Metaenga Data Processing Agreement
Version: 0.2
Last updated: 28 July 2026
Effective date: The date this DPA becomes part of the Agreement
This Data Processing Agreement (“DPA”) is between:
- the customer identified in an Order, master services agreement or other agreement for Metaenga Services (“Customer”); and
- Metaenga, Inc., a Delaware corporation with a registered address at 1111B South Governors Avenue, Dover, Delaware 19904, United States (“Metaenga”).
This DPA forms part of the agreement under which Metaenga provides Services to Customer (the “Agreement”). It applies where Metaenga Processes Customer Personal Data on Customer’s behalf. It is not executable for a deployment until the applicable Order or execution copy completes the Processing, location, retention, Subprocessor and transfer details required by the schedules.
If Customer accepts the Agreement for an organisation, the person accepting it represents that they are authorised to bind that organisation.
1. Definitions
In this DPA:
Applicable Data Protection Law means the privacy, data-protection and data-security laws applicable to the Processing, including, where applicable:
- Regulation (EU) 2016/679 (“GDPR”);
- the UK GDPR and Data Protection Act 2018;
- the Swiss Federal Act on Data Protection;
- the California Consumer Privacy Act, as amended (“CCPA”); and
- other applicable U.S. state privacy laws.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Process, Processing, Special Category Data and Supervisory Authority have the meanings given by Applicable Data Protection Law.
Customer Personal Data means Personal Data that Metaenga Processes on Customer’s behalf under the Agreement.
Order means the applicable order form, quote, statement of work, services agreement or other ordering document accepted by the parties.
Services means the Metaenga services, software, applications, content, support, integrations and professional services identified in the Agreement.
SCCs means the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914.
Subprocessor means another Processor engaged by Metaenga to Process Customer Personal Data.
2. Scope, roles and precedence
For Customer Personal Data:
- Customer is the Controller and Metaenga is the Processor, unless the Processing Schedule identifies a different lawful role;
- where Customer is itself a Processor, Metaenga acts as Customer’s Subprocessor;
- under U.S. state privacy laws, Metaenga acts as Customer’s Service Provider, Contractor or Processor, as applicable.
Customer determines the purpose and essential means of the Processing. Customer is responsible for:
- establishing a lawful basis;
- providing required notices to Data Subjects;
- obtaining any required consents;
- ensuring that Customer’s instructions comply with Applicable Data Protection Law;
- deciding which learners, data fields, results and retention periods are required.
If this DPA conflicts with another part of the Agreement regarding Customer Personal Data, this DPA prevails. Any applicable unmodified SCCs prevail over conflicting commercial terms.
The Privacy Policy describes Processing for which Metaenga independently determines the purposes and means. It does not replace this DPA.
3. Documented instructions and purpose limitation
Metaenga will Process Customer Personal Data only:
- to provide, secure, maintain and support the Services;
- according to Customer’s documented instructions in the Agreement, the Processing Schedule and authorised support requests; or
- where applicable law requires the Processing, in which case Metaenga will notify Customer before Processing unless the law prohibits notice.
Metaenga will promptly inform Customer if Metaenga reasonably believes an instruction infringes Applicable Data Protection Law. Metaenga may suspend the affected Processing while the parties resolve the instruction.
Metaenga will not:
- sell Customer Personal Data;
- share it for cross-context behavioural advertising or targeted advertising;
- use enterprise learner data for Metaenga marketing;
- retain, use or disclose it outside the contracted business purpose and Customer’s instructions;
- combine it with Personal Data received from another customer or collected from Metaenga’s own interaction with a Data Subject, except where Applicable Data Protection Law permits the combination and it is necessary to provide the Services;
- use it to train or retrain a shared, general-purpose or third-party AI model without a separate written agreement, lawful assessment and required transparency;
- attempt to re-identify data that has been validly de-identified, except to test whether de-identification controls are effective where law permits.
Metaenga will not Process biometric, health, Special Category or other highly sensitive Personal Data unless the parties expressly document the purpose, lawful condition and additional safeguards.
