Data Processing Agreement (DPA)
Last updated: February 23, 2026
1. Parties and Scope
This Data Processing Agreement ("DPA") forms part of the service agreement between OVR IT STUDIO ("OVR IT", "Processor") and the contracting institution or organization ("Customer", "Controller"). This DPA governs personal data processing performed by OVR IT to provide OVR IT and associated institutional services.
2. Processing Details
Subject matter: Delivery of student planning, course-task management, analytics, and institutional reporting features.
Duration: For the term of the service agreement, plus limited retention required for legal, security, and contractual obligations.
Categories of data subjects: Students, authorized institution administrators, and support contacts.
Categories of personal data: Account identifiers, course/task metadata, uploaded academic planning documents, usage logs, and institutional configuration data.
3. Customer Instructions
OVR IT processes personal data only on documented instructions from Customer, including instructions reflected in the service configuration, support requests, and this DPA. OVR IT promptly informs Customer if an instruction appears to conflict with applicable data protection law.
4. Security Controls
OVR IT maintains technical and organizational controls appropriate to risk, including encrypted transport, authenticated access controls, least-privilege administrative access, row-level security enforcement, environment secret management, and operational logging for security monitoring.
OVR IT enforces internal safeguards to prevent unauthorized disclosure of student data and maintains confidentiality obligations for personnel with access to Customer data.
5. Subprocessors
OVR IT may use subprocessors to deliver infrastructure and platform functions. As of the Last Updated date, primary subprocessors include Supabase (data platform), Vercel (application hosting), Stripe (billing), and OpenAI (AI feature processing where enabled).
OVR IT remains responsible for subprocessors and maintains written agreements requiring confidentiality, security, and data protection obligations consistent with this DPA.
6. Cross-Border Transfers
Where personal data is transferred across jurisdictions, OVR IT uses legally recognized transfer mechanisms and contractual safeguards as required by applicable law.
7. Data Subject Rights
Taking into account processing nature and available system capabilities, OVR IT assists Customer with requests for access, rectification, deletion, portability, restriction, and objection, to the extent required by applicable law.
8. Incident Response
OVR IT maintains incident response procedures and notifies Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer data, including known facts, likely impact, and mitigation steps available at the time of notification.
9. Retention and Deletion
At contract end or on documented instruction, OVR IT deletes or returns Customer personal data unless legal retention obligations apply. Customer may request verified deletion workflows through support channels.
10. Audit and Evidence
OVR IT provides reasonable information necessary to demonstrate compliance with this DPA. Customer audit requests are handled through mutually agreed scope, timing, and confidentiality protections.
11. Contact
Questions regarding this DPA or data protection practices can be sent to hello@ovrit.app.