Academy CanLup · Legal information
Corporate data processing
Processing instructions: the customer’s purposes, the provider’s duties and participants’ data.
- The customer defines lawful purposes and corporate data scope.
- The provider processes data within the agreed instructions.
- Region, external processors and time limits are fixed in the specific agreement.
Parties and scope
This document is intended for incorporation into a contract between the corporate customer and the Academy CanLup provider. Publishing it or an employee creating an account does not conclude processing instructions on the company’s behalf. Before processing begins on this basis, the parties specify the parameters below and confirm the agreement in a form establishing their intentions.
Provider: Баца Алла Антоновна. Status: Самозанятый, плательщик налога на профессиональный доход, без ИП. Country: Российская Федерация. Tax / registration number: 890603453994. This preliminary edition does not specify a postal address for formal correspondence; the necessary details must be established before a paid contract is concluded. Email: batsaaleksey@gmail.com.
For the corporate workspace, the customer determines purposes, categories of participants and data, and permitted operations. The provider acts within those instructions. Under Russian law this is processing on an operator’s instructions; where the GDPR applies, it is a controller–processor arrangement to the relevant extent.
Details of the specific agreement
The agreement applies only with completed and agreed parameters. It is not blanket permission to process any information about any person. Changes to purpose, data scope, region or processors are documented before the corresponding processing changes.
- Customer and provider identities, workspace and the customer representative’s authority.
- Subject matter, nature, purposes and duration; categories of people and the permitted personal data.
- Permitted operations, region and actual processing locations, including access from other countries.
- Approved processors and integrations, the data disclosed to them and grounds for external transfers.
- Request and incident contacts, notification deadlines, review of safeguards and completion procedures.
Purposes, data and operations
The ordinary corporate purpose is to provide tools for hosting the organisation’s own materials, managing participant access, assigning tasks and recording completion. People may include employees and others lawfully invited by the company. The specific scope is fixed in the instructions.
Permitted data may include a participant’s name or identifier, work contact, account identifier, organisation, department, role, assignments, responses, attempts, progress, work materials and related technical events. Ordinary use does not require passport details, health information or other special-category data.
Within the instructions, operations may include receipt, recording, organisation, storage, updating, retrieval, use, authorised access, restriction, deletion and destruction. Disclosure to an external processor requires agreed conditions. The provider’s independent advertising use of corporate materials is not included.
Customer obligations
- Establish a lawful purpose and basis, give participants required information and obtain consent where required. A company–provider contract does not automatically establish the basis for processing an employee’s data.
- Provide necessary, accurate data; limit administrator authority and promptly revoke unnecessary access.
- Check rights to materials and communicate restrictions affecting their use.
- Do not instruct processing of special-category, biometric or children’s data without separate legal and technical arrangements.
Provider obligations
- Process corporate data only on documented lawful instructions for agreed purposes. Notify the customer of an identified unlawful instruction and suspend the disputed operation to the necessary extent.
- Maintain confidentiality and restrict access to authorised people subject to appropriate duties.
- Apply necessary organisational and technical safeguards, observe applicable localisation requirements and do not expand recipients merely because a plan changes.
- Provide information and documents demonstrating compliance with instructions and safeguards on request, assist with enquiries and notify relevant incidents as required by law.
- Do not use instructed data for independent incompatible purposes. Processing for another independent purpose requires a separate lawful basis and the necessary information to individuals; these instructions do not grant that permission.
Access and safeguards
Workspaces, departments and roles restrict corporate access. Personal Inbox, Vault and conversations do not become corporate data simply through organisation membership. Moving material between areas requires permission compatible with its original access rights.
Agreed measures cover access management, connection and credential protection, significant-event records, vulnerability handling, incident response and completion controls. Protecting a connection must not be described as encrypting all database contents.
Compliance review is reasonably coordinated in advance without exposing other customers’ data or secrets or threatening service operation. This does not limit mandatory regulatory powers or evidence required by law.
Region and external processors
A region is established for the specific workspace after checking deliverability and the requirements applicable to participants’ data. The company’s registration country does not determine all localisation obligations. No automatic deployment in every customer’s country may be assumed without separate confirmation.
Primary-database location and absence of international transfers are different characteristics. Assessment includes external connections, service messages, diagnostics and processor access. Processing outside an agreed territory requires an applicable lawful basis and the necessary procedures.
Engaging another processor requires the authorisation specified in the agreement. The customer receives information needed to assess recipients, functions, data and processing geography. General authorisation requires an agreed advance-change notice and objection procedure. Equivalent duties are imposed on the processor; engaging it does not remove the provider’s own obligations.
A connection incompatible with territorial restrictions must not be enabled until a compliant arrangement is agreed. Publishing these rules does not establish that such a mode has already been implemented for a particular customer.
Participant requests
Corporate-data requests are referred to the party authorised to determine the action, with necessary assistance from the other party. The provider does not disclose corporate data on an unverified request, and the customer cannot use these instructions to request someone’s private area.
The parties help locate data, determine the basis and carry out lawful correction, restriction, export or deletion. Referring a request is not used to evade a required response. Requests relating to the provider’s independent purposes are handled in its own role.
Incidents and cooperation
When a security breach affecting instructed data is identified, the provider informs the customer without undue delay through the agreed channel. Maximum notification time and responsible contacts are fixed so that the customer can meet mandatory deadlines. An incomplete investigation does not justify postponing the initial notification.
As available at each stage, notification describes the event, affected categories and approximate data volume, possible consequences, measures taken and a contact. Material updates follow. The parties preserve necessary evidence and allocate mandatory notification actions according to their roles.
Completing the processing
When the agreed term ends or the customer gives a lawful instruction, the provider stops the relevant processing and returns or deletes data through the agreed procedure within applicable mandatory deadlines. Export format, collection period and deletion confirmation are specified before processing begins.
Where law requires retention of particular records, the provider identifies the basis and necessary scope, restricts access and does not use them for incompatible purposes. Deleting a corporate workspace does not automatically delete an independent personal account or data lawfully processed for another purpose.
Independent purposes and mandatory rules
Customer relationship management, payment accounting, service protection and independent personal-account features may involve purposes determined by the provider. These are disclosed in the privacy notice and are not concealed within corporate instructions.
Where the GDPR applies, the arrangement must also meet Article 28, assistance requirements under Articles 32–36 and Chapter V requirements for international transfers. Processing subject to Russian law must meet mandatory requirements of Federal Law No. 152-FZ. Language selection or signing this document alone does not demonstrate completion of all procedures.