LearningLevels

Data Processing Agreement

Effective: 2026-06-23 en Download PDF

LearningLevels AG — Data Processing Agreement

Data Processing Agreement

LearningLevels AG

Effective date: 23 June 2026

1. Introduction and Scope

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between
LearningLevels AG (“Processor”) and the Customer (“Controller”) and governs the processing of personal data by LearningLevels on behalf of the Customer in connection with the LearningLevels platform and services (“Services”).
This DPA applies to all processing of personal data carried out by LearningLevels on behalf of the Customer, including processing carried out by authorized subprocessors. It is intended to comply with the requirements of the EU General Data Protection Regulation (GDPR) , the
Swiss Federal Act on Data Protection (DSG), the Family Educational Rights and Privacy Act (FERPA), and the Children’s Online Privacy Protection Act (COPPA) as applicable.

2. Definitions

  • “Applicable Data Protection Law” means GDPR, the Swiss nDSG, FERPA, COPPA, and any other applicable data protection legislation.
  • “Personal Data” has the meaning given in Applicable Data Protection Law and includes Student Data.
  • “Student Data” means any personal data relating to a student, including education records as defined under FERPA.
  • “Processing” has the meaning given in Applicable Data Protection Law.
  • “Data Subject” means any identified or identifiable natural person to whom Personal
    Data relates.
  • “Subprocessor” means any third-party processor engaged by LearningLevels to process Personal Data.
  • “Security Incident” means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

3. Roles of the Parties

The Customer is the Data Controller in respect of Personal Data processed through the
Services. LearningLevels is the Data Processor acting on behalf of the Customer. Where
LearningLevels processes Personal Data for its own purposes (e.g., account management), it acts as an independent Data Controller, as described in the Privacy Policy.
For FERPA purposes, LearningLevels acts as a school official with a legitimate educational interest when processing education records on behalf of U.S. educational institutions.

4. Processing Instructions

LearningLevels shall process Personal Data only on documented instructions from the
Customer, as set out in this DPA and the Terms of Service, unless required to do so by applicable law. LearningLevels shall promptly inform the Customer if, in its opinion, any instruction infringes Applicable Data Protection Law.
The Customer instructs LearningLevels to process Personal Data for the following purposes:
LearningLevels AG | legal@learninglevels.com

  • Providing and maintaining the LearningLevels platform and Services;
  • Enabling AI-assisted content generation features using the Customer’s uploaded materials;
  • Supporting student progress tracking, gamification, and peer help features;
  • Sending notifications and communications related to the Services;
  • Providing customer support;
  • Complying with legal obligations.

5. Details of Processing

The following table describes the personal data processing carried out under this DPA:

Category Data Subjects Data Types Retention
Account data Teachers, admins
Name, email, password hash, role
Duration of account +
30 days
User content Teachers
Uploaded documents, generated materials
Duration of account or on deletion
Student data Students (13+)
Name, progress, assignments, class membership
Duration of contract +
90 days
Billing data Account holders
Stripe customer ID, plan status
Duration of account
Analytics Teachers, students
Usage events, progress metrics
Anonymized after 12 months

6. Obligations of LearningLevels

LearningLevels shall:

  • Process Personal Data only as instructed by the Customer or as required by law;
  • Ensure that persons authorized to process Personal Data are bound by appropriate confidentiality obligations;
  • Implement and maintain appropriate technical and organizational security measures as described in Section 8;
  • Not engage Subprocessors without prior authorization from the Customer as described in Section 9;
  • Assist the Customer in responding to Data Subject requests to the extent reasonably practicable given the nature of the processing;
  • Assist the Customer in meeting its obligations under applicable data protection and privacy laws, including Articles 32–36 GDPR, the Swiss Federal Act on Data
    Protection, FERPA, and COPPA, in particular with respect to security, breach notification, data protection impact assessments, and comparable compliance obligations;
  • At the Customer’s choice, delete or return all Personal Data upon termination of the
    Services;
  • Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA.

7. Obligations of the Customer

The Customer shall:

  • Ensure it has a lawful basis for processing Personal Data under Applicable Data
    Protection Law before instructing LearningLevels;
  • Ensure that Data Subjects have been provided with appropriate information about the processing, including through the Customer’s own privacy notices;
  • Where deploying the Services to students under 13, comply with COPPA consent requirements and ensure appropriate parental or school consent is in place;
  • Ensure that use of the Services complies with FERPA where applicable, including designating LearningLevels as a school official in its FERPA records as appropriate;
  • Not instruct LearningLevels to process Personal Data in a manner that would violate
    Applicable Data Protection Law.

