DATA PROCESSING AGREEMENT (DPA) – LMS DOMAIN
This Data Processing Agreement (“DPA”) forms part of the Terms of Service and governs how Techiegram, operating under the name LMS Domain (“LMS Domain”, “we”, “us”, “our”), processes personal data on behalf of you or your institution (“Controller”, “you”, “your”) when using our AI-powered Learning Management System (“Platform”, “Service”).
This DPA explains what data we process, why we process it, how we secure it, and the commitments we make in relation to data privacy and protection. It applies whenever we act as a Processor handling personal data on your behalf.
1. Roles and Responsibilities
1.1 Controller
You, the institution or individual using LMS Domain, determine:
- What personal data is collected
- How long the data is kept
- Which users have access
- The purposes for which the data is processed
1.2 Processor
LMS Domain will:
- Process personal data only on your documented instructions
- Provide the technical and operational infrastructure to support secure processing
- Not use your data for advertising or external analytics
- Not train external AI models using your data
1.3 Sub-Processors
To operate our platform reliably and securely, we use carefully selected sub-processors including:
- Infrastructure: AWS, Cloudflare
- Email Delivery: Amazon SES, SendGrid, Mailgun
- Payments: Stripe, Razorpay, PayPal
- AI API Providers: OpenAI API (used only for AI-based functionality such as chat assistance, summaries, and content generation)
- Other operational services: logging, error monitoring, backup services
We remain responsible for ensuring these sub-processors meet comparable data protection and security standards.
2. Types of Data We Process
LMS Domain processes the following data categories strictly for the purpose of providing the Platform:
- 2.1 Account and Identity Data: Name, email, phone number (optional), encrypted passwords, roles, institution affiliation.
- 2.2 Learning-Related Data: Enrollments, assignments, evaluations, submissions, grades, certificates, progress logs, uploaded media, communication logs.
- 2.3 AI Interaction Data: Prompts submitted to AI tools, responses generated, metadata needed to operate AI features. (Note: Data sent to OpenAI via API is not used to train OpenAI models.)
- 2.4 Technical and Log Data: IP addresses, device/browser information, login timestamps, usage logs, API activity logs, error reports.
- 2.5 Billing and Transaction Data: Subscription details, payment confirmations, transaction IDs, invoices. (Processed by third-party payment gateways, not stored by us.)
3. Purpose and Scope of Processing
We process personal data solely to provide, operate, and improve the LMS Domain Platform, including:
- User account creation and authentication
- Delivery of learning content, AI-powered assistance, assessments and digital classrooms
- Institution configuration and multi-tenant management
- Security monitoring and fraud detection
- Customer support
- Generating anonymized or aggregated insights
- Ensuring performance, backups and disaster recovery
We do not:
- Sell personal data
- Use it for advertising
- Mine it for marketing
- Share it with third parties unrelated to service delivery
4. Instructions & Compliance
LMS Domain will process data only:
- As described in this DPA
- As instructed by the Controller
- As required by law
Where legally permitted, we will notify you before processing your data for any new purpose not covered in this DPA.
5. Security Measures
We implement industry-standard administrative, technical, and physical safeguards including:
Technical Safeguards
- AES-256 encryption at rest & TLS 1.2+ encrypted connections
- Role-based access control (RBAC)
- Secure API authentication and tokens
- Network firewalls and IDS/IPS
- Multi-layer access restrictions
Administrative Safeguards
- Staff confidentiality agreements
- Access limited to essential personnel
- Regular security and compliance training
- Audit logging and monitoring
Physical Safeguards
- Secure AWS data centers
- Redundant storage
- Disaster recovery protocols
6. Data Retention and Deletion
We retain data only for:
- The duration of the institution’s or user’s active subscription
- A reasonable post-termination period for backups
- Legal and regulatory obligations
Upon termination or upon request from the Controller:
- Personal data will be deleted from active systems
- Backup copies will expire automatically as part of routine backup cycles
- Any remaining logs are retained only for security, compliance, or audit purposes
If you request deletion of specific data, we will act promptly unless legally restricted.
7. International Data Transfers
Depending on your region, data may be processed in or transferred to other countries. Where necessary, we use:
- Standard Contractual Clauses (SCCs) for EU transfers
- DPDP-compliant safeguards for Indian users
- Industry-standard compliance frameworks for US and other regions
We ensure equivalent protection irrespective of the hosting region.
8. Rights of the Controller and Users
We provide reasonable assistance to enable you to fulfill data subject rights under applicable laws including:
- Access requests
- Correction of inaccurate data
- Deletion requests
- Objections to processing
- Data portability
- Consent withdrawal
If your account is institution-managed, users must submit requests through the institution.
9. Confidentiality
All personnel authorized to process personal data are bound by strict confidentiality obligations. We will not disclose your data unless:
- Requested by the Controller
- Required by law
- Needed to protect the safety or rights of users
- Needed to operate the Platform (only via approved sub-processors)
10. Data Breach Notification
In the event of an actual or suspected breach affecting personal data:
- We will notify the Controller without unreasonable delay
- Provide details, scope, and nature of the breach
- Describe mitigation steps taken
- Support the Controller in reporting obligations to legal authorities or affected users
We maintain a formal incident response process to limit risk.
11. Sub-Processor Management
Before engaging a new sub-processor, we:
- Conduct a security and privacy evaluation
- Ensure contractual protections equivalent to this DPA
- Take responsibility for sub-processor actions
You may request a current list of sub-processors at any time.
12. Audit Rights
Upon reasonable notice, and where legally required, the Controller may:
- Request documentation related to data protection
- Request summaries of security audits
- Request verification of compliance measures
Direct physical audits of facilities are permitted only where required by law and coordinated with our cloud providers.
13. Term, Termination and Survival
This DPA:
- Becomes effective upon acceptance of the LMS Domain Terms of Service
- Remains valid as long as LMS Domain processes personal data on behalf of the Controller
- Survives termination of the main agreement with respect to confidentiality and data deletion obligations
14. Contact Information
For privacy questions, compliance requests, data access, or sub-processor details:
LMS Domain (Techiegram)
Email: support@lmsdomain.com
Website: https://lmsdomain.com