Data Processing Addendum
Last updated 22 August 2026 · Privacy Policy · Terms of Service
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between LOST END FOUND LTD (trading as SCORMBridge, the “Processor”, “we”) and the organisation that has accepted the Terms (the “Customer”, “you”) — a client organisation, a publisher, or both. It applies whenever we process personal data on your behalf in providing the Platform, and it takes effect automatically; no signature is needed. A countersigned copy is available on request from support@scormbridge.app.
Terms used but not defined here have the meaning given in the Terms or in the UK GDPR. “Data Protection Law” means the UK GDPR and Data Protection Act 2018 and, where it applies to the processing, the EU GDPR.
1. Roles
- For Learner data — the launch, tracking and learning-record data described in Annex 1 — the Customer is the controller and we are the processor. Where a Publisher licenses a Course to a Client, each is an independent controller for its own purposes (the Client for delivering training to its Learners; the Publisher for reporting on use of its Course), and we process for each of them under this DPA.
- The Client instructs us, as part of the service, to make launch and completion statistics for its Licences available to the Publisher of the Course. That sharing is a disclosure between the two controllers and is governed by their agreement with each other.
- For the accounts of your staff who sign in to the portal, we are the controller, as set out in the Privacy Policy; this DPA does not apply to that data.
2. Our obligations as processor
We will:
- process personal data only on your documented instructions — which are the Terms, this DPA, and the settings and actions you take in the portal (granting licences, setting seat limits or domains, suspending or expiring licences, requesting exports or deletion) — unless required to do otherwise by law, in which case we will tell you first where the law allows;
- tell you promptly if we believe an instruction infringes Data Protection Law;
- ensure that people we authorise to process the data are bound by confidentiality;
- implement the technical and organisational measures in Annex 2 and keep them appropriate to the risk;
- engage sub-processors only as set out in section 4;
- assist you, taking into account the nature of the processing, in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection) — normally within 10 business days of your request — and in meeting your obligations on security, breach notification, data-protection impact assessments and prior consultation;
- notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal-data breach affecting your data, with the information we have at the time and updates as we learn more;
- at the end of the service, delete or return the data as set out in section 6;
- make available the information needed to demonstrate compliance with this DPA, and allow and contribute to audits as set out in section 7.
3. Your obligations as controller
- You are responsible for the lawfulness of the processing you instruct, including having a lawful basis for delivering courses to Learners and for the reporting the service produces, and for giving Learners the privacy information the law requires (the LMS operator’s privacy notice normally does this).
- You will not instruct us to process special-category data, criminal-offence data or data about children under 13 through the Platform unless we have agreed to it in writing first. SCORM
suspend_dataand similar fields can carry free text; you are responsible for what your Courses store there. - You will keep the Licence settings (seats, domains, expiry) accurate and promptly tell us if you need a Licence suspended for a data-protection reason.
4. Sub-processors
You give general authorisation for the sub-processors listed in Annex 3. We will give at least 30 days’ notice (by email to organisation administrators or a notice in the portal) before adding or replacing one; if you object on reasonable data-protection grounds and we cannot address the objection, you may terminate the affected service and we will