This Data Processing Agreement (“DPA”) forms part of the agreement governing the use of the KWIGA Platform and Services, including the KWIGA Terms & Conditions (the “Agreement”), between:
TUTERIA VCC, with registered address at 17A Vrabcha Street, Floor 1, Apt 3, 1000 Sofia, Bulgaria (“KWIGA”, “TUTERIA”, “we”, “us” or the “Processor”),
and
the individual, company, organization, school, Expert, course creator or other entity using the KWIGA Services and determining the purposes and means of processing personal data through the KWIGA Platform (the “Customer”, “Platform User” or “Controller”).
This DPA applies where and to the extent that TUTERIA VCC processes Personal Data on behalf of the Customer in connection with the provision of the KWIGA Services.
This DPA supplements the Agreement and shall be interpreted together with the KWIGA Privacy Policy and other applicable contractual documents.
For the purposes of this DPA:
“Applicable Data Protection Laws” means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including, where applicable, Regulation (EU) 2016/679 (“GDPR”).
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given to them under the GDPR or other applicable Data Protection Laws.
“Customer” means the Platform User that uses the KWIGA Services and determines the purposes and means of Processing Service Data.
“Service Data” means Personal Data uploaded to, collected through, generated within or otherwise processed through the KWIGA Platform by or on behalf of the Customer in connection with its use of the Services.
Service Data may include Personal Data processed through the KWIGA CRM, LMS, courses, educational programs, student and customer management functionality, communication tools, automations, assessments and other Platform features used by the Customer.
“Subprocessor” means a third party engaged by KWIGA to Process Service Data on behalf of the Customer.
Where the Customer determines the purposes and means of Processing Service Data, the Customer acts as the Controller of such Personal Data.
The Customer is responsible for its Processing activities and for compliance with the obligations applicable to Controllers under Applicable Data Protection Laws.
Where TUTERIA VCC Processes Service Data on behalf of the Customer and in accordance with the Customer's instructions, TUTERIA VCC acts as the Processor.
TUTERIA VCC shall Process such Service Data in accordance with this DPA, the Agreement, the Customer's documented instructions and Applicable Data Protection Laws..
Certain Processing activities may be carried out by TUTERIA VCC for purposes independently determined by TUTERIA VCC.
Such purposes may include, where applicable:
administration and operation of the KWIGA Platform;
Platform security and integrity;
fraud and abuse prevention;
detection and investigation of unauthorized access and security incidents;
compliance with legal or regulatory obligations;
management of TUTERIA VCC's own contractual relationships;
establishment, exercise or defence of legal claims; and
other purposes described in the KWIGA Privacy Policy.
Where TUTERIA VCC independently determines the purposes and means of such Processing, TUTERIA VCC acts as an independent Controller with respect to that Processing.
Such Processing is governed by the KWIGA Privacy Policy and Applicable Data Protection Laws and does not constitute Processing carried out by TUTERIA VCC as Processor under this DPA.
The fact that the Customer and TUTERIA VCC may Process certain information relating to the same Data Subject does not, by itself, mean that the parties act as joint controllers.
The role of each party shall be determined by reference to the purposes and means of the relevant Processing activity.
The Customer shall comply with Applicable Data Protection Laws in connection with its collection, use, disclosure and other Processing of Service Data.
The Customer is responsible for ensuring that:
a. it has an appropriate legal basis for Processing Service Data;
b. Service Data has been collected lawfully;
c. Service Data is lawfully disclosed or otherwise made available to KWIGA for Processing;
d. Data Subjects receive any privacy notices and information required under Applicable Data Protection Laws;
e. any consent required for the Customer's Processing activities has been validly obtained;
f. the Customer's instructions to KWIGA comply with Applicable Data Protection Laws;
g. the Customer processes only Personal Data necessary for its legitimate and lawful purposes; and
h. appropriate retention periods are established for Service Data under the Customer's control.