4. Confidentiality and personnel
Metaenga will ensure that persons authorised to Process Customer Personal Data:
- are bound by confidentiality obligations;
- receive access only where required for their role;
- receive appropriate privacy and security guidance;
- Process the data only on documented instructions.
Metaenga will maintain a process to grant, review, change and revoke access. Privileged production access will be limited, protected by MFA and periodically reviewed.
5. Security
Taking account of the state of the art, implementation costs, and the nature, scope, context and purposes of the Processing, Metaenga will implement technical and organisational measures appropriate to the risk.
The applicable measures are described in Schedule 2 and may be supplemented by an Order or customer security schedule. Metaenga may update those measures if the update does not materially reduce the overall security of the applicable Services.
Customer acknowledges that a hosting or infrastructure provider’s certification applies only to that provider and the services included within the certification scope. It does not certify Metaenga.
6. Subprocessors
Customer gives Metaenga general written authorisation to engage the Subprocessors identified in the current customer-specific Processing Schedule or Subprocessor Register.
Metaenga will:
- provide at least 30 days’ prior written notice of a new or replacement Subprocessor that will Process Customer Personal Data, unless an urgent change is reasonably required to protect the Services or comply with law;
- enter into a written agreement that imposes data-protection obligations no less protective in substance than the applicable obligations in this DPA;
- remain responsible to Customer for the Subprocessor’s performance of those obligations;
- provide information reasonably necessary for Customer to assess a notified change.
If prior notice is not reasonably possible for an urgent change, Metaenga will notify Customer as soon as reasonably practicable afterward and provide the information needed for review.
Customer may object during the notice period on reasonable data-protection grounds. The parties will work in good faith to address the objection. If no reasonable alternative is available, either party may terminate the affected Service, and Metaenga will refund any prepaid fees covering the unused terminated period.
A provider used only for Metaenga’s unrelated corporate or marketing activities is not a Subprocessor for Customer merely because Metaenga uses that provider elsewhere.
7. Data Subject requests
Taking account of the nature of the Processing, Metaenga will provide reasonable assistance for Customer to respond to requests to exercise Data Subject rights.
If Metaenga receives a request relating to Customer Personal Data, Metaenga will:
- notify Customer without undue delay;
- not respond substantively unless Customer authorises the response or law requires Metaenga to respond;
- securely retain the request only as long as required to complete and evidence the response.
Customer remains responsible for verifying the requester, deciding how to respond and communicating the decision.
8. Personal Data Breaches
Metaenga will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
As information becomes available, the notice will describe:
- the nature of the breach;
- the affected systems and categories of data;
- the approximate number of affected Data Subjects and records, where known;
- likely consequences;
- containment, investigation and remediation measures;
- a contact for further information.
Metaenga will take reasonable steps to contain, investigate and remediate the breach and will provide progress updates reasonably required for Customer’s assessment and notifications.
A breach notification is not an admission of fault or liability.
Any shorter notification target expressly agreed in an Order or customer security schedule applies.
9. DPIAs, consultations and compliance assistance
Taking account of the nature of Processing and information available to Metaenga, Metaenga will provide reasonable assistance with:
- Data Subject requests;
- security obligations;
- breach assessment and notification;
- data-protection impact assessments;
- prior consultation with a Supervisory Authority;
- records or enquiries relating to Metaenga’s Processing.
Customer is responsible for the final DPIA, its lawful basis and any required consultation.
Routine assistance is included in the Services. Material bespoke work may be chargeable if agreed in advance, except where the work is required because Metaenga breached this DPA.
10. Compliance information and audits
Metaenga will make available information reasonably necessary to demonstrate compliance with its Processor obligations.
Customer should first use available:
- policy and control documentation;
- completed security questionnaires;
- relevant technical evidence;
- hosting-provider assurance reports and certifications;
- audit or test reports that Metaenga is legally and contractually permitted to share.
