Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement governing use of the Cognivio platform (the “Agreement”) between Cognivio Ltd. (in formation) (“Cognivio”) and the educational institution identified in the Agreement (“Customer”). This DPA applies to the extent Cognivio processes personal data on behalf of Customer in the course of providing the Service.
1. Definitions
- “Student Data” means personal data relating to an identifiable student, as defined under applicable education and data protection laws.
- “Personal Data” has the meaning given under applicable data protection laws.
- “Non-Identifiable Data” has the meaning set forth in Cognivio’s Privacy Policy.
- “Processing” has the meaning given under GDPR Article 4.
- “Subprocessor” means a third party engaged by Cognivio to process Personal Data on behalf of Customer.
2. Roles of the Parties
2.1 Customer as Controller
Customer is the Data Controller (or equivalent) with respect to Student Data and determines the purposes and lawful basis for Processing.
2.2 Cognivio as Processor
Cognivio acts as a Data Processor and processes Student Data solely on behalf of and in accordance with Customer’s documented instructions, this DPA, and the Agreement.
2.3 Independent Control of Non-Identifiable Data
Cognivio may independently determine how Non-Identifiable Data is used, provided such data does not reasonably identify any individual.
3. Scope of Processing
3.1 Subject Matter
Processing of classroom video, audio, and related metadata for professional learning, instructional feedback, and system operation.
3.2 Duration
For the term of the Agreement, subject to deletion instructions.
3.3 Nature and Purpose
Hosting, storage, analysis, transmission, and deletion of Student Data solely to provide the Service.
3.4 Categories of Data Subjects
Students, educators, and authorized school personnel.
4. Customer Responsibilities
Customer is solely responsible for:
- Determining the legality of recording classroom content
- Providing notices and obtaining all required consents (including parental and biometric consents where applicable)
- Ensuring its use of the Service complies with applicable laws
- Providing documented processing instructions to Cognivio
Customer acknowledges that Cognivio does not monitor classroom environments or verify consent.
5. Cognivio Obligations
Cognivio shall:
- Process Student Data only in accordance with Customer instructions
- Implement appropriate technical and organizational safeguards
- Ensure personnel confidentiality
- Restrict access to Student Data on a need-to-know basis
- Assist Customer with reasonable data subject requests, where applicable
6. Personnel Access and Vetting
Access to unblurred Student Data is limited to authorized Cognivio personnel whose job responsibilities require such access.
Such personnel undergo background screening consistent with applicable law, receive privacy and data protection training, and are subject to confidentiality obligations and disciplinary measures for misuse.
7. Subprocessors
7.1 Authorization
Customer authorizes Cognivio to engage Subprocessors, including cloud infrastructure providers such as Amazon Web Services.
7.2 Obligations
Cognivio imposes data protection obligations on Subprocessors that are no less protective than those set forth in this DPA.
7.3 Responsibility
Cognivio remains responsible for the performance of its Subprocessors as required under applicable data protection laws.
8. Infrastructure Incidents and Remediation
In the event of a security incident or service disruption involving a Subprocessor:
- Cognivio will cooperate with Customer in investigation and remediation
- Cognivio will provide information reasonably necessary for Customer to meet its legal obligations
- Cognivio will pass through to Customer any applicable credits, remedies, or indemnities received from the Subprocessor, to the extent permitted by Cognivio’s agreements
9. De-Identified and Behavioral Data
Cognivio may create and use Non-Identifiable Data, including aggregated or abstracted Behavioral and Interactional Data, for:
- Improving and developing the Service
- Training and improving analytical and machine-learning models
- Developing related features and capabilities
Cognivio commits that it will not attempt to re-identify Non-Identifiable Data and will contractually prohibit third parties from doing so.
10. Biometric Processing
To the extent facial or voice characteristics are processed solely to enable optional blurring or masking features:
- Such processing is automated and limited to rendering content less identifiable
- Biometric data is not used for identification or recognition
- Where enabled, Destructive Blurring permanently deletes unblurred originals after processing
Customer is responsible for determining whether biometric consent is required.
11. Data Retention and Deletion
Upon Customer instruction or termination of the Agreement, Cognivio will delete or return Student Data in accordance with the Service’s functionality, subject to legal retention requirements.
12. Audits
Upon reasonable written request, Cognivio will provide information necessary to demonstrate compliance with this DPA. On-site audits are not permitted without Cognivio’s prior written consent.
13. Governing Law
This DPA is governed by the laws specified in the Agreement, without prejudice to mandatory data protection laws applicable to Customer.
14. Order of Precedence
In the event of conflict, this DPA governs with respect to data processing obligations.
15. Signatures
This DPA is effective upon acceptance of the Agreement.