Skoolara

Legal

Data Processing Agreement


Operator Agreement / Data Processing Addendum

POPIA sections 20–21 / GDPR Article 28

Between:

[School Name], a [public school / independent school / other] operating from [School Address] (the "School" or "Responsible Party" / "Controller");

and

Teleios IT Consulting (Pty) Ltd, a private company registered in the Republic of South Africa under registration number 2025/487193/07, whose registered office is the address recorded against that registration number in the CIPC register from time to time, operating the Skoolara platform ("Skoolara" or "Operator" / "Processor"). Teleios IT Consulting (Pty) Ltd's designated Information Officer is Sachen Govender, registered with the Information Regulator of South Africa under reference 2026-005741.

Each a "Party" and together the "Parties".


1. Background

1.1. The School has subscribed to the Skoolara platform for the administration of the School and the education of its learners.

1.2. In the course of operating the platform, Skoolara processes personal information on behalf of the School. The School is the Responsible Party under POPIA and, where applicable, the Controller under GDPR; Skoolara is the Operator / Processor.

1.3. This Operator Agreement / Data Processing Addendum (the "Addendum") sets out the written agreement required by POPIA sections 20 and 21 and GDPR Article 28. It forms part of the School Agreement between the Parties and, in relation to the processing of personal information, prevails over any inconsistent provision in the School Agreement, the Terms of Service or any other document incorporated by clause 5 of the School Agreement.


2. Definitions

In this Addendum, unless the context indicates otherwise:


3. Subject matter and duration

3.1. Subject matter. The processing of Personal Information by Skoolara on behalf of the School for the purpose of providing the Skoolara platform.

3.2. Duration. This Addendum commences on the earlier of (i) the effective date of the School's subscription or (ii) the date Skoolara begins to process Personal Information on behalf of the School, and continues for as long as Skoolara processes such Personal Information.


4. Nature and purpose of processing

Skoolara processes Personal Information to:

Skoolara processes Personal Information only on the documented instructions of the School, which are embodied in the Terms of Service, this Addendum, configurations made by the School within the platform, and any further written instructions accepted by Skoolara.


5. Types of personal information and categories of data subjects

5.1. Categories of Data Subjects:

5.2. Categories of Personal Information:


6. Obligations of Skoolara (Operator)

6.1. Instructions. Skoolara shall process Personal Information only on the documented instructions of the School, except where required to do otherwise by law (in which case Skoolara shall, unless prohibited, inform the School).

6.2. Confidentiality. Skoolara shall ensure that personnel authorised to process Personal Information are bound by written confidentiality obligations or a statutory duty of confidentiality.

6.3. Security. Skoolara shall implement and maintain appropriate technical and organisational measures to safeguard Personal Information, taking into account the state of the art, cost of implementation, nature of the information, and the risks to Data Subjects. Measures shall include:

6.4. Sub-Operators. Skoolara may engage Sub-Operators subject to clause 7.

6.5. Assistance with Data-Subject requests. Skoolara shall, taking into account the nature of the processing, assist the School by appropriate technical and organisational measures, insofar as possible, to respond to requests by Data Subjects exercising their rights under Applicable Data Protection Laws.

6.5.1. Data Subjects who hold no account on the platform. The Parties record that some Data Subjects described in clause 5.1 — in particular emergency contacts and persons authorised to collect a learner — hold no user account on the platform. The self-service request tooling within the platform is available only to account holders. In respect of such a Data Subject, Skoolara's assistance under clause 6.5 is rendered manually: on the School's documented instruction, Skoolara shall locate, produce, correct, restrict or delete the relevant records within the timeframes the School must meet. Where Skoolara receives such a request directly (for example at privacy@skoolara.co.za), it shall route it to the School without undue delay and shall not respond substantively to the Data Subject save to acknowledge receipt and to identify the School as Responsible Party. The decision on the request remains the School's.

6.6. Assistance with compliance. Skoolara shall assist the School in ensuring compliance with its obligations under POPIA s19-22 and GDPR Articles 32-36, including security, breach notification, and data-protection impact assessments.

6.7. Breach notification. Skoolara shall notify the School without undue delay, and in any event within 72 hours of becoming aware of a Security Compromise affecting Personal Information processed under this Addendum. Such notification shall, to the extent known, describe:

Skoolara shall cooperate with the School to enable the School to meet its own notification obligations to the Information Regulator, supervisory authorities and Data Subjects.

6.8. Records. Skoolara shall maintain records of processing activities carried out on behalf of the School as required by POPIA and GDPR Art 30(2), and shall make such records available to the School on request.

6.9. Return or deletion. On termination of the Addendum or expiry of the subscription, Skoolara shall, at the School's election, return and/or delete all Personal Information processed on behalf of the School in accordance with clause 11.


7. Sub-Operators

7.1. General authorisation. The School grants Skoolara general authorisation to engage Sub-Operators, subject to this clause.

7.2. Current Sub-Operators. At the effective date, the following Sub-Operators are engaged:

Sub-Operator Role Location of processing
Amazon Web Services EMEA SARL Application and database hosting; object storage for uploaded files (identity documents, medical certificates, report attachments); transactional email delivery Cape Town, Republic of South Africa (af-south-1)
Google LLC — Firebase Cloud Messaging Push-notification delivery to the School's mobile app users Google global infrastructure (cross-border — see clause 8.2)

No other Sub-Operators are engaged at the effective date. In particular, Skoolara does not engage a payment processor: the platform records fee transactions that the School's own bank has already confirmed, and at no point receives, holds or transmits funds or card data on the School's behalf.

