Data Processing Addendum

Effective Date: August 7, 2026

Version: 1.0

This Data Protection Addendum ("Addendum" or "DPA") forms part of the Terms of Service ("ToS") entered into between: (1) The Customer ("Data Controller") accessing or using the Learnyst LMS platform; and (2) Learnyst Insight Private Limited, a company incorporated under the Companies Act, 2013, having its registered office at #110, Krishna Garden Main Road, Rajarajeshwari Nagar, Bangalore – 560 098, Karnataka, India ("Learnyst" or "Data Processor").

This Addendum is incorporated into and forms an integral part of the Terms of Service between the Parties. All capitalised terms not defined in this Addendum shall have the meanings ascribed to them in the Terms of Service or the Privacy Policy, as applicable. In the event of any conflict between this Addendum and the Terms of Service with respect to data protection matters, the terms of this Addendum shall prevail.

This Addendum applies to the extent that Learnyst processes Personal Data on behalf of the Data Controller in connection with the provision of the Learnyst Platform and associated services. It is intended to ensure that all processing activities are conducted in compliance with applicable Data Protection Laws, including, where applicable, the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, the California Consumer Privacy Act (“CCPA”), the California Privacy Rights Act (“CPRA”), and other applicable United States state privacy laws.

  1. Definitions And Interpretation

1.1 Definitions

In this Addendum, the following terms shall have the meanings set out below:

  1. Addendum / DPA: This Data Protection Addendum, including all Annexures attached hereto, as amended or updated from time to time.

  2. Agreement Personal Data: Any Personal Data processed by Learnyst on behalf of the Data Controller in connection with providing the Platform and Services, as described in Annexure A.

  3. Data Controller: The Customer who determines the purposes and means of processing Personal Data, as more particularly described in the Terms of Service.

  4. Data Processor: Learnyst Insight Private Limited, which processes Personal Data on behalf of, and under the instructions of, the Data Controller.

  5. Data Protection Laws: All applicable laws and regulations relating to data protection and privacy, including the DPDPA 2023, EU GDPR (Regulation 2016/679), UK GDPR, CCPA/CPRA, Swiss FADP, and any other applicable national or state data protection legislation, together with all related subordinate legislation, guidance, and codes of practice.

  6. Data Security Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Agreement Personal Data. This does not include unsuccessful attempts or activities that do not compromise Personal Data.

  7. Data Subject: An identified or identifiable natural person to whom the Agreement Personal Data relates, including learners, instructors, administrators, and other end users of the Platform.

  8. Data Subject Request: An actual or purported request, complaint, or notice from or on behalf of a Data Subject exercising their rights under applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, or objection.

  9. Documented Instructions: Written directives issued by the Data Controller to Learnyst specifying the purposes, means, scope, and conditions under which Learnyst is authorised to process Agreement Personal Data.

  10. DPDPA: The Digital Personal Data Protection Act, 2023, enacted by the Parliament of India, and its rules and regulations made thereunder, as amended from time to time.

  11. EEA: The European Economic Area, comprising the Member States of the European Union together with Iceland, Liechtenstein, and Norway.

  12. GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data, as amended, supplemented, or replaced from time to time.

  13. Personal Data: Any information relating to an identified or identifiable natural person. This includes, but is not limited to, name, email address, phone number, location data, IP address, device identifiers, learning activity data, and any other data that can directly or indirectly identify an individual. The term includes equivalent concepts under applicable Data Protection Laws, including 'personal information' under the CCPA.

  14. Platform / Services: The Learnyst Learning Management System (LMS) platform, applications, tools, and related services provided by Learnyst under the Terms of Service.

  15. Restricted Transfer: Any transfer of Agreement Personal Data to a country or territory that does not provide an adequate level of protection for Personal Data as determined under applicable Data Protection Laws, including transfers outside India, the EEA, or the UK.

  16. SCCs: The Standard Contractual Clauses for the transfer of Personal Data to third countries as established by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 under the GDPR, and incorporated into this Addendum by reference.

  17. Sensitive Personal Data: Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning a person's sex life or sexual orientation, financial account details, official identifiers (such as Aadhaar or passport numbers), and any other category of data designated as sensitive under applicable Data Protection Laws.

  18. Sub-Processor: Any third party engaged by Learnyst, or by any Learnyst group company, to process Agreement Personal Data in connection with providing the Platform and Services.

  19. Technical and Organisational Measures (TOMs): The security and organisational safeguards implemented to protect Agreement Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

  20. UK Addendum: The International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner under section 199A(1) of the UK Data Protection Act 2018.

1.2 Interpretation

In this Addendum:

(a) Headings are for convenience only and shall not affect interpretation;

(b) References to statutes or legislation include any amendment or re-enactment thereof;

(c) The singular includes the plural and vice versa;

(d) The word 'including' shall be construed without limitation; and

(e) References to 'Clauses' or 'Annexures' are to those in this Addendum unless otherwise specified.

