Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Agreement between the Customer identified in the applicable Order Form (“Customer”) and the Coly entity identified in that Order Form (“Coly”).
This DPA applies to Coly’s Processing of Customer Personal Data on Customer’s behalf in connection with the Services. Capitalized terms not defined in this DPA have the meanings given in the SaaS Subscription Agreement.
- Definitions
“Applicable Data Protection Law” means any law applicable to Coly’s Processing of Customer Personal Data under the Agreement, including, as applicable, the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the United Kingdom GDPR (“UK GDPR”), the Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”) and other applicable Canadian federal or provincial privacy laws, the California Consumer Privacy Act, as amended (“CCPA”), other applicable United States state privacy laws, and applicable Canadian privacy law.
“Authorized User” means an Individual User or Customer Personnel whom Customer authorizes to access or use the Services within the Subscription Scope.
“Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process,” “Processing,” “Processor,” and “Supervisory Authority” have the meanings given under Applicable Data Protection Law.
“Customer Personal Data” means Personal Data contained in Customer Data that Coly Processes on Customer’s behalf in providing the Services.
“Customer Personnel” means Customer’s employees, faculty members, staff members, administrators, contractors, agents, and other personnel whom Customer authorizes to access or administer the Services on Customer’s behalf.
“Individual User” means an individual who accesses or uses the Services in a personal or individual capacity under Customer’s subscription, including a student, prospective student, applicant, tenant, resident, or prospective resident.
“FERPA” means the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99.
“Subprocessor” means a third party engaged by Coly to Process Customer Personal Data on Customer’s behalf.
- Roles and Scope
As between the parties, Customer is the Controller or other entity determining the purposes and means of Processing Customer Personal Data, and Coly is the Processor or service provider Processing that data on Customer’s behalf. If Customer acts as a Processor for another Controller, Coly will act as Customer’s Subprocessor.
This DPA applies only to Customer Personal Data that Coly Processes on Customer’s behalf. It does not apply to data for which Coly independently determines the purposes and means of Processing, provided that Coly will identify any such Processing in its applicable Privacy Notice and comply with Applicable Data Protection Law.
The subject matter, duration, nature, purposes, categories of Data Subjects, and types of Customer Personal Data are described in Exhibit A. Article 28 of the GDPR requires that a controller-processor contract specify these processing details and impose particular requirements concerning instructions, confidentiality, security, subprocessors, assistance, deletion, and audit rights.
- Customer Instructions and Responsibilities
Customer instructs Coly to Process Customer Personal Data only as necessary to:
- provide, operate, configure, support, secure, and maintain the Services;
- perform Coly’s obligations and exercise its rights under the Agreement;
- prevent or address fraud, misuse, security incidents, and technical problems;
- comply with Customer’s other documented instructions consistent with the Agreement; and
- comply with applicable legal requirements.
The Agreement, including this DPA, the Order Form, Customer’s configuration and use of the Services, and any written instructions accepted by Coly, constitutes Customer’s documented instructions.
Coly will notify Customer if, in Coly’s reasonable opinion, a Customer instruction violates Applicable Data Protection Law. Coly may suspend the affected Processing until the parties resolve the issue.
Customer is responsible for:
- determining that its instructions and use of the Services comply with Applicable Data Protection Law;
- establishing an appropriate legal basis for Processing;
- providing required notices;
- obtaining required authorizations or consents, including parental or guardian consent where applicable;
- limiting Customer Personal Data to information reasonably necessary for the Services; and
- responding to Data Subjects and regulators except to the extent Coly is required to assist under this DPA.
- Processing Restrictions
Coly will Process Customer Personal Data only on Customer’s documented instructions and only for the limited and specified purposes described in the Agreement and Exhibit A, unless Processing is required by applicable law. If applicable law requires other Processing, Coly will notify Customer before Processing unless legally prohibited from doing so.
Coly will not:
- sell or share Customer Personal Data;
- use Customer Personal Data for targeted or cross-context behavioral advertising;
- retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer, except as permitted by Applicable Data Protection Law;
- retain, use, or disclose Customer Personal Data for a commercial purpose other than providing, maintaining, securing, or improving the Services as permitted by the Agreement and Applicable Data Protection Law;
- combine Customer Personal Data with Personal Data received from another customer or collected from Coly’s independent interaction with an individual, except as permitted by Applicable Data Protection Law;
- use Customer Personal Data to build an advertising profile concerning an Individual User; or
- use identifiable or pseudonymized Coly Assistant conversation data to train, fine-tune, or develop an artificial intelligence model, except with Customer’s express written authorization and subject to Applicable Data Protection Law.
