Data Processing Agreement (DPA)
Data Processing Agreement (DPA)
Version 2.1 · September 2026
In accordance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), this Data Processing Agreement (the "DPA") governs the processing of personal data that KLUPPY, S.L. (the "Processor") carries out on behalf of the Educational Centre or Institution (the "Controller") for the provision of the Kluppy educational platform service.
This DPA forms an integral part of the Terms and Conditions of the School Plan (B2B) (the "B2B Terms and Conditions") and prevails over them in all matters relating to the protection of personal data.
Identification of the parties
The Processor
- Legal name: KLUPPY, S.L.
- Tax ID (NIF): B75131953
- Registered office: Mikeletegi pasealekua 65 (Planta Baja, Local 1), 20009 Donostia-San Sebastián, Gipuzkoa
- Registry details: Registro Mercantil de Gipuzkoa, Tomo 2693, Folio 44, Hoja SS-37422
- Data protection contact: info@kluppy.com
The Controller (the "Centre", referred to in the B2B Terms and Conditions as "the School")
- Legal name / official designation: _______________________________
- Tax ID (NIF/CIF): _______________________________
- Registered office: _______________________________
- Legal representative: _______________________________
- Contact email: _______________________________
1. Subject matter, nature, purpose and duration of the processing
1.1. Subject matter. The Controller engages Kluppy to process such personal data of its students and teaching staff as is necessary for the provision of the Kluppy typing learning platform.
1.2. Nature and purpose. The processing consists of hosting, storage and computation, the generation of exercises, performance measurement (WPM, accuracy, levels), the presentation of educational and gamification metrics and, where the Controller activates it, the issuing of evidence reports that arrange those measurements by period in order to support the assessment of the keyboard-writing block (clause 12), solely and exclusively for the provision of the contracted service. Kluppy shall not process the data for its own purposes (marketing, profiling with legal effects, or the training of AI models).
1.3. Duration. The processing carried out on the Controller's behalf has the same duration as the licence/service contract between the parties. Upon its termination, the provisions of clause 9 (return or deletion) shall apply.
2. Documented instructions
2.1. Kluppy shall process the personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by law, in which case it shall inform the Controller beforehand unless that law prohibits such information.
2.2. The service contract, its terms and this DPA constitute the Controller's initial instructions. Kluppy shall inform the Controller if, in its opinion, an instruction infringes data protection law.
3. Confidentiality
Kluppy shall ensure that the persons authorised to process the personal data have expressly committed themselves in writing to confidentiality, or are under an appropriate statutory obligation of confidentiality, and that they receive the necessary training.
4. Security of processing (Art. 32 GDPR)
Kluppy shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as detailed in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of data subjects, with particular regard to the fact that the data concerned is that of minors.
5. Sub-processors (Arts. 28.2 and 28.4 GDPR)
5.1. The Controller authorises the engagement of the sub-processors listed in Annex III.
5.2. Kluppy shall impose on each sub-processor, in writing, the same data protection obligations as those set out in this DPA, in particular by providing sufficient guarantees to implement appropriate technical and organisational measures. Kluppy shall remain fully liable to the Controller for the performance of the sub-processor's obligations.
5.3. Kluppy shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors at least 30 days in advance, giving the Controller the opportunity to object on legitimate data protection grounds.
6. Assistance to the Controller (Arts. 28.3.e and 28.3.f GDPR)
6.1. Data subjects' rights. Kluppy shall assist the Controller, by appropriate technical and organisational measures (including the export and deletion tools available on the platform), in responding to requests for the exercise of rights (access, rectification, erasure, restriction, portability and objection; Arts. 15-22 GDPR). If a data subject addresses a request to Kluppy, Kluppy shall forward it to the Controller without delay.
6.2. Security, DPIAs and prior consultation. Kluppy shall assist the Controller in complying with its obligations under Arts. 32-36 GDPR (security, personal data breach notification, data protection impact assessments and prior consultation of the supervisory authority), providing the necessary technical information about the platform.
7. Notification of personal data breaches (Art. 33.2 GDPR)
Kluppy shall notify the Controller, without undue delay after having become aware of a personal data breach, providing it with at least the information referred to in Art. 33.3 GDPR: the nature of the breach (the categories and approximate number of data subjects and of personal data records concerned), a contact point from which further information may be obtained, the likely consequences and the measures taken or proposed to be taken. This notification enables the Controller to comply, where applicable, with its own obligation to notify the supervisory authority (72 hours, Art. 33.1) and the data subjects (Art. 34).
8. Audits and inspections (Art. 28.3.h GDPR)
8.1. Kluppy shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 (including audit reports and certifications of the underlying infrastructure).
