Data Processing Agreement

Last updated March 19, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Hamilton Consulting LLC("Processor" or "we") and the entity or individual agreeing to these terms ("Controller" or "you"), governing the processing of personal data in connection with the Edura platform (https://www.getedura.com).

This DPA is designed to comply with Article 28 of the General Data Protection Regulation (GDPR) (EU) 2016/679 and applies when Edura processes personal data on behalf of organizations (e.g., educational institutions, employers) that use our platform for their members or students.

Short version

  • The DPA applies when Edura processes personal data for an organization acting as controller.
  • Edura processes data only to provide the service and follow documented instructions.
  • Subprocessors are listed publicly and should be reviewed before organization use.
  • We support deletion, return, breach notification, and data-subject request workflows.
  • Organizations can start a self-serve DPA request from this page.

Self-serve DPA request

Organizations that need a signed DPA can prepare a request packet here. The form opens a pre-filled email to our team with the details needed for review, signature routing, and any security questionnaire follow-up.

Loading DPA request form...

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person as defined under GDPR.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
  • "Data Subject" means the individual whose Personal Data is being processed.
  • "Sub-processor" means a third party engaged by Edura to process Personal Data on behalf of the Controller.

2. Roles and Responsibilities

2.1 Controller

The Controller determines the purposes and means of processing Personal Data. When an organization uses Edura for its members or students, the organization acts as the Controller.

2.2 Processor

Hamilton Consulting LLC acts as the Processor, processing Personal Data only on documented instructions from the Controller, unless required to do so by applicable law.

3. Data Processing Details

3.1 Types of Personal Data

  • Account information (name, email, profile image)
  • Educational profile data (school, grade, interests)
  • User-generated content (comments, reviews, blog posts)
  • AI conversation history
  • Usage and interaction data
  • Payment data (processed by Stripe)

3.2 Categories of Data Subjects

  • Students (aged 16+)
  • Educators and administrators
  • Parents and guardians
  • Professionals

3.3 Purpose of Processing

Personal Data is processed to provide the Edura platform services, including account management, personalized recommendations, AI-powered assistance, and communication.

4. Sub-processors

The Controller authorizes Edura to engage the subprocessors listed in our public Subprocessors register. The current list is summarized below.

Sub-processor
Purpose
Location
Supabase
Stores application data, manages authentication, and enforces row-level security
United States
Vercel
Hosts the Edura web application and serves pages, assets, and server-rendered routes
United States / global edge network
Stripe
Processes subscriptions, AI credit purchases, listing promotions, invoices, and fraud checks
United States
OpenAI
Processes prompts and context for AI assistant and generation features
United States
Anthropic
Processes prompts and context for AI assistant and generation features
United States
Sentry
Captures errors, stack traces, performance data, and error-triggered replay buffers
United States
PostHog
Measures product usage, funnels, feature adoption, surveys, and accepted session replays
United States
Google
Provides sign-in, location search, and optional file import integrations
United States / global infrastructure
Mapbox
Displays maps and geocodes listing or user-provided locations
United States
Resend
Sends account, notification, invite, and service emails
United States
Convex
Supports real-time interactions where enabled
United States
Firecrawl
Extracts content from URLs submitted for AI or listing workflows
United States
Microlink
Fetches public website metadata for listing display
United States / global infrastructure

We will notify the Controller before adding or replacing sub-processors. The Controller may object to a new sub-processor within 30 days of notification. If the objection is not resolved, either party may terminate the agreement.

5. Data Security

We implement appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Row-level security (RLS) policies on our database to ensure data isolation
  • Authentication and access controls via Supabase
  • Regular security reviews and monitoring
  • Employee access limited to need-to-know basis
  • Sentry session replay data with sensitive fields masked

6. Data Breach Notification

In the event of a Personal Data breach, we will:

  • Notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach
  • Provide all information reasonably necessary for the Controller to fulfill its breach notification obligations under GDPR Article 33
  • Take immediate steps to contain and remediate the breach
  • Document the breach, its effects, and remedial actions taken

7. Data Subject Rights

We will assist the Controller in responding to Data Subject requests to exercise their rights under GDPR, including:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)

We will respond to Controller requests regarding Data Subject rights within 10 business days.

8. Data Deletion and Return

Upon termination of the agreement or upon the Controller's request:

  • We will delete or return all Personal Data within 30 days
  • We will delete all existing copies unless retention is required by applicable law
  • We will provide written confirmation of deletion upon request

9. International Data Transfers

Edura and its sub-processors primarily process data in the United States. For transfers of Personal Data from the EU/EEA to the United States, we rely on:

  • Standard Contractual Clauses (SCCs) as adopted by the European Commission
  • Sub-processor certifications under applicable data transfer frameworks

We will ensure that any transfer of Personal Data to a third country is subject to appropriate safeguards as required by GDPR Chapter V.

10. Audits

We will make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Audit requests must be submitted with at least 30 days' notice.

11. Duration and Termination

This DPA remains in effect for the duration of the Controller's use of Edura. Obligations regarding data deletion, confidentiality, and compliance survive termination.

12. Related Documents

13. Contact Us

For questions about this DPA or to exercise data protection rights, contact us:

  • Email: support@getedura.com
  • Mail: Adam Hamilton