Data Processing Addendum
Plain English summary: This Data Processing Addendum forms part of the agreement between LANALTX and a teacher, tutoring business, company or organisation using Lesson Studio to process information about adult learners.
The customer decides what adult learner information to enter and why. LANALTX processes that information to provide Lesson Studio. Lesson Studio must not be used for anyone under 18.
SECTION 1 - PARTIES AND APPLICATION
This Data Processing Addendum, referred to as the "DPA", is entered into between:
- LANALTX, established in the Republic of Cyprus, VAT number CY005503795H, referred to as "LANALTX" or the "Processor"; and
- the teacher, tutor, tutoring business, company, organisation or other customer that has accepted the Lesson Studio Terms of Service, referred to as the "Customer" or the "Controller".
This DPA applies where LANALTX processes Customer Personal Data on behalf of the Customer through Lesson Studio.
This DPA is incorporated into and forms part of the Lesson Studio Terms of Service and the Customer's agreement with LANALTX. It takes effect when the Customer accepts the Lesson Studio Terms, accepts this DPA electronically, or begins submitting Customer Personal Data to Lesson Studio, whichever occurs first.
SECTION 2 - DEFINITIONS
In this DPA:
Applicable Data Protection Law means the GDPR and any other data-protection law that applies to the relevant processing.
Customer Personal Data means personal data processed by LANALTX on behalf of the Customer through Lesson Studio.
Data Subject, Personal Data, Personal Data Breach, Processing, Processor and Controller have the meanings given in Applicable Data Protection Law.
GDPR means Regulation (EU) 2016/679.
Subprocessor means another processor engaged by LANALTX to process Customer Personal Data.
Lesson Studio means the lesson creation, storage, sharing, adult learner portal, scheduling, vocabulary, feedback and related services supplied by LANALTX.
SECTION 3 - DATA-PROTECTION ROLES
The Customer acts as Controller where it decides what adult learner information is entered into Lesson Studio, the purposes for which it is used and how long it should be retained.
LANALTX acts as Processor for Customer Personal Data processed to provide Lesson Studio on the Customer's behalf.
LANALTX acts as an independent Controller for information it processes for its own purposes, including account administration, subscription management, billing records, security, fraud prevention, support, legal compliance and the operation of its business. That processing is governed by the Lesson Studio Privacy Policy and is outside the processor obligations in this DPA.
SECTION 4 - CUSTOMER RESPONSIBILITIES
The Customer is responsible for:
- processing Customer Personal Data lawfully, fairly and transparently;
- providing required privacy information to adult learners and other Data Subjects;
- identifying and documenting an appropriate legal basis;
- entering only information that is relevant, accurate and reasonably necessary;
- ensuring every learner entered into Lesson Studio is at least 18 years old;
- obtaining any required permission to upload source materials or third-party information;
- responding to Data Subject requests and regulatory enquiries as Controller;
- configuring and using Lesson Studio in a manner appropriate to the Customer's risks and obligations; and
- keeping account credentials, share links and exported records secure.
The Customer must not instruct LANALTX to process personal data in a way that breaches Applicable Data Protection Law.
SECTION 5 - ADULTS-ONLY REQUIREMENT
Lesson Studio is strictly limited to users and learners aged 18 or over.
The Customer must not use Lesson Studio to create profiles for, enter information about, invite, teach, manage or monitor anyone under 18.
If LANALTX reasonably believes that Customer Personal Data concerns a person under 18, LANALTX may suspend the relevant processing, restrict the account, request information from the Customer and delete or return the affected data where appropriate.
SECTION 6 - DOCUMENTED INSTRUCTIONS
LANALTX will process Customer Personal Data only:
- on the Customer's documented instructions;
- as necessary to provide, secure, maintain and support Lesson Studio;
- as described in this DPA, the Lesson Studio Terms and the Customer's use of the Service; or
- where required by Union or Member State law.
The Customer's use and configuration of Lesson Studio, including submitted prompts, uploaded materials, learner records, sharing choices, deletion actions and integration settings, constitute documented instructions.
