Articles in this section

Data Processing Addendum (DPA)

Last updated: August 20, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between ImmerseMe Limited (“ImmerseMe”) and the customer identified in the applicable order, subscription, services agreement or other contract (“Customer”) to the extent ImmerseMe processes Personal Data on behalf of Customer in connection with the ImmerseMe service.

1. Definitions

“Applicable Data Protection Law” means privacy, data-protection and student-data laws that apply to the relevant processing, including where applicable the GDPR, UK GDPR, FERPA, COPPA, US state privacy/student-privacy laws and the New Zealand Privacy Act 2020.

“Customer Data” means data submitted to, stored in, generated through or otherwise processed by the service on Customer's behalf, including Personal Data and institutional/student data.

“Personal Data” means information relating to an identified or identifiable person, or equivalent concepts under Applicable Data Protection Law.

“Subprocessor” means a third party engaged by ImmerseMe to process Personal Data on behalf of Customer in connection with the service.

2. Roles and Instructions

Where Customer determines the purposes and means of processing, Customer acts as controller/business or equivalent and ImmerseMe acts as processor/service provider. Where Customer is itself a processor, ImmerseMe acts as Customer's subprocessor.

ImmerseMe will process Customer Personal Data only:

  • to provide, secure, support and maintain the service;
  • in accordance with Customer's documented instructions as expressed in the agreement, this DPA and authorized use of the service;
  • as otherwise required by applicable law, in which case ImmerseMe will notify Customer before processing unless legally prohibited; and
  • for no unrelated advertising, sale, data-brokerage or cross-context behavioral profiling purpose.

3. Customer Responsibilities

Customer is responsible for ensuring that:

  • it has a lawful basis and all required notices, permissions or consents for Personal Data submitted to the service;
  • its instructions comply with Applicable Data Protection Law;
  • only appropriate Personal Data is submitted to the service; and
  • account administrators configure and use optional features, including AI and integrations, in accordance with Customer's policies and legal obligations.

4. Nature, Purpose and Duration of Processing

The nature and purpose of processing are to provide a hosted immersive language-learning platform, including account administration, roster/class management, language-learning activities, progress and reporting, speech processing, optional AI conversation, integrations, transactional communications, support, security, backup and disaster recovery.

Processing continues for the term of the agreement and for any limited retention period required to complete deletion, backup expiry, legal obligations or valid preservation requirements.

5. Categories of Data Subjects

Data subjects may include learners/students, teachers, school or institutional administrators, customer contacts, individual subscribers and support/feedback submitters.

6. Categories of Personal Data

Depending on Customer's use of the service, data may include:

  • names, email addresses, usernames, roles and profile/locale information;
  • organization, school, class, roster and relationship information;
  • authentication and security metadata, including IP address, browser/user-agent and account activity;
  • learning responses, scores, progress, completion, XP and reporting data;
  • assignments, tasks and grades where enabled;
  • streamed microphone audio for speech/AI functionality, which ImmerseMe does not intentionally persist as a stored raw audio file/entity;
  • AI conversation text, generated responses, moderation metadata and session reports/metrics;
  • support/feedback content and technical context; and
  • operational logs, security telemetry and backup data.

7. Student and Education Data

Where FERPA or similar student-privacy law applies, ImmerseMe will process education records and student data only for authorized educational/service purposes and subject to Customer's direction and the applicable agreement.

ImmerseMe will not sell student Personal Data, use it for targeted third-party advertising, or use it for unrelated commercial profiling.

Where required by the applicable school relationship, ImmerseMe will act in a manner intended to support the institution's obligations under FERPA's school-official framework or equivalent state-law service-provider provisions, subject to the institution maintaining the control and contractual conditions required by law.

8. Confidentiality and Personnel

ImmerseMe will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive appropriate security, privacy and responsible-AI awareness requirements relevant to their roles.

Access to Customer Data is limited by role and business need.

9. Security Measures

ImmerseMe maintains technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Measures include, as appropriate:

  • role-based access control and privileged-access restrictions;
  • multi-factor or additional authentication controls for key administrative access;
  • encryption in transit using TLS and cloud-provider encryption at rest;
  • secure secrets and cryptographic-key management;
  • Cloudflare WAF and Azure network controls;
  • application, authentication and infrastructure logging;
  • vulnerability scanning and remediation processes;
  • secure SDLC and change-management controls;
  • incident-response procedures;
  • endpoint and remote-work security requirements;
  • backup/recovery and business-continuity controls; and
  • vendor/subprocessor risk management.

Customer acknowledges that specific controls may evolve over time, provided ImmerseMe does not materially reduce the overall level of protection without appropriate risk review.

10. Security Incidents

ImmerseMe will notify Customer without undue delay after confirming a Security Incident involving Customer Personal Data where notification is required by Applicable Data Protection Law or the agreement.

The notice will include information reasonably available at the time, such as the nature of the incident, affected data, likely consequences, containment/remediation actions and a contact for follow-up. Information may be provided in phases as investigation continues.

ImmerseMe will take reasonable steps to contain, investigate and remediate the incident and cooperate with Customer's reasonable information requests relating to the incident.

11. Subprocessors

Customer authorizes ImmerseMe to use Subprocessors to provide the service, subject to this Section.

ImmerseMe will:

  • maintain a current list of material Subprocessors;
  • require Subprocessors that process Customer Personal Data to be subject to data-protection obligations appropriate to the processing;
  • remain responsible for its obligations under this DPA where processing is delegated to a Subprocessor, subject to applicable contractual and legal limitations; and
  • review material Subprocessor changes through its vendor-risk process.

