Legal

Data Processing Addendum

Effective Date: April 28, 2026

Cues Technologies Inc.  |  9171 Wilshire Blvd, Ste 500, Beverly Hills, CA 90210

hello@gradingpal.com

This Data Processing Addendum (“DPA”) supplements and forms part of the agreement between Cues Technologies Inc. (“GradingPal”) and the Educational Institution or (where applicable) a Teacher in relation to the transfer and processing of Covered Data in connection with the provision of the Service.

1. Definitions

1.1 Unless otherwise defined in this DPA, capitalized terms used but not defined within this DPA will have the meaning set forth in the Agreement. The following capitalized terms used in this DPA will be defined as follows:

"Agreement" means the agreement entered into between GradingPal and the Customer incorporating the terms at www.gradingpal.com/terms or as otherwise agreed between the parties.
"Applicable Data Protection Laws" means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time, including (without limitation) the GDPR.
"Authorized Sub-processor" means the Sub-processors listed in Schedule 4 of this DPA, and any other Sub-processors appointed in accordance with paragraph 7.4.
"Controller Purposes" means: (a) undertaking internal research and development to develop, test, improve and alter the functionality of GradingPal's products and services; (b) creating fully de-identified and anonymized datasets for evaluation and quality assessment of GradingPal's products and services, provided that such datasets contain no Student Data or other personally identifiable information; and (c) administering Customer accounts on the Service and managing GradingPal's relationship with the Customer under the Agreement, in each case as further described in Schedule 1. For the avoidance of doubt, GradingPal does not use Student Data or personally identifiable information to train its AI models or those of its sub-processors.
"Covered Data" means Personal Data that is: (a) provided by or on behalf of the Customer to GradingPal in connection with the provision of the Service; or (b) obtained, developed, produced or otherwise Processed by GradingPal, or its agents or subcontractors, for the purposes of providing the Service, in each case as further described in Schedule 1.
"Customer" means the Educational Institution or a Teacher that enters into the Agreement with GradingPal in relation to the Service.
"Data Subject" has the meaning given to it in the GDPR.
"Effective Date" means the date GradingPal and the Customer enter into the Agreement.
"GDPR" means Regulation (EU) 2016/679 (the "EU GDPR") or, where applicable, the "UK GDPR", as defined in section 3(10) of the Data Protection Act 2018.
"Personal Data" has the meaning given to it in the GDPR.
"Processing" has the meaning given to it in the GDPR, and "Process", "Processes" and "Processed" will be interpreted accordingly.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to (including unauthorized internal access to), Covered Data.
"Lawful Transfer Mechanism" means any mechanism recognised under Applicable Data Protection Laws as providing an adequate basis for the international transfer of Personal Data, including adequacy decisions, certification under an approved data privacy framework (such as the EU-US Data Privacy Framework or UK-US Data Bridge), standard contractual clauses, binding corporate rules, or such other mechanisms as may be recognised under applicable law from time to time.
"Sub-processor" means a processor engaged by another processor to carry out the instructions of the controller.
"Swiss Data Protection Laws" means the Swiss Federal Act on Data Protection of 25 September 2020 ("FADP") and the Swiss Data Protection Ordinance of 31 August 2022, and any new or revised version of these laws that may enter into force from time to time.

1.2 The terms “controller” and “processor” have the meanings given to them in the GDPR.

2. Interaction with the Agreement

2.1 This DPA is incorporated into and forms an integral part of the Agreement. This DPA supplements and (in case of contradictions) supersedes the Agreement with respect to any Processing of Covered Data.

3. Role of the Parties

3.1 The Parties acknowledge and agree that:

  1. save as set out in paragraph 3.1(b), GradingPal Processes Covered Data as a processor in the performance of its obligations under the Agreement and this DPA, and Customer acts as a controller; and
  2. GradingPal acts as a controller with respect to the Processing of Covered Data for the Controller Purposes as identified in Schedule 1.

