Request a security review

Data Processing Agreement

For customers who need a processor agreement in place.

Last updated 1 October 2026

Overview Terms Privacy DPA Refunds Security Subprocessors SLA Questionnaire

How to use this. This agreement applies automatically to every paid customer as part of the Terms of Service — you do not need to sign anything. If your procurement process requires a signed copy, email info@fullpass.ai and we will return one countersigned.

1. Roles

For personal data contained in the courses you upload and in the reports produced from them, you are the controller and FULLPASS is the processor. For your own account and billing data, we are the controller; that is covered by our Privacy Policy.

2. Subject matter and duration

We process your data in order to analyse e-learning packages and produce QA reports, for as long as your account is open, plus the retention periods set out below.

3. Nature of the processing

CategoryDetail
Data subjectsYour staff who use FULLPASS; any individuals named in your course content
Personal dataNames, work email addresses, optional profile pictures; any personal data present in course text or narration
Special category dataNone requested or required. Do not upload courses containing special category data without telling us first
Processing operationsStorage of reports, automated text and layout analysis, optional reading of text and speech inside video
RetentionTrial 30 days · Solo 180 days · Studio 365 days · Team 365 days; account data until the account is closed

4. Our obligations

We will: process your data only on your documented instructions, which these terms and your use of the product constitute; ensure everyone with access is bound by confidentiality; apply the technical and organisational measures described on our Security page; assist you with data subject requests, security incidents and impact assessments; and, at your choice, delete or return your data when the agreement ends.

5. Course files

Course packages are processed in memory only and are never written to persistent storage. They cannot be recovered by us after a scan, and they are not included in backups. Only the report is retained.

6. Sub-processors

You give general authorisation for the sub-processors listed on our Subprocessors page. We will give at least 30 days' notice by email before adding one, and you may object; if we cannot resolve an objection you may terminate the affected service and receive a pro-rata refund.

7. International transfers

Where data is transferred outside the UK or EEA, it is covered by the relevant Standard Contractual Clauses or an adequacy decision, as recorded for each sub-processor.

8. Security incidents

We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with what we know at the time and what we are doing about it.

9. Audit

We will provide the information reasonably needed to demonstrate compliance, including answering a security questionnaire. On-site audits may be requested once per year with 30 days' notice, at your cost, subject to reasonable confidentiality terms.

10. Deletion

On termination we delete your reports and account data. You can trigger the same deletion yourself at any time from the Account screen. Backups age out within 7 days.

11. Liability

The liability provisions of the Terms of Service apply to this agreement.

12. Signature

Accepted on behalf of FULLPASS by the FULLPASS team. A countersigned copy naming your organisation is available on request from info@fullpass.ai.