Hypatia Systems Data Processing Agreement
Last Updated: July 22, 2026
1.1 This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Hypatia Systems Software License Agreement and Terms of Service between Hypatia Systems Inc. ("Hypatia", "we", "us") and the customer ("Customer", "you") (together, the "Agreement").
1.2 This DPA applies where Hypatia processes Personal Data on behalf of the Customer in connection with the Services, and where that processing is subject to European Data Protection Law.
1.3 For the purposes of this DPA, the Customer acts as the controller and Hypatia acts as the processor. Where the Customer is itself a processor acting on behalf of a third-party controller, the Customer warrants that it has the authority of that controller to enter into this DPA, and Hypatia acts as a sub-processor on equivalent terms.
1.4 Hypatia acts as a controller in respect of limited Personal Data it processes for its own purposes, including account administration, billing, security, fraud prevention, and service improvement. That processing is described in the Hypatia Privacy Policy and is not governed by this DPA.
1.5 Student data in the United States. Where Hypatia provides Services to a school, school district, or other educational institution in the United States, the processing of student personal information is governed by Section 20 of the Terms of Service and by any executed student data privacy agreement, not by this DPA. Where both apply, the student data privacy agreement controls in respect of that data.
"European Data Protection Law" means, as applicable: Regulation (EU) 2016/679 ("EU GDPR"); the EU GDPR as incorporated into the law of the United Kingdom ("UK GDPR") together with the Data Protection Act 2018; and the Swiss Federal Act on Data Protection.
"Personal Data" means personal data, as defined in European Data Protection Law, that Hypatia processes on behalf of the Customer under the Agreement.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
"SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (transfer controller to processor).
"Sub-processor" means any third party engaged by Hypatia to process Personal Data.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
Terms including "controller", "processor", "data subject", "processing", and "supervisory authority" have the meanings given in the EU GDPR.
3.1 Hypatia shall process Personal Data only on the documented instructions of the Customer, including with regard to transfers, unless required to do otherwise by law to which Hypatia is subject. Where such a legal requirement applies, Hypatia shall inform the Customer before processing, unless prohibited by that law on important grounds of public interest.
3.2 The Agreement, this DPA, and the Customer's configuration and use of the Services constitute the Customer's complete documented instructions. Additional instructions outside their scope require agreement in writing and may be subject to additional fees.
3.3 Hypatia shall inform the Customer if, in its opinion, an instruction infringes European Data Protection Law. Hypatia may suspend performance of an instruction it reasonably believes to be unlawful until it is confirmed, withdrawn, or amended.
3.4 Hypatia does not sell Personal Data, does not share Personal Data for cross-context behavioural advertising, and does not use Personal Data to train artificial intelligence or machine learning models other than those directly required to deliver user-facing features of the Services to the Customer.
3.5 The Customer is responsible for the accuracy and lawfulness of the Personal Data it provides and for having a valid legal basis for the processing, including any consent or notice required in respect of its own users.
The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of data subjects are set out in Annex I.
5.1 Hypatia shall ensure that all persons authorised to process Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and have received appropriate guidance on their responsibilities.
5.2 Hypatia shall limit access to Personal Data to those personnel who require access to perform the Agreement.
6.1 Hypatia shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Those measures are described in Annex II.
6.2 Hypatia may update the measures in Annex II from time to time, provided the updated measures do not materially decrease the overall level of security.
7.1 The Customer grants Hypatia general authorisation to engage Sub-processors, subject to this Section.
7.2 The Sub-processors engaged as at the date of this DPA are listed in Annex III. A current list is available to Customers on written request to privacy@hypatiasys.com.
7.3 Hypatia shall give the Customer at least thirty (30) days' prior written notice of the addition or replacement of any Sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees.
7.4 Hypatia shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA. Hypatia remains fully liable to the Customer for the performance of each Sub-processor's obligations.
8.1 Taking into account the nature of the processing, Hypatia shall assist the Customer by appropriate technical and organisational measures, insofar as reasonably possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights under Chapter III of the EU GDPR.
8.2 Where Hypatia receives a request directly from a data subject relating to Personal Data processed on the Customer's behalf, Hypatia shall not respond to the request itself, except to confirm receipt and direct the data subject to the Customer, and shall notify the Customer without undue delay.
8.3 Hypatia shall provide the assistance described in this Section without additional charge, save where requests are manifestly unfounded, excessive, or repetitive.
Taking into account the nature of processing and the information available to it, Hypatia shall provide reasonable assistance to the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the EU GDPR, including security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
10.1 Hypatia shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on the Customer's behalf.
10.2 The notification shall describe, to the extent known at the time and supplemented as further information becomes available: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and the name and contact details of a point of contact at Hypatia.
