Legal · Data Protection
Data Processing Agreement
How iBrothers Group LLC processes personal data on behalf of enterprise customers — compliant with GDPR Article 28 and UK GDPR.
This DPA is between iBrothers Group LLC (data processor) and the enterprise customer in the applicable Order Form (data controller). It governs how iGurus handles personal data when providing platform services. iGurus processes only on documented instructions, notifies of breaches within 72 hours, and deletes or returns data within 30 days of termination. Incorporated by reference into the Master Services Agreement.
Parties & Scope
This DPA is between the parties identified in the executed Master Services Agreement or Order Form.
- Processor
- iBrothers Group LLC, an Indiana limited liability company operating as iGurus, with its principal place of business at Greenwood, Indiana, USA.
- Controller
- The enterprise customer named in the applicable Order Form who is entering into the Master Services Agreement with iGurus.
- Scope
- This DPA applies wherever iGurus processes Personal Data on behalf of the Controller in the course of providing the Services described in the MSA and any applicable Order Form.
- Precedence
- In the event of conflict between this DPA and the MSA, this DPA prevails with respect to the processing of Personal Data.
For the purposes of this DPA, the terms "Personal Data", "Controller", "Processor", "Data Subject", "Processing", "Supervisory Authority", and "Personal Data Breach" have the meanings given to them in applicable data protection law, including GDPR and UK GDPR.
Subject Matter & Duration
The subject matter and duration of the processing are determined by the MSA and Order Form.
- Subject matter
- The provision of the iGurus learning platform and related Services as described in the MSA and applicable Order Form(s), which requires iGurus to process Personal Data on behalf of the Controller.
- Duration
- Processing commences on the effective date of the MSA or Order Form and continues for the duration of the Subscription Period, until all Order Forms have expired or been terminated, or until the Controller instructs iGurus to cease processing — whichever is earliest.
Nature & Purpose of Processing
iGurus processes Personal Data only as necessary to deliver the Services and only on the documented instructions of the Controller.
- Nature
- Collection, storage, retrieval, consultation, use, disclosure by transmission, erasure, and destruction of Personal Data as required to provide the platform Services.
- Purpose
- Providing the Controller's authorised Users with access to the iGurus learning platform, including course delivery, progress tracking, certificate issuance, support, and account administration.
- Instructions
- The Controller's instructions are set out in this DPA and the MSA. iGurus shall notify the Controller promptly if it believes any instruction infringes applicable data protection law.
Data Types & Data Subjects
The categories of Personal Data and Data Subjects processed depend on what the Controller uploads or enables through the Services.
Categories of Data Subjects
- Learners / Users
- Employees, contractors, or other individuals authorised by the Controller to access the platform.
- Administrators
- Individuals designated by the Controller to manage their organisation's iGurus account.
Categories of Personal Data
- Identity data
- Full name, username, profile photo (if uploaded).
- Contact data
- Email address.
- Usage data
- Course enrolment, progress, lesson completion, quiz scores, certificate issuance.
- Technical data
- IP address, device type, browser, session logs (for security and platform performance purposes).
- Special categories
- iGurus does not intentionally process special category data (GDPR Art. 9) or criminal conviction data (Art. 10). The Controller must not upload such data without first obtaining iGurus' written consent and executing an appropriate addendum.
Processor Obligations
As required by GDPR Article 28(3), iGurus shall:
- (a) Instructions only
- Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. iGurus shall inform the Controller of such legal requirements before processing, unless that law prohibits it on public interest grounds.
- (b) Confidentiality
- Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
- (c) Security
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of Personal Data in transit and at rest, ongoing confidentiality and integrity of processing systems, ability to restore availability of Personal Data in a timely manner following a physical or technical incident, and a process for regularly testing and evaluating the effectiveness of security measures.
- (d) Sub-processors
- Not engage sub-processors without prior written consent of the Controller (general authorisation as set out in §06 below). Where sub-processors are engaged, impose data protection obligations equivalent to those in this DPA.
- (e) Data subject rights
- Assist the Controller in responding to requests from Data Subjects exercising their rights under applicable data protection law (access, rectification, erasure, restriction, portability, objection). iGurus shall forward any Data Subject request received directly to the Controller without undue delay.
- (f) Controller assistance
- Assist the Controller in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments (DPIAs), and prior consultation with supervisory authorities, having regard to the nature of processing and the information available to iGurus.
- (g) Deletion or return
- At the Controller's choice, delete or return all Personal Data to the Controller after the end of the provision of Services, and delete existing copies — unless applicable law requires retention. See §09 for full terms.
- (h) Audit cooperation
- Make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28, and allow for and contribute to audits and inspections by the Controller or an auditor mandated by the Controller. See §08 for full terms.
Personal Data Breach Notification: iGurus shall notify the Controller without undue delay — and in any event within 72 hours of becoming aware — of a Personal Data Breach affecting Personal Data processed under this DPA. Notification shall be sent to the Controller's designated contact email and to dpo@igurus.org. The notification will include, to the extent then known: the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed.
