This is a machine translation of the Bulgarian original. Where the two differ, the Bulgarian text prevails. Read the original in Bulgarian.
Legal
Data Processing Agreement
The agreement under Article 28 GDPR between the school, which is the controller of its teachers’ and students’ data, and us as processor.
Last updated:
This document was prepared from the facts published on this website and follows the structure of Art. 28(3) GDPR. It is not a substitute for legal advice. Before it is signed with schools, it must be reviewed by a lawyer and the details of the company and of the infrastructure provider must be filled in.
1. Parties and roles
This agreement is concluded between the school using the School Exams platform, referred to as the “controller”, and «ФИРМА», UIC «ЕИК», with registered seat «седалище и адрес на управление», referred to as the “processor”.
The school determines the purposes and means of processing the data of its teachers and students. It is a controller within the meaning of Art. 4(7) GDPR.
We process this data only to provide the service and only on the school’s instructions. We are a processor within the meaning of Art. 4(8).
This agreement is an integral part of the subscription contract and is signed together with it.
2. Subject matter, duration, nature and purpose of the processing
Subject matter: processing of personal data of teachers and students necessary for organising, conducting, grading and archiving school exams.
Nature of the processing: collection, recording, storage, structuring, consultation, use, restriction, erasure and transmission of the data to authorised users of the school.
Purpose: provision of the platform under the subscription contract. We do not process the data for any purpose of our own — neither for analysis, nor for training models, nor for advertising.
Duration: for the term of the subscription contract and for the period after its termination set out in section 10.
3. Categories of data subjects and types of data
Categories of data subjects: students, teachers and administrative staff of the school.
Types of data: names; business or school email address; class and study group; subject; content of exam papers and answers; grades, points and comments by criterion; files attached by the user; log of actions in the system; technical access data, including IP address and session data.
No special categories of data under Art. 9 GDPR are processed, unless the school enters such data on its own initiative in free text. The school is responsible for whether such entry is permissible.
4. Processing only on the controller’s instructions
We process personal data only on documented instructions from the school, including with regard to transfers to a third country, unless required to do so by Union or Member State law. In such a case we inform the school before processing, unless the law prohibits this. (Art. 28(3)(a))
The settings made by the school in the platform and the subscription contract constitute documented instructions.
If we consider that an instruction infringes the GDPR or other data protection provisions, we inform the school immediately.
5. Confidentiality of persons with access
Persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. (Art. 28(3)(b))
Access is granted only to employees who need it to maintain the service, and only to the extent necessary.
6. Security measures
We apply appropriate technical and organisational measures under Art. 32 GDPR. (Art. 28(3)(c))
isolation of data per school at database level — one school’s data is not accessible to another;
encryption of all traffic with modern protocols; older versions are disabled;
one active session per user — a new sign-in ends the previous sessions;
request rate limits, separately for the main API, for files and for management;
separation of processes — the database, the cache and the application run with separate rights;
at the school’s option — restricting exams to the IP addresses of the school network only;
a log of every sensitive action: who, when and on what;
regular backups and periodic verification by restoring them in a separate environment.
The measures are described in detail on the security page of this website.
7. Sub-processors
The school gives general prior authorisation for the use of sub-processors. (Art. 28(3)(d), in conjunction with paragraphs 2 and 4)
At present, the sub-processor is the infrastructure provider «хостинг доставчик и държава», which provides hosting for the application, the database and email.
We notify the school in writing at least 30 days before engaging or replacing a sub-processor. The school may object within that period; in the event of a justified objection it has the right to terminate the contract without penalty.
We impose on every sub-processor the same data protection obligations as we have. We are liable to the school for its actions as for our own.
8. Assistance with data subject rights
We assist the school with appropriate technical and organisational measures in responding to requests to exercise rights under Chapter III GDPR. (Art. 28(3)(e))
For this purpose the platform provides: a view of the data stored about the user; export in the machine-readable JSON format; a request to delete an account which, once approved, leads to cascading deletion.
If a request is sent directly to us, we do not answer it on the merits but forward it to the school without undue delay.
9. Assistance under Art. 32–36 and breach notification
We assist the school in fulfilling its obligations under Art. 32–36 GDPR, taking into account the nature of the processing and the information available to us. (Art. 28(3)(f))
In the event of a personal data breach we notify the school without undue delay and no later than 72 hours after becoming aware of it.
The notification contains: what happened, which categories and approximately how many data subjects and records are affected, the likely consequences and the measures we have taken or propose.
10. Deletion or return of the data
After the end of the provision of the service, at the school’s choice, we delete or return all personal data and delete existing copies, unless Union or Member State law requires their storage. (Art. 28(3)(g))
The school states its choice in writing within 30 days of termination. If it does not state a choice, we proceed to deletion once that period has expired.
Backup copies are deleted when their usual retention cycle expires.
11. Information and audits
We make available to the school all information necessary to demonstrate compliance with the obligations under Art. 28, and allow for and contribute to audits, including inspections, conducted by the school or another auditor mandated by it. (Art. 28(3)(h))
Audits are carried out after written notice, during business hours and in a way that does not compromise the security of other schools’ data.
12. Place of processing
The data is processed within the European Economic Area.
We do not transfer data to a third country without the school’s instructions and without a basis under Chapter V GDPR.