You may object on reasonable data protection grounds within those 30 days. If we cannot resolve your objection, you may terminate the affected part of the subscription and receive a pro-rata refund of prepaid fees for the unused remainder of the term. Where a change is forced on us urgently to keep the service secure or running, we will notify you as soon as we can and your objection right is unaffected.

We impose on each sub-processor, by contract, data protection obligations that are no less protective than those in this agreement, and we remain fully liable to you for their performance.

Endpoints that you configure — a learning record store, a learning management system, or an issue tracker — are not our sub-processors. Data flows to them at your instruction and under your control, and you are responsible for the arrangements covering them. Section 16 sets out what those connectors actually do.

8. Assisting with data subject rights

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise a data subject’s rights under Chapter III GDPR.

Some of this your people can do without either of us: a seat holder can delete their own account from their profile, can see and revoke their own active sessions, can export their own training record — certificates, exam history and curriculum progress — as CSV or PDF from the My Record page, can download their own certificates, and can export the work-product documents they authored to PDF from inside the product.

Beyond that there is no general-purpose portability button, and we will not pretend otherwise. For a copy of the rest of the personal data we hold, for rectification, restriction, objection, or for erasure of items your administrators cannot reach, write to us and we will produce it. We respond within 30 days, as GDPR requires. If a data subject contacts us directly about data we process on your behalf, we will not answer the substance ourselves: we will refer them to you and tell you about it promptly.

Erasure removes or anonymises the personal data we hold, including the actor reference in your workspace audit records, subject to the retention periods in section 12.

9. Personal data breach

We notify you of a personal data breach affecting personal data processed on your behalf without undue delay after becoming aware of it and, where feasible, within 48 hours. This is a commitment we are making in this agreement, not a certified capability.

The notification will describe, to the extent known at the time and supplemented as more becomes known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. We will not delay an initial notification in order to complete an investigation.

Where we are the controller — for the relationships described in section 2 — we notify the competent supervisory authority within 72 hours of a breach likely to result in a risk to rights and freedoms, and inform affected users without undue delay, as Articles 33 and 34 GDPR require.

If you believe you have found a security vulnerability, please tell us before disclosing it publicly. We will confirm receipt and keep you informed while we fix it.

10. Deletion or return on termination

At your choice, we delete or return all personal data processed on your behalf after the end of the provision of services, and delete existing copies, unless Union or Member State law requires us to keep them. Tell us which you want before your subscription ends; if you tell us nothing, we delete.

Before closure, your administrators can export training records and reports, and your people can export their own records and documents, using the mechanisms in section 8. We will keep the workspace readable for 30 days after termination so that export is actually possible, unless you ask us to delete sooner.

Backups. Deleted data persists in encrypted backups until those backups rotate. Our own database backups run and rotate on a fixed short cycle, and our hosting provider also keeps its own managed backups on its schedule; the exact schedule and retention horizon are stated in the written control statement described in sections 6 and 11. We do not restore a backup to recover deleted personal data except to recover from an incident, and if such a restore reintroduces data that was deleted at your instruction we re-apply the deletion.

11. Information and audit rights

We make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate.

Concretely, and on request, we provide: a description of our hosting and sub-processor arrangements; a completed security questionnaire; documentation of the technical and organisational measures described in Annex II; and a walkthrough of those measures with a named engineer. We can show a reviewer the configuration behind any measure. We will sign a mutual non-disclosure agreement first if you want one.

An on-site or remote inspection may be requested on 30 days’ written notice, no more than once in any 12-month period, during business hours, subject to confidentiality undertakings and without unreasonable disruption to the service — except where a supervisory authority requires otherwise, or following a personal data breach affecting your data, in which case those limits do not apply.

12. Retention

These are the periods we operate today. They are the same ones published in our privacy policy.

