Education Data Processing Addendum (DPA)

Scope boundary: For Institution-controlled student and staff workspace data, the Institution determines who is added, why the service is used and the permitted educational purpose; CV Bright processes that data only to provide and secure the contracted Education service and on documented Institution instructions. CV Bright may separately act as an independent controller for its own Institution application/verification, account security, fraud prevention, billing, legal compliance, support and service administration records.

1. Parties and incorporation

This Data Processing Addendum forms part of the agreement between an Education Institution using CV Bright Pathways for Education (the Institution) and CV Bright (the Service Provider) where CV Bright processes personal data on the Institution's behalf. It is intended to satisfy the controller-processor contract requirements of applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018, as amended.

The Institution is the Controller and CV Bright is the Processor for the processing described below. If the parties execute an order form, procurement agreement or other written contract, that document and this DPA are read together. If there is a conflict about Institution Personal Data, this DPA takes priority to the extent required by applicable data protection law.

2. Definitions

3. Controller instructions and Institution responsibilities

4. CV Bright processor obligations

5. Sub-processors and international transfers

The Institution gives CV Bright general written authorisation to use the Sub-processors listed below and to make reasonable changes where necessary to provide the service. CV Bright will impose appropriate data protection obligations on Sub-processors and remains responsible to the Institution for their performance to the extent required by law.

ProviderPurpose
Google Firebase / Google CloudAuthentication, Firestore/database services, backend administration and cloud infrastructure.
OpenAIAI processing requested through Pathways or related CV Bright AI features; only content reasonably necessary to generate the requested output should be sent.
ResendTransactional email delivery, including invitations and reminders where used.
GoDaddy / hosting infrastructureWebsite/API hosting, network and server infrastructure; may process technical logs.
Cloudflare (where enabled)DNS, traffic delivery, performance and security.
Zoho MailOperational/support email where personal data is included in support communications.
StripeInstitution billing/subscriptions. Stripe ordinarily processes Institution billing/contact data rather than student Pathways content.

Where a restricted transfer outside the UK occurs, CV Bright will use an available lawful transfer mechanism and appropriate safeguards.

6. Rights requests, compliance assistance and breaches

7. Audit and demonstration of compliance

CV Bright will make available information reasonably necessary to demonstrate compliance with processor obligations. On reasonable notice and subject to confidentiality, security and proportionality safeguards, CV Bright will permit or contribute to audits required by Applicable Data Protection Law. Documentation and remote review should be used first where they can reasonably satisfy the Institution's needs.

8. Return and deletion

At the end of the Institution relationship, CV Bright will, at the Institution's choice and where technically and legally feasible, return or delete Institution Personal Data processed solely as Processor, unless law requires retention. Protected backups may remain until overwritten under normal cycles. CV Bright may retain separate controller records such as necessary billing, security, fraud, legal, support and audit information under its Privacy Policy.

9. Separate personal accounts

A student or staff member may also hold a separate personal CV Bright or Pathways account. Institution-funded access is linked to the Institution membership, while independent personal-account data and entitlements are governed by the applicable personal terms and privacy notice.

10. Processing details

Subject matterEducation workspace administration, student/staff access, Pathways delivery, reminders, limited engagement analytics and support.
DurationFor the active Institution relationship and any limited post-termination period needed for secure deletion, backups, support, disputes or legal obligations.
Nature/purposeCollection, storage, retrieval, authorised access, AI generation where requested, membership administration, operational analytics, restriction and deletion necessary to provide the Institution-controlled Education service.
Data subjectsInstitution staff/owners and students added or invited by the Institution, potentially including people under 18.
Personal dataName, email, Institution/cohort/role/access data, invitation/membership state, Pathways goals/responses, generated roadmap/progress data, usage counters, timestamps and necessary support/audit information.
Special-category dataNot required as a standard field; may appear incidentally in CVs or free text. Institutions and users should avoid it unless genuinely necessary and lawful.

11. Security measures

12. Acceptance and contact

This DPA may be accepted electronically as part of the Institution service agreement or signed separately if required by the Institution's procurement process.

Data protection/DPA: info@cvbright.com
Support: support@cvbright.com
Website: https://cvbright.com

Institutions may request a countersigned copy or procurement/security information. CV Bright may update this DPA to reflect legal or service changes and should communicate material changes affecting processor obligations through reasonable means.