This Data Processing Agreement governs the processing of personal data by Zackly on behalf of schools and educational institutions using the Zackly platform.
The School / Institution
The legal entity that has entered into a service agreement with Zackly for the use of the Zackly platform, as identified in the school account registration.
Hereinafter: "Controller" or "School"
Zackly (German Word Games)
The operator of the Zackly vocabulary learning platform, reachable at privacy@zackly.app.
Hereinafter: "Processor" or "Zackly"
For the purposes of this Agreement, the following definitions apply:
By registering a school account on the Zackly portal, or by continuing to use the Services after the effective date of this Agreement, the Controller accepts and agrees to the terms of this DPA, which forms part of the broader service agreement between the parties.
This Agreement governs the Processing of Personal Data by Zackly on behalf of the Controller in connection with the provision of the Services described in the school service agreement.
Zackly will Process Personal Data only for the duration of the service relationship, beginning on the date the school account is activated and ending on the later of:
Zackly processes Personal Data on behalf of the Controller solely to provide the following functions of the Services:
| Processing activity | Purpose |
|---|---|
| Student account creation and management | Enabling students to access the platform with a class code; linking activity data to individual learner records |
| Vocabulary learning session tracking | Recording which words a student has practised, their accuracy, and session duration to power adaptive learning |
| Progress and analytics reporting | Providing the teacher dashboard with per-student and class-level performance data, completion rates, and gap analysis |
| Word assignment management | Recording teacher-assigned vocabulary sets, deadlines, and completion status |
| AI writing feedback (Schreiben mode) | Submitting anonymised student writing samples (in the studied language) to an AI model for grammar and CEFR-level evaluation; returning feedback to the student |
| Gamification and engagement tracking | Recording XP, streaks, achievements, and challenge progress to support student motivation |
| Service communications | Sending transactional emails to teachers (account setup, assignment reminders); not used for marketing without separate consent |
Zackly will not Process Personal Data for any purpose outside the scope of the Services, or for its own commercial purposes, without the prior written consent of the Controller.
Categories of data subjects:
Categories of personal data processed:
| Data category | Data subjects | Examples |
|---|---|---|
| Account identifiers | Students, Teachers | User ID, class code, display name |
| Contact data | Teachers | Email address (required for teacher login and notifications) |
| Learning activity data | Students | Words practised, correct/incorrect answers, session timestamps, game mode used |
| Progress and performance data | Students | CEFR level, accuracy rate per word, XP, streaks, assignment completion |
| Writing samples | Students | Free-text German writing submitted for AI evaluation in Schreiben mode |
| Device and usage data | Students, Teachers | Device type, OS version, app version, error logs (no IP addresses stored longer than 24 h) |
Zackly does not knowingly process special categories of personal data as defined in GDPR Art. 9, nor criminal conviction data under Art. 10. The Controller shall ensure that no such data is submitted to the platform.
Zackly, acting as Processor, undertakes to:
Obligations of the Controller: The Controller represents and warrants that it has a lawful basis under GDPR for the Processing described in this Agreement (e.g. a legitimate interest in providing education, or consent of students' guardians where required), and that it has provided all required notices to data subjects.
Zackly implements and maintains the following technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access:
| Category | Measure |
|---|---|
| Encryption in transit | All data transmitted between clients and the Zackly backend is encrypted using TLS 1.2 or higher. API endpoints are served exclusively over HTTPS. |
| Encryption at rest | Data stored in DynamoDB and S3 is encrypted at rest using AES-256 (AWS server-side encryption). |
| Access control | Access to production infrastructure is restricted to authorised personnel only. Role-based access controls are enforced at both application and AWS IAM level. Principle of least privilege applied. |
| Authentication | Teacher and student accounts are protected by authenticated sessions with 30-day inactivity timeouts. Tokens stored in device secure storage (iOS Keychain / Android Keystore). |
| Data minimisation | Students can join a class using only a class code — no email address is required. Only data necessary for platform function is collected. |
| Pseudonymisation | Writing samples submitted to the AI evaluation service are stripped of student identifiers before transmission. |
| Logging and monitoring | Application error logs are retained for 90 days. Logs do not contain plain-text credentials or full personal data records. |
| Backup and recovery | DynamoDB point-in-time recovery is enabled. Recovery procedures are tested periodically. |
| Vulnerability management | Third-party dependencies are regularly reviewed for known CVEs. Security patches are applied promptly. |
| Organisational measures | Personnel with access to Personal Data receive data protection awareness training. Internal data handling procedures are documented. |
Zackly may update these measures over time to reflect the evolving security landscape, provided that the overall level of protection is not reduced. Material changes will be communicated to the Controller.
