Data Processing Agreement
Last updated: 27/08/2026
This Data Processing Agreement forms part of the Clasbi Terms of Service. It governs Clasbi's processing of personal data on the center's behalf under Article 28 of the GDPR.
1. Roles of the parties
The contracting center is the controller of personal data that it or its users enter into Clasbi. Clasbi is the processor for that data. Each party remains responsible for the duties that apply to its role under Regulation (EU) 2016/679 and applicable Spanish data protection law.
2. Subject matter, duration, and data categories
The processing covers hosting, organizing, consulting, transmitting, backing up, and otherwise handling data needed to provide Clasbi during the service term and the deletion period. It may include identification, contact, academic, attendance, schedule, enrollment, payment-status, communication, support, document, device, and technical-log data concerning students, families, teachers, staff, prospects, and other people managed by the center.
3. Documented instructions
Clasbi processes center data only on documented instructions contained in the service configuration, these documents, support requests, and lawful written directions from authorized center representatives. Clasbi will notify the center if an instruction appears to breach data protection law, unless the law prohibits that notice.
4. Confidentiality and personnel
Clasbi limits access to people who need it to provide or secure the service. Those people are bound by confidentiality and receive access appropriate to their functions. The center is responsible for assigning suitable roles to its own users.
5. Security measures
Clasbi applies technical and organizational measures appropriate to the risk, including access control, authentication, tenant isolation, encrypted transport, managed infrastructure, backups where applicable, logging, dependency and vulnerability management, and procedures for incidents and data restoration. Measures may evolve without reducing the overall level of protection.
6. Subprocessors
The center gives general authorization for the providers identified in the current Subprocessor List. This authorization does not cover providers that process data as independent controllers. Clasbi will impose on each subprocessor data-protection obligations equivalent to those in this agreement. If a subprocessor fails to meet those obligations, Clasbi remains fully liable to the center for the performance of that subprocessor's data-protection obligations under Article 28(4) GDPR. Clasbi will update the list before adding or replacing a subprocessor that materially affects processing. The center may object on reasonable data-protection grounds by contacting support without undue delay. Providers selected independently by the center are not Clasbi subprocessors merely because the service includes a link or integration.
7. International transfers
Clasbi selects European processing regions where available. If a provider processes data outside the European Economic Area, Clasbi relies on a valid transfer mechanism, such as an adequacy decision, the European Commission's standard contractual clauses, or another mechanism allowed by law.
8. Assistance to the center
Taking into account the nature of the processing and available information, Clasbi will provide reasonable assistance with data-subject requests, security, impact assessments, prior consultations, and evidence needed for the center to meet its obligations. The center remains responsible for deciding and responding to requests concerning records it controls.
9. Personal-data incidents
Clasbi will notify the center without undue delay after becoming aware of a personal-data breach affecting center data. The notice will contain the information reasonably available at that time and will be updated as the investigation progresses. This notice does not by itself admit fault or liability.
10. Information and audits
Clasbi will make available information reasonably necessary to show compliance with this agreement. If that information is not sufficient, the center may request a proportionate audit subject to confidentiality, reasonable advance notice, security limits, and measures that avoid disruption or exposure of other customers' data.
11. Return and deletion
At the center's choice and subject to the service features, Clasbi will return or delete center personal data after the service ends, unless applicable law requires retention. Data in temporary backups may remain until the normal backup cycle expires, protected and unavailable for ordinary use. Clasbi does not change or delete center-controlled records in response to an individual request without the center's instruction or another valid legal duty.
12. Term and precedence
This agreement forms part of the Terms of Service and applies while Clasbi processes personal data on the center's behalf. For data-protection matters, it prevails over any conflicting provision of the Terms of Service.
Related documents
Contact
For data-processing questions, email support@clasbi.com.