4. Details of Data Processing

4.1 The details of the Processing of Personal Data under the Agreement and this DPA (including subject matter, nature and purpose of the Processing, categories of Personal Data and Data Subjects) are described in the Agreement and in Schedule 1 to this DPA.

4.2 Other than in respect of its Processing of Covered Data for the Controller Purposes:

  1. GradingPal will only Process Covered Data under the instructions provided by the Customer and in accordance with Applicable Data Protection Laws; and
  2. the Agreement and this DPA shall constitute the instructions to GradingPal for the Processing of Covered Data by GradingPal, and the Customer may issue further written instructions in accordance with this DPA.

4.3 GradingPal will:

  1. provide the Customer with information to enable the Customer to conduct and document any data protection impact assessments and prior consultations with supervisory authorities required under Applicable Data Protection Laws; and
  2. promptly inform the Customer if, in its opinion, an instruction from the Customer infringes Applicable Data Protection Laws.

5. Compliance

5.1 The Customer shall comply with its obligations under Applicable Data Protection Laws and shall ensure that:

  1. any instructions to GradingPal in relation to the Processing of Covered Data comply with Applicable Data Protection Laws;
  2. it provides such information to Data Subjects regarding the Processing of Covered Data by GradingPal as required under Applicable Data Protection Laws; and
  3. it promptly notifies GradingPal of any request received from a Data Subject to exercise their rights under Applicable Data Protection Laws.

6. Confidentiality and Disclosure

6.1 GradingPal shall:

  1. limit access to Covered Data to personnel who have a business need to have access to such Covered Data; and
  2. ensure that such personnel are subject to obligations at least as protective of the Covered Data as the terms of this DPA and the Agreement, including duties of confidentiality with respect to any Covered Data to which they have access.

7. Sub-Processors

7.1 GradingPal may Process Covered Data anywhere that GradingPal or its Sub-processors maintain facilities, subject to the remainder of this paragraph 7. Covered Data is processed and stored on infrastructure located in the United States and other jurisdictions where GradingPal and its Sub-processors operate. GradingPal ensures that any international transfer of Covered Data is made in accordance with Applicable Data Protection Laws and the requirements of Schedule 3 of this DPA.

7.2 The Customer grants GradingPal general authorization to engage any Authorized Sub-processor listed in Schedule 4 to Process Covered Data.

7.3 GradingPal shall:

  1. use commercially reasonable efforts to ensure that each Authorized Sub-processor maintains appropriate data protection standards consistent with applicable law and the nature of the Covered Data processed; and
  2. remain liable for each Authorized Sub-processor's compliance with the obligations under this DPA.

7.4 GradingPal maintains a current list of Authorized Sub-processors at www.gradingpal.com/sub-processors. GradingPal will update this page prior to adding or replacing any sub-processor and will notify institutional Customers of material changes to the sub-processor list upon request. If the Customer has a reasonable objection to the addition or replacement of a sub-processor, it may notify GradingPal in writing and the parties will work together in good faith to address the concern.

8. Data Subject Rights Requests

8.1 GradingPal will notify the Customer without undue delay of any request received by GradingPal or any Authorized Sub-processor from a Data Subject to assert their rights under Applicable Data Protection Laws in relation to Covered Data Processed by GradingPal as a processor or sub-processor (a “Data Subject Request”).

8.2 Other than in respect of GradingPal's Processing of Covered Data for the Controller Purposes, as between GradingPal and the Customer, the Customer will have sole discretion in responding to the Data Subject Request. GradingPal shall not respond to the Data Subject Request without the Customer's prior consent, save that GradingPal may advise the Data Subject that their request has been forwarded to the Customer.

8.3 GradingPal will provide the Customer with reasonable assistance as necessary for the Customer to fulfil its obligation under Applicable Data Protection Laws to respond to Data Subject Requests in respect of Covered Data.

9. Security

9.1 GradingPal will implement and maintain appropriate technical and organizational data protection and security measures designed to ensure security of Covered Data, including protection against unauthorized or unlawful Processing and against accidental loss, destruction, or damage of or to Covered Data.