The Customer shall not use the Services to collect or Process Special Categories of Personal Data within the meaning of Article 9 GDPR unless the Customer has established a valid legal basis and, where required, an applicable condition under Article 9 GDPR for such Processing.
Where the Customer uses questionnaires, forms, custom fields, uploaded content or other features of the Services to collect or Process such data, the Customer acts as Controller and is responsible for determining the lawfulness, purposes and scope of such Processing, providing any required information to Data Subjects, obtaining explicit consent where consent is relied upon, and complying with all other applicable requirements of Applicable Data Protection Laws.
KWIGA Processes such Service Data on behalf of the Customer and in accordance with the Customer's documented instructions and this DPA.
The Customer instructs KWIGA to Process Service Data as necessary to:
provide the Services selected and configured by the Customer;
host and maintain Service Data;
provide CRM, LMS and other Platform functionality;
provide access to courses and other products;
administer functionality selected by the Customer;
provide technical support;
maintain and secure the Services; and
otherwise perform the Agreement and the Customer's documented instructions.
The Client’s use and configuration of the KWIGA Platform, including settings, actions and functionality activated by the Client, as well as the Client’s creation and publication of web pages, forms, notifications and other materials using the Platform, may be considered documented instructions for the purposes of this DPA.
The Client independently determines the content of its Privacy Policy, privacy notices, forms and other materials provided to Data Subjects using the Platform and is responsible for ensuring that such materials comply with Applicable Data Protection Law and accurately reflect the Client’s actual processing of personal data. KWIGA is not required to review or approve the content of such materials.
If KWIGA reasonably considers that an instruction from the Customer infringes Applicable Data Protection Laws, KWIGA shall inform the Customer without undue delay.
KWIGA may suspend the relevant Processing to the extent reasonably necessary until the instruction is amended, clarified or confirmed to be lawful.
KWIGA shall Process Service Data only on documented instructions from the Customer, unless Processing is required by applicable Union or Member State law.
Where KWIGA is required by law to Process Service Data other than on the Customer's instructions, KWIGA shall inform the Customer of that legal requirement before Processing, unless the law prohibits such information on important grounds of public interest.
KWIGA shall ensure that persons authorized to Process Service Data:
Process such data only as necessary for the performance of their duties;
are subject to appropriate confidentiality obligations; and
are provided access only where reasonably necessary.
KWIGA shall implement appropriate technical and organizational measures designed to protect Service Data in accordance with Section 7 and Appendix B of this DPA.
Taking into account the nature of the Processing and the information available to KWIGA, KWIGA shall provide reasonable assistance to the Customer in fulfilling its obligations under Applicable Data Protection Laws, including obligations relating to:
Data Subject requests;
security of Processing;
Personal Data Breaches;
data protection impact assessments; and
consultations with Supervisory Authorities, where applicable.
KWIGA shall maintain records and information relating to its Processing activities to the extent required by Applicable Data Protection Laws.
The Customer, as Controller, is primarily responsible for responding to requests from Data Subjects relating to Service Data Processed by KWIGA on the Customer's behalf.
KWIGA provides the Customer with functionality and/or appropriate mechanisms to access, manage and export Service Data under the Customer's control and, where supported by the relevant functionality, to correct or delete such Service Data, subject to applicable legal requirements.
Taking into account the nature of the Processing, KWIGA shall provide reasonable assistance to the Customer by appropriate technical and organizational measures, insofar as possible, for the fulfilment of the Customer's obligations to respond to Data Subject requests.
If KWIGA receives a Data Subject request relating primarily to Service Data for which the Customer is the Controller, KWIGA may refer the Data Subject to the Customer and, where appropriate, inform the Customer of the request.
KWIGA shall not independently respond to such request on behalf of the Customer unless:
instructed by the Customer;
permitted under the Agreement; or
required by applicable law.
The Customer, as Controller, is responsible for determining appropriate retention periods for Service Data Processed for purposes determined by the Customer, subject to the retention and deletion arrangements established under this DPA and the Agreement.