10.3 Hypatia shall take reasonable steps to contain, investigate, and remediate the breach, and shall document the facts, effects, and remedial action taken.
10.4 Hypatia's notification is not, and shall not be construed as, an acknowledgement of fault or liability.
11.1 On termination or expiry of the Agreement, and at the Customer's choice, Hypatia shall delete or return all Personal Data processed on the Customer's behalf, and delete existing copies, within ninety (90) days, unless retention is required by law.
11.2 Hypatia shall certify deletion in writing on the Customer's request.
11.3 Where deletion is not immediately possible because Personal Data is held in backup or archive media, Hypatia shall securely isolate the data, cease active processing, and delete it on its ordinary backup cycle.
11.4 Operational and error logs are retained for a maximum of thirty-six (36) months, as described in the Privacy Policy. Where an individual account is deleted, Hypatia additionally runs an automated process to remove that user's email address from existing logs.
12.1 Hypatia shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 of the EU GDPR.
12.2 Hypatia shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to the following: audits shall be limited to once per twelve-month period unless required by a supervisory authority or following a Personal Data Breach; the Customer shall give at least thirty (30) days' prior written notice; audits shall occur during normal business hours, shall not unreasonably disrupt Hypatia's operations, and shall be subject to confidentiality obligations; and the Customer shall bear its own costs and reimburse Hypatia's reasonable costs for audits beyond the annual allowance.
12.3 Hypatia may satisfy an audit request by providing a current third-party certification, audit report, or completed security questionnaire where these reasonably address the Customer's request.
13.1 Where Personal Data is stored. Personal Data processed through the Services is stored on infrastructure located in the United States, operated by Amazon Web Services (region us-west-2, Oregon). Hypatia personnel located in Canada, and Sub-processor personnel in other locations, may access Personal Data for the purposes of providing, supporting, securing and maintaining the Services.
13.2 Standard Contractual Clauses. Where Personal Data subject to European Data Protection Law is transferred to Hypatia, the SCCs are incorporated into this DPA by reference and apply to that transfer, as completed in Annex IV. The SCCs apply whether or not an adequacy decision would also cover the transfer.
13.3 United Kingdom. For transfers subject to the UK GDPR, the SCCs apply as modified by the UK Addendum, which is incorporated by reference.
13.4 Switzerland. For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, references to Member State courts read as references to Swiss courts, and the Swiss Federal Data Protection and Information Commissioner treated as the competent supervisory authority.
13.5 Onward transfers. Where Personal Data is transferred onward to a Sub-processor, Hypatia shall ensure that the transfer is subject to an appropriate safeguard, being the Sub-processor's participation in the EU–US Data Privacy Framework and, as applicable, its UK Extension or Swiss–US framework, or standard contractual clauses concluded with that Sub-processor.
13.6 Government access. Hypatia shall notify the Customer if it receives a legally binding request from a public authority for disclosure of Personal Data, unless prohibited by law. Where prohibited, Hypatia shall use reasonable efforts to obtain a waiver of the prohibition. Hypatia shall challenge requests it considers unlawful and shall provide the minimum amount of information permissible when responding.
13.7 Transfer impact. Hypatia shall notify the Customer if it becomes aware that laws applicable to it or a Sub-processor prevent it from fulfilling its obligations under this Section, and shall provide the Customer with information reasonably required for any transfer impact assessment the Customer is required to carry out.
14.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, including the aggregate caps and the enhanced cap applicable to breaches of obligations relating to student data or personal information.
14.2 Section 14.1 does not limit either party's liability to a data subject under the third-party beneficiary rights in the SCCs.
15.1 In the event of conflict, the following order applies: (a) the SCCs; (b) this DPA; (c) the Agreement.
15.2 Where a student data privacy agreement has been executed in respect of United States student data, that agreement controls over this DPA in respect of that data.
This DPA takes effect on the effective date of the Agreement and continues until Hypatia ceases all processing of Personal Data on the Customer's behalf. Sections 5, 10, 11, 12, 14 and 15 survive termination.
17.1 This DPA is governed by the law governing the Agreement, except that the law applicable to the SCCs is determined in accordance with Annex IV.
17.2 Nothing in this DPA restricts a data subject's rights, or a supervisory authority's powers, under European Data Protection Law.
Data protection enquiries: privacy@hypatiasys.com
Hypatia Systems Inc. 1764 Bowman Ave Coquitlam, British Columbia V3J 6C8 Canada
Data exporter (controller): the Customer, as identified in the Agreement or applicable order form. Contact details as provided by the Customer. Role: controller.
