Data processing
DPCA
The Data Processing and Cross-Border Addendum describes how AdaptLearn supports controller-processor expectations, cross-border handling, and operational safeguards for teams and institutions using the platform.
Legal contact
Company
AdaptLearn Technologies
Support email
[email protected]Business correspondence address
11 Tunde Akodu, NEPA Estate, Behind Kayroy Hotel, Off Igbe Road, Ginti, Ikorodu, Lagos, Nigeria
Effective date
March 16, 2026
Version
v1.0
Language notice
This legal page follows your selected interface language for navigation and page framing. The current governing legal text remains this published English version until reviewed local-language versions are issued.
1. Scope
This addendum applies where AdaptLearn processes personal data on behalf of a customer, institution, team owner, or organizational administrator in connection with platform use. In those cases, the customer acts as the controller or business customer for that customer data, and AdaptLearn acts as a processor or service provider for the limited processing described here.
2. Processing instructions
AdaptLearn processes personal data only to provide the contracted services, support the learner experience, secure the platform, respond to documented customer instructions, and meet legal obligations. AdaptLearn should not process customer data for purposes incompatible with those instructions except where required by applicable law.
3. Categories of data and data subjects
Typical categories may include learner account details, profile preferences, learning records, tutor interactions, assessment results, support records, payment metadata, and organization seat assignments. Data subjects may include learners, administrators, institutional contacts, and billing contacts. AdaptLearn does not need to store full payment card numbers or card verification data to provide the service.
4. Security measures
AdaptLearn is expected to maintain reasonable technical and organizational measures such as access control, authentication, confidentiality obligations for personnel, auditability, payment verification, abuse controls, service monitoring, backup and recovery practices, and other secure operational measures appropriate to the risk profile of the service.
5. Subprocessors
AdaptLearn may engage infrastructure, AI, payment, email, analytics, and support subprocessors where necessary to operate the service. Those subprocessors should be bound by obligations consistent with confidentiality, security, and lawful data handling. Where payments are processed through a third-party payment provider, that provider may process cardholder data directly within its own controlled payment environment, and AdaptLearn should receive only the payment and subscription data needed to complete billing, fraud prevention, support, and audit functions.
6. Cross-border transfers
Where data is transferred internationally, AdaptLearn should rely on appropriate transfer mechanisms and safeguards consistent with applicable privacy laws, including contractual protections, subprocessor controls, and other safeguards where needed.
7. Assistance and incident handling
AdaptLearn should support reasonable requests relating to privacy rights, incident response, deletion, return or export of customer data, and compliance inquiries, to the extent required by law and feasible within the service architecture. AdaptLearn should also provide reasonable cooperation in connection with security incidents affecting customer data and make available information reasonably necessary to demonstrate compliance with its processor obligations.
8. Contractual completion before launch
This page is a product-facing summary, not a negotiated enterprise data processing agreement. Before broad launch or large organizational contracting, the final contractual DPCA should still be reviewed and completed with counsel so it matches your actual subprocessors, data flows, retention rules, incident obligations, and jurisdiction-specific requirements.
