Data Processing Addendum
Controller and processor roles, security, sub-processors and breach notification.
Data Processing Addendum is not yet published.
The text below is a draft awaiting legal review. It is not in force, no part of it creates any obligation or right, and nothing on this page should be relied on. Passages marked [TO BE CONFIRMED] are values that have deliberately been left blank rather than guessed.
Catomni Studio handles information about children, so these documents go to a lawyer before they take effect rather than being generated and published.
If you need answers about how your data is handled before these are published, contact your studio directly.
Draft revised: 2026-08-17
Notes for legal review
Open questions and drafting assumptions in this document. These notes are removed when the document goes into force.
- DRAFT for review. This is the document a customer's own counsel is most likely to redline, and the one most likely to be relied on in a procurement review.
- Drafted with the STUDIO as controller/business and Catomni as processor/service provider. Consistent with the Privacy Policy and Children's Privacy Notice; all three change together if that decision changes.
- Annex A records special-category/health data (allergy and medical notes) and children as a category of data subject, because both are true of the product. Confirm whether any additional Art. 9 or state-law conditions need addressing.
- Breach notification is drafted at "without undue delay and no later than 72 hours". Confirm this is operationally achievable before committing to it — an unmet contractual notification window is a breach of contract on top of a security incident.
- International transfer mechanism is unresolved and marked. The SCCs are referenced but not annexed; decide whether to incorporate by reference or attach.
- Audit rights are drafted as information-provision plus a limited on-site right. Confirm the position, including who bears cost and frequency.
- Sub-processor changes are drafted as general authorisation with notice and a right to object. Confirm the notice period and what happens if a customer objects.
1. How this Addendum applies
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Shannon Cyber Services, LLC ("Processor", "we") and the Customer ("Controller", "you") and applies where we process personal data on your behalf in providing Catomni Studio.
Where this DPA conflicts with the Terms of Service, this DPA prevails on the subject of personal data processing. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
2. Definitions
"Data Protection Laws" means all laws applicable to the processing under this DPA, including the UK GDPR, the EU GDPR, the California Consumer Privacy Act as amended ("CCPA"), other US state privacy laws, and COPPA. "Controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "sub-processor" have the meanings given in the GDPR; "business", "service provider", "sell" and "share" have the meanings given in the CCPA. "Customer Personal Data" means personal data within Customer Data.
3. Roles of the parties
You are the controller (and, where the CCPA applies, the business) for Customer Personal Data. We are the processor (and service provider). You determine the purposes and means of processing; we process only as set out in this DPA and on your instructions.
You are responsible for the lawfulness of the personal data you provide and of your instructions, including having a lawful basis, giving the required notices, and obtaining any verifiable parental consent required for personal data about children.
We act as controller for a limited set of our own processing — administering studio staff accounts, billing you, securing and maintaining the platform, and our own business records. The Privacy Policy covers that processing; this DPA does not.
4. Our obligations as processor
- Process Customer Personal Data only for the purpose of providing the Service, on your documented instructions, and as otherwise permitted by law. The Terms of Service, this DPA and your use of the Service's features constitute your instructions.
- Not sell or share Customer Personal Data, and not retain, use or disclose it for any purpose other than performing the Service. We do not combine it with personal data received from any other source except as permitted by the CCPA, and we do not use it for our own commercial purposes or to train machine-learning models. We hereby certify that we understand and will comply with these restrictions.
- Ensure that personnel with access are subject to confidentiality obligations and are trained appropriately, and limit access to those who need it.
- Implement and maintain the technical and organisational measures described in Annex B.
- Tell you without undue delay if, in our opinion, an instruction infringes Data Protection Laws, and not carry out that instruction pending resolution.
- Assist you, at your cost where the assistance is substantial, with data protection impact assessments and consultation with supervisory authorities, to the extent the assistance relates to our processing.
- On termination, delete or return Customer Personal Data as set out in section 11.
5. Sub-processors
You give general authorisation for us to engage sub-processors. The current list, with the purpose and categories of data for each, is maintained at the Sub-processor List page and is incorporated here by reference.
- We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, by written contract.
- We remain responsible to you for a sub-processor's performance of those obligations.
- We will give at least [TO BE CONFIRMED: sub-processor change notice period] notice before a new sub-processor begins processing Customer Personal Data.
- You may object on reasonable data protection grounds within that period. We will work with you in good faith to address the objection; if we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the terminated portion.
6. Security
We implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, having regard to the state of the art, the cost of implementation and the risks involved. Those measures are described in Annex B and in the Security Overview.
You are responsible for the parts of security within your control: configuring roles and permissions appropriately, managing your users' access and removing it when no longer needed, protecting credentials, and deciding what information to record in the first place.
