Data Processing Addendum
Last updated: October 6, 2026
For business customers
If you use Course Parse for a company, school, university or other organisation, and you put personal data of other people into it (for example your students' names and work), this addendum applies to you. It forms part of the Terms of Service from the moment you accept them. For a countersigned copy, email support@courseparse.com with your organisation's legal name and address and we will send one.
1. Roles
For personal data that you or your users submit to the Service on your behalf, you are the controller (or a processor acting for your own customer) and Course Parse, run by Mustafa Rasheed, is your processor. For our own account, billing, security and analytics data about you, we are a controller, as described in our Privacy Policy.
2. What we process and why
We process the documents, text, questions, answers and account details you submit, only to provide the Service as described in the Terms and as you instruct through your use of it. The types of data subject are your instructors, students and other users; the data is whatever they choose to submit. We expect no special-category data and ask you not to submit any.
3. Our commitments
- We process personal data only on your documented instructions, which are the Terms, this addendum and your use of the Service. If we think an instruction breaks the law we will tell you.
- People who can access the data are bound by confidentiality.
- We do not sell the data, and we do not use your content to train AI models. We will not do so without your explicit, separate consent.
- We keep the technical and organisational measures in section 6 in place.
- We help you answer requests from individuals about their data. The Service has self-service tools to export and to delete an account, and we will do the rest on request.
- We help you with security, breach notification, impact assessments and consultations with regulators, as far as the information we hold allows.
4. Sub-processors
You authorise the sub-processors on our sub-processor list. We bind each of them to data protection terms no less protective than these. We give customers on this addendum at least 30 days' notice by email before adding or replacing one. If you object on reasonable data protection grounds and we cannot accommodate it, you may end your subscription and we will refund the unused part of the current period.
5. International transfers
Data is stored in India and the United States and may be processed in the European Union, as listed on the sub-processor page. Where the law requires a transfer mechanism, the Standard Contractual Clauses approved by the European Commission (Module 2, controller to processor, or Module 3 where you are a processor) and, for the UK, the UK Addendum to them, are incorporated into this addendum by reference, with your contact details and ours as the parties, the Irish courts and law selected for the clauses where the EU version applies, and the technical measures in section 6 as the annex.
6. Security measures
- Encrypted connections (HTTPS) for all traffic to the Service.
- Our database and file-storage providers encrypt stored data at rest.
- Row-level access rules in the database so one account cannot read another's data, plus server-side checks on every request.
- Passwords are hashed by our authentication provider and never stored or seen by us in plain text.
- Rate limiting on sign-in, uploads, exports and other sensitive actions.
- Access to production systems limited to the people who need it.
- Error monitoring configured not to collect personal data by default.
We do not currently hold a SOC 2 report or ISO 27001 certificate. We will not describe the Service as certified or audited unless and until that is true.
7. Personal data breaches
We will tell you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data, with what we know about what happened, the data involved and what we are doing about it.
8. Return and deletion
While your account is active you can download a copy of your data from Settings. When you delete the account, or ask us to, we delete the data from live systems straight away. Copies held in provider backups expire as those backups roll over, and we keep only what the law requires us to keep.
9. Audits
On written request we will give you the information reasonably needed to show we meet this addendum. An on-site audit is available only where a regulator requires it or where we have suffered a breach of your data, with reasonable notice and at your cost.
10. General
This addendum lasts as long as we process data for you. If it conflicts with the Terms on the handling of personal data, this addendum wins. Liability under it is subject to the limits in the Terms, to the extent the law allows.