Data Processing Addendum (DPA)
This Data Processing Addendum governs the Processing of Institutional Data by Q2T Suite on behalf of an Organization, as contemplated by Section 9.1 of our Terms of Service.
1Parties and Definitions
1.1Parties
This Data Processing Addendum ("DPA") is entered into between Q2T Suite ("Processor," "we," "us," or "our") and the Organization identified in the applicable order form, account registration, or written agreement referencing this DPA ("Controller," "you," or "Organization").
This DPA becomes effective only when it has been expressly executed, accepted, or otherwise incorporated by written agreement between Q2T Suite and the Organization, as contemplated by Section 9.1 of our Terms of Service. Mere use of the Service, without such execution, does not create a binding DPA between the parties.
1.2Definitions
For purposes of this DPA:
- "Applicable Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Institutional Data under this DPA, including, where applicable, FERPA, COPPA, applicable U.S. state student-privacy laws, the GDPR, and the UK GDPR;
- "Controller" means the Organization, which determines the purposes and means of Processing Institutional Data;
- "Data Subject" means an identified or identifiable individual to whom Institutional Data relates, including Students, Teachers, and other Authorized Users;
- "Institutional Data" means personal data submitted to, or collected by, the Service on behalf of the Organization, including Student records, grades, assessment results, attendance information, and related educational data;
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Institutional Data;
- "Processing" means any operation performed on Institutional Data, including collection, storage, use, disclosure, and deletion;
- "Processor" means Q2T Suite, which Processes Institutional Data on behalf of, and under the instructions of, the Organization;
- "Sub-processor" means any third party engaged by Q2T Suite to Process Institutional Data on its behalf.
Capitalized terms not defined in this DPA have the meaning given to them in our Terms of Service.
2Purpose and Scope
2.1Purpose
This DPA governs the Processing of Institutional Data by Q2T Suite on behalf of the Organization in connection with the Service, and is intended to help the Organization meet its obligations under Applicable Data Protection Laws.
2.2Relationship to the Terms of Service
This DPA supplements, and is incorporated into, the Terms of Service. In the event of a conflict between this DPA and the Terms of Service with respect to the Processing of Institutional Data, this DPA governs to the extent of that conflict.
2.3Role of the Parties
For purposes of Institutional Data, the Organization acts as the Controller and Q2T Suite acts as the Processor. Q2T Suite Processes Institutional Data solely on behalf of, and in accordance with, the documented instructions of the Organization, except where otherwise required by applicable law.
3Categories of Data and Data Subjects
3.1Categories of Institutional Data
Depending on how the Organization configures and uses the Service, Institutional Data may include:
- names and contact information;
- student identification numbers or class rosters;
- grades, scores, and assessment results;
- attendance and participation records;
- teacher comments, feedback, and evaluations;
- educational content created by Teachers or Students;
- usage and login information associated with an Authorized User’s account.
3.2Categories of Data Subjects
Data Subjects may include Students, Teachers, and other Authorized Users of the Organization.
3.3Sensitive Information
The Organization should not submit special categories of sensitive personal information (such as health, disability, or disciplinary records) through the Service unless reasonably necessary for a legitimate educational purpose and permitted under Applicable Data Protection Laws. Q2T Suite does not request or require such information to provide the Service.
4Processor Obligations
4.1Processing on Instructions
Q2T Suite will Process Institutional Data only in accordance with the Organization’s documented instructions, as reflected in the Service’s configuration and functionality, unless otherwise required by applicable law, in which case Q2T Suite will inform the Organization of that legal requirement before Processing, unless prohibited from doing so.
4.2Confidentiality
Q2T Suite will ensure that personnel authorized to Process Institutional Data are subject to appropriate confidentiality obligations.
4.3No Use for Unrelated Purposes
Q2T Suite will not use, sell, disclose, or otherwise make available Institutional Data for any purpose other than providing, securing, and improving the Service on behalf of the Organization, and will not use Institutional Data for behavioral advertising, marketing to Students, or building profiles of Students unrelated to the Service.
