Lurnnet Data Processing Agreement (DPA)
Version: 1.2.0 Effective date: 13 August 2026 Replaces: 1.1.0 (10 August 2026)
Plain-language summary (read this first)
Who Lurnnet is. Lurnnet is operated by Andrew Fahmy, doing business as Lurnnet. We may transfer this DPA to a company we form. Contact:
privacy@lurnnet.com.This DPA is the operational contract that runs between you (the teacher Subscriber, as Controller of your Students' and TAs' Personal Data) and Lurnnet (as Processor).
It is incorporated by reference into your Subscriber Terms at
/legal/terms(Part A, §1). By accepting Subscriber Terms, you agree to this DPA.The DPA covers what Personal Data we process for you, why, on what legal basis, on which Sub-Processors, with what security, with what audit rights, and what happens when there's a breach or when your subscription ends.
The most important things in this DPA:
- You are the Controller; Lurnnet is the Processor. Lurnnet processes only on your documented instructions.
- Lurnnet captures parental consent on your behalf for under-18 Students through the parent-email-confirmation flow. The consent records are owned by you.
- Lurnnet supports you on parent Data Subject Requests (5-working-day acknowledgement, identity verification, routing to you; in Egypt six working days to respond, otherwise 30 days unless a shorter local deadline applies).
- Sub-Processors get 30 days' prior notice for additions; you can terminate for cause.
- Lurnnet notifies you within 72 hours of becoming aware of a Personal-Data breach.
- 30-day restricted export window, then permanent deletion of Class data, when your subscription ends. Export is your responsibility.
- Cross-border transfers use contracts and any approvals required by applicable law — see §11.
- Liability allocation mirrors Subscriber Terms.
1. Definitions
In this DPA, capitalised terms have the meanings given in the Subscriber Terms (/legal/terms) and in the Privacy Policy (/legal/privacy), and additionally:
- "Affiliate" — any entity that controls, is controlled by, or is under common control with a party.
- "Applicable Data Protection Law" — the Egyptian Personal Data Protection Law no. 151 of 2020 ("PDPL") and its Executive Regulations (Decree no. 816 of 2025) ("PDPL ER"), the Egyptian Child Law no. 12 of 1996 to the extent applicable to under-18 Personal Data, and any of the following that apply to a particular Data Subject by virtue of habitual residence: the Saudi Personal Data Protection Law (and SDAIA AI Ethics Principles where AI features are involved), UAE Federal Decree-Law no. 45 of 2021, Bahrain Personal Data Protection Law no. 30 of 2018 and Resolution 42 of 2022, Qatar Law no. 13 of 2016, Oman’s Personal Data Protection Law (Royal Decree 6/2022), and any Kuwaiti privacy or e-transactions rules that apply. The EU GDPR and the UK GDPR are included only if we later offer the Service in the EEA or the UK.
- "Class Data" — Personal Data of Students, TAs, Parents, and any other natural persons that the Controller (Subscriber) places onto, generates through, or instructs Lurnnet to process within the Service in connection with a Class. Class Data does not include the Subscriber's own account, billing, and Subscription data, for which Lurnnet is the Controller.
- "Controller" — the Subscriber who has accepted Part A of the Subscriber Terms and who determines the purposes and means of processing the Class Data.
- "Personal Data" — has the meaning in PDPL Article 1.
- "Processing" — has the meaning in PDPL Article 1.
- "Processor" — Lurnnet, processing the Class Data on the Controller's documented instructions per this DPA.
- "Personal Data Breach" — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Class Data transmitted, stored, or otherwise processed by Lurnnet or its Sub-Processors.
- "Standard Contractual Clauses (SCCs)" — where a transfer of Class Data triggers Standard Contractual Clauses required under any Applicable Data Protection Law (for example, between Lurnnet and a Sub-Processor in a non-adequate jurisdiction), the SCCs published by the relevant regulator and incorporated by reference into the Sub-Processor agreement.
- "Sub-Processor" — any natural or legal person, public authority, agency, or body other than Lurnnet, the Controller, the Data Subject, or a person under the direct authority of any of the foregoing, who processes the Class Data on Lurnnet's behalf. The current list is published at
/legal/sub-processors. - "Effective Date" — 13 August 2026.
