SyllonautBETA
Legal · organisations and teachers

Data Processing Agreement

This DPA governs processing of personal data by Syllonaut on behalf of schools, companies and other organisations using Team, School or Campus plans, and on behalf of teachers with individual Free, Teacher or Teacher Pro accounts who use Syllonaut to process students’ personal data in teaching.

Version 1.4 · effective 25/09/2026

1. Parties, role and incorporation into the service contract

The controller is the school, company or other organisation identified in the Syllonaut organisation order, or a teacher with an individual Free, Teacher or Teacher Pro account who uses Syllonaut to process students’ personal data in teaching (or the school or organisation for which that teacher teaches) (“Controller”). The processor is Václav Loubek, Business ID 88878431, Slepá 868, 289 24 Milovice – Mladá, Czech Republic (“Processor” or “Syllonaut”).

This Data Processing Agreement (“DPA”) forms part of the Syllonaut service contract when an authorised representative of the Controller expressly accepts the DPA in the organisation ordering flow. For individual accounts it forms part of the contract concluded by accepting the Terms (Terms section 2). It applies only to processing performed by Syllonaut on behalf of the Controller.

Where Syllonaut determines its own purposes and means of processing, in particular for its own billing, accounting, fraud prevention, service security, legal claims and contract evidence, Syllonaut acts as an independent controller and that processing is governed by the Privacy Notice rather than this DPA.

2. Subject matter, duration, nature and purpose of processing

Syllonaut processes personal data on behalf of the Controller to provide, secure and support the organisation or individual teacher account, lesson authoring and sharing, live classroom sessions, student participation, responses and results, teacher administration and, where enabled and requested, AI-assisted lesson operations and AI evaluation, and, where included in the plan, Syllonaut Help (AI answers to teachers’ questions about using the app, plans and allowances).

Processing lasts for the duration of the organisation or individual service relationship and for the limited period needed to return or delete Controller Data after termination, unless Union or Member State law requires continued storage.

3. Data subjects and categories of personal data

  • Data subjects: teachers, organisation owners/administrators, invited staff and students/participants joining live lessons of the Controller.
  • Account and administration data: name where provided, email address, account identifiers, role, organisation membership and invitation data.
  • Student/live lesson data: display name, responses, team assignment, results, submission timestamps and session/participation metadata.
  • Teaching content: lesson text, teacher instructions, source text extracted from uploaded materials and other content supplied by authorised users where it contains personal data.
  • Technical and security data: request/session identifiers, device/security signals and audit metadata needed to operate and protect the service.
  • Special-category or highly sensitive personal data are not required for Syllonaut’s normal operation. The Controller must not submit such data unless it has determined that doing so is necessary, lawful and appropriately safeguarded.

4. Documented instructions and limits on use

The Processor shall process Controller Data only on documented instructions from the Controller, including this DPA, the Terms, organisation settings, actions performed by authorised organisation users and documented support requests. If Union or Member State law requires other processing, the Processor will inform the Controller before processing unless the law prohibits that notice.

The Processor shall not use Controller Data for unrelated advertising, profiling or its own model training. Current Syllonaut AI inference routes enforce zero data retention at the Vercel AI Gateway layer.

If the Processor believes an instruction infringes the GDPR or other applicable Union or Member State data-protection law, it shall inform the Controller without undue delay.

5. Confidentiality, access control and technical and organisational measures

  • Access to organisation and student data is restricted to authorised users and server-side service paths according to role and scope.
  • Persons authorised by the Processor to handle Controller Data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality.
  • Database access is protected by server-side authorisation, row-level security and least-privilege grants where applicable; privileged internal tables are not intentionally exposed to ordinary clients.
  • Secrets and service credentials are kept out of client-side code and source control; sensitive server operations use dedicated server credentials.
  • Transport uses HTTPS/TLS. Capability and invitation tokens use cryptographically strong random values and/or stored hashes where implemented.
  • Operational analytics are designed not to receive lesson prompts, lesson text, student answers, student names or other content/PII payloads.
  • Retention jobs and product rules limit storage of live-session data; ended live sessions are scheduled for deletion after 12 months and abandoned lobby/live sessions after 30 days unless an earlier deletion instruction applies. Real-time live-control copies (Cloudflare Durable Objects) are deleted automatically 7 days after the session’s last activity.
  • Current AI routes use zero-data-retention configuration and Syllonaut applies input/content separation so student or source text is treated as untrusted content, not as authority to alter system instructions.

