Data Processing Agreement
For schools, organisations and other customers that use LectaMe and engage LectaMe as a processor. Compliant with the General Data Protection Regulation.
Last updated: 1 september 2026 · Document version 2.5
Plain-language summary
- Your organisation decides which data is processed — LectaMe carries this out within the arrangements set out below.
- Primary storage within the EU. For sub-processors outside the EEA, the DPF and/or Standard Contractual Clauses apply.
- We report data breaches to the controller without undue delay; the controller then assesses whether to notify the supervisory authority and the data subjects.
- We do not use personal data from your processing for our own marketing or AI training.
Status: this document is a standard draft based on the GDPR. For large organisations and tenders, we are happy to work with a signed version tailored to your situation. In that case, please get in touch via legal@lectame.com.
1. Parties
This data processing agreement applies between:
The school, organisation or business user that uses LectaMe (hereinafter: Client). If used by an individual teacher without an organisation, that teacher may also act as Client for their own processing. The Client determines the purpose and means of the processing.
To be completed by the Client upon signing:
- Organisation name: ____________________________
- Address: ____________________________
- Chamber of Commerce number: ____________________________
- Contact person: ____________________________
- Email address: ____________________________
LYNT V.O.F. (trading under the name LectaMe)
Rotterdam, Nederland
Chamber of Commerce number: 97241229
Email: privacy@lectame.com
Jointly referred to as the "Parties".
2. Definitions
- GDPR: Regulation (EU) 2016/679, the General Data Protection Regulation.
- Personal data: all information relating to an identified or identifiable natural person, as referred to in Article 4(1) GDPR.
- Processing: any operation relating to personal data, such as collection, recording, storage, alteration, consultation, disclosure or erasure.
- Data subject: the natural person to whom the personal data relates — primarily teachers and participants.
- Data breach: a breach of security that, accidentally or unlawfully, leads to the destruction, loss, alteration, unauthorised disclosure of or access to personal data.
- Sub-processor: a third party engaged by the Processor to process personal data on behalf of the Controller.
3. Subject matter
This agreement governs the processing of personal data by LectaMe in connection with the provision of the LectaMe platform — an AI-supported presentation and interaction platform for education and training.
4. Term and termination
The agreement takes effect when the Client starts using LectaMe (by creating an account or organising a session in which participant data is processed) and remains in force for as long as LectaMe processes personal data on behalf of the Client.
The agreement terminates automatically when LectaMe no longer processes any personal data for the Client, or upon written termination by either of the Parties subject to the notice period set out in the main agreement.
5. Roles
- Client is the controller for processing carried out in connection with their teaching or training activities using LectaMe.
- LectaMe is the processor for processing carried out on behalf of the Client.
- For processing that LectaMe carries out for its own business purposes (such as account management, security, invoicing, own marketing), LectaMe is itself the controller. This agreement does not cover that; see the privacy policy.
6. Documented instructions
LectaMe processes personal data solely on the basis of documented instructions from the Client. This agreement, the terms and conditions and the privacy policy together form those instructions, along with the settings the Client configures in the application (for example, the choice to turn AI features or analytics on or off).
LectaMe informs the Client if it considers that an instruction infringes the GDPR.
6a. Coaching data and the separation of coaching and assessment
Within LectaMe's mentoring and development environments, data subjects record data for the purpose of their own professional development: reflections, coaching conversations, observations and agreements with a mentor. In the system this data has the privacy scope private or coaching and is technically separated from the formal space in which assessment takes place.
Data recorded within LectaMe as coaching data is processed solely for the purpose of professional development and mentoring. It is not disclosed to managers, HR, assessors or other representatives of the Client, and is not used for formal personnel assessment, unless the data subject has deliberately moved that data to the formal space themselves.
The Client expressly instructs LectaMe not to make data with the privacy scope private or coaching available for HR, assessment, management or general administrative purposes, and not to include it in general exports. Any additional instruction that changes this purpose falls outside the agreed processing and requires a separate contractual amendment and privacy assessment.
Two exceptions
- A legal obligation on LectaMe, including a lawful order from a competent authority. LectaMe informs the Client in advance, unless such notification is prohibited by law.
- A request from the data subject themselves under their GDPR rights, including access and data portability. That request concerns their own data and does not go through the Client.