The Controller provides general authorisation for Zackly to engage sub-processors, subject to the conditions below. Zackly will impose data protection obligations on each sub-processor equivalent to those in this Agreement. Zackly remains liable to the Controller for the performance of each sub-processor's obligations.
The following sub-processors are currently authorised:
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure: database, storage, compute, API gateway, and text-to-speech generation of listening-exercise audio (app content only — no personal data in the audio pipeline) | European Union (eu-central-1, Frankfurt) | AWS Data Processing Addendum; data stored and processed in the EU |
| Anthropic (Claude API) | AI evaluation of anonymised student writing samples in Schreiben mode | United States | Anthropic usage policies; data not used to train models; SCCs |
| RevenueCat | Subscription and in-app purchase management (applies to individual consumer accounts, not school plans) | United States | RevenueCat DPA; SCCs |
| PostHog | Pseudonymised product analytics (screen views, feature-usage events linked to app user ID); collected only with in-app consent (opt-in), withdrawable anytime | European Union (EU cloud) | PostHog DPA; EU data residency |
| Google (Firebase Crashlytics) | Crash reports and device diagnostics for stability monitoring | United States / global | Google Data Processing Terms; SCCs |
Zackly will provide the Controller with at least 30 days' prior notice of any intended addition or replacement of a sub-processor. The Controller may object to such changes within that period by notifying privacy@zackly.app. Where the Controller objects and the parties cannot resolve the issue, the Controller may terminate the relevant services upon written notice.
Some sub-processors listed in Section 7 are located in the United States, which means Personal Data may be transferred outside the European Economic Area (EEA). Zackly relies on the following safeguards for such transfers:
Upon request, Zackly will provide the Controller with copies of or links to the applicable SCCs or equivalent transfer mechanisms for each sub-processor.
As the Controller, the School is responsible for handling data subject requests (e.g. access, rectification, erasure, portability, restriction of Processing) from students, parents, and teachers. Zackly will assist the Controller in fulfilling such requests as follows:
Requests and supporting documentation should be sent to privacy@zackly.app.
In the event of a Personal Data breach involving the Controller's data, Zackly will:
Breach notifications should be expected at: privacy@zackly.app.
The Controller has the right to audit Zackly's compliance with this Agreement, subject to the following conditions:
In lieu of an on-site audit, Zackly may satisfy audit requests by providing up-to-date third-party security certifications, penetration test summaries, or equivalent documentation.
Upon expiry or termination of the service agreement, or upon written request from the Controller, Zackly will:
Zackly may retain Personal Data beyond this period only to the extent required by Union or Member State law, in which case Zackly will notify the Controller and restrict Processing of such data to the legally required purposes.
To initiate data export or deletion upon account closure, please contact privacy@zackly.app with the subject line "Data Deletion Request — [School Name]".
This Agreement is incorporated by reference into the Zackly school service agreement. By registering a school account or by countersigning this document, both parties agree to be bound by its terms. For a countersigned copy, please send a request to privacy@zackly.app.
On behalf of the Data Controller
School / Institution name
Authorised signatory — name, title, date
On behalf of the Data Processor
Zackly (German Word Games)
Authorised signatory — name, title, date