Scope: how DevAcademia satisfies the EU General Data Protection Regulation (Regulation (EU) 2016/679), and the UK GDPR, when providing services to institutions in the EU, EEA, and UK.
Audience: data-protection officers, EU/UK institution legal counsel, and security auditors performing vendor due diligence.
About this document. This is a transparent description of
how DevAcademia is built to meet its GDPR processor obligations
and support every data-subject right — what we collect, what we
preserve, and what we do with data. It is reviewed periodically
and updated as our services and applicable law evolve. The
specific processor terms are set out in the Data Processing
Agreement entered into with each institution.
#Executive summary
When engaged by an institution, DevAcademia is designed to act as a data processor under Article 4(8), processing personal data only on the documented instructions of that institution, which is the data controller. DevAcademia provides an Article 28 Data Processing Agreement (DPA) to every institution it works with and supports the full set of data-subject rights directly in the product.
#What GDPR protects
Personal data (Article 4(1)): any information relating to an identified or identifiable person. For DevAcademia this includes:
- User account data (name, email, institution membership)
- Coursework metadata (submissions, attempts, grades)
- Communications data (notifications, feedback)
- Audit metadata (who did what, when)
- Usage/behavioural data (login times, usage patterns) —
minimised by design
Special categories (Article 9) are NOT processed. DevAcademia does not process health data, biometric identifiers, or data revealing racial or ethnic origin, political opinions, religious beliefs, or sexual orientation. Any future change here would require a fresh assessment, an updated DPA, and explicit consent.
Children (Article 8). DevAcademia does not process the personal data of children below the applicable member-state digital-consent age without parental consent obtained by the subscribing institution. Institutions using DevAcademia with under-age learners are contractually responsible, as controllers, for securing that consent, and attest to it in the product.
#DevAcademia's role and lawful basis
DevAcademia acts as a processor, not a controller, and does not decide the purposes of processing on its own account. Every institution DPA:
- Names DevAcademia as processor under Article 28.
- Sets out the documented instructions for processing.
- Prohibits processing for any other purpose.
- Requires compliance with the Article 5 principles: lawfulness,
fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
The lawful basis for processing is the institution's contract (Article 6(1)(b) and Article 28). DevAcademia does not process personal data for advertising, resale, or profiling, and does not use personal data to train external AI models.
#Data-subject rights on the platform
DevAcademia supports the following rights directly in the product, so an institution can honor a data subject's request without a custom engineering effort. Institutions remain the controller and make the final decision on each request.
| Right | Article | How it works on DevAcademia |
|---|---|---|
| Access | Art. 15 | Signed-in users can download a machine-readable copy of their own data from their dashboard. |
| Data portability | Art. 20 | The same export is a structured, commonly-used, machine-readable format the subject can hand to another provider. |
| Rectification | Art. 16 | Users can file a request to correct inaccurate records; the institution reviews and resolves it. |
| Erasure ("right to be forgotten") | Art. 17 | Users can request erasure of their data; the institution reviews and, unless a legal exception applies, schedules deletion. |
| Restriction of processing | Art. 18 | When filing a rectification request, a user can also ask that the disputed data be restricted while the request is pending. |
| Objection | Art. 21 | Objections are handled by the institution as controller; DevAcademia provides the tools to give effect to the decision. |
| Not to be subject to solely-automated decisions | Art. 22 | Grading and scoring always allow human review (instructor override and a grade-dispute path), so no decision producing legal or similarly significant effects is made on a solely-automated basis. |
Every rights request and its resolution is recorded in the institution's compliance audit trail. Where a statutory deadline applies, the platform surfaces a countdown to the reviewing administrator. Access requests return in seconds — well within the one-month Article 12(3) response window.
#Security of processing (Article 32)
- Data is encrypted in transit (TLS) and at rest (provider-managed,
block-level encryption on our hosted database and backups).
- Access is gated by role and institution membership; one
institution's data is never visible to another.
- Sensitive integration secrets are additionally encrypted at the
application layer, with keys rotated at least annually.
- The platform includes protections against common web attacks and
applies rate limits to sensitive operations.
- Every administrative action is recorded in an append-only,
tamper-evident audit trail.
#International data transfers (Articles 44–49)
Some of DevAcademia's sub-processors are located in the United States and some in the EU. Transfers to the US rely on the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback. EU-region processing is available on request for institutions that require their data to stay within the EU/EEA. Each sub-processor's transfer mechanism is listed in the public sub-processor list.
#Records, assessments, and accountability
- Records of processing (Article 30): DevAcademia maintains a
processor register of its processing activities and makes it available to a supervisory authority on request.
- Data Protection Impact Assessments (Article 35): a DPIA is
the controller's responsibility. DevAcademia provides the technical detail an institution needs to complete its own DPIA under Article 28(3)(g).
- Cookies / e-Privacy: DevAcademia uses only strictly-necessary
cookies (for signing in and keeping you signed in). It sets no advertising, analytics, or tracking cookies, so no consent banner is required.
#Breach notification (Articles 33 and 34)
DevAcademia notifies an affected institution within 72 hours of confirming an unauthorized disclosure and provides the information the institution needs to meet its own Article 33 (supervisory- authority) and Article 34 (data-subject) obligations. DevAcademia does not notify a supervisory authority on the institution's behalf — that decision belongs to the controller. Full details are in the incident & breach notification policy, which covers the GDPR alignment for EU/EEA/UK institutions.
#Data protection officer and contact
DevAcademia's security lead is the accountable point of contact for data-protection matters, and a formal DPO designation is kept under review as the platform grows and as member-state law requires. Data-protection questions, DPA requests, and rights requests that need DevAcademia's help go to compliance@devacademia.com.
#Change history
| Date | Change |
|---|---|
| 2026-07-12 | Initial public version. |