Skip to content
HTECH Solutions
Legal

Data Processing Addendum

Last updated: 16 August 2026

This Data Processing Addendum ("DPA") forms part of the agreement between a customer institution ("Customer") and HTECH Solutions ("Processor", "we", "us") for the provision of the HTECH University Management System ("HTECH UMS" or the "Services") (the "Agreement"). It applies to the extent that we process personal data on the Customer's behalf in providing the Services. It does not apply to the htech-ums.com marketing website, which is covered by our Privacy Policy and Cookie Policy. This DPA takes effect between the parties when it is incorporated into the Agreement and its Annexes are completed for the Customer's deployment.

1. Definitions

"Applicable Data Protection Law" means all laws relating to data protection and privacy applicable to the processing of Personal Data under the Agreement, including, where applicable, the UK GDPR, the EU General Data Protection Regulation (Regulation (EU) 2016/679), and any implementing or successor legislation.

"Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings given in Applicable Data Protection Law.

"Sub-processor" means any third party engaged by the Processor to process Personal Data on the Customer’s behalf. Capitalised terms not defined here have the meaning given in the Agreement.

2. Roles of the parties

For Personal Data processed in providing the Services, the Customer is the Controller and HTECH Solutions is the Processor. Where the Customer acts as a processor on behalf of a third-party controller, HTECH Solutions acts as a sub-processor.

Each party complies with its obligations under Applicable Data Protection Law. The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.

3. Processing on instructions

HTECH Solutions processes Personal Data only on the Customer’s documented instructions — including as set out in the Agreement and this DPA, and as necessary to provide the Services — unless required to do otherwise by law, in which case it informs the Customer of that legal requirement before processing, unless the law prohibits it.

HTECH Solutions informs the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

4. Confidentiality

HTECH Solutions ensures that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the Personal Data only on the Customer’s instructions.

5. Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals, HTECH Solutions implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with Article 32 of the GDPR. Those measures are described in Annex 2.

6. Sub-processors

The Customer provides a general authorisation for HTECH Solutions to engage Sub-processors to process Personal Data, subject to this section. The current Sub-processors are described in Annex 3.

HTECH Solutions imposes on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each Sub-processor’s obligations.

HTECH Solutions gives the Customer prior notice of any intended addition or replacement of a Sub-processor and a reasonable opportunity to object on reasonable data-protection grounds.

7. Assistance with data-subject rights

Taking into account the nature of the processing, HTECH Solutions assists the Customer, by appropriate technical and organisational measures and insofar as possible, to fulfil the Customer’s obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law. If a Data Subject contacts HTECH Solutions directly, HTECH Solutions refers them to the Customer.

8. Assistance with the Customer’s compliance

Taking into account the nature of processing and the information available to it, HTECH Solutions assists the Customer in ensuring compliance with its obligations relating to the security of processing, notification of Personal Data Breaches, data protection impact assessments, and prior consultation with a Supervisory Authority.

9. Personal Data Breach

HTECH Solutions notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer’s Personal Data, and provides sufficient information to enable the Customer to meet any obligation to report to, or notify, a Supervisory Authority or affected Data Subjects.

10. Return or deletion of Personal Data

On termination or expiry of the Services, and at the Customer’s choice, HTECH Solutions deletes or returns the Personal Data to the Customer and deletes existing copies, unless retention is required by law. Personal Data held in routine backups is deleted in the ordinary course within the applicable backup-retention period.

11. Audits and records

HTECH Solutions makes available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates — subject to reasonable prior notice, confidentiality obligations, reasonable frequency limits, and measures to protect the security and data of other customers.

12. International transfers

HTECH Solutions does not transfer the Customer’s Personal Data to a country outside the UK or the EEA that is not subject to an adequacy decision unless it has put in place a transfer mechanism required by Applicable Data Protection Law — such as the applicable Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum — which are incorporated into this DPA by reference where they apply.

13. Liability, term, and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

This DPA takes effect on its incorporation into the Agreement and continues for as long as HTECH Solutions processes Personal Data on the Customer’s behalf. In the event of a conflict between this DPA and the rest of the Agreement regarding the processing of Personal Data, this DPA prevails. This DPA is governed by the law and subject to the jurisdiction stated in the Agreement.

Annex 1 — Details of the processing

Subject matter: provision of the HTECH UMS platform and the modules the Customer uses.

Duration: the term of the Agreement, plus any period during which HTECH Solutions is permitted or required to retain the Personal Data.

Nature and purpose: hosting, storing, and processing Personal Data as necessary to operate the Services and their modules (for example admissions, student records, registration, examinations, finance, HR, and related functions).

Categories of Data Subjects: applicants, students, alumni, staff, faculty, and other individuals whose data the Customer manages in the Services.

Types of Personal Data: identity and contact details; academic and enrolment records; assessment and examination data; financial and fee information; employment and HR data; and account, authentication, and usage data. The Services process special-category data (such as health data) only where the Customer configures and uses modules for that purpose and on the Customer’s instructions.

Annex 2 — Technical and organisational measures

HTECH Solutions maintains measures appropriate to the risk, including:

  • Encryption of Personal Data in transit (TLS) and encryption at rest for sensitive data.
  • Role-based access control on a least-privilege basis, with multi-factor authentication for administrative access.
  • Logical isolation and access controls between customers and between environments.
  • Audit logging of access to, and changes affecting, Personal Data.
  • Regular backups with tested restoration procedures for resilience and recovery.
  • Vulnerability management and secure software-development practices.
  • Screening of uploaded files for malware before they are stored.
  • Confidentiality obligations and data-protection awareness for personnel.
  • Physical and environmental security at the facilities used to host the Services.
  • An incident-response process for detecting, handling, and reporting Personal Data Breaches.

Annex 3 — Sub-processors

HTECH Solutions engages the following categories of Sub-processors to support the Services:

  • Infrastructure and hosting providers that host the deployment on the Customer’s behalf.
  • A transactional email provider used to send system notifications, such as account and credential emails.
  • Where the Customer enables optional assistance features, the providers of those features, which process the inputs submitted to them solely to deliver the feature.

The specific Sub-processors engaged for the Customer’s deployment are recorded and made available to the Customer, and HTECH Solutions updates that list and notifies the Customer of changes in accordance with section 6.

Contact

For any questions about this DPA or our processing of Personal Data, contact HTECH Solutions at .

Questions? Contact us.