9.2 When assessing the appropriate level of security, GradingPal shall take into account the nature, scope, context and purpose of the Processing as well as the risks presented by the Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Covered Data.

9.3 GradingPal will implement and maintain as a minimum standard the measures set out in Schedule 2.

10. Information and Audits

10.1 The Customer may audit GradingPal's compliance with this DPA in respect of its Processing of Covered Data. The Parties agree that all such audits will be conducted:

  1. not more than annually, unless more frequent audits are required by a supervisory authority with jurisdiction over the Processing of Covered Data or otherwise under Applicable Data Protection Laws;
  2. upon reasonable written notice to GradingPal;
  3. only during GradingPal's normal business hours; and
  4. in a manner that does not materially disrupt GradingPal's business or operations.

10.2 With respect to any audits conducted in accordance with this paragraph:

  1. the Customer may engage a third-party auditor to conduct the audit on its behalf, save that GradingPal may reasonably object to the engagement of a third-party auditor if such third-party auditor is a competitor of GradingPal; and
  2. GradingPal shall not be required to facilitate any such audit unless and until the Parties have agreed in writing the scope and timing of such audit.

10.3 The Customer shall promptly notify GradingPal of any non-compliance discovered during an audit. The results of the audit shall be GradingPal's confidential information.

10.4 GradingPal shall provide to the Customer upon request, or may provide in response to any audit request, either: (a) data protection compliance certifications issued by a commonly accepted certification issuer which has been audited by a data security expert or publicly certified auditing company; or (b) such other documentation reasonably evidencing the implementation of the technical and organizational data security measures in accordance with industry standards.

10.5 If an audit requested by the Customer is addressed in the documents or certification provided by GradingPal, and: (a) the certification or documentation is dated within twelve (12) months of the Customer's audit request; and (b) GradingPal confirms that there are no known material changes in the controls audited — the Customer agrees to accept that certification or documentation in lieu of conducting a physical audit of the controls covered.

11. Security Incidents

11.1 GradingPal shall notify the Customer in writing without undue delay after becoming aware of any Security Incident.

11.2 GradingPal shall take reasonable steps to contain, investigate, and mitigate any Security Incident, and shall send the Customer timely information about the Security Incident, to the extent known to GradingPal or as the information becomes available, including but not limited to: the nature of the Security Incident; the measures taken to mitigate or contain the Security Incident; and the status of the investigation.

11.3 GradingPal shall provide reasonable assistance with the Customer's investigation of any Security Incidents and any of the Customer's obligations in relation to the Security Incident under Applicable Data Protection Laws, including any notification to Data Subjects or supervisory authorities.

11.4 GradingPal's notification of or response to a Security Incident under this paragraph 11 shall not be construed as an acknowledgement by GradingPal of any fault or liability with respect to the Security Incident.

12. Term, Deletion and Return

12.1 This DPA shall commence on the Effective Date and, notwithstanding any termination of the Agreement, will remain in effect until, and automatically expire upon, GradingPal's deletion of all Covered Data as described in this DPA.

12.2 GradingPal shall:

  1. if requested to do so by the Customer within thirty (30) days of expiry of the Agreement (the “Retention Period”), provide a copy of all Covered Data in such commonly used format as requested by the Customer, or provide a self-service functionality allowing the Customer to download such Covered Data; and
  2. on expiry of the Retention Period, delete all copies of Covered Data Processed by GradingPal or any Authorized Sub-processors, other than any Covered Data that GradingPal is required to retain to comply with applicable law, to pursue or defend legal claims, or for the Controller Purposes.

13. International Transfers

13.1 GradingPal ensures that any transfer of Covered Data outside the EEA, UK, or other jurisdiction from which the Customer transfers data, is made in accordance with Applicable Data Protection Laws, including by relying on a Lawful Transfer Mechanism as defined in clause 1.1 of this DPA and as further described in Schedule 3.

13.2 GradingPal will promptly inform the Customer if, in its reasonable opinion, a change in Applicable Data Protection Laws means that GradingPal can no longer provide a Lawful Transfer Mechanism for the international transfer of Covered Data, and the parties will work together in good faith to identify an alternative lawful basis for the transfer.