  1. Roles And Relationship Of The Parties

2.1 Controller and Processor

The Parties acknowledge and agree that, in relation to the processing of Agreement Personal Data:

  • The Data Controller determines the purposes and means of processing Agreement Personal Data and is responsible for ensuring that its instructions to Learnyst comply with all applicable Data Protection Laws.

  • Learnyst acts as the Data Processor and processes Agreement Personal Data only on behalf of, and in accordance with the Documented Instructions of, the Data Controller, except to the extent required to do otherwise by applicable law.

2.2 Independent Controllership

Notwithstanding Section 2.1, Learnyst may process certain Personal Data as an independent Data Controller for its own legitimate business purposes, such as account management, billing, fraud prevention, platform improvement, and compliance with applicable laws. In such cases, Learnyst's Privacy Policy governs the processing.

Learnyst may additionally process business contact information of the Data Controller’s representatives as an independent controller for account administration, billing, legal compliance, fraud prevention, and business relationship management purposes.

2.3 Data Controller Warranties

The Data Controller represents and warrants that:

  • It has a lawful basis for processing and for disclosing Agreement Personal Data to Learnyst.

  • It has provided all necessary notices and obtained all required consents from Data Subjects in connection with the processing contemplated by this Addendum.

  • Its instructions to Learnyst will at all times comply with applicable Data Protection Laws.

  • It will not instruct Learnyst to process Personal Data in a manner that would cause Learnyst to violate any applicable Data Protection Law.

  • The Data Controller is solely responsible for obtaining all necessary parental consents, school authorisations, and lawful permissions required for the processing of Personal Data relating to minors or children under applicable laws.

  • The Data Controller shall be solely responsible for determining, documenting, and maintaining the lawful basis for processing Personal Data under applicable Data Protection Laws.

  1. Learnyst's Processing Obligations

3.1 Processing in Accordance with Instructions

Learnyst shall:

  1. Process Agreement Personal Data only on the Documented Instructions of the Data Controller, including with regard to international transfers of Agreement Personal Data, unless otherwise required by applicable law, in which case Learnyst shall promptly notify the Data Controller (to the extent permitted by law);

  2. Not sell, rent, or otherwise commercially exploit Agreement Personal Data received in connection with providing the Services for any purpose other than the performance of the Services;

  3. Not retain, use, or disclose Agreement Personal Data outside the scope of its direct business relationship with the Data Controller;

  4. Not combine Agreement Personal Data with Personal Data obtained from any other source, except as necessary for the provision of the Services and as permitted under applicable Data Protection Laws;

  5. Promptly notify the Data Controller if, in Learnyst's reasonable opinion, any Documented Instruction infringes applicable Data Protection Laws.

3.2 Confidentiality

Learnyst shall ensure that all personnel authorised to process Agreement Personal Data are bound by appropriate obligations of confidentiality with respect to such data, and that access to Agreement Personal Data is limited to those personnel who require access for the purpose of providing the Services.

3.3 No Sale of Personal Data

Learnyst confirms that it does not and will not sell Agreement Personal Data. Learnyst shall not share Agreement Personal Data for cross-context behavioral advertising or for any purpose that constitutes a 'sale' or 'share' under the CCPA/CPRA or any other applicable Data Protection Law.

3.4 Notification Obligations

If Learnyst becomes aware that a Documented Instruction would cause it to violate applicable Data Protection Laws, Learnyst shall promptly notify the Data Controller. In such case, Learnyst shall be entitled to suspend the relevant processing until the Data Controller provides modified instructions that are lawful.

3.5 CCPA/CPRA Service Provider Status

To the extent applicable under the CCPA/CPRA, Learnyst acts as a “Service Provider” and/or “Contractor” and shall process Personal Data solely for the limited and specified purposes set out in this Addendum and the Terms of Service.

3.6 HIPAA and Protected Health Information

The Services are not intended for the processing or storage of Protected Health Information (“PHI”) regulated under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), unless expressly agreed by the Parties in writing under a separate agreement. The Data Controller shall not upload, submit, or otherwise process PHI through the Services without Learnyst’s prior written consent.

3.7 Educational and Children’s Data Compliance

Where the Services are used in connection with educational institutions or minors, the Data Controller shall be solely responsible for ensuring compliance with all applicable educational and children’s privacy laws, including FERPA, COPPA, and equivalent laws in other jurisdictions.

  1. Technical And Organisational Security Measures

4.1 Security Obligations

Learnyst shall implement and maintain appropriate Technical and Organisational Measures (TOMs) to ensure a level of security appropriate to the risk presented by the processing of Agreement Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures include, without limitation:

  • Encryption of Personal Data in transit and at rest using industry-standard protocols (TLS 1.2 or higher for data in transit; AES-256 or equivalent for data at rest);

  • Ongoing confidentiality, integrity, availability, and resilience of processing systems and services;

  • Ability to restore the availability and access to Agreement Personal Data in a timely manner in the event of a physical or technical incident;

  • Regular testing, assessment, and evaluation of the effectiveness of technical and organisational measures for ensuring the security of processing;

  • Role-based access controls, multi-factor authentication, and audit logging for systems that process Agreement Personal Data;

  • Regular vulnerability assessments and penetration testing;

  • Employee training and awareness programmes on data protection and information security;

  • Business continuity and disaster recovery procedures.

