Data processing agreement
Our standard terms for processing personal data on behalf of universities.
Legal documents are published in English. Text in [brackets] is a placeholder to be completed before launch.
1. Scope and roles#
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer (the controller) and Oxonia (the processor) for Oxonia Govern. It applies to personal data we process on the Customer’s behalf ("Customer Personal Data"), and is designed to meet the processor requirements of the Nigeria Data Protection Act 2023, the UK GDPR and the EU GDPR where they apply.
2. Processing on instructions#
We process Customer Personal Data only on the Customer’s documented instructions — the agreement, the Customer’s configuration of the Service, and further written instructions — unless the law requires otherwise, in which case we will inform the Customer first where legally allowed. We will tell the Customer if we believe an instruction infringes data protection law.
3. Details of processing#
| Item | Description |
|---|---|
| Subject matter | Provision of Oxonia Govern (governance meetings, AI policy and compliance, training and related services) |
| Duration | The subscription term, plus the exit period |
| Data subjects | Staff, students, governing-body members, invitees, vendors and other people whose data the Customer enters |
| Categories of data | Identity and contact data; governance records; recordings and transcripts; AI-use declarations and process evidence; training records; incident and case records; audit logs |
| Special categories | Only where the Customer chooses to include them (for example in confidential minutes or integrity cases); the Customer is responsible for the lawful basis |
| Location | The data region selected for the Customer’s tenant, and sub-processor locations listed on the Sub-processors page |
4. Confidentiality of personnel#
Everyone we authorise to process Customer Personal Data is bound by confidentiality, trained, and given access only as needed. Support access to a tenant, including impersonation, requires a stated reason and is recorded in the Customer’s audit log.
5. Security measures#
We implement appropriate technical and organisational measures, including:
- encryption in transit (TLS 1.2 or higher) and at rest, with per-tenant keys for documents;
- tenant isolation enforced in the application and by database row-level security;
- role-based access, per-item confidentiality, and mandatory two-factor authentication for privileged roles;
- append-only audit logs of access, approvals, votes, exports, agent runs and impersonation;
- secure development, dependency management, and testing of isolation and permissions on every change;
- backups with tested restoration, and business continuity arrangements.
6. Sub-processors#
The Customer gives general authorisation for the sub-processors on our Sub-processors page. We will give at least 30 days’ notice of any addition or replacement, during which the Customer may object on reasonable data protection grounds. We impose data protection terms on each sub-processor no less protective than this DPA and remain responsible for their performance.
7. Assistance and data subject requests#
We help the Customer respond to data subject requests (the Service includes export and deletion tools), and with data protection impact assessments, prior consultations and security obligations, taking into account the nature of the processing.
8. Personal data breaches#
We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include what we know about its nature, likely consequences and the measures taken, and we will update the Customer as we learn more. The Customer remains responsible for notifying regulators and data subjects where required.
9. International transfers#
We will not transfer Customer Personal Data outside the selected region except to sub-processors listed on our Sub-processors page, and then only with appropriate safeguards required by applicable law, such as standard contractual clauses or equivalent mechanisms.
10. Audits#
We make available information necessary to demonstrate compliance, including our security documentation and independent reports as they become available. The Customer may carry out an audit, on reasonable notice and at most once a year unless a breach or regulator requires otherwise, subject to confidentiality.
11. Return and deletion#
At the end of the agreement the Customer can export its data for at least 30 days. We then delete Customer Personal Data, including from backups within their normal rotation, unless the law requires us to keep it, and confirm deletion on request.
Signing the DPA#
Customers who need a countersigned copy can request one from legal@oxonia.app.