Data Processing Agreement (DPA)
Last updated: September 2026 · Version 1.0
This Data Processing Agreement (“DPA”) forms part of the agreement between the institute/school customer (“Controller”, “you”) and Bitscy, operator of the eClassy Teacher and eClassy Class applications (“Processor”, “we”, “eClassy”), for the provision of the eClassy platform (the “Service”).
This DPA applies where we process personal data on behalf of the Controller in connection with the Service, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Cyprus / EU data-protection law.
This document is a practical template aligned with how eClassy operates. It is not a substitute for legal advice. Controllers should review it (and, if needed, have counsel review it) before relying on it.
1. Parties and roles
- Controller: the institute, school, tutoring centre, or other education organisation that uses eClassy Teacher to manage classes, students, staff, and parent communication, and that determines the purposes and means of processing school-related personal data.
- Processor: Bitscy (eClassy), providing the Service (mobile/web apps and related backend) and processing personal data only on documented instructions of the Controller, as set out in this DPA and the Service documentation.
Individual teacher accounts and parent/guardian accounts also have their own privacy notices (see Teacher privacy policy and Class privacy policy). Where an institute uses eClassy for student and parent school data, the institute is typically the controller for that school data and eClassy is the processor.
2. Definitions
Terms such as “personal data”, “processing”, “data subject”, “controller”, “processor”, “sub-processor”, and “personal data breach” have the meanings given in the GDPR. “Customer Data” means personal data uploaded to or generated in the Service by or for the Controller (including student, parent/guardian, and staff data managed in the institute’s workspace).
3. Subject matter, duration, nature and purpose
- Subject matter: hosting and operating the eClassy platform so the Controller can manage classes, students, attendance, homework, announcements, calendar, grades/results, payments/invoices, institute staff, and in-app messaging with parents and staff.
- Nature of processing: collection, storage, organisation, retrieval, transmission (including push notifications), display, and deletion/anonymisation of Customer Data as needed to provide the Service.
- Purpose: providing the Service to the Controller and authorised users (owners, principals, teachers, assistants, parents’ association roles, parents/guardians linked to students), including support and security.
- Duration: for the term of the Controller’s use of the Service, and for any limited retention needed after termination as described in this DPA and our privacy policies (for example backups), unless longer retention is required by law.
4. Types of personal data and data subjects
Data subjects may include:
- Teachers, institute owners, assistants, and other staff users
- Students
- Parents / guardians
- Other contacts entered by the Controller for school communication
Categories of personal data may include:
- Identity and contact data (name, phone, email)
- Account and authentication-related data
- Class, student, attendance, homework, announcement, calendar, and grade/result data
- Payment / invoice reminders and related fee records managed in the Service
- In-app messages (parent–teacher and staff chat), including message content and related student/class context
- Device tokens and notification history needed to deliver push alerts
- Institute membership, roles, and permission settings
The Controller shall not instruct eClassy to process special categories of data (GDPR Art. 9) unless strictly necessary for the Service and lawful; the Service is not designed as a medical or sensitive-data system.
5. Controller instructions
The Processor shall process Customer Data only on documented instructions from the Controller, including those set out in this DPA, the Service configuration, and the Controller’s use of the apps/admin features, unless required to do otherwise by EU or Member State law (in which case we will inform the Controller unless legally prohibited).
The Controller is responsible for the lawfulness of its instructions, for informing parents/staff as required, and for ensuring it has a valid legal basis to process Customer Data in the Service.
6. Confidentiality
The Processor ensures that persons authorised to process Customer Data are bound by confidentiality obligations and process such data only as needed to provide the Service or as required by law.
7. Security measures
Taking into account the state of the art, costs, and the nature/scope/context of processing, the Processor implements appropriate technical and organisational measures to protect Customer Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These include, as applicable:
- Access control and authentication for user accounts
- Role/permission controls within institutes
- Encrypted transmission (HTTPS/TLS)
- Server-side access restrictions and operational logging as needed for security/support
- Deletion and anonymisation workflows for account erasure requests
No method of transmission or storage is 100% secure. The Controller must also protect account credentials and limit staff access appropriately.
8. Sub-processors
The Controller authorises the Processor to engage sub-processors as needed to provide the Service. Current material sub-processors include:
- Google / Firebase — authentication, push messaging (FCM), and related cloud infrastructure used by the apps
- Hosting / infrastructure providers used to run the eClassy backend and databases (as configured by Bitscy)
- Apple App Store / Google Play — where subscription billing is processed by the store (they may act as independent controllers for payment data)
The Processor shall impose data-protection obligations on sub-processors that are materially no less protective than those in this DPA. The Processor remains responsible for sub-processor performance insofar as required by GDPR Art. 28.
