Data processing agreement

Last updated 2026-08-26Đọc bản tiếng Việt

In plain English

This is the part your lawyer will ask for. It says in contract language what the privacy policy says in plain language.

It forms part of the terms of service automatically - you do not need to sign a separate copy, though you can request one.

1. Parties and roles

This agreement is between the customer and VNIS Vietnam Company Limited, a company registered in Vietnam (business registration number 0106023568) with its registered office at No. 25, Alley 8, Lane 260 Cau Giay Street, Cau Giay Ward, Hanoi, Vietnam, which operates Schoolory.

The customer is the controller. VNIS Vietnam Company Limited is the processor. Where the customer is itself a processor for another controller, VNIS Vietnam Company Limited is a sub-processor.

2. Scope and purpose

We process personal data only to provide the service described in the terms, and only on documented instructions from the customer. Using the product is such an instruction.

Categories of data subject: staff, students, and parents or guardians. Categories of data: identity and contact details, academic records, attendance, and financial records relating to tuition.

3. Confidentiality

Everyone with access to customer data is bound by confidentiality obligations. Access is limited to staff who need it to run or support the service, and every such access is logged.

4. Security

Each customer's data is held in a separate database with separate credentials. Isolation is architectural rather than a query filter.

Data is encrypted in transit and at rest. Credentials for customer databases are encrypted before storage.

Passwords are stored using bcrypt. Sessions can be revoked centrally.

5. Sub-processors

Always in use: Turso (database hosting), Vercel (application hosting), Resend (email delivery), Paddle (payments for your Schoolory subscription, as merchant of record).

Used only when the customer switches the relevant feature on: Anthropic (AI features), Stripe (card payments from parents - funds go to the customer's own Stripe account, not ours), Google (Meet links, and push notifications to the parent app), Zoom and Microsoft (meeting links, as alternatives to Meet), Meta (WhatsApp messages to parents), Cloudflare (Turnstile, the sign-in captcha - it receives the visitor's IP address; a customer can enable it for their own workspace, and we may also enable it platform-wide during a credential-stuffing attack), and VietQR (renders a bank-transfer QR code in the parent app).

Used only when we switch it on: Sentry (error monitoring, server-side only - it never runs in your browser or a parent's). It receives the error type, a message with personal data stripped out, the code location, and your workspace's short name. It does not receive student records.

Where the customer configures their own SMTP server instead of our email provider, that server is theirs and is not a sub-processor of ours.

We will give 30 days' notice before adding a sub-processor, and the customer may object. Notice goes to the account owner's email address.

6. International transfers

Databases are currently hosted in Asia-Pacific. Transfers outside the EEA rely on Standard Contractual Clauses with the relevant sub-processor. Where additional regions are offered, the customer chooses theirs when the workspace is created.

7. Assisting the controller

We will assist with data subject requests, data protection impact assessments, and regulator enquiries, taking into account the nature of the processing and the information available to us.

The export tools in the product cover students, classes, invoices and payments, so many requests can be answered without contacting us. For anything outside that set, we provide the data on request.

8. Breach notification

We will notify the customer without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting their data, with the information needed for the customer to meet their own obligations.

9. Deletion and return

On termination, the customer may export students, classes, invoices and payments through the product, and may request the remainder of their data from us, which we provide within 30 days and without a fee. Thirty days after termination, the customer's database is deleted in full.

10. Audit

We will make available the information needed to demonstrate compliance with this agreement, and allow for audits by the controller or an auditor they mandate, on reasonable notice and no more than once a year unless a regulator requires otherwise.