Sample agreement

    Data processing agreement for schools

    When a school uses Zeitlernen, it remains responsible for its pupils' data. We process that data on its behalf. What exactly that means, which service providers are involved and how we protect the data is set out in this agreement.

    As at August 3, 2026 · Agreement version 1.0

    This is the sample version without school details filled in. Schools with an account see their own version in the school area under “Documents”, where they can conclude the agreement electronically and download it as a PDF.

    Data Processing Agreement

    Agreement on the processing of personal data on behalf of a controller, version 1.0

    Between

    Name
    ________________________
    Address
    ________________________
    Represented by
    ________________________
    Role
    ________________________

    hereinafter the “Controller”

    And

    Name
    blackpine GmbH
    Address
    Bahnhofstrasse 2, 6210 Sursee, Switzerland
    Represented by
    Philippe Wettstein and Marc Sen, partners

    hereinafter the “Processor”, together the “Parties”

    Preamble

    The Controller uses the Zeitlernen learning application to teach pupils how to read a clock and to follow their learning progress. In doing so, the Processor processes personal data for which the Controller remains responsible.

    This agreement governs that processing on behalf of the Controller. It gives effect to the requirements of Art. 9 of the Swiss Federal Act on Data Protection (FADP), Art. 7 of the Data Protection Ordinance (DPO) and Art. 28 of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) to the extent that it applies. Where the Controller is a public body subject to a cantonal data protection act, the provisions of this agreement apply accordingly to the outsourcing of data processing provided for there.

    1. Subject matter and duration

    1.1 The subject matter of this agreement is the processing of personal data by the Processor in the course of providing and operating Zeitlernen for the Controller. The nature, scope and purpose of the processing are set out in Annex 1.

    1.2 This agreement starts when the Controller accepts it and runs for as long as the Controller uses Zeitlernen. It ends automatically when the usage relationship ends, without any separate termination being required. The obligations under clause 13 and clause 6 survive its end.

    1.3 In all matters concerning the processing of personal data on behalf of the Controller, this agreement takes precedence over the Zeitlernen general terms and conditions.

    2. Scope and allocation of responsibilities

    2.1 This agreement covers only that personal data which the Controller records, or has recorded, in the school area of Zeitlernen, in particular data on classes and on pupils together with the learning and usage data arising from it (“School Data”).

    2.2 The Controller is the controller of the School Data within the meaning of data protection law. The Processor processes it solely on behalf of and on the instructions of the Controller.

    2.3 This agreement does not cover:

    • a) The accounts of teachers and other team members, namely email address, sign-in data and profile details. The Processor is itself the controller of this data because it enters into a separate usage relationship with the person concerned. That processing is governed by the Zeitlernen privacy policy.
    • b) Accounts that parents or guardians open privately and outside the school context, together with the child profiles created in them. Here too the Processor is itself the controller.
    • c) Data that the Processor processes in order to meet its own legal obligations or to keep its systems secure, to the extent that it decides on the purposes and means itself. In doing so it remains bound by the confidentiality obligation under clause 6.

    2.4 The Controller ensures that there is a valid legal basis for recording and processing the School Data, that the data subjects and their parents or guardians have been informed to the extent required, and that any authorisations or notifications required under cantonal law are in place.

    3. Nature, scope and purpose of the processing

    3.1 The categories of data subjects, the categories of data processed, the purposes and the nature of the processing are described in Annex 1.

    3.2 Processing takes place solely in order to provide the contractually agreed services. There is no processing for the Processor's own purposes.

    3.3 The Controller undertakes not to record any sensitive personal data within the meaning of Art. 5 lit. c FADP or any special categories of data within the meaning of Art. 9 GDPR in Zeitlernen. The application provides neither fields nor special safeguards for such data. Free-text fields are to be used sparingly accordingly.

    4. The Controller's right to issue instructions

    4.1 The Processor processes the School Data solely on documented instructions from the Controller. This agreement including its annexes, together with the use of the functions provided in the application, constitutes such instructions.

    4.2 Instructions that go beyond the use of the functions provided are to be sent in text form to the contact point named in Annex 4. Instructions given verbally are to be confirmed in text form without delay.

    4.3 If the Processor considers that an instruction infringes applicable data protection law, it informs the Controller without delay. It is entitled to suspend execution of the instruction until it is confirmed or amended.

    4.4 If the Processor is required by law to carry out processing that departs from the instructions, it notifies the Controller before the processing takes place, unless the law prohibits such notification.

    5. Obligations of the Processor

    5.1 The Processor processes the School Data only within the framework of this agreement and the Controller's instructions.