8.2. Kluppy shall likewise allow for and contribute to audits, including inspections, conducted by the Controller or by another auditor mandated by it, subject to the following reasonable conditions: at least 15 business days' prior notice; a maximum frequency of once a year (save where required by the supervisory authority or in the event of a personal data breach); respect for the confidentiality and security of other customers; and the Controller bearing any costs that do not arise from a breach by Kluppy of its obligations.
9. Return or deletion at the end of the provision of services (Art. 28.3.g GDPR)
9.1. Upon the end of the provision of the service, and at the choice of the Controller, Kluppy shall return or delete all personal data processed on its behalf, and shall delete the existing copies, unless there is a legal obligation to retain the data. To that end, Kluppy shall make available to the Controller a full export of the data in a structured format (JSON). In the absence of an instruction to return the data, or to delete it earlier, Kluppy shall permanently delete it once 180 days have elapsed from the end of the provision of the service. [updated 2026-08-03: 90→180 days, aligned with the school year and with the platform's other retention periods — to be validated by legal counsel]
9.2. During the term of this DPA, where the Controller deactivates an individual student via the administration panel, that data subject's data shall be kept blocked and inaccessible for a maximum of 180 days (allowing the student to rejoin without losing their progress) and, once that period has elapsed, shall be permanently and automatically deleted. The Controller may at any time instruct the immediate deletion of a particular data subject's data, which Kluppy shall carry out without undue delay.
10. International transfers (Chapter V GDPR, Arts. 44-49)
10.1. As a general rule, data is processed and stored within the European Economic Area (EEA).
10.2. Certain sub-processors belong to corporate groups with a US parent company (Google, Stripe, Microsoft, Mailjet). Where access to the data from outside the EEA is unavoidable (for example, for technical support), such processing is covered by the appropriate safeguards under Art. 46: the EU-US Data Privacy Framework where the provider is certified or, failing that, standard contractual clauses (SCCs) approved by the European Commission. The details for each provider are set out in Annex III. [the mechanism applicable to each provider to be validated]
11. Transparency regarding the use of Artificial Intelligence (Art. 50 Regulation (EU) 2024/1689)
11.1. Kluppy generates part of the practice texts using a generative AI system (Google Vertex AI, EU eu multi-region). No student personal data is included in the prompts sent to the AI; the system is not used to assess students automatically or to take decisions producing legal effects. The evidence reports under clause 12 do not use AI: they are calculated using deterministic arithmetic rules applied to the recorded measurements.
11.2. Kluppy visibly identifies AI-generated content and provides the Controller with the information it needs so that it can, in turn, inform students and families, in accordance with the transparency obligation under Art. 50 of Regulation (EU) 2024/1689. The risk classification of the system under that Regulation is documented separately. [risk classification to be validated by legal counsel]
12. Evidence reports supporting assessment (human oversight)
12.1. Subject matter. At the Controller's request, Kluppy issues reports that arrange each student's typing measurements by period (speed, accuracy, level reached, cumulative keystrokes and sessions worked) and place them in achievement bands, for the purpose of providing the Controller's teaching staff with objective evidence.
12.2. Nature of the report. The report is an interpretative proposal, not a grade. By itself it produces no effect on the student: it does not change their level, their access or their progress on the platform, and it is not disclosed to any third party outside the Controller's organisation.
12.3. Method. The bands are obtained by applying deterministic, auditable arithmetic rules to the recorded measurements and to the cut-points agreed with the Controller. No AI systems, no profiling and no inferences about the student's personal characteristics are involved. Kluppy does not process students' age for these purposes.
12.4. No automated decision-making (Art. 22 GDPR). Since the grade is always determined by a person within the Controller's organisation, and that person may change or discard any proposed band, the processing does not constitute a decision based solely on automated processing within the meaning of Art. 22 GDPR. Kluppy shall provide the Controller, upon request, with an explanation of how a particular band was calculated, so that the Controller can respond to requests from data subjects exercising their rights.
12.5. Limits on use. In accordance with the B2B Terms and Conditions, the Controller may not use the reports as the sole or main basis of the student's official assessment. The Controller shall set and document the weight it gives the keyboard-writing block within the subject; the tool requires this as a mandatory parameter and rejects a setting of 100%.
12.6. Classwork signal. For context, the platform infers from the group's own aggregate activity the sessions in which each group worked, and records in how many of those sessions each student worked. It is not an attendance-monitoring mechanism, it is neither presented nor exported as such, and it plays no part in the achievement bands.
12.7. Traceability. The reports issued and the cut-points applied are recorded in an immutable log, so that the Controller can demonstrate, to data subjects and to the supervisory authority, what evidence was provided to it and on what parameters that evidence was based.
