Data processing agreement
Version: 2026-10-02.5
Este documento está disponible en inglés. En caso de discrepancia prevalece la versión neerlandesa.
This data processing agreement is intended for schools and other organisations that use Retrieva for their pupils or staff, where we process personal data on behalf of that organisation. For regular individual accounts it is not needed: there Codea Solutions is itself the controller, see the privacy statement. This agreement applies between the organisation (“Controller”) and Codea Solutions (“Processor”) as soon as we have agreed in writing (including by email) that Retrieva is used in this way.
1. Subject and duration
The Processor processes personal data solely to provide Retrieva to the Controller and on the Controller’s documented instructions, as laid down in this agreement and the agreements about the service. The agreement lasts as long as the Processor processes personal data on behalf of the Controller.
2. Nature and purpose of the processing, data and data subjects
| Item | Description |
|---|---|
| Purpose | Letting pupils or staff study with explanations, practice questions, flashcards, tests, planner and progress overview. |
| Data subjects | Pupils, students and staff of the Controller who use an account. |
| Types of data | Name, email address, login data (password only as a hash), study content entered or uploaded by the user, photos and files of homework and tests, results, planner, usage data (activity, AI usage) and settings. No special categories of personal data are knowingly processed; the Controller instructs users not to upload them. |
| Nature | Storing, structuring, forwarding to an AI processor to generate answers, displaying, exporting, making backups and deleting. |
3. Obligations of the Processor
- Processes personal data only on documented instructions from the Controller, including for transfers, unless a law requires otherwise. If the Processor considers an instruction to infringe the GDPR, it informs the Controller immediately.
- Ensures that persons who process data are bound by confidentiality.
- Takes appropriate technical and organisational measures, see the annex.
- Assists the Controller, as far as reasonable, with data subject requests (access, rectification, erasure, portability, objection), and with security, data breach notifications, data protection impact assessments and consultation of the supervisory authority. Users can export their own data and delete their own account in the app.
- After the end of the service deletes or returns all personal data, as the Controller chooses, and deletes existing copies unless the law requires retention. Backups are encrypted, kept for no longer than 10 days (one per day) and then deleted.
- Makes available the information needed to demonstrate compliance with these obligations and cooperates with audits, reasonably, after notice and at reasonable cost.
4. Data breaches
The Processor notifies a personal data breach affecting the Controller’s data without undue delay, and in any case within 48 hours after becoming aware of it, with the information available at that moment (nature, data subjects and data concerned, likely consequences, measures taken and proposed). Notifying the supervisory authority and data subjects is the Controller’s responsibility.
5. Sub-processors
The Controller gives the Processor general authorisation to engage sub-processors. At present these are:
| Sub-processor | Purpose | Country |
|---|---|---|
| Anthropic, PBC | AI: explanations, practice questions, summaries and assessment of answers | United States |
| Replit, Inc. | Hosting of the app, the database, files and backups | United States |
| Google (Google Ireland Ltd. / Google LLC) | Google Drive for encrypted backups; email | Ireland / United States |
| OpenAI, L.L.C. | Only if photos for questions are switched on: an AI-written description of a photo, without name or email address | United States |
The Processor imposes the same obligations on sub-processors as in this agreement and remains liable for their compliance. If the Processor wants to add or replace a sub-processor it will tell the Controller at least 30 days beforehand; within that period the Controller may object in writing with reasons.
6. Transfers outside the EEA
Transfer to the United States (Anthropic, Replit, Google and OpenAI) takes place only on the basis of a valid instrument under Chapter V GDPR: the EU-US Data Privacy Framework or standard contractual clauses.
7. Liability and governing law
The liability provisions of the terms of service apply to liability, as far as the law allows. This agreement is governed by Dutch law.
8. Annex: security measures
- Encrypted connections (https) and strict security headers.
- Passwords as a hash (bcrypt); API keys entered by users encrypted (AES-256-GCM).
- Access to photos and files only for the owner; separation between accounts is tested automatically.
- Limits on login attempts; sessions expire after at most 7 days (with ‘Remember me’), otherwise after at most 24 hours.
- Daily backups, stored encrypted (AES-256-GCM) for no longer than 10 days; administrator access only where necessary; administrator actions are logged.
- No third-party scripts or fonts on the site.
- A data breach procedure and a maintained register of processing activities.
Contact for this agreement: privacy@retrieva.nl. Version 2026-10-02.5.