Outside these two cases there is no route — technical or contractual — by which the Client can obtain coaching data for personnel assessment.
7. Nature and purpose of the processing
- Creating and editing presentations, including any AI-generated content at the teacher's request.
- Organising and facilitating live sessions in which participants join via a session code or QR code.
- Recording and presenting participants' answers and responses to the teacher, for formative purposes.
- Management and authentication of the Client's accounts and those of their staff.
- Logging and monitoring for security and stability purposes.
- Supporting the guidance and professional development of students or employees: learning goals, practice assignments, portfolio and evidence, feedback, coaching conversations, planning, work placements, exams and exemptions — insofar as the Client uses the module in question.
- Recording self-assessments and mentor assessments against work processes from a qualification or competence framework, and deriving progress and points of attention from them.
8. Categories of personal data
| Category | Data |
|---|---|
| Teacher / administrator account | Email address, name (optional), hashed password or OAuth identifier, optionally a TOTP secret |
| Participant profile | Self-chosen display name, session code, timestamps |
| Session content | Answers, responses, contributions and any open input |
| Presentation content | Presentations, slides and associated uploads created by teachers |
| Technical data | IP address, User-Agent, timestamps, limited log data |
| Billing data (for paid accounts) | Processed by our payment service (Mollie); LectaMe only sees invoice metadata, no card details |
| Lesson progress of identifiable students (within an organization) | When a logged-in student joins a live lesson within the same organization as the teacher: name, progress (slides viewed/completed), quiz results, personal notes and AI-explanation questions. Visible to the relevant teacher; outside a shared organization participation remains anonymous. |
| Student account and file | Name or display name, email address, file number, programme, cohort, year and period, school or organisation, file status and any work placement period. |
| Learning goals and progress | Self-formulated learning goals with actions, deadlines and status; links to a qualification or competence framework; self-assessment and mentor assessment per work process; derived progress, signals and points of attention. |
| Portfolio and evidence | Files and links added by the student, title and description, reflection, links to learning goals, visibility setting and assessment status. |
| Feedback and coaching conversations | Feedback questions and answers between student and mentor, including who was asked and who answered; scheduled conversations with type, date, participants, summary, agreements and notes; planning with tasks and deadlines. |
| Mentoring relationships | Who is linked to whom, in which role (mentor, teacher, practice supervisor, work supervisor, examiner), with which permission level, valid from and until, and whether the link has been accepted. |
| Wellbeing reflection (My Growth module) | Self-reported reflections on how the data subject is doing. These data carry the privacy scope private or coaching, are not visible to assessors or managers and fall under the instruction in article 6b. They may contain health data; see article 10. |
9. Categories of data subjects
- Teachers and administrators of the Client who have an account.
- Participants (typically students or course participants) who join a live session via a session code.
- Guests who create presentations without an account under the responsibility of the Client.
- Students with an account who work on their learning goals, portfolio and professional development within the Client's guidance and development environment.
- Mentors from outside the educational institution such as practice supervisors and work supervisors at a training company, who follow a student on invitation, within the limits of their role and permission level.
10. Special categories of personal data
LectaMe is niet ontworpen voor de structurele verwerking van bijzondere persoonsgegevens (artikel 9 AVG) of strafrechtelijke gegevens (artikel 10 AVG). De Opdrachtgever zorgt ervoor dat gebruikers binnen de eigen organisatie geen medische gegevens, diagnoses, religieuze overtuiging, etniciteit, seksuele gerichtheid of vergelijkbare gegevens invoeren in presentatie-inhoud, AI-prompts of sessiegegevens, tenzij daar vooraf een rechtmatige basis en passende maatregelen voor zijn ingericht.
LectaMe toont waar relevant in de interface waarschuwingen aan gebruikers om geen persoonsgegevens, patiëntgegevens of vertrouwelijke informatie in AI-prompts op te nemen.
One module is an explicit exception, and it was designed that way. My Growth invites the data subject to reflect on wellbeing, balance, habits, goals and personal experiences. An answer to that may reveal information about a person's physical or mental health. The Parties therefore assume that special categories of personal data within the meaning of article 9 GDPR may be processed within My Growth. A prohibition would not be credible while the module deliberately asks about wellbeing; instead the processing is regulated along the conditions in this article.
