Data Processing Agreement (DPA)
Controller/processor terms governing how CanoryX processes student personal data on behalf of partner agencies under the UK GDPR / EU GDPR Article 28.
Last updated: 06 July 2026
1. Parties & roles
This Data Processing Agreement ("DPA") is between the agency using CanoryX (the "Controller") and Canoryx Limited ("CanoryX", the "Processor"). It applies where CanoryX processes personal data of students / enquirers on the Controller's behalf via the course finder and related services, and forms part of the Terms of Service.
2. Subject matter & duration
The Processor processes personal data for the duration of the service relationship and as needed to provide the service, after which data is returned or deleted per section 9.
3. Nature & purpose of processing
Collecting and storing student enquiries submitted through the Controller's course finder, making them available to the Controller, and supporting related communications and analytics, strictly on the Controller's documented instructions.
4. Types of data & data subjects
- Data subjects: prospective students and enquirers.
- Personal data: name, email address, WhatsApp / phone number, search criteria and enquiry content; associated metadata (timestamps, acquisition channel).
- No special-category data is intended to be processed through the service.
5. Processor obligations
- Process personal data only on the Controller's documented instructions.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (section 7).
- Assist the Controller with data-subject requests and with security / breach duties.
- Notify the Controller without undue delay on becoming aware of a personal data breach.
- Make available information necessary to demonstrate compliance with Article 28.
6. Sub-processors
The Controller provides general authorisation for the Processor to engage sub-processors (e.g. cloud hosting, email delivery, payment and optional analytics providers) under written terms no less protective than this DPA. A current list is available from hello@canoryx.com. The Processor will inform the Controller of intended changes and give an opportunity to object.
7. Security measures
Measures include encryption in transit, access controls and authentication, hashing of credentials and API keys at rest, audit logging of administrative actions, and least-privilege access. Specific measures are described in [Security Annex].
8. International transfers
Where personal data is transferred outside the UK / EEA, the Processor relies on an appropriate transfer mechanism (adequacy, Standard Contractual Clauses, or the UK IDTA).
9. Return & deletion
On termination, or on the Controller's request, the Processor will delete or return personal data and delete existing copies, unless retention is required by law. Automated retention controls may delete or irreversibly anonymise data after the configured period.
10. Audits
The Processor will make available information reasonably necessary to demonstrate compliance and allow for audits, subject to reasonable confidentiality and security conditions.
11. Acceptance
Agencies accept this DPA in the CanoryX agent portal (Settings → Legal & Compliance). Acceptance is recorded with a timestamp and the document version. For questions, contact hello@canoryx.com.