Data Processing Agreement
Last updated: 2026-06-10
Awaiting counsel review — this document is a template and is not yet legally final.
This Data Processing Agreement (DPA) governs Gradefeed's processing of personal data on behalf of the school. A school accepts this DPA by completing the KVKK attestation in the app.
Roles
The school is the data controller. Gradefeed is the data processor and processes personal data only on the school's documented instructions.
Subject matter and duration
Processing covers exam grading and return for the duration of the school's use of Gradefeed and the retention window in the Privacy Policy.
Sub-processors and cross-border transfer
Gradefeed uses the sub-processors listed below. Paper PDFs and rubric content are transmitted to Anthropic (US) during grading — a cross-border transfer the school accepts by attesting. A KVKK-strict school may find this unacceptable; that is a known limitation of this version.
Security
Data is encrypted in transit and at rest by the underlying providers. Access to production data is limited to Gradefeed operators.
| Vendor | Purpose | Data | Region |
|---|---|---|---|
| Supabase | Database, auth, file storage | All app data + paper PDFs | eu-central-1 |
| Vercel | Application hosting, edge | App requests + logs | fra1 / global edge |
| Anthropic | AI grading + objection review | Paper PDFs + rubric content (in-flight) | US |
| Resend | Transactional email | Recipient email + subject + body | eu-west-1 |
| Cloudflare | DNS, email forwarding | DNS queries | global |