13. Enhanced protection of minors (Art. 7 LOPDGDD; LOPIVI)
13.1. The Controller warrants that it has a valid legal basis for the processing of its students' data — generally the exercise of its educational function as a task carried out in the public interest and, where applicable, the consent of the holders of parental authority in the case of children under 14 (Art. 7 LOPDGDD) — and that it has informed the data subjects and their legal guardians.
13.2. Kluppy applies data minimisation measures in the social features (pseudonymisation in leagues and rankings) and does not carry out profiling producing legal effects on minors. Kluppy has content moderation mechanisms and a reporting channel for incidents in place.
13.3. The obligations under LOPIVI (Spanish Organic Law 8/2021) concerning the wellbeing of minors in the educational context rest with the Centre in respect of its students; Kluppy, as a technology provider, supplies the moderation and reporting tools referred to above and cooperates with the Centre's wellbeing and protection coordinator. [LOPIVI scope to be validated by legal counsel]
14. Obligations of the Controller
The Controller undertakes to: (a) have a valid legal basis and to have informed the data subjects; (b) enter its use of Kluppy as processor in its Record of Processing Activities (ROPA); (c) issue lawful instructions; (d) handle, as controller, requests from data subjects exercising their rights; and (e) where it activates the evidence reports, inform the data subjects and their legal guardians accordingly, set and document the weight of the block in accordance with clause 12.5, and ensure that the grade is always determined by its teaching staff.
15. Applicable law and signature
This DPA is governed by the GDPR, the LOPDGDD and Spanish law. For the resolution of any disputes arising from it, the parties submit to the Courts and Tribunals of Donostia-San Sebastián.
| For the Processor (KLUPPY, S.L.) | For the Controller (the Centre) |
|---|---|
| Name: ____________________________ | Name: ____________________________ |
| Position: ________________________ | Position: ________________________ |
| Date: ____________________________ | Date: ____________________________ |
| Signature: _______________________ | Signature: _______________________ |
ANNEX I — Description of the processing
- Categories of data subjects: students (including minors) and teaching and administrative staff of the Centre.
- Categories of personal data: full name, pseudonym/username, email address (corporate or personal, where applicable), typing progress data (WPM, accuracy, timings), gamification levels and achievements, technical usage metadata and, where the Controller activates the evidence reports, the aggregates for the period derived from the foregoing (proposed achievement band, cumulative keystrokes and group sessions worked). Neither the age nor the date of birth of students is processed.
- Special categories of personal data (Art. 9 GDPR): not processed. The Centre undertakes not to enter special categories of personal data (e.g. health data in free-text fields).
- Purpose: provision of the educational service, performance metrics, monitoring of school progress and gamification and, where the Controller activates them, the issuing of evidence reports supporting assessment (clause 12), with no automated decision-making and with no use of AI.
- Duration: the term of the service contract.
ANNEX II — Technical and organisational security measures (Art. 32 GDPR)
- Pseudonymisation: cryptographic identifiers (UIDs) and pseudonyms in leagues and rankings.
- Encryption: in transit using HTTPS/TLS; at rest using infrastructure-managed encryption (AES-256) on Google Cloud.
- Access control (RBAC): strong authentication and granular security rules (Firestore Security Rules); the data of each Centre is logically isolated and inaccessible to other Centres.
- Resilience and availability: serverless architecture with automatic scaling and daily backups of the database.
- Logging and traceability: logging of relevant administration and security events.
- Certifications of the underlying infrastructure (Google Cloud): ISO 27001, ISO 27017, ISO 27018 and SOC 2.
- Incident management: procedure for the detection and notification of personal data breaches in accordance with clause 7.
ANNEX III — Authorised sub-processors
| Sub-processor | Service | Data | Processing location | Transfer safeguard |
|---|---|---|---|---|
| Google Cloud EMEA (Firebase / Cloud) | Hosting, database and authentication | All | EU (eur3: Belgium / Netherlands) | US parent company: EU-US DPF / SCCs [to be validated] |
| Google Vertex AI | AI text generation | No personal data (technical parameters only) | EU (eu multi-region) |
Included in the Google Cloud DPA |
| Google Workspace / Classroom | Directory import (optional, initiated by the Centre) | Email and name | EU | Included in the Google Cloud DPA |
| Microsoft (Azure AD / Entra ID) | Authentication and directory import | Email and name | Ireland (EU) | US parent company: EU-US DPF / SCCs [to be validated] |
| Stripe Payments Europe, Ltd. | Payment gateway (data relating to the Centre's payer) | Email and payment data | Ireland (EU) | US parent company: EU-US DPF / SCCs [to be validated] |
| Holded | Invoicing | Email, name and tax ID (paying customers only) | Spain | Processing within the EU |
| Mailjet | Transactional email | Recipient's email | EU | Processing within the EU |
To arrange for this document to be formally signed, or with any queries, contact: info@kluppy.com