# Data processing agreement: full text

This is the full agreement, published so that a customer's data protection
officer can read the whole thing rather than a summary. To sign it, fill in the
blanks marked with a line, tick one option in Schedule 4, sign at the end and
send the signed copy to [training@rtriibe.com](mailto:training@rtriibe.com). We
will countersign it and send it back. The summary is at /dpa.

---

## Parties

**The Processor:** RTRIIBE LTD, a company registered in England and Wales with
company number 12065235, whose registered office is Level One Basecamp
Liverpool, 49 Jamaica Street, Liverpool, England, L1 0AH ("rTriibe", "we",
"us").

**The Controller:** ______________________ (legal name), company or registered
body number ____________, registered office ______________________ ("you").

**Effective date:** the date both parties sign below. If they sign on different
days, it is the later of the two.

This agreement is incorporated into the organisation terms at /terms/business
(the "Agreement"). Where this agreement and the Agreement conflict on the
processing of personal data, this agreement prevails.

## 1. Definitions

"UK GDPR", "controller", "processor", "personal data", "processing", "personal
data breach" and "supervisory authority" have the meanings given in the Data
Protection Act 2018 and the UK GDPR. "Learner Data" means personal data relating
to individuals you enrol on the platform. "Sub-processor" means a third party
engaged by us to process Learner Data.

## 2. Roles

2.1 You are the controller of Learner Data. We are the processor.

2.2 We are a controller in our own right, and not your processor, for:

(a) each learner's own training record and certificates, as clause 2.3 sets out;

(b) the questions a learner asks Ask or the section tutor, and the answers. They
are the learner's, are kept for 90 days, and are never shown to you;

(c) product analytics, only where the individual has consented to it, and for
learners you enrol only to the extent Schedule 4 allows;

(d) reports of errors on our servers, which carry an account's internal id and
no other information about the person;

(e) a weekly report to our own administrators of certificates due for renewal,
which is not sent to you;

(f) marketing to individuals who signed up or bought training from us for
themselves. We never send marketing to a learner who came to the platform
through you or any other organisation, including after they leave;

(g) personal data of individuals who buy training from us directly; our own
account, billing and security records; and data relating to your administrators'
use of the platform for the purpose of running and securing the service; and

(h) statistical analysis of assessment responses to demonstrate to an
accrediting body that assessments are valid; identifying and correcting results
affected by a faulty assessment item; and our complaints and appeals records.

That processing is governed by our privacy notice at /privacy and is outside
this agreement.

2.3 A learner's own copy of their training record. The parties acknowledge that an
individual holds their own training record, that this record persists when the
individual ceases to be your worker, and that our retention of it at that point is
carried out as a controller on the lawful bases set out in our privacy notice
rather than as your processor. Your copy of the same evidence is held under this
agreement. Nothing in this agreement requires either party to destroy the other's
copy.

## 3. Our obligations

We will:

3.1 Process Learner Data only on your documented instructions, which are the
Agreement, this agreement, and any further written instruction you give. We will
tell you if we believe an instruction infringes data protection law, and may
suspend performance of that instruction until it is resolved.

3.2 Not process Learner Data for our own purposes, except as clauses 2.2 and 2.3
describe. Where we wish to derive product analytics from learner behaviour, that
is only to the extent set out in Schedule 4 and only where you have selected it.

3.3 Ensure that anyone we authorise to process Learner Data is subject to a duty
of confidence and has been trained appropriately.

3.4 Implement the technical and organisational measures in Schedule 3, and not
materially reduce them during the term.

3.5 Assist you, at your cost where the work is substantial, with: responding to
data subject requests; data protection impact assessments; consultations with the
supervisory authority; and demonstrating compliance.

3.6 Notify you of a personal data breach affecting Learner Data without undue
delay and in any event within 48 hours of becoming aware of it, with the
information required by Article 33(3) so far as we have it, and updates as we
learn more. We will not delay notification because our investigation is
incomplete.

3.7 Make available the information reasonably necessary to demonstrate compliance
and submit to audit in accordance with clause 7.

3.8 On termination, deal with Learner Data in accordance with clause 8.

## 4. Your obligations

You will:

4.1 Ensure you have a lawful basis for enrolling each learner and for instructing
us to process their data, and that you have given them the information required by
Articles 13 and 14, including that their training record persists and follows
them if they leave you.

4.2 Send us only the personal data necessary for the service: name, work email
address, role, site or team, and joining and leaving dates. Not send special
category data, and not use free-text fields for it.

4.3 Keep learner data accurate, and in particular record leavers promptly.

4.4 Ensure that your administrators use the role permissions provided rather than
granting broad access, and remove access when a person changes role.