8. Security Measures

LearningLevels implements and maintains the following technical and organizational measures:

  • Encryption of Personal Data at rest using Google Cloud Platform managed encryption;
  • Encryption of Personal Data in transit using TLS;
  • Access controls ensuring Personal Data is accessible only to authorized personnel on a need-to-know basis;
  • Role-based access control and authentication for all platform access;
  • Audit logging of access to systems containing Personal Data;
  • Security incident detection and response procedures as documented in the internal
    Security Incident Runbook;
  • Regular review of security measures.
    LearningLevels shall notify the Customer without undue delay, and in any case within 48 hours of becoming aware of a Security Incident affecting the Customer’s Personal Data, to allow the Customer to meet its own 72-hour GDPR notification obligation where applicable.

9. Subprocessors

The Customer hereby provides general authorization for LearningLevels to engage the following approved Subprocessors:

Subprocessor Location Purpose
Google Cloud EMEA Limited (incl. Cloud SQL, Cloud
Storage, Document AI, Gemini
API)
EU / EEA
Cloud infrastructure, database hosting, document digitization, AI content generation
Stripe Payments Europe
Limited
EU / EEA
Payment processing and subscription management
Resend Inc. EU / EEA Transactional email delivery (account notifications, DSAR export delivery, deletion request confirmations)

LearningLevels will notify the Customer at least 30 days in advance of any intended addition or replacement of Subprocessors. The Customer may object to such changes on reasonable grounds within 14 days of notification.
LearningLevels shall impose data protection obligations on each Subprocessor equivalent to those in this DPA.

10. Data Subject Rights

LearningLevels shall, to the extent technically feasible, assist the Customer in fulfilling its obligation to respond to Data Subject requests, including requests for access, rectification, erasure, restriction of processing, data portability, and objection. The Customer remains responsible for responding to Data Subjects directly.
LearningLevels shall support deletion and data export requests through its internal tooling and shall execute such requests within 30 days of a valid instruction from the Customer.

11. Data Transfers

LearningLevels processes Personal Data within the EU/EEA and Switzerland. Where data is transferred outside these territories, LearningLevels shall ensure that appropriate transfer mechanisms are in place, including Standard Contractual Clauses or equivalent safeguards recognized under Applicable Data Protection Law.
For Swiss Personal Data, transfers comply with the requirements of the Swiss nDSG and applicable FDPIC guidance.

12. FERPA-Specific Provisions

Where the Customer is a U.S. educational institution subject to FERPA, LearningLevels agrees to:

  • Process student education records only as directed by the institution and solely for the purpose of providing the Services;
  • Not disclose education records to third parties without the institution’s prior written consent, except as permitted by FERPA;
  • Not use student education records for any commercial purpose, including advertising or marketing;
  • Return or delete education records upon request or termination of the agreement;
  • Maintain reasonable security measures to protect education records from unauthorized access or disclosure.

13. COPPA-Specific Provisions

Where the Customer deploys the Services to students under 13, the Customer acts as the
COPPA consent authority on behalf of parents under the school consent exception (16
C.F.R. Part 312.4(c)). In reliance on this consent, LearningLevels agrees to:

  • Collect from students under 13 only the personal data strictly necessary to provide the educational Services;
  • Not use personal data of students under 13 for any commercial purpose;
  • Not disclose personal data of students under 13 to third parties except to
    Subprocessors as listed in Section 9;
  • Delete personal data of students under 13 promptly upon request from the Customer or upon termination.

14. Audit Rights

Upon reasonable written notice, LearningLevels shall make available to the Customer information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits conducted by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality protections. LearningLevels may satisfy this obligation by providing relevant certification reports, third-party audit results, or written representations.

15. Term and Termination

This DPA is effective for the duration of the Terms of Service and terminates automatically upon expiry or termination of the Terms. Upon termination, LearningLevels shall, at the
Customer’s written election, delete or return all Personal Data within 30 days, subject to any applicable legal retention obligations. LearningLevels shall certify such deletion in writing upon request.

16. Liability

Each party’s liability under this DPA is subject to the limitations set out in the Terms of
Service. Nothing in this DPA limits either party’s liability for damages caused by intentional misconduct or gross negligence.

17. Governing Law

This DPA is governed by Swiss law. The courts of Switzerland have exclusive jurisdiction over disputes arising under this DPA.

18. Order of Precedence

In the event of conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the processing of Personal Data.

19. Contact

For data protection enquiries, please contact:
Data Protection Contact: LearningLevels AG
Email: privacy@learninglevels.com

Exhibit A — Standard Contractual Clauses Notice

Where Personal Data is transferred from the European Economic Area or Switzerland to a third country, such transfers are subject to the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (Commission
Decision C(2021) 3972), incorporated herein by reference, with LearningLevels acting as data exporter and the relevant Subprocessor as data importer. For Swiss transfers, the
FDPIC-recognized equivalents apply.


© 2026 LearningLevels AG · learninglevels.ch