Sub-Processors
By entering into this DPA, the Controller provides general written authorisation for iGurus to engage the sub-processors listed below and any replacements or additions subject to the notice process in this section.
iGurus currently engages the following categories of sub-processors to provide the Services:
- Cloud hosting & infrastructure
- [NEEDS INPUT — confirm hosting provider, country of processing]
- Payment processing
- Stripe, Inc. — USA — payment processing for course purchases. Stripe processes payment card data as an independent controller for PCI-DSS purposes; iGurus does not store card data.
- Email delivery
- [NEEDS INPUT — confirm transactional email provider and country]
- Video hosting
- [NEEDS INPUT — confirm video hosting provider if applicable]
New sub-processors: iGurus shall give the Controller at least 30 days' prior written notice before engaging any new sub-processor or replacing an existing one. The Controller may object to any new sub-processor within 14 days of receiving notice by notifying iGurus in writing. If the Controller objects and iGurus cannot accommodate the objection, either party may terminate the affected Order Form(s) with 30 days' notice and iGurus will issue a pro-rata refund for unused Services.
iGurus shall impose data protection obligations on all sub-processors equivalent to those set out in this DPA and shall remain liable to the Controller for the performance of its sub-processors.
International Transfers
iGurus is based in the United States. Transfers of Personal Data from the EEA or UK to iGurus in the USA are subject to the following safeguards.
- EU–US transfers
- Transfers from the EEA to the USA are made on the basis of the European Commission's Standard Contractual Clauses (SCCs), Module 2 (Controller to Processor), incorporated into this DPA. ⚠️ ATTORNEY ACTION: Attach signed SCCs as Annex A before this DPA is executed with any EU customer.
- UK transfers
- Transfers from the UK are made on the basis of the UK International Data Transfer Addendum (IDTA) to the SCCs, or the UK-US Data Bridge where applicable. ⚠️ ATTORNEY ACTION: Confirm UK transfer mechanism and attach as Annex B.
- Sub-processor transfers
- iGurus shall ensure that any transfer of Personal Data to a sub-processor located outside the EEA or UK is subject to an appropriate transfer mechanism.
Audit Rights
iGurus shall cooperate with the Controller's reasonable audit requests to demonstrate compliance with this DPA.
- Documentation
- iGurus shall make available to the Controller, on request and within a reasonable timeframe, all information necessary to demonstrate compliance with the obligations in this DPA and GDPR Article 28.
- On-site audits
- iGurus shall permit and contribute to audits or inspections conducted by the Controller or a mandated third-party auditor, subject to: (a) at least 30 days' prior written notice; (b) execution of a non-disclosure agreement acceptable to iGurus; (c) audits conducted during normal business hours without unreasonably disrupting iGurus' operations; (d) costs borne by the Controller.
- Frequency
- The Controller may exercise audit rights no more than once per calendar year, unless a Personal Data Breach or a supervisory authority investigation reasonably requires more frequent assessment.
Return & Deletion of Data
At the end of the processing relationship, iGurus will return or delete Personal Data as instructed.
- On termination
- Within 30 days of the expiry or termination of the MSA or the relevant Order Form, iGurus shall, at the Controller's written election: (a) securely delete all Personal Data processed under this DPA and certify deletion in writing; or (b) return all Personal Data to the Controller in a machine-readable format (CSV or JSON) and then delete all copies.
- Legal retention obligations
- iGurus may retain Personal Data beyond the deletion period where — and only to the extent that — retention is required by applicable law (e.g., tax, financial reporting, or anti-fraud obligations). Any such data shall continue to be protected by the obligations in this DPA.
- Backup retention
- System backups containing Personal Data are purged on a rolling cycle. iGurus shall ensure that all backup copies are deleted no later than 90 days following the deletion instruction.
Liability
Liability between the parties in respect of this DPA is governed by the limitations set out in the MSA, subject to the exceptions below.
- MSA cap applies
- Each party's total aggregate liability under or in connection with this DPA is subject to the limitations of liability set out in the MSA.
- Processor liability to regulators
- Where iGurus is held liable by a supervisory authority or court for a breach of this DPA caused by the Controller's instructions, the Controller shall indemnify iGurus for such liability to the extent attributable to the Controller.
- Data subject claims
- If a Data Subject brings a claim against iGurus in respect of processing carried out under this DPA, iGurus shall notify the Controller promptly. The parties shall cooperate in good faith in defending such claims. Each party shall be liable for the damage caused by its own processing that infringes applicable data protection law.
Governing Law
This DPA is governed by the laws of the State of Indiana, USA, without regard to conflict of law principles, except to the extent that mandatory provisions of applicable data protection law (including GDPR, UK GDPR, or equivalent) require otherwise.
For EU and UK customers, where applicable data protection law requires a specific supervisory authority or court to have jurisdiction over disputes arising from this DPA, the parties agree to submit to that jurisdiction in respect of such disputes.
Attorney review required: This DPA is AI-drafted. It must be reviewed by a licensed attorney qualified in US, EU, and UK data protection law before it is presented to, or executed by, any customer. It does not constitute legal advice and is not a substitute for attorney-reviewed documentation.
Contact
For all DPA-related queries, data subject rights requests, breach notifications, and audit enquiries:
Registered address: iBrothers Group LLC, Greenwood, Indiana, USA
Social Sharing