4.2 Annexure B

A more detailed description of Learnyst's current Technical and Organisational Measures is set out in Annexure B to this Addendum. Learnyst may update these measures from time to time, provided that any updates shall not materially diminish the overall level of protection afforded to Agreement Personal Data.

  1. Data Security Breaches

5.1 Notification

In the event that Learnyst becomes aware of a confirmed Data Security Breach affecting Agreement Personal Data, Learnyst shall:

  1. Notify the Data Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach, to the extent this is reasonably practicable;

  2. Provide the Data Controller with sufficient information to allow it to meet its obligations to notify the relevant supervisory authority and/or affected Data Subjects, including: (a) a description of the nature of the breach; (b) the categories and approximate number of Data Subjects affected; (c) the categories and approximate number of records concerned; (d) the likely consequences of the breach; and (e) the measures taken or proposed to address the breach.

  3. Take all reasonable steps to investigate, remediate, and mitigate the effects of the Data Security Breach;

  4. Cooperate fully with the Data Controller and provide any information reasonably requested to assist the Data Controller in complying with its legal obligations.

5.2 No Admission

Learnyst's notification of or response to a Data Security Breach shall not be construed as an admission of fault or liability by Learnyst. Learnyst shall not make any public statement or communication regarding a Data Security Breach relating to Agreement Personal Data without the prior written consent of the Data Controller, except as required by applicable law.

5.3 Government Disclosure Requests

Unless prohibited by applicable law, Learnyst shall make commercially reasonable efforts to notify the Data Controller prior to disclosing Agreement Personal Data in response to any legally binding request from a governmental authority, law enforcement agency, or regulatory body.

  1. Data Subject Rights

6.1 Assistance with Data Subject Requests

Learnyst shall, taking into account the nature of the processing, assist the Data Controller by implementing appropriate technical and organisational measures, insofar as this is possible, to fulfil the Data Controller's obligations to respond to Data Subject Requests. Such requests may include, but are not limited to:

  • Right of access to Personal Data (Article 15, GDPR; Section 11, DPDPA);

  • Right to rectification or correction of inaccurate data (Article 16, GDPR; Section 12, DPDPA);

  • Right to erasure or deletion ('right to be forgotten') (Article 17, GDPR; Section 13, DPDPA);

  • Right to restriction of processing (Article 18, GDPR);

  • Right to data portability (Article 20, GDPR);

  • Right to object to processing (Article 21, GDPR);

  • Rights in relation to automated decision-making (Article 22, GDPR);

  • Right to opt out of sale or sharing (CCPA/CPRA).

6.2 Forwarding Requests

Where Learnyst receives a Data Subject Request directly from a Data Subject, Learnyst shall promptly forward such request to the Data Controller without responding to the Data Subject, unless the Data Controller has authorised Learnyst in writing to respond on its behalf, or unless Learnyst is required by applicable law to respond directly. Learnyst shall provide all reasonable assistance to enable the Data Controller to respond to Data Subject Requests within applicable statutory time limits.

  1. Sub-Processors

7.1 General Authorisation

The Data Controller hereby provides a general written authorisation to Learnyst to engage Sub-Processors in connection with the provision of the Services, subject to the conditions set out in this Section 7. A list of current Sub-Processors is set out in Annexure C to this Addendum and is available at Learnyst's website at trust.learnyst.com.

7.2 Obligations Regarding Sub-Processors

Learnyst shall:

  1.  Enter into a written agreement with each Sub-Processor imposing data protection obligations equivalent to those placed on Learnyst under this Addendum, to the extent required by applicable Data Protection Laws;

  2. Remain fully liable to the Data Controller for the acts and omissions of its Sub-Processors to the same extent as if Learnyst had performed the processing itself;

  3. Conduct appropriate due diligence on Sub-Processors prior to engagement and on an ongoing basis to ensure their capability to maintain appropriate security and data protection standards.

7.3 Changes to Sub-Processors

Learnyst shall provide the Data Controller with prior notice of any intended changes concerning the addition or replacement of Sub-Processors ("Sub-Processor Notice") by updating the Sub-Processor list on its website and/or by direct notification. The Data Controller may object to any new or replacement Sub-Processor on reasonable grounds relating to data protection within fourteen (14) calendar days of receipt of the Sub-Processor Notice. If the Parties are unable to resolve the Data Controller's objection within thirty (30) days, the Data Controller may terminate the relevant Services upon written notice, subject to the terms of the ToS.

