DPA
Data Processing Addendum (Schools)
This public DPA page recreates the exported school-processing terms for AfterClass with Chamberlin Innovations SASU as processor.
Parties
Customer (Controller)
- School or institution name: _______________________________
- Address: _______________________________
- Contact email: _______________________________
Provider (Processor)
- Chamberlin Innovations SASU
- 870 Rue des Thermes
- 65130 Capvern, France
- SIREN: 993 523 836
- dpa@afterclass.training
1. Scope
This DPA applies to the processing of "Student Data" provided by the Customer via AfterClass, including:
- Student names and or pseudonymized identifiers
- Voice recordings or session audio used for learning analysis
- Performance scores, transcripts, and progress data
- Teacher-created assignments, class rosters, and learner records
2. Processor Obligations
2.1 Security
Processor shall implement appropriate technical and organizational measures to protect Student Data, including encryption at rest and in transit, role-based access controls, regular security reviews, and European-hosted infrastructure where configured.
2.2 Confidentiality
Processor ensures that personnel processing Student Data are subject to confidentiality obligations and receive appropriate data protection training.
2.3 Processing Limitations
Processor shall only process Student Data to provide the educational service and never for third-party advertising, unrelated profiling, training general-purpose public AI models, or sale to third parties except authorized sub-processors.
3. Authorized Sub-Processors
The Controller authorizes the following sub-processors. Processor will notify Controller of material changes to this list 30 days in advance.
| Sub-Processor | Location | Purpose |
|---|---|---|
| Supabase | EU (Frankfurt) | Database, authentication, file storage |
| OpenAI | US | Audio transcription and feedback APIs |
| Mistral | EU | Pedagogical generation and analysis |
| US/EU | Speech, Drive, and Calendar services when enabled | |
| Lemon Squeezy | US/Global | Payment processing and tax compliance |
4. Data Deletion
Upon termination of the agreement, Processor shall delete or return Student Data within 60 days unless European Union or French law requires longer retention.
Controller may request a data export in JSON or CSV format before termination.
5. Security Incidents
Processor shall notify Controller without undue delay, and in any event within 72 hours after becoming aware of a personal data breach affecting Student Data.
Notification will include the nature of the breach, categories of data affected, approximate number of records, and recommended mitigation steps when available.
6. Audit Rights
Controller may request, on 30 days' written notice, evidence of Processor compliance with this DPA, including relevant security documentation, penetration-test summaries, or sub-processor information where appropriate.
7. Duration
This DPA remains in effect for the duration of the Controller's use of AfterClass and survives termination with respect to any Student Data retained under legal obligations.
Signatures
Processor
- Chamberlin Innovations SASU
- Authorized signature: _______________________________
- Name: Eric Chamberlin
- Title: Founder
- Date: January 1, 2026
Controller (School)
- Organization: _______________________________
- Authorized signature: _______________________________
- Name: _______________________________
- Title: _______________________________
- Date: _______________________________
DPA Footer
- Questions: dpa@afterclass.training
- Document version: 1.0
- Last updated: December 2025