Schedule 1: Details of Processing

A. List of Parties

Customer (Data Exporter)GradingPal (Data Importer)
RoleData exporter (controller)Data importer (controller / processor)
Contact personThe administrator of the Customer's account as notified to GradingPal.hello@gradingpal.com
Activities relevant to the transferThe performance of the Agreement.The performance of the Agreement.

B. Description of Processing

Data SubjectsCategories of Personal DataSensitive DataPurpose of Processing
Main points of contact for accounts held by Educational Institutions (Account Administrators)Contact information: name, email address, name of Educational Institution. Account preferences. Questions and correspondence submitted in relation to the Service.NoneCommunicating with Account Administrators in relation to the administration of the Agreement and the relationship between the parties. Sending promotional emails in accordance with Account Administrator preferences. Identifying ways to improve the Service.
Teachers with accounts associated with, authorized by, or paid for by an Educational Institution (Teachers on School Accounts)Contact information: name, email address, name of Educational Institution. Account preferences for service-related messages. Account tier. Questions and correspondence. Subjects taught and student year groups or grades. Content and materials created through the Service, including graded assignments and AI-generated feedback. Feedback in relation to content generated through the Service. Features and functionalities used on the Service.None, unless contained in content and materials generated through, or prompts or feedback submitted to the Service.Provision of access to the features and functionalities of the Service, including personalization. Provision of service-related communications. Provision of technical support. Distribution of promotional emails in accordance with data subject preferences. Informing product development and improvement.
Teachers with individual accounts not associated with, authorized by, or paid for by an Educational Institution (Independent Teachers)Contact information, account tier, payment information (processed by Stripe). Account preferences. Questions and correspondence. Subjects taught and student year groups or grades. Content and materials created through the Service. Websites visited in respect of which the Service is activated. Feedback in relation to content generated. Features and functionalities used on the Service. Device used to access the Service (IP address).None, unless contained in content and materials generated through, or prompts or feedback submitted to the Service.Provision of access to the features and functionalities of the Service, including personalization. Processing subscription payments. Provision of service-related communications. Provision of technical support. Distribution of promotional emails in accordance with data subject preferences. Informing product development and improvement.
StudentsIdentity (name, email address); academic information (grade level, subject, course name); submitted assignments and coursework across all supported content types; AI-generated grades and feedback; performance analytics; technical data (IP address, device information). Where a teacher has connected Google Classroom, data may also be read from or written back to Google Classroom.Any sensitive personal data contained in work product uploaded to the Service by the Student.Provision of AI-powered grading and feedback. Generating performance analytics. Reading from and writing scores and feedback to Google Classroom on teacher instruction. Service security and operation.
All usersDevice used to access the Service, such as IP address.NoneProvision of access to the features and functionalities of the Service. Ensuring the security and integrity of the Service.

C. Competent Supervisory Authority

For transfers of Covered Data from customers located in the European Economic Area, the competent supervisory authority is the Irish Data Protection Commissioner, unless otherwise required by applicable law.

For transfers of Covered Data from customers located in the United Kingdom, the competent supervisory authority is the UK Information Commissioner's Office (ICO), acting independently under the UK GDPR and the Data Protection Act 2018.

Schedule 2: Technical and Organizational Measures

GradingPal employs a combination of policies, procedures, guidelines and technical and physical controls to protect the Personal Data it processes from accidental loss and unauthorized access, disclosure or destruction.

Governance and Policies

  • GradingPal assigns personnel with responsibility for the determination, review and implementation of security policies and measures.
  • GradingPal has documented its security measures in a security policy and/or other relevant guidelines and documents, and reviews its security measures on a regular basis to ensure they continue to be appropriate for the data being protected.
  • GradingPal establishes and follows secure configurations for systems and software and ensures that security measures are considered during project initiation and the development of new IT systems.