Data importer (processor): Hypatia Systems Inc., 1764 Bowman Ave, Coquitlam, British Columbia V3J 6C8, Canada. Contact: privacy@hypatiasys.com. Activities relevant to the transfer: provision of Hypatia Create and Hypatia Teach, software for creating, editing and sharing mathematical content, delivered through the Hypatia website, the Google Workspace Marketplace, Microsoft Office add-ins, and the Canva app. Role: processor.
Categories of data subjects
Categories of Personal Data
Service and licence type | Personal Data processed |
Hypatia Create — Google site licence | One-way cryptographic hash of email address; pseudonymous usage information recorded under a randomly generated identifier. No name, IP address or location. |
Hypatia Create — individual and group licences; Microsoft and Canva versions | Email address; name as provided by the user; hashed password or third-party sign-in provider identifier; most recent IP address; approximate location derived from IP address (city or region level); usage information associated with the account. |
Hypatia Teach | Student name; school-issued email address; class or course roster membership; student work product submitted through the Service; approximate location derived from IP address. |
All Services | Support correspondence; operational and error log data, which may include IP address, device and browser information, and error reports. |
Sensitive data
None. The Agreement prohibits the Customer from submitting special categories of Personal Data except as expressly agreed in writing.
Data relating to children
Where the Customer is an educational institution, the Personal Data may relate to children. The Customer is responsible for obtaining any consent required under applicable law.
Frequency of the transfer
Continuous, for the duration of the Agreement.
Nature and purpose of the processing
Hosting, storage, transmission, display and retrieval of Customer content; authentication and account management; provision of technical support; security monitoring and fraud prevention; generation of aggregated and pseudonymous usage statistics; and such other processing as is necessary to provide the Services.
Period for which Personal Data will be retained
For the term of the Agreement, plus the deletion period in Section 11 and the log-retention period in Section 11.4.
Transfers to Sub-processors
Sub-processors process Personal Data for the purposes, and for the durations, described in Annex III.
The supervisory authority of the Member State in which the Customer is established, or, where the Customer is not established in the EEA, the supervisory authority of the Member State in which the Customer's EU representative is established.
Encryption and data protection
Access control
Infrastructure
Data minimisation and pseudonymisation
Logging and monitoring
Backup and recovery
Secure development and vulnerability management
Retention and deletion
Measures applying to Sub-processors
Sub-processor | Purpose | Personal Data accessed | Processing location |
Amazon Web Services, Inc. | Cloud hosting, application infrastructure and data storage | All Personal Data processed through the Services | United States — us-west-2 (Oregon) |
Cloudflare, Inc. | Content delivery, edge protection, and IP-based approximate location | IP addresses, request metadata | United States and global edge network |
Stripe, Inc. | Payment and subscription processing | Payment instrument data, billing contact details | United States |
Zoho Corporation | Business email | Contact details and correspondence sent to Hypatia | United States; support personnel may access from India |
A current list is available to Customers on written request to privacy@hypatiasys.com. Changes are notified in accordance with Section 7.3.
The standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this DPA and completed as follows:
Element | Selection |
Module | Module Two — transfer controller to processor |
Clause 7 — docking clause | Included |
Clause 9 — use of sub-processors | Option 2, general written authorisation, with the notice period in Section 7.3 of this DPA |
Clause 11(a) — independent dispute resolution | Optional language not included |
Clause 13 — supervisory authority | As identified in Annex I.C |
Clause 17 — governing law | Option 1, the law of the Member State in which the Customer is established. Where the Customer is not established in an EU Member State, the law of Ireland. |
Clause 18(b) — choice of forum | The courts of the Member State identified in Clause 17 |
SCC Annex I.A — list of parties | Annex I.A of this DPA |
SCC Annex I.B — description of transfer | Annex I.B of this DPA |
SCC Annex I.C — competent supervisory authority | Annex I.C of this DPA |
SCC Annex II — technical and organisational measures | Annex II of this DPA |
SCC Annex III — list of sub-processors | Annex III of this DPA |
For transfers subject to the UK GDPR, the UK Addendum applies, with Table 1 completed by reference to Annex I.A of this DPA, Table 2 selecting the SCCs as completed above, Table 3 completed by reference to Annexes I, II and III of this DPA, and Table 4 specifying that neither party may end the Addendum as set out in Section 19 of the Addendum.
The full text of the SCCs is published by the European Commission and is available at: https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en
The full text of the UK Addendum is published by the Information Commissioner's Office and is available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-data-transfer-agreement-and-guidance/
Where a Customer requires a signed copy of the SCCs, Hypatia will execute them on request. Contact privacy@hypatiasys.com.