Skip to content

Legal

Data Processing Addendum (DPA)

Effective / last updated: July 14, 2026· Connectivo, Inc.

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Controller” or “Institution”) and Connectivo, Inc. (“Processor” or “Connectivo”) for the provision of the Connectivo Accessibility Platform (the “Services”). It governs Connectivo’s processing of Personal Data on the Institution’s behalf.

This standard DPA is intended to be executed together with your customer agreement. A signature-ready copy is available on request from [email protected].

1. Definitions

Capitalized terms not defined here have the meaning given in the agreement or in applicable Data Protection Laws. “Data Protection Laws” means all laws applicable to the processing of Personal Data under the agreement, including the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and FERPA, as applicable. “Personal Data,” “Controller,” “Processor,” “Data Subject,” and “processing” have the meanings in the GDPR. “Standard Contractual Clauses” (“SCCs”) means the clauses approved by the European Commission for transfers of Personal Data to third countries.

2. Roles & scope

The Institution is the Controller and Connectivo is the Processor of Personal Data processed under the Services. Where the Institution is itself a processor, Connectivo acts as a sub-processor. Connectivo processes Personal Data only to provide the Services and as described in Annex A. This DPA applies to the extent Connectivo processes Personal Data subject to Data Protection Laws.

3. Processing on documented instructions

Connectivo will process Personal Data only on the Institution’s documented instructions (including as set out in the agreement, this DPA, and configuration of the Services), unless required by law, in which case Connectivo will inform the Institution unless legally prohibited. Connectivo will promptly inform the Institution if, in its opinion, an instruction infringes Data Protection Laws. Connectivo does not sell Personal Data and does not use Personal Data for its own purposes, for advertising, or to train or improve AI models — except where the Institution documents its opt-in.

4. Confidentiality

Connectivo ensures that personnel authorized to process Personal Data are bound by confidentiality obligations and receive appropriate data-protection and security training, and it limits access to those with a need to know.

5. Security measures

Connectivo implements and maintains appropriate technical and organizational measures to protect Personal Data, as summarized in Annex B and in our Security & Trust Overview, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects.

6. Sub-processors

The Institution provides general authorization for Connectivo to engage sub-processors to support the Services. Connectivo maintains a current list at connectivo.ai/trust/subprocessors (Annex C), imposes data-protection obligations on each sub-processor no less protective than this DPA, and remains liable for its sub-processors. Connectivo will give the Institution advance notice (generally at least 30 days) of any intended addition or replacement of a sub-processor, and the Institution may object on reasonable data-protection grounds.

7. Assistance with data-subject rights

Taking into account the nature of the processing, Connectivo will assist the Institution by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights (access, rectification, erasure, restriction, portability, and objection), and will promptly forward any such request it receives directly to the Institution.

8. Personal-data breaches

Connectivo will notify the Institution without undue delay and, in any event, within 72 hoursafter becoming aware of a confirmed Personal Data Breach affecting the Institution’s Personal Data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed. Connectivo will provide reasonable assistance to the Institution’s breach-handling obligations, followed by a post-incident report.

9. International transfers

By default, Personal Data of U.S. institutions is processed in the United States. Where Connectivo processes Personal Data subject to the GDPR and transfers it outside the EEA/UK to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses are incorporated into this DPA by reference and completed with the details in the Annexes. Connectivo will assist with transfer impact assessments as reasonably required.

10. CCPA/CPRA service-provider terms

Where the CCPA applies, Connectivo acts as a Service Provider. Connectivo will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Services, or as otherwise permitted by the CCPA; (c) retain, use, or disclose Personal Data outside the direct business relationship; or (d) combine Personal Data with data from other sources except as permitted by the CCPA. Connectivo certifies that it understands and will comply with these restrictions.

11. FERPA terms

To the extent Connectivo processes “education records” under FERPA, Connectivo acts as a “school official” with a legitimate educational interest, under the Institution’s direct control, uses such data only for the authorized purpose, and does not re-disclose it except as permitted by FERPA and the Institution. As described in our Privacy Policy, Connectivo does not store education records in the ordinary course.

12. Return & deletion of data

On expiry or termination of the Services, Connectivo will, at the Institution’s choice, return and/or delete Personal Data within 90 days by cryptographic erasure, and delete existing copies unless retention is required by law. On request, Connectivo will certify completion of deletion.

13. Audits

Connectivo will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Institution or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits. Connectivo may satisfy audit requests by providing its HECVAT, penetration-test summaries, and relevant documentation under NDA.

Annexes

Annex A — Details of processing

Subject matterProvision of the Connectivo Accessibility Platform (accessibility scanning, remediation, and governance).
DurationThe term of the agreement plus the deletion period (up to 90 days).
Nature & purposeScanning and remediating digital content for accessibility; account administration; reporting.
Categories of Data SubjectsInstitution administrators and authorized users; individuals whose personal data may incidentally appear in Institution-published content.
Categories of Personal DataName, business/institutional email, role, account identifiers, and log data. Special-category data is not requested and should not be provided; Connectivo does not process PHI, PCI, or biometric data.
FrequencyContinuous, for the duration of the Services.

Annex B — Technical & organizational measures

Summary (full detail in the Security & Trust Overview): encryption in transit (TLS 1.2/1.3, mTLS) and at rest (AES-256) with HSM-backed key management; SSO (SAML/OIDC), MFA, and role-based access control; least-privilege administration with just-in-time elevation and audit logging; network segmentation and Web Application Firewall; SAST/SCA/DAST and independent penetration testing; 24×7 monitoring and incident response with a 72-hour breach-notification commitment; encrypted, cross-region backups with tested recovery; personnel background checks and mandatory security training; and tenant isolation with per-tenant keys.

Annex C — Approved sub-processors

The current list of approved sub-processors is maintained at connectivo.ai/trust/subprocessors and incorporated by reference.

Contact & execution

To request a signature-ready copy of this DPA or to discuss customer-specific terms, contact [email protected]. This DPA supplements and, in case of conflict regarding the processing of Personal Data, prevails over the agreement.