Last updated: June 15, 2026
Data Processing Agreement
How Locuto.PRO processes personal data on behalf of schools and organizations under the GDPR.
This Data Processing Agreement ("DPA") forms part of the School & Business Terms between the school or organization (the "Customer" or "Controller") and Locuto.PRO (the "Processor", "we") and governs the processing of personal data carried out by us on the Customer's behalf. It is designed to meet the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR").
Where the Customer requires a signed copy, we will provide one on request at [email protected].
1. Roles of the Parties
The Customer is the controller and Locuto.PRO is the processor with respect to the personal data processed through the Service on the Customer's behalf ("Customer Personal Data"). Each party will comply with its obligations under applicable data protection law.
2. Scope and Details of Processing
The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Appendix A. We process Customer Personal Data for the duration of the agreement and as needed to provide the Service.
3. Processing on Documented Instructions
We will process Customer Personal Data only on the Customer's documented instructions, including those given through configuration and use of the Service and this DPA, unless required to act otherwise by EU or member-state law (in which case we will inform the Customer unless the law prohibits it). We will inform the Customer if, in our opinion, an instruction infringes data protection law.
4. Confidentiality
We ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and process the data only as needed to provide the Service.
5. Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the data. A summary of these measures is set out in Appendix B.
6. Sub-processors
The Customer provides general authorization for us to engage sub-processors to provide the Service. Our current sub-processors are listed on our Sub-processor list. We impose data protection obligations on our sub-processors substantially similar to those in this DPA and remain responsible for their performance. We will provide a mechanism to be notified of changes to sub-processors and a reasonable opportunity to object on legitimate data protection grounds.
7. Assistance with Data Subject Rights
Taking into account the nature of the processing, we will assist the Customer by appropriate measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR (access, rectification, erasure, restriction, portability, and objection).
8. Personal Data Breach Notification
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to us to help the Customer meet its own notification obligations.
9. Assistance with DPIAs
We will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, where required and taking into account the information available to us.
10. Return or Deletion of Data
On termination of the Service, we will, at the Customer's choice and on request made within a reasonable period, make Customer Personal Data available for export and then delete it, unless retention is required by law. Some content, such as lesson recordings, is also automatically deleted after its applicable retention period.
11. Audits and Information
We will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality and security conditions and reasonable advance notice.
12. International Transfers
Some sub-processors are located outside the European Economic Area. Where we transfer Customer Personal Data outside the EEA, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference where applicable.
13. Children and Students (Minors)
The Customer acknowledges that its Authorized Users may include minors. The Customer, as controller, is responsible for establishing a valid legal basis for processing minors' personal data and for obtaining any parental or guardian consent required by applicable law (for example, where the student is below the age of digital consent, which is 16 in Poland and between 13 and 16 across the EEA). We process minors' personal data only on the Customer's instructions to provide the Service, do not use it for advertising or profiling, and apply additional protections (such as not enabling session-replay analytics for accounts identified as minors). Where the Customer is subject to laws such as FERPA or COPPA in the United States, the Customer is responsible for compliance and we will act as a service provider / school official acting on its behalf.
14. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions set out in the School & Business Terms, including the aggregate liability cap, except to the extent such limitation is not permitted by applicable data protection law.
15. General
This DPA is governed by the laws of Poland. In the event of a conflict between this DPA and the other terms of the agreement regarding the processing of personal data, this DPA prevails. If any provision is found unenforceable, the remaining provisions remain in effect.
Appendix A — Details of Processing
- Subject matter: provision of the Locuto.PRO language learning platform to the Customer.
- Duration: the term of the agreement and any period needed to return or delete data afterwards.
- Nature and purpose: hosting, storing, and processing personal data to operate the platform, including accounts, lessons, recordings, assessments, communications, and AI-assisted features.
- Categories of data subjects: the Customer's administrators, teachers, and students (who may include minors).
- Types of personal data: identity and contact data (name, email, optional phone), profile data (date of birth, country, language, avatar, bio), learning and engagement data, lesson and homework content and submissions, audio and video from live lessons and recordings, usage and diagnostic data.
- Special categories: the Service is not intended for the collection of special-category data; the Customer should not submit such data through free-text or content fields.
Appendix B — Technical and Organizational Measures
- Encryption of data in transit (HTTPS/TLS);
- Access controls and role-based permissions, with tenant isolation between organizations;
- Authentication safeguards, including session and CSRF protections;
- Use of reputable hosting and storage providers with their own security certifications;
- Time-limited, signed URLs for access to stored media and recordings;
- Logging, error monitoring, and reliability monitoring;
- Automatic deletion of recordings and certain media after their retention period;
- Confidentiality obligations on personnel and sub-processors.
Contact
For data protection questions or to request a signed DPA, contact us at [email protected].
Преподавайте с современными инструментами
Создавайте интерактивные уроки, назначайте практику и управляйте преподаванием языков в личном кабинете преподавателя.
Начать преподаватьЕще выбираете? Читайте FAQ