Draft for counsel review
Data Processing Addendum
A placeholder DPA outline for B2B customers where Next Degrees processes personal data.
Last updated: 2026-06-22
Draft status
This DPA is a product placeholder for negotiation and counsel review. It does not replace a signed customer data processing agreement.
Roles
For employer, school, or enterprise deployments, the customer is generally the controller of learner personal data and Next Degrees is generally the processor. Next Degrees may act as an independent controller for account administration, security, billing, and legal compliance.
Processing instructions
Next Degrees processes personal data to provide hosted courses, enrollment, assessment, progress reporting, credential issuance, support, security, and related product operations under the customer agreement and documented instructions.
Security commitments
- Access controls and least-privilege handling for production systems.
- Encryption in transit and appropriate encryption or managed protection at rest.
- Operational logging, backup, vulnerability management, and incident-response procedures.
- Personnel confidentiality and role-appropriate security training.
Subprocessors
Next Degrees may use subprocessors for hosting, authentication, database, email, payment, support, analytics, and learning-record services. A production DPA must include the live subprocessor list, locations, purpose of processing, and notice process for changes.
Assistance and deletion
Next Degrees will reasonably assist customers with data subject requests, security reviews, incident notices, and deletion or return of customer personal data, subject to credential integrity, legal retention, and backup lifecycle constraints.
Transfers
International transfer terms, standard contractual clauses, local addenda, and data residency commitments must be finalized by counsel before regulated production deployment.