  1. International Data Transfers

8.1 Restricted Transfers

Learnyst shall not transfer Agreement Personal Data to any country or territory outside India, the EEA, or the UK (each a "Restricted Transfer") unless one of the following conditions is met:

  • The transfer is to a country or territory that has been designated as providing an adequate level of protection for Personal Data by the competent authority (e.g., European Commission adequacy decision, or Indian government notification);

  • Appropriate safeguards have been implemented in accordance with applicable Data Protection Laws, including the execution of SCCs and/or the UK Addendum; or

  • Another derogation or exception under applicable Data Protection Laws applies.

8.2 Standard Contractual Clauses

To the extent that any Agreement Personal Data from the EEA, Switzerland, or the UK is transferred to Learnyst or its Sub-Processors in a country not providing adequate protection, the Parties agree to execute the Standard Contractual Clauses as set out in Commission Implementing Decision (EU) 2021/914 (Module Two: Controller to Processor), which are incorporated into this Addendum by reference. For transfers from the UK, the UK Addendum shall apply in addition. The Annexures to the SCCs shall be populated with the information set out in Annexures A, B, and C of this Addendum, as applicable.

The SCCs and any applicable UK Addendum shall be deemed executed and incorporated by reference automatically upon commencement of any Restricted Transfer subject to applicable Data Protection Laws.

8.3 India Cross-Border Transfers

For transfers of Personal Data of Indian Data Principals outside India, the Parties shall comply with Section 16 of the DPDPA 2023 and any rules or notifications issued thereunder. Learnyst shall only transfer such data to countries or territories permitted by the Government of India or in accordance with applicable transfer mechanisms.

8.4 Remote Access and Global Infrastructure

The Data Controller acknowledges and agrees that the provision of the Services may involve remote access to Agreement Personal Data and the use of globally distributed cloud infrastructure, support systems, and Sub-Processors located in multiple jurisdictions, subject to the safeguards set out in this Addendum.

  1. Audits And Compliance Assistance

9.1 Audit Rights

Learnyst shall make available to the Data Controller all information reasonably necessary to demonstrate compliance with the obligations set out in this Addendum and shall allow for and contribute to audits and inspections conducted by the Data Controller or its appointed auditor, subject to the following conditions:

  1.  The Data Controller shall provide Learnyst with at least thirty (30) days prior written notice of any intended audit;

  2.  Audits shall be conducted during normal business hours, in a manner that minimises disruption to Learnyst's operations;

  3.  The Data Controller (or its auditor) shall execute a confidentiality agreement satisfactory to Learnyst prior to commencing any audit;

  4. The Data Controller shall bear all costs associated with any audit, unless the audit reveals a material non-compliance by Learnyst, in which case Learnyst shall bear reasonable audit costs;

  5. The frequency of audits shall not exceed once per calendar year, unless a Data Security Breach or regulatory investigation requires more frequent audits.

  6. Audits shall primarily be conducted through the review of existing third-part certifications, audit reports, and security documentation made available by Learnyst, unless otherwise required by applicable law or a competent supervisory authority.

9.2 Third-Party Certifications

Learnyst may satisfy its audit obligations under Section 9.1 by providing the Data Controller with relevant third-party certifications, audit reports, or attestations (e.g., ISO 27001, SOC 2 Type II) that are subject to confidentiality obligations, provided such reports are reasonably current and address the scope of Learnyst's data processing activities.

9.3 Regulatory Assistance

Learnyst shall, at the Data Controller's cost, provide all reasonable assistance to enable the Data Controller to conduct data protection impact assessments (DPIAs) and prior consultations with supervisory authorities, as required by applicable Data Protection Laws.

Any assistance requested by the Data Controller beyond Learnyst’s standard obligations under this Addendum may be subject to reasonable additional fees and resource availability.

  1. Data Retention And Deletion

10.1 Retention During Services

Learnyst shall retain Agreement Personal Data for no longer than is necessary for the provision of the Services, unless a longer retention period is required by applicable law or agreed between the Parties in writing.

10.2 Return or Deletion on Termination

Upon the termination or expiry of the Terms of Service, or upon the Data Controller's written request at any time during the term of the Services, Learnyst shall, at the Data Controller's election:

  • Securely return to the Data Controller a complete copy of all Agreement Personal Data in a commonly used, machine-readable format; or

  • Securely delete and destroy all Agreement Personal Data and all copies thereof (including data stored by Sub-Processors), and provide the Data Controller with a written certification of deletion.

10.3 Retention for Legal Obligations

Notwithstanding Section 10.2, Learnyst may retain Agreement Personal Data to the extent, and for the period, required by applicable law, provided that Learnyst shall ensure the confidentiality of such data and shall not process it for any other purpose.

  1. Liability And Indemnification

11.1 Mutual Compliance

Each Party shall be liable for its own violations of applicable Data Protection Laws. Where a Party is held liable for any infringement of Data Protection Laws by the other Party, the latter Party shall indemnify the former to the extent that it is liable for the relevant infringement, in accordance with and subject to the limitations in the Terms of Service.

