1. Definitions and scope
This Data Processing Agreement ("DPA") is concluded between:
Processor: Praktikal Education OÜ, Sirbi 13, Tartu, Estonia, registry code 16229727, VAT EE102398843 ("Praktikal")
Controller: the customer organisation that concludes this DPA ("Customer")
Definitions. "GDPR" means Regulation (EU) 2016/679. "Controller", "processor", "processing", "personal data", "personal data breach", "data subject" and "supervisory authority" have the meanings given in the GDPR. "Customer Personal Data" means personal data that Praktikal processes on the Customer's behalf under the Main Agreement. "Sub-processor" means a processor engaged by Praktikal to process Customer Personal Data. "Main Agreement" means the Terms of Service or other commercial agreement between the parties.
Scope. This DPA governs Praktikal's processing of Customer Personal Data in connection with the Praktikal platform and supplements the Main Agreement when concluded under Form and conclusion below.
Precedence. In case of conflict on the subject matter of this DPA, this DPA prevails over the Main Agreement. The annexes prevail over the body of this DPA where they are more specific.
Duration. This DPA applies for as long as Praktikal processes Customer Personal Data, and survives termination of the Main Agreement until deletion or return is complete under section 10.
Form and conclusion. This DPA is concluded in written or electronic form when it is expressly incorporated into the Main Agreement, accepted by an authorised representative of the Customer, or executed by both parties. It applies to accounts through which the Customer causes personal data to be processed under the Main Agreement.
Governing law. The governing law and jurisdiction of the Main Agreement apply to this DPA.
2. Roles and details of processing
Roles. The Customer is the controller for personal data processed through the platform in the course of its educational activities. Praktikal is the processor for that data.
Praktikal is an independent controller, and this DPA does not apply, for: account administration and billing, customer relationship management, security and abuse prevention, and operation of the public website. Those are covered by Praktikal's privacy notice.
Details of processing. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex II.
Instructions. Praktikal processes Customer Personal Data only on the Customer's documented instructions, including as to transfers to a third country, unless required to process by Union or Member State law, in which case Praktikal informs the Customer of that requirement before processing unless the law prohibits it. The Main Agreement, this DPA, and the Customer's configuration and use of the platform constitute the Customer's documented instructions. Praktikal does not process Customer Personal Data for its own purposes.
Praktikal informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law, and may suspend performance of that instruction until it is confirmed or withdrawn.
Customer obligations. The Customer is responsible for the lawfulness of the personal data it provides and the instructions it gives, for having a valid legal basis, and for providing any information required to data subjects under Arts. 13 and 14 GDPR. The Customer is instructed not to enter special categories of personal data into the platform, which is not configured for it.
3. Security
Praktikal implements and maintains the technical and organisational measures set out in Annex III, appropriate to the risk under Art. 32 GDPR. Praktikal may update those measures to reflect technical development, provided the level of protection is not reduced.
Praktikal ensures that persons authorised to process Customer Personal Data are bound by an obligation of confidentiality, and limits access to personnel who require it for their role.
4. Breach notification
Praktikal notifies the Customer without undue delay and no later than 48 hours after becoming aware of a personal data breach affecting Customer Personal Data, with the information available at that time, supplemented as the investigation progresses.
The notification describes the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for further information, to the extent that information is available to Praktikal.
Praktikal assists the Customer in meeting its own obligations under Arts. 33 and 34 GDPR, taking into account the nature of the processing and the information available to Praktikal. Notification under this section is not an acknowledgement of fault or liability.
5. Assistance and cooperation
Data subject requests. Praktikal notifies the Customer without undue delay of any request it receives directly from a data subject relating to Customer Personal Data, and does not respond to it itself unless instructed by the Customer. Taking into account the nature of the processing, Praktikal assists the Customer by appropriate technical and organisational measures in fulfilling the Customer's obligation to respond to requests to exercise data subject rights.
Impact assessments and prior consultation. Praktikal assists the Customer in ensuring compliance with Arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to Praktikal. Praktikal provides the information reasonably necessary for the Customer to carry out a data protection impact assessment, including the processing description in Annex II, the measures in Annex III, and the sub-processor list in Annex IV.
How assistance is provided, and cost. Where the platform provides functionality by which the Customer can meet a request itself, making that functionality available constitutes Praktikal's assistance. Assistance covered by platform functionality and by Praktikal's standard documentation is provided at no additional charge. Where the Customer requests assistance that requires significant effort beyond that, Praktikal may charge its reasonable costs, notified to the Customer in advance.
6. Audit
Praktikal makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR, in the form of its security documentation package, including the measures in Annex III.