6. Sub-processors and changes to the list

The Controller gives general prior authorisation for the Processor to use the sub-processors listed below. The Processor shall impose data-protection obligations on each sub-processor that are no less protective for the relevant processing than the obligations applicable to the Processor under this DPA.

For a planned addition or replacement of a sub-processor that may materially affect Controller Data, the Processor will provide notice at least 15 days in advance where reasonably practicable. The Controller may object within 10 days on reasonable documented data-protection grounds. The parties will seek a practical resolution; if none is reasonably available, the Controller may terminate the affected processing/service without being forced to continue processing through the objected sub-processor.

Where an urgent security, availability or legal requirement makes advance notice impracticable, the Processor may make the change first and notify the Controller without undue delay.

Sub-processorPurposeData scopeLocation / transfers
Neon (Databricks)
Databricks, Inc. (parent company of Neon, LLC)
160 Spear Street, Suite 1300, San Francisco, CA 94105, United States
privacy@databricks.com
Production PostgreSQL database, authentication (Neon Auth) and Data API.Teacher/admin account and sign-in data, organisation membership data, lesson/session data, student display names, responses, results and related metadata stored in Syllonaut.The production project is hosted in the EU (AWS eu-central-1, Frankfurt). Any access from outside the EEA is covered by the Standard Contractual Clauses in the Databricks Data Processing Addendum.
Supabase
Supabase, Inc.
970 Toa Payoh North #07-04, Singapore 318992
privacy@supabase.io
Read-only backup of the former database until the backup is deleted. No new data is written to it.Data stored in Syllonaut up to the move to Neon on 23 September 2026: teacher/admin account data, organisation membership data, lesson/session data, student display names, responses, results and related metadata.The backup is hosted in the EU (eu-west-1). Any other processing by the provider must be covered by the provider’s applicable GDPR transfer safeguards.
Vercel
Vercel Inc.
440 N Barranca Avenue #4133, Covina, CA 91723, United States
privacy@vercel.com
Application hosting, serverless execution, delivery infrastructure and AI Gateway.Application requests, technical metadata and content that must pass through the application or AI Gateway to perform the controller-requested operation.Where processing occurs outside the EEA, Syllonaut relies on an applicable Chapter V GDPR transfer mechanism.
Cloudflare
Cloudflare, Inc.
101 Townsend St., San Francisco, CA 94107, United States
Data Protection Officer · privacyquestions@cloudflare.com
Turnstile bot protection on the sign-in and registration forms, and Workers / Durable Objects for real-time control of live lessons.Turnstile: technical request, browser and anti-abuse signals; lesson content and student answers are not supplied to Turnstile. Live control: student display names, the lesson content shown to students, student and team responses and live-session state. Live-control data is deleted automatically 7 days after the session’s last activity.Live-control Durable Objects run and store data only in the Cloudflare EU jurisdiction. The stateless entry Worker handles requests in the nearest Cloudflare data centre, and Cloudflare logs the object identifier outside the EU for billing and debugging; any processing outside the EEA is covered by the provider’s applicable Chapter V GDPR transfer safeguards.
Resend
Plus Five Five, Inc.
2261 Market Street #5039, San Francisco, CA 94114, United States
Resend Security · privacy@resend.com
Transactional emails, organisation invitations and service notifications.Teacher/admin email addresses and the content of the relevant operational email. Student answers are not intentionally sent through Resend.Where processing occurs outside the EEA, the provider’s applicable GDPR transfer safeguards are used.
OpenAI
OpenAI Ireland Limited
1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland
privacy@openai.com
AI lesson generation/revision, AI evaluation/grading and Syllonaut Help answers on routes that use OpenAI.Prompts, lesson text and, where the controller uses AI grading, the student response and grading context needed for that operation. For Syllonaut Help: the teacher’s question, the earlier messages in the open Help panel and the teacher’s plan and allowance usage; Syllonaut does not store the conversation text.Current Syllonaut AI routes enforce zero data retention at the Vercel AI Gateway layer. Any transfer outside the EEA must be covered by an applicable Chapter V GDPR mechanism.
Amazon Web Services (Bedrock)
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy, L-1855 Luxembourg
Data Protection Officer · aws-EU-privacy@amazon.com
AI processing for supported generation flows using source materials when selected by Syllonaut routing.Prompt and extracted source text needed for the requested AI operation.Processing is used only through the configured Syllonaut route and must remain covered by applicable GDPR transfer safeguards.
Microsoft Azure
Microsoft Ireland Operations Limited
One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Data Protection Officer
AI processing for supported generation flows using source materials when selected by Syllonaut routing.Prompt and extracted source text needed for the requested AI operation.Processing is used only through the configured Syllonaut route and must remain covered by applicable GDPR transfer safeguards.