If LANALTX is legally required to process Customer Personal Data outside the Customer's instructions, LANALTX will inform the Customer before processing unless the law prohibits that notice on important public-interest grounds.
LANALTX will inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. LANALTX may suspend the affected instruction until it is amended or confirmed as lawful.
SECTION 7 - CONFIDENTIALITY
LANALTX will ensure that persons authorised to process Customer Personal Data:
- are subject to an appropriate duty of confidentiality;
- receive access only where reasonably necessary for their role;
- process the data only on authorised instructions; and
- receive appropriate security and data-protection guidance.
SECTION 8 - SECURITY
Taking account of the nature, scope, context and purposes of processing, the state of the art, implementation costs and relevant risks, LANALTX will maintain appropriate technical and organisational measures designed to protect Customer Personal Data.
The current categories of measures are described in Schedule 2.
The Customer acknowledges that no online service can guarantee absolute security and remains responsible for using appropriate account, device, export and share-link controls.
SECTION 9 - PERSONAL DATA BREACHES
LANALTX will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
Where available, the notice will include:
- the nature of the breach;
- the categories and approximate number of affected Data Subjects and records;
- the likely consequences;
- the measures taken or proposed to address the breach; and
- available contact information for follow-up.
Information may be provided in phases where it is not all available at the same time.
The Customer remains responsible for deciding whether notification to a supervisory authority or communication to Data Subjects is legally required. LANALTX will provide reasonable assistance based on the nature of the processing and information available to it.
A notification under this section is not an admission of fault or liability.
SECTION 10 - DATA SUBJECT REQUESTS
Taking account of the nature of the processing, LANALTX will provide reasonable technical and organisational assistance to help the Customer respond to requests to exercise Data Subject rights.
Available assistance may include account controls for access, correction, export, deletion, unlinking or removal of learner records.
If LANALTX receives a request relating primarily to Customer Personal Data controlled by the Customer, LANALTX may direct the requester to the Customer and notify the Customer where appropriate. LANALTX will not independently respond on the Customer's behalf unless authorised or legally required.
SECTION 11 - ASSISTANCE WITH COMPLIANCE
Taking account of the nature of the processing and information available, LANALTX will provide reasonable assistance with the Customer's obligations concerning:
- security of processing;
- Personal Data Breach assessment and notification;
- data-protection impact assessments;
- prior consultation with a supervisory authority; and
- demonstrating compliance with processor-related obligations.
Where a request requires substantial work beyond the ordinary Service, the parties may agree reasonable charges in advance, unless the work is required because LANALTX failed to comply with this DPA.
SECTION 12 - SUBPROCESSORS
The Customer gives LANALTX general written authorisation to engage Subprocessors for the purposes described in this DPA.
LANALTX will:
- engage Subprocessors under written terms requiring data-protection obligations appropriate to the processing;
- remain responsible to the Customer for the performance of its Subprocessors' processor obligations;
- maintain a current list of core Subprocessors in Schedule 3 or on the published DPA page; and
- provide reasonable electronic notice before a material new Subprocessor begins processing Customer Personal Data, except where an urgent replacement is necessary for security, availability or legal reasons.
The Customer may object to a new Subprocessor on reasonable data-protection grounds by contacting LANALTX promptly after receiving notice.
The parties will work in good faith to address a justified objection. If no reasonable alternative is available, the Customer may stop using the affected feature or terminate the affected paid Service in accordance with the applicable agreement.
SECTION 13 - INTERNATIONAL TRANSFERS
LANALTX will not transfer Customer Personal Data outside the European Economic Area except:
- on the Customer's documented instructions;
- where the transfer is necessary to provide an authorised Service feature; and
- where a lawful transfer mechanism and appropriate safeguards are in place.
Safeguards may include an adequacy decision, Standard Contractual Clauses approved by the European Commission, supplementary technical and organisational measures, or another lawful transfer mechanism.
Where LANALTX relies on Standard Contractual Clauses for a processor-to-processor transfer, the relevant clauses are incorporated by reference to the extent required by law.