If that information is insufficient, Customer may ordinarily conduct one audit in a 12-month period on at least 30 days’ notice. The frequency and notice limits do not restrict an audit required by Applicable Data Protection Law, a Supervisory Authority, a material Personal Data Breach or reasonable evidence of material non-compliance. Urgent security reviews may proceed on shorter reasonable notice.
An audit must:
- be limited to systems and records relevant to Customer Personal Data;
- protect other customers’ confidentiality and security;
- occur during normal business hours;
- avoid unreasonable disruption;
- be performed by Customer or an independent auditor that is not Metaenga’s competitor and is bound by confidentiality.
Customer bears its audit costs unless the audit identifies a material breach by Metaenga.
11. Return, retention and deletion
Metaenga will retain Customer Personal Data only for:
- the contracted Services;
- Customer’s documented instructions;
- a legal obligation; or
- a documented, access-restricted legal hold.
At the end of the Services, or earlier on Customer’s written instruction, Metaenga will, at Customer’s choice and unless applicable law requires retention:
- return Customer Personal Data in the agreed export format and delete remaining copies; or
- delete Customer Personal Data according to the Processing Schedule and the Data Retention and Secure Deletion Policy.
Unless the Processing Schedule states otherwise, the intended standard is:
- disable hosted Customer accounts at termination;
- delete Customer Personal Data from active Metaenga systems within 30 calendar days;
- remove local application or device records according to the applicable device workflow and agreed schedule;
- allow residual protected recovery copies to expire through the documented rolling backup cycle;
- prevent backup records from returning to ordinary production use;
- if a backup is restored, reapply and verify the deletion record before production access.
Metaenga will provide a written deletion confirmation on request. The confirmation may record the scope, dates, systems checked, exceptions and expected backup-expiry date without reproducing the deleted Personal Data.
Deletion may be delayed only for a documented legal obligation or legal hold. Metaenga will isolate the affected data, restrict access and delete it when the restriction ends.
The periods stated above are the standard position. The customer-specific active-system, local-device and backup periods completed in Schedule 1 control for a particular deployment.
12. Processing locations and remote access
The applicable hosting, backup, support and administrative-access locations are stated in Schedule 1.
Where Customer purchases an EEA-restricted or other location-restricted deployment, Metaenga will not intentionally move Customer Personal Data or permit routine production access outside the agreed boundary without:
- Customer’s prior written approval;
- an updated location and Subprocessor schedule; and
- any transfer mechanism required by Applicable Data Protection Law.
EEA hosting alone does not determine whether a restricted international transfer occurs. The contracting entity, remote access, support, onward transfers and legal access must also be assessed.
13. International transfers
The parties will document each restricted transfer of Customer Personal Data.
13.1 EEA transfers
Where Customer transfers Personal Data protected by the GDPR to Metaenga or a Subprocessor in a third country and no adequacy decision or other valid transfer mechanism applies, the SCCs are incorporated by reference as follows:
- Module Two applies where Customer is a Controller and Metaenga is a Processor;
- Module Three applies where Customer is a Processor and Metaenga is a Subprocessor;
- Clause 7, the optional docking clause, applies;
- Clause 9(a), Option 2, general written authorisation, applies with the notice period in Section 6;
- the competent Supervisory Authority is determined under Clause 13 of the SCCs;
- unless the applicable Processing Schedule selects another eligible EU Member State, Ireland is selected for Clauses 17 and 18;
- Schedule 1 supplies Annex I information, Schedule 2 supplies Annex II measures and Schedule 3 supplies the relevant Subprocessor information, but only when those schedules are fully completed.
Nothing in this DPA varies or limits the SCCs in a manner they do not permit.
The parties will cooperate on a transfer assessment and supplementary measures where required.
The incorporated SCCs are the official text of Commission Implementing Decision (EU) 2021/914, available from the European Commission. They are effective only when the applicable modules, Annex I, Annex II and any required Annex III information are fully completed. If those SCCs are not legally available for the relevant transfer, including because the importer’s relevant Processing is directly subject to the GDPR in a way not covered by the clauses, the parties must document another valid mechanism before the restricted transfer.
