Data Processing Agreement
ReviewED Solutions Corporation | Last updated: July 2026
Effective date: July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the subscribing school or educational institution ("School" or "Controller") and ReviewED Solutions Corporation ("ReviewED" or "Processor"), a corporation registered in the Republic of the Philippines. This DPA governs the processing of Personal Data by ReviewED on behalf of the School in connection with the provision of the ReviewED platform and services (the "Service").
This DPA supplements and is incorporated by reference into the Terms of Service and School Agreement between the parties. In the event of any conflict between this DPA and the Terms of Service regarding data processing, this DPA shall prevail.
1. Definitions
Capitalised terms used but not defined in this DPA have the meanings given in the Terms of Service. For the purposes of this DPA:
- "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including but not limited to: the Philippine Data Privacy Act of 2012 (RA 10173) and its Implementing Rules and Regulations; the EU General Data Protection Regulation (GDPR) 2016/679; the UK GDPR; the Swiss Federal Act on Data Protection; and, to the extent applicable, CCPA, FERPA, and COPPA.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
- "Data Subject Request" means any request from a Data Subject to exercise their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection.
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by ReviewED on behalf of the School under this DPA.
- "Processing" means any operation performed on Personal Data, whether by automated means or not, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
- "Standard Contractual Clauses" or "SCCs" means the EU Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as may be amended or superseded.
- "Student Data" means Personal Data within the School Data that relates to an identified or identifiable student.
- "Sub-processor" means any third party engaged by ReviewED to process Personal Data on behalf of the School under this DPA.
2. Roles of the Parties
The parties acknowledge and agree that:
- The School is the Data Controller with respect to all Personal Data processed through the Service. The School determines the purposes and means of processing Personal Data.
- ReviewED is the Data Processor with respect to all Personal Data processed through the Service. ReviewED processes Personal Data solely on the School's documented instructions as set out in this DPA and the Terms of Service.
- Each party shall comply with its respective obligations under Applicable Data Protection Law.
3. Details of Processing
Annex A (Processing Details) sets out the subject matter, nature, purpose, and duration of processing; the types of Personal Data processed; and the categories of Data Subjects whose Personal Data is processed under this DPA. Annex A forms an integral part of this DPA.
4. Data Processing Activities
ReviewED processes the following categories of data, as further described in Annex A:
- School Administrative Data: School name, physical address, contact information, enrollment figures, evaluation bodies, curricula offered, and school leadership details.
- User Account Data: Names, professional email addresses, job titles/roles, and account credentials of Authorised Users (adult school staff only). Students do not have accounts on or direct access to the Service.
- School Documents & Evidence: Files, documents, self-study reports, action plans, policies, meeting minutes, survey results, and other materials uploaded by Authorised Users for evaluation preparation and school improvement purposes.
- Student-Related Data: Student academic performance records, assessment results, enrollment statistics, and other student-related information uploaded by Authorised Users for evaluation evidence gathering. Students cannot directly input or access data on the Service.
- Analysis Results & Reports: Platform-generated analysis, readiness assessments, gap analyses, and evaluation reports produced from School Data.
- Activity Logs & Usage Data: Login timestamps, feature usage, actions taken, and technical logs for security and support purposes.
5. Controller Obligations
The School, as Data Controller, is responsible for and warrants that:
- It has a lawful basis for processing all Personal Data uploaded to or processed through the Service, including any necessary consents from Data Subjects (or their parents/guardians, in the case of students);
- It has provided all necessary notices to Data Subjects regarding the processing of their Personal Data through the Service, as required by Applicable Data Protection Law;
- It has the authority to instruct ReviewED to process Personal Data as described in this DPA;
- It is solely responsible for the accuracy, quality, and legality of the Personal Data it provides to ReviewED and the means by which it acquired such data;
- It will not instruct ReviewED to process Personal Data in a manner that would violate Applicable Data Protection Law;
- It has designated an appropriate contact person for data protection matters and will notify ReviewED of any changes to such designation.
6. Processor Obligations
ReviewED, as Data Processor, agrees and warrants that it shall:
- Process on Instructions: Process Personal Data only in accordance with the School's documented instructions as set out in this DPA and the Terms of Service, unless required to do otherwise by applicable law;
- Confidentiality: Ensure that all personnel authorised to process Personal Data are bound by appropriate confidentiality obligations, whether by contract or by statutory duty;
- Security: Implement and maintain the technical and organisational measures set out in Section 7 to protect Personal Data;
- Sub-processing: Comply with Section 8 when engaging any Sub-processor;
- Data Subject Requests: Provide reasonable assistance to the School in responding to Data Subject Requests, to the extent possible and as required by Applicable Data Protection Law;
- Data Breach Notification: Notify the School of any Security Incident in accordance with Section 11;
- DPIAs and Consultations: Provide reasonable assistance to the School in conducting data protection impact assessments (DPIAs) and prior consultations with supervisory authorities, where required by Applicable Data Protection Law;
- Deletion or Return: At the School's choice and upon termination of the Service, delete or return all Personal Data in accordance with Section 9;
- Audit and Compliance: Make available to the School all information necessary to demonstrate compliance with this DPA and Applicable Data Protection Law, and allow for and contribute to audits in accordance with Section 12;
- Record-Keeping: Maintain written records of all categories of processing activities carried out on behalf of the School, as required by Applicable Data Protection Law;
- Lawful Instructions: Immediately inform the School if, in ReviewED's opinion, an instruction from the School infringes Applicable Data Protection Law.