4.5 Determine, and tell us, the retention period for your copy of training
records if you want a period other than the default in Schedule 5.

## 5. Data subject requests

5.1 Where we receive a request from one of your learners that relates to Learner
Data, we will not respond substantively on your behalf. We will acknowledge the
request, tell the individual that you are the controller, pass it to your data
protection contact without undue delay, and tell the individual that we have done
so.

5.2 Every learner holds their own training record with us under clause 2.3, so a
request about that record, including a request to erase it, is answered by us as
controller. We will say clearly which parts of a request we have answered
ourselves and which we have passed to you.

5.3 Where an individual asks for erasure and you have a continuing lawful claim to
retain the record as evidence, we will retain it and will tell the individual that
we have done so on your instruction and that you are the controller to whom any
objection should be addressed.

## 6. Sub-processors

6.1 You give general authorisation for the sub-processors listed in Schedule 2.

6.2 We will give you at least 30 days' notice before adding or replacing a
sub-processor. You may object on reasonable data protection grounds; if we
cannot resolve the objection you may terminate the affected part of the service
without penalty for the unexpired term.

6.3 Each sub-processor is engaged under a written contract imposing obligations
equivalent to those in this agreement. We remain liable to you for their acts and
omissions.

## 7. Audit

7.1 On 30 days' written notice, no more than once in any twelve-month period
except following a personal data breach, you may audit our compliance with this
agreement.

7.2 We may satisfy an audit request by providing written responses to your
questionnaire and any certification or test reports we then hold. Where these do
not answer your question, an on-site or remote audit will be arranged.

7.3 Audits are at your cost, are conducted during business hours, and must not
require us to disclose another customer's data or information that would
compromise the security of the platform.

## 8. Return and deletion

8.1 On termination you may instruct us to return Learner Data in a
machine-readable form, to delete it, or both. Absent an instruction within 30
days of termination we will retain it in accordance with Schedule 5 and then
delete it.

8.2 Retention of training records. You acknowledge that training evidence normally
needs to outlast the contract, and instruct us to retain it for the period in
Schedule 5. During that period your nominated contacts retain read and export
access at no charge.

8.3 We may retain Learner Data where required by law, and will delete it when that
requirement ends.

8.4 Clause 2.3 continues to apply: deletion of your copy does not delete an
individual's own record.

## 9. International transfers

9.1 Learner Data is stored in the United Kingdom, in Supabase's London region
(AWS eu-west-2). The application runs in Vercel's London region (lhr1).

9.2 Some of the sub-processors in Schedule 2 handle personal data outside the
United Kingdom. Where a provider handles personal data outside the UK and the
country does not have UK adequacy, the transfer is covered by the UK
International Data Transfer Addendum to the EU Standard Contractual Clauses, or
by the UK Extension to the EU-US Data Privacy Framework where the provider is
certified, and we assess the risk of each transfer before we make it. We will
share that assessment with you on request.

## 10. Liability and term

10.1 This agreement runs for as long as we process Learner Data, whether or not
the Agreement has ended.

10.2 Liability under this agreement is subject to the limits in the Agreement,
except where data protection law does not permit that limit.

---

## Schedule 1: Processing operations

**Subject matter:** provision of online compliance training and maintenance of
training records.

**Duration:** the term of the Agreement, plus the retention period in Schedule 5.

**Nature and purpose:** account creation; granting course access; recording
progress; delivering and marking assessments; issuing, storing and verifying
certificates; producing compliance reports and evidence exports; sending
service emails including assignment and expiry reminders.

**Types of personal data:** name; work email address; role; site or team;
membership dates; course entitlements and assignments; section progress;
assessment attempts, scores and results; certificates and their metadata;
technical logs.