7.3. Changes to Sub-Operators. Skoolara shall notify the School at least 30 days in advance of any addition or replacement of Sub-Operators. The School may object to a proposed Sub-Operator on reasonable, documented grounds related to data-protection. Where the Parties cannot resolve an objection, the School may terminate the affected part of the subscription without penalty.

7.4. Contracts with Sub-Operators. Skoolara shall impose on each Sub-Operator, by written contract, data-protection obligations equivalent to those in this Addendum. Skoolara remains liable to the School for the performance of each Sub-Operator.


8. Location of processing and international transfers

8.1. Processing within the Republic. Personal Information processed through Skoolara — including all database records, uploaded files (identity documents, medical certificates, report attachments) and transactional email — is stored and processed on infrastructure located within the Republic of South Africa (Cape Town). Skoolara does not transfer learner records outside the Republic in the ordinary course of providing the platform.

8.2. Limited exception — push notifications. Where the School enables mobile push notifications, delivery is performed by Google LLC (Firebase Cloud Messaging) on infrastructure outside the Republic. The information transferred is limited to what is necessary to deliver the message: a device registration token, a generic category title (for example "New notice" or "Attendance update"), a fixed generic body ("Open Skoolara to view the details."), and opaque resource identifiers. No learner name, mark, message content or other identifying information is transferred: the payload is normalised at the sending boundary so that identifying content cannot leave the process, and a payload that looks name-shaped is logged and replaced. Full learner records are never transferred to this Sub-Operator — the device retrieves those from South African infrastructure when the User opens the app. This matches the statement made to parents in section 8 of the Privacy Policy.

8.3. Transfer basis. For the transfer described in clause 8.2, Skoolara shall ensure a lawful basis under POPIA s72 — and, where GDPR applies, under GDPR Chapter V — including binding corporate rules, Standard Contractual Clauses or equivalent contractual safeguards, an adequacy decision where available, or another lawful transfer mechanism affording a level of protection substantially similar to the conditions for lawful processing under POPIA.

8.4. No relocation without notice. Skoolara shall not relocate the processing described in clause 8.1 to infrastructure outside the Republic of South Africa without giving the School at least 30 days' prior written notice. The School may object on reasonable, documented data-protection grounds and, where the Parties cannot resolve the objection, terminate the affected part of the subscription without penalty.

8.5. On request, Skoolara shall provide the School with copies of relevant transfer safeguards (with commercially sensitive terms redacted).


9. Audit rights

9.1. Skoolara shall make available to the School the information reasonably necessary to demonstrate compliance with this Addendum.

9.2. Skoolara undertakes annual independent security assessments (for example, ISO/IEC 27001, SOC 2 or equivalent) and will share executive summaries with the School on request and subject to confidentiality.

9.3. On reasonable notice (not less than 30 days), and no more than once per year unless a Security Compromise has occurred or a regulator has required it, the School (or a qualified independent auditor appointed by it and acceptable to Skoolara, which acceptance shall not be unreasonably withheld) may audit Skoolara's compliance with this Addendum. Audits shall:


10. Liability

10.1. Each Party's liability under this Addendum is subject to the limitations and exclusions in clause 9 of the School Agreement, which apply to claims under this Addendum as if set out in full here, save that nothing in this Addendum limits liability that cannot lawfully be limited (including liability for fraud, wilful misconduct, or statutory administrative fines payable to a regulator in respect of that Party's own acts or omissions).

10.2. Where both Parties are responsible for an event causing damage to a Data Subject, liability shall be apportioned in accordance with POPIA and, where applicable, GDPR Art 82(4)-(5).


11. Termination and data return

11.1. Termination. This Addendum terminates automatically on the termination or expiry of the School Agreement between the Parties.

11.2. Return and deletion. Within 30 days after the end of the 30-day export period provided for in clause 7.6 of the School Agreement — that is, within 60 days after termination — Skoolara shall, at the School's election:

11.3. Backups. Personal Information contained in routine backups shall be deleted in accordance with the rolling backup-retention cycle set out in data-retention-schedule.md.

11.4. Legal retention. Where law requires Skoolara to retain specific Personal Information, Skoolara shall retain it for the period required and protect it by appropriate security measures during that period.

11.5. Written confirmation. On request, Skoolara shall provide the School with written confirmation of return or deletion.


12. Order of precedence

12.1. The order of precedence is that set out in clause 5.1 of the School Agreement: (1) this Addendum, for anything concerning personal information; (2) Schedule A of the School Agreement, for anything commercial; (3) the School Agreement; (4) the Service Level Agreement; (5) the Terms of Service; (6) the Privacy Policy, POPIA Collection Notice and Data Retention Schedule. This Addendum accordingly prevails over each of those documents in relation to the processing of Personal Information.

12.2. In the event of any conflict between this Addendum and Applicable Data Protection Laws, the laws prevail.


13. Miscellaneous

13.1. Amendments. This Addendum may be amended only in writing signed by both Parties, save that Skoolara may update sub-Operators in accordance with clause 7.

13.2. Governing law. This Addendum is governed by the laws of the Republic of South Africa.

13.3. Jurisdiction. The Parties submit to the exclusive jurisdiction of the competent courts of the Republic of South Africa.


14. Signatures

For the School (Responsible Party / Controller):

Name: ____ Capacity: ____ Signature: ____ Date: ____

For Skoolara (Operator / Processor):

Name: ____ Capacity: ____ Signature: ____ Date: ____


End of Operator Agreement / Data Processing Addendum (v1.0).