Retrieva Back to the site

Data processing agreement

Version: 2026-10-02.5

Este documento está disponible en inglés. En caso de discrepancia prevalece la versión neerlandesa.

This data processing agreement is intended for schools and other organisations that use Retrieva for their pupils or staff, where we process personal data on behalf of that organisation. For regular individual accounts it is not needed: there Codea Solutions is itself the controller, see the privacy statement. This agreement applies between the organisation (“Controller”) and Codea Solutions (“Processor”) as soon as we have agreed in writing (including by email) that Retrieva is used in this way.

1. Subject and duration

The Processor processes personal data solely to provide Retrieva to the Controller and on the Controller’s documented instructions, as laid down in this agreement and the agreements about the service. The agreement lasts as long as the Processor processes personal data on behalf of the Controller.

2. Nature and purpose of the processing, data and data subjects

ItemDescription
PurposeLetting pupils or staff study with explanations, practice questions, flashcards, tests, planner and progress overview.
Data subjectsPupils, students and staff of the Controller who use an account.
Types of dataName, email address, login data (password only as a hash), study content entered or uploaded by the user, photos and files of homework and tests, results, planner, usage data (activity, AI usage) and settings. No special categories of personal data are knowingly processed; the Controller instructs users not to upload them.
NatureStoring, structuring, forwarding to an AI processor to generate answers, displaying, exporting, making backups and deleting.

3. Obligations of the Processor

  • Processes personal data only on documented instructions from the Controller, including for transfers, unless a law requires otherwise. If the Processor considers an instruction to infringe the GDPR, it informs the Controller immediately.
  • Ensures that persons who process data are bound by confidentiality.
  • Takes appropriate technical and organisational measures, see the annex.
  • Assists the Controller, as far as reasonable, with data subject requests (access, rectification, erasure, portability, objection), and with security, data breach notifications, data protection impact assessments and consultation of the supervisory authority. Users can export their own data and delete their own account in the app.
  • After the end of the service deletes or returns all personal data, as the Controller chooses, and deletes existing copies unless the law requires retention. Backups are encrypted, kept for no longer than 10 days (one per day) and then deleted.
  • Makes available the information needed to demonstrate compliance with these obligations and cooperates with audits, reasonably, after notice and at reasonable cost.

4. Data breaches

The Processor notifies a personal data breach affecting the Controller’s data without undue delay, and in any case within 48 hours after becoming aware of it, with the information available at that moment (nature, data subjects and data concerned, likely consequences, measures taken and proposed). Notifying the supervisory authority and data subjects is the Controller’s responsibility.

5. Sub-processors

The Controller gives the Processor general authorisation to engage sub-processors. At present these are:

Sub-processorPurposeCountry
Anthropic, PBCAI: explanations, practice questions, summaries and assessment of answersUnited States
Replit, Inc.Hosting of the app, the database, files and backupsUnited States
Google (Google Ireland Ltd. / Google LLC)Google Drive for encrypted backups; emailIreland / United States
OpenAI, L.L.C.Only if photos for questions are switched on: an AI-written description of a photo, without name or email addressUnited States

The Processor imposes the same obligations on sub-processors as in this agreement and remains liable for their compliance. If the Processor wants to add or replace a sub-processor it will tell the Controller at least 30 days beforehand; within that period the Controller may object in writing with reasons.

6. Transfers outside the EEA

Transfer to the United States (Anthropic, Replit, Google and OpenAI) takes place only on the basis of a valid instrument under Chapter V GDPR: the EU-US Data Privacy Framework or standard contractual clauses.

7. Liability and governing law

The liability provisions of the terms of service apply to liability, as far as the law allows. This agreement is governed by Dutch law.

8. Annex: security measures

  • Encrypted connections (https) and strict security headers.
  • Passwords as a hash (bcrypt); API keys entered by users encrypted (AES-256-GCM).
  • Access to photos and files only for the owner; separation between accounts is tested automatically.
  • Limits on login attempts; sessions expire after at most 7 days (with ‘Remember me’), otherwise after at most 24 hours.
  • Daily backups, stored encrypted (AES-256-GCM) for no longer than 10 days; administrator access only where necessary; administrator actions are logged.
  • No third-party scripts or fonts on the site.
  • A data breach procedure and a maintained register of processing activities.

Contact for this agreement: privacy@retrieva.nl. Version 2026-10-02.5.