Data Processing

Data Processing Agreement (DPA)

The agreement under Article 28 of Regulation (EU) 2016/679 (GDPR) between the customer as controller and LECTURE GURU, s. r. o. as processor for the use of the LectureGuru service.

When it applies

The agreement applies automatically upon acceptance of the Terms and Conditions if you are a business or an organization and you upload content containing personal data of other people. No separate signature is required.

Who is who

The controller is the customer, who determines the purposes and means of processing the uploaded content. The processor is LECTURE GURU, s. r. o., which processes that content only on the customer’s instructions.

What it covers

Eleven clauses on instructions, security, subprocessors, data subject rights, breach notification and deletion, complemented by three annexes: the specification of the processing, the technical and organisational measures, and the list of approved subprocessors.

1. Subject matter and parties

1.1 The processor is LECTURE GURU, s. r. o., with its registered seat at Bottova 8005/5, 811 09 Bratislava - mestská časť Staré Mesto, Slovak Republic, company ID 57517690, tax ID 2122824154 (‘Processor’). The controller is the customer — a business or organization that has entered into an agreement for the provision of the LectureGuru service (the Terms and Conditions or an individual agreement — the ‘Main Agreement’) (‘Controller’).

1.2 The Processor provides the Controller with the LectureGuru platform for creating and updating training and presentation materials (the ‘Service’). In providing the Service it processes personal data on behalf of the Controller to the extent set out in Annex 1.

1.3 This agreement is concluded under Article 28 of Regulation (EU) 2016/679 (GDPR), forms an annex to the Terms and Conditions and applies automatically upon acceptance of the Main Agreement; no separate signature is required. It remains in force for the duration of the Main Agreement.

2. Controller instructions

2.1 The Processor processes personal data only on documented instructions from the Controller; use of the Service’s features (uploading a document, starting a generation, configuring source monitoring, deleting a project) and written instructions sent to privacy@lecture-guru.com are considered such instructions.

2.2 If the Processor considers an instruction to infringe the GDPR, it will inform the Controller without undue delay.

2.3 The Processor does not use the Controller’s personal data to train artificial intelligence models. Under the API terms the Processor relies on, its AI subprocessors OpenAI and Anthropic do not use content submitted through their APIs to train their models either.

3. Confidentiality

Persons authorised to process personal data at the Processor are bound by a duty of confidentiality that continues after their engagement with the Processor ends.

4. Security

The Processor has implemented the technical and organisational measures under Article 32 GDPR set out in Annex 2 and maintains them having regard to the state of the art and the risks of the processing.

5. Subprocessors

5.1 The Controller grants general authorisation to engage the subprocessors listed in Annex 3.

5.2 The Processor will give at least 14 days’ advance notice (by e-mail or in the application) of any change or addition of a subprocessor. The Controller may raise a reasoned objection; if the parties do not reach agreement, the Controller may terminate the Main Agreement with effect from the day the new subprocessor is deployed.

5.3 The Processor has agreements in place with its subprocessors imposing obligations equivalent to those in this agreement and remains responsible for their performance.

6. Data subject rights and assistance

6.1 The Processor will assist the Controller in handling data subject requests (access, rectification, erasure and other rights under Chapter III GDPR). A request received directly by the Processor will be forwarded to the Controller without undue delay.

6.2 The Processor will also assist with data protection impact assessments (DPIA), prior consultation with the supervisory authority, and compliance with the obligations under Articles 32 to 36 GDPR.

7. Personal data breaches

The Processor will notify the Controller of a personal data breach without undue delay after becoming aware of it, at the latest within 48 hours, together with a description of the nature of the breach, its likely consequences and the measures taken.

8. Transfers to third countries

Transfers of data to subprocessors outside the EEA take place on the basis of an adequacy decision (the EU-U.S. Data Privacy Framework) or the EU standard contractual clauses; details are set out in Annex 3.

9. Audit

The Processor will make available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and will allow for an audit conducted by the Controller or an appointed auditor, announced at least 30 days in advance, no more than once a year, during business hours and without unreasonable disruption of operations. The costs of the audit are borne by the Controller.

10. Deletion and return of data

After the end of the Main Agreement the Processor will, at the Controller’s choice, return the data (exported in the formats offered by the Service within 30 days) or delete it; absent an instruction it will delete the personal data within 30 days of the end of the Main Agreement and copies held in backups at the latest within 90 days, except for data it is required to retain by law.

