Legal

Legal, Compliance & Regulatory Framework

GBSI operates with full transparency across all jurisdictions. Our complete legal documentation — governing platform usage, data protection, security, and compliance — is published here in its entirety.

This page contains the official legal text migrated from the GBSI legal documentation. The text has been preserved for completeness and formatted for improved readability.Source: https://corporate.lutinx.com/dpa/

Data Processing Addendum (DPA)

Last updated: January 30, 2026

This Data Processing Addendum ("DPA") incorporates by reference the rules between Lutin Technologies Ltd. ("LutinX") and Client, or any other agreement between Client and LutinX governing when Personal Data is transferred between LutinX and Client. This DPA is an agreement between the Client and LutinX. Unless otherwise defined in this DPA or in the Agreement, all capitalized terms used in this DPA will have the meanings given to them in the Agreement and this DPA. In the event of a conflict of terms, this DPA shall prevail.

1. Definitions

a. "Applicable Data Protection Laws" means all data protection, privacy, and data security laws applicable to the processing of personal data, including but not limited to, GDPR; the United Kingdom Data Protection Act 2018 ("UK GDPR"); the Swiss Federal Act on Data Protection Act ("FADP"); the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100-.199 ("CCPA"); or Family Educational Rights and Privacy Act ("FERPA").

b. "Client Data" means the data, including Personal Data, that is uploaded to the LutinX Services by the Client. Client Data shall not include Earner Data.

c. "Connected Earner" means an Earner that has consented to share their Connected Earner Data with the Client.

d. "Connected Earner Data" means the information, including but not limited to Personal Data, from a Connected Earner's LutinX account that the Connected Earner consents to share with the Client.

e. "Controller" means the entity that determines the purposes and means of the Processing of Personal Data.

f. "LutinX Information Security Standards" means the security standards attached to the Agreement, or if none are attached to the Agreement, attached to this DPA as Annex II.

g. "Earner Data" means the data of an Earner that is processed by LutinX according to an agreement between LutinX and that Earner.

h. "EEA" means the European Economic Area.

i. "GDPR" means Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

j. "Processing" has the meaning given to it in the GDPR, and "process", "processes", and "processed" will be interpreted accordingly.

k. "Processor" means the entity which processes Personal Data on behalf of the Controller.

l. "Security Incident" — a failure of LutinX's adherence to Annex II security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Client Data.

m. "Standard Contractual Clauses" or "SCC" means the Appendix to the European Commission Implementing Decision ((EU) 2021/914 of 4 June 2021) on Standard Contractual Clauses for the transfer of personal data to third countries under Regulation (EU) 2016/679 of the European Parliament and of the Council.

n. "UK Addendum" means the 'Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament under s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses'.

2. Data Processing

a. Scope and Roles. This DPA applies to the transfer of Personal Data between LutinX and Client.

b. Family Educational Rights and Privacy Act ("FERPA"). To the extent FERPA is applicable, LutinX agrees to comply with all applicable federal and state laws related to the protection and privacy of student records, including, but not limited to, FERPA. LutinX will implement safeguards that: (a) ensure the security and confidentiality of Client Data; (b) protect against any anticipated threats or hazards to the security or integrity of such information; and (c) protect against unauthorized access to or use of such information, which could result in substantial harm or inconvenience to any students. If LutinX subcontracts with a third party for any of the services that it is required to undertake in furtherance of this Agreement, LutinX will take reasonable steps to verify that such third parties implement practices that protect Client Data.

c. Details of Data Processing.

  • i. Subject matter: The subject matter of the data processing under this DPA is personally identifiable Client Data or Earner Data.
  • ii. Duration: As between LutinX and Client, the duration of the data processing under this DPA is for the Term of the Agreement.
  • iii. Purpose: The purpose of the data processing under this DPA is the provision of the Services.
  • iv. Nature of the processing: LutinX will provide a platform for the Client to create, manage, issue, and use Credentials.
  • v. Categories of Personal Data: Client Data uploaded to the Services under Client accounts on LutinX or Earner Data made available to Client according to the consent of the applicable Earner.
  • vi. Categories of data subjects: The data subjects may include Earners or Client's customers, employees, end-users, and other individuals that are issued Credentials by Client.
  • vii. Location: LutinX shall store data in Europe.

d. Storage in the United States. Notwithstanding anything to the contrary in this Agreement, the Parties acknowledge that LutinX can store Personal Data, including Client Data, in the United States, and the storage by LutinX of Personal Data in the United States shall not be deemed a violation of this Section or create a right of action under this Agreement.

e. Storage in Europe. LutinX stores the Personal Data of European Citizens in Germany and the European Union.

f. Compliance with Applicable Data Protection Laws. The Parties represent that (a) the Connected Earner Data shall be lawfully collected and transferred by Applicable Data Protection Laws (as defined in the DPA); and (b) the Parties have, and shall maintain, the systems and processes in place to ensure compliance with the terms of the Agreement.

g. Cooperation between the Parties. The Parties will assist each other to comply with requests or complaints of data subjects or supervisory authorities regarding compliance with Applicable Data Protection Laws about Connected Earner Data. The Parties will notify each other of any requests, inquiries, monitoring activities, and similar measures undertaken by supervisory authorities regarding the handling of Personal Data under this DPA.