7. Assistance with data-subject rights, DPIAs and supervisory authorities

Taking into account the nature of the processing, the Processor shall provide reasonable assistance through appropriate technical and organisational measures so the Controller can respond to requests for access, rectification, erasure, restriction, portability or objection where applicable.

The Processor shall provide reasonable information and assistance for data-protection impact assessments and prior consultation with a supervisory authority where the requested assistance relates to processing carried out by Syllonaut on behalf of the Controller.

If Syllonaut directly receives a request relating to Controller Data, it will not independently decide the request on the Controller’s behalf unless legally required; where appropriate it will direct the requester to the Controller or notify the Controller.

8. Personal-data breaches

The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller Data. The notice will include the information reasonably available to Syllonaut about the nature of the breach, affected categories of data/data subjects, likely consequences and measures taken or proposed to address the breach. Information may be provided in phases where it is not available at the same time.

The Processor shall reasonably cooperate with the Controller in investigating, containing and documenting the incident and in meeting the Controller’s notification obligations.

9. Return and deletion of Controller Data

During the service term, the Controller may use available product features or contact vaclav@syllonaut.com to request deletion or a reasonable export/return of Controller Data.

On termination of the organisation service, the Controller may request return of available Controller Data in a reasonably usable format. Unless return is requested or Union/Member State law requires continued storage, the Processor will delete personal data processed solely on behalf of the Controller after the service relationship ends and the operational wind-down needed to complete that deletion.

This clause does not require deletion of data that Syllonaut must retain in its separate role as controller, such as invoices, payment records, security evidence or contract/acceptance evidence, which is governed by the Privacy Notice and applicable law.

10. Demonstrating compliance and audits

The Processor shall make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. The Controller may request a reasonable audit or inspection relevant to Controller Data, subject to appropriate confidentiality and security controls.

Unless required by a supervisory authority, a material incident or credible evidence of non-compliance, audits should ordinarily be limited to once in any 12-month period, be notified reasonably in advance and avoid unnecessary disruption or exposure of other customers’ data.

11. International transfers, precedence and contact

The Processor shall not transfer Controller Data outside the EEA unless the transfer is permitted under Chapter V GDPR, for example because an adequacy decision applies or appropriate safeguards such as standard contractual clauses are in place.

If this DPA conflicts with the Terms on an issue specifically concerning processing of Controller Data on behalf of the Controller, this DPA prevails for that issue. Mandatory GDPR obligations remain unaffected.

Data-protection and DPA notices may be sent to vaclav@syllonaut.com. The current DPA version is 1.4, effective from 2026-09-25.

Related documents

Terms of Service · Privacy Notice