11.2 Limitation of Liability

The Parties' liability to each other under or in connection with this Addendum shall be subject to the limitations and exclusions set out in the Terms of Service, except to the extent that such limitations or exclusions are not permitted by applicable Data Protection Laws.

11.3 Indemnification by Data Controller

The Data Controller shall indemnify, defend, and hold harmless Learnyst and its officers, directors, employees, and agents from and against any claims, damages, penalties, fines, or expenses arising from: (a) the Data Controller's breach of this Addendum; (b) any processing of Personal Data carried out by the Data Controller outside the scope of this Addendum or in violation of applicable Data Protection Laws; or (c) any failure by the Data Controller to provide lawful Documented Instructions.

  1. TERM AND TERMINATION

This Addendum shall commence on the Effective Date and shall remain in force for the duration of the Terms of Service, unless earlier terminated in accordance with its terms. Termination of the Terms of Service shall automatically terminate this Addendum, subject to those provisions which by their nature survive termination, including without limitation Sections 4 (Security), 5 (Data Security Breaches), 10 (Data Retention and Deletion), and 11 (Liability and Indemnification).

The obligations relating to confidentiality, security, international transfers, audit rights, liability, indemnification, and deletion of Agreement Personal Data shall survive termination of this Addendum for so long as Learnyst retains Agreement Personal Data.

GOVERNING LAW AND DISPUTE RESOLUTION

13.1 Governing Law

This Addendum shall be governed by and construed in accordance with the laws of India, without prejudice to the mandatory requirements of applicable Data Protection Laws in other jurisdictions. For Data Subjects in the EEA, the provisions of the GDPR and applicable EU Member State legislation shall apply to the extent required by law.

13.2 Jurisdiction

Any disputes arising out of or in connection with this Addendum shall be subject to the exclusive jurisdiction of the courts of Bangalore, Karnataka, India, subject to any mandatory provisions of applicable law regarding jurisdiction for data protection matters.

13.3 Dispute Resolution

Prior to initiating any legal proceedings, the Parties shall attempt in good faith to resolve any dispute arising from this Addendum through escalation to senior management of each Party within thirty (30) days of written notice of the dispute.

14. General Provisions

14.1 Entire Agreement

This Addendum, together with the Terms of Service and Privacy Policy, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior agreements, understandings, and representations relating to data processing.

14.2 Amendments

Learnyst reserves the right to amend this Addendum from time to time to reflect changes in applicable Data Protection Laws, regulatory guidance, or business practices. Learnyst shall provide the Data Controller with at least thirty (30) days' notice of any material amendments. The Data Controller's continued use of the Platform following the effective date of any amendment shall constitute acceptance of the amended Addendum.

14.3 Severability

If any provision of this Addendum is found to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect. The Parties shall negotiate in good faith to replace any invalid provision with a valid provision that achieves the same economic and legal effect.

14.4 Waiver

No failure or delay by either Party in exercising any right or remedy under this Addendum shall operate as a waiver of that right or remedy. A waiver must be in writing and signed by the waiving Party to be effective.

14.5 Contact Information and Data Protection Officer

Learnyst has appointed a Data Protection Officer in accordance with Article 37 of the GDPR. The Data Protection Officer may be contacted directly by the Data Controller, by Data Subjects, and by supervisory authorities on all matters relating to the Processing of Personal Data under this Addendum.

Data Protection Officer

Name: Sridhar Dubbaka
Learnyst Insight Private Limited #110, Krishna Garden Main Road, Rajarajeshwari Nagar Bangalore – 560 098, Karnataka, India
Email: privacy@learnyst.com
Website: www.learnyst.com

Any queries, requests, or notices relating to this Addendum or to Learnyst's data processing activities — including requests for the current list of Sub-Processors under Annexure C, and requests made under Section 6 (Data Subject Rights) — should be addressed to the Data Protection Officer at the address above.

14.6 Order of Precedence

In the event of any conflict or inconsistency between:

(a) the Standard Contractual Clauses;

(b) this Addendum, and

(c) the Terms of Service,

The order of precedence shall be:

(i) the Standard Contractual Clauses;

(ii) this Addendum; and

(iii) the Terms of Service,

solely with respect to matters relating to Personal Data processing and protection.

SCHEDULE 1

Annex I

Details Of Processing Of Personal Data

This Annex I forms an integral part of the Data Protection Addendum (“DPA”) entered into between Learnyst Insight Private Limited (“Learnyst”, “Processor”, or “Service Provider”) and the applicable customer, institution, organization, educator, enterprise, or other business entity utilizing the Learnyst Learning Management System platform (“Customer” or “Controller”).

This Annex sets out the details relating to the Processing of Personal Data in accordance with applicable Data Protection Laws and the obligations of the parties under the DPA.