Breach Response

  • GradingPal has a breach response plan that has been developed to address data breach events. The plan is regularly tested and updated.
  • In the event of a Security Incident, GradingPal will notify affected Customers without undue delay in accordance with applicable law and this DPA.

Intrusion, Anti-Virus and Anti-Malware Defences

  • GradingPal's IT systems used to process Personal Data have appropriate data security software installed, including industry standard firewall, anti-virus, anti-malware and intrusion detection systems.
  • GradingPal collects, maintains and reviews event logs to identify suspicious activity.

Access Controls

  • Limiting administrative access privileges and use of administrative accounts.
  • Changing all default passwords before deploying operating systems, assets or applications.
  • Requiring authentication and authorization to gain access to IT systems.
  • Implementing least privilege access to IT systems.
  • Maintaining appropriate procedures for controlling the allocation and revocation of Personal Data access rights, including revoking employee access when they leave or change role.
  • Using multi-factor authentication to access data on GradingPal's systems.
  • Automatically timing out and locking user terminals if left idle.
  • Blocking access to IT systems after multiple failed authentication attempts.
  • Monitoring and logging access to and amendments of IT systems.

Availability and Back-Up of Personal Data

  • GradingPal has a documented disaster recovery plan that ensures that key systems and data can be restored in a timely manner in the event of a physical or technical incident. The plan is regularly tested and updated.
  • GradingPal regularly backs up information on IT systems and keeps back-ups in separate locations. Back-ups are tested regularly.

Segmentation of Personal Data

  • GradingPal separates and limits access between network components and, where appropriate, implements measures to provide for separate processing of Personal Data collected and used for different purposes.
  • GradingPal does not use live data for testing its systems.

Encryption

  • GradingPal encrypts data at rest using AES-256 and in transit using TLS 1.2 or higher.
  • Encryption keys are stored separately from the encrypted information.

Transmission or Transport of Personal Data

  • GradingPal implements appropriate controls to secure Personal Data during transmission or transit, including encryption in transit and logging Personal Data when transmitted electronically.

Asset and Software Management

  • GradingPal maintains an inventory of IT assets and the data stored on them, together with a list of owners of the relevant IT assets.
  • GradingPal requires network level authentication and uses client certificates to validate and authenticate systems.
  • GradingPal deploys automated patch management tools and software update tools for operating systems and software, and proactively monitors software vulnerabilities.
  • GradingPal stores API keys securely in environment variables and does not store API keys on the client side or publish them in public code repositories.

Staff Training and Awareness

  • GradingPal's agreements with staff and contractors set out information security responsibilities.
  • GradingPal carries out regular staff training on data security and privacy issues and ensures new starters receive appropriate training before they begin their role.
  • GradingPal conducts appropriate screening and background checks on individuals who have access to sensitive Personal Data.
  • Staff are subject to disciplinary measures for breaches of GradingPal's policies and procedures relating to data privacy and security.

Selection of Service Providers

  • GradingPal assesses service providers' ability to meet its security requirements before engaging them.
  • GradingPal has written contracts in place with service providers requiring them to implement appropriate security measures to protect the Personal Data they have access to and to limit the use of Personal Data in accordance with GradingPal's instructions.

Assistance with Data Subject Rights Requests

  • GradingPal maintains accurate records to enable it to identify quickly all Personal Data processed on behalf of the Customer.
  • Back-ups of Personal Data processed by GradingPal on behalf of the Customer are overwritten on a regular basis and in any event every thirty (30) days to ensure deletion and rectification requests are fully actioned.

Schedule 3: International Data Transfers

This Schedule describes how GradingPal ensures that international transfers of Covered Data are made lawfully in accordance with Applicable Data Protection Laws.