10a. My Growth — conditions for processing
My Growth is OFF by default. The module is activated per institution only, after the Client has established in writing on which legal basis under article 6 GDPR it processes, which exception under article 9(2) GDPR it invokes, and whether a data protection impact assessment (DPIA) is required. Activation is technical and per organisation; without that action the module does not exist for the Client's data subjects.
Purpose limitation
Data from My Growth is processed solely for guidance and self-reflection. It is not used for assessment, examination, disciplinary measures, admission, selection or binding study advice, nor for staff appraisal.
Voluntary use
Use of My Growth is voluntary for the data subject. The Client ensures that non-use has no adverse consequences for the data subject's education, guidance or assessment.
Private by default
What the data subject enters is private by default. Sharing occurs only through an explicit action by the data subject, is limited to the mentors they designate, and can be withdrawn by them at any time. Withdrawal operates prospectively: previously shared content is no longer displayed.
Minimal access
Access is limited to predetermined mentors with an active, valid link. Assessors, examiners, managers and general administrators have no access to private or coaching content, and this content does not appear in general exports. See also article 6b.
No automated decisions
Within My Growth, LectaMe applies no automated risk scores, classifications or decisions with legal effect or similarly significant effect. Signals and summaries are aids to conversation; a human mentor remains responsible for any conclusion.
AI processing
Private content from My Growth is not submitted to external AI services. Where the module offers AI support on sensitive parts, it does so with a model running within LectaMe's own infrastructure. Processing by an external AI service takes place only after an explicit action by the data subject and only for the content they designate.
Retention, deletion and export
Retention periods for My Growth are configurable per institution. The data subject can view, export and delete their content. Access to and sharing of content is logged, so that it can be established afterwards who viewed what.
Instruction and support
The Client instructs its users on the purpose and limits of My Growth and on what does not belong in the module. LectaMe supports the Client with a DPIA and with data subject requests by making the necessary information, exports and deletion functions available.
The legal basis remains with the Client
This agreement does not choose a legal basis on the Client's behalf and in particular does not assume consent as a general legal ground. Given the relationship of dependence between a data subject and their educational institution or employer, the tenability of consent is an assessment the Client makes itself as controller, together with its data protection officer or legal adviser. The DPIA decision likewise remains with the Client; LectaMe can supply a shared baseline assessment, but that does not replace the local assessment.
11. Confidentiality
All LectaMe staff and all external persons engaged by LectaMe who may gain access to personal data are bound by confidentiality under their employment or service contract or an additional confidentiality declaration.
12. Technical and organisational measures
LectaMe takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk. In broad terms, these include:
- Access management, authentication and role-based authorisation.
- Encryption of connections and encryption of storage at the platform level.
- Logging and monitoring of security-relevant events.
- Backup and recovery provisions.
- Regular updates and patching of components.
- Incident response procedures.
- Assessment of suppliers and sub-processors.
- Data minimisation and purpose limitation in the design of features.
- Periodic evaluation of the measures.
A high-level explanation can be found on the security page. Additional details can be shared under confidentiality arrangements with schools and organisations that need them for their own assessment.
13. Sub-processors
The Client hereby gives general written authorisation for the engagement of the sub-processors listed below. The procedure in Article 14 applies to changes.
