Data Processing Terms
최종 업데이트:
Processor agreement under Art. 9 FADP and Art. 28 GDPR
These Data Processing Terms apply whenever EasyO processes student and scheduling data on behalf of a teacher or an institution. They form part of the Terms of Service and are accepted together with them. Institutions can request a countersigned copy with the same content.
1. Scope and parties
- These Data Processing Terms ("DPT") apply when EasyO (Daniel Vayman, Fridbachweg 9, 6300 Zug, Switzerland, contact@easyo.app) processes personal data on behalf of a customer. The customer is the controller: the teacher for an individual account, or the Institution for its linked teachers (Terms of Service, section 16). EasyO is the processor.
- The DPT form part of the Terms of Service and are accepted together with them. They meet the requirements of Art. 9 of the Swiss Federal Act on Data Protection (FADP) and, where the GDPR applies, Art. 28 GDPR. Institutions can request a countersigned copy with the same content.
- For data protection matters, the DPT take precedence over the Terms of Service. They apply for as long as EasyO processes personal data for the customer.
2. Details of the processing
- Subject matter and purpose: providing EasyO, in particular collecting student availability through public forms, storing and planning lessons, generating and editing timetables, exports, calendar feeds and optional email notifications.
- Nature of the processing: collection, storage, organisation, retrieval, adaptation, disclosure on the customer's instruction (for example notification emails, exports and calendar feeds) and deletion.
- Data subjects: students (including minors), other persons whose contact details the customer enters for a student, teachers and Institution staff.
- Categories of personal data: names, level or grade, lesson length, frequency and number of lessons, workplace, availability and preferred times, email addresses, school student IDs (Institutions), timetable, attendance and calendar entries, and any notes the customer enters. Sensitive personal data is not required and should only be entered where strictly necessary.
- Duration: for the term of the contract and until deletion under section 9.
3. Instructions
- EasyO processes customer data only on the customer's documented instructions. The Terms of Service, these DPT and the customer's use and configuration of the service are the complete instructions at the time of acceptance; further instructions can be given by email.
- EasyO processes customer data for other purposes only where required by law, and then informs the customer in advance unless the law prohibits this. The only other use is the service improvement described in section 10.
- EasyO informs the customer if it considers that an instruction infringes data protection law.
4. Confidentiality
Persons at EasyO who have access to customer data (currently only the provider) are bound to confidentiality. Any future staff or contractors will be bound to confidentiality in writing before they receive access.
5. Security
EasyO implements appropriate technical and organisational measures (Annex 1) and adapts them to the state of the art. It may change measures as long as the level of protection is not reduced.
6. Subprocessors
- The customer authorises the subprocessors listed in Annex 2. EasyO may engage new subprocessors or replace existing ones. It informs customers by email at least 30 days in advance and updates this page. The customer may object on reasonable data protection grounds within that period; if no solution is found, the customer can terminate the affected service with effect from the change and receives a pro rata refund of prepaid fees.
- EasyO imposes data protection obligations on each subprocessor that are equivalent in substance to these DPT, and remains responsible to the customer for its subprocessors.
7. International transfers
Customer data is stored in the EU (Frankfurt, Germany) and managed from Switzerland; Switzerland and the EU recognise each other's level of data protection as adequate. Where a subprocessor may access data from another country (Annex 2), EasyO ensures an adequate level of protection, in particular through a recognised adequacy decision (for example certification under the EU‑U.S. or Swiss‑U.S. Data Privacy Framework) or the EU Standard Contractual Clauses with the amendments required for Switzerland.
8. Support for the customer
- Requests from data subjects: the customer can view, correct, export and delete student data directly in EasyO. If a data subject contacts EasyO, EasyO forwards the request to the customer without undue delay and does not answer it itself unless instructed.
- Data security breaches: EasyO notifies the customer without undue delay, where possible within 48 hours, after becoming aware of a breach of data security affecting customer data. The notification describes, as far as known, the nature of the breach, the data and data subjects affected, the likely consequences and the measures taken or proposed.
- Other support: taking into account the information available to it, EasyO supports the customer with data security, data protection impact assessments and consultations with supervisory authorities. After prior notice, EasyO may charge at cost for extensive support that goes beyond the normal service.
9. Deletion and return
- During the contract, the customer can export and delete customer data at any time.
- When an account is deleted, EasyO deletes the customer data from its live systems within 30 days and from backups in the regular backup cycle, unless the law requires retention. Deleting the account is the customer's instruction to delete; the customer should export any data it needs beforehand.
- For Institutions, section 16 of the Terms of Service governs what happens to the data when the contract ends or a teacher is unlinked.
10. Service improvement (EasyO as separate controller)
The customer authorises EasyO to keep pseudonymised records of generation runs and timetable corrections (names removed, student IDs replaced by keyed hashes) and to use them only to develop and test EasyO's scheduling algorithms, as described in section 7 of the Terms of Service. For this processing EasyO acts as a separate controller. The customer can switch this off at any time in Settings or by email; EasyO then deletes the existing records for the account. The records are deleted with the account and after 24 months at the latest.
11. Information and audits
- On request, EasyO provides the customer with the information needed to demonstrate compliance with these DPT, in particular by answering reasonable questionnaires and providing documentation.
- If this is not sufficient, or if a supervisory authority requires it, the customer or an independent auditor bound to confidentiality may carry out an audit at most once a year, with at least 30 days' notice, during business hours and without disproportionate disruption. Each party bears its own costs; if the audit reveals a material breach by EasyO, EasyO bears the costs of the audit.
12. Liability and final provisions
- Liability between the parties is governed by the Terms of Service. The rights of data subjects under data protection law are not limited.
- Governing law and place of jurisdiction follow the Terms of Service. If a provision of these DPT is invalid, the remaining provisions stay in force. The German and English versions are binding; if they differ, the German version prevails.
Annex 1: Technical and organisational measures
- Encryption in transit: all connections use HTTPS (TLS) with HTTP Strict Transport Security.
- Access control: each teacher's workspace is separated from other accounts; Institution administrators see the roster, seats and billing, not lesson data; administrative access to the platform is limited to the provider and logged.
- Authentication: passwords are stored only as salted hashes; optional sign‑in with Google or Microsoft where offered; session cookies are HttpOnly, Secure and SameSite; a limited number of simultaneous device sessions; email verification before emails can be sent.
- Abuse protection: rate limiting and bot protection on public forms and sign‑up.
- Hosting and availability: application and database run on a managed cloud platform in the EU (Frankfurt) with regular backups.
- Data minimisation and pseudonymisation: EasyO stores no payment card data; service improvement records are pseudonymised; inactive accounts are deleted automatically after prior warning; deleted students are removed from the trash after 7 days.
- Incident handling: error and security logs are reviewed; affected customers are notified as described in section 8.
Annex 2: Subprocessors
- Render Services, Inc. (USA): hosting of the application and database; data is stored in the Frankfurt (EU) region. Possible access from the USA for operations and support is covered by the provider's data processing agreement with the EU Standard Contractual Clauses.
- Infomaniak Network SA (Switzerland): sending emails (account emails and notifications sent on the customer's instruction).
- Cloudflare, Inc. (USA): bot protection (Turnstile) on public forms and sign‑up; processes technical data such as IP address and browser signals. Safeguards: Data Privacy Framework certification and EU Standard Contractual Clauses.
Paddle.com (payments for individual plans) and Google or Microsoft (optional sign‑in) process teacher account data as separate controllers, not student data; see the Privacy Policy.