Data Processing Addendum

Last updated: 2026-06-05

This Data Processing Addendum (“DPA”) forms part of the agreement between Larnnit and a customer that uses Larnnit on behalf of an organisation (typically a university, faculty, or enterprise) and provides Larnnit with personal data of its students, staff, or other data subjects (the “Customer Personal Data”). It is offered to satisfy Article 28 of the EU and UK GDPR and equivalent provisions in the Kenya Data Protection Act (2019), the Brazilian LGPD, and the California CPRA.

If you would like a counter-signed copy, email legal@larnnit.com with the legal entity name, registered address, and contact details of your data-protection officer.

1. Roles

  • Customer is the Controller of Customer Personal Data.
  • Larnnit is the Processor, acting on Customer's documented instructions.
  • For data Larnnit processes about Customer's personnel for billing, support, and account management, Larnnit acts as Controller; that processing is governed by our Privacy Policy.

2. Scope & instructions

  • Larnnit will process Customer Personal Data only (a) as instructed by Customer through use of the platform, (b) as required by law, and (c) as necessary to operate the agreed services.
  • Customer instructs Larnnit to process Customer Personal Data as set out in the Privacy Policy and the platform documentation, and as required to provide support, security, fraud prevention, and product improvement using aggregated and de-identified data.
  • Larnnit will inform Customer if, in its opinion, an instruction infringes applicable law.

3. Description of processing

  • Subject matter: provision of the Larnnit platform to Customer's users.
  • Duration: for the term of the service contract, plus any retention period required by law (see Privacy Policy §4).
  • Nature and purpose: hosting and operating an academic platform — accounts, content, communication, marketplace, tutoring.
  • Categories of data subjects: Customer's students, staff, alumni, and other authorised users.
  • Categories of personal data: identifiers (name, email, username, profile photo); affiliation (faculty, programme, year); content (posts, comments, messages, uploaded files); technical data (IP, device, app version, logs); transactional data where applicable.
  • Special categories: none required by the service. Customer should avoid sharing special-category data unless and until specifically configured to do so.

4. Confidentiality

Larnnit ensures that personnel authorised to process Customer Personal Data have committed to appropriate confidentiality obligations.

5. Security

Larnnit implements appropriate technical and organisational measures including TLS in transit, encryption at rest, hashed passwords with bcrypt, JWT with refresh-token rotation, network and application firewalls, rate limiting, audit logs of administrative actions, vulnerability management, secure SDLC, and least-privilege access controls. See Privacy Policy §7 for the user-facing summary.

6. Subprocessors

  • Customer authorises Larnnit to use the subprocessors listed at /subprocessors.
  • Larnnit will give Customer at least 14 days' notice before engaging a new subprocessor and will allow Customer to object on reasonable grounds.
  • Larnnit remains liable for the acts and omissions of its subprocessors in respect of Customer Personal Data.

7. Data-subject requests

Larnnit will, taking into account the nature of the processing, assist Customer to respond to requests from data subjects to exercise their rights of access, rectification, erasure, restriction, portability, objection, and not to be subject to automated decision-making.

8. Personal-data breach

  • Larnnit will notify Customer without undue delay and, where feasible, within 72 hours after becoming aware of a personal-data breach affecting Customer Personal Data.
  • The notification will include the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed.

9. Data Protection Impact Assessment

Larnnit will provide reasonable assistance to Customer in carrying out a DPIA where one is required, and in any prior consultation with a supervisory authority.

10. Return or deletion

At the end of the service contract, Larnnit will, at Customer's choice, delete or return Customer Personal Data and delete existing copies, except to the extent retention is required by law. Backups are purged on the normal 90-day rotation.

11. Audits

Customer may, no more than once per 12 months and on at least 30 days' notice, audit Larnnit's compliance with this DPA. Audits may be conducted by Customer or a qualified independent auditor (subject to mutual NDA). Larnnit may, in lieu of an on-site audit, provide a current SOC 2, ISO 27001, or equivalent third-party attestation where one is held.

12. International transfers

Where Larnnit transfers Customer Personal Data of EEA, UK, or Swiss data subjects to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, where the UK is involved, the UK International Data Transfer Addendum, with Larnnit as data importer and Customer as data exporter. Module 2 (Controller to Processor) applies.

13. Liability

Each party's liability arising out of or related to this DPA is subject to the limits in the main service contract. Nothing in this DPA limits either party's liability to data subjects under applicable law.

14. Governing law

This DPA is governed by the law of the main service contract. If the service contract is silent, English law applies in the EEA/UK, and Kenyan law applies elsewhere.