Data Processing Addendum

Last updated: 17 August 2026

This Addendum (“DPA”) applies where a school, university, language centre or other organisation (“Customer”) uses Listening, no kidding to teach its own students. It satisfies Article 28(3) GDPR and forms part of the Terms of Use.

Who needs this

Individual teachers on a personal subscription do not need a DPA — we are the controller and the Privacy Policy governs. An institution that decides why and how its students’ data is processed is the controller and should sign this. It costs nothing: email privacy@listeningnokidding.com for a countersigned copy.

1. Roles

The Customer is the controller and Vito Schiuma is the processorfor personal data processed under this DPA. The Customer is responsible for having a lawful basis for the processing and for giving data subjects the information the GDPR requires. We process personal data only on the Customer’s documented instructions, of which the Terms of Use and use of the platform’s features are the primary set.

If we believe an instruction breaches the GDPR or other EU or Member State law, we will tell the Customer without undue delay.

2. Subject matter of the processing

ItemDetail
Subject matterProviding an AI-assisted English listening lesson platform
DurationFor as long as the Customer’s subscription is active, plus the retention periods in clause 9
Nature and purposeHosting, storage, generation of lesson content, transcription of audio, running live classroom sessions, analytics on lesson progress
Categories of data subjectThe Customer’s teaching staff and administrators; students taking part in lessons and live sessions
Categories of personal dataNames, email addresses, role; lesson and classroom content; the name a student chooses when joining a live session, and their answers for the duration of that session
Special categoriesNone. The Customer must not submit special-category data, and the platform is not designed to hold it.

3. Our obligations

  • Process personal data only on documented instructions, including for transfers.
  • Ensure that anyone authorised to process the data is bound by an appropriate duty of confidentiality.
  • Apply the security measures set out in clause 5.
  • Respect the conditions in clause 7 for engaging another processor.
  • Assist the Customer, so far as is reasonably possible, in answering requests from data subjects exercising their rights.
  • Assist the Customer with data protection impact assessments, prior consultation, and security and breach obligations under Articles 32 to 36.
  • Delete or return personal data at the end of the service, as clause 9 provides.
  • Make available the information needed to demonstrate compliance and allow for audits, as clause 8 provides.

4. Customer obligations

  • Establish and maintain a lawful basis for the processing, including any parental consent required for pupils below the digital-consent age in the relevant Member State.
  • Give students and staff a privacy notice covering this processing.
  • Keep account credentials secure and manage who on its staff has access to student data.
  • Not submit special-category data or data about identifiable students into AI generation prompts.

5. Security (Article 32)

Technical and organisational measures currently in place:

  • Encryption of personal data in transit (TLS) and at rest.
  • Authentication through Firebase Authentication; HTTP-only, Secure, SameSite session cookies.
  • Document-level authorisation enforced both by database security rules and again in server-side code, so a compromised client cannot read another tenant’s data.
  • Per-account rate limiting on the endpoints that spend AI resources.
  • Access to production data restricted to personnel who need it.
  • Automated daily backups, with restoration tested periodically.
  • Logging of administrative access and of security-relevant events.

We may update these measures, but not in a way that materially reduces the level of security.

6. Personal data breaches

We will notify the Customer without undue delay, and in any event within 48 hoursof becoming aware of a personal data breach affecting the Customer’s data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Notifying the supervisory authority and, where required, the data subjects, is the Customer’s responsibility as controller; we will provide the information needed to do it.

7. Sub-processors

The Customer gives general authorisation for us to engage the sub-processors listed on the sub-processors page. Each is engaged under a written contract imposing data protection obligations equivalent to those in this DPA, and we remain fully liable to the Customer for their performance.

We will give at least 30 days’ notice before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees.

8. Audits

On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this DPA, including our security documentation and available third-party certifications for our infrastructure providers. Where that is insufficient, we will cooperate with an audit conducted by the Customer or an independent auditor bound by confidentiality, at reasonable times, without unreasonable disruption, and at the Customer’s cost.

9. Deletion and return

On termination, the Customer may export its data through the platform or ask us for an export. We delete the Customer’s personal data within 90 days of termination unless EU or Member State law requires us to keep it, in which case we keep only what is required and only for as long as required. Backups expire on their normal rotation, within 90 days.

Live-session data follows a different, tighter timeline of its own, independent of termination: a student’s chosen name and individual answers are deleted the moment the teacher ends the session, or automatically within 24 hoursif a session is started and never explicitly ended. Only an anonymous, per-question count survives — see section 5.2 of the Privacy Policy.

10. International transfers

Where a sub-processor processes personal data outside the EEA, the transfer is made under the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Three (processor to processor), together with any supplementary measures a transfer impact assessment identifies, or under an adequacy decision where one applies. The safeguard for each provider is named on the sub-processors page. The Clauses are incorporated into this DPA by reference and prevail over it in the event of conflict.

11. Liability, order of precedence, and signature

Liability under this DPA is subject to the limitations in the Terms of Use, except where the GDPR does not permit such a limitation. In the event of conflict, the Standard Contractual Clauses prevail, then this DPA, then the Terms of Use.

Accepting this DPA

Email privacy@listeningnokidding.com with your institution’s legal name, address and the name of the signatory. We will return a countersigned PDF of this document, with the version date shown at the top of this page.