Last updated: Sept 24, 2025
Important: This Data Processing Agreement ("DPA") is an integral part of our service agreement with educational institutions. XFocus AS exclusively serves schools and educational organizations. This DPA governs how we process personal data on behalf of schools in compliance with GDPR Article 28.
This agreement should be read together with our Terms of Service and Privacy Policy.
Data Controller: The educational institution (school, district, or organization) that determines the purposes and means of processing personal data.
Data Processor: XFocus AS, acting on behalf of and under the instructions of the Controller.
This DPA governs the processing of personal data by XFocus AS when providing educational platform services to Controllers, in accordance with GDPR Article 28.
XFocus processes the following categories of personal data on behalf of Controllers:
Processing is performed solely to provide educational platform services including project-based learning management, student collaboration tools, and educational content delivery as instructed by the Controller.
Processing continues for the duration of the service agreement. Upon termination, data will be returned or anonymized according to Section 8 of this DPA.
XFocus AS commits to:
The Controller provides general authorization for XFocus AS to engage the sub-processors listed below. XFocus AS will notify Controllers of any intended changes concerning sub-processors, giving the Controller opportunity to object.
| Service Provider | Purpose | Location | Data Processed |
|---|---|---|---|
| Amazon Web Services | Infrastructure & Hosting | EU (Frankfurt) | All platform data |
| Stripe | Payment Processing | EU/US | Billing contact information only |
| OpenAI | AI Learning Features | US | Conversation content (optional feature) |
| Resend | Email Services | US | Email addresses, notification content |
| Sentry | Error Monitoring | US | Error logs, performance data (anonymized) |
Note: This list is maintained and updated at xfocus.no/legal/dpa
XFocus AS ensures all sub-processors are bound by data protection obligations no less protective than those in this DPA and remain fully liable for sub-processor performance.
XFocus AS will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Controller's data.
Breach notifications will include:
XFocus AS will assist the Controller in fulfilling obligations to respond to data subject requests for:
XFocus AS will respond to Controller requests for assistance within 10 business days or as required to meet regulatory deadlines.
Upon termination of services, XFocus AS will, at the Controller's choice:
Anonymized data may be retained for statistical analysis and service improvement purposes.
Anonymization will be performed using industry-standard techniques to ensure data cannot be re-identified. This includes removing direct identifiers, generalizing quasi-identifiers, and applying appropriate statistical disclosure controls.
Complete anonymization does not apply to data XFocus AS is required to retain under EU or Norwegian law. Such data will be protected and processing limited to legal requirements only.
The Controller has the right to conduct audits to verify XFocus AS's compliance with this DPA, subject to:
XFocus AS maintains records of processing activities and will provide relevant compliance documentation upon reasonable request.
Liability under this DPA is subject to the limitations set forth in the main service agreement, except where prohibited by applicable law.
Each party will defend and indemnify the other against claims arising from that party's breach of this DPA or applicable data protection laws.
Personal data is primarily processed within the EEA. Any transfers outside the EEA are conducted using appropriate safeguards:
This DPA remains in effect for the duration of the service agreement. Provisions relating to data protection obligations survive termination to the extent required by applicable law.
This DPA is governed by Norwegian law and GDPR. Disputes shall be resolved according to the dispute resolution provisions in the main service agreement.
Data Protection Contact:
XFocus AS
General Support: support@xfocus.no
By using XFocus services as an educational institution, the Controller agrees to the terms of this Data Processing Agreement. This DPA forms part of and is incorporated into the main service agreement.