GDPR Art. 28

Data Processing Agreement

This Data Processing Agreement governs the processing of personal data by Zackly on behalf of schools and educational institutions using the Zackly platform.

📅 Effective: 1 May 2026 · Updated: 18 July 2026 📄 Version: 1.0 ⚖️ Governing law: EU GDPR (Regulation 2016/679)
Contents
Section 1

Parties and Definitions

Data Controller

The School / Institution

The legal entity that has entered into a service agreement with Zackly for the use of the Zackly platform, as identified in the school account registration.

Hereinafter: "Controller" or "School"

Data Processor

Zackly (German Word Games)

The operator of the Zackly vocabulary learning platform, reachable at privacy@zackly.app.

Hereinafter: "Processor" or "Zackly"

For the purposes of this Agreement, the following definitions apply:

By registering a school account on the Zackly portal, or by continuing to use the Services after the effective date of this Agreement, the Controller accepts and agrees to the terms of this DPA, which forms part of the broader service agreement between the parties.

Section 2

Subject Matter and Duration

This Agreement governs the Processing of Personal Data by Zackly on behalf of the Controller in connection with the provision of the Services described in the school service agreement.

Zackly will Process Personal Data only for the duration of the service relationship, beginning on the date the school account is activated and ending on the later of:

Section 3

Nature and Purpose of Processing

Zackly processes Personal Data on behalf of the Controller solely to provide the following functions of the Services:

Processing activity Purpose
Student account creation and management Enabling students to access the platform with a class code; linking activity data to individual learner records
Vocabulary learning session tracking Recording which words a student has practised, their accuracy, and session duration to power adaptive learning
Progress and analytics reporting Providing the teacher dashboard with per-student and class-level performance data, completion rates, and gap analysis
Word assignment management Recording teacher-assigned vocabulary sets, deadlines, and completion status
AI writing feedback (Schreiben mode) Submitting anonymised student writing samples (in the studied language) to an AI model for grammar and CEFR-level evaluation; returning feedback to the student
Gamification and engagement tracking Recording XP, streaks, achievements, and challenge progress to support student motivation
Service communications Sending transactional emails to teachers (account setup, assignment reminders); not used for marketing without separate consent

Zackly will not Process Personal Data for any purpose outside the scope of the Services, or for its own commercial purposes, without the prior written consent of the Controller.

Section 4

Categories of Personal Data and Data Subjects

Categories of data subjects:

Categories of personal data processed:

Data category Data subjects Examples
Account identifiers Students, Teachers User ID, class code, display name
Contact data Teachers Email address (required for teacher login and notifications)
Learning activity data Students Words practised, correct/incorrect answers, session timestamps, game mode used
Progress and performance data Students CEFR level, accuracy rate per word, XP, streaks, assignment completion
Writing samples Students Free-text German writing submitted for AI evaluation in Schreiben mode
Device and usage data Students, Teachers Device type, OS version, app version, error logs (no IP addresses stored longer than 24 h)

Zackly does not knowingly process special categories of personal data as defined in GDPR Art. 9, nor criminal conviction data under Art. 10. The Controller shall ensure that no such data is submitted to the platform.

Section 5

Obligations of the Processor

Zackly, acting as Processor, undertakes to:

  1. Process only on documented instructions. Process Personal Data only on the documented instructions of the Controller, including the instructions set out in this Agreement and the service agreement. If required by Union or Member State law, Zackly will inform the Controller before Processing unless prohibited from doing so.
  2. Ensure confidentiality. Ensure that all persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
  3. Implement security measures. Implement the technical and organisational measures described in Section 6.
  4. Respect sub-processor obligations. Engage sub-processors only as set out in Section 7.
  5. Assist with data subject rights. Taking into account the nature of the Processing, assist the Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under Chapter III GDPR.
  6. Assist with compliance obligations. Assist the Controller in ensuring compliance with the obligations in GDPR Arts. 32–36 (security, breach notification, DPIAs, prior consultation) insofar as this relates to data Processed by Zackly.
  7. Delete or return data. At the choice of the Controller, delete or return all Personal Data upon termination of the Services in accordance with Section 12.
  8. Provide audit information. Make available to the Controller all information necessary to demonstrate compliance with this Agreement and allow for and contribute to audits as described in Section 11.

Obligations of the Controller: The Controller represents and warrants that it has a lawful basis under GDPR for the Processing described in this Agreement (e.g. a legitimate interest in providing education, or consent of students' guardians where required), and that it has provided all required notices to data subjects.