  • Active account data — for as long as the account exists
  • Learning progress and certifications — for the duration of the subscription plus 3 years, so certificates can be verified after someone leaves
  • Payment records — 10 years where required by tax law, otherwise 7 years
  • Support tickets and contact messages — up to 3 years
  • Session recordings (signed-in application only) — up to 30 days, then automatically deleted by PostHog
  • Backend error events in Sentry — up to 90 days
  • Server access logs and security events — 90 days
  • Backups — encrypted, and rotated and overwritten on a fixed schedule

Where a sub-processor holds a copy of content on its own retention schedule rather than ours — most significantly a model provider that retains a submitted answer for its own quality and abuse review — we say so in Annex III rather than implying our schedule governs it.

13. International transfers

Everything we run ourselves runs in the EU. Our application, database, storage, backups and background processing all run in DigitalOcean’s Frankfurt region. Backend error tracking uses Sentry’s German region and product analytics use PostHog’s EU region. Neither of those two is a transfer outside the EEA. We operate no data store of our own outside the EU, and we do not copy, mirror or back up customer data to any other region.

Some of our sub-processors do process data outside the EEA, and Annex III marks exactly which. For any such transfer we rely on either an adequacy decision by the European Commission, the EU–US Data Privacy Framework where the provider is certified under it, or Standard Contractual Clauses combined with technical safeguards such as encryption in transit and at rest. We will tell you which mechanism applies to a specific provider on request.

The transfer most likely to involve something one of your people wrote is AI-assisted grading: an open-text exam answer is sent to a model provider in the United States to be marked. Section 14 sets out how that works.

14. AI-assisted grading and automated processing

When one of your people answers an open-text exam question, that answer is sent together with the marking rubric to a large language model provider in the United States to be graded — automatically, and without a human in the loop. OpenAI is the provider currently used; Anthropic is configured as an alternative for the same feature. That text can be retained by the provider for its own quality and abuse review, on its retention schedule rather than ours. We have not asked for it to be used for model training, and where a provider offers that setting we have turned it off.

Google’s Gemini models are used in internal authoring and support tooling and in video subtitle alignment.

We do not currently offer a self-service switch to turn AI-assisted grading off. If you want your organisation’s answers excluded from it, write to us and we will arrange it. Because the grading is automated and affects an assessment result, tell your people about it: as controller, that disclosure is yours to make, and section 8 covers the assistance we give you in making it.

The career path recommender, exam adaptation and learning suggestions rank content from behavioural signals. These are not legally significant automated decisions in the sense of Article 22 GDPR: none of them determines whether somebody passes, and none of them determines what anybody is charged.

15. What our own telemetry sees

Two of our sub-processors receive personal data as a by-product of running the service, and a reviewer should know exactly what, rather than reading "error metadata" and assuming it is anonymous.

Sentry (German region) receives server-side error reports. Those reports include stack traces, application log lines, database and cache activity, and the id and email address of the affected user; where AI-assisted grading is involved they also include the graded answer text. Credentials and tokens are removed before sending. Browser-side error reporting to Sentry is switched off. Treat these reports as containing personal data, not as anonymous.

PostHog (EU region, reached through our own subdomain so that no third-party analytics host is contacted directly from a browser) receives product analytics, autocapture and heatmaps on both the public site and the signed-in application, plus session replay with input masking in the signed-in application only. Session replay is not enabled on the public marketing site, and replays are deleted after 30 days.

16. Integrations you configure

If you connect the platform to your own systems, activity data flows to the endpoint you configured, at your instruction and under your control. You are the controller of that onward flow and it is outside the sub-processor list in Annex III.

The issue-tracker connector is read-only: it retrieves data from your system and sends none of your users’ personal data to it. The learning record store and learning management system connectors do send activity data outward, to the endpoint your administrator names.

Credentials for these integrations — issue-tracker API tokens, learning record store authorisation headers, OAuth tokens — are stored as Fernet ciphertext under separate per-purpose keys that support rotation, never as plaintext.