11. Final provisions

11.1 Liability of the parties is governed by the Main Agreement; this is without prejudice to liability under Article 82 GDPR.

11.2 This agreement is governed by the law of the Slovak Republic. In the event of a conflict between this agreement and the Main Agreement, this agreement prevails in matters of personal data protection.

11.3 This agreement takes effect upon acceptance of the Main Agreement and does not require signatures of the parties. Enterprise customers may request a countersigned standalone copy at privacy@lecture-guru.com.

11.4 This agreement is drawn up in Slovak; versions in other languages are provided for convenience and, in the event of a discrepancy, the Slovak version prevails.

Annex 1 — Specification of the processing

  • Subject matter: provision of the LectureGuru platform — creating interactive presentations, narrated videos, PDF exports and quizzes from the Controller’s materials, monitoring source changes (WebWatcher) and producing demo videos from a web address (Magic Demo Video).
  • Nature and purpose: storing source materials, automated analysis and content generation by artificial intelligence, voice synthesis, image generation, rendering of outputs, monitoring of source changes, delivery of outputs and backups.
  • Categories of data subjects: users of the Controller’s accounts; viewers of presentations shared by the Controller; individuals named in uploaded documents and in monitored sources (in particular employees and, where applicable, the Controller’s clients).
  • Categories of data: identification and contact data of users (name, work e-mail); presentation viewing data (viewer identifier, slides viewed, quiz answers); personal data contained in uploaded materials, the scope of which is determined by the Controller. Special categories of data under Article 9 GDPR must not be uploaded unless the parties agree otherwise.
  • Duration: for the term of the Main Agreement and the deletion periods under clause 10.

Annex 2 — Technical and organisational measures

  • Protection of personal data in transit and at rest appropriate to the risk and nature of the processing.
  • Identity and access management based on roles, least privilege, secure authentication, and confidentiality obligations.
  • Logical separation of customer environments and controlled storage and delivery of files.
  • Measures protecting the confidentiality, integrity, availability, and resilience of systems, including backup, recovery, and secure deletion of data.
  • Monitoring, abuse prevention, and vulnerability and change management.
  • Supplier governance and contractual data-protection and security requirements.
  • Documented procedures for security-incident response, business continuity, and personal-data-breach notification under clause 7 of this agreement.
  • Regular review of the appropriateness and effectiveness of the measures. A detailed operational description and reasonable supporting evidence are available to authorized Controller contacts in the confidential Customer Security Annex; that annex becomes a contractual supplement where it is referenced in an Order Form or a countersigned standalone copy of this agreement.

Annex 3 — Approved subprocessors

SubprocessorPurposeLocation of processingTransfer safeguard
VercelApplication hostingUSA/EUDPF / SCC
SupabaseDatabase hostingUSA/EUDPF / SCC
CloudflareFile and video storage; Service-security controlsUSA/EUDPF / SCC
OpenAIAI text generationUSASCC / DPF
AnthropicAI generation for selected featuresUSASCC / DPF
ElevenLabsVoice synthesisUSASCC / DPF
ModalConverting uploaded documents to textEUIn the EEA; otherwise SCC
FirecrawlFetching customer-submitted web pagesUSASCC / DPF
ReplicateAI image generationUSASCC / DPF
Trigger.devBackground job processingUSA/EUSCC / DPF
ResendE-mail deliveryUSASCC / DPF
StripePayments (billing data only)USA/EUSCC / DPF
PostHogProduct analytics (user data, not document content)EUIn the EEA; otherwise SCC
ComposioOnly where the customer connects third-party appsUSASCC / DPF
Browserbase / HyperbrowserBrowser sessions for automated demo-video recordingUSA/EUSCC / DPF

The current list is published on this page. We give notice of any change or addition of a subprocessor at least 14 days in advance under clause 5.2.

Contact information

LECTURE GURU, s. r. o.

Bottova 8005/5, 811 09 Bratislava - mestská časť Staré Mesto, Slovakia
Company ID (IČO): 57517690 · Tax ID (DIČ): 2122824154

Data protection contact

Email: privacy@lecture-guru.com

General questions: support@lecture-guru.com

Web: lecture-guru.com

Enterprise customers may request a countersigned standalone copy of this agreement at privacy@lecture-guru.com. Processing for which we act as controller is described in our Privacy Policy.

Data Processing Agreement (DPA) | LectureGuru