    5.2 In particular, it does not use the School Data

    • a) for its own purposes, for advertising or for market research,
    • b) to build profiles outside the agreed learning functions,
    • c) to train, develop or improve artificial intelligence or machine learning systems,
    • d) to pass it on to third parties, except to the subprocessors named in Annex 3 and in cases of a legal obligation.

    5.3 It maintains a record of the processing activities carried out on behalf of the Controller and, on request, provides the Controller with the details needed for the Controller's own record.

    5.4 It assists the Controller in meeting the Controller's obligations under clauses 10 to 12.

    5.5 If the School Data held by the Processor is put at risk by seizure, attachment, insolvency proceedings or measures taken by third parties, it informs the Controller without delay.

    6. Confidentiality

    6.1 The Processor uses only its own employees to process the School Data. They are bound to secrecy by their employment relationship and by Art. 321a of the Swiss Code of Obligations and are familiar with the relevant provisions of data protection law. In accordance with Art. 321a para. 4 CO, the obligation continues after the employment relationship ends.

    6.2 The confidentiality obligation extends to all data and information learned in the course of this agreement, whether or not it constitutes personal data.

    6.3 The group of people with access to production data is limited to what operations require and is reviewed periodically.

    7. Technical and organisational measures

    7.1 The Processor takes the technical and organisational measures described in Annex 2 to ensure data security in accordance with Art. 8 FADP, Art. 3 DPO and Art. 32 GDPR.

    7.2 The measures are subject to technical progress. The Processor may adapt them provided that the agreed level of protection is not thereby reduced. Material changes are documented and communicated to the Controller on request.

    7.3 The Processor reviews the effectiveness of the measures periodically, at least once a year.

    8. Subprocessing

    8.1 The Controller gives the Processor general authorisation to engage the subprocessors listed in Annex 3.

    8.2 The Processor contractually binds every subprocessor to data protection obligations that are substantially equivalent to those in this agreement, in particular to adequate technical and organisational measures. It is liable for their conduct as for its own.

    8.3 If the Processor intends to engage a further subprocessor or to replace an existing one, it informs the Controller in text form at least 30 days in advance. The information is sent to the Controller's address recorded in Annex 4 and is also published by updating the list available in the school area.

    8.4 The Controller may object to the change in text form within 30 days of receiving the information, on substantive grounds relating to data protection. If no mutually acceptable solution is then found, the Controller may terminate the usage relationship extraordinarily and free of charge with effect from the date of the intended change.

    8.5 Ancillary services that the Processor uses in order to run its business, such as telecommunications, postal services or cleaning, as well as services that involve no access to School Data, do not count as subprocessing.

    9. Processing abroad

    9.1 The School Data is stored in a data centre in Switzerland. The infrastructure provider operates the database in the Europe (Zurich) region of Amazon Web Services (region code eu-central-2), located in Switzerland.

    9.2 For individual services, technical connection data or, in the case of email delivery, teachers' contact details arise at subprocessors domiciled outside Switzerland and the European Economic Area. The services concerned, the types of data and the places of processing are set out in Annex 3.

    9.3 Where data is disclosed to a country without an adequate level of protection, the Processor relies on the European Commission's standard contractual clauses, supplemented by the Swiss adaptations recognised by the Federal Data Protection and Information Commissioner, or on another mechanism permitted under Art. 16 FADP or Chapter V GDPR.

    10. Rights of data subjects

    10.1 Upholding the rights of data subjects is the Controller's responsibility. Requests from pupils or their parents and guardians are addressed primarily to the Controller.

    10.2 If a data subject approaches the Processor directly, the Processor forwards the request to the Controller without delay and does not answer it itself, unless instructed to do so or legally obliged.

    10.3 The Processor assists the Controller with appropriate technical and organisational measures in responding to requests for access, rectification, erasure, restriction, objection and data portability. To that end the school area of Zeitlernen provides functions for viewing, correcting and deleting data, and for exporting the master data, the learning analyses and the raw learning data at event level in a common, machine-readable format, which the Controller can use on its own.

    10.4 For assistance that goes beyond the functions available in the application and involves considerable effort, the Processor may charge a reasonable fee. It announces this in advance.

    11. Assistance with further obligations

    Taking into account the information available to it, the Processor assists the Controller to the extent required with

    • a) ensuring data security,
    • b) notifying data security breaches to the competent supervisory authority and to data subjects,
    • c) carrying out a data protection impact assessment under Art. 22 FADP or Art. 35 GDPR,
    • d) any prior consultation of the supervisory authority.

