Data Processing Addendum
This addendum governs our processing of personal data on your behalf. It forms part of the Terms of Service and applies automatically — you do not need to sign a separate copy.
Effective September 5, 2026
Need a countersigned copy for procurement? Email info@baccuracy.com and we will execute one. This online version is already binding without it.
1. Parties and scope
This Data Processing Addendum (“DPA”) is between the Customer (the Controller) and B-ACCURACY INFOTECH (the Processor), and forms part of the Terms of Service for B-Accuracy LMS (the “Service”).
It applies where the Customer uses the Service to process personal data subject to the UK GDPR, the EU GDPR, or comparable data protection law. Where this DPA conflicts with the Terms of Service, this DPA prevails on data protection matters.
Terms such as personal data, processing, controller, processor, data subject and personal data breach have the meanings given in the GDPR.
2. Roles of the parties
The Customer is the controller and determines the purposes and means of processing. We are the processor and act only on the Customer’s documented instructions.
The Customer is responsible for ensuring it has a lawful basis for the personal data it uploads or collects through the Service, and for issuing any privacy notices its own data subjects require.
Where we process personal data as a controller in our own right — for example, the account and billing data of the Customer’s own administrators — our Privacy Policy governs instead.
3. Details of processing
| Subject matter | Provision of a multi-tenant learning management platform. |
|---|---|
| Duration | The term of the Customer’s subscription, plus the retention period in section 10. |
| Nature and purpose | Hosting, storage, transmission, retrieval and display of learning content and learner records; delivery of transactional email; analytics on learning activity; issuance of certificates. |
| Categories of data subject | The Customer’s administrators, instructors, managers and learners. |
| Categories of personal data | Identity and contact data; authentication data; organisational data such as department, group and manager relationships; learning activity including enrollments, progress, quiz attempts, assignment submissions and SCORM tracking; engagement data including forum posts, notes and gamification records; certificates issued; and any custom profile fields the Customer defines. |
| Special category data | Not required by the Service. The Customer should not upload special category data unless it has a lawful basis under Article 9 and has told us in advance. |
4. Our obligations
We will:
- Process personal data only on the Customer’s documented instructions, including as to international transfers, unless required otherwise by law — in which case we will inform the Customer first unless that law prohibits it.
- Ensure personnel authorised to process personal data are bound by confidentiality obligations.
- Implement the technical and organisational measures described in section 6.
- Respect the conditions in section 5 for engaging subprocessors.
- Assist the Customer with data subject requests, as described in section 8.
- Assist the Customer with data protection impact assessments and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to us.
- Delete or return personal data as described in section 10.
- Make available the information necessary to demonstrate compliance with Article 28, and allow for audits as described in section 9.
- Inform the Customer if, in our opinion, an instruction infringes data protection law.
5. Subprocessors
The Customer grants general authorisation for us to engage the subprocessors listed below. Each is bound by a written agreement imposing data protection obligations no less protective than those in this DPA. We remain fully liable to the Customer for their performance.
| Subprocessor | Purpose | Data handled | Location |
|---|---|---|---|
| Cloud infrastructure hosting | Application and database hosting | All Customer Data stored by the Service | European Union |
| Content delivery and domain infrastructure | CDN, DNS, TLS certificate provisioning for custom domains, and (where selected) video streaming | IP addresses, request metadata, video content | Global edge network |
| Razorpay Software Private Limited | Subscription billing and payment processing | Billing contact details, payment card/UPI/bank data (collected directly by Razorpay), invoice records | India |
| Resend | Transactional email delivery (verification, invitations, notifications, scheduled reports) | Email address, name, message content | United States |
| Video hosting and streaming (optional) | Video storage and streaming, where the Customer selects a third-party video provider other than the default above | Video content, viewer IP addresses | Global edge network |
Named infrastructure vendors. Payment and email providers are named above because the Customer’s own end users already see them directly. The infrastructure categories (hosting, CDN, video) are described by function rather than brand, since the specific vendor behind a category can change without changing how personal data is handled — that is exactly the kind of change this section’s notice-and-objection right already exists to cover. This is not a limitation on the Customer’s Article 28(2) rights: the current named vendor behind each category is available on request at info@baccuracy.com, and we will name it before it changes, the same as any other subprocessor.