3. Client Instructions

The parties agree that this DPA and the Agreement constitute the Client's documented instructions regarding LutinX's processing of Client Data ("Documented Instructions"). LutinX will process Client Data only by Documented Instructions. Client shall obtain all consents required by any Applicable Data Protection Law from Earners for LutinX to lawfully store, transfer, and process Personal Data provided by Client to LutinX according to the Agreement. Additional instructions outside the scope of the Documented Instructions (if any) require prior written agreement between LutinX and Client, including agreement on any additional fees payable by Client to LutinX for carrying out such instructions. The client is entitled to terminate this DPA and the Agreement if LutinX declines to follow instructions requested by the Client that are outside the scope of, or changed from, those given or agreed to be given in this DPA.

4. Confidentiality of Client Data

LutinX will not access or use, or disclose to any third party, any Client Data, except, in each case, as necessary to maintain under the Agreement, or to comply with the law or a valid and binding order of a governmental body (such as a subpoena or court order). If a governmental body sends LutinX a demand for Client Data, LutinX will attempt to redirect the governmental body to request that data directly from the Client. As part of this effort, LutinX may provide the Client's basic contact information to the government body. If compelled to disclose Client Data to a government body, then LutinX will give Client reasonable notice of the demand to allow Client to seek a protective order or other appropriate remedy unless LutinX is legally prohibited from doing so.

5. Confidentiality Obligations of LutinX Personnel

LutinX restricts its personnel from processing Client Data without authorization by LutinX. LutinX shall impose appropriate contractual obligations upon its personnel, including relevant obligations regarding confidentiality, data protection, and data security.

6. Security of Data Processing

LutinX has implemented and will maintain the technical and organizational measures for the Services as set forth in the LutinX Information Security Standards, attached hereto as Annex II to the SCC.

7. Sub-processing

a. Authorized Sub-processors. Client agrees that LutinX may use sub-processors to fulfill its contractual obligations under this DPA or to provide certain services on its behalf. The LutinX website lists sub-processors that are currently engaged by LutinX to process Client Data on behalf of the Client. At least 30 days before LutinX engages any new sub-processor to carry out processing activities on Client Data on behalf of Client, LutinX will email notice to the notice email set forth on the Order Form. If Client reasonably objects to a new sub-processor and such objection cannot be satisfactorily resolved, the Client may terminate the Agreement with respect to those Services which cannot be provided by LutinX without the use of the objected-to new sub-processor by providing written notice to LutinX.

b. Sub-processor Obligations. LutinX will impose data protection terms on any sub-processor it appoints that require the sub-processor to protect the Client Data to the standard required by Applicable Data Protection Laws. LutinX will remain responsible for each sub-processor's compliance with the obligations of this DPA and for any acts or omissions of such sub-processor that cause LutinX to breach any of its obligations under this DPA.

8. Data Subject Requests

LutinX will provide reasonable cooperation to assist Client in responding to requests from data subjects exercising their rights under Applicable Data Protection Laws. If LutinX receives a request directly from a data subject relating to Client Data, LutinX will promptly notify the Client and, to the extent permissible, will not respond to such request without the Client's prior consent.

9. Data Breach

LutinX will notify Client without undue delay and in any event, within seventy-two (72) hours after LutinX becomes aware of a Security Incident. LutinX will provide Client with all information related to the Security Incident reasonably requested by Client to the extent that such information is available to LutinX and does not otherwise compromise security or other data subject interests. LutinX will take reasonable steps to mitigate the effects of the Security Incident.

10. Data Protection Impact Assessment

Upon Client's request, LutinX will provide Client with reasonable cooperation and assistance needed to fulfill Client's obligation under the GDPR to carry out a data protection impact assessment related to Client's use of the Services, to the extent Client does not otherwise have access to the relevant information.

11. Return and Deletion of Data

Upon termination of the Agreement for any reason or expiration of its term, LutinX will, at the choice of Client, delete or return all Client Data in LutinX's possession or control. The foregoing obligation will not apply to the extent that LutinX is required by applicable law to retain some or all of the Client Data. In that case, LutinX will inform Client of any retention requirements that are applicable.

12. Standard Contractual Clauses

To the extent Client Data is transferred from the EEA, the United Kingdom, or Switzerland to countries which do not ensure an adequate level of data protection within the meaning of applicable data protection laws, LutinX will enter into the Standard Contractual Clauses or UK Addendum (as applicable) with the Client. If the SCCs and/or the UK Addendum apply, the Parties agree that such SCCs and/or UK Addendum are hereby incorporated into this DPA by reference.

Contact

For DPA inquiries, execution of individual DPAs, or data protection questions:

Company: Lutin Technologies Ltd.
Email: legal@lutinx.com
DPO: dpo@lutinx.com
Subject: "DPA / Data Processing Request"

Legal Department

For questions related to this document, contact our legal team.

Contact Legal