    12. Data security breaches

    12.1 The Processor notifies the Controller of every data security breach affecting School Data without delay after becoming aware of it, and at the latest within 48 hours.

    12.2 As far as known, the notification contains:

    • a) a description of the nature of the breach, the categories concerned and the approximate number of data subjects and records affected,
    • b) the time or period of the incident,
    • c) the likely consequences,
    • d) the measures taken or proposed to address the breach and to mitigate possible adverse effects,
    • e) a contact point for questions.

    12.3 If not all details are available yet, an initial notification is made with the information at hand; the remainder follows without delay.

    12.4 The Processor documents data security breaches including the measures taken.

    12.5 Notifications to supervisory authorities or to data subjects are made by the Controller. The Processor does not notify on the Controller's behalf without the Controller's instruction.

    13. Deletion and return

    13.1 Throughout the term of the agreement the Controller can extract the School Data in a common, machine-readable format using the export function in the school area.

    13.2 After the agreement ends, the Processor deletes the School Data within 30 days, unless the Controller has requested its return beforehand. On request, deletion is confirmed in text form.

    13.3 Backup copies that still contain the deleted data are overwritten in line with the regular backup cycle, at the latest within a further 30 days. Until then the data remains excluded from productive use.

    13.4 Data is retained beyond these periods only where statutory retention obligations require it. In that case the data concerned is blocked and processed solely for the purpose of meeting that obligation.

    13.5 Anonymised or aggregated analyses that do not allow any conclusions about individuals may continue to be used.

    14. Evidence and audits

    14.1 On request, the Processor demonstrates compliance with its obligations under this agreement, primarily by providing information in text form, by supplying the current version of Annex 2 and by answering an audit questionnaire from the Controller.

    14.2 Where this evidence is not sufficient in an individual case, the Controller may carry out an on-site audit or have one carried out by an independent auditor bound to confidentiality. The audit must be announced at least 30 days in advance, takes place during regular business hours and must not unreasonably disrupt operations. Without specific cause, an audit is permitted at most once a year.

    14.3 The auditor must not be a competitor of the Processor. No access is granted to other customers' data.

    14.4 The Controller bears the cost of audits under clause 14.2, unless the audit reveals a material breach by the Processor.

    15. Liability

    15.1 Liability is governed by the Zeitlernen general terms and conditions and by applicable law.

    15.2 Claims by data subjects under Art. 82 GDPR, as well as fines and sanctions imposed on a party by the competent authorities, are excluded from any limitation of liability; each party bears these to the extent of its own contribution to the breach.

    16. Final provisions

    16.1 Amendments and additions to this agreement require text form. This also applies to any waiver of this form requirement.

    16.2 The Processor may amend this agreement if the legal situation, supervisory practice or the service changes materially. It informs the Controller at least 30 days before the amendment takes effect. If the Controller objects within that period, either party may terminate the usage relationship in the ordinary way with effect from the date the amendment takes effect.

    16.3 Should any provision of this agreement be invalid, the validity of the remaining provisions is unaffected. The parties replace the invalid provision with a valid one that comes closest to its economic purpose.

    16.4 In the event of conflict, the following order applies: the annexes to this agreement, this agreement, the Zeitlernen general terms and conditions.

    16.5 This agreement is governed by Swiss law. The place of jurisdiction is Sursee, canton of Lucerne, Switzerland, unless mandatory law provides otherwise. For controllers domiciled in the European Union, mandatory places of jurisdiction under the GDPR are reserved.

    17. Conclusion

    This agreement is concluded electronically. Confirmation by a person authorised to sign on behalf of the Controller in the school area of Zeitlernen constitutes conclusion of the agreement within the meaning of Art. 28 para. 9 GDPR, which expressly permits electronic form.

    Draft version. This document has not been accepted yet. It is concluded electronically in the school area of Zeitlernen or by signing the printed copy.

    Name
    ________________________
    Role
    ________________________
    Date
    ________________________
    Signature
    ________________________
    For the Processor
    blackpine GmbH
    Represented by
    Philippe Wettstein and Marc Sen, partners
    Signature
    blackpine GmbH, Sursee

    Annex 1: Description of the processing

    Subject matter

    Provision and operation of the Zeitlernen learning application for the Controller, including management of classes and learners, running exercises and quizzes, and presenting learning progress to the Controller's teachers.

    Nature of the processing

    Collection, storage, organisation, alteration, retrieval, querying, use, disclosure by transmission to authorised teachers, restriction, erasure and destruction, in each case by automated means.

