Data Processing Agreement
Baseline data processing terms for business and institutional customers.
Effective date: September 25, 2026 · Version 2.0-20260925
Published and last updated: September 25, 2026. This expanded edition clarifies service scope, privacy, safeguarding, complaints and applicable legal rights. Publication is not your acceptance and does not retrospectively change an existing agreement. Material contractual changes apply to an existing relationship only after the required notice and valid agreement; mandatory legal rights remain unaffected.
Previous published edition. Privacy notices explain actual processing and are not requests for blanket consent. Payment and DPA frameworks apply only as described in those documents.
Table of contents
- 1. Status and formation
- 2. Roles and order of precedence
- 3. Subject matter, duration and instructions
- 4. Confidentiality and access
- 5. Security obligations
- 6. Subprocessors
- 7. International transfers and government requests
- 8. Assistance with individual rights
- 9. Personal-data breaches
- 10. Assessments and regulator cooperation
- 11. Return, deletion and legal retention
- 12. Compliance information and audits
1. Status and formation
These are standard terms for a separately agreed controller–processor arrangement. Publishing or reading them does not execute a DPA, appoint RALMIX as processor for all activities, activate an enterprise product or establish an international-transfer mechanism. A binding DPA requires the Customer and RALMIX LLC to identify the service and complete the schedules below in a signed agreement or another specifically agreed acceptance process that records both parties' agreement.
“Customer” means the organisation identified in that execution record. “Customer Data” means personal data actually processed by RALMIX on its documented instructions under that service. “Applicable Data Protection Law” means the law applicable to the relevant processing, including GDPR or Egyptian data-protection law where their territorial and material requirements are met. Terms such as controller, processor, data subject and personal-data breach have their statutory meanings.
2. Roles and order of precedence
The Customer acts as controller or as a processor authorised by its controller to appoint RALMIX as subprocessor. RALMIX acts as processor only for the listed activities. Processing for RALMIX's independently determined purposes, including its own legal records and obligations, is assessed separately and described in its Privacy Policy. Neither party may relabel processing to evade its actual obligations.
Applicable mandatory law and any valid mandatory transfer clauses prevail. This DPA prevails over conflicting service terms for Customer Data protection. The executed schedules define scope but cannot weaken compulsory protections. Commercial terms do not limit a data subject's statutory rights or a regulator's powers.
3. Subject matter, duration and instructions
Processing is limited to delivering, supporting and securing the specifically contracted learning service and completing lawful return/deletion obligations. The schedules must identify its start, term and any controlled exit period. No perpetual processing permission is implied.
RALMIX shall process Customer Data only on documented instructions, including for international transfers, unless binding law requires otherwise. It shall inform the Customer of that legal requirement before processing unless prohibited on important public-interest grounds. If an instruction appears to infringe applicable data-protection law, RALMIX shall inform the Customer without undue delay and may suspend the affected processing pending a lawful resolution.
The Customer shall issue lawful, specific instructions, provide required notices and establish the relevant legal bases and authority, including authority concerning minors. Those obligations do not excuse RALMIX's independent processor duties. New sensitive-data uses or materially different services require an updated schedule and safeguards before processing.
4. Confidentiality and access
RALMIX shall ensure that persons authorised to process Customer Data are bound by confidentiality or an appropriate statutory duty. Access shall be restricted to what their authorised task requires and withdrawn when no longer justified. Confidentiality continues after access or the service ends.
Neither party shall send production credentials or unnecessary sensitive data through general support channels. Customer instructions cannot require disclosure of another customer's data, private security secrets or information prohibited by law.
5. Security obligations
RALMIX shall implement appropriate technical and organisational measures considering the state of the art, implementation costs, processing context and risks to people. Schedule B must describe the controls actually agreed and available for the service. They may include access authorisation, secure transmission, separation of environments, backup/recovery arrangements, incident response and deletion controls, but listing these subjects is not certification that each has already been implemented.
Before execution, the parties must agree sufficient measures for the identified risks. During the term, RALMIX shall maintain that protection and not materially reduce it without a lawful, agreed alternative. Security information shall be shared at an appropriate level without exposing credentials or creating new vulnerabilities. No SOC 2, ISO 27001, PCI, end-to-end encryption or testing certification is implied by this framework.
6. Subprocessors
Appointment of a subprocessor requires the Customer's prior specific or general written authorisation. Under general authorisation, RALMIX shall notify intended additions or replacements in advance, providing a reasonable opportunity to object on substantiated data-protection grounds before the new processing begins. The executed schedule must specify notice and objection arrangements.
RALMIX shall impose materially equivalent applicable data-protection obligations by contract and remains responsible to the Customer for the subprocessor's performance of those obligations. An unresolved objection should be addressed by a suitable alternative, cessation of the affected processing or termination of that affected service under the agreed commercial consequences. It is not permission to continue an unauthorised transfer. A public provider name is not evidence of an executed subprocessor contract.
7. International transfers and government requests
The parties shall identify processing/access locations, exporters and importers, and establish a permitted mechanism before a restricted transfer. Where required, they shall execute the appropriate standard contractual clauses or other instrument, complete its annexes and assess necessary supplementary measures. This DPA is not itself those clauses and does not claim that Egypt or any provider location is covered by an adequacy decision.
