Operator Data Processing Agreement
1. Parties and Scope
This Data Processing Agreement ("DPA") is entered into between the educational center subscribing to the Service ("Operator" or "Controller") and Acivem Solutions ("HWA" or "Processor"). It governs the processing of personal data carried out by HWA on behalf of the Operator under the Operator Terms.
2. Definitions
Terms such as "personal data", "processing", "data subject", "controller", and "processor" have the meanings given in Ley 1581 de 2012 and Decreto 1377 de 2013.
3. Subject Matter and Duration
HWA processes personal data solely to provide the Service to the Operator. Processing continues for the term of the Operator Terms and any wind-down period defined in Section 11.
4. Nature and Purpose of Processing
- Account management for attendants, students, and staff.
- Calendar, attendance, and communication functionality.
- Security monitoring, backup, and disaster recovery.
- Technical support requested by the Operator.
5. Categories of Data and Data Subjects
- Data subjects: Operator staff, students, parents/guardians, attendants.
- Categories: identifiers, contact data, role/membership, attendance records, calendar entries, in-app messages, technical/log data.
- No sensitive data should be uploaded unless expressly permitted by the Service.
- Audit ledger entries: records of data-changing actions performed in the Service, including the acting user's identity (email in plaintext, Auth0 subject, roles at the time), the operation and target record type and id, before/after snapshots of the changed record (which may include personal data of Operator staff, students, parents/guardians, and attendants), and request context (IP, user-agent, device platform, timestamps, and correlation ids). Passwords, tokens, and secrets are not stored. Ledger entries are retained for five (5) years from the date of each action for information security, accountability, misuse detection, and the establishment, exercise, or defence of legal claims — including beyond termination of the Operator subscription or a data subject's account deletion (see Sections 7 and 11).
6. Obligations of the Operator
- Obtain and document all authorizations required from data subjects, including parents/guardians of minors.
- Provide accurate privacy notices to its data subjects.
- Use the Service in accordance with applicable Colombian law.
- Configure access controls, roles, and retention settings appropriately.
7. Obligations of HWA
- Process personal data only on documented instructions from the Operator.
- Ensure that personnel authorized to process data are bound by confidentiality.
- Implement the technical and organizational measures described in Annex A.
- Assist the Operator in responding to data subject requests and regulatory inquiries.
- Notify the Operator without undue delay, and in any event within seventy-two (72) hours, of any confirmed personal data breach affecting Operator data.
- Maintain the security audit ledger described in Section 5 for information security, accountability, misuse detection, and the establishment, exercise, or defence of legal claims. Ledger entries are retained for five (5) years and are not deleted when a data subject exercises the right to erasure over their other personal data. This limitation on erasure is disclosed in the Privacy Policy.
8. Sub-Processors
The Operator authorizes HWA to engage sub-processors listed in Annex B, including:
- Auth0 (Okta): identity and access management.
- Amazon Web Services (S3): object storage for media attachments and backups.
- Google (Firebase Cloud Messaging): push notification delivery.
- Cloud hosting provider: compute and database infrastructure.
- Transactional email provider: system notifications.
HWA will notify the Operator of additions or replacements at least thirty (30) days in advance. The Operator may object on reasonable grounds related to data protection.
9. International Transfers
Where sub-processors operate outside Colombia, HWA implements contractual safeguards aligned with SIC guidance for cross-border data transfers.
10. Security Measures (Annex A summary)
- Encryption in transit (TLS 1.2+) and at rest for production stores.
- Role-based access control and least-privilege administration.
- Centralized audit logging and monitoring.
- Regular vulnerability scanning and patch management.
- Documented backup and disaster-recovery procedures.
- Security awareness training for staff with access to personal data.
- Append-only security audit ledger of data-changing actions, retained per the period stated in Section 5 and disclosed in the Privacy Policy, used for information security, accountability, and misuse detection.
11. Return or Deletion
Upon termination of the Operator Terms, HWA will, at the Operator's choice, return or delete Operator personal data within ninety (90) days, except where retention is required by law. The security audit ledger described in Section 5 is retained beyond termination for the security, accountability, and legal-claims purposes disclosed in the Privacy Policy, and is not affected by this return-or-delete obligation.
12. Audit Rights
The Operator may, upon thirty (30) days' written notice and no more than once per year, request reasonable audit evidence (certifications, summaries of penetration tests, or written responses to questionnaires).
13. Liability
Liability under this DPA is governed by the limitation of liability set forth in the Operator Terms.
14. Governing Law
This DPA is governed by the laws of the Republic of Colombia.
15. Contact
For DPA matters: dpo@acivem-solutions.com.