A. LIST OF PARTIES

  1. Data Exporter / Controller

Name: The Data Exporter shall be the Customer, institution, organization, educator, enterprise, corporate entity, or other legal person that has entered into an agreement with Learnyst for the use of the Learnyst LMS Platform and related services.

Address

The address of the Data Exporter shall be the address specified in the applicable:

  • Master Service Agreement,

  • Subscription Agreement,

  • Order Form,

  • Account registration records, or

  • Other governing commercial agreement executed between the parties.

Contact Person: The contact person shall be the individual designated by the Customer for administrative, operational, privacy, compliance, or contractual communications relating to the Services and the Processing of Personal Data.

Activities Relevant to the Processing of Personal Data

The Data Exporter utilizes the Learnyst LMS Platform and associated services for purposes that may include, but are not limited to:

  • Creation, hosting, management, and delivery of educational content and digital learning programs;

  • Student, learner, instructor, and user account administration;

  • Course enrollment, assessments, certifications, examinations, and progress tracking;

  • Communication and engagement with learners, instructors, employees, affiliates, or customers;

  • Business operations, reporting, analytics, and performance monitoring;

  • Subscription management, customer relationship management, and related educational technology activities;

  • Management of online training, coaching, educational institutions, academies, and enterprise learning initiatives.

Signature and date: Signature and date are set out in the Agreement.

Role: For the purposes of applicable Data Protection Laws, the Data Exporter acts as the Controller or equivalent legal entity determining the purposes and means of the Processing of Personal Data.

2. Data Importer / Processor

Name: Learnyst Insight Private Limited

Registered Address

#110, Krishna Garden Main Road
Rajarajeshwari Nagar
Bangalore – 560098
Karnataka, India

Contact Information: Email: privacy@learnyst.com

Activities Relevant to the Processing of Personal Data

The Data Importer provides software, infrastructure, hosting, support, maintenance, analytics, security, communication, and related technology services associated with the Learnyst LMS Platform.

In connection with the provision of the Services, Learnyst may Process Personal Data for activities including:

  • Hosting and operation of the Learnyst LMS Platform;

  • Provision of educational technology infrastructure and cloud-based learning services;

  • User authentication, access management, and account administration;

  • Data storage, backup, synchronization, and recovery;

  • Technical support, customer assistance, and troubleshooting;

  • Platform analytics, monitoring, reporting, and service optimization;

  • Communication services including notifications, emails, alerts, and learner engagement tools;

  • Security monitoring, fraud prevention, threat detection, and system integrity management;

  • Integration with third-party tools, payment gateways, communication platforms, and business applications authorized by the Customer;

  • Compliance with legal obligations, regulatory requirements, and legitimate operational necessities.

Signature and date: Signature and date are set out in the Agreement.

Role: For the purposes of applicable Data Protection Laws, Learnyst acts as the Processor or equivalent legal entity Processing Personal Data on behalf of and in accordance with the documented instructions of the Controller.

B. Description Of Transfer

Categories of data subjects whose personal data is transferred

Customer’s authorized users of the Services;

  • Students and learners;

  • Instructors and educators;

  • Customer administrators and employees;

  • Prospective users and website visitors;

  • Support and communication contacts.

Categories of personal data transferred
  • Name;

  • Address;

  • Date of Birth;

  • Age;

  • Education details;

  • Email address;

  • Gender;

  • Image or profile photograph;

  • Job or occupation information;

  • Language preferences;

  • Phone number;

  • Related person or emergency contact information;

  • Related URLs or social profile links;

  • User ID;

  • Username;

  • Account credentials and login information;

  • Course participation and learning progress;

  • Assessment and certification records;

  • Technical and device information;

  • Usage analytics and platform interaction data.

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures

No sensitive personal data or special categories of personal data are intentionally collected as part of the ordinary provision of the Services.

To the extent the Customer uploads or Processes any sensitive personal data through the Services, such Processing shall occur solely under the Customer’s instructions and responsibility. They shall be subject to appropriate technical and organizational safeguards, including:

  • Strict purpose limitation;

  • Role-based access restrictions;

  • Confidentiality obligations for authorized personnel;

  • Access logging and monitoring;

  • Restrictions on onward transfers;

  • Encryption and security controls were appropriate.

  • Additional security measures proportionate to the nature and risks associated with such data

The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis)

Continuous basis during the term of the Agreement and throughout the Customer’s use of the Services.

Nature of the processing

The Processing activities may include:

  • Collection;

  • Recording;

  • Organization;

  • Structuring;

  • Storage and hosting;

  • Retrieval and consultation;

  • Use and analysis;

  • Transmission and disclosure where necessary for service delivery;

  • Synchronization with third-party integrations;

  • Communication and notifications;

  • Reporting and analytics;

  • Restriction;

  • Deletion and destruction.

Such Processing is carried out solely for the purpose of providing, maintaining, supporting, securing, improving, and administering the Services in accordance with the Agreement and the Customer’s documented instructions.