Capitalised terms not defined here have the meaning given in the Subscriber Terms or the Privacy Policy.
2. Roles, scope, and structure
2.1. Controller / Processor allocation
The Controller (Subscriber) and Lurnnet (Processor) confirm that:
- The Controller is the Subscriber for all Class Data processed under or in connection with the Subscriber's use of the Service.
- Lurnnet is the Processor for all Class Data and processes Class Data only on the Controller's documented instructions. The Subscriber Terms and this DPA, taken together, are the Controller's documented instructions; the Controller may issue further specific instructions inside the Service (for example, by configuring retention periods, by issuing a deletion on a specific Student, or by setting standing instructions for parent-DSR fulfilment).
- Lurnnet remains the Controller for: the Subscriber's own account, billing, subscription, support, and complaints data; Lurnnet's own service-operations data (telemetry, fault logs, performance metrics); the Lurnnet marketing list (where the Subscriber has separately consented); and any Personal Data the Subscriber does not place onto the Platform under the educational-service umbrella.
2.2. Subject matter
Lurnnet's processing of Class Data covers the delivery of the Service to the Controller and to the End Users in the Controller's Classes — including class management, content delivery, AI-tutor and AI-assisted features, AI-assisted grading that requires human review before a grade is final, performance analytics, in-Class messaging, push notifications, billing and subscription operations (where relevant), security, and audit.
2.3. Duration
This DPA enters into force on the Effective Date or, if later, on the date the Controller accepts the Subscriber Terms (which incorporate this DPA by reference). It remains in force for the duration of the Subscriber Terms, plus any post-termination period contemplated by §15 (deletion or return).
2.4. Order of precedence
Where this DPA conflicts with the Subscriber Terms on a topic this DPA addresses, this DPA controls. Where a Sub-Processor's flow-down terms differ from this DPA on a topic the Sub-Processor's terms address, Lurnnet remains responsible to the Controller for the level of protection set in this DPA.
3. Lawful basis, instructions, and lawful-purpose limit
3.1. The Controller's role
The Controller represents and warrants that:
(a) the Controller has a lawful basis under Applicable Data Protection Law for the processing of each category of Class Data (for under-18 Students, parental consent captured through the parent-email-confirmation flow described in §8; for older Users and for processing reasonably necessary to deliver the educational service to a Student under 18 within the lawful boundaries of the parental consent, what the law allows for delivering the class the parent agreed to);
(b) the Controller has provided the necessary information to Data Subjects (and, for under-18 Students, to their Parents through the Parent Notice) about the processing;
(c) the Controller's instructions to Lurnnet under this DPA do not infringe Applicable Data Protection Law.
3.2. Lurnnet's role
Lurnnet processes Class Data only on the documented instructions of the Controller, including with regard to transfers of Class Data to a country outside the country of habitual residence of the relevant Data Subject. The Subscriber Terms and this DPA (taken together) are the Controller's documented instructions; specific operational instructions may be given through the Service or through written communications to privacy@lurnnet.com confirmed by Lurnnet.
If Lurnnet considers that an instruction infringes Applicable Data Protection Law, Lurnnet will inform the Controller without undue delay (subject to any prohibition on disclosure imposed by law).
3.3. The single under-18 parental-consent threshold
The parties agree that the Controller will obtain parental consent for every Student under 18 — that is, the single under-18 threshold described in the Privacy Policy — regardless of whether Applicable Data Protection Law permits child-or-guardian consent for some sub-segment of that age range. Lurnnet operates the parent-email-confirmation flow on the Controller's behalf as the technical means.
3.4. Confidentiality
Lurnnet ensures that persons authorised to process the Class Data (Lurnnet personnel and, by flow-down, Sub-Processor personnel) are bound by confidentiality obligations with adequate scope and duration.