| Sub-processor | Service | Location | Data category | Safeguard |
|---|---|---|---|---|
| Leaseweb Netherlands B.V. | VPS-hosting en gegevensopslag | Amsterdam, Nederland | Alle applicatiegegevens: accountgegevens, presentatie-inhoud, sessiegegevens, geüploade bestanden. | Verwerking binnen EER. |
| Cloudflare Inc. | CDN, DNS, edge-beveiliging en AI-inferentie | Wereldwijd edge-netwerk | IP-adres en technische verbindingsgegevens. Bij AI-inferentie daarnaast de door de docent ingevoerde lesinhoud, gelijk aan wat naar de andere AI-leveranciers gaat. | EU-US Data Privacy Framework (DPF) gecertificeerd; aanvullend Standard Contractual Clauses via Cloudflare DPA. |
| Groq, Inc. | AI-inferentie | Verenigde Staten | Door de docent ingevoerde lesinhoud (onderwerp, leerdoelen, casusbeschrijving). De docent is zelf verantwoordelijk om geen persoonsgegevens in de prompt op te nemen. | Standard Contractual Clauses + interface-waarschuwing tegen invoer van persoonsgegevens. |
| Mistral AI SAS | AI-inferentie | Frankrijk (EER) | Door de docent ingevoerde lesinhoud (onderwerp, leerdoelen, casusbeschrijving) — dezelfde categorie als bij Groq. De docent is zelf verantwoordelijk om geen persoonsgegevens in de prompt op te nemen. | Verwerking binnen EER. Hergebruik van invoer voor modeltraining uitgeschakeld in de accountinstellingen. |
| Mollie B.V. | Betalingsverwerking | Amsterdam, Nederland | Naam, factuuradres, e-mailadres, betalingsgegevens (Mollie verwerkt kaartgegevens zelfstandig — LectaMe ontvangt deze niet). | Verwerking binnen EER. |
| Resend, Inc. | Transactionele e-mail | Verenigde Staten (EU-routes beschikbaar) | E-mailadres, bericht-inhoud, verzendmetadata. | Standard Contractual Clauses; dataminimalisatie (alleen noodzakelijke transactionele berichten). |
| Google Ireland Ltd. | Optionele website-analytics | EU + VS | Geanonimiseerd IP-adres, paginabezoeken, apparaattype. | EU-US Data Privacy Framework; IP-anonimisatie ingeschakeld; geen verwerking zonder consent. |
14. Changes to sub-processors
LectaMe informs the Client at least 30 days before a planned change to the sub-processors (addition, replacement or change of location). Within that period, the Client may object with reasons. In the event of a well-founded objection, the Parties will seek a reasonable solution; if that is not possible, the Client may terminate the agreement.
15. International transfers
Primary storage takes place within the EEA. For sub-processors where processing may (partly) take place outside the EEA, we apply safeguards such as the EU-US Data Privacy Framework and/or Standard Contractual Clauses. The applicable safeguard per sub-processor is shown in the table above.
16. Support with privacy rights
LectaMe supports the Client in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) by, where possible, making the necessary data accessible or exportable via the platform's management functions.
For requests that the Client cannot handle themselves, LectaMe provides reasonable assistance with the requested information.
17. DPIA and prior consultation
LectaMe supports the Client in carrying out a data protection impact assessment (DPIA) and in any prior consultation of the supervisory authority, insofar as this can reasonably be expected of LectaMe.
18. Data breaches
LectaMe reports a possible data breach to the Client without undue delay after LectaMe becomes aware of it. The Client then assesses, as the controller, whether notification to the supervisory authority (in principle within 72 hours of the Client becoming aware) and to the data subjects is necessary.
LectaMe's notification includes, as far as possible:
- The nature of the incident.
- The categories of personal data and data subjects.
- An (estimated) number of data subjects.
- The likely consequences.
- The measures taken and proposed.
- Contact details of a point of contact at LectaMe.
- Additional information as soon as it becomes available.
LectaMe documents all data breaches and the measures taken in response.
19. Audits and provision of information
Upon request, LectaMe provides the Client with reasonably available information enabling the Client to verify compliance with this agreement. An audit by or on behalf of the Client is possible on the basis of written notice, with due regard to reasonable preparation time and business continuity, and subject to confidentiality arrangements. Any costs of an audit are borne by the Client, unless the audit reveals a material shortcoming.
20. Deletion or return after the end of the service
After termination of the service, LectaMe deletes the personal data from active systems within 30 days, unless statutory retention obligations require otherwise. At the Client's request, an export is made available in a common format prior to deletion.
Rotating backups that are still persistent at the time of deletion are removed in accordance with our hosting provider's backup schedule; during that period, data stored in them remains encrypted and inaccessible for production use.
21. Liability
LectaMe's liability under this agreement aligns with the liability provisions in our terms and conditions, except insofar as mandatory law provides otherwise (such as Article 82 GDPR).
22. Order of precedence between documents
In the event of a conflict between this data processing agreement, the terms and conditions and the privacy policy, the following order of precedence applies:
- This data processing agreement (for processing matters).
- The terms and conditions.
- The privacy policy (as an explanation of the processing).
23. Contact
Questions about this data processing agreement? Email privacy@lectame.com or legal@lectame.com. If you have complaints about the processing of personal data, you can also contact the Autoriteit Persoonsgegevens.
Document version 2.5 · Last updated on 1 september 2026.
Questions? Email privacy@lectame.com.