13.2 United Kingdom
Where a restricted transfer is governed by the UK GDPR, the parties must execute the then-current UK International Data Transfer Addendum to the EU SCCs with completed tables, or document another valid UK transfer mechanism, before the restricted transfer.
13.3 Switzerland
Where Swiss data-protection law applies, references in the SCCs will be adapted as required so that they cover Swiss Personal Data and the competent Swiss authority and courts.
14. U.S. state privacy terms
Where a U.S. state privacy law applies and Customer is a Business or Controller, Metaenga will act as its Service Provider, Contractor or Processor for Customer Personal Data.
Metaenga will:
- Process the data only for the limited and specified purposes in the Agreement;
- comply with applicable obligations and provide the same level of privacy protection required by the relevant law;
- allow Customer to take reasonable and appropriate steps to help ensure compliant use;
- notify Customer if Metaenga determines it can no longer meet an applicable obligation;
- allow Customer, after notice, to take reasonable and appropriate steps to stop and remediate unauthorised Processing;
- require relevant subcontractors to comply with equivalent restrictions.
Metaenga certifies that it understands and will comply with these restrictions when they apply.
15. Government and third-party requests
Unless prohibited by law, Metaenga will notify Customer of a binding request from a public authority for Customer Personal Data before disclosure.
Metaenga will:
- review the request for legal validity;
- challenge an unlawful or disproportionate request where there are reasonable grounds;
- disclose only the minimum data legally required;
- document the request and response where lawful.
Metaenga will not voluntarily provide bulk access to Customer Personal Data.
16. Liability, duration and termination
This DPA begins when it becomes part of the Agreement and continues while Metaenga Processes Customer Personal Data.
Liability under this DPA is subject to the liability provisions of the Agreement, except where Applicable Data Protection Law or the SCCs prohibit the limitation.
Confidentiality, return and deletion, audit, transfer and liability provisions survive for as long as required to complete their purpose.
17. Changes
Metaenga may update this public DPA prospectively to reflect legal or service changes. A material change will not reduce Customer’s data-protection rights during an active committed term without Customer’s agreement.
A signed DPA or customer-specific schedule cannot be amended solely by posting a revised website version.
18. Signatures and electronic acceptance
This DPA may be accepted through an Order that incorporates it, an electronic acceptance flow or signature by both parties.
Where the parties sign an execution copy, the signature blocks are completed as follows.
Customer
Legal name:
Name:
Title:
Date:
Signature:
Metaenga, Inc.
Name:
Title:
Date:
Signature:
Schedule 1 — Details of Processing
This Schedule must be completed or incorporated from the applicable Order for each Customer deployment.
| Item | Customer-specific details |
|---|
| Customer / data exporter | [Legal name, address, contact and role] |
| Metaenga / data importer | Metaenga, Inc., 1111B South Governors Avenue, Dover, Delaware 19904, United States; privacy@metaenga.com; Processor or Subprocessor as stated above |
| Subject matter | Delivery, administration, support and reporting for the agreed Metaenga Services |
| Duration | Agreement term plus the return, deletion and backup periods below |
| Nature and purpose | Account provisioning; authentication; training delivery; local/offline operation where applicable; synchronisation where enabled; reporting; support; security; Customer-approved export or integration |
| Data Subjects | Authorised learners, administrators, business contacts and support contacts |
| Account data | Business email or opaque learner ID; name where required; tenant, organisation and role identifiers; account and invitation status |
| Training data | Module/scenario/version; session and attempt identifiers; timestamps; duration; completion; pass/fail; score; stages, actions, decisions, errors, retries and time between actions where enabled |
| Device and technical data | Headset/device or app identifier; app version; synchronisation state; IP, authentication, audit and security events where necessary |
| Support data | Support request content and related diagnostic records supplied by Customer or an Authorised User |
| Special Category Data | Not intended or authorised unless expressly stated here with purpose and safeguards |
| Frequency | On account events and during or after training sessions; security monitoring as applicable |
| Return/export format | [Dashboard / PDF / CSV / agreed API, xAPI statement set or other approved method] |
| Active-system retention | [Complete] |
| Local-device retention | [Complete if applicable] |
| Backup retention | [Complete] |
| Hosting locations | [Exact services and regions] |
| Backup and log locations | [Exact services and regions] |
| Authorised support/access locations | [Countries or regions] |
| Customer privacy contact | [Complete] |
| Metaenga privacy contact | privacy@metaenga.com |
| Competent Supervisory Authority | [Complete according to applicable law and SCC Clause 13] |
| Additional instructions | [Complete or state “None”] |
For an enterprise evaluation pilot, the parties should attach a short pilot schedule that fixes the participants, fields, retention, backup expiry, hosting, access boundary, support route and deletion evidence.