Different retention periods may apply to Service Data depending on the nature and purpose of the relevant data and the functionality through which such data is Processed.
Following the termination or expiration of the Client’s subscription, Service Data relating to the relevant Client may be retained for up to ninety (90) days from the end of the Client’s subscription period to allow for reactivation, data retrieval, and the orderly discontinuation of the use of the Services.
Upon expiration of the aforementioned 90-day period, the relevant account and/or school may be deactivated, hidden, or otherwise made inaccessible through the ordinary interface of the KWIGA Platform without deleting or modifying the Service Data contained therein.
The relevant Service Data may be retained for an additional period of up to ninety (90) days for the purposes of enabling restoration, resolving technical or contractual matters, and ensuring the orderly completion of the provision of the Services.
Upon expiration of a total period of one hundred and eighty (180) days from the termination or expiration of the subscription, the relevant Service Data shall be deleted from the active systems of the KWIGA Platform in accordance with the applicable data retention and deletion procedures.
The foregoing procedure shall apply subject to the documented instructions of the relevant Controller, this DPA, and Applicable Data Protection Laws. It shall not apply to Personal Data that TUTERIA VCC independently and lawfully Processes in its capacity as an independent Controller pursuant to Section 5.7.
Service Data is generally retained for the duration of the Customer's use of the relevant KWIGA Services and in accordance with:
the Customer's documented instructions;
this DPA;
the Agreement; and
Applicable Data Protection Laws.
Nothing in this Section relieves the Customer of its responsibility as Controller to determine whether particular Service Data remains necessary and should continue to be retained.
KWIGA provides the Customer with functionality and/or appropriate mechanisms to access, manage and export Service Data under the Customer's control and, where supported by the relevant functionality, to delete such Service Data, subject to applicable legal requirements.
Following the termination or expiration of the Client’s subscription, Service Data may be retained in accordance with the periods and conditions set forth in Section 5.2.
During the first ninety (90) days, the Client may be provided with a reasonable opportunity to retrieve or export Service Data, subject to the functionality of the relevant Services.
Upon expiration of this period, the relevant account and/or school may be deactivated, hidden, or made inaccessible through the ordinary interface of the KWIGA Platform. Service Data may be retained for an additional period of up to ninety (90) days in accordance with Section 5.2.
Upon expiration of a total period of one hundred and eighty (180) days from the termination or expiration of the subscription, the relevant Service Data shall be deleted from the active systems of the KWIGA Platform in accordance with the applicable deletion procedures, this DPA, the Controller’s documented instructions, and Applicable Data Protection Laws.
Where Service Data remains temporarily in backup, disaster recovery or similar systems after deletion from active systems, such data shall remain subject to appropriate security measures and shall not be restored or used for ordinary Processing except where necessary for disaster recovery, security, legal compliance or other legitimate technical purposes.
Such copies shall be deleted or overwritten in accordance with KWIGA's applicable backup retention procedures.
This Section applies to Service Data Processed by TUTERIA VCC as Processor.
It does not require TUTERIA VCC to delete Personal Data that TUTERIA VCC independently and lawfully Processes in its capacity as Controller.
Such data may be retained where necessary for purposes described in the KWIGA Privacy Policy and in accordance with Applicable Data Protection Laws.
The Customer provides general authorization for KWIGA to engage Subprocessors where reasonably necessary for the provision, maintenance, support, operation or security of the KWIGA Services.
Before allowing a Subprocessor to Process Service Data, KWIGA shall ensure that the Subprocessor is subject to contractual data protection obligations that provide an appropriate level of protection for Service Data and comply with the requirements applicable to subprocessors under Applicable Data Protection Laws.
KWIGA shall remain responsible for the performance of its data protection obligations by its Subprocessors to the extent required under Applicable Data Protection Laws.
KWIGA shall make information regarding relevant Subprocessors available to Customers through an appropriate mechanism.
Where required by Applicable Data Protection Laws, KWIGA shall provide reasonable notice of intended material changes concerning the addition or replacement of Subprocessors.