1. General Commitment

GradingPal ensures that any transfer of Covered Data outside the EEA, UK, Switzerland, Australia, or other jurisdiction from which the Customer provides data, is made in accordance with Applicable Data Protection Laws. GradingPal does this by relying on one or more of the following Lawful Transfer Mechanisms, as appropriate to the relevant transfer:

  • An adequacy decision issued by the relevant regulatory authority confirming that the destination country provides an equivalent level of data protection;
  • Certification of the recipient under an approved data privacy framework, such as the EU-US Data Privacy Framework or the UK-US Data Bridge;
  • Standard Contractual Clauses adopted by the European Commission or approved under applicable UK or Swiss law; or
  • Such other lawful transfer mechanism as may be recognised under Applicable Data Protection Laws from time to time.

2. Current Transfer Safeguards

GradingPal currently transfers Covered Data primarily to the United States, where GradingPal and its Sub-processors are located. The majority of GradingPal's Sub-processors (including AWS, Google, OpenAI, Anthropic, Stripe, Vercel, Render, Upstash, Loops, Resend, Mixpanel, Sentry, and Ably) are certified under the EU-US Data Privacy Framework and/or the UK-US Data Bridge, providing a lawful basis for these transfers without the need for additional contractual safeguards. For Sub-processors that are not certified under these frameworks, GradingPal relies on Standard Contractual Clauses or other appropriate safeguards as required. Mistral AI SAS is a French company whose infrastructure is hosted within the European Union; no transfer safeguard is required for data processed by Mistral.

GradingPal will maintain an up-to-date record of the transfer mechanisms applicable to each Sub-processor and will make this available to the Customer upon request.

3. Changes to Transfer Mechanisms

Data transfer law evolves over time. GradingPal will monitor changes to Applicable Data Protection Laws and will update its transfer mechanisms as necessary to ensure continued compliance. GradingPal will notify the Customer if any material change to the applicable transfer mechanism is required and will work with the Customer in good faith to maintain a lawful basis for the transfer of Covered Data.

4. Australia

Where Covered Data originates from Australia and is transferred to GradingPal in the United States, GradingPal will take reasonable steps to ensure that it handles such Covered Data in a manner consistent with the Australian Privacy Principles. GradingPal is responsible for the acts and omissions of overseas recipients of Australian Covered Data as if they were its own. In the event of a suspected Security Incident affecting Australian Covered Data, GradingPal will carry out a reasonable and expeditious assessment within 30 days of becoming aware.

Schedule 4: Authorized Sub-Processors

The following sub-processors are authorized to process Covered Data in connection with the provision of the Service. GradingPal maintains the current and complete sub-processor list at www.gradingpal.com/sub-processors and will update it prior to adding or replacing any sub-processor in accordance with paragraph 7.4 of this DPA.

Sub-processorPurposeCountry
Ably Realtime Ltd.Real-time messagingUnited Kingdom
Amazon Web Services, Inc.Cloud infrastructureUnited States
Anthropic PBCAI servicesUnited States
Axiom, Inc.Logging and observabilityUnited States
Chatwoot, Inc.Customer supportUnited States
Functional Software, Inc.Error monitoringUnited States
Google LLCCloud infrastructure and AIUnited States
Linear Orbit, Inc.Internal operationsUnited States
Loops, Inc.Email communicationsUnited States
Microsoft CorporationAI servicesUnited States
Mistral AI SASAI servicesFrance
Mixpanel, Inc.Product analyticsUnited States
Notion Labs, Inc.Internal operationsUnited States
OpenAI OpCo, LLCAI servicesUnited States
Render Services, Inc.Cloud infrastructureUnited States
Resend, Inc.Email communicationsUnited States
Slack Technologies, LLCInternal communicationsUnited States
Stripe, Inc.Payment processingUnited States
Supabase, Inc.Cloud infrastructureUnited States
Unstructured Technologies, Inc.Document processingUnited States
Upstash, Inc.Cloud infrastructureUnited States
Velt, Inc.Collaboration servicesUnited States
Vercel, Inc.Cloud infrastructureUnited States

Executing This Addendum

Customers wishing to execute a signed copy of this Data Processing Addendum should contact hello@gradingpal.com. By using GradingPal's Services, Customers agree to the terms and conditions of this DPA.

Effective Date: April 28, 2026  |  Cues Technologies Inc. (GradingPal)  |  hello@gradingpal.com