Studyula
FeaturesLearning CoachPricingInstitutionsResourcesBlog
Sign InStart Free
FeaturesLearning CoachPricingInstitutionsResourcesBlog
Sign InStart Free
STUDYULA • INSTITUTIONS

Data Processing Agreement (DPA) — Standard Terms

This page describes Studyula’s standard data-processing approach for agreements with educational institutions.

Last updated: 4 September 2026

Summary

The institution’s instructions and legal responsibilities for student/staff data and Studyula’s service-provider/processor role are defined by contract and applicable law. A signed DPA is completed with institution details and country-specific schedules where needed.

1. Roles and scope

Where the institution determines the purposes and means of processing, it may act as controller and Studyula as processor acting on documented instructions. Processing where Studyula acts independently as controller remains subject to the Privacy Policy.

2. Processing and instructions

Studyula processes account, class, course, assignment, assessment, attendance, academic-analysis, guidance/support and school-operation data only to provide the service, protect security and follow lawful authorized instructions. Unlawful instructions are not followed.

3. Confidentiality and security

Authorized personnel are subject to confidentiality. Studyula applies role-based access, tenant isolation, secure authentication/sessions, encrypted communications, security and audit logs, backups, monitoring and appropriate access controls.

4. Subprocessors and transfers

Subprocessors may be used for necessary service components. Current categories are listed on the Subprocessors page. Institution-specific DPAs may identify active providers, regions and contractual transfer mechanisms where required.

5. Data-subject requests and incidents

Studyula provides reasonable technical assistance for data-subject requests falling under the institution’s responsibility. Where a verified security incident affects institution data, Studyula coordinates with the institution under applicable contract and law.

6. Return/deletion at end of service

When the service ends, institution data may be returned, deleted or anonymized according to the contract, subject to legal retention, security and backup requirements. Ending institution membership does not necessarily delete an independent personal learner account.

7. Executed version

This public page summarizes Studyula’s standard DPA principles. A legally binding institution DPA should separately include the parties’ formal details, data categories, purposes, retention, subprocessors, transfer terms and signatures.

Related security and data documents
PrivacyKVKK NoticeDPASubprocessorsTrust CenterVulnerability DisclosureData Rights Center
Studyula

Studyula brings your materials and learning data together so you can see more clearly what to study, why it matters, and how you are progressing.

Grade 5+6 languagesAI-powered
ProductFeaturesPersonal Learning CoachAI Study AssistantAI Homework HelperPDF Study ToolAI Quiz GeneratorPricingResourcesBlogInvite a Friend
InstitutionsStudyula for InstitutionsAI Teacher StudioDifferentiated AssignmentRisk CenterSmart TimetableInstitution Sign InInstitution RegistrationData Processing Agreement (DPA)
CompanyAboutFAQContactsupport@studyula.com
LegalPrivacyKVKK NoticeTerms of UseCookiesAcceptable UseChild SafetyGrade 5+ Usage PolicyRefund Policy
Security & DataPrivacy / Data RightsTrust CenterSubprocessorsReport a Vulnerability
© 2026 Studyula. All rights reserved.studyula.com