Data Processing Agreement
Last updated: August 18, 2026
1. PURPOSE AND NATURE OF THE AGREEMENT
This Data Processing Agreement (the "Agreement") governs the processing of personal data that Edena Software S.L. (Tax ID: B27627462; "Edena") carries out on behalf of the client organization in the context of providing the service, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR). The Agreement forms an integral part of the service's Terms and Conditions.
For the purposes of this Agreement, the client organization (the educational center) is the Data Controller and Edena acts as the Data Processor.
2. NATURE, PURPOSE AND DURATION OF THE PROCESSING
Edena will process the personal data provided or generated by the controller solely to provide the platform's services (management of people and records, billing, communications and associated features), for the duration of the contractual relationship.
3. DATA SUBJECTS AND CATEGORIES OF DATA
- Data subjects: students, families and guardians, center staff and other users managed by the controller in the platform.
- Categories of data: identification and contact data, academic data, billing data and, where applicable, essential health data (allergies or special needs) entered under the center's responsibility.
4. INSTRUCTIONS FROM THE CONTROLLER
Edena will process the data exclusively following the controller's documented instructions, including the configuration and use the controller makes of the platform, unless required otherwise by European Union or Member State law; in that case, Edena will inform the controller before processing, unless that law prohibits it.
5. CONFIDENTIALITY
Edena guarantees that the persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
6. SECURITY OF PROCESSING
Edena applies appropriate technical and organizational measures in accordance with Article 32 of the GDPR, including encryption of data in transit and at rest, role-based access control (least privilege), data isolation between organizations, periodic backups and activity logging.
7. SUB-PROCESSORS
The controller authorizes Edena to engage the sub-processors listed below. All of them are bound by a contract imposing data protection obligations equivalent to those in this Agreement, and Edena remains liable to the controller for their performance.
7.1 Infrastructure
- Supabase — database and authentication. Germany (AWS eu-central-1, Frankfurt).
- Google Cloud (Cloud Run) — application hosting. Belgium (europe-west1).
- Cloudflare R2 — file and document storage. Configured location Western Europe; see section 13.
- Upstash — background job queue and cache. Belgium (europe-west1).
7.2 Communications
- Resend — transactional email delivery (invoices, invitations and notices). United States.
- Expo — push notification delivery to mobile devices. United States. Receives the device identifier and the notification text.
7.3 Payments
- Stripe — payment and direct debit processing. Ireland and United States.
7.4 Artificial intelligence
- Scaleway — language models. France (Paris). The only provider that may process organization data, and its terms exclude training on that data.
- Mistral AI — translation of organizational structure names. France.
- Groq — fallback for the above. United States. Receives organizational level names only (for example "Stage", "Year" or "Group"), never personal data.
Edena uses no other artificial intelligence provider. This restriction is implemented in the code itself and does not depend on environment configuration, so it cannot be widened without a reviewed change to the software.
7.5 Services connected by the controller
Where the controller voluntarily connects an external service (for example Google Calendar or Microsoft), the data synchronized with it leaves the platform on the controller's own instruction and into an account the controller operates. Such services are not Edena sub-processors, and their processing is governed by the relationship between the controller and that provider.
7.6 Communications required by law
Where the controller has invoicing under the VeriFactu system enabled, the platform submits invoicing records to the Spanish Tax Agency (Agencia Estatal de Administración Tributaria), including the identifying and tax details of the invoice recipient. This communication discharges a legal obligation of the controller itself, so the Tax Agency does not act as an Edena sub-processor but as a recipient provided for by law.
Edena will notify the controller of any intended change to this list at least 30 days in advance, giving the controller the opportunity to object. Where the controller objects on reasoned grounds and no reasonable alternative is available, it may terminate the contract without penalty.
8. ASSISTANCE TO THE CONTROLLER
Edena will assist the controller, taking into account the nature of the processing, in responding to requests to exercise data subject rights (access, rectification, erasure, objection, restriction and portability), as well as in complying with security obligations, notification of data breaches and impact assessments.
The platform includes tools to export and anonymize a data subject's data, enabling the controller to fulfil access, portability and erasure rights.
9. DATA OF MINORS
It is the controller's responsibility, as an educational center, to obtain any necessary consents from parents or legal guardians before entering minors' data in the platform. Edena does not use minors' data for any purpose other than providing the service to the controller.
10. NOTIFICATION OF DATA BREACHES
Edena will notify the controller without undue delay after becoming aware of a personal data breach, providing the relevant available information so that the controller can comply with its notification obligations to the supervisory authority and to data subjects.
11. DELETION OR RETURN OF THE DATA
Upon termination of the service, Edena will delete or return to the controller, at the controller's choice, the personal data and existing copies, unless it must retain them under a legal obligation (for example, billing records subject to tax obligations), in which case they will remain blocked for the legally required periods.
12. AUDIT
Edena will make available to the controller the information necessary to demonstrate compliance with the obligations of Article 28 of the GDPR and will allow and contribute to reasonable audits, including inspections, in accordance with a procedure agreed between the parties.
13. INTERNATIONAL TRANSFERS
The database, application hosting, the background job queue and the artificial intelligence providers that may process organization data (section 7.4) are located in the European Union.
The sub-processors identified in section 7 as being based in the United States (Resend, Expo, Stripe and Groq) involve an international transfer of data. Those transfers rely on the Standard Contractual Clauses approved by the European Commission or, where the provider is certified, on the EU-US Data Privacy Framework, together with any supplementary measures required following the corresponding transfer impact assessment.
File storage (Cloudflare R2) is configured with a Western Europe location. As this is a placement preference rather than a binding jurisdictional restriction, and as the provider is a United States entity, this relationship relies on the same safeguards set out in the preceding paragraph.
Should a sub-processor change the location from which it processes data, Edena will notify the controller as provided in section 7.
14. CONTACT
For any questions related to this Agreement you can write to us at [email protected].