7. Personal data breach
We will notify you without undue delay, and no later than 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Notification will be sent to your account contact.
The notification will include, to the extent then known and as further information becomes available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it and mitigate its effects. We will assist you in meeting your own notification obligations to authorities and data subjects.
Our notification is not an acknowledgement of fault or liability. We will not notify a supervisory authority or a data subject on your behalf unless you instruct us to or the law requires us to.
8. Data subject requests
The Service gives you the tools to access, correct, export and delete Customer Personal Data yourself, which will usually be the fastest route to responding to a request.
If a data subject contacts us directly about Customer Personal Data, we will not respond substantively. We will tell them to contact you, and forward the request to you where we can identify the relevant Customer. We will provide reasonable assistance if you need it. We do not delete or alter your records on the instruction of anyone other than you, because we are not in a position to verify who is entitled to ask.
9. Audit and information
On reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, we will provide information reasonably necessary to demonstrate compliance with this DPA.
Where that information is insufficient and an audit is required by Data Protection Laws, you may conduct one — at your cost, on at least 30 days' notice, during business hours, subject to confidentiality, and in a manner that does not disrupt the Service or compromise the security or confidentiality of other customers' data. We do not currently hold a SOC 2 or ISO 27001 report to offer in place of an audit; the Security Overview states our position on certifications plainly.
10. International transfers
Customer Personal Data is processed in the United States and on Cloudflare's global network. Where you transfer personal data subject to the UK or EU GDPR to us, the transfer mechanism relied upon is [TO BE CONFIRMED: SCC module 2 with UK Addendum, and/or EU-US Data Privacy Framework participation]. Where the Standard Contractual Clauses apply, Annex A serves as their Annex I and Annex B as their Annex II, and the parties select [TO BE CONFIRMED: SCC clause options — docking, governing law, supervisory authority].
11. Deletion and return
You may export Customer Personal Data at any time during the term and for at least 30 days after termination. After that period, we will delete or de-identify Customer Personal Data within [TO BE CONFIRMED: deletion window after export period], except to the extent we are required by law to retain it.
Backups expire on their own rotation schedule, so a copy may persist in encrypted backup storage briefly after deletion from the live system. It is not accessible in the ordinary course and is deleted when the backup expires.
12. Liability and term
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA takes effect when you accept the Terms of Service and continues for as long as we process Customer Personal Data.
Annex A — Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Catomni Studio platform to the Customer. |
| Duration | The term of the Terms of Service, plus the post-termination export and deletion periods. |
| Nature and purpose | Hosting, storage, retrieval, organisation, display, transmission, backup, deletion and support, for the purposes of studio management: student and family records, scheduling and enrolment, attendance and check-in, progression tracking, messaging, reporting and tuition collection. |
| Categories of data subject | The Customer's staff and instructors; parents, guardians and other family account holders; and students — who are frequently children. |
| Categories of personal data | Identity and contact details; date of birth; family and guardian relationships; enrolment, attendance and check-in records; programme, rank and milestone progression; instructor notes; billing identifiers, payment and invoice status; message content and delivery status; uploaded photographs and files; and technical, audit and log data. |
| Special category / sensitive data | Health information, where the Customer records allergy or medical notes about a student. The Customer decides whether to record any, and is responsible for the conditions for doing so. |
| Children's data | Yes. Personal data about children is a core category. The Customer is responsible for obtaining any verifiable parental consent required. |
| Frequency of transfer | Continuous, for the duration of the Service. |
| Retention | For the term, then as set out in section 11 or as instructed by the Customer. |
Annex B — Technical and organisational measures
- Encryption of personal data in transit over TLS, and encryption at rest by our infrastructure providers.
- Logical separation of each Customer's data, enforced in the application's data access layer so that every query is scoped to a single studio.
- Role-based access control, with permissions the Customer configures for its own users.
- Multi-factor authentication required for platform administrator accounts.
- Session cookies that are HTTP-only, restricted to secure transport in production, and bound to a server-side session record that can be revoked.
- Cryptographically signed check-in codes, bound to a specific student and studio so a code cannot be replayed against another.
- Secrets held in the platform provider's secret store, not in source code or configuration files.
- Least-privilege administrative access, with time-limited support sessions recorded in an audit log.
- Audit logging of significant actions on records.
- Automated bot and abuse mitigation on public forms, and a managed web application firewall at the network edge.
- Backups, retained and rotated on a defined schedule. [TO BE CONFIRMED: backup frequency, retention period and restoration testing cadence].
- A documented incident response process, including the breach notification commitment in section 7.
- Written data protection and confidentiality obligations for personnel with access.
Annex C — Sub-processors
As set out on the Sub-processor List page, incorporated by reference and maintained as the current list for the purposes of section 5.