← Back to home

Data Processing Addendum

This Data Processing Addendum (“DPA”) applies where an organization (the “Customer”) licenses the 10x Technologies platform for its people, and 10x Technologies processes personal information on the Customer's behalf. It supplements the Terms of Service and the Customer's licence agreement, and takes precedence over both on the subject of data protection.

Individuals who use the free resources or buy a course for themselves are covered by the Privacy Policy, not by this DPA — there we are the controller in our own right.

To execute this DPA for your organization, or to request it as a countersigned document, use the contact form. A signature is not required for it to apply to Customer data we already process under a licence agreement.

1. Roles

For the personal information of learners the Customer enrols, the Customer is the controller (or “business”, under the CCPA/CPRA) and 10x Technologies is the processor (or “service provider”). The Customer is responsible for having a lawful basis for the processing it instructs, and for giving its people the notice its own law requires.

We remain an independent controller for a limited set of our own purposes: securing the platform, billing, and meeting our legal obligations. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use Customer personal information for advertising or to train machine-learning models.

2. Scope of processing (Annex I)

  • Subject matter: provision of the 10x Technologies learning platform.
  • Duration: the term of the Customer's licence, plus the deletion period in section 10.
  • Nature and purpose: hosting a learning platform — authenticating users, delivering learning paths and courses, grading assessments, issuing certificates, providing administrator dashboards and reporting, and sending transactional email.
  • Categories of data subjects: the Customer's employees, contractors, and other individuals the Customer enrols; the Customer's platform administrators.
  • Types of personal data: name; work email address; a stable account identifier from the identity provider; organization, team, and role; learning activity (enrolments, modules opened, quiz attempts and scores, completions, certificates, streaks and points); skill self-assessments; content the user submits (comments, ratings, workshop notes, course artifacts); and technical data needed to operate and secure the service (IP address, request logs, general device and browser information).
  • Special categories: none. The platform is not designed for special-category data, and the Customer must not instruct processing of it.
  • Frequency: continuous, for the duration of the licence.

3. Our obligations as processor

  • We process personal information only on the Customer's documented instructions — this DPA, the licence agreement, and the Customer's use of the platform's features are those instructions — except where law requires otherwise, in which case we will tell the Customer first unless the law forbids it.
  • We will tell the Customer if, in our opinion, an instruction infringes applicable data protection law.
  • We ensure that personnel authorised to process personal information are bound by confidentiality.
  • We do not retain, use, or disclose personal information for any purpose other than performing the services, and not outside the direct business relationship.

4. Security (Annex II)

We maintain technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (TLS) and at rest for the database and object storage.
  • Federated authentication through the Customer's identity provider — we never receive or store end-user passwords.
  • Role-based access control in the application, with organization-scoped data access, and least-privilege database roles; administrative access to infrastructure is limited to named personnel using multi-factor authentication.
  • Managed-identity credentials for platform services rather than long-lived shared secrets, where the platform supports it.
  • Network isolation of the database, rate limiting on state-changing endpoints, and content-security controls on user-submitted content.
  • Automated dependency-vulnerability alerting, an automated test suite gating every change, and a separate pre-production environment that no Customer data reaches.
  • Managed daily backups of the database with point-in-time restore, and application logging sufficient to reconstruct access to Customer data.

We review these measures periodically and may update them, provided the level of protection is not reduced.

5. Sub-processors (Annex III)

The Customer gives general authorisation for the sub-processors below. We remain liable for their performance.

  • Microsoft Corporation (Microsoft Azure) — application hosting, database, object storage, and transactional email (Azure Communication Services). Processing location: Canada Central.
  • Anthropic PBC — optional AI-assisted features (for example, drafting and feedback aids), only when the Customer's administrator enables them. Content sent to this sub-processor is not used to train its models. Processing location: United States.
  • Payment processor — used only for individual course purchases, not for licensed organization accounts; it receives billing data, not learning records.
  • Cloudflare, Inc. — DNS for our domains, and cookieless website analytics. The analytics product sets no cookies and builds no cross-site profile; it derives an aggregate page-view measurement from the request itself and discards the rest. It receives no learning records, no account data, and nothing a learner submits.

We will give the Customer at least 30 days' notice before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the Customer may terminate the affected part of the licence without penalty for the unexpired term.

6. International transfers

Personal information is hosted in Canada, which the European Commission recognises as providing an adequate level of protection for data subject to PIPEDA. Where a transfer to another country occurs — for example to the AI sub-processor in the United States when those features are enabled — it is made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), with the UK Addendum where the UK GDPR applies. Those clauses are incorporated into this DPA by reference; Annexes I, II, and III above populate them, the docking clause applies, and in a conflict the clauses prevail.

7. Assistance with data subject rights

The platform gives the Customer's administrators direct access to correct, export, and delete the records of the people they enrol. Where a request cannot be satisfied that way, we will assist the Customer by appropriate technical and organisational measures, at no charge for a reasonable volume of requests. If a data subject contacts us directly about Customer data, we will not respond substantively — we will refer them to the Customer promptly.

8. Personal data breach

We will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer personal information, and will provide the information the Customer reasonably needs to meet its own notification duties, including the nature of the breach, the categories and approximate number of records involved, the likely consequences, and the measures taken or proposed. Our notification is not an acknowledgement of fault.

9. Data protection impact assessments

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with the Customer's data protection impact assessments and any prior consultation with a supervisory authority.

10. Deletion and return

On termination of the licence, we will delete Customer personal information within 90 days, except where law requires us to keep it, in which case we will isolate it and protect it from further processing. At the Customer's written request made before that period expires, we will first return the data in a machine-readable export. Backups are overwritten on their normal rotation, within a further 35 days.

11. Audit

On reasonable written notice and no more than once in any 12-month period (unless required by a supervisory authority or following a breach), we will make available the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to an audit conducted by the Customer or an independent auditor bound by confidentiality. Audits must be conducted during business hours, must not unreasonably disrupt the service, and must not access the data of other customers. We may first offer relevant third-party certifications or reports from our sub-processors where they answer the question.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service and the licence agreement, except where applicable law does not permit that. Where this DPA conflicts with those documents on data protection, this DPA prevails; where it conflicts with the Standard Contractual Clauses, the clauses prevail.

13. Contact

For data protection questions, to execute this DPA, or to raise a sub-processor objection: use the contact form.