17. Term, precedence and changes

This agreement takes effect when your team subscription begins and continues for as long as we process personal data on your behalf. It forms part of the Terms of Service. Where it conflicts with the Terms of Service or with any other agreement between us on a matter of data protection, this agreement prevails.

We may update this agreement, for example to reflect a change in the law or in the platform, but not in a way that materially reduces your protections or the security level in Annex II. Material changes are announced by email to active users and by a prominent notice in the app before they take effect, and the version number and effective date at the top of this page always reflect the current version. Previous versions are available on request.

Our liability under this agreement is governed by the limitations and exclusions in the Terms of Service, except where those limitations are not permitted by Article 82 GDPR or by mandatory law.

18. Governing law and jurisdiction

This agreement is governed by the laws of the Federal Republic of Germany, without regard to conflict-of-law rules. For business users the exclusive jurisdiction for any dispute is the competent courts of Berlin, Germany, except where mandatory law requires otherwise. This mirrors section 18 of our Terms of Service so that the two cannot point in different directions.

Annex I — Details of processing

Categories of data subjects

  • Your employees, contractors and other individuals to whom you assign a learning seat
  • Your workspace owners, administrators, analytics viewers and mentors
  • Your billing and administrative contacts
  • Individuals you have invited who have not yet accepted

Types of personal data

  • Identity and account — name, email address, password stored only as a bcrypt hash or, where the person signs in with Google, an OAuth identity and the profile picture their browser loads from Google
  • Professional profile — job title and professional role fields, and the mentor or internal-expert designations your administrators set
  • Learning records — curriculum and concept progress, video position, assignment status, competence assessments, certificates and their verification records
  • Assessment content — exam attempts, selected answers, free-text answers, scores, grader feedback and dispute correspondence
  • Authored content — work-product documents, safety-case material, annotations, comments and any files uploaded into the workspace
  • Workspace governance — the append-only audit trail of administrative actions, including who did what and when
  • Technical and security data — IP address, user agent, device and session metadata, authentication events, server access logs and error reports
  • Support — messages your people send us and our replies
  • Commercial contact data — billing contact name and email, purchase order reference, legal entity name, billing address and VAT or tax identifier (processed by us as controller under section 2)

Frequency and duration

Continuous for the term of the subscription. Retention as set out in section 12.

Special categories

None requested and none required by the service. If your people volunteer such data in free-text fields it will be processed incidentally under the same terms; the platform provides no field designed to collect it.

Annex II — Technical and organisational measures

These are engineering facts about the running system, not aspirations. We can walk a reviewer through the configuration behind any of them.

Encryption in transit

Everything is served over HTTPS on an HTTPS-only domain, and database and cache connections require TLS. Our exact transport configuration at the edge, and which of our surfaces sends which security header, are stated in the written control statement rather than in this published Annex.

Encryption at rest

Sensitive fields — OAuth tokens, refresh secrets, third-party integration credentials — are stored as Fernet ciphertext (AES-128-CBC with HMAC) under separate per-purpose keys that support rotation. Database backups are encrypted with AES-256 before they leave the job host.

Authentication

Passwords are hashed with bcrypt and never stored or logged in a recoverable form. Access tokens are asymmetrically signed (RS256) and short-lived, sessions are tracked server-side with a concurrency limit, and users can see and revoke their own active sessions. The full set of authentication options available on an account is listed in the written control statement.

Least-privilege database access

The application connects to the production database with a limited-privilege role. The administrative credential is held separately and used only for schema changes.

Append-only workspace audit log

Administrative actions inside a team workspace are written to an audit table that the database itself protects: triggers reject any UPDATE or DELETE from the application role. Two documented exceptions run under a separate privileged role — scheduled retention pruning, and anonymising the actor reference when a user exercises their right to erasure.

