Data Processing Addendum
Effective: 3 August 2026 · Version: 1.0
This Data Processing Addendum (the “DPA”) is entered into between Group Everest Limited, trading as Qualify Nation, a company registered in England and Wales under company number 10588069, ICO registration ZB294348 (the “Processor”), and the business customer that has accepted the Qualify Nation Partner Terms or entered into another written agreement with the Processor for the provision of the Services (the “Controller”).
This DPA supplements, and is incorporated into, the Partner Terms, order form, reseller agreement or other written agreement between the Parties governing the Controller’s use of the Services (the “Principal Agreement”). It takes effect upon the Controller’s acceptance of the Principal Agreement, whether by electronic acceptance, signature, or first use of the Services, and no separate signature is required. In the event of conflict between this DPA and the Principal Agreement in respect of the processing of personal data, this DPA prevails.
1. Definitions
1.1 “Data Protection Legislation” means the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, in each case as amended or replaced from time to time.
1.2 “Services” means the Qualify Nation platforms and related services provided to the Controller under the Principal Agreement, including as applicable the Learn, Labs, Exam and Grow platforms, whether provided under Qualify Nation branding or on a white-label basis.
1.3 “Customer Personal Data” means the personal data described in Schedule 1 processed by the Processor on behalf of the Controller in connection with the Services.
1.4 “Controller”, “processor”, “data subject”, “personal data”, “personal data breach”, “processing” and “supervisory authority” have the meanings given in the UK GDPR.
1.5 “Sub-processor” means any third party engaged by the Processor to process Customer Personal Data.
2. Roles and Scope
2.1 The Parties acknowledge that, in respect of Customer Personal Data, the Controller is the data controller and the Processor is a data processor.
2.2 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Schedule 1. This DPA applies to whichever of the Services the Controller has contracted for under the Principal Agreement.
2.3 This DPA does not apply to personal data of which the Processor is itself the controller (including personal data of the Processor’s own direct learners and customers, and personal data processed for the Processor’s own business administration, billing and security purposes).
2.4 Where the Controller acts as a reseller and individuals introduced or sponsored by it enrol as the Processor’s own learners, the Parties are independent controllers in respect of those individuals as set out in the Principal Agreement: personal data exchanged between the Parties in that context is disclosed on a controller-to-controller basis and falls outside this DPA under clause 2.3, and this DPA applies only to Customer Personal Data the Processor processes on the Controller’s behalf (including through any white-label instance provided to the Controller for use by those individuals).
3. Processor Obligations
The Processor shall:
3.1 process Customer Personal Data only on the documented instructions of the Controller, including with regard to transfers of Customer Personal Data outside the United Kingdom, unless required to do otherwise by law to which the Processor is subject, in which case the Processor shall inform the Controller of that legal requirement before processing (unless prohibited by law from doing so). The Principal Agreement, this DPA, and the Controller’s configuration and use of the features of the Services constitute the Controller’s documented instructions;
3.2 immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Legislation;
3.3 ensure that all persons authorised to process Customer Personal Data are subject to binding obligations of confidentiality;
3.4 implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 UK GDPR, including as a minimum the measures set out in Schedule 2;
3.5 taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests from data subjects exercising their rights under Chapter III UK GDPR, and promptly (and in any event within three (3) business days) notify the Controller if it receives any such request directly;
3.6 assist the Controller in ensuring compliance with the Controller’s obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to the Processor;
3.7 notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting Customer Personal Data, providing sufficient information to enable the Controller to meet its obligations under Articles 33 and 34 UK GDPR, and cooperate with the Controller in investigating and mitigating the breach;
3.8 not disclose Customer Personal Data to any third party except as permitted by this DPA, as instructed by the Controller, or as required by law;
3.9 maintain records of its processing activities in respect of Customer Personal Data in accordance with Article 30(2) UK GDPR.
4. Sub-processing
4.1 The Controller grants the Processor general written authorisation to engage Sub-processors, subject to this clause 4.
4.2 The Sub-processors engaged as at the Effective Date are listed at qualifynation.com/sub-processors/ (the “Sub-processor List”), and the Controller approves their engagement.
4.3 The Processor shall update the Sub-processor List and notify subscribed Controllers at least fourteen (14) days before the addition or replacement of any Sub-processor. The Controller may object on reasonable grounds relating to data protection within that period; if the objection cannot be resolved, the Controller may terminate the affected Services in accordance with the Principal Agreement as its sole remedy.
4.4 The Processor shall impose on each Sub-processor, by written contract, data protection obligations materially equivalent to those in this DPA, and shall remain fully liable to the Controller for the performance of each Sub-processor’s obligations.
5. International Transfers
5.1 The Processor shall not transfer Customer Personal Data outside the United Kingdom except: (a) to the Sub-processors and destinations identified in the Sub-processor List; or (b) with the Controller’s prior written consent, in each case subject to a transfer mechanism valid under Chapter V UK GDPR.
5.2 The Parties acknowledge that, where AI-powered features of the Services are used, Customer Personal Data submitted to those features (which may include CV content, learner queries, chat and voice interactions, and assessment-related context) is transferred to artificial-intelligence Sub-processors in the United States, as identified in the Sub-processor List, safeguarded in each case by the EU Standard Contractual Clauses as amended by the UK International Data Transfer Addendum, incorporated into the Processor’s data processing agreement with each such Sub-processor.