Purpose(s) of the data transfer and further processing

The purpose of the transfer is to facilitate the performance, delivery, operation, administration, security, and improvement of the Services more fully described in the Agreement, Addendum, Subscription Plans, and accompanying Order Forms.

Such purposes may include:

  • Providing access to the Learnyst LMS Platform;

  • Delivering educational and training services;

  • Managing customer and learner accounts;

  • Facilitating communication and learner engagement;

  • Conducting assessments and certifications;

  • Providing analytics and reporting;

  • Delivering customer support and technical assistance;

  • Ensuring platform security, reliability, and functionality;

  • Complying with applicable legal and regulatory obligations.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

The period for which the Customer Personal Data will be retained is more fully described in the Agreement, Addendum, Subscription Plans, and accompanying Order Forms.

Personal Data shall be retained only for as long as necessary to:

  • Fulfill the purposes described in the Agreement;

  • Provide the Services;

  • Comply with legal and regulatory obligations;

  • Resolve disputes;

  • Enforce contractual obligations;

  • Maintain legitimate business and operational records.

Upon termination or expiration of the Services, Personal Data shall be deleted or returned in accordance with the Agreement and applicable law.

For transfers to (sub-) processors, also specify subject matter, nature, and duration of the processing

Learnyst may engage authorized Sub-Processors to support the provision and operation of the Services, including providers of:

  • Cloud hosting and infrastructure services;

  • Data storage and backup services;

  • Analytics and monitoring tools;

  • Communication and notification systems;

  • Payment processing services;

  • Customer support and operational tools.

The subject matter, nature, and duration of the Processing carried out by Sub-Processors shall be limited to what is necessary to perform the Services as more fully described in the Agreement, Addendum, and accompanying Order Forms.

Learnyst shall ensure that authorized Sub-Processors are bound by appropriate contractual obligations relating to confidentiality, security, and data protection.

C. COMPETENT SUPERVISORY AUTHORITY

Where the Data Exporter is established in a member state of the European Economic Area (“EEA”), the competent supervisory authority shall be determined in accordance with Clause 13 of the EU Standard Contractual Clauses (“EU SCCs”).

The competent supervisory authority shall be identified based on:

  • The location of the Data Exporter;

  • The jurisdiction governing the Processing activities;

  • Applicable legal and regulatory requirements.

ANNEXURE A

Description of Processing Activities

This Annexure sets out the subject matter, nature, purpose, and duration of the processing, as well as the categories of Personal Data processed and the categories of Data Subjects affected.

Field

Subject Matter

Nature of Processing

Purpose of Processing

Duration of Processing

Categories of Personal Data

Sensitive Personal Data

Categories of Data Subjects

Frequency of Transfer

Primary Processing Location

Details

Details

Processing of Personal Data in connection with the provision of the Learnyst Learning Management System (LMS) and related services.

Processing of Personal Data in connection with the provision of the Learnyst Learning Management System (LMS) and related services.

Collection, storage, organisation, structuring, adaptation, retrieval, consultation, use, disclosure, erasure, and destruction of Personal Data as necessary for the provision of the Services.

Collection, storage, organisation, structuring, adaptation, retrieval, consultation, use, disclosure, erasure, and destruction of Personal Data as necessary for the provision of the Services.

Provision and operation of the LMS platform; user authentication and account management; course delivery and tracking; assessments and certifications; analytics and reporting; communications and notifications; payment processing; customer support; platform security and fraud prevention; compliance with applicable law.

Provision and operation of the LMS platform; user authentication and account management; course delivery and tracking; assessments and certifications; analytics and reporting; communications and notifications; payment processing; customer support; platform security and fraud prevention; compliance with applicable law.

For the duration of the Terms of Service plus any applicable retention period required by law, or until the Data Controller instructs deletion.

For the duration of the Terms of Service plus any applicable retention period required by law, or until the Data Controller instructs deletion.

Contact and identity data (name, email address, phone number); account credentials (username, encrypted password); professional and organisational data; learning and assessment data (course progress, quiz scores, certificates); usage data (IP address, device information, browser type, access logs); payment information (processed via third-party payment gateways); communications data; and any other data submitted by users through the Platform.

The Data Controller shall not upload, process, or store Sensitive Personal Data through the Services unless such processing is strictly necessary, lawful under applicable Data Protection Laws, and expressly authorised by Learnyst in writing.

Learners / Students enrolled in courses; Course creators and instructors; Platform administrators and account owners; Business contacts of the Data Controller; Visitors to the Data Controller's Learnyst-powered website or portal.

On a continuous basis for the duration of the Services.

India (Bangalore, Karnataka). Data may be replicated to cloud infrastructure in other regions subject to Section 8 of this Addendum.

India (Bangalore, Karnataka). Data may be replicated to cloud infrastructure in other regions subject to Section 8 of this Addendum.