Where that package does not answer the Customer's question, the Customer may audit Praktikal's compliance with this DPA once per twelve months, on 30 days' written notice, during business hours, without unreasonable disruption to Praktikal's operations, at the Customer's cost, and subject to confidentiality. An auditor appointed by the Customer must be suitably qualified and must not be a competitor of Praktikal.
The once-per-twelve-months limit does not apply to an audit mandated by a supervisory authority, or to an audit following a confirmed personal data breach affecting the Customer's data.
7. Sub-processors
The Customer gives Praktikal general written authorisation to engage sub-processors. Praktikal maintains the current list of sub-processors at https://www.praktikal.ee/subprocessors. That published list governs; Annex IV records the list as at the date of this DPA and is not re-executed when it changes.
Praktikal notifies the Customer of any intended addition or replacement at least 30 days before the change takes effect, by email to the Customer's designated contact. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected service without penalty.
Praktikal engages each sub-processor under a written contract imposing data protection obligations equivalent to those in this DPA, and remains fully liable to the Customer for the performance of that sub-processor's obligations, in accordance with Art. 28(4) GDPR.
8. AI processing
The platform offers AI-assisted features in two modes, with different allocations of responsibility.
(a) Praktikal-provided AI. Where the Customer enables AI features that run on Praktikal's own provider credentials, the AI providers listed in Annex IV act as Praktikal's sub-processors and this DPA applies to that processing in full. Praktikal remains fully responsible to the Customer for their performance under Art. 28(4) GDPR. Any choice the Customer makes between the providers offered is a configuration option and does not make the Customer responsible for Praktikal's relationship with that provider.
(b) Customer-directed AI. Where the Customer enables the use of its own AI provider credentials, or connects an external AI client to the platform through the Model Context Protocol, Praktikal transmits data to the endpoint the Customer has designated, acting on the Customer's instruction. The Customer is responsible for its own relationship with that provider, including concluding any processing agreement, determining the location of that processing, and carrying out any impact assessment required before enabling the connection. Praktikal does not control, and is not responsible for, processing carried out by that provider once the data has been transmitted.
Where the Customer opens such a connection, the destination of that processing is determined by the Customer and not by Praktikal.
(c) Controller-level enablement. Both modes are enabled at the level of the Customer's organisation by an administrator authorised by the Customer, not by individual users.
(d) Data minimisation. Where personal data is transmitted to an AI provider under this section, Praktikal applies the pseudonymisation and scrubbing measures described in Annex III. The parties acknowledge that pseudonymised data remains personal data within the meaning of the GDPR.
9. International transfers
Customer Personal Data processed under this DPA is hosted and stored within the European Union.
Where the Customer enables AI features on Praktikal's own credentials under 8(a), content is transmitted to the AI sub-processors identified in Annex IV, which process it outside the European Union. Praktikal has concluded with each of those sub-processors the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, and applies the pseudonymisation and minimisation measures in Annex III as supplementary measures.
Processing directed by the Customer under 8(b) takes place wherever the provider chosen by the Customer processes it.
Praktikal does not introduce a further sub-processor outside the European Union without following the notice and objection procedure in section 7.
10. Term, suspension and deletion
Term. This DPA takes effect when it is concluded under section 1 and continues for as long as Praktikal processes Customer Personal Data.
Suspension. Where Praktikal is in material breach of this DPA, the Customer may notify Praktikal in writing, specifying the breach. If Praktikal has not remedied the breach within 30 days of that notice, the Customer may instruct Praktikal to suspend the processing of Customer Personal Data until the breach is remedied, or may terminate the Main Agreement insofar as it concerns the affected processing.
Praktikal may terminate this DPA insofar as it concerns processing under a particular instruction where, after Praktikal has informed the Customer that the instruction infringes applicable law under section 2, the Customer insists on compliance with it.
Deletion and return. On termination, at the Customer's choice, Praktikal returns Customer Personal Data to the Customer or deletes it. Where the Customer requests return, Praktikal provides an export of its content and data within 30 days of the request. Praktikal deletes Customer Personal Data, including any copies, within 30 days of termination or of the Customer's request, except where retention is required by Union or Member State law. Backups are deleted on the ordinary backup rotation cycle, which does not exceed 30 days, and remain subject to this DPA until deleted. Praktikal certifies deletion on request.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Main Agreement.
Nothing in this DPA limits or excludes either party's liability to a data subject under Art. 82 GDPR, liability for a regulatory fine imposed on that party, or any liability that cannot be limited or excluded under applicable law.
Praktikal's responsibility for its sub-processors under section 7 is not affected by this section, other than as to the amount recoverable.