4. Categories of Personal Data and Data Subjects
4.1. Categories of Personal Data
| Category | Examples |
|---|---|
| Identity | Display name, email address, optional avatar, date of birth |
| Authentication | Hashed password and session data |
| Class membership | Class identifiers, role inside the Class (Student / TA), join date, status |
| Submissions | Student answers, exam responses, free-text inputs, uploaded files |
| AI-tutor | Prompt content, response content, safety-gate decision, audit metadata |
| Class activity | Assignment results, attendance, and related class use |
| Grades and feedback | AI-suggested grades, teacher-assigned grades, TA-assigned grades, feedback comments |
| In-Class messages | The contents of messages sent inside the Class |
| Push tokens | Device notification tokens, kept only as needed to deliver notifications |
| Parental-consent records | Confirmation time, hashed parent email, notice version, and child identifier |
4.2. Categories of Data Subjects
- Students — natural persons aged 13 and above who join a Class as learners.
- TAs — natural persons aged 18 and above appointed by the Controller to assist with Class management or grading. Lurnnet treats every TA as an adult. Appointing a TA under 18 is the Controller's breach.
- Parents (legal guardians) — natural persons who interact with Lurnnet through the parent-email-confirmation flow or through the email-only parent-DSR intake at
privacy@lurnnet.com. - Other natural persons the Controller places onto the Platform under the educational-service umbrella (e.g., guest speakers in a Class).
4.3. Categories Lurnnet does not process as Class Data
Lurnnet does not process plaintext payment-card data (payment partners handle cards directly), plaintext passwords, precise location data, or biometric templates.
5. Sub-Processors
5.1. The Sub-Processor list
Lurnnet's current Sub-Processor list — identity, purpose, and country — is published at /legal/sub-processors. That page is the live list. This DPA does not repeat vendor internals.
5.2. General authorisation and prior-notice mechanism
The Controller grants Lurnnet a general authorisation to engage the Sub-Processors listed at the Sub-Processor URL, on the terms of this §5. Lurnnet will give the Controller at least 30 calendar days' prior notice of any addition or replacement of a Sub-Processor processing Class Data. Notice is given in-app and by email.
5.3. Right to object (terminate for cause)
If the Controller objects to a new Sub-Processor on reasonable, lawful grounds, the Controller may, before the new Sub-Processor takes effect:
(a) submit the objection in writing to privacy@lurnnet.com with the specific basis for the objection; or
(b) terminate the Subscriber Terms and this DPA for cause and receive a pro-rated refund of any prepaid fees for the remaining unused period (this is the same right as Subscriber Terms §7).
5.4. Sub-Processor flow-down and due diligence
Lurnnet ensures that each Sub-Processor is bound by a written agreement that imposes obligations on the Sub-Processor that are substantively equivalent to those imposed on Lurnnet under this DPA, including security, sub-Sub-Processor management, breach notification within Lurnnet's onward-notice timeframe, audit cooperation, deletion or return on termination, and assistance with DSRs.
Lurnnet conducts due diligence on each Sub-Processor before engagement and on a periodic basis thereafter (no less than annually), assessing the Sub-Processor's security posture, data-protection maturity, and continued fit for purpose.
5.5. Lurnnet's responsibility for Sub-Processors
Lurnnet remains fully responsible to the Controller for the performance of each Sub-Processor's obligations as if Lurnnet had performed them itself, subject to the liability allocation in §16.
6. Security measures
6.1. Technical and organisational measures (TOMs)
Lurnnet implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as the PDPL requires. The measures include:
- Encryption in transit and at rest.
- Access controls and isolation between organisations.
- Secrets handling with separated environments.
- Audit logging of administrative actions.
- Password and account protections (including checks against known breaches and limits on repeated failed sign-ins).
- Additional verification for some accounts.
- Runtime monitoring for errors and abuse.
- Stricter automated AI checks for users under 17.
- Due diligence and written terms with Sub-Processors.
- Backup, continuity, and incident-response procedures, including breach notice as in §8.
- Personnel access on a need-to-know basis, with revocation when roles change.
- Periodic vendor review.
Lurnnet may update its TOMs from time to time provided the security level is not reduced. Material reductions follow the change-of-DPA process in §17.
6.2. PCI-DSS scope
Payment-card numbers are entered only with our payment partners and do not pass through Lurnnet. This applies to Subscriber-side billing only; Class Data does not include payment-card data.