4.4Assistance with Data Subject Requests
Taking into account the nature of the Processing, Q2T Suite will provide reasonable assistance to the Organization in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws, to the extent the Organization is unable to reasonably fulfill such requests using the self-service tools available within the Service.
4.5Assistance with Compliance
Q2T Suite will provide the Organization with reasonably requested information about its security measures and Sub-processors to assist the Organization in demonstrating compliance with Applicable Data Protection Laws.
5Controller Obligations
5.1Lawful Basis and Consents
The Organization is responsible for ensuring it has a lawful basis, and has obtained any consents required under Applicable Data Protection Laws (including any required parental consent), before submitting Institutional Data to the Service.
5.2Accuracy and Lawfulness of Instructions
The Organization is responsible for the accuracy, quality, and legality of Institutional Data and the means by which it was obtained, and for ensuring that its instructions to Q2T Suite comply with Applicable Data Protection Laws.
5.3Compliance with Education Privacy Laws
Where applicable, the Organization is responsible for complying with FERPA, COPPA, and any other applicable federal, state, or local student-privacy laws governing its use of the Service, including determining what Institutional Data may be submitted to the Service.
5.4Authorized Users
The Organization is responsible for determining which of its Teachers, staff, and other personnel are authorized to access Institutional Data through the Service and for managing the permissions granted to those individuals.
6Security Measures
6.1Technical and Organizational Measures
Q2T Suite maintains commercially reasonable technical and organizational security measures designed to protect Institutional Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, appropriate to the risk presented by the Processing.
6.2Encryption
Q2T Suite uses encryption to protect Institutional Data in transit over public networks, and maintains reasonable safeguards for data at rest.
6.3Access Controls
Access to Institutional Data is restricted to personnel and systems with a legitimate need to access it in order to provide, secure, or support the Service, subject to authentication and role-based access controls.
6.4No Guarantee of Absolute Security
No security measure is completely impenetrable. Q2T Suite cannot and does not guarantee that Institutional Data will never be subject to unauthorized access, consistent with Section 19.2 of our Terms of Service.
7Sub-processors
7.1Authorization
The Organization authorizes Q2T Suite to engage Sub-processors to Process Institutional Data in connection with providing the Service, subject to the requirements of this Section.
7.2Current Sub-processors
As of the effective date of this DPA, Q2T Suite’s Sub-processors for Institutional Data may include the categories of providers described below. An organization may request the current list of named Sub-processors by contacting Q2T Suite using the information in Section 16.
| Category | Example Purpose |
|---|---|
| Cloud hosting and database (e.g., Google Cloud, Firebase) | Hosting, storage, and authentication |
| Payment processing | Billing and subscription payments |
| Artificial intelligence providers (e.g., OpenAI, Anthropic, Google Cloud AI) | Powering AI Features, as described in Section 16 of our Terms of Service |
7.3Sub-processor Obligations
Q2T Suite will enter into written agreements with its Sub-processors imposing data protection obligations reasonably consistent with this DPA, and will remain responsible for the acts and omissions of its Sub-processors to the same extent Q2T Suite would be responsible if performing the services directly.
7.4Changes to Sub-processors
Q2T Suite may add or replace Sub-processors from time to time as reasonably necessary to operate the Service. Where required by Applicable Data Protection Laws, Q2T Suite will provide reasonable notice of material changes to its Sub-processors and a reasonable opportunity for the Organization to object on legitimate data protection grounds.
8Data Retention
Q2T Suite will retain Institutional Data for as long as reasonably necessary to provide the Service, in accordance with Section 19.3 of our Terms of Service, unless a different retention period is agreed in writing between the parties.
9Data Deletion and Return
9.1Deletion Upon Termination
Upon termination of the Organization’s use of the Service, or upon written request, Q2T Suite will delete or, where reasonably feasible using tools made available through the Service, return Institutional Data within a reasonable period, except to the extent retention is required by applicable law or for legitimate backup, archival, or dispute-resolution purposes, consistent with Section 19.4 of our Terms of Service.
