The agreement under Article 28 of Regulation (EU) 2016/679 (GDPR) between the customer as controller and LECTURE GURU, s. r. o. as processor for the use of the LectureGuru service.
The agreement applies automatically upon acceptance of the Terms and Conditions if you are a business or an organization and you upload content containing personal data of other people. No separate signature is required.
The controller is the customer, who determines the purposes and means of processing the uploaded content. The processor is LECTURE GURU, s. r. o., which processes that content only on the customer’s instructions.
Eleven clauses on instructions, security, subprocessors, data subject rights, breach notification and deletion, complemented by three annexes: the specification of the processing, the technical and organisational measures, and the list of approved subprocessors.
1.1 The processor is LECTURE GURU, s. r. o., with its registered seat at Bottova 8005/5, 811 09 Bratislava - mestská časť Staré Mesto, Slovak Republic, company ID 57517690, tax ID 2122824154 (‘Processor’). The controller is the customer — a business or organization that has entered into an agreement for the provision of the LectureGuru service (the Terms and Conditions or an individual agreement — the ‘Main Agreement’) (‘Controller’).
1.2 The Processor provides the Controller with the LectureGuru platform for creating and updating training and presentation materials (the ‘Service’). In providing the Service it processes personal data on behalf of the Controller to the extent set out in Annex 1.
1.3 This agreement is concluded under Article 28 of Regulation (EU) 2016/679 (GDPR), forms an annex to the Terms and Conditions and applies automatically upon acceptance of the Main Agreement; no separate signature is required. It remains in force for the duration of the Main Agreement.
2.1 The Processor processes personal data only on documented instructions from the Controller; use of the Service’s features (uploading a document, starting a generation, configuring source monitoring, deleting a project) and written instructions sent to privacy@lecture-guru.com are considered such instructions.
2.2 If the Processor considers an instruction to infringe the GDPR, it will inform the Controller without undue delay.
2.3 The Processor does not use the Controller’s personal data to train artificial intelligence models. Under the API terms the Processor relies on, its AI subprocessors OpenAI and Anthropic do not use content submitted through their APIs to train their models either.
Persons authorised to process personal data at the Processor are bound by a duty of confidentiality that continues after their engagement with the Processor ends.
The Processor has implemented the technical and organisational measures under Article 32 GDPR set out in Annex 2 and maintains them having regard to the state of the art and the risks of the processing.
5.1 The Controller grants general authorisation to engage the subprocessors listed in Annex 3.
5.2 The Processor will give at least 14 days’ advance notice (by e-mail or in the application) of any change or addition of a subprocessor. The Controller may raise a reasoned objection; if the parties do not reach agreement, the Controller may terminate the Main Agreement with effect from the day the new subprocessor is deployed.
5.3 The Processor has agreements in place with its subprocessors imposing obligations equivalent to those in this agreement and remains responsible for their performance.
6.1 The Processor will assist the Controller in handling data subject requests (access, rectification, erasure and other rights under Chapter III GDPR). A request received directly by the Processor will be forwarded to the Controller without undue delay.
6.2 The Processor will also assist with data protection impact assessments (DPIA), prior consultation with the supervisory authority, and compliance with the obligations under Articles 32 to 36 GDPR.
The Processor will notify the Controller of a personal data breach without undue delay after becoming aware of it, at the latest within 48 hours, together with a description of the nature of the breach, its likely consequences and the measures taken.
Transfers of data to subprocessors outside the EEA take place on the basis of an adequacy decision (the EU-U.S. Data Privacy Framework) or the EU standard contractual clauses; details are set out in Annex 3.
The Processor will make available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and will allow for an audit conducted by the Controller or an appointed auditor, announced at least 30 days in advance, no more than once a year, during business hours and without unreasonable disruption of operations. The costs of the audit are borne by the Controller.
After the end of the Main Agreement the Processor will, at the Controller’s choice, return the data (exported in the formats offered by the Service within 30 days) or delete it; absent an instruction it will delete the personal data within 30 days of the end of the Main Agreement and copies held in backups at the latest within 90 days, except for data it is required to retain by law.
11.1 Liability of the parties is governed by the Main Agreement; this is without prejudice to liability under Article 82 GDPR.
11.2 This agreement is governed by the law of the Slovak Republic. In the event of a conflict between this agreement and the Main Agreement, this agreement prevails in matters of personal data protection.
11.3 This agreement takes effect upon acceptance of the Main Agreement and does not require signatures of the parties. Enterprise customers may request a countersigned standalone copy at privacy@lecture-guru.com.
11.4 This agreement is drawn up in Slovak; versions in other languages are provided for convenience and, in the event of a discrepancy, the Slovak version prevails.
| Subprocessor | Purpose | Location of processing | Transfer safeguard |
|---|---|---|---|
| Vercel | Application hosting | USA/EU | DPF / SCC |
| Supabase | Database hosting | USA/EU | DPF / SCC |
| Cloudflare | File and video storage; Service-security controls | USA/EU | DPF / SCC |
| OpenAI | AI text generation | USA | SCC / DPF |
| Anthropic | AI generation for selected features | USA | SCC / DPF |
| ElevenLabs | Voice synthesis | USA | SCC / DPF |
| Modal | Converting uploaded documents to text | EU | In the EEA; otherwise SCC |
| Firecrawl | Fetching customer-submitted web pages | USA | SCC / DPF |
| Replicate | AI image generation | USA | SCC / DPF |
| Trigger.dev | Background job processing | USA/EU | SCC / DPF |
| Resend | E-mail delivery | USA | SCC / DPF |
| Stripe | Payments (billing data only) | USA/EU | SCC / DPF |
| PostHog | Product analytics (user data, not document content) | EU | In the EEA; otherwise SCC |
| Composio | Only where the customer connects third-party apps | USA | SCC / DPF |
| Browserbase / Hyperbrowser | Browser sessions for automated demo-video recording | USA/EU | SCC / DPF |
The current list is published on this page. We give notice of any change or addition of a subprocessor at least 14 days in advance under clause 5.2.
LECTURE GURU, s. r. o.
Bottova 8005/5, 811 09 Bratislava - mestská časť Staré Mesto, SlovakiaData protection contact
Email: privacy@lecture-guru.com
General questions: support@lecture-guru.com
Web: lecture-guru.com
Enterprise customers may request a countersigned standalone copy of this agreement at privacy@lecture-guru.com. Processing for which we act as controller is described in our Privacy Policy.