6. Audit
6.1 The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
6.2 Audits under clause 6.1: (a) require at least thirty (30) days’ written notice; (b) are limited to once per twelve-month period, except following a personal data breach or where required by a supervisory authority; (c) shall be conducted during business hours with minimal disruption; and (d) may in the first instance be satisfied by the Processor providing existing audit reports, certifications and security documentation.
7. Return and Deletion
7.1 Upon termination or expiry of the Principal Agreement, or upon the Controller’s earlier written request, the Processor shall, at the Controller’s election, return all Customer Personal Data to the Controller in a commonly used, machine-readable format and/or securely delete it, and shall delete existing copies within thirty (30) days, unless and to the extent that retention is required by law (including any obligation on the Processor, as an awarding body, to maintain certification and verification records). The Processor shall certify deletion in writing upon request.
7.2 Customer Personal Data held in immutable backup storage shall be deleted upon expiry of the applicable backup retention cycle set out in Schedule 2, and shall not be restored to any live system following termination except as required by law.
8. Changes to this DPA
8.1 The Processor may update this DPA from time to time to reflect changes in law, regulatory guidance or the Services. The Processor shall give the Controller at least thirty (30) days’ notice of material changes. No change shall reduce the overall level of protection for Customer Personal Data. The version in force is published at qualifynation.com/dpa/, and continued use of the Services after the effective date of a change constitutes acceptance.
9. Liability, Term and General
9.1 Each Party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement, save that nothing limits either Party’s liability for amounts payable to a supervisory authority or data subject to the extent caused by that Party’s breach of this DPA.
9.2 This DPA takes effect upon acceptance of the Principal Agreement and remains in force for as long as the Processor processes Customer Personal Data.
9.3 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Schedule 1 — Details of Processing
Subject matter: The provision of the Qualify Nation platforms contracted for under the Principal Agreement — Learn (learning management), Labs (practical lab environments), Exam (assessment and examination, including proctoring), and Grow (candidate representation and recruitment) — whether under Qualify Nation branding or on a white-label basis.
Duration: The term of the Principal Agreement, plus the return/deletion period in clause 7.
Nature and purpose of processing: Hosting, storage, organisation, retrieval, transmission and analysis of Customer Personal Data to enable, as applicable to the contracted Services:
(a) Learn: learner account management; enrolment; delivery of course content; progress, engagement and completion tracking; learning assistance features; communications with learners.
(b) Labs: provisioning and operation of individual lab and sandbox environments; storage of learner-created content within those environments; activity logging.
(c) Exam: assessment and examination delivery; identity verification; proctoring (including environment monitoring and behavioural analysis); marking and results processing; certification and credential issuance and verification.
(d) Grow: candidate account management; CV storage and AI-assisted CV analysis and improvement suggestions; submission of applications to job boards and employers on candidates’ behalf; consent capture and record-keeping; correspondence routing (including proxy/masked email); interview and assessment tracking.
(all Services): platform security, abuse prevention, support and troubleshooting.
Categories of data subjects: Learners, candidates and end users registered by or with the Controller; the Controller’s staff, consultants, tutors and administrative users; employer and job board contacts corresponding through the Services.
Types of personal data: Name, email address, telephone number and account details; enrolment, progress, engagement and completion records; assessment submissions, examination responses, marks and results; proctoring records (identity verification imagery, examination session recordings, environment and behavioural monitoring data); certificates and credential verification records; learner-created content within lab environments; CV content (employment history, education, skills and any information the data subject has included therein); application records and status; interview activity; consent records; correspondence passing through the Services; support communications; technical data (IP address, session identifiers, device information, cookies, activity logs).
Special category data: Not requested or required by the Processor. May be present incidentally within free-text content (such as CVs, assessment submissions or support communications) where included by the data subject; processed only as an incidental component of that content on the Controller’s instructions. Proctoring identity verification does not involve the creation of biometric templates for unique identification unless expressly agreed in the Principal Agreement.
Schedule 2 — Technical and Organisational Measures
- Encryption: All Customer Personal Data encrypted in transit (TLS). Data at rest encrypted on managed database and storage services.
- Access control: Role-based access; Customer Personal Data accessible only to authenticated users entitled to see it; administrative access restricted to authorised Processor personnel; audit logging of platform and administrative activity.
- Infrastructure: Managed cloud infrastructure with network-level protection (web application firewall, DDoS mitigation, bot management); hardened origin servers; segregated production environments; isolated lab/sandbox environments not intended for public deployment.
- Tenant isolation: Logical separation of each Controller’s data from other platform tenants, enforced at the application and database layer.
- Resilience and backups: Blue/green deployment for change control; regular backups including immutable (WORM) backup copies held in a segregated account; backup retention of 35 days.
- Vulnerability and incident management: Security assessment aligned to OWASP ASVS and the OWASP API Security Top 10; documented incident response procedure with incident records maintained.
- Organisational measures: Information security management aligned to ISO 27001; personnel confidentiality obligations; documented sub-processor management.
- Data minimisation in AI processing: Only content and context necessary for the relevant AI-powered feature is transmitted to AI Sub-processors; no Customer Personal Data is used by the Processor or any Sub-processor to train AI models.