6.3. Penetration testing and vulnerability management
Lurnnet conducts external penetration tests at least annually, manages vulnerabilities through a documented process, and addresses critical and high-severity vulnerabilities within Lurnnet's documented SLAs.
7. Lurnnet's parent-DSR support obligations
Lurnnet supports the Controller in fulfilling parent Data Subject Requests, in the time the PDPL and other Applicable Data Protection Law set.
7.1. Email intake
Lurnnet maintains an email intake at privacy@lurnnet.com for parent data-subject requests. A parent portal is not available yet.
7.2. The verification process
When a Parent emails privacy@lurnnet.com exercising a right under the PDPL (for example access, rectification, erasure, restriction, objection, or withdrawal of consent), Lurnnet:
- Acknowledges the request within 5 working days.
- Verifies identity against the parent-confirmation record from the flow in §8.
- Where the verification matches, Lurnnet routes the request to the Controller with enough context to act (request type, class, and student).
- Where the Controller has given documented standing instructions, Lurnnet acts on those instructions.
7.3. The Controller's response
The Controller responds to the Parent's request inside the time Applicable Data Protection Law sets (Lurnnet's operational target is 30 days unless a shorter statutory deadline applies), with Lurnnet's processor-side support. Lurnnet helps with export, deletion, and similar actions as instructed, including by email to privacy@lurnnet.com.
7.4. Where Lurnnet acts directly
For technical actions where Lurnnet has standing instruction (for example, automatic deletion on Parent withdrawal of consent), Lurnnet acts within the Controller's documented instruction. For all other actions, Lurnnet does not respond to the Parent on substance — only the Controller can decide the substantive outcome.
7.5. The consent-record audit log
The consent-record audit log captured through the parent-email-confirmation flow is owned by the Controller. The Controller may export the records through the Service or by email to privacy@lurnnet.com. Lurnnet retains the records as required by applicable children's-data rules, unless the Controller instructs a shorter retention.
8. The parent-email-confirmation flow (Lurnnet's processor-side technical means)
Lurnnet operates the parent-email-confirmation flow on the Controller's behalf as Processor, in compliance with the Controller's documented instruction (this DPA + the Subscriber's acceptance of the residency and sub-processor picture under Subscriber Terms §4).
8.1. The flow
- The Student installs the app, enters their date of birth at signup, and creates an account.
- If the date of birth indicates the Student is under 18, the next signup screen requires the Parent's email address.
- Lurnnet generates the Parent Notice (English and Arabic, server-side PDF, version
v1.0) and emails it to the Parent. The Parent Notice contains: the description of the Service, the Residency and Sub-Processor Disclosure, the categories of Personal Data Lurnnet processes for the Student under the Controller's instruction, the parental-consent confirmation request with a one-click link valid for 7 days, and the parent-rights summary. - Until the Parent confirms, the Student account stays inactive — no class membership and no AI features.
- When the Parent confirms, Lurnnet captures the consent record described in §4.1.
- The Controller can export the consent records through the Service or by email to
privacy@lurnnet.com. - Where the Parent does not confirm within 7 days, Lurnnet sends the Notice once more. Still no confirmation, the pending Student account is automatically deleted after 30 days.
- Where the Parent withdraws consent, Lurnnet routes the withdrawal to the Controller within 5 working days and applies the Controller's standing instructions for processing withdrawal — by default, the Student account and Personal Data are erased within 30 days, or sooner if Applicable Data Protection Law requires.
8.2. The decision is the Controller's; the technical means is Lurnnet's
The decision that parental consent is required is the Controller's, formalised through Subscriber Terms §12 and this DPA. The responsibility for consent quality (was the Parent given enough information; did the Parent meaningfully understand the disclosure) remains with the Controller. Lurnnet's role is to provide the technical mechanism and to capture the audit evidence. Lurnnet cannot prevent a Student or TA from entering a false date of birth; verifying roster ages remains the Controller's responsibility. This allocation does not shift Lurnnet's role from Processor to Controller for the consent processing.