Changes. We will give at least 30 days’ notice before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.
Customer-configured providers. Where the Customer connects its own AI provider key or its own video provider account, that provider is engaged by the Customer directly under the Customer’s own agreement, and is not our subprocessor.
6. Security measures
Taking account of the state of the art, cost of implementation, and the nature, scope and purposes of processing, we implement appropriate technical and organisational measures including:
- Tenant isolation. Every tenant-scoped table enforces a database-level access policy bound to the active tenant, applied on every query — including queries made over a database connection that would otherwise have unrestricted access to the table, not only ones the application layer happens to filter correctly. The specific database technology and configuration are available to the Customer on request; we describe the property here rather than the exact mechanism, for the same reason Section 5 above names infrastructure categories rather than brands.
- Encryption. TLS in transit; encryption at rest for stored data; AES-256-GCM encryption for Customer-supplied provider credentials.
- Authentication. Passwords stored only as bcrypt hashes; HttpOnly, SameSite session cookies; optional SAML 2.0 or OIDC single sign-on.
- Access control. Role-based permissions across administrator, instructor, manager and learner roles, with scoped API keys that can be rotated or revoked immediately.
- Accountability. Administrative actions and impersonation sessions are written to an audit log available to the Customer.
- Resilience. Regular backups and documented restoration procedures.
We may update these measures over time provided the level of protection is not reduced.
7. Personal data breach
We will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer’s personal data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
We will cooperate with the Customer and take reasonable steps to mitigate the breach. Notification is not an acknowledgement of fault or liability.
8. Data subject requests
The Service includes self-service tooling that lets the Customer fulfil most requests directly and immediately — data export and permanent deletion are built-in functions, not support requests.
Where a data subject contacts us directly regarding data we process on the Customer’s behalf, we will not respond substantively and will refer them to the Customer, notifying the Customer promptly. Where the tooling is insufficient, we will provide reasonable assistance.
9. Audits
On reasonable written request, no more than once in any 12-month period, we will provide the information reasonably necessary to demonstrate compliance with this DPA. Where a supervisory authority requires it, or following a personal data breach, the Customer may request an audit more frequently.
Audits must be conducted on at least 30 days’ notice, during business hours, subject to confidentiality obligations, and in a manner that does not disrupt the Service or compromise the security or data of other customers.
10. International transfers, retention and deletion
Transfers
Where processing involves transferring personal data outside the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision. Those clauses are incorporated into this DPA by reference and take precedence in the event of conflict.
Retention and deletion
- During the subscription, the Customer may export or permanently delete personal data at any time using the Service’s self-service tooling — this takes effect immediately in our live systems and does not wait for termination.
- Where the subscription ends without the Customer using that tooling first, the Customer has 30 days to export personal data.
- After that period we will delete or irreversibly anonymise the personal data within a further 30 days, except where retention is required by law.
- Personal data may persist in encrypted backups for a limited period until those backups rotate out on their normal schedule, regardless of which path above removed it. It remains protected by this DPA until deleted.
11. Liability and governing law
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where those limitations are not permitted by applicable data protection law.
This DPA is governed by the laws of India, except where the Standard Contractual Clauses require a different governing law, in which case that requirement prevails for the purposes of those clauses.
12. Contact
Data protection queries, subprocessor objections and audit requests: info@baccuracy.com.
Registered office: #26, Ethiraj Salai, "Fagun Chambers", Office No. 6, 3rd Floor, Egmore, Chennai - 600 008, Tamil Nadu, India. Email: info@baccuracy.com. Phone: +91-9600039197, +91-44-28211811.