Mosra.
FeaturesTemplatesLearnPricingFAQLog inGet started free

Data Processing Addendum

For schools and companies using Mosra with learners: the terms on which we process your data.

  • Version1.0
  • Effective{{EFFECTIVE_DATE}}
  • Last updated{{EFFECTIVE_DATE}}

On this page

  • 1. Scope and roles
  • 2. Processing instructions
  • 3. Confidentiality
  • 4. Security measures
  • 5. Sub-processors
  • 6. Assisting with data subject requests
  • 7. Data incidents
  • 8. Audit and demonstrating compliance
  • 9. International transfers
  • 10. Return and deletion
  • Annex A — Description of processing
  • Annex B — Technical and organisational measures

In short

  • You are the controller. We are the processor and act only on your instructions.
  • We give notice before adding a new sub-processor.
  • We help you answer learner requests inside the statutory deadlines.
  • When the contract ends, we return or delete the data as you choose.

1. Scope and roles

This Addendum applies where you (the "Controller") use Mosra, provided by {{LEGAL_NAME}} (the "Processor", "we"), to process personal data of your learners or staff. It forms part of the Terms of Service.

You determine the purposes and means of processing. We process on your behalf and do not use that data for our own purposes.

For the administrator's own account data (email, name, billing) we remain the controller and the Privacy Policy applies.

2. Processing instructions

We process personal data only on: (a) the instructions expressed through your use of the Service's features, (b) written instructions you send us, and (c) requirements of law.

If we believe an instruction breaches data protection law, we will tell you and may pause that part of the processing.

If the law requires processing beyond your instructions, we will tell you first unless the law forbids it.

3. Confidentiality

Only people who need access to run the Service get it, and they are bound by confidentiality obligations.

We do not disclose your data to third parties beyond the sub-processors in section 5 and where the law requires.

4. Security measures

We apply appropriate technical and organisational measures, at minimum:

  • Encryption in transit (HTTPS/TLS) for all traffic.
  • Hashed passwords, never stored in readable form.
  • Role-based access control on a least-privilege basis.
  • Access logging for production systems.
  • Regular backups with restore testing.
  • Rate limiting and monitoring for abuse.
  • Data separation between customer organisations.

Annex B lists these in more detail, and we provide an up-to-date description on request.

5. Sub-processors

You authorise our use of the sub-processors listed on the Sub-processors page. That list forms part of this Addendum.

We contract with each sub-processor on data protection terms no less protective than this Addendum, and remain responsible for their performance as for our own.

We give at least 30 days' notice before adding a new sub-processor. If you object on reasonable grounds we will look for an alternative; where none is workable, you may terminate the affected part of the Service and receive a refund of unused prepaid fees.

6. Assisting with data subject requests

The Service gives you tools to access, correct, export and delete your learners' data yourself.

Where those tools are not enough, we assist within a reasonable time so you can meet the statutory deadlines (acknowledgement in 2 working days; access and correction in 10 days; withdrawal of consent in 15 days; deletion in 20 days).

If a learner contacts us directly, we pass the request to you rather than acting on it, unless you instruct otherwise.

7. Data incidents

We notify you without undue delay after becoming aware of an incident affecting your personal data, and in any case early enough for you to meet your own 72-hour notification duty.

The notice covers the nature of the incident, the categories of data and approximate number of data subjects affected, likely consequences, and the measures taken or planned.

We cooperate reasonably so you can notify the authority and the affected individuals.

8. Audit and demonstrating compliance

We provide the information you reasonably need to demonstrate compliance, including a description of our security measures and answers to vendor assessment questionnaires.

You may audit no more than once a year, on at least 30 days' notice, during business hours, without disrupting the Service and without access to other customers' data. You bear the cost unless a material breach is found.

9. International transfers

Some sub-processors process data outside Vietnam. We complete the cross-border transfer impact assessment Vietnamese law requires and apply standard contractual clauses where EU/UK law applies.

If your organisation requires data to stay in-country, the self-hosted deployment is the right option and this Addendum applies with a correspondingly narrower scope.

10. Return and deletion

When the contract ends you have 30 days to export your data with the built-in tools or ask us to hand it over.

After that we delete it from production systems. Copies in backups are removed on the backup rotation, at most 30 days from the backup date.

We keep only what the law requires us to keep, such as accounting records, and only to that extent.

Annex A — Description of processing

ItemDetail
Subject matterProviding a platform for authoring lessons, running assessments and reporting results
DurationFor the term of the contract, plus the deletion period in section 10
Nature and purposeStorage, display, grading, report aggregation, sending notifications
Types of dataName or nickname, email, results and answers, time taken, technical session data
Categories of data subjectsLearners, teachers, organisation administrators
Sensitive dataOut of scope. The Controller does not put sensitive data into the Service

Annex B — Technical and organisational measures

  • Encryption in transit: all traffic over TLS.
  • Authentication: hashed passwords, Google sign-in support, time-limited sessions.
  • Authorisation: roles scoped by organisation, class and resource.
  • Logging: administrative access and sensitive operations are recorded.
  • Backups: regular, restore-tested, retained no more than 30 days.
  • Abuse prevention: per-route rate limits, separate quota for AI features.
  • Change management: automated tests before release.
  • Incident process: detection, assessment, notification within 72 hours.

Need a signed DPA or your organisation's security questionnaire completed? Write to {{PRIVACY_EMAIL}}. Postal address: {{BUSINESS_ADDRESS}}.

Related documents

Terms of ServicePrivacy PolicyCookiesSub-processorsStudent data
Mosra.

Interactive lessons your LMS can actually track.

Product

FeaturesTemplatesFree PPTX to SCORM converterLearnLMSComparePricingFAQAbout

All features

e-Learning exportPDF exportPowerPointQuestionsVideo exportCollaborationSelf-hosted

Learn

SCORM vs xAPIWhat is cmi5What is an LRS

Legal

Terms of ServicePrivacy PolicyCookiesSub-processorsData Processing AddendumStudent data
© 2026 MosraEnglish · Tiếng Việt