The Customer may raise reasonable objections relating specifically to data protection concerns arising from the proposed Subprocessor.
The parties shall work in good faith to address any such reasonable objection.
Where a Customer independently enables or connects a third-party integration using its own account, credentials or API keys, TUTERIA processes and transmits Service Data to that third party on the Customer's documented instructions.
The Customer is responsible for determining whether its use of such third-party service complies with Applicable Data Protection Laws, including establishing any required contractual arrangements and international data transfer safeguards with that third party.
Taking into account the state of the art, costs of implementation and the nature, scope, context and purposes of Processing, as well as the risks of varying likelihood and severity for the rights and freedoms of individuals, KWIGA shall implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk.
Depending on the nature and risks of the relevant Processing, such measures may include:
a. access control and authorization mechanisms;
b. measures designed to maintain appropriate separation and authorization between Customer environments and data;
c. authentication and access management measures;
d. logging and monitoring;
e. measures designed to detect suspicious activity, abuse and unauthorized access;
f. traffic and request controls, including rate controls where appropriate;
g. vulnerability management;
h. security testing;
i. incident detection and response procedures;
j. backup and recovery measures;
k. controls relating to access by contractors, service providers and other authorized persons;
l. procedures for review of security events and incidents; and
m. periodic review and testing of relevant technical and organizational security controls.
Additional information regarding the categories of technical and organizational measures implemented by KWIGA is set out in Appendix B.
KWIGA may update its technical and organizational measures from time to time to reflect:
technological developments;
identified risks;
changes to the Services;
results of security reviews;
security incidents; and
changes in applicable law.
Such changes shall not materially reduce the overall level of protection provided to Service Data.
KWIGA shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Service Data Processed by KWIGA on behalf of the Customer.
To the extent the relevant information is reasonably available to KWIGA, the notification shall include:
a. a description of the nature of the Personal Data Breach;
b. the categories of affected Personal Data;
c. the categories of affected Data Subjects;
d. the approximate number of affected Data Subjects, where known;
e. the approximate number of affected Personal Data records, where known;
f. the likely consequences of the Personal Data Breach, where reasonably capable of being determined;
g. measures taken or proposed to contain, investigate and remediate the Personal Data Breach; and
h. contact details or another appropriate contact channel through which further information may be obtained.
Where all relevant information is not available at the time of the initial notification, KWIGA may provide available information initially and supplement it in phases as the investigation progresses.
KWIGA shall take appropriate measures to:
investigate the incident;
identify its nature and scope;
contain the incident;
mitigate reasonably foreseeable adverse effects;
preserve relevant evidence;
remediate identified vulnerabilities where appropriate; and
take reasonable measures designed to reduce the risk of recurrence.
Taking into account the nature of the Processing and the information available to KWIGA, KWIGA shall provide reasonable assistance to the Customer in fulfilling applicable obligations relating to:
notification of a Supervisory Authority;
communication with affected Data Subjects;
assessment of risks to the rights and freedoms of individuals; and
documentation of the Personal Data Breach.
The Customer remains responsible, in its capacity as Controller, for determining whether a Personal Data Breach affecting Service Data requires:
notification to a Supervisory Authority;
communication to affected Data Subjects; or
other action required under Applicable Data Protection Laws.
This does not affect any independent legal obligations of TUTERIA VCC relating to Personal Data for which TUTERIA VCC acts as Controller.
Notification of or cooperation in relation to a Personal Data Breach shall not, by itself, constitute an admission of fault or liability by either party.
Where Service Data is Processed within the European Economic Area (“EEA”), such Processing does not constitute a transfer to a third country for purposes of Chapter V of the GDPR.
Where KWIGA or an authorized Subprocessor transfers Service Data outside the EEA to a jurisdiction that has not been recognized as providing an adequate level of protection under applicable law, KWIGA shall ensure that an appropriate transfer mechanism is implemented where required.
