Data Processing Agreement
The terms under which SizaPoint processes personal data on behalf of an institutional customer, aligned with GDPR Article 28.
1. Purpose and Scope
This Data Processing Agreement ("DPA") applies where an institution ("Controller") uses SizaPoint and SizaPoint ("Processor") processes personal data of the institution's students or staff on the Controller's behalf. It supplements the Terms of Service and, on execution by both parties, forms part of the contract between them.
2. Definitions
"Personal Data," "Processing," "Controller," "Processor," and "Data Subject" have the meanings given in applicable data protection law (including GDPR and POPIA, as relevant to the Controller).
3. Processing Instructions
SizaPoint will process personal data only on the Controller's documented instructions, including with regard to international transfers, unless required to do otherwise by law — in which case SizaPoint will inform the Controller of that legal requirement before processing, unless the law prohibits such notice.
4. Confidentiality
SizaPoint ensures that personnel authorised to process personal data are subject to a duty of confidentiality.
5. Security Measures
SizaPoint implements appropriate technical and organisational measures as described in our Security & Data Protection page, including encryption in transit and at rest, access controls, and monitoring.
6. Sub-processors
SizaPoint may engage sub-processors (for hosting, email delivery, and payments) under written contracts imposing data protection obligations equivalent to this DPA. SizaPoint will inform the Controller of any intended changes to sub-processors and give the Controller an opportunity to object on reasonable grounds.
7. Assistance with Data Subject Rights
SizaPoint will provide reasonable assistance to help the Controller respond to requests from data subjects exercising their rights, and to meet its obligations regarding security, breach notification, and data protection impact assessments where applicable.
8. International Transfers
Where personal data is transferred outside the Controller's jurisdiction, SizaPoint relies on recognised transfer mechanisms (such as Standard Contractual Clauses) to provide an adequate level of protection.
9. Breach Notification
SizaPoint will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide information reasonably needed for the Controller to meet its own notification obligations.
10. Audit Rights
SizaPoint will make available information reasonably necessary to demonstrate compliance with this DPA and allow for, and contribute to, audits or inspections conducted by the Controller or an appointed auditor, subject to reasonable notice and confidentiality.
11. Deletion or Return of Data
On termination of the underlying agreement, SizaPoint will, at the Controller's choice, delete or return all personal data processed on its behalf, unless retention is required by law.
12. Contact for Enterprise / Institutional Agreements
To execute a signed DPA for your institution, email legal@sizapoint.com (data-protection queries can go to privacy@sizapoint.com), or use the Contact page under "General enquiry," specifying your institution's name and the plan you're evaluating.
Have a question about this document? Contact us.