Annex I — List of parties
Processor. Praktikal Education OÜ, Sirbi 13, Tartu, Estonia, registry code 16229727, VAT EE102398843. Contact: Omari Loid, info@praktikal.ee.
Controller. The customer organisation that concludes this DPA.
This DPA may be concluded without a separate signature through express electronic incorporation or authorised acceptance under section 1. A copy for signature is available on request; that copy records the details of both parties.
Annex II — Description of the processing
Categories of data subjects
- Teachers and other staff of the Customer
- Students and session participants, both authenticated and anonymous
- Organisation administrators appointed by the Customer
Categories of personal data
| Category | Detail |
|---|---|
| Identity and account | Name, email address, authentication identifiers, role, organisation context |
| Authored content | Lessons, worksheets, questions, comments, uploaded materials and related collaboration metadata |
| Learning data | Answers, results, grades, correctness state, participation records |
| Session data | System-assigned pseudonymous participant names, session chat, raise-hand events, shared board content |
| Live audio and video | Audio and video streams in live sessions, processed on Praktikal's self-hosted media infrastructure |
| Technical and security | IP address, browser and device data, language preference, sign-in metadata, audit and security logs |
| Support | Support correspondence and troubleshooting context |
Special categories of data. Not intended. The platform is not configured for special category data and the Customer is instructed not to enter it.
Nature and purpose of processing. Hosting and delivering the platform; storing and serving authored content; running live sessions; recording and presenting answers, results and grades; search indexing; notification delivery; and, where enabled by the Customer, AI-assisted authoring and analysis.
Duration. The term of the Main Agreement, plus the deletion window in section 10.
Annex III — Technical and organisational measures
Pseudonymisation
- Participants are assigned a system-generated pseudonym. No user-supplied name is stored as the participant identifier.
- Within the platform, an authenticated participant's responses remain linked to their account, and are presented to their teacher under their account name. Pseudonymisation is applied at the boundary where data leaves Praktikal, not as a property of the platform's internal storage.
- Data transmitted to AI providers and to external tools connected over the Model Context Protocol carries the system-generated pseudonym only. Account names and authentication identifiers are not transmitted, including for authenticated participants.
- The mapping between pseudonym and account is held only by Praktikal, within the European Union.
- User identity is not included in AI system context; the account is resolved only to determine access rights.
- Identifying information is scrubbed from free-text answer content before that content is transmitted to an AI provider.
Access control
- Role-based permissions enforced server-side per item of content, applied on read as well as write.
- Authentication through a dedicated identity provider, with organisation and role context carried in the session.
Encryption
- Encryption in transit for all client traffic, using certificates issued by a public certificate authority and managed automatically.
- Application-level encryption of session chat content, authentication session data, API keys, and external service credentials, with encryption keys held in a dedicated secrets manager separate from the application database.
- Encryption at rest for databases and object storage.
Infrastructure and segregation
- Separate development, staging, and production environments.
- Live media processed on self-hosted infrastructure rather than a third-party cloud media service.
- Secrets held in a dedicated secrets manager and injected at deployment, not stored in source control.
Logging, backup, and continuity
- Application and security logging with audit trails.
- Database backups written to object storage in the European Union (IONOS, region eu-central-3), compressed and transmitted over TLS.
- Daily database backups, plus a dump before each schema migration.
- Backup retention: 30 days for daily backups, 7 days for pre-migration dumps.
Organisational
- Personnel with access to personal data are bound by confidentiality obligations in their employment or contractor agreements.
- Dependencies are monitored and updated through automated dependency management.
- A defined escalation path for suspected personal data breaches, supporting the notification commitment in section 4.
- Access to production systems is limited to personnel who require it for their role.
Annex IV — Sub-processors
Sub-processors engaged for processing on the Customer's behalf, as at the date of this DPA. The current list is maintained at https://www.praktikal.ee/subprocessors and governs; changes are made under section 7.
| Sub-processor | Purpose | Location |
|---|---|---|
| IONOS SE | Hosting, infrastructure, and object storage for uploaded images, attachments and media | Frankfurt and Berlin, Germany |
| Novu | Notification delivery | European Union |
| Anthropic PBC | LLM inference, engaged only where the Customer enables AI features on Praktikal-provided credentials | United States |
| OpenAI | LLM inference, engaged only where the Customer enables AI features on Praktikal-provided credentials | United States |
| DeepL SE | Machine translation of authored text, on user request | European Union |
Hosting and storage of personal data take place within the European Union. The AI sub-processors process outside the European Union; transfers to them are governed by section 9.