Such mechanisms may include:
an adequacy decision adopted by the European Commission;
Standard Contractual Clauses approved by the European Commission;
Binding Corporate Rules, where applicable; or
another lawful transfer mechanism recognized under Applicable Data Protection Laws.
Where required under Applicable Data Protection Laws, KWIGA shall implement supplementary measures appropriate to the relevant transfer and associated risks.
KWIGA shall provide reasonable information concerning applicable international transfer safeguards upon the Customer's request where required by Applicable Data Protection Laws.
KWIGA shall make available to the Customer information reasonably necessary to demonstrate compliance with KWIGA's obligations as Processor under Applicable Data Protection Laws.
Upon reasonable written request, KWIGA shall provide relevant information concerning:
its Processing of Service Data;
applicable technical and organizational measures;
relevant Subprocessors; and
other matters reasonably required for the Customer to assess KWIGA's compliance with this DPA.
Where the information made available by KWIGA is not reasonably sufficient to demonstrate compliance and where an audit is required under Applicable Data Protection Laws, KWIGA shall allow for and contribute to reasonable audits or inspections relating to the Processing of Service Data.
Unless otherwise required by a Supervisory Authority or Applicable Data Protection Laws, the Customer shall:
provide reasonable advance written notice of an audit;
limit the audit to matters relevant to Processing under this DPA;
conduct the audit during normal business hours where reasonably possible;
avoid unnecessary disruption to KWIGA's operations; and
ensure that auditors are subject to appropriate confidentiality obligations.
An audit shall not entitle the Customer or its auditor to access:
Personal Data belonging to another Customer;
confidential information of another Customer;
information that would compromise the security of KWIGA systems;
source code or other protected intellectual property except where specifically required by applicable law; or
information unrelated to the Customer's Processing activities.
The parties shall cooperate in good faith regarding reasonable audit requests from competent Supervisory Authorities.
Taking into account the nature of the Processing and the information available to KWIGA, KWIGA shall provide reasonable assistance to the Customer with data protection impact assessments where the Customer is required to conduct such an assessment under Applicable Data Protection Laws.
Where required under Applicable Data Protection Laws, KWIGA shall provide reasonable assistance relating to prior consultation with a competent Supervisory Authority concerning Processing carried out through the Services.
Each party shall protect Personal Data and confidential information received in connection with this DPA against unauthorized disclosure.
KWIGA shall ensure that contractors, service providers and other persons authorized to Process Service Data are subject to appropriate confidentiality obligations or an applicable statutory duty of confidentiality.
The Customer shall ensure that credentials, access rights and administrative functionality made available through the KWIGA Platform are used only by appropriately authorized persons.
Each party shall maintain records relating to its Processing activities to the extent required by Applicable Data Protection Laws.
The parties shall reasonably cooperate with each other where necessary to respond to lawful requests from Supervisory Authorities relating to Processing governed by this DPA.
Nothing in this DPA requires either party to disclose information where disclosure is prohibited by applicable law.
Each party shall be responsible for its own compliance with Applicable Data Protection Laws and for obligations allocated to it under this DPA.
Liability between the parties arising under or in connection with this DPA shall be subject to the limitations and exclusions of liability contained in the Agreement, to the extent permitted by Applicable Data Protection Laws.
Nothing in this DPA excludes or limits liability where such exclusion or limitation is prohibited by applicable law.
This DPA becomes effective when the Customer becomes bound by the Agreement and KWIGA begins Processing Service Data on behalf of the Customer.
This DPA remains effective for as long as KWIGA Processes Service Data on behalf of the Customer.
Termination or expiration of the Agreement does not affect provisions of this DPA which by their nature are intended to survive termination, including provisions concerning confidentiality, deletion or return of Service Data, liability and applicable law.
This DPA forms part of the Agreement between the Customer and TUTERIA VCC governing use of the KWIGA Services.
In the event of a conflict between this DPA and another provision of the Agreement concerning Processing of Service Data by TUTERIA VCC as Processor, this DPA shall prevail with respect to the conflicting data protection matter.