Where the CCPA applies, the parties intend that Coly qualify as a “service provider” or “contractor,” as applicable. Coly will comply with applicable CCPA obligations, provide the same level of privacy protection required of Customer with respect to Customer Personal Data, notify Customer if Coly determines it can no longer meet those obligations, and permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized Processing. Current CCPA regulations require service-provider contracts to identify limited and specific business purposes and restrict selling, sharing, combining, and Processing outside the direct business relationship.
- Confidentiality
Coly will ensure that persons authorized to Process Customer Personal Data are subject to appropriate contractual or statutory confidentiality obligations and receive access only to the extent necessary to perform their responsibilities.
Coly will maintain reasonable access controls designed to restrict Customer Personal Data to authorized personnel with a legitimate need for access.
- Security
Coly will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Coly’s current technical and organizational measures are described in Exhibit B. Coly will not materially reduce the overall protection provided by those measures during the Subscription Term.
Customer acknowledges that security measures may evolve as technology, threats, and the Services change. Coly may modify the measures in Exhibit B if the modifications do not materially reduce the overall security of the Services.
- Personal Data Breaches
Coly will notify Customer without undue delay and, in any event, within forty-eight (48) hours after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
To the extent known at the time, the notice will describe:
- the nature of the Personal Data Breach;
- the categories and approximate number of affected Data Subjects and records;
- the likely consequences;
- measures taken or proposed to contain, investigate, and remediate the incident; and
- a contact for further information.
Coly may provide information in phases as it becomes available. Coly will reasonably cooperate with Customer’s investigation, risk assessment, notification, and remediation obligations.
Coly’s notice of a Personal Data Breach is not an acknowledgment of fault or liability. Customer remains responsible for determining whether notice must be provided to a regulator, Data Subject, or other person, except to the extent Applicable Data Protection Law places that obligation directly on Coly.
- Subprocessors
Customer generally authorizes Coly to engage the Subprocessors identified in Exhibit C to Process Customer Personal Data in connection with the Services.
Coly will ensure that each Subprocessor is bound by a written agreement or other legally binding terms that impose the same data-protection obligations applicable to Coly under this DPA, to the extent relevant to the Subprocessor’s Processing, including requirements to provide sufficient guarantees and implement appropriate technical and organizational measures.
Such terms may consist of the Subprocessor’s standard data-processing terms incorporated into the agreement governing Coly’s use of the Subprocessor’s services.
Coly will limit each Subprocessor’s Processing to the services performed for Coly and, to the extent required by Applicable Data Protection Law, remain liable to Customer for the Subprocessor’s performance of its data-protection obligations.
Coly will maintain and make available to Customer current information identifying its Subprocessors and the nature and location of their Processing.
Coly will provide Customer reasonable prior written notice of any intended addition or replacement of a Subprocessor that will Process Customer Personal Data, thereby giving Customer an opportunity to object before the change takes effect.
Customer may object on reasonable and documented data-protection grounds. The parties will work in good faith to address the objection. If the parties cannot resolve it, Coly may elect not to use the proposed Subprocessor for Customer, provide a commercially reasonable alternative, or permit Customer to terminate the materially affected Services and receive a prorated refund of prepaid fees for the unused portion.
- Data Subject Requests
Taking into account the nature of the Processing, Coly will reasonably assist Customer through appropriate technical and organizational measures in responding to requests by Data Subjects to exercise rights under Applicable Data Protection Law.
If Coly receives a request relating to Customer Personal Data directly from a Data Subject, Coly will notify Customer and, unless legally required, will not independently respond other than to acknowledge the request or direct the Data Subject to Customer.
Customer is responsible for verifying the requester’s identity, determining the validity of the request, and communicating the substantive response.
- Regulatory Assistance
Taking into account the nature of the Processing and information available to Coly, Coly will reasonably assist Customer with:
- security-of-processing obligations;
- Personal Data Breach investigations and notifications;
- data-protection impact assessments;
- consultations with Supervisory Authorities; and
- inquiries or investigations concerning Coly’s Processing of Customer Personal Data.
Customer will reimburse Coly’s reasonable costs for assistance that is materially beyond the ordinary operation of the Services, unless the assistance is required because Coly breached this DPA.
- Information and Audits
Coly will make available information reasonably necessary to demonstrate its compliance with this DPA.
Customer may conduct one audit during any twelve-month period on reasonable prior written notice. Additional audits may be conducted following a Personal Data Breach materially affecting Customer Personal Data or where required by a Supervisory Authority.
Audits will:
- occur during normal business hours;
- avoid unreasonable disruption to Coly’s operations;
- be subject to appropriate confidentiality and security requirements;
- not provide access to another customer’s data or confidential information; and
- use existing independent assessments, certifications, questionnaires, and documentation where reasonably sufficient.
