Legal
Data Processing Agreement
Schedule A to the EnrollUp Master Service Agreement. It governs how EnrollUp processes an institute's personal data as a Data Processor under India's Digital Personal Data Protection Act, 2023.
Last updated: 21 July 2026. This agreement forms part of the Master Service Agreement an institute accepts at onboarding.
Parties & roles
- Institute = Data Fiduciary (determines purpose & means).
- EnrollUp (Kwickprep Education Services LLP) = Data Processor (processes only on the Fiduciary's documented instructions).
1. Subject-matter, duration, nature & purpose
Processing of Authorised Users' personal data to provide the LMS/CRM platform, for the subscription term.
2. Categories of Data Principals & Personal Data
- Data Principals: students, parents/guardians, teachers, staff, admins, leads.
- Personal Data: name, contact (email, mobile/WhatsApp), date of birth, address, guardian details, learning activity, order/payment references. No payment card data is stored (held by the gateway).
3. Processor obligations (DPDP Rule-6-aligned)
- Process only on the Fiduciary's documented instructions; no independent purposes.
- Implement reasonable technical & organisational security safeguards; maintain confidentiality (personnel bound to confidentiality).
- Assist the Fiduciary with data-principal requests (access, correction, erasure, withdrawal), security, breach notification, and audits.
- Notify the Fiduciary without undue delay upon becoming aware of a personal-data breach, with the information the Fiduciary needs to meet its DPDP notification duties (Data Protection Board + affected principals).
- On termination, delete or return all personal data at the Fiduciary's choice, save where retention is legally required.
4. Sub-processors (disclosed; Fiduciary consents; flow-down obligations)
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, AI (Bedrock) | India + US |
| MongoDB Atlas | Database | India |
| Razorpay | Payments | India |
| Meta / WhatsApp Cloud API | Messaging / OTP | US / global |
| Zeptomail | Transactional email | India |
| OpenAI | AI-assisted features | US |
| Sign-in / contact features | Global |
EnrollUp imposes data-protection terms on each sub-processor no less protective than this DPA, and notifies the Fiduciary of material changes.
5. Children's data (DPDP §9)
For students under 18, processing is conditioned on the Fiduciary having obtained verifiable parental/ guardian consent. The platform provides guardian-mobile OTP verification as the mechanism. No tracking/behavioural profiling or targeted advertising directed at children.
6. Cross-border transfers
Where sub-processors process data outside India, transfers are made consistent with the DPDP Act and any applicable government restrictions.
7. Audit, liability allocation, governing law (India)
EnrollUp makes available information necessary to demonstrate compliance and allows reasonable audits. Liability for data-protection breaches allocated per fault; governing law India.
See also our platform privacy policy and Master Service Agreement.