Egyptian permits or other local requirements must be satisfied independently where applicable. RALMIX shall inform the Customer of a legally binding disclosure request unless prohibited and limit disclosure to what is legally required. It shall not voluntarily grant unrestricted access to Customer Data merely because an authority or private party requests it. Lawful challenges and notification duties under any applicable transfer instrument remain in force.
8. Assistance with individual rights
Taking account of the nature of processing, RALMIX shall assist the Customer by appropriate technical and organisational measures with requests for access, correction, erasure, restriction, portability, objection and other applicable rights. A request received directly concerning Customer-controlled data shall be passed to the Customer promptly, unless RALMIX is legally required or expressly instructed to respond itself.
The Customer decides the lawful response for its processing; RALMIX shall provide relevant data and execution assistance in time for applicable deadlines. Protecting other persons' data may require redaction, not withholding all assistance. Any agreed charge for exceptional work must be reasonable and cannot prevent mandatory cooperation.
9. Personal-data breaches
RALMIX shall notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data. Notification must not be postponed merely until an investigation is complete. Available information shall describe the nature of the breach, affected data/people and approximate numbers where known, likely consequences, measures taken or proposed, and an incident contact. Information may be provided in stages as it becomes available.
RALMIX shall take reasonable containment and mitigation steps, preserve relevant evidence and cooperate with the Customer's legally required assessment and notifications. Each party retains its own statutory notification duties. This clause does not create a fictitious universal 72-hour processor-to-customer deadline or authorise withholding notice until loss is conclusively proven.
10. Assessments and regulator cooperation
Taking account of the nature of processing and information available, RALMIX shall assist with security obligations, breach duties, data-protection impact assessments and prior consultation where applicable. The Customer must identify high-risk processing before instructing it. RALMIX may refuse an instruction that cannot lawfully be supported by the agreed service.
Both parties shall cooperate with competent supervisory authorities as required. Neither party may use commercial confidentiality to defeat compulsory regulatory access or the other's mandatory compliance obligations.
11. Return, deletion and legal retention
At the end of the relevant processing, at the Customer's choice, RALMIX shall return Customer Data in the agreed usable format and/or delete it and existing copies, unless applicable law requires storage. The schedule must state the return channel, exit period, backup treatment and confirmation process before execution.
Where law requires retention, RALMIX shall explain the basis and limit further processing to that purpose, with continued protection. Backup constraints must have a bounded deletion/replacement process rather than indefinite retention. A restoration must not revive data contrary to a completed deletion instruction without addressing it. Records held by RALMIX as independent controller remain subject to the Privacy Policy and their own lawful basis.
12. Compliance information and audits
RALMIX shall make available information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by the Customer or its mandated auditor where applicable law requires. The parties shall arrange reasonable notice, confidentiality, access controls and scope to protect others' data and avoid unnecessary disruption.
Documentary evidence or remote review may be used where sufficient; it cannot become an absolute bar to a legally necessary inspection. Urgent incidents or regulator requirements may justify shorter notice. No audit term may prevent required disclosure to an authority. Neither party is authorised to conduct intrusive testing of production systems without specific permission.
13. Liability, suspension and termination
The service agreement governs commercial liability only insofar as consistent with applicable law and any mandatory transfer instrument. It does not limit a person's direct statutory rights. Each party is responsible for the obligations legally assigned to its role.
A material unresolved breach may justify suspension of affected processing and, where lawful and proportionate, termination. Suspension must protect Customer Data and not obstruct return, security, rights requests or compulsory preservation. Duties that by nature survive, including confidentiality and lawful deletion, continue after termination.
Schedule A. Processing description to be completed before execution
The execution record must identify both legal entities, authorised contacts, service agreement, purpose, operations, duration, frequency, locations, lawful instructions and role allocation. It must select only categories actually needed:
- Data subjects: authorised Students, Tutors, Parents / Guardians, Customer administrators or other organisation users only where the contracted service supports them. Visitors are included only for identified Customer-controlled processing.
- Data: Account/contact identifiers, selected profile fields, Lesson scheduling and learning data, messages/materials and support records, technical connection/access data. Live media is included only for the contracted classroom. Financial records are included only for an activated service; raw payment credentials are not presumed.
- Sensitive data: identify any legally sensitive category, including children's data where applicable, the necessity, authority, restrictions and additional safeguards. Do not default to an unrestricted “all data” permission.
- Instructions: authorised recipients, permitted operations, retention criteria and deletion/return events. No advertising, independent AI training or unrelated profiling of Customer Data is authorised by this schedule.
Schedule B. Security and exit measures to be confirmed
Record actual access roles, authentication, secure transmission/storage controls, confidentiality arrangements, incident contacts, backup location and recovery procedures, change management, rights-request handling, retention/deletion procedures and audit evidence available. Distinguish implemented controls from a roadmap. Any required control not yet available must be resolved before signing, not silently represented as operational.
Schedule C. Subprocessors and transfers to be confirmed
List each authorised provider's legal name, purpose, data, role, processing/access countries, applicable contractual safeguards and authorisation basis. Include LiveKit or an AI provider only if used for the contracted processing. Complete notification/objection contacts and timing. Identify any SCC module and executed annexes or other lawful mechanism and relevant local permits. A blank schedule means the DPA is not ready for execution.
14. Requests and related documents
Request an individually completed DPA through ralmix.top@gmail.com, identifying the organisation and intended service without sending its full personal-data set. See the Privacy Policy, Terms of Use and Contact and Legal Notice.

