eClassy

Data Processing Agreement (DPA)

Last updated: September 2026 · Version 1.0

This Data Processing Agreement (“DPA”) forms part of the agreement between the institute/school customer (“Controller”, “you”) and Bitscy, operator of the eClassy Teacher and eClassy Class applications (“Processor”, “we”, “eClassy”), for the provision of the eClassy platform (the “Service”).

This DPA applies where we process personal data on behalf of the Controller in connection with the Service, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Cyprus / EU data-protection law.

This document is a practical template aligned with how eClassy operates. It is not a substitute for legal advice. Controllers should review it (and, if needed, have counsel review it) before relying on it.

1. Parties and roles

Individual teacher accounts and parent/guardian accounts also have their own privacy notices (see Teacher privacy policy and Class privacy policy). Where an institute uses eClassy for student and parent school data, the institute is typically the controller for that school data and eClassy is the processor.

2. Definitions

Terms such as “personal data”, “processing”, “data subject”, “controller”, “processor”, “sub-processor”, and “personal data breach” have the meanings given in the GDPR. “Customer Data” means personal data uploaded to or generated in the Service by or for the Controller (including student, parent/guardian, and staff data managed in the institute’s workspace).

3. Subject matter, duration, nature and purpose

4. Types of personal data and data subjects

Data subjects may include:

Categories of personal data may include:

The Controller shall not instruct eClassy to process special categories of data (GDPR Art. 9) unless strictly necessary for the Service and lawful; the Service is not designed as a medical or sensitive-data system.

5. Controller instructions

The Processor shall process Customer Data only on documented instructions from the Controller, including those set out in this DPA, the Service configuration, and the Controller’s use of the apps/admin features, unless required to do otherwise by EU or Member State law (in which case we will inform the Controller unless legally prohibited).

The Controller is responsible for the lawfulness of its instructions, for informing parents/staff as required, and for ensuring it has a valid legal basis to process Customer Data in the Service.

6. Confidentiality

The Processor ensures that persons authorised to process Customer Data are bound by confidentiality obligations and process such data only as needed to provide the Service or as required by law.

7. Security measures

Taking into account the state of the art, costs, and the nature/scope/context of processing, the Processor implements appropriate technical and organisational measures to protect Customer Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These include, as applicable:

No method of transmission or storage is 100% secure. The Controller must also protect account credentials and limit staff access appropriately.

8. Sub-processors

The Controller authorises the Processor to engage sub-processors as needed to provide the Service. Current material sub-processors include:

The Processor shall impose data-protection obligations on sub-processors that are materially no less protective than those in this DPA. The Processor remains responsible for sub-processor performance insofar as required by GDPR Art. 28.

We may update the sub-processor list as the Service evolves. Material changes will be reflected in this DPA or related notices. Continued use of the Service after notice constitutes acceptance of the updated list, unless the Controller terminates as allowed under the main agreement.

9. International transfers

Where Customer Data is transferred outside the EEA/UK, the Processor shall ensure an appropriate transfer mechanism under GDPR Chapter V (for example Standard Contractual Clauses and/or the sub-processor’s own transfer tools, such as those used by Google).

10. Assistance with data-subject rights

Taking into account the nature of processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Controller’s obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, objection).

If a data subject contacts eClassy directly about Controller-held school data, we may redirect the request to the Controller and/or assist the Controller to handle it.

11. Personal data breaches

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and shall provide information reasonably available to help the Controller meet its GDPR notification obligations.

Breach notices should be sent to the Controller’s primary admin/owner contact on file and/or the email associated with the institute account. Controllers should keep contact details up to date and may also write to k.ioannouy@bitscy.com.

12. Retention, deletion and return

See also: Teacher – delete account · Class – delete account.

13. Audits and information

The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with GDPR Art. 28, and shall allow for and contribute to audits (including inspections) conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice, confidentiality, security, and frequency limits so as not to disrupt the Service or other customers. Remote questionnaires and existing documentation will be preferred where sufficient.

14. Controller obligations

The Controller shall:

15. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the main Service terms / subscription terms between the parties, except where such limitation is prohibited by mandatory law (including GDPR). Nothing in this DPA reduces either party’s responsibilities under GDPR that cannot be contracted out of.

16. Order of precedence

If there is a conflict between this DPA and other non-privacy terms, this DPA prevails for data-protection matters. More specific written instructions agreed by both parties in writing may supplement this DPA.

17. Governing law

This DPA is governed by the laws of the Republic of Cyprus, without prejudice to mandatory GDPR provisions and the supervisory authority competence applicable to the Controller.

18. Contact

For DPA or privacy questions:
Email: k.ioannouy@bitscy.com
Related policies: Teacher privacy · Class privacy · Support

19. Acceptance

By creating or administering an institute on eClassy Teacher, or by otherwise using the Service as an institute customer, the Controller acknowledges this DPA. Where a signed copy is required, the parties may complete the signature block below (or execute an equivalent electronic acceptance).

Signature block (optional)

Controller (Institute)

Processor (Bitscy / eClassy)

Annex A — Summary of processing

Annex B — Sub-processors (illustrative)