9. Personal-Data breach notification
9.1. Lurnnet's notification to the Controller
Lurnnet notifies the Controller without undue delay and within 72 hours of becoming aware of a Personal-Data Breach affecting Class Data.
The notification, to the extent reasonably practicable at the time of notification, includes:
(a) a description of the nature of the Breach (categories and approximate number of Data Subjects affected; categories and approximate number of Personal Data records affected);
(b) the name and contact details of the data-protection contact (privacy@lurnnet.com) or other point of contact where more information can be obtained;
(c) a description of the likely consequences of the Breach;
(d) a description of the measures taken or proposed by Lurnnet to address the Breach, including, where appropriate, measures to mitigate its possible adverse effects.
Where it is not possible to provide all the information at the same time, the information may be provided in phases without undue further delay.
9.2. Cooperation
Lurnnet cooperates with the Controller in the Controller's onward notification to the regulator (the PDPC and / or equivalent in the relevant jurisdiction) and, where required, to the Data Subjects (or their Parents). Lurnnet provides the documentation and information reasonably required for the Controller to discharge its own breach-notification obligations.
9.3. Data Subject notification
Where the Breach is likely to result in a high risk to the rights of Data Subjects, the Controller communicates the Breach to the Data Subjects without undue delay, as Applicable Data Protection Law requires. Lurnnet supports with the technical means (notification mechanisms inside the Service) and the categorical information.
9.4. Records
Lurnnet maintains a record of all Personal-Data Breaches, including the facts, the effects, and the remedial action taken. The records are available to the Controller on reasonable request.
10. Audit rights
10.1. Documentation-based audit
The Controller has the right, on reasonable advance notice and at most once per calendar year, to request:
- a copy of Lurnnet's most recent independent third-party audit (where available);
- a security-summary documentation pack describing Lurnnet's TOMs at the relevant point in time;
- copies of Sub-Processor due-diligence summaries (subject to Sub-Processor confidentiality where applicable);
- records of recent penetration tests (subject to redaction of vulnerability details that have not yet been remediated);
- records of relevant audit-log entries on the Controller's own Class Data (provided as an export on request).
The documentation-based audit is the primary audit mechanism for this DPA, in line with industry practice for B2C SaaS at scale.
10.2. On-site or on-systems audit (exceptional)
Where the documentation-based audit is insufficient and the Controller has reasonable grounds to believe Lurnnet is in material breach of this DPA, the Controller may request an on-site or on-systems audit by an independent third-party auditor. Such audits:
(a) require at least 30 calendar days' written notice to Lurnnet;
(b) are subject to the auditor signing reasonable confidentiality and security undertakings;
(c) take place during Lurnnet's normal business hours and do not unreasonably interfere with Lurnnet's operations;
(d) are conducted at the Controller's expense, except where the audit reveals a material breach of this DPA by Lurnnet, in which case Lurnnet bears the reasonable cost of the audit.
10.3. Cooperation with regulator audits
Lurnnet cooperates with the PDPC, SDAIA, the UAE Data Office, the Bahrain Personal Data Protection Authority, and the competent authorities in Qatar, Oman, and Kuwait in any audit or inquiry directed at the Controller's processing of Class Data, providing reasonable assistance to the Controller in responding.
11. Cross-border transfers
11.1. Cross-border transfers
Class Data may be processed by Sub-Processors located outside the country of habitual residence of the relevant Data Subject. Transfers use written contracts with those companies, and the transfer rules that apply. Egyptian PDPL restricts storing or transferring personal data abroad without Centre approval. We do not currently hold that approval. We will obtain it before relying on it.
The live Sub-Processor list is at /legal/sub-processors. By incorporating this DPA, the Controller authorises the transfers needed to deliver the Service through that list.
11.2. Sub-Processor flow-down DPAs
For each Sub-Processor processing Class Data outside the Data Subject's country of habitual residence, Lurnnet has executed a flow-down DPA that obliges the Sub-Processor to maintain a level of protection substantively equivalent to this DPA. Lurnnet provides copies of the flow-down terms (subject to Sub-Processor confidentiality) on the Controller's request.