The KWIGA Privacy Policy governs Processing activities for which TUTERIA VCC acts as Controller.
This DPA governs Processing of Service Data carried out by TUTERIA VCC on behalf of the Customer as Processor.
This DPA shall be governed by the law applicable to the Agreement between the Customer and TUTERIA VCC, without prejudice to mandatory provisions of Applicable Data Protection Laws.
Nothing in this DPA limits the application of the GDPR or the powers and jurisdiction of a competent Supervisory Authority where such law or jurisdiction applies.
KWIGA may update this DPA where reasonably necessary to:
comply with changes in Applicable Data Protection Laws;
reflect changes to the KWIGA Services;
update technical or organizational measures;
update Processing arrangements; or
clarify the rights and obligations of the parties.
Where an amendment materially affects the Processing of Service Data or the Customer's data protection rights and obligations, KWIGA shall provide reasonable notice where required by applicable law or the Agreement.
Questions regarding this DPA or KWIGA's Processing of Service Data on behalf of a Customer may be submitted to:
TUTERIA VCC
17A Vrabcha Street, Floor 1, Apt 3
1000 Sofia, Bulgaria
Email: support@kwiga.com
This Appendix forms part of the Data Processing Agreement.
Processing of Service Data by KWIGA as necessary to provide, maintain, support and secure the KWIGA Services selected and configured by the Customer.
For the duration of the Customer's use of the relevant KWIGA Services. Following termination or expiry of the Customer's subscription, Customer-specific Service Data may be retained for up to ninety (90) days from the end of the Customer's subscription period to permit reactivation, data retrieval and orderly termination of the Services.
Following expiry of this period, Personal Data contained in Customer-specific Service Data, including associated order data, shall be anonymized in accordance with Section 5 of the DPA and KWIGA's applicable retention procedures. Following an additional ninety (90) days after such anonymization, the corresponding data shall be permanently deleted from the active systems of the KWIGA Platform in accordance with applicable retention and deletion procedures, unless continued retention is required by applicable law or otherwise permitted under the DPA. Where TUTERIA VCC Processes Personal Data on behalf of the Customer as Processor, this retention and deletion process shall apply subject to the Customer's documented instructions, the applicable data processing agreement and Applicable Data Protection Laws.
Personal Data Processed by TUTERIA VCC in its capacity as an independent Controller is subject to the retention periods applicable to that Processing.
Depending on the Services selected and configured by the Customer, Processing may include:
collection;
recording;
organization;
structuring;
storage;
hosting;
adaptation;
retrieval;
consultation;
use;
transmission;
making available;
administration;
analysis as instructed by the Customer;
restriction;
export;
deletion;
anonymization; and
other Processing necessary to provide the selected Services.
Processing Service Data for the purposes determined by the Customer, including, depending on the Customer's use of KWIGA:
management of students and customers;
CRM functionality;
LMS functionality;
delivery and administration of courses and educational programs;
administration of access to digital products;
tests, quizzes and assignments;
course progress tracking;
certificates;
communication with students and customers;
email and notification functionality;
automations;
order administration;
integration functionality;
customer support;
reporting and analytics selected by the Customer; and
other functionality enabled or configured by the Customer.
Depending on the Customer's use of the Services, Data Subjects may include:
students;
learners;
customers;
prospective customers;
subscribers;
course participants;
employees and contractors of the Customer;
instructors;
administrators;
assistants;
representatives of the Customer; and
other individuals whose Personal Data is submitted to or processed through the KWIGA Platform by or on behalf of the Customer.
Depending on the Services used by the Customer, Service Data may include:
Identity and profile information
first name;
middle name;
last name;
profile image;
account or profile identifiers.
Contact information
email address;
phone number;
other contact details submitted by the Customer or Data Subject.
Educational and learning information
courses and programs;
enrolment;
access information;
course progress;
lesson completion;
quiz and test answers;
test results;
scores;
assignments;
comments;
certificates;
achievements;
points and statuses.
