Data Processing Agreement
Last updated Jul 27, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Progma, Inc. ("Progma", "Processor") and the institution that uses the Service ("Institution", "Controller"). It governs the processing of personal data that Progma carries out on behalf of the Institution in connection with the Service.
Placeholder — confirm with counsel. This DPA is a template aligned to the Philippine Data Privacy Act of 2012 (RA 10173) and its implementing rules. It must be reviewed and, for many customers, executed as a signed agreement. Bracketed items require completion.
1. Roles of the parties
For personal data processed under the Service, the Institution acts as the personal information controller and Progma acts as a personal information processor that processes such data only on the Institution's documented instructions, including as set out in this DPA and the Terms.
For certain data—such as account administration, billing, and prospect inquiries—Progma acts as a controller; that processing is governed by the Privacy Policy.
2. Subject matter and scope
- Subject matter: Progma's provision of the programming-education Service.
- Duration: the term of the Institution's subscription, plus any period required for return or deletion of data.
- Nature and purpose: hosting, executing, grading, storing, transmitting, and supporting the data necessary to operate the Service.
- Categories of data subjects: the Institution's administrators, teachers, and students (who may include minors).
- Categories of personal data: identity and contact data, account and authentication data, course and enrollment data, learning data (including submitted code and grades), and related records. The Institution must not submit special categories of data except as agreed.
3. Processor obligations
Progma will:
- process personal data only on the Institution's documented instructions, unless required by law (in which case it will inform the Institution where legally permitted);
- ensure persons authorized to process personal data are bound by appropriate confidentiality obligations;
- implement appropriate technical and organizational security measures (see Section 6);
- assist the Institution, taking into account the nature of processing, in responding to data-subject requests and in meeting the Institution's security, breach-notification, and impact-assessment obligations;
- make available information reasonably necessary to demonstrate compliance; and
- at the Institution's choice, delete or return personal data at the end of the engagement, except where retention is required by law.
4. Sub-processors
The Institution authorizes Progma to engage sub-processors to provide the Service. A current list is published at Sub-processors. Progma will impose data-protection obligations on sub-processors that are substantially similar to those in this DPA and remains responsible for their performance. Progma will provide a mechanism for notice of changes to sub-processors so the Institution may object on reasonable grounds.
5. International transfers
Where personal data is transferred outside the Philippines, Progma will take steps intended to ensure an adequate level of protection consistent with applicable law.
Placeholder — confirm with counsel: the transfer mechanism and the locations of sub-processors.
6. Security measures
Progma maintains technical and organizational measures designed to protect personal data, which may include: access controls and role-based authorization; logical isolation between institution tenants; encryption of data in transit; secure credential storage; two-factor authentication available for accounts that sign in with a password and required for Progma platform administrators; audit logging of sensitive actions, with out-of-band notice to the account holder of security-relevant account changes; and operational monitoring.
Placeholder: attach or reference the detailed, current security-measures schedule.
7. Personal data breach
Progma will notify the Institution without undue delay after becoming aware of a personal data breach affecting the Institution's data, and will provide information reasonably available to assist the Institution in meeting its obligations, including any notification to the National Privacy Commission and affected data subjects.
8. Data-subject requests
If Progma receives a request from a data subject relating to data processed on behalf of the Institution, Progma will, where legally permitted, direct the request to the Institution and assist the Institution in responding.
9. Return and deletion
On termination or expiry, Progma will delete or return personal data processed on behalf of the Institution in accordance with the Institution's instructions, except where retention is required by law. Some data is soft-deleted before permanent deletion as part of normal operations.
10. Audits
Progma will make available to the Institution information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits, subject to reasonable confidentiality, security, and scheduling conditions.
Placeholder — confirm with counsel: audit scope, frequency, and cost allocation.
11. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls.
12. Contact
Questions about this DPA may be sent to support@progma.app, attention Data Protection Officer [Placeholder — add DPO name and email].