Data-protection terms for organisations that use Examiar to process personal data. If a signed customer order conflicts with this public page, the signed order controls for that customer.
1. Application and roles
This Data Processing Addendum forms part of the Terms or a written order when Examiar processes personal data on behalf of a customer. The customer is the controller or processor with authority to appoint Examiar. Examiar is the processor or subprocessor for customer-controlled personal data.
2. Processing details
The subject matter is delivery of Examiar’s curriculum, question-bank, assessment, import, team and support functions. Processing lasts for the service term and a limited deletion period. It may include collection, storage, organisation, retrieval, transmission, backup and deletion. Data subjects may include authorised users, staff and people identified in customer content. Data may include identity, contact, role, activity and customer-submitted assessment information.
3. Documented instructions
Examiar will process customer personal data only to provide and secure the service, comply with the agreement and follow documented customer instructions, unless law requires otherwise. The customer is responsible for lawful instructions, notices, consents and data accuracy.
4. Confidentiality and security
People authorised to process customer personal data are subject to confidentiality duties. Examiar maintains safeguards appropriate to the risk, including access controls, encrypted transport, credential protection, backups, logging, patching and incident handling.
5. Subprocessors and transfers
The customer authorises the providers on the Subprocessor List. Examiar remains responsible for contractual subprocessor obligations appropriate to their work. We will provide reasonable notice of a material new subprocessor. Where required, international transfers will use a lawful transfer mechanism.
6. Assistance and incidents
Taking account of the nature of processing, Examiar will provide reasonable assistance with data-subject requests, security assessments, breach obligations and regulator enquiries. We will notify the customer without undue delay after confirming a personal-data breach affecting customer data and will provide available information needed for the customer’s response.
7. Return, deletion and audit information
On termination or written request, Examiar will return or delete customer personal data where reasonably practicable, except where law requires retention. Restricted backup copies age out through the normal retention cycle. We will make information reasonably necessary to demonstrate compliance available to the customer, subject to confidentiality, security and reasonable scope limits.
8. Contact and signed copies
For privacy questions, transfer terms or a signed organisation-specific DPA, contact privacy@examiar.com.