9.2Export of Data
Where the Service provides export functionality, the Organization may export Institutional Data prior to termination. Q2T Suite is not obligated to provide export formats beyond those made available within the Service, unless otherwise agreed in writing.
9.3Residual Copies
Deletion under this Section does not require Q2T Suite to remove residual copies of Institutional Data retained in encrypted backups, disaster-recovery systems, or legally required records, provided such residual copies are not used for any purpose other than backup, legal compliance, or dispute resolution, and are deleted in the ordinary course of Q2T Suite’s data retention schedule.
10Personal Data Breach Notification
10.1Notification Timeline
Q2T Suite will notify the Organization without undue delay, and in any event within the timeframe required by Applicable Data Protection Laws, after becoming aware of a confirmed Personal Data Breach affecting Institutional Data.
10.2Notification Content
To the extent known at the time of notification, Q2T Suite will provide the Organization with a description of the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.
10.3Cooperation
Q2T Suite will provide reasonable cooperation and information to assist the Organization in meeting its own notification obligations to Data Subjects, regulators, or other authorities under Applicable Data Protection Laws.
11International Data Transfers
Institutional Data may be transferred to, and Processed in, countries other than the Organization’s own, including the United States. Where required by Applicable Data Protection Laws, the parties will implement appropriate safeguards for such transfers (such as standard contractual clauses), consistent with our Privacy Policy.
12Audits and Compliance
12.1Information and Documentation
Upon reasonable written request, and no more than once per year absent a Personal Data Breach or other reasonable cause, Q2T Suite will make available information reasonably necessary to demonstrate compliance with this DPA, such as summaries of security practices and Sub-processor information.
12.2On-Site or Third-Party Audits
Any on-site audit, or audit conducted by a third party on the Organization’s behalf, is subject to reasonable advance notice, confidentiality obligations, and scheduling that avoids undue disruption to Q2T Suite’s operations and other customers, and may be satisfied through a mutually agreed third-party certification or report where available.
13Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations of liability and exclusions set out in Sections 22 through 24 of our Terms of Service, which apply to this DPA as if fully set forth herein.
14Term and Termination
This DPA remains in effect for as long as Q2T Suite Processes Institutional Data on behalf of the Organization under the Terms of Service, and will automatically terminate upon expiration or termination of the Organization’s underlying agreement with Q2T Suite, subject to the survival of any obligations that by their nature should reasonably continue (such as post-termination deletion and confidentiality obligations).
15General Provisions
15.1Governing Law
This DPA is governed by the same governing law and dispute resolution provisions set out in Section 29 of our Terms of Service, unless otherwise required by Applicable Data Protection Laws.
15.2Entire Agreement
This DPA, together with the Terms of Service and Privacy Policy, constitutes the entire agreement between the parties regarding the Processing of Institutional Data, and supersedes any prior discussions or agreements on that subject, unless a separately executed written agreement expressly states otherwise.
15.3Amendments
Q2T Suite may update this standard DPA from time to time to reflect changes in applicable law, security practices, or Sub-processors. Where required by law, reasonable notice of material changes will be provided. A separately and expressly executed DPA between the parties governs over this standard form in the event of a conflict.
15.4Severability
If any provision of this DPA is held invalid or unenforceable, the remaining provisions will remain in full force and effect.
15.5Execution
This DPA is intended to be reviewed and, where required by the Organization’s policies, formally executed by authorized representatives of both parties (including by electronic signature) before it becomes binding as a standalone agreement, as contemplated by Section 9.1 of our Terms of Service.
16Contact Us
If you have any questions, please contact us:
Q2T Suite
Email: support@q2tsuite.com
Address: 3258 Balsam St, Oceanside, NY 11572
✎Signatures
This DPA is executed by the authorized representatives of each party below.