We may update the sub-processor list as the Service evolves. Material changes will be reflected in this DPA or related notices. Continued use of the Service after notice constitutes acceptance of the updated list, unless the Controller terminates as allowed under the main agreement.
9. International transfers
Where Customer Data is transferred outside the EEA/UK, the Processor shall ensure an appropriate transfer mechanism under GDPR Chapter V (for example Standard Contractual Clauses and/or the sub-processor’s own transfer tools, such as those used by Google).
10. Assistance with data-subject rights
Taking into account the nature of processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Controller’s obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, objection).
If a data subject contacts eClassy directly about Controller-held school data, we may redirect the request to the Controller and/or assist the Controller to handle it.
11. Personal data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and shall provide information reasonably available to help the Controller meet its GDPR notification obligations.
Breach notices should be sent to the Controller’s primary admin/owner contact on file and/or the email associated with the institute account. Controllers should keep contact details up to date and may also write to k.ioannouy@bitscy.com.
12. Retention, deletion and return
- Chat messages (parent–teacher and staff chat) are automatically deleted after 90 days.
- When a user deletes/anonymises their account, eClassy anonymises profile identifiers and permanently deletes that user’s chat conversations and device push tokens, as described in our delete-account pages.
- School records (classes, students, attendance, grades, invoices, etc.) may be retained for the Controller’s legitimate administration for as long as the institute workspace remains active, or as otherwise required by law.
- Upon termination of the Service relationship, the Controller may export available data using the Service features (where provided) before closure. After termination, the Processor will delete or anonymise Customer Data within a reasonable period, except where retention is required by law or needed for limited backup/security purposes.
See also: Teacher – delete account · Class – delete account.
13. Audits and information
The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with GDPR Art. 28, and shall allow for and contribute to audits (including inspections) conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice, confidentiality, security, and frequency limits so as not to disrupt the Service or other customers. Remote questionnaires and existing documentation will be preferred where sufficient.
14. Controller obligations
The Controller shall:
- Use the Service only for lawful educational / administrative purposes
- Ensure staff enter only data they are authorised to process
- Configure roles and permissions appropriately (including sensitive institute functions)
- Provide required privacy information to parents, students (where applicable), and staff
- Not misuse messaging or upload unlawful content
15. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the main Service terms / subscription terms between the parties, except where such limitation is prohibited by mandatory law (including GDPR). Nothing in this DPA reduces either party’s responsibilities under GDPR that cannot be contracted out of.
16. Order of precedence
If there is a conflict between this DPA and other non-privacy terms, this DPA prevails for data-protection matters. More specific written instructions agreed by both parties in writing may supplement this DPA.
17. Governing law
This DPA is governed by the laws of the Republic of Cyprus, without prejudice to mandatory GDPR provisions and the supervisory authority competence applicable to the Controller.
18. Contact
For DPA or privacy questions:
Email:
k.ioannouy@bitscy.com
Related policies:
Teacher privacy ·
Class privacy ·
Support
19. Acceptance
By creating or administering an institute on eClassy Teacher, or by otherwise using the Service as an institute customer, the Controller acknowledges this DPA. Where a signed copy is required, the parties may complete the signature block below (or execute an equivalent electronic acceptance).
Signature block (optional)
Controller (Institute)
- Institute name: _______________________________
- Authorised signatory name: ____________________
- Title / role: _________________________________
- Email: ______________________________________
- Date: _______________________________________
- Signature: __________________________________
Processor (Bitscy / eClassy)
- Authorised signatory name: ____________________
- Title / role: _________________________________
- Email: k.ioannouy@bitscy.com
- Date: _______________________________________
- Signature: __________________________________
Annex A — Summary of processing
- Services: eClassy Teacher, eClassy Class, related APIs and admin tools
- Main processing activities: school/class administration and parent–teacher communication
- Chat retention: 90 days automatic deletion
- Account erasure: profile anonymisation + chat purge + device token removal
Annex B — Sub-processors (illustrative)
- Google LLC / Firebase — auth, FCM, related cloud services
- Bitscy hosting providers for application/database hosting
- Apple / Google (store billing), where subscriptions are purchased via the stores