    Purposes

    • Creating and managing classes as well as pupils
    • Assigning and managing the sign-in codes for pupil access
    • Running learning units, exercises and quizzes
    • Recording and analysing learning progress for the teachers responsible
    • Adapting the difficulty level to the age and school level
    • Operation, maintenance, troubleshooting and security of the application
    • Support for the Controller

    Categories of data subjects

    • Pupils of the Controller
    • Teachers and other team members of the Controller, insofar as they are assigned to classes and appear in the School Data

    Categories of personal data

    Master data of the school and the classes
    Name and address of the school, language, class names, school level, assignment of teachers to classes.
    Master data of the pupils
    First name (mandatory), year of birth (mandatory), class assignment, sign-in code, display name, avatar selection as well as learning settings such as bedtime and preferred difficulty level. Optional and controlled by the Controller: surname, full date of birth.
    Learning and usage data
    Progress in learning to read the clock, tasks set and answers given, time and duration of exercises, quiz sessions, history of class assignments.
    Technical data
    Technical connection data arises when the application is opened (IP address of the device, browser and device details). None of this is stored permanently against individual pupils; they have no account, and the School Data contains neither an IP address nor a time of access. For teachers' accounts the privacy policy applies, see clause 2.3.
    Special categories
    None. The application provides no fields for them. Under clause 3.3 the Controller must not record such data.

    Duration

    For the duration of the usage relationship, thereafter in accordance with clause 13.


    Annex 2: Technical and organisational measures

    As at August 3, 2026. The Processor operates no servers of its own. The technical infrastructure is obtained through the subprocessors named in Annex 3; the measures below cover both the Processor's own measures and the measures contractually assured by those providers.

    1. Physical access control

    • The database and the server functions are operated in a data centre in Switzerland (Amazon Web Services, Europe (Zurich) region, eu-central-2). Physical access, video surveillance, visitor management, uninterruptible power supply and fire protection are the responsibility of the data centre operator and meet industry standards.
    • The Processor keeps no local copies of production data on portable media.
    • The Processor's work devices run with full-disk encryption, screen lock and an up-to-date operating system.
    • The infrastructure provider is certified to ISO/IEC 27001 and holds a SOC 2 Type 2 report.

    2. System access control

    • Teachers and team members sign in with an email address and password or through an identity provider (Google, Apple, Microsoft).
    • Passwords are stored only as a hash, never in plain text.
    • Sign-in attempts are subject to server-side rate limiting. Registration and password resets are additionally preceded by bot protection (Cloudflare Turnstile).
    • Sessions run on short-lived access tokens with automatic renewal. For every account the last access is recorded with the time, browser and device details, a truncated IP prefix and the sign-in method.
    • Pupils sign in solely with a code issued by the Controller, without an email address and without a password. Codes can be regenerated at any time.
    • Password resets and changes of email address run through a confirmed second channel using time-limited one-time codes.
    • Accounts can optionally be protected with two-factor authentication. The Controller decides whether its teachers make use of it; there is no obligation to do so.

    3. Data access control

    • Data access is secured throughout by row level security at the database layer. Row level security is enabled on all tables in the application schema; access is checked in the database itself, not only in the application.
    • Within a school a graded role model applies: administration, co-administration, teacher and read-only. Teachers see the data of the classes assigned to them.
    • Privileged server credentials are held exclusively server-side and never reach the browser or the mobile application.
    • Administrative functions of the Processor are protected by a separate role check and are logged.
    • Credentials and keys are held in a secret store outside the source code and are not contained in the version control system.

    4. Transfer control

    • All traffic between the device, the delivery network and the servers is encrypted with TLS. Unencrypted connections are redirected.
    • The application uses a content security policy restricting the permitted sources for scripts, styles and connections.
    • Data is encrypted at rest with AES-256. Access tokens and keys are additionally encrypted at application level before being stored.
    • School Data is never sent by email or on physical media. Exports are made solely through the authenticated export function in the school area.

    5. Input control (traceability)

    • Administrative interventions by the Processor are recorded in an audit log with the acting person, the action, the record concerned, the time and the IP address. The log is readable only by authorised persons.
    • Records carry timestamps for creation and last change.
    • Security-relevant events and the sending of system emails are logged.
    • Write operations carry a unique event identifier, which rules out duplicate entries when an operation is retried.

    6. Separation control (tenant separation)

    • All School Data is assigned to a school identifier. The separation is enforced by row level security in the database, not merely through the user interface.
    • Access across school boundaries is impossible even if a query in the application is faulty.
    • Production and development environments are separate. No production data is used in development.