11.3. Bahrain whitelist
Bahrain Resolution 42/2022 publishes a whitelist of countries for certain transfers. Egypt, Germany, the Netherlands, Ireland, and the United States appear on the published list. Hosting in the EU and limited US processing for AI and some security checks are disclosed on the Sub-Processor list. Transfers still use contracts and any approvals required.
11.4. Additional approvals
Where a regulator requires a per-Controller approval instead of (or in addition to) Lurnnet’s own filings, Lurnnet will notify the Controller and will work in good faith to support that application.
12. The Controller's obligations
The Controller represents and warrants throughout the term of this DPA that:
12.1. Lawful authority
The Controller has lawful authority under Applicable Data Protection Law to: (a) instruct Lurnnet to process the Class Data; (b) invite each Student and TA into the Service; (c) decide each lawful basis applied; (d) determine retention periods within the educational purpose.
12.2. Parental consent
For every Student under 18, the Controller obtains parental consent through the parent-email-confirmation flow described in §8 before the Student can use the Service inside a Class. The Controller is responsible for the quality of that consent (was the Parent given enough information; did the Parent meaningfully understand the disclosure).
The Controller takes reasonable steps to verify that dates of birth on the roster are true. A date of birth entered at signup is a technical gate, not a guarantee of true age. If a Student or TA enters a false date of birth and bypasses the parent-email-confirmation flow, that failure is the Controller's, not Lurnnet's.
12.3. The Parent Notice and Residency Disclosure
The Controller agrees that Lurnnet will, on the Controller's behalf as Processor, deliver the Parent Notice — including the Residency and Sub-Processor Disclosure — to each Parent at the parent-email-confirmation step. The Controller re-confirms the Residency and Sub-Processor Disclosure on each Parent's behalf as Controller.
12.4. Retention
The Controller decides retention within the educational purpose. Defaults are described in the Privacy Policy. The Controller may instruct Lurnnet to apply a shorter retention (including by email to privacy@lurnnet.com). The Controller acknowledges that retention beyond the educational purpose is not permitted.
12.5. TA appointments
The Controller appoints only adult TAs (18 or older). Lurnnet treats every TA as an adult. If the Controller appoints a TA under 18, that appointment — including any processing of other Students' Personal Data by that TA — is the Controller's breach, not Lurnnet's. The Controller may request records of TA actions.
12.6. Disclosure to third parties
The Controller will not disclose Class Data to a third party outside Lurnnet's Sub-Processor chain except (a) where the Data Subject (or, for under-18 Students, the Parent) has consented; (b) where required by law and the Controller has first sought legal advice; (c) where the disclosure is to the Class's institutional sponsor under a separate written agreement that meets the standard of this DPA. The Controller will inform Lurnnet of any compelled disclosure where lawfully able to do so.
12.7. Cooperation
The Controller cooperates with Lurnnet on matters touching this DPA, including responding to Lurnnet's requests for documented instructions, providing reasonable evidence of the Controller's own controller-side compliance when needed for Lurnnet to defend a regulatory inquiry, and giving Lurnnet reasonable advance notice of any change of Controller (for example, transferring a Class roster to another teacher).
12.8. Regulator inquiries directed at the Controller
The Controller responds as Controller to regulator inquiries from the PDPC, SDAIA, the UAE Data Office, the Bahrain Personal Data Protection Authority, and the competent authorities in Qatar, Oman, and Kuwait. Lurnnet supports under §7 (parent-DSR), §9 (breach notification cooperation), and §10 (audit cooperation).
12.9. Insurance and recordkeeping
The Controller maintains records of processing as Applicable Data Protection Law requires and retains evidence of consent and Controller-side decisions for the period legally required.
13. Lurnnet's processor and children's-data obligations
In addition to the obligations elsewhere in this DPA, Lurnnet undertakes — as Processor under the PDPL, including for children's data — to:
13.1. Process only on documented controller-instruction
Process Class Data only on the Controller's documented instructions, including with regard to transfers of Class Data to a country outside the country of habitual residence of the relevant Data Subject; or where required by Applicable Data Protection Law to which Lurnnet is subject (in which case Lurnnet informs the Controller of the legal requirement before processing, unless the law prohibits such information on important grounds of public interest).