SECTION 14 - GOOGLE CALENDAR DATA
Where the Customer enables the optional Google Calendar connection, LANALTX may process selected calendar and event information on the Customer's behalf to provide read-only scheduling and lesson-organisation features.
This may include calendar identifiers, event identifiers, titles, dates, times, descriptions, locations, update timestamps and attendee information where available.
OAuth tokens may be processed and stored securely to maintain the connection.
The Customer controls whether the integration is connected, which calendars are selected and whether imported records are retained or deleted.
The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
SECTION 15 - AI PROCESSING
Where the Customer requests AI-assisted generation, relevant prompts, lesson instructions, source material and selected adult learner context may be transmitted to an authorised AI Subprocessor to create the requested output.
The Customer must minimise personal data included in AI prompts and must not submit unnecessary special-category, highly confidential or prohibited information.
LANALTX will use commercial AI services under provider terms intended for business or API use. The Customer remains responsible for reviewing generated output before use.
SECTION 16 - RETURN AND DELETION
During the term, the Customer may use available controls to export or delete Customer Personal Data.
At the end of the relevant Service, LANALTX will, at the Customer's choice and subject to available product functionality, delete or return Customer Personal Data and delete remaining copies, unless applicable law requires retention.
If the Customer does not communicate a choice, LANALTX may delete Customer Personal Data in accordance with the published retention and account-deletion process.
Deleted data may remain temporarily in protected backups until overwritten or securely removed under the applicable backup cycle.
LANALTX may retain limited information where required for security, fraud prevention, legal claims, tax, accounting or other legal obligations. Any retained Customer Personal Data remains protected under this DPA and will not be used for unrelated purposes.
SECTION 17 - AUDITS AND INFORMATION
LANALTX will make available information reasonably necessary to demonstrate compliance with this DPA.
The Customer should first use available documentation, policy information, security summaries and written responses.
If that information is insufficient, the Customer may request an audit relating specifically to LANALTX's processing of Customer Personal Data, subject to the following conditions:
- reasonable advance written notice;
- no more than once in any 12-month period unless required by a supervisory authority or following a material security incident;
- the audit must be proportionate, conducted during normal business hours and avoid disruption;
- the auditor must be independent, suitably qualified and bound by confidentiality;
- the audit must not expose information relating to other customers or compromise security; and
- the Customer bears reasonable audit costs unless the audit identifies a material breach of this DPA by LANALTX.
LANALTX may satisfy an audit request through a relevant third-party assessment, certification, report or remote evidence where that provides reasonable assurance.
SECTION 18 - REGULATORY COOPERATION
LANALTX will cooperate with a competent supervisory authority as required by Applicable Data Protection Law.
Where a regulator contacts LANALTX about Customer Personal Data, LANALTX may notify the Customer unless prohibited by law.
SECTION 19 - LIABILITY
Liability arising from this DPA is subject to the liability provisions in the Lesson Studio Terms of Service or the applicable customer agreement.
Nothing in this DPA limits liability or Data Subject rights where limitation is prohibited by Applicable Data Protection Law.
SECTION 20 - TERM AND TERMINATION
This DPA remains in force for as long as LANALTX processes Customer Personal Data on behalf of the Customer.
Sections concerning confidentiality, security, deletion, retained data, audits, liability and international transfers continue for as long as relevant Customer Personal Data remains in LANALTX's possession or control.
SECTION 21 - PRECEDENCE AND CHANGES
If this DPA conflicts with another part of the agreement regarding the processing of Customer Personal Data, this DPA takes priority.
LANALTX may update this DPA where reasonably necessary to reflect changes in law, regulatory guidance, security, Subprocessors or Service features.
Material changes will be communicated with reasonable notice where practicable. Changes will not reduce the protection of Customer Personal Data in a manner that causes the processing to breach Applicable Data Protection Law.
SECTION 22 - GOVERNING LAW
This DPA is governed by the laws of the Republic of Cyprus, without removing any mandatory rights or jurisdiction provided by Applicable Data Protection Law.