If an onsite inspection remains reasonably necessary after review of available materials, the parties will agree on its scope, timing, duration, and security requirements. Customer is responsible for audit costs unless the audit identifies a material breach of this DPA by Coly.
- Return, Deletion, and Preservation
During the Subscription Term, Customer may access or export Customer Personal Data using functionality made available through the Services or by submitting a reasonable written request to Coly.
Upon expiration or termination of the applicable Services, Coly will, at Customer’s election, return or delete Customer Personal Data and delete existing copies, except to the extent retention is required by applicable law or a valid legal hold.
Customer must communicate its election within thirty (30) days after termination or expiration. If Customer does not do so, Coly may delete Customer Personal Data according to its standard deletion process.
Customer Personal Data may remain in encrypted backups until overwritten through Coly’s ordinary backup cycle, provided that it remains protected under this DPA and is not restored except for disaster recovery, legal compliance, or security purposes.
Upon Customer’s written legal-hold instruction identifying specific data, Coly will suspend routine deletion of that data until Customer releases the hold. Customer is responsible for the scope, duration, and legality of its preservation instruction.
- FERPA
Where Customer is an educational agency or institution subject to FERPA and Customer discloses education records to Coly under the school-official exception, Coly:
- performs institutional services or functions for which Customer would otherwise use employees;
- is under Customer’s direct control with respect to the use and maintenance of education records;
- will use personally identifiable information from education records only for the purposes for which Customer disclosed it;
- will not redisclose that information except as authorized by Customer or permitted by FERPA;
- will provide reasonable assistance to enable Customer to respond to a request to inspect or review education records; and
- will return or delete education records as provided in this DPA.
The FERPA school-official exception requires an outsourced provider to perform an institutional function, remain under the institution’s direct control regarding education records, and comply with FERPA’s use and redisclosure restrictions.
Customer is responsible for determining that its disclosure to Coly complies with FERPA, including its annual notification criteria and legitimate educational interest requirements. Customer acknowledges that information entered by Customer personnel about a student, and Coly Assistant conversation data maintained on Customer’s behalf, may constitute education records.
- Canadian Privacy Law
To the extent PIPEDA or other applicable Canadian privacy law applies, Customer remains responsible for Customer Personal Data under its control, and Coly will Process that data only to provide the Services and in accordance with Customer’s documented instructions. Coly will maintain safeguards appropriate to the sensitivity of the data, provide a level of protection comparable to that required of Customer under applicable Canadian privacy law, and reasonably assist Customer with access requests, complaints, investigations, and breach-response obligations.
- International Transfers
Coly will not transfer Customer Personal Data across national borders except as described in Exhibit A or Exhibit C and in compliance with Applicable Data Protection Law.
If Customer Personal Data protected by the GDPR is transferred to a country that has not received an applicable adequacy determination, the parties will rely on a valid transfer mechanism, including the European Commission’s then-current standard contractual clauses for international transfers, where applicable.
If Customer Personal Data protected by the UK GDPR is transferred to a country not subject to applicable United Kingdom adequacy regulations, the parties will use the applicable United Kingdom International Data Transfer Addendum or another lawful transfer mechanism.
Coly will provide information reasonably necessary for Customer to assess the transfer mechanism and will implement supplementary measures where legally required and appropriate to the Processing.
- Coly Assistant Processing
If Customer activates Coly Assistant, Customer instructs Coly to Process conversation data and related information as reasonably necessary to provide, operate, maintain, secure, support, evaluate, develop, and improve Coly Assistant and the Services, including to generate and deliver responses, maintain conversation history, provide user-directed functionality, address reported messages and technical issues, prevent misuse, evaluate response quality, and test changes to Coly Assistant’s functionality and operating instructions.
Coly may conduct such activities using Customer Personal Data only in accordance with this DPA, the Coly Assistant Schedule, Customer’s documented instructions, and Applicable Data Protection Law, and will apply appropriate access controls and safeguards based on the nature of the Processing.
Coly will not use identifiable or pseudonymized conversation data for advertising, to profile an Individual User for unrelated purposes, to assess or predict an Individual User’s mental health, emotional state, or risk of harm, or to train, fine-tune, or develop an artificial intelligence model, except with Customer’s express written authorization and as permitted by Applicable Data Protection Law.
These restrictions do not apply to data that has been anonymized so that it no longer constitutes Personal Data under Applicable Data Protection Law, which Coly may use for any lawful business purpose, including to develop, train, test, evaluate, maintain, and improve its products, services, models, and related technologies, provided that Coly does not attempt to re-identify the data or disclose it in a manner that identifies Customer or an Individual User.
The Coly Assistant Schedule governs product-specific functionality and use restrictions, and this DPA governs the Processing and protection of Personal Data.
