ISO 26262 Academy · Legal · for organisations
Data Processing Agreement
The public form of our Article 28 GDPR terms for organisations using team workspaces. The execution copy includes the current supplier, transfer and detailed security schedules.
Version 1.1 · Effective 24 August 2026 · Last updated: August 24, 2026
Request an execution copy
Email [email protected] with your organisation's legal name, registered address and signatory. We will provide the completed agreement and its current schedules for electronic signature. We can also review a customer template.
1. Parties and scope
The processor is Paul Danci, trading as ISO 26262 Academy, Am Feger 3, 71063 Sindelfingen, Germany (“Academy” or “Processor”). The controller is the organisation identified in the execution copy or order (“Customer” or “Controller”).
This agreement governs personal data processed by the Academy on the Customer's behalf in a team workspace. The Academy remains an independent controller for its own billing, legal, security and direct customer-relationship records, as explained in the Privacy Policy.
It takes effect when signed by both parties or when an order expressly incorporates the execution copy, and continues while the Academy processes personal data on the Customer's behalf.
2. Processing details
Subject matter and purpose. Providing and supporting the online training platform, including accounts, learning records, assessments, certificates, workspace administration, reporting, security and customer-configured integrations.
Nature. Collection, recording, organisation, storage, retrieval, consultation, use, transmission to authorised providers or Customer-selected systems, restriction, export and deletion.
Duration. The subscription term plus the deletion, return and retention periods described below.
3. Documented instructions
The Processor will process personal data only on documented instructions from the Controller, including for transfers to a third country, unless Union or Member State law requires otherwise. Where legally permitted, the Processor will inform the Controller of that requirement before processing.
This agreement, the order, the Customer's workspace settings and written directions from authorised Customer contacts form the documented instructions. The Processor will inform the Controller if it believes an instruction infringes applicable data protection law.
4. Confidentiality
Persons authorised to process Customer personal data are bound by confidentiality and receive access only to the extent needed for their duties. The obligation continues after their access or engagement ends.
5. Security of processing
Taking account of the state of the art, implementation cost, processing context and risk, the Processor maintains appropriate technical and organisational measures. The execution copy contains a detailed schedule. Its public control categories are:
Access control
Access is limited by role and business need. Team workspaces are logically separated and administrative actions are recorded.
Encryption and credential protection
Data is protected in transit, sensitive credentials are protected at rest, and passwords are stored only in non-recoverable form.
Availability and recovery
Backups, recovery procedures and service monitoring support availability and restoration after an incident.
Secure operation
We use security logging, dependency review, change controls and incident-handling procedures appropriate to the service and its risk.
Data minimisation and deletion
We limit collection to service, security and legal needs and apply retention and deletion rules by data category.
Supplier management
Providers that process personal data are subject to contractual data-protection obligations and are reviewed according to risk.
Measures may evolve with the service, provided the overall level of protection is not materially reduced during the agreement term.
6. Subprocessors
The Controller grants general written authorisation for the subprocessors listed in the schedule supplied before execution. The schedule identifies each provider, location, function, relevant data and transfer basis. It is available to current and prospective customers on request.
The Processor will give at least 30 days' prior notice of an intended addition or replacement. The Controller may object on reasonable data-protection grounds during that period. If the parties cannot resolve the objection, the Controller may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused period.
Each subprocessor is bound by data-protection obligations no less protective than those applicable to the relevant processing under this agreement. The Processor remains responsible for its subprocessors' performance as required by Article 28.
7. International transfers
The primary service infrastructure is located in the European Union. Some specialised subprocessors may process limited personal data outside the EEA.
A restricted transfer will take place only on documented instructions and under an applicable adequacy decision, the EU-US Data Privacy Framework for a participating provider, or Standard Contractual Clauses with any necessary supplementary measures. Provider-specific information is in the execution schedule.
8. Assistance and data-subject rights
Taking account of the nature of processing, the Processor will assist the Controller with requests under Chapter III GDPR and with obligations under Articles 32 to 36, including security, breach notification, impact assessments and prior consultation. If a data subject contacts the Processor about Customer-controlled data, the Processor will refer the request to the Controller unless legally prohibited.
9. Personal data breaches
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer data and provide available information needed for the Controller's assessment and notification duties. The Processor will take reasonable steps to contain, investigate and remediate the incident.
10. Deletion, return and retention
At the end of the service, the Processor will, at the Controller's choice, return or delete personal data and delete existing copies unless applicable law requires retention. Data may remain in protected backups until overwritten in the ordinary backup cycle; restored data remains subject to the deletion instruction.
- Account data: while the account is active and thereafter only as needed for closure, disputes or legal obligations
- Learning records and certificates: for the subscription term and generally up to three years afterwards for continuity and verification
- Billing and tax records: for the statutory retention period, which may be up to ten years
- Support and business communications: generally up to three years
- Short-lived interaction diagnostics: up to 30 days
- Operational error and security records: generally up to 90 days, unless an incident requires longer preservation
- Backups: until overwritten in the ordinary backup cycle
11. Information and audits
The Processor will make available information reasonably necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits by the Controller or its mandated independent auditor.
Unless a supervisory authority or a breach requires otherwise, audits require reasonable advance notice, must protect other customers' data and confidential information, occur during normal business hours and avoid unreasonable disruption. The parties may agree to satisfy a request first through documentation, a security questionnaire and a remote review.
12. AI-assisted processing
Where enabled as part of the service, open-text exam answers may be sent to an AI subprocessor for automated grading. This processing, the relevant data, location and transfer basis are identified in the execution schedules. The Customer must ensure that its users receive any notice required for Customer-controlled processing.
13. Term, precedence and law
This agreement ends when the Processor no longer processes personal data on the Controller's behalf. If it conflicts with another agreement between the parties on data-protection matters, this agreement prevails.
It is governed by German law. For business customers, the competent courts agreed in the applicable order or Terms of Service have jurisdiction, subject to mandatory law.
Annex I — Data subjects and data types
Data subjects
- Customer employees, contractors, learners, invitees and workspace administrators
- Customer billing, procurement and administrative contacts
Personal data
- Identity, account, professional-profile and contact data
- Learning records, assessment content, results, certificates and authored work
- Workspace roles, configuration and administrative audit records
- Technical, security, usage, support and integration data
The service does not require special-category or criminal-conviction data. The Customer must not submit it unless necessary, lawful and expressly agreed.
Annex II — Execution schedules
The signed agreement includes: (A) the detailed technical and organisational measures; and (B) the current subprocessor and transfer schedule. Those schedules form part of the agreement and are supplied before signature. They are not repeated on this indexed public page because they contain operational and supplier details intended for authorised customer review.
Execution
Processor: Paul Danci, trading as ISO 26262 Academy, at the address stated above.
Controller: the organisation named in the execution copy or order.
Request: [email protected].