Last updated: June 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Data Controller") and RegNexus Limited ("Data Processor"), registered in England and Wales, for the provision of the RegNexus Lumen platform.
Terms used in this DPA have the meanings given in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. "Personal Data", "Processing", "Controller", "Processor", and "Data Subject" have the meanings defined therein.
RegNexus Limited processes the following categories of personal data on the Controller's instructions: account data (names, email addresses, roles); learning activity data (session attendance and punctuality, questions asked, exercise, homework and quiz submissions and marks); competence and progress records (including hash-chained assessment artifacts and derived scores); communications within the Platform; and, where the Controller generates parent reports, the names and email addresses of parents or guardians. Data Subjects include the Controller's staff and learners, including learners under 18— the Controller is responsible for the lawful basis (including any parental consent) for processing children's data. Processing comprises storage, organisation, analysis for the educational features the Controller enables (including AI-assisted drafting and assessment), and disclosure only as instructed.
The Processor shall:
The following sub-processors are currently engaged:
The Processor maintains the following technical and organisational measures:
Where Personal Data is transferred outside the UK/EEA (including to AI sub-processors in the United States), transfers are protected by Standard Contractual Clauses (SCCs) or equivalent safeguards. No personal data is sent to AI models without anonymisation measures.
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach. The notification shall include the nature of the breach, categories of data affected, likely consequences, and measures taken to mitigate the breach.
The Processor shall assist the Controller in fulfilling data subject rights requests including access, rectification, erasure, restriction, portability, and objection. The Platform provides data export functionality to support these obligations.
The Controller has the right to audit the Processor's compliance with this DPA, subject to reasonable notice and confidentiality obligations. The Processor shall provide reasonable assistance and access to relevant information.
This DPA remains in effect for the duration of the service agreement. Upon termination, the Processor shall delete or return all Personal Data within 30 days, except where retention is required by law or for regulatory compliance purposes.
For DPA enquiries, contact our Data Protection team at privacy@reg-nexus.com.