What the DPA covers
- Roles. Your school is the data controller; Viva is the data processor. We process student data only on your documented instructions.
- Scope of data. The categories of student data we handle, the purpose of each, and its retention period, matching the tables in our Privacy Policy.
- Subprocessors. The full list of technology providers we use, each bound by a written agreement no less protective than the DPA. See the current list in the Trust Center.
- Security. Encryption in transit and at rest, tenant isolation, access controls, and breach notification within 72 hours.
- Deletion. Voice recordings within 30 days of each session; all student data deleted or anonymised after the contract period, with written confirmation on request.
- International transfers. The appropriate mechanism for your jurisdiction — a Korea PIPA Addendum, EU/UK Standard Contractual Clauses and the UK IDTA, or the equivalent for your country.
Jurisdiction-specific addenda
The base DPA is executed alongside the Master Service Agreement, with a jurisdiction-specific addendum where your local law requires one. We maintain, among others:
- Republic of Korea: Korea PIPA Addendum — cross-border transfer disclosure, voiceprint consent, and under-14 guardian consent.
- EEA / UK: Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum (IDTA).
- United States: FERPA "school official" terms and, for under-13 students, COPPA service-provider terms.
How to get it
Email privacy@vivaproof.com with your school name and country and we will send the DPA for your jurisdiction, ready for signature, along with the current subprocessor list and our Vendor Security Overview.
Also see our Privacy Policy · Trust Center · Student Privacy Notice.