In short
- These terms apply when a business customer puts personal data into the service, for example names or case details in uploaded documents.
- The customer is the controller of that data and we are its processor. We process it only to provide the service.
- We use the subprocessors listed on our website, give notice before adding new ones, and help with data subject requests and breaches.
- Transfers outside the EU are covered by the Standard Contractual Clauses.
Scope and roles
These Data Processing Terms (“DPA”) form part of the Terms of Service between Individual Entrepreneur Axel Elearning (“we”, the “processor”) and a customer that uses Course AI Builder for business purposes (“you”). They apply to personal data contained in your Customer Content that we process on your behalf (“Customer Personal Data”).
For Customer Personal Data you are the controller, or a processor acting for your own client, and we are your processor or sub-processor. For account, billing and usage data about you and your users, we are a controller under our Privacy Policy, and this DPA does not apply to it.
If this DPA and the Terms of Service conflict about Customer Personal Data, this DPA prevails.
Details of the processing
| Item | Description |
|---|---|
| Subject matter | Generating, storing, editing and exporting course content from your inputs |
| Duration | While your account exists, plus the deletion periods below |
| Nature of processing | Storage, text extraction, transmission to AI providers for generation, display, packaging, deletion |
| Purpose | Providing the service to you |
| Types of personal data | Any personal data you include in topics, instructions or uploaded documents, for example names, job roles, contact details or case descriptions |
| Data subjects | People mentioned in your inputs, such as your staff, clients or other individuals |
| Special categories | Not intended. Do not include them unless you have a legal ground and they are needed for the course |
Our obligations
We will:
- process Customer Personal Data only on your documented instructions, which are these terms and your use of the service, unless the law requires otherwise, in which case we will tell you unless the law prohibits it;
- make sure that anyone we authorise to process it is bound by confidentiality;
- apply the technical and organisational measures described below;
- assist you, as far as we reasonably can, in answering requests from data subjects and in meeting your obligations on security, breach notification, data protection impact assessments and prior consultation;
- notify you without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information you need to meet your own obligations;
- delete Customer Personal Data when you delete the content or close your account, and remove remaining copies from backups within 30 days, unless the law requires us to keep it; you can export your content before closing;
- make available the information necessary to demonstrate compliance with Article 28 GDPR, and allow audits through a written questionnaire once a year, or more often after a breach or at a supervisory authority’s request. Other audits are at your cost, with 30 days’ notice and under confidentiality.
Subprocessors
You give us general authorisation to engage the subprocessors listed on the subprocessors page. We impose data protection obligations on each subprocessor that are no less protective than this DPA, and remain responsible for their performance.
We will tell you about a new subprocessor at least 30 days before it starts processing Customer Personal Data, by email to the account owner and by updating the subprocessors page. If you object on reasonable data protection grounds, tell us within that period; if we cannot address the objection, you may close your account and receive a refund of the courses you have not used.
International transfers
We are established in Georgia, and some subprocessors are in other countries, including the United States. Where Customer Personal Data subject to the GDPR is transferred to us or onwards to a country without an adequacy decision, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply and are incorporated into this DPA by reference: Module Two where you are a controller, Module Three where you are a processor. For the Clauses, the annexes are the processing details and security measures in this DPA, the optional docking clause does not apply, subprocessors are authorised generally with the notice period above, and the governing law and courts are those of the EU Member State where you are established, or Ireland if you are not established in the EU. For data subject to the UK GDPR, the UK International Data Transfer Addendum applies in the same way.
Security measures
- Encryption in transit (TLS) for all access to the service and for connections to subprocessors.
- Logical separation of workspaces; every request is checked against the workspace that owns the data.
- Access to production systems limited to the people who run the service, with individual credentials, and logged.
- Passwords stored only as hashes; payment card data never processed by us.
- AI providers receive only the content each request needs, without account identifiers.
- Backups kept for 30 days with restricted access.
- Uploaded documents deleted 30 days after upload, and exported packages and course backup files 30 days after they were created.
- Exported packages contain no tracking; a package makes no network requests when a learner opens it.
Liability
Each party’s liability under this DPA is subject to the limitations in the Terms of Service, to the extent the law allows.
Contact
Write to support@courseaibuilder.com about this DPA. If you need a countersigned copy for your records, ask us and we will send one.