Skip to main content

Campus Life

Data processing agreement

This agreement sets out how Campus Life processes the personal data the Academy entrusts to it — data of students, their guardians and staff — on whose instructions, and under what protection.

Effective from

Contents
  1. Subject matter and roles
  2. Categories of data and data subjects
  3. Instructions and limits of processing
  4. Confidentiality and staff access
  5. Security measures
  6. Processors we engage
  7. Incidents and assistance
  8. Return and erasure of data
  9. Term and verification

Subject matter and roles

1.1

The parties to this agreement are the Academy and Հովհաննես Խարազյան ԱՁ (hereinafter "Campus Life"). It applies alongside the Terms of Use and governs the processing of personal data only.

1.2

Data of students, their legal guardians and Academy staff is controlled by the Academy: it decides the purposes and means of processing and answers to the data subjects.

1.3

Campus Life processes that data solely on the Academy’s instructions and solely to operate the platform. It is not used for our own purposes, not sold, and not passed on for advertising.

Categories of data and data subjects

2.1

Operating the platform involves processing:

  • student data: first and last name, contact details, date of birth, learning progress, attendance, test results, payment status;
  • data of a minor’s legal guardian — where the training agreement is concluded with their involvement;
  • data of Academy staff: name, contact details, role and access rights;
  • technical data: sign-in dates, device and session identifiers needed for account security.

Instructions and limits of processing

3.1

The instruction to process is given by using the platform itself: the Academy uploading data, forming groups and opening accounts constitutes that instruction. Separate written instructions prevail where they do not conflict with the law.

3.2

Campus Life does not change the purposes of processing, does not widen the set of data, and takes no action beyond providing the service and this agreement.

3.3

If, in our assessment, an instruction from the Academy conflicts with the requirements of the law, we say so and may suspend acting on it until the matter is clarified.

Confidentiality and staff access

4.1

Only staff who need the data to do their work have access to it, and only to the extent needed. They are bound by confidentiality obligations that survive the end of their employment.

4.2

Within the Academy’s accounts, rights are separated by role and granted by the Academy itself: Campus Life staff do not gain access to teaching content automatically.

Security measures

5.1

The following technical and organisational measures apply:

  • every Academy gets its own database: one academy’s data is not physically mixed with another’s;
  • all traffic is encrypted in transit;
  • passwords are stored only in irreversible form, using the bcrypt algorithm;
  • the session cookie carries the `__Host-` prefix and `SameSite=Strict`, and the `Origin` of mutating requests is checked;
  • public forms are rate limited, and the sender’s IP address is stored only as a hash;
  • backups run daily into separate storage where the server has no right to delete.

Processors we engage

6.1

Providing the service involves the following processors:

  • a cloud infrastructure provider — the servers and the backup storage;
  • a network infrastructure provider — DNS, TLS certificates and protection against attacks; traffic passes through its network;
  • an email delivery service — sending notifications and invoices.
6.2

The current list of engaged processors, naming their jurisdictions, is provided at the Academy’s request. The Academy is notified in advance before a new processor is engaged and may object. Each of them is bound by obligations no weaker than those in this agreement. Servers and backups are located outside Armenia, with a provider operating in European Union countries; this is a cross-border transfer and it is described in the Privacy Policy.

Incidents and assistance

7.1

On discovering a personal data breach, Campus Life notifies the Academy without undue delay, stating the known circumstances, the scope of impact and the measures taken.

7.2

A request from a data subject is answered by the Academy as the controller. Campus Life assists technically: exporting, correcting or erasing data on the Academy’s instruction.

7.3

Data is disclosed to a public authority only in the cases the law provides for; so far as possible and permitted by law, the Academy is informed.

Return and erasure of data

8.1

The Academy can export its data at any time using the platform. If the subscription ends, the ability to export remains for a reasonable period after access is withdrawn.

8.2

After that the Academy’s data is erased, except what the law requires us to keep — accounting and contractual documents. Backups lose the data when their retention period ends.

Term and verification

9.1

This agreement lasts for as long as Campus Life processes the Academy’s data and ends when that data is erased. The Academy is notified of changes in the same way as of changes to the Terms of Use.

9.2

The Academy may request information about how this agreement is performed. Any such review is carried out so as not to reveal other academies’ data and not to disrupt the service.

Հովհաննես Խարազյան ԱՁ

Tax ID
78046621
Website
campuslife.am
Address
Մամիկոնյանց 21/1, ք. Երևան, Հայաստան