- General Provisions
This DPA remains in effect for as long as Coly Processes Customer Personal Data.
If this DPA conflicts with another part of the Agreement concerning the Processing or protection of Personal Data, this DPA controls. An Order Form modifies this DPA only if it expressly identifies the provision being modified and states that the modification controls.
The liability limitations and exclusions in the SaaS Subscription Agreement apply to this DPA except to the extent prohibited by Applicable Data Protection Law.
The governing-law and dispute-resolution provisions of the SaaS Subscription Agreement apply to this DPA, except where Applicable Data Protection Law or an applicable transfer mechanism requires otherwise.
EXHIBIT A
Details of Processing
- Subject Matter
Coly Processes Customer Personal Data to provide, operate, configure, support, secure, and maintain the Services purchased under the applicable Order Form.
- Duration
Processing continues for the Subscription Term and afterward only as necessary to return or delete Customer Personal Data, comply with law, preserve data subject to legal hold, or maintain protected backup copies through the ordinary backup cycle.
- Nature and Purposes
Processing may include:
- collection, receipt, organization, storage, and retrieval;
- account creation and authentication;
- administration of assessments and surveys;
- generation of profiles, insights, reports, and matching results;
- roommate or shared-living matching;
- satisfaction check-ins and feedback;
- provision of staff and community insights;
- provision of customer support and training;
- configuration and integration of the Services;
- security, logging, troubleshooting, analytics, and abuse prevention;
- responding to Customer instructions and Data Subject requests;
- return, export, preservation, and deletion; and
- if activated, generation and storage of Coly Assistant conversations and end-user-initiated support notifications.
- Categories of Data Subjects
- students;
- prospective students;
- tenants, residents, and prospective residents;
- applicants;
- Customer Personnel;
- Authorized Users and Customer account contacts; and
- other individuals whose information Customer submits to the Services.
- Categories of Personal Data
- name and contact information;
- account identifiers and authentication information;
- date of birth, age, and gender identity, where provided;
- institution, housing, units, location, course, program, or organizational affiliation;
- personality, values, preference, interests, assessment, survey, and matching information;
- roommate or shared-living preferences;
- satisfaction, feedback, and outcome information;
- usage, device, network, IP address, and technical event data;
- support requests and communications;
- Customer staff notes and administrative information;
- Coly Assistant conversation content, where activated;
- information voluntarily included by an Individual User in free-text fields; and
- other data submitted by Customer consistent with the Services.
- Sensitive or Special-Category Data
Customer Personal Data may include sensitive or special-category information submitted through assessments, free-text fields, or Coly Assistant conversations. Customer is responsible for ensuring that its instructions concerning such data comply with Applicable Data Protection Law, including establishing any required lawful basis or additional processing condition and providing any required notices or obtaining any legally required consents or authorizations.
- Frequency
Processing occurs continuously or as initiated by Customer and Authorized Users during the Subscription Term.
- Customer Rights and Obligations
Customer determines the purposes of Processing, selects the Services and features to be enabled, administers Authorized Users, issues documented instructions, and exercises the rights and responsibilities stated in the Agreement.
EXHIBIT B
Technical and Organizational Measures
Coly will maintain measures appropriate to the nature and risk of the Processing, including:
Hosting and segregation: Hosting on Amazon Web Services infrastructure with logical segregation of customer workspaces.
Encryption: Encryption in transit using TLS 1.2 or higher and encryption at rest using AES-256 or an equivalent industry-standard method.
Access controls: Role-based, least-privilege access; administrative authentication controls; logging of privileged access; and periodic or event-driven access review.
Personnel: Written confidentiality obligations, security and privacy training, and documented onboarding and offboarding procedures.
Backups and resilience: Encrypted backups, point-in-time recovery where applicable, documented restoration procedures, and geographic or availability-zone redundancy appropriate to the Services.
Logging and monitoring: Logging of relevant account, application, and infrastructure activity; restricted access to logs; error monitoring; and threat monitoring.
Secure development: Version control, code review, testing, change authorization, dependency monitoring, and risk-based vulnerability remediation.
Incident response: A documented incident-response process addressing identification, containment, remediation, recovery, notification, and post-incident review.
Subprocessor management: Security and privacy review before engagement, written Processing restrictions, and ongoing oversight proportionate to risk.
Deletion: Processes designed to delete Customer Personal Data according to the applicable retention schedule and to exclude information subject to a valid legal hold.
AI-specific controls: Scoped operating instructions, data minimization, request and token limits, output safeguards, workspace-level activation controls, and restrictions against model training using conversation data.
Business continuity: Documented business-continuity and disaster-recovery procedures reviewed and tested periodically.
EXHIBIT C
Authorized Subprocessors