13.2. Assist the Controller with DSRs
Assist the Controller, by appropriate technical and organisational measures, to fulfil the Controller's obligation to respond to Data Subject Requests, including the parent-DSR support described in §7.
13.3. Assist with breach notification
Assist the Controller in meeting security and breach-notification duties under Applicable Data Protection Law — including notifying the Controller within 72 hours, providing the documentation in §9.1, and cooperating with the Controller's onward notification.
13.4. Assist with DPIAs
Assist the Controller in carrying out data-protection impact assessments where the relevant processing requires one under Applicable Data Protection Law.
13.5. Cooperate with PDPC and MENA-equivalent regulators
Cooperate, on the Controller's request, with regulator inquiries and audits.
13.6. Children's-data safeguards
Apply the children's-data safeguards relevant to Lurnnet's Processor role, including stricter automated AI checks for under-17 End Users, no marketing to Parents, and no use of Class Data to train third-party AI models.
13.7. Confidentiality
Ensure that personnel authorised to process Class Data are bound by confidentiality obligations.
14. International transfers — assistance to Controller
Where the Controller's onward processing of Class Data involves an international transfer outside the country of habitual residence of the Data Subject (other than the cross-border transfers Lurnnet effects through its Sub-Processor chain), Lurnnet supports the Controller's compliance with Applicable Data Protection Law by:
(a) providing copies of Lurnnet's relevant Sub-Processor flow-down DPAs;
(b) providing documentation of any approvals we hold, or supporting the Controller's own application where required;
(c) providing the security-summary documentation referenced in §10;
(d) providing technical measures such as encryption, access controls, and audit records.
15. Termination, deletion, and return
15.1. Termination
This DPA terminates automatically upon the termination of the Subscriber Terms.
15.2. Deletion or return
Within 30 calendar days after termination, Class Data is held in a restricted state (export, transfer, or deletion only — not ordinary teaching use). Retrieval and export in that window are the Controller's sole responsibility. Lurnnet is not a backup or archive. At the Controller's choice (instructed by email to privacy@lurnnet.com or through account tools when available), Lurnnet:
(a) deletes all Class Data, including from backup media (as backup expiry permits — typically within 90 days of deletion from primary systems); or
(b) returns all Class Data to the Controller in a machine-readable format; or
(c) transfers all Class Data to a successor Controller (another teacher) under their separate Subscriber Terms.
Default at the end of the 30-day window, where the Controller has not instructed otherwise, is permanent deletion. That deletion includes teaching materials the Controller uploaded. The Controller was on notice to export. Lurnnet has no obligation to restore Class Data after the window.
15.3. Sub-Processor deletion
Lurnnet flows down the deletion / return / transfer instruction to the Sub-Processors processing Class Data, in compliance with the timelines in each Sub-Processor's flow-down DPA.
15.4. Retained anonymised metadata
Lurnnet may retain anonymised, aggregated metadata necessary for legitimate Lurnnet-controller purposes (security, audit, fraud prevention) after termination. Such metadata is no longer Personal Data.
15.5. Legal retention
Lurnnet may retain Class Data, on a restricted-access basis, where required by law (for example, parental-consent records as required by applicable children's-data rules; tax-related records for the period set in Egyptian VAT Law no. 67 of 2016).
15.6. Survival
Sections 1, 6 (security), 9 (breach notification — for Breaches occurring before termination), 10 (audit, to a reasonable degree), 13 (Lurnnet's processor and children's-data obligations), 15 (this section), and 16 (liability allocation) survive termination.
16. Liability allocation
16.1. Mirroring the Subscriber Terms cap
Each party's liability under this DPA is capped per Subscriber Terms §11, subject to the carve-outs in that section. For clarity:
- Lurnnet's liability to the Controller under this DPA is capped at the greater of (a) the fees paid by the Controller to Lurnnet for one month of the service (for an annual plan, one-twelfth of that year’s fee), or (b) USD 500.