Schedule 2 — Technical and Organisational Measures
The following measures apply to the extent relevant to the purchased deployment. The applicable Order or customer security schedule identifies the measures that apply to a specific deployment.
A. Governance and personnel
- Defined responsibility for privacy and information security.
- Approved information-security, incident-response, access-control, backup and deletion procedures.
- Confidentiality obligations and role-appropriate training.
- Periodic risk, access, supplier and policy reviews.
B. Identity and access management
- Unique accounts for authorised personnel.
- Role-based access and least privilege.
- MFA for privileged production access.
- Controlled joiner, mover and leaver process.
- Periodic privileged-access review.
- Restricted and logged emergency access.
C. Application and platform security
- HTTPS/TLS for web, API and synchronisation traffic.
- Secure password hashing and protected secret storage.
- Customer/tenant separation and server-side authorisation.
- Separate development, test and production environments where applicable.
- Code review, dependency checking and controlled deployment.
- Security logging, monitoring and alert handling.
D. Infrastructure and resilience
- Approved infrastructure services identified in the applicable Order.
- Region and access restrictions configured where a Customer purchases them.
- Protected backups and restricted recovery access.
- Documented recovery objectives, restoration procedures and periodic tests.
- Patch, vulnerability, configuration and change management.
E. Data minimisation and lifecycle
- Minimum required learner fields and configurable result detail.
- No enterprise learner data for marketing or general-purpose AI-model training.
- Local-device retention and synchronisation controls where applicable.
- Documented active-system deletion, backup expiry and restore-and-redelete procedures.
- Non-identifying deletion evidence.
F. Incident management
- Defined detection, triage, containment, investigation and recovery process.
- Customer notification without undue delay.
- Breach documentation, lessons learned and corrective-action tracking.
G. Supplier management
- Security and privacy due diligence proportionate to provider risk.
- Written Subprocessor terms.
- Processing-location and transfer review.
- Periodic review of relevant certifications and assurance material.
Schedule 3 — Subprocessors
The final list must identify only providers used for the relevant Customer deployment.
| Provider | Purpose | Data involved | Processing location | Transfer mechanism | Applicability |
|---|
| OVHcloud contracting entity stated in the Order | Hosting, storage, network, logs and backup where Metaenga-hosted Services are selected | Customer account, training, technical and security data as configured | Exact services and regions in the Order; Ireland/EEA configuration available for approved deployments | As documented for the deployment | Confirmed in the applicable Order |
| Google or Microsoft identity service, if Customer enables it | Authentication or federated identity | Business identifier, login and authentication metadata | Provider-specific | Customer instruction and applicable transfer mechanism | Optional |
| Transactional email provider approved for the deployment | Invitations, account notices and password reset | Business email and message metadata | Provider-specific | Applicable transfer mechanism | Confirmed in the applicable Order |
| Customer-selected LMS or integration endpoint | Customer-approved result delivery | Minimum agreed result and learner identifier | Customer/provider environment | Customer instruction | Optional |
Website analytics, advertising, payment and sales systems are not Subprocessors for enterprise learner data unless they are deliberately used to provide the Customer Services and are listed here.