Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between you (the “Instructor,” acting on behalf of your school or institution where one exists, or in your individual capacity where none does) and Antoinette LLC (the “Service Provider”) governing the Service Provider’s processing of personal data belonging to your students in connection with the Antoinette application (the “Application”). Capitalized terms not defined here have the meaning given in the Terms of Service and Privacy Policy.
1. Roles of the Parties
For personal data you provide about your own account — your name, email, billing details, and your own usage of the Application — the Service Provider is the Data Controller, as described in the Privacy Policy.
For personal data about your students — identity information, submitted coursework, revision history, academic-integrity signals, and enrollment records — you are the Data Controller and the Service Provider is your Data Processor, processing that data solely on your documented instructions as set out in this DPA. Where you are acting on behalf of a school or institution, “you” in this DPA means that school or institution, and you represent that you have the authority to enter into this DPA on its behalf.
2. Subject-Matter, Duration, Nature, and Purpose of Processing
The subject-matter of processing is the operation of the Application for your course(s): accepting, storing, and displaying student submissions; computing academic-integrity signals; supporting grading and feedback; and providing the reporting and roster features described in the Application. Processing continues for as long as your account remains active, and for any period afterward required to comply with the deletion or retention terms in Section 10.
3. Categories of Data and Data Subjects
The data subjects are the students you enroll or otherwise enter into the Application. The categories of personal data processed are described in full in the Service Provider’s internal data inventory and, in summary, include: student name, email, and (where you choose to provide them) date of birth and phone number; submitted coursework, including full revision history; academic-integrity signals derived from that work; enrollment and course-roster records; and system-generated records such as timestamps and audit-log entries. A current, detailed list is available on request.
4. Processor Obligations
The Service Provider will process student personal data only on your documented instructions, as reflected in the Application’s ordinary functionality and this DPA, and only for the purposes described in Section 2. The Service Provider will not use student personal data for its own independent purposes — including, without limitation, training any AI/machine-learning model, marketing, or sale of any kind — consistent with the commitments in the Privacy Policy.
5. Confidentiality
The Service Provider ensures that personnel authorized to process student personal data are subject to confidentiality obligations, whether contractual or statutory.
6. Security Measures (Art. 32 GDPR)
The Service Provider implements technical and organizational measures appropriate to the risk, described in summary on the Privacy and Security page and in greater detail on request, including encryption in transit, database-level tenant isolation, mandatory multi-factor authentication for administrative access, and an append-only audit log.
7. Sub-Processors
You grant the Service Provider general authorization to engage sub-processors to operate the Application, subject to imposing data-protection obligations on those sub-processors consistent with this DPA and notifying you of any material change. A current list of sub-processors, and what each one sees, is available on request by contacting privacy@antoinette-official.com.
8. Assistance with Data-Subject Rights
The Service Provider will provide reasonable assistance to help you respond to requests from your students (or their parents or guardians, where applicable) to exercise their data-subject rights. In practice, much of this assistance is already available directly in the Application: you can view, correct, and manage your students’ records, and deactivate a student’s account, without needing to contact the Service Provider.
9. Personal Data Breach Notification
The Service Provider will notify you without undue delay after becoming aware of a personal data breach affecting your students’ personal data, consistent with the 72-hour supervisory-authority notification commitment in the Privacy Policy, so that you can meet your own notification obligations as controller.
10. Deletion or Return of Data
On termination of your account, the Service Provider will delete or anonymize student personal data in line with the retention and deletion mechanisms described in the Privacy Policy and the Application’s account-deletion features, except to the extent retention is required by law or for the legitimate purpose of maintaining academic records. You may request deletion of specific student records at any time, subject to those same limits.
11. Audit and Compliance
The Service Provider will make available the information reasonably necessary to demonstrate compliance with this DPA, including the security documentation referenced in Section 6, and will cooperate with audits or inspections conducted by you or an auditor you mandate, subject to reasonable notice and confidentiality safeguards.
12. FERPA School-Official Designation
Where the Family Educational Rights and Privacy Act (“FERPA”) applies, you designate the Service Provider as a “school official” with a “legitimate educational interest” in the student data described in Section 3, for the sole purpose of providing the Application. The Service Provider will: use the data only for that contracted purpose; maintain direct control over the data consistent with this DPA; not re-disclose the data except as necessary to provide the Application or as you direct; and delete the data on request consistent with Section 10.