Current Subprocessor information, including provider name, service/purpose, data categories, processing locations and transfer information, is published through ImmerseMe's Privacy Policy / Trust Center and maintained from the authoritative Subprocessor Register.

Where Customer reasonably objects to a new material Subprocessor on documented data-protection grounds, the parties will work in good faith to address the concern. If no reasonable solution is available, the applicable agreement will govern any termination rights.

12. International Transfers

ImmerseMe's core production environment is centered in Australia East, but approved Subprocessors may process data globally.

Where Personal Data subject to the GDPR, UK GDPR or another transfer-restricted regime is transferred internationally, ImmerseMe will use an applicable lawful transfer mechanism where required, which may include the European Commission Standard Contractual Clauses (“SCCs”), the UK International Data Transfer Addendum or other recognized safeguards.

If the SCCs are required between Customer and ImmerseMe, they are incorporated by reference to the extent legally necessary, using the module appropriate to the parties' roles. The applicable agreement and this DPA supply the commercial and processing details to the extent permitted by the SCCs.

13. Data Subject Requests

Taking into account the nature of processing, ImmerseMe will provide reasonable assistance to Customer with requests from individuals to exercise applicable privacy rights where the relevant data is processed by ImmerseMe on Customer's behalf.

If ImmerseMe receives a request directly relating to school/institution-controlled data, ImmerseMe may refer the requester to Customer or coordinate with Customer, unless law requires ImmerseMe to respond directly.

14. Privacy Impacts and Compliance Assistance

Taking into account the nature of processing and information available to ImmerseMe, ImmerseMe will provide reasonable information to assist Customer with applicable privacy-impact assessments, data-protection impact assessments, regulator inquiries and security/privacy questionnaires relating to the service.

15. Audits and Assurance

ImmerseMe will make available reasonable information necessary to demonstrate compliance with this DPA, including relevant policies, security questionnaires, HECVAT responses, subprocessor information and available third-party assurance evidence, subject to confidentiality and security restrictions.

Where a Customer reasonably requires additional audit activity, the parties will agree scope, timing, confidentiality, non-disruption requirements and responsibility for reasonable costs in advance. Customer security testing must not occur without prior written authorization and agreed rules of engagement.

16. Return, Deletion and Retention

At the end of the service relationship or upon a valid deletion instruction, ImmerseMe will delete or approved-anonymize Customer-controlled production Personal Data in accordance with the agreement and its Data Retention & Deletion Standard, normally within 30 calendar days after a confirmed termination or approved deletion trigger unless law or contract requires a different period.

Database backup copies are retained for up to 30 days in Azure Blob Storage, with temporary local backup copies retained for up to 3 days. Data deleted from production may remain in backups until normal expiry and will not be restored except for legitimate recovery purposes.

Where reasonably required by the agreement, ImmerseMe will provide an opportunity to export available Customer Data before deletion. In a planned service-retirement or business-closure scenario, ImmerseMe aims to provide at least 90 days' notice/opportunity for Customer to export or migrate available data where practicable, subject to legal, security, insolvency and technical constraints.

17. Ownership

As between the parties, Customer retains ownership of Customer-provided data, inputs and associated institutional content. ImmerseMe receives only the rights necessary to provide, secure, support and improve the contracted service as permitted by the agreement and Applicable Data Protection Law.

18. AI Processing

Where Customer enables AI functionality, Customer authorizes the processing reasonably necessary to provide that feature through approved AI/speech Subprocessors.

ImmerseMe does not use Customer institutional data to train an ImmerseMe-owned foundation model. OpenAI model-improvement/data-sharing is disabled for the production API organization. Standard vendor-side abuse-monitoring retention may still apply where zero-data-retention controls are not enabled.

Customer should avoid submitting unnecessary sensitive information into free-form AI conversations and should configure AI use consistently with its own policies and legal obligations.

19. Government Requests

ImmerseMe will review government and law-enforcement requests for valid legal authority, jurisdiction, scope and proportionality. Where legally permitted and contractually appropriate, ImmerseMe will seek to notify Customer before disclosing Customer Data. ImmerseMe will disclose only information legally required.

20. Conflict and Precedence

If this DPA conflicts with the main agreement regarding the protection or processing of Personal Data, this DPA controls to the extent of that conflict, unless the parties expressly agree otherwise in writing.

21. Governing Agreement

Except as modified by this DPA, the main agreement remains in effect. Governing law, liability limitations, dispute resolution and other commercial terms are determined by the main agreement unless Applicable Data Protection Law requires otherwise.

Schedule 1 — Processing Details

This Schedule describes the processing of Personal Data carried out by ImmerseMe on behalf of Customer under the DPA.

Subject Matter Provision of the ImmerseMe language-learning SaaS service.
Duration Term of the Customer agreement plus applicable limited retention and deletion periods.
Nature and Purpose Hosting, account management, educational and language-learning functionality, speech processing, optional AI functionality, integrations, communications, support, security, backup and recovery.
Categories of Data Subjects Learners/students, teachers, administrators, institutional contacts, subscribers and support/feedback users.
Categories of Personal Data Account and identity information; institutional, school, class and roster information; authentication and security metadata; learning responses, progress, scores and reporting data; assignments and grades where enabled; streamed microphone audio for speech/AI functionality; AI conversation content and outputs; support/feedback information; operational logs, security telemetry and backup data.
Sensitive / Special-Category Data Not intentionally required as a standard account field. Free-form content submitted by users may nonetheless contain sensitive or special-category information.
Frequency of Processing Continuous or episodic, according to Customer and user use of the service.

 

Questions about privacy, security, or compliance?

We are always happy to help. Contact our team at hello@immerseme.com

 

Was this article helpful?
0 out of 0 found this helpful