Trust
Data Processing Addendum
Every institutional customer enters into a Data Processing Addendum alongside the Terms of Service. Onetap acts as Data Processor; the institution is the Data Fiduciary.
The DPA is referenced in section B.11 of the Terms of Service and forms part of them once entered into. It applies to all institutional use of the Service; there is no direct-to-consumer arrangement to which it would not apply.
What it covers
| Scope and purposes of processing | What data is processed, for what, and for how long. |
| Instructions and obligations as Processor | Onetap processes only on the institution's documented instructions. |
| The institution's consent warranty | The institution warrants it has obtained verifiable parental consent and that its enrolment records are accurate. |
| Sub-processor approval and change notice | At least 30 days' notice before any addition or replacement, with a right to object. |
| Audit rights | The institution's right to verify compliance. |
| Incident notification | Aligned with section A.12 of the Privacy Policy — Board notification within 72 hours, and notice to the institution without undue delay. |
| Return and deletion after termination | Aligned with section B.17 — 30 days to export, then deletion from production systems. |
Requesting the current form
The executable form is issued on request, so that the copy you sign is the current one rather than whatever a page happened to be serving. Write to legal@onetaplabs.com with your institution’s name and we will send it.
Questions about how data is processed, rather than about the agreement itself, go to privacy@onetaplabs.com. The current list of sub-processors is at /trust/sub-processors.