    7. Availability and resilience

    • The database is backed up automatically every day by the infrastructure provider. Backups are kept for 7 days and are then overwritten.
    • Static content is served redundantly through a global delivery network with protection against denial-of-service attacks.
    • Recovery procedures are documented and reviewed periodically.
    • Write operations that fail because of a network interruption are buffered locally and retried automatically, which avoids data loss when the connection in the classroom is unstable.

    8. Pseudonymisation and data minimisation

    • Pupils have no account with an email address or password; they sign in with a code.
    • Mandatory details are limited to first name and year of birth. Surname and full date of birth are optional; the Controller may leave it at the year of birth.
    • IP addresses are not stored in full in the database, only as a truncated prefix.
    • No payment or invoicing data about data subjects is collected.
    • The application uses no advertising or tracking cookies and no analytics services.

    9. Recoverability and deletion

    • The Controller can delete learners, classes and the entire school on its own. The deletion cascades to the associated classes, assignments, invitations and learning states.
    • Teachers' accounts can be deleted in the account settings; the deletion is carried out server-side.
    • Deletion periods and the procedure after the agreement ends are governed by clause 13.

    10. Organisational measures

    • Access to production data is granted solely to employees of blackpine GmbH, and only insofar as their task requires it. They are bound to secrecy by their employment contract and by Art. 321a CO. Permissions are reviewed periodically and withdrawn when someone leaves. External service providers receive no access.
    • Changes to the system go through a release procedure with static code analysis, type checking and an automated test suite, all of which run before anything is merged into the main branch.
    • Database changes are made solely through versioned migrations traceable in the version control system.
    • Security advisories from the infrastructure provider are reviewed periodically.
    • For incidents there is a reporting path under clause 12 with a defined contact point.
    • Dependencies are updated regularly; the updates go through the same chain of checks.

    11. Measures that are not currently in place

    The Processor states transparently what is not part of the measures:

    • The Processor itself is not certified to ISO/IEC 27001 and does not provide its own SOC 2 report. The certifications of its infrastructure provider are set out in Annex 2 clause 1.
    • No regular external penetration tests are carried out.

    Annex 3: Subprocessors

    As at August 3, 2026. The current version is available in the school area of Zeitlernen.

    1. Subprocessors with access to School Data

    CompanyDomicileServiceData processedPlace of processing
    Supabase, Inc.USADatabase, authentication, server functions, backupsall School Datadata centre in Switzerland (AWS eu-central-2, Zurich)
    Cloudflare, Inc.USADelivery of the application, protection against attacks, bot protection at sign-inconnection data including IP address, browser and device detailsglobal network, delivery from the nearest location
    Plus Five Five, Inc. (Resend)USASending system emails to teachers and team membersemail address, display name, content of the messageUSA

    A data processing agreement including standard contractual clauses is in place with all three companies. The versions currently in force are publicly available: Supabase at supabase.com/legal/customer-resources/data-processing-addendum, Cloudflare at cloudflare.com/cloudflare-customer-dpa, Resend at resend.com/legal/dpa.

    2. Further services where technical connection data arises

    These services receive no School Data, only technical connection information about the device used to open the application. They are listed for the sake of transparency.

    CompanyDomicileServiceData processedOccasion
    Adobe Inc.USADelivery of the interface typefaceIP address, browser and device detailsevery time the application is opened, on the web and in the app
    Google Ireland Ltd.IrelandDelivery of the interface typefaceIP address, browser and device detailsevery time the application is opened, on the web and in the app
    Florian Körner (DiceBear)GermanyGeneration of avatar imagesIP address; no names and no learning dataonly when the avatar generator is opened

    3. Mobile application and app stores

    In the app for iOS and Android the learning content is part of the application package. To that extent there is no disclosure to third parties. The app talks to the same services as the web interface; it does not create any additional recipients of School Data.

    Apple and Google are not subprocessors under this agreement. The App Store and Google Play distribute only the application package and receive no School Data in doing so. The data arising on download is processed by Apple and Google as controllers in their own right vis-à-vis the person installing the app.


    Annex 4: Contact points

    Processor

    Company
    blackpine GmbH
    Address
    Bahnhofstrasse 2, 6210 Sursee, Switzerland
    Data protection contact point
    [email protected]
    Notifications under clause 12
    [email protected]

    Controller

    School
    ________________________
    Address
    ________________________
    Contact person
    ________________________
    Role
    ________________________
    Email for notifications and change announcements
    ________________________