1. Scope and roles
This Addendum applies where you (the "Controller") use Mosra, provided by {{LEGAL_NAME}} (the "Processor", "we"), to process personal data of your learners or staff. It forms part of the Terms of Service.
You determine the purposes and means of processing. We process on your behalf and do not use that data for our own purposes.
For the administrator's own account data (email, name, billing) we remain the controller and the Privacy Policy applies.
2. Processing instructions
We process personal data only on: (a) the instructions expressed through your use of the Service's features, (b) written instructions you send us, and (c) requirements of law.
If we believe an instruction breaches data protection law, we will tell you and may pause that part of the processing.
If the law requires processing beyond your instructions, we will tell you first unless the law forbids it.
3. Confidentiality
Only people who need access to run the Service get it, and they are bound by confidentiality obligations.
We do not disclose your data to third parties beyond the sub-processors in section 5 and where the law requires.
4. Security measures
We apply appropriate technical and organisational measures, at minimum:
- Encryption in transit (HTTPS/TLS) for all traffic.
- Hashed passwords, never stored in readable form.
- Role-based access control on a least-privilege basis.
- Access logging for production systems.
- Regular backups with restore testing.
- Rate limiting and monitoring for abuse.
- Data separation between customer organisations.
Annex B lists these in more detail, and we provide an up-to-date description on request.
5. Sub-processors
You authorise our use of the sub-processors listed on the Sub-processors page. That list forms part of this Addendum.
We contract with each sub-processor on data protection terms no less protective than this Addendum, and remain responsible for their performance as for our own.
We give at least 30 days' notice before adding a new sub-processor. If you object on reasonable grounds we will look for an alternative; where none is workable, you may terminate the affected part of the Service and receive a refund of unused prepaid fees.
6. Assisting with data subject requests
The Service gives you tools to access, correct, export and delete your learners' data yourself.
Where those tools are not enough, we assist within a reasonable time so you can meet the statutory deadlines (acknowledgement in 2 working days; access and correction in 10 days; withdrawal of consent in 15 days; deletion in 20 days).
If a learner contacts us directly, we pass the request to you rather than acting on it, unless you instruct otherwise.
7. Data incidents
We notify you without undue delay after becoming aware of an incident affecting your personal data, and in any case early enough for you to meet your own 72-hour notification duty.
The notice covers the nature of the incident, the categories of data and approximate number of data subjects affected, likely consequences, and the measures taken or planned.
We cooperate reasonably so you can notify the authority and the affected individuals.
8. Audit and demonstrating compliance
We provide the information you reasonably need to demonstrate compliance, including a description of our security measures and answers to vendor assessment questionnaires.
You may audit no more than once a year, on at least 30 days' notice, during business hours, without disrupting the Service and without access to other customers' data. You bear the cost unless a material breach is found.
9. International transfers
Some sub-processors process data outside Vietnam. We complete the cross-border transfer impact assessment Vietnamese law requires and apply standard contractual clauses where EU/UK law applies.
If your organisation requires data to stay in-country, the self-hosted deployment is the right option and this Addendum applies with a correspondingly narrower scope.
10. Return and deletion
When the contract ends you have 30 days to export your data with the built-in tools or ask us to hand it over.
After that we delete it from production systems. Copies in backups are removed on the backup rotation, at most 30 days from the backup date.
We keep only what the law requires us to keep, such as accounting records, and only to that extent.
Annex A — Description of processing
| Item | Detail |
|---|---|
| Subject matter | Providing a platform for authoring lessons, running assessments and reporting results |
| Duration | For the term of the contract, plus the deletion period in section 10 |
| Nature and purpose | Storage, display, grading, report aggregation, sending notifications |
| Types of data | Name or nickname, email, results and answers, time taken, technical session data |
| Categories of data subjects | Learners, teachers, organisation administrators |
| Sensitive data | Out of scope. The Controller does not put sensitive data into the Service |
Annex B — Technical and organisational measures
- Encryption in transit: all traffic over TLS.
- Authentication: hashed passwords, Google sign-in support, time-limited sessions.
- Authorisation: roles scoped by organisation, class and resource.
- Logging: administrative access and sensitive operations are recorded.
- Backups: regular, restore-tested, retained no more than 30 days.
- Abuse prevention: per-route rate limits, separate quota for AI features.
- Change management: automated tests before release.
- Incident process: detection, assessment, notification within 72 hours.
Need a signed DPA or your organisation's security questionnaire completed? Write to {{PRIVACY_EMAIL}}. Postal address: {{BUSINESS_ADDRESS}}.