SECTION 23 - CONTACT
For data-protection, processor, security or procurement questions, contact:
LANALTX
79 Ellados Avenue, Office 201
Pafos, 8020
Cyprus
VAT number: CY005503795H
Email: [email protected]
Website: www.lanaltx.com
SCHEDULE 1 - DETAILS OF PROCESSING
| Subject matter | Provision of Lesson Studio, including lesson creation, storage, sharing, adult learner records, vocabulary, homework, feedback, scheduling, student portal features and optional integrations. |
|---|---|
| Duration | For the term of the Customer's use of Lesson Studio and any limited retention period described in the agreement, Privacy Policy or applicable law. |
| Nature of processing | Collection, recording, organisation, storage, retrieval, consultation, use, transmission to authorised Subprocessors, generation, display, sharing at the Customer's direction, restriction, export and deletion. |
| Purpose | To provide, secure, maintain and support the features requested by the Customer. |
| Data Subjects | Adult learners, Customer users, authorised staff, adult attendees included in authorised calendar events and other adults whose personal data the Customer lawfully submits. |
| Personal data categories | Names, email addresses, language levels, native languages, learning goals, interests, lesson notes, vocabulary, grammar and pronunciation records, homework, quiz responses, feedback, progress information, scheduling information, event information, prompts, uploaded source material, shared content and relevant technical identifiers. |
| Special-category data | Not intended or authorised as a normal part of the Service. The Customer must not submit unnecessary health, biometric, political, religious, sexual, criminal-offence or other sensitive information. Any exceptional processing requires a lawful basis and appropriate safeguards. |
| Processing frequency | Continuous or occasional, depending on the Customer's use of Lesson Studio. |
| Controller rights and obligations | As set out in the agreement, this DPA and Applicable Data Protection Law. |
SCHEDULE 2 - TECHNICAL AND ORGANISATIONAL MEASURES
1. Access control
- Authenticated account access.
- Role, ownership and permission checks.
- Database row-level security and user-scoped access where implemented.
- Restricted service-role and administrative credentials.
- Separation of teacher, adult learner and administrative functionality.
2. Data protection in transit and storage
- Encrypted HTTPS connections for data in transit.
- Provider-managed encryption at rest for hosted database and infrastructure services where supported.
- Environment-based storage of secrets and service credentials.
- Token-based share links rather than exposing teacher dashboards.
3. Availability and resilience
- Managed hosting and database infrastructure.
- Backup, recovery and service-restoration capabilities supplied by relevant infrastructure providers.
- Application logging and error monitoring.
- Operational checks for critical data-storage and access-control functions.
4. Security operations
- Access limited according to operational need.
- Authentication and session controls.
- Security and ownership validation on protected routes.
- Incident investigation and remediation procedures.
- Updates and changes to address identified vulnerabilities and operational risks.
5. Data minimisation and lifecycle
- Adults-only product rules.
- Restrictions on unnecessary sensitive information.
- Account, learner and lesson deletion workflows.
- Google Calendar disconnect and token-removal controls.
- Limited legal, security and backup retention after deletion where necessary.
6. Ongoing review
LANALTX may update the measures in this Schedule to reflect technical development, risk, Service changes and the state of the art, provided that the overall level of protection is not materially reduced.
SCHEDULE 3 - CURRENT CORE SUBPROCESSORS
| Subprocessor | Purpose | Data potentially processed |
|---|---|---|
| Supabase | Database, authentication and related backend services. | Account identifiers, adult learner records, lesson data, application records, authentication and access information. |
| Railway | Application hosting, runtime and infrastructure. | Data transmitted through or stored by the hosted Lesson Studio application, plus technical and diagnostic information. |
| Anthropic | AI-assisted lesson and educational-content generation. | Prompts, selected lesson context, authorised source material, selected adult learner context and generated output. |
| Google LLC and/or Google Ireland Limited | Optional Google sign-in, OAuth and Google Calendar connectivity. | Authentication identifiers, selected calendar and event information, attendee information where available and OAuth tokens. |
Provider entities, processing locations and transfer safeguards may vary according to the contracted service, selected infrastructure region and user location. LANALTX will use applicable contractual and transfer safeguards as required by law.