Skip to main content
← Back to Home

Data Processing Agreement (DPA)

Last updated: February 23, 2026

1. Parties and Scope

This Data Processing Agreement ("DPA") forms part of the service agreement between OVR IT STUDIO ("OVR IT", "Processor") and the contracting institution or organization ("Customer", "Controller"). This DPA governs personal data processing performed by OVR IT to provide OVR IT and associated institutional services.

2. Processing Details

Subject matter: Delivery of student planning, course-task management, analytics, and institutional reporting features.

Duration: For the term of the service agreement, plus limited retention required for legal, security, and contractual obligations.

Categories of data subjects: Students, authorized institution administrators, and support contacts.

Categories of personal data: Account identifiers, course/task metadata, uploaded academic planning documents, usage logs, and institutional configuration data.

3. Customer Instructions

OVR IT processes personal data only on documented instructions from Customer, including instructions reflected in the service configuration, support requests, and this DPA. OVR IT promptly informs Customer if an instruction appears to conflict with applicable data protection law.

4. Security Controls

OVR IT maintains technical and organizational controls appropriate to risk, including encrypted transport, authenticated access controls, least-privilege administrative access, row-level security enforcement, environment secret management, and operational logging for security monitoring.

OVR IT enforces internal safeguards to prevent unauthorized disclosure of student data and maintains confidentiality obligations for personnel with access to Customer data.

5. Subprocessors

OVR IT may use subprocessors to deliver infrastructure and platform functions. As of the Last Updated date, primary subprocessors include Supabase (data platform), Vercel (application hosting), Stripe (billing), and OpenAI (AI feature processing where enabled).

OVR IT remains responsible for subprocessors and maintains written agreements requiring confidentiality, security, and data protection obligations consistent with this DPA.

6. Cross-Border Transfers

Where personal data is transferred across jurisdictions, OVR IT uses legally recognized transfer mechanisms and contractual safeguards as required by applicable law.

7. Data Subject Rights

Taking into account processing nature and available system capabilities, OVR IT assists Customer with requests for access, rectification, deletion, portability, restriction, and objection, to the extent required by applicable law.

8. Incident Response

OVR IT maintains incident response procedures and notifies Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer data, including known facts, likely impact, and mitigation steps available at the time of notification.

9. Retention and Deletion

At contract end or on documented instruction, OVR IT deletes or returns Customer personal data unless legal retention obligations apply. Customer may request verified deletion workflows through support channels.

10. Audit and Evidence

OVR IT provides reasonable information necessary to demonstrate compliance with this DPA. Customer audit requests are handled through mutually agreed scope, timing, and confidentiality protections.

11. Contact

Questions regarding this DPA or data protection practices can be sent to hello@ovrit.app.