7. Data Security Measures
ReviewED shall implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures shall include, at a minimum:
- Encryption: Data encrypted in transit using TLS 1.2 or higher; data at rest encrypted using AES-256 encryption;
- Access Control: Role-based access control (RBAC) with the principle of least privilege; multi-factor authentication (MFA) for administrative and privileged access; unique user IDs and strong password policies;
- Authentication: Secure password hashing (bcrypt); secure session management with configurable timeout; optional MFA for user accounts;
- Network Security: Firewalls, network segmentation, intrusion detection and prevention systems (IDS/IPS), and DDoS protection;
- Application Security: Secure software development lifecycle (SDLC) practices; regular static and dynamic application security testing; input validation and output encoding to prevent common vulnerabilities (OWASP Top 10); regular dependency and vulnerability scanning;
- Monitoring: Continuous security event logging and monitoring; automated alerts for suspicious activity; regular security reviews and penetration testing;
- Backup & Recovery: Daily encrypted backups; tested disaster recovery and business continuity plan; recovery time objective (RTO) of 24 hours; recovery point objective (RPO) of 24 hours;
- Personnel: Security awareness training for all staff who access Personal Data; background screening for staff with privileged access; formal incident response procedures.
8. Sub-Processors
ReviewED currently engages the following Sub-processors to assist in providing the Service:
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Base44 Cloud Infrastructure | Platform hosting, storage, and infrastructure | EU / US |
| Stripe | Payment processing (PCI-DSS compliant). No School Data or Student Data is shared with Stripe. | US / EU |
| Transactional Email Provider | Service-related email communications (billing notices, security alerts, account notifications) | US / EU |
ReviewED shall notify the School of any new or changed Sub-processors at least thirty (30) days before the change takes effect, via email or in-Service notification. The School may object to a new Sub-processor on reasonable data protection grounds by notifying ReviewED in writing. If ReviewED is unable to accommodate the School's objection, the School may terminate this DPA and the associated Services on thirty (30) days' written notice.
ReviewED shall ensure that each Sub-processor is bound by data protection obligations no less stringent than those in this DPA.
9. Data Retention & Deletion
ReviewED retains Personal Data while the School's subscription is active. Upon termination or expiry of the subscription, ReviewED will retain Personal Data for thirty (30) days to allow the School to export its data. After this period, ReviewED will securely and irreversibly delete all Personal Data using industry-standard data deletion methods, unless legally required to retain it for a longer period.
At the School's written request, ReviewED will confirm in writing that deletion has been completed.
10. International Data Transfers
Where Personal Data is transferred outside the School's country or outside the European Economic Area (EEA), ReviewED will ensure that such transfers are subject to appropriate safeguards under Applicable Data Protection Law. Appropriate safeguards may include Standard Contractual Clauses (SCCs), adequacy decisions, or other mechanisms recognised under applicable law.
Upon request, ReviewED will provide the School with information about the safeguards in place for international data transfers.
11. Incident Notification
In the event of a Security Incident, ReviewED will:
- Notify the School without undue delay, and in any event within seventy-two (72) hours of becoming aware of the Security Incident, to the extent such notification is reasonably possible;
- Provide the School with the following information (to the extent known at the time of notification, with further information provided as it becomes available): (a) the nature of the Security Incident; (b) the categories and approximate number of Data Subjects affected; (c) the categories and approximate volume of Personal Data affected; (d) the likely consequences of the Security Incident; and (e) the measures taken or proposed to address the Security Incident;
- Cooperate with the School in any investigation, regulatory notification, or remediation required as a result of the Security Incident.
The School is responsible for determining whether to notify relevant supervisory authorities or Data Subjects, as required by Applicable Data Protection Law. ReviewED will provide reasonable assistance to the School in making such determinations and notifications.
12. Audit Rights
The School has the right to audit ReviewED's data processing practices to verify compliance with this DPA, upon reasonable written notice of at least thirty (30) days. Audits shall be: (a) conducted during regular business hours and without unreasonably disrupting ReviewED's operations; (b) carried out no more than once per calendar year, unless a Security Incident has occurred; (c) at the School's cost; and (d) subject to the execution of a non-disclosure agreement if ReviewED reasonably requires it to protect sensitive security documentation.
ReviewED may satisfy its audit obligations by providing the School with audit reports, certifications, or attestations from independent third-party auditors (e.g., ISO 27001 certification, SOC 2 report), where available. To schedule an audit, please visit our Contact Us page.
13. Governing Law
This DPA is governed by and shall be construed in accordance with the laws of the Republic of the Philippines, and in particular the Philippine Data Privacy Act of 2012 (RA 10173). For schools in other jurisdictions, applicable local data protection laws shall also apply to the extent required by law.
14. Contact
For questions, notices, or concerns regarding this Data Processing Agreement, please contact us through:
- The Contact Us page on the ReviewED website; or
- LinkedIn Page: ReviewED
