Data Processing Agreement
How Eduworks processes customer data on your instructions, as your processor.
Draft — not yet reviewed by counsel. This document is published for internal review and customer feedback. It does not yet bind Eduworks or any customer, and it must not be relied on in a contract or a security review until legal review is complete.
Questions or corrections: legal@eduworks.com.
Last updated September 2026.
This agreement applies where Eduworks processes personal data on a customer's behalf in the hosted CADRE service. It forms part of the Terms of Service. Where a signed DPA exists between us, that signed document governs.
1. Roles
The Customer is the controller of the personal data it puts into its instance and decides why and how it is processed. Eduworks is the processor and acts only on the Customer's documented instructions. Using the service as designed — provisioning, running, backing up and supporting the instance — constitutes those instructions.
2. Subject matter and scope
| Subject matter | Provision of the hosted CADRE competency and training-analytics service. |
|---|---|
| Duration | For as long as the subscription is in effect, plus any retention period agreed afterwards. |
| Nature and purpose | Hosting, storage, indexing, backup, analysis and display of competency and training records. |
| Categories of data subject | The Customer's personnel, learners and trainees; the Customer's administrators. |
| Types of personal data | Identity and contact details; role and organizational unit; competency assertions, assessments, evidence and training records; usage and audit records. |
| Special categories | Not required by the service. The Customer should not submit special-category data without agreeing it with us first. |
3. Our obligations
- Process personal data only on the Customer's documented instructions, including on transfers, unless the law requires otherwise — in which case we will tell the Customer first unless prohibited from doing so.
- Ensure that people authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (section 4).
- Assist the Customer, so far as we reasonably can, with data subject requests, security obligations, breach notification and impact assessments.
- Delete or return personal data at the end of the engagement, at the Customer's choice (section 8).
- Make available the information reasonably needed to demonstrate compliance (section 9).
4. Security measures
Current measures are described in detail on the Trust Center, and in summary are: a dedicated isolated instance per subscription with no shared datastore between customers; network policy restricting traffic between tenants; encryption in transit and at rest; federated single sign-on with no password held by Eduworks; a customer- controlled user allow-list that grants access to nobody by default; optional network-level restriction to customer-specified addresses; logged and notified administrative access by named staff; and backups to private, access-controlled storage scoped per subscription.
We may update these measures, but not in a way that materially reduces the level of protection.
5. Subprocessors
The Customer authorizes the subprocessors listed on the Trust Center. We remain responsible for their performance, and impose data protection obligations on them no less protective than these. We will update that list before engaging a new subprocessor; the Customer may object on reasonable data protection grounds, and if we cannot resolve the objection the Customer may terminate the affected service.
6. Data subject requests
The service gives the Customer direct access to its own data, so most requests can be satisfied without us. Where a data subject contacts us directly, we will refer them to the Customer rather than act on their data. We will assist the Customer with requests it cannot fulfil through the service itself.
7. Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting its data, and in any event within [notification window to be set by counsel]. The notification will describe what we know, the likely consequences, and the measures taken or proposed. We will provide further detail as the investigation develops rather than delaying the first notification until everything is known.
8. Return and deletion
The Customer can export its data at any time using the backup facility in the service. Note the default behaviour on cancellation: we retain the instance's storage rather than deleting it, so that reactivating restores the data, and backups remain downloadable. On the Customer's written request we will delete the data and confirm when it is done, subject to any retention the law requires of us.
The Customer can also carry this out itself, without asking us. The account page offers an election to delete everything when the subscription ends, and an immediate permanent deletion once it has been cancelled; both remove the instance storage and every stored backup, and a deletion record is written. Eduworks staff cannot invoke either on a Customer's behalf. This is the documented, verifiable deletion process required by CSA CCM DSP-16, and how we meet MP-6 and 800-171 03.08.03.
9. Audit
We will make available the information reasonably necessary to demonstrate compliance with this agreement, including the Trust Center, completed security questionnaires, and the results of any independent testing we hold. Eduworks does not currently hold a SOC 2 attestation; where a customer's audit rights require more than the above, we will agree scope, timing and cost in advance.
10. International transfers
Customer data is hosted in the United States and we do not transfer it elsewhere in the course of providing the service. Where a customer is subject to a jurisdiction requiring a specific transfer mechanism, contact us during contracting. [Standard contractual clauses to be attached by counsel if EU or UK customers are in scope.]