Section 6

Technical and Organisational Measures (TOMs)

Zackly implements and maintains the following technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access:

Category Measure
Encryption in transit All data transmitted between clients and the Zackly backend is encrypted using TLS 1.2 or higher. API endpoints are served exclusively over HTTPS.
Encryption at rest Data stored in DynamoDB and S3 is encrypted at rest using AES-256 (AWS server-side encryption).
Access control Access to production infrastructure is restricted to authorised personnel only. Role-based access controls are enforced at both application and AWS IAM level. Principle of least privilege applied.
Authentication Teacher and student accounts are protected by authenticated sessions with 30-day inactivity timeouts. Tokens stored in device secure storage (iOS Keychain / Android Keystore).
Data minimisation Students can join a class using only a class code — no email address is required. Only data necessary for platform function is collected.
Pseudonymisation Writing samples submitted to the AI evaluation service are stripped of student identifiers before transmission.
Logging and monitoring Application error logs are retained for 90 days. Logs do not contain plain-text credentials or full personal data records.
Backup and recovery DynamoDB point-in-time recovery is enabled. Recovery procedures are tested periodically.
Vulnerability management Third-party dependencies are regularly reviewed for known CVEs. Security patches are applied promptly.
Organisational measures Personnel with access to Personal Data receive data protection awareness training. Internal data handling procedures are documented.

Zackly may update these measures over time to reflect the evolving security landscape, provided that the overall level of protection is not reduced. Material changes will be communicated to the Controller.

Section 7

Sub-processors

The Controller provides general authorisation for Zackly to engage sub-processors, subject to the conditions below. Zackly will impose data protection obligations on each sub-processor equivalent to those in this Agreement. Zackly remains liable to the Controller for the performance of each sub-processor's obligations.

The following sub-processors are currently authorised:

Sub-processor Purpose Location Safeguard
Amazon Web Services (AWS) Cloud infrastructure: database, storage, compute, API gateway, and text-to-speech generation of listening-exercise audio (app content only — no personal data in the audio pipeline) European Union (eu-central-1, Frankfurt) AWS Data Processing Addendum; data stored and processed in the EU
Anthropic (Claude API) AI evaluation of anonymised student writing samples in Schreiben mode United States Anthropic usage policies; data not used to train models; SCCs
RevenueCat Subscription and in-app purchase management (applies to individual consumer accounts, not school plans) United States RevenueCat DPA; SCCs
PostHog Pseudonymised product analytics (screen views, feature-usage events linked to app user ID); collected only with in-app consent (opt-in), withdrawable anytime European Union (EU cloud) PostHog DPA; EU data residency
Google (Firebase Crashlytics) Crash reports and device diagnostics for stability monitoring United States / global Google Data Processing Terms; SCCs

Zackly will provide the Controller with at least 30 days' prior notice of any intended addition or replacement of a sub-processor. The Controller may object to such changes within that period by notifying privacy@zackly.app. Where the Controller objects and the parties cannot resolve the issue, the Controller may terminate the relevant services upon written notice.

Section 8

International Data Transfers

Some sub-processors listed in Section 7 are located in the United States, which means Personal Data may be transferred outside the European Economic Area (EEA). Zackly relies on the following safeguards for such transfers:

Upon request, Zackly will provide the Controller with copies of or links to the applicable SCCs or equivalent transfer mechanisms for each sub-processor.

Section 9

Data Subject Rights

As the Controller, the School is responsible for handling data subject requests (e.g. access, rectification, erasure, portability, restriction of Processing) from students, parents, and teachers. Zackly will assist the Controller in fulfilling such requests as follows:

Requests and supporting documentation should be sent to privacy@zackly.app.

Section 10

Personal Data Breach Notification

In the event of a Personal Data breach involving the Controller's data, Zackly will:

  1. Notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
  2. Provide the following information, or supplement it as soon as it becomes available:
    • A description of the nature of the breach, including the categories and approximate number of data subjects and records concerned;
    • The name and contact details of the data protection contact at Zackly;
    • A description of the likely consequences of the breach;
    • The measures taken or proposed to address the breach, including mitigation actions.
  3. Cooperate fully with the Controller's own breach notification obligations to supervisory authorities and data subjects.

Breach notifications should be expected at: privacy@zackly.app.

Section 11

Audit Rights

The Controller has the right to audit Zackly's compliance with this Agreement, subject to the following conditions:

In lieu of an on-site audit, Zackly may satisfy audit requests by providing up-to-date third-party security certifications, penetration test summaries, or equivalent documentation.

Section 12

Termination and Data Deletion

Upon expiry or termination of the service agreement, or upon written request from the Controller, Zackly will:

  1. Cease all Processing of the Controller's Personal Data;
  2. At the Controller's choice:
    • Return a structured export of all Personal Data in a machine-readable format (JSON or CSV) within 30 days; or
    • Delete all Personal Data, including backups, within 30 days, and provide written confirmation of deletion.

Zackly may retain Personal Data beyond this period only to the extent required by Union or Member State law, in which case Zackly will notify the Controller and restrict Processing of such data to the legally required purposes.

To initiate data export or deletion upon account closure, please contact privacy@zackly.app with the subject line "Data Deletion Request — [School Name]".

Execution

This Agreement is incorporated by reference into the Zackly school service agreement. By registering a school account or by countersigning this document, both parties agree to be bound by its terms. For a countersigned copy, please send a request to privacy@zackly.app.

On behalf of the Data Controller

School / Institution name

Authorised signatory — name, title, date

On behalf of the Data Processor

Zackly (German Word Games)

Authorised signatory — name, title, date