**Categories of data subject:** your employees, workers, volunteers and
candidates.

**Special category data:** none instructed and none to be provided.

## Schedule 2: Sub-processors

| Sub-processor | Purpose | Location |
| --- | --- | --- |
| Supabase | Database, authentication, file storage, and sign-in link emails | London, United Kingdom (AWS eu-west-2) |
| Vercel | Application hosting, content delivery and scheduled jobs | The application runs in Vercel's London region (lhr1). Static files are served from Vercel's edge network nearest the visitor, which can be outside the UK, and Vercel may process request logs outside the UK, including in the United States |
| Stripe | Payment processing (controller for card data) | The United Kingdom, the European Union and the United States |
| PostHog | Product analytics and recordings of public-site visits, only where enabled and consented; browser error reports with consent; server error reports carrying an account's internal id only. No assessment data | European Union |
| ElevenLabs | Narration and read-aloud audio from section text and assessment question text; no learner data sent | The United States and the European Union |
| OpenAI | Course cover image generation from our prompts, and transcription of our own narration recordings to check them, with no learner data; and Ask and the section tutor, which receive a learner's question, the course text, matching help pages, the learner's last three questions in the same conversation and, on the Ask page, a summary of the learner's own account: plan, courses open to them, progress, certificate and renewal dates, and due dates. Never their name, email, organisation, any identifier or assessment data. A moderation check receives the question alone, and naming a new Ask chat sends its first question and the start of the answer once. Requests are sent with storage switched off | The United States |
| Anthropic | Drafting course sections and assessment questions with Claude from the sources and plan we give it; and Claude used by our staff through our course-authoring connector, which can read the names, qualifications, registration numbers and email addresses of the authors and reviewers on our register. No learner data sent | The United States |
| Microsoft | Email through Microsoft 365 and Microsoft Graph, sent from training@rtriibe.com, with a copy kept in that mailbox's sent items for up to 12 months | Microsoft's data centres, which may be outside the United Kingdom, including in the European Union and the United States |

## Schedule 3: Technical and organisational measures

- Encryption of data in transit (HTTPS). Our database and file storage are
  encrypted at rest by Supabase.
- Row-level security in the database, keyed on user identity first and on an
  organisation's grant second, so that a defect in application code cannot expose
  one customer's data to another.
- Role-based access within a customer account, with a manager restricted to
  pass or fail and the certificate; answers, scores and attempt history are not
  exposed to any organisation role.
- Access to production data only for rTriibe staff who need it for their work,
  granted by a director, removed when no longer needed, and reviewed at least
  once a year.
- Append-only audit log of the changes our staff make.
- Backups: daily, kept for up to 7 days by our database provider. Restore
  testing: at least once a year.
- Secure development: the key that can bypass the database's access rules is held
  only on the server, and the build fails if any code that reaches the browser
  could import it. We have not yet commissioned an independent penetration test.
- Staff: checks appropriate to the role, confidentiality undertakings, annual
  data protection training.
- Certification: we do not yet hold a security certification such as ISO 27001
  or Cyber Essentials.
- Business continuity and incident response plan reviewed at least once a year.

## Schedule 4: Product analytics on learners

Select one. If nothing is selected, option A applies.

**Option A: Masked (default).** No behavioural analytics is attributed to any
of your learners. No identifier is attached to any event, no analytics state
persists between a learner's visits, no visit is recorded, and events describing
an individual's route through a lesson are not transmitted. Anonymous
measurement, such as pageviews outside lessons and whether a control in the
lesson player (captions, for example) was used, is unaffected: it carries no
identifier and cannot be joined across visits. The separate document described
below lists every event that is still sent.

**Option B: Permitted.** You instruct us to process your learners' behavioural
data for the purpose of improving course content and platform usability, on the
basis that: no assessment data is included; identification is by opaque user
identifier only, never by name or email address; data is held in the European
Union; we keep it for up to 12 months; and you may withdraw this instruction at
any time with effect within 5 working days.

In both options, assessment data (answers, scores, pass or fail, item references)
is never transmitted to any analytics service for any customer. The technical
implementation of the masking switch is documented in a separate document written
for your data protection officer, which we send on request.

Selected (the Controller ticks one): Option A ☐ Option B ☐

## Schedule 5: Retention

| Record | Retention | Set by |
| --- | --- | --- |
| Your copy of training records and certificates | 6 years from the end of your subscription, unless you set another period here: ______________ | You |
| Membership history (joiners and leavers) | Same as training records | You |
| Assignment and reminder history | Same as training records | You |
| Invitations | Can be accepted for 30 days, then expire; an expired invitation is kept for the same period as training records | You |
| Learner's own record and certificates | For as long as the learner's account exists, per our privacy notice, as controller | Us |
| Certificates of an archived learner account, which still verify | For as long as the archived account exists; deleted, and no longer verifiable, if the learner asks to be erased | Us |
| Ask and section tutor questions and answers | 90 days, deleted by a daily job | Us |
| Text of emails sent | 12 months, then cleared by a daily job | Us |
| Technical and security logs | No more than 30 days | Us |
| Backups | Daily, kept for up to 7 days by our database provider | Us |
| Analytics events, where Option B applies | Up to 12 months | Us |

## Signatures

Signed for and on behalf of the Controller:

- Signature: ______________________
- Name: ______________________
- Role: ______________________
- Date: ______________________

Signed for and on behalf of the Processor, RTRIIBE LTD:

- Signature: ______________________
- Name: ______________________
- Role: ______________________
- Date: ______________________