CRM and customer management information
tags;
groups;
customer status;
notes;
customer history;
communication history;
custom fields configured by the Customer.
Order and transaction-related information
order identifiers;
products;
amounts;
currencies;
discounts;
coupons;
payment status;
transaction dates;
refund information;
installment or subscription parameters;
other order information processed on behalf of the Customer.
KWIGA does not require Customers to submit payment card security data such as full card numbers or CVC codes into ordinary CRM or LMS Service Data fields.
Communications
messages;
emails;
comments;
support-related information;
other communications processed through functionality selected by the Customer.
Technical information
To the extent Processed on behalf of the Customer:
IP address;
login/activity information;
device or browser information;
technical identifiers;
timestamps.
The KWIGA Services do not require the Customer to Process Special Categories of Personal Data. However, Service Data may include Special Categories of Personal Data where the Customer chooses to collect or otherwise Process such data through questionnaires, forms, custom fields, uploaded content, communications or other configurable features of the Services.
The Customer determines the content and purposes of such Processing and is responsible for establishing an applicable legal basis and, where required, an applicable condition under Article 9 GDPR.
Processing may occur continuously or periodically for the duration of the Customer's use of the relevant Services, depending on the functionality selected and the Customer's instructions.
TUTERIA VCC implements technical and organizational measures designed to provide a level of security appropriate to the risks associated with Processing Service Data.
The measures described below represent categories of security measures and may be adapted or supplemented from time to time based on the nature of Processing, technological developments, identified risks and changes to the KWIGA Services.
KWIGA implements measures designed to restrict access to Personal Data and Platform functionality to authorized users, authorized persons and systems.
Such measures may include:
user authentication;
role and permission management;
authorization controls;
access restrictions based on relevant user or Customer context;
management and review of internal access rights; and
measures designed to prevent unauthorized access between Customer environments.
KWIGA implements technical controls designed to ensure that access to Customer data is appropriately restricted according to the Customer, account, school, project or other applicable authorization context.
Authorization controls are reviewed and tested as appropriate to the relevant functionality.
KWIGA uses logging and monitoring mechanisms appropriate to the operation and security of the Services.
These measures may include:
application and system logging;
security event monitoring;
suspicious activity detection;
error monitoring;
traffic monitoring;
analysis of unusual or potentially abusive activity; and
maintenance of relevant security incident records.
KWIGA implements measures designed to detect, restrict and respond to abuse, unauthorized access and automated misuse of Platform functionality.
Depending on the relevant service or endpoint, such measures may include:
request controls;
rate controls;
access restrictions;
automated or manual blocking mechanisms;
suspicious activity detection; and
additional verification or authorization controls.
KWIGA maintains processes for identifying, assessing and remediating security vulnerabilities.
Such measures may include:
security reviews;
testing of authorization controls;
automated testing where appropriate;
vulnerability remediation;
review of security findings;
regression testing; and
verification of corrective measures.
KWIGA maintains processes designed to detect, escalate, investigate, contain and remediate security incidents and Personal Data Breaches.
Such processes may include:
incident escalation;
technical investigation;
preservation and analysis of relevant logs;
containment measures;
remediation;
risk assessment;
regulatory and Customer notification assessment;
post-incident review; and
implementation of corrective actions.
Persons authorized to access Service Data are subject to appropriate confidentiality obligations.
Access to Personal Data is provided based on operational requirements and is limited where reasonably practicable.
KWIGA maintains backup and recovery processes appropriate to the relevant Services and infrastructure.
Backup data is subject to appropriate access and security controls.
Deleted Personal Data may remain temporarily in backup systems until deleted or overwritten in accordance with applicable backup retention procedures.
KWIGA implements measures designed to support the availability and resilience of the Services appropriate to the nature and risk of the relevant Processing.
Technical and organizational measures may be reviewed and updated based on:
changes to the Platform;
identified security risks;
vulnerability findings;
incidents;
changes to applicable legal requirements; and
technological developments.
Updates shall not materially reduce the overall level of protection provided to Service Data.