Data Processing & Sub-processors
How EaseAcademia processes personal data on behalf of schools, and the sub-processors we rely on to deliver the platform.
- Effective
- 23 July 2026
- Last updated
- 23 July 2026
This page combines our Data Processing Addendum (DPA) — which applies when EaseAcademia processes personal data on behalf of a school — with the current register of sub-processors we engage. It supplements our Terms of Service and Privacy Policy.
1. Roles of the parties
For personal data contained in Customer Data — student, guardian and staff records — the school is the data controller and EaseAcademia is the data processor. EaseAcademia processes such personal data only on the school’s documented instructions, including as set out in the Terms and this addendum, except where required otherwise by law.
2. Scope and details of processing
- Subject matter — provision of the EaseAcademia school management platform.
- Duration — for the term of the subscription, plus any deletion or return period described below.
- Nature and purpose — hosting, storage, processing and transmission of Customer Data to operate the Services.
- Categories of data subjects — students and their guardians, staff, and other users the school adds.
- Types of personal data — identity and contact details, enrolment, academic and attendance records, behaviour, health/welfare notes, HR and finance records, as configured by the school.
3. Our obligations as processor
EaseAcademia will:
- process personal data only on documented instructions from the school;
- ensure persons authorised to process the data are bound by confidentiality obligations;
- implement appropriate technical and organisational security measures (see our Security page);
- assist the school, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification and impact-assessment obligations;
- make available information necessary to demonstrate compliance and allow for reasonable audits; and
- at the school’s choice, delete or return personal data at the end of the engagement, as described below.
4. Sub-processors
EaseAcademia engages the sub-processors below to help provide the Services. Each is bound by a written agreement imposing data-protection obligations no less protective than those in this addendum. This list is the authoritative, current register:
| Sub-processor | Purpose | Location | Data handled |
|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure, application hosting, encrypted file storage, and transactional email delivery | United States / selected AWS region | All platform data (encrypted at rest and in transit) |
| Supabase, Inc. | Managed database hosting for the platform’s primary data store | United States / selected region | All platform data (encrypted at rest and in transit) |
| Paystack Payments Limited | Card and bank payment processing for school fees and store purchases | Nigeria | Payer name, contact details and transaction metadata |
We may update this list as our infrastructure evolves. Where required, we will give schools advance notice of a new sub-processor so they can raise a reasonable objection. To receive change notifications, email privacy@easeacademia.com.
5. International transfers
Where personal data is transferred to a country without an adequacy determination, EaseAcademia relies on appropriate safeguards — such as standard contractual clauses or equivalent mechanisms — to protect the data, and requires the same of its sub-processors.
6. Security measures
We maintain encryption in transit and at rest, role-based access control, network isolation, logging and monitoring, regular backups, and a documented incident-response process. A fuller description is available on our Security page and forms part of this addendum.
7. Personal data breaches
EaseAcademia will notify the affected school without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide the information reasonably needed for the school to meet its own notification obligations.
8. Return and deletion of data
On termination or expiry of the subscription, and at the school’s election, EaseAcademia will return or delete Customer Data within a reasonable period, except to the extent retention is required by law. Backups are deleted in the ordinary course of our backup-rotation cycle.
9. Contact
For DPA requests, to sign a counter-signed copy, or to ask about sub-processors, contact our privacy team at privacy@easeacademia.com or our Data Protection Officer at dpo@easeacademia.com.
Related documents