- The Controller's liability to Lurnnet under this DPA is capped at the same cap, subject to the carve-outs in Subscriber Terms §11, including that the Controller's liability for failing to obtain lawful parental consent is not capped (including a Student or TA who entered a false date of birth, and a TA under 18 the Controller appointed), and that the Controller's liability for grading and academic decisions (including those that used AI) is not capped.
16.2. Indemnity allocation
The indemnity allocation in Subscriber Terms §11 applies in full to this DPA, with no double-counting.
16.3. Statutory processor liability
Nothing in this DPA limits Lurnnet's separate, statutory liability to Data Subjects under Applicable Data Protection Law for processor-side breaches. Where Lurnnet is held liable to a Data Subject under those provisions, Lurnnet may seek contribution from the Controller for the portion of the loss attributable to the Controller's breach.
17. Updates to this DPA
17.1. Notice
Lurnnet may update this DPA from time to time. Lurnnet will give the Controller at least 30 calendar days' notice of the update, by in-app notice and email.
17.2. Material vs non-material changes
Material changes (changes that materially reduce the Controller's rights, materially expand processing scope, materially weaken security commitments, materially alter the liability allocation, or add a Sub-Processor processing data outside the categories already covered) require the Controller's active re-acceptance. Lurnnet will mark such changes clearly in the change notice.
Non-material changes take effect on continued use after the notice period.
17.3. Right to terminate for non-acceptance of material change
If the Controller does not accept a material change, the Controller may terminate the Subscriber Terms and this DPA before the change takes effect, with a pro-rated refund of any prepaid fees for the remaining unused period.
18. Governing law and jurisdiction
This DPA is governed by the laws of the Arab Republic of Egypt, without reference to its conflict-of-laws rules. Any formal legal proceedings arising under or in connection with this DPA must be brought in the courts of Cairo, Egypt, which have exclusive jurisdiction to the maximum extent local law permits. Nothing in this DPA displaces non-waivable rights under Applicable Data Protection Law in any other jurisdiction, including the right to complain to a competent data-protection authority.
19. Notices under this DPA
| To | At |
|---|---|
| The Controller | The email address registered to the Subscriber's Lurnnet account, plus in-app notice |
| Lurnnet (general DPA matters) | privacy@lurnnet.com |
| Lurnnet's data-protection contact | privacy@lurnnet.com |
| Lurnnet (legal notices, formal) | support@lurnnet.com with the subject line "LEGAL NOTICE", with a copy to privacy@lurnnet.com (a postal address for service will be published upon entity incorporation) |
20. Miscellaneous
20.1. Counterparts. This DPA is concluded electronically by the Controller's acceptance of the Subscriber Terms (which incorporate this DPA by reference under Subscriber Terms §1). Acceptance constitutes a signed counterpart under Egypt’s e-signature rules.
20.2. Severability. If a provision of this DPA is held unenforceable, the rest remains in force, and the unenforceable provision is interpreted as closely as possible to the original intention while being enforceable.
20.3. No third-party rights. Save for Data Subjects exercising statutory rights under Applicable Data Protection Law, no person other than the Controller and Lurnnet has any right under this DPA. Lurnnet's Affiliates and Sub-Processors are intended beneficiaries only of the parts of §16 (liability allocation) and §15 (deletion / return) that explicitly extend to them.
20.4. Entire agreement on Processor obligations. This DPA, together with the Subscriber Terms and the Privacy Policy, is the entire agreement between the Controller and Lurnnet on the Processor obligations, and supersedes any prior representations on those obligations.
20.5. Headings. Headings are for convenience only and do not affect interpretation.
20.6. Language. This English version applies until an Arabic version is published for Subscribers in Egypt. If the two conflict, the Arabic version controls for those Subscribers; otherwise the English version controls.
Effective date: 13 August 2026
Version: 1.2.0
Document URL: /legal/data-processing-agreement
Companion documents: Terms of Service /legal/terms · Privacy Policy /legal/privacy · Sub-Processor list /legal/sub-processors · Cookie Policy /legal/cookies · AUP /legal/acceptable-use · AI Features Disclosure /legal/ai-features · EULA /legal/eula · Subscription Terms /legal/subscription · Refund and Cancellation Policy /legal/refunds