ANNEXURE B

Technical and Organisational Security Measures

Learnyst implements the following Technical and Organisational Measures to protect Agreement Personal Data. These measures are reviewed and updated regularly to reflect the current state of technology and the evolving threat landscape.

1. Data Centre and Infrastructure Security

  • Agreement Personal Data is hosted on secure cloud infrastructure with physical access controls, surveillance, redundancy, and environmental controls.

  • The underlying cloud infrastructure and data centres operated by Google Cloud Platform maintain industry-recognized certifications and attestations, including ISO/IEC 27001 and SOC 2 reports, or equivalent standards.

  • Learnyst maintains an ISO/IEC 27001-certified Information Security Management System (ISMS) and implements appropriate technical and organizational measures to protect Agreement Personal Data.

  • Network segmentation, firewalls, and other security controls are used to isolate and protect sensitive data environments.

2. Encryption

  • All Agreement Personal Data is encrypted in transit using TLS 1.2 or higher.

  • All Agreement Personal Data is encrypted at rest using AES-256 or equivalent industry-standard encryption.

  • Encryption keys are managed using hardware security modules (HSMs) or equivalent key management systems.

3. Access Controls

  • Access to systems and data is controlled through role-based access control (RBAC) and the principle of least privilege.

  • Multi-factor authentication (MFA) is enforced for administrative and privileged access.

  • Access to Agreement Personal Data is restricted to authorised personnel who require access for the purposes of providing the Services.

  • All access events are logged and monitored through centralised logging systems.

4. Vulnerability Management

  • Learnyst conducts regular internal and external vulnerability assessments of its systems and applications.

  • Penetration testing is performed at least annually by qualified security professionals.

  • A formal patch management process is in place to address identified vulnerabilities within defined timescales based on severity.

5. Incident Response

  • Learnyst maintains a documented security incident response plan.

  • A dedicated security team is responsible for monitoring, detecting, investigating, and responding to security incidents.

  • Incidents are classified, escalated, and communicated in accordance with the procedures set out in Section 5 of this Addendum.

6. Business Continuity and Disaster Recovery

  • Learnyst maintains a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) to ensure the availability and resilience of the Platform and Agreement Personal Data.

  • Regular backups of Agreement Personal Data are performed and tested for integrity and recoverability.

  • Recovery time objectives (RTOs) and recovery point objectives (RPOs) are defined and regularly tested.

7. Personnel and Organisational Measures

  • All Learnyst personnel who process Agreement Personal Data are subject to confidentiality obligations.

  • Privacy and security awareness training is provided to all relevant personnel at onboarding and on an ongoing basis.

  • Background checks are conducted on personnel with access to Agreement Personal Data, to the extent permitted by applicable law.

8. Supplier and Third-Party Management

  • All Sub-Processors are subject to due diligence assessments prior to engagement and on an ongoing basis.

  • Written data processing agreements are in place with all Sub-Processors, containing obligations equivalent to those in this Addendum.

ANNEXURE C

List of Approved Sub-Processors

The following is a list of Sub-Processors currently engaged by Learnyst Insight Private Limited in connection with the provision, operation, maintenance, support, security, analytics, monitoring, communication, and delivery of the Services.

This list may be updated periodically in accordance with the applicable terms of the Data Processing Addendum (“DPA”). An updated list of Sub-Processors may be maintained and provided upon request

Sub-Processor

Entity Location

Purpose

Data Processed

HubSpot, Inc.

USA / Global

CRM, customer communication, marketing automation, support management

Contact information, communication data, customer account data

Google Workspace (Google LLC)

USA / Global

Business communication, email services, collaboration tools, document management

Email data, communication records, business documents


GitHub, Inc.

USA / Global

Source code management, software development collaboration, DevOps workflows

Developer metadata, repository information, technical logs

Google Cloud Platform (Google LLC)

Global

Cloud infrastructure, hosting, storage, application services

Application data, system logs, operational data

Atlassian Jira

USA / Global

Project management, issue tracking, engineering workflows, support operations

Operational data, support tickets, internal project information

Debounce

USA / Global

Email verification and validation services

Email addresses and verification metadata

Scout Monitoring

USA / Global

Infrastructure monitoring, performance monitoring, operational alerting

System metrics, infrastructure logs, operational monitoring data

Honeybadger Industries LLC

USA

Error tracking, application monitoring, debugging, and incident diagnostics

Application logs, error reports, diagnostic information

Note:This list may be updated from time to time in accordance with the applicable provisions of the Data Processing Addendum and operational requirements. Customers or Data Controllers may request the latest list of approved Sub-Processors by contacting:

Email: privacy@learnyst.com 

Why to trust us?

Our Partners

Copyright © 2026 Learnyst. All Rights Reserved

Why to trust us?

Our Partners

Copyright © 2026 Learnyst. All Rights Reserved

Why to trust us?

Our Partners

Copyright © 2026 Learnyst. All Rights Reserved

Why to trust us?

Our Partners

Copyright © 2026 Learnyst. All Rights Reserved