Encrypted, EU-resident backups

The database is backed up on a fixed schedule, encrypted with AES-256 before it leaves the job host, and written to a private Frankfurt bucket that refuses anonymous requests; longer-horizon recovery relies on our hosting provider’s own managed backups. The retention horizon and the restore procedure are in the written control statement, and section 10 covers what backups mean for deletion.

Card data never reaches us

Payments are collected on Stripe-hosted pages. No card-entry field exists anywhere in our applications and no card number is transmitted to or stored on our systems; we retain only the last four digits and the card brand that Stripe reports back. Stripe states that it is a PCI DSS Level 1 certified service provider; that certification is Stripe’s, not ours.

Browser hardening

Every response that leaves our edge carries X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN and a strict Referrer-Policy, and the signed-in application’s page shell is served no-store. Our public pages carry HSTS, a Permissions-Policy that switches camera, microphone, geolocation and topic-based advertising off, and a Content Security Policy. The per-surface header inventory is in the written control statement.

EU-region observability

Backend error tracking uses Sentry’s German region; browser-side error reporting is switched off. Product analytics use PostHog’s EU region, reached through a first-party domain so that no third-party analytics host is contacted directly from a browser. Section 15 sets out what those reports contain.

Dependency and code review

Automated weekly dependency-update scanning across our Python and JavaScript packages, and review of authentication-related code.

Data minimisation

We do not sell personal data and we do not share it with advertising networks. There are no ad or remarketing pixels anywhere on the platform.

Segregation

Team workspaces are logically separated: every workspace-scoped read and write is bound to the acting user’s membership of that workspace, and administrative capability is derived from their role in it.

Annex III — Authorised sub-processors

This list matches the one published in our privacy policy and was last reviewed on 24 August 2026. "Outside the EEA" marks the providers to which section 13 applies.

  • DigitalOcean (EU, Frankfurt region) — application hosting, database, object storage, encrypted database backups and background processing. This is where your data lives.
  • Stripe (United States, outside the EEA) — payment processing, subscription billing and fraud prevention. Checkout is hosted by Stripe, which receives the payer’s email address, name and billing address.
  • Postmark, an ActiveCampaign product (United States, outside the EEA) — delivery of transactional and, with consent, marketing email. Postmark receives the recipient’s email address, their name and the full content of the message, records opens and clicks, and also receives replies to our support address.
  • PostHog (EU region, ingested through a first-party subdomain of ours rather than a third-party host) — product analytics, autocapture and heatmaps on both the public site and the signed-in application, plus session replay with masking in the signed-in application only.
  • Sentry (German region) — server-side error tracking. See section 15 for exactly what a report contains.
  • OpenAI (United States, outside the EEA) — the large language model provider currently used to grade open-text exam answers.
  • Anthropic (United States, outside the EEA) — configured as an alternative provider for the same grading feature.
  • Google (United States, outside the EEA) — Gemini models used in internal authoring and support tooling and in video subtitle alignment; OAuth identity provider when a user chooses to sign in with it, and the source of that user’s profile picture and of the web fonts used in the signed-in application and on our Teams page. The browser requests that picture and those fonts from Google directly rather than through us, so Google sees the user’s IP address. The rest of our public site serves its fonts from our own domain.
  • Cloudflare (United States, outside the EEA) — content delivery network, edge security, and the Turnstile bot-protection challenge. The browser loads that challenge from challenges.cloudflare.com directly on any page carrying a public form, so Cloudflare sees the user’s IP address there as well as when we verify the answer.

Providers we have configured but do not currently use, and which therefore receive nothing: PayPal and LinkedIn sign-in. If either is ever switched on, the change notice in section 7 applies first.

Execution

Processor: ISO 26262 Academy, established in Germany. Registered legal name and address are stated on the counter-signed copy and provided on request.

Controller: the organisation named on the order, represented by the signatory it nominates.

To execute: email [email protected] with the subject line "DPA request". We return a completed, counter-signed PDF. Electronic signature is sufficient.

Related documents: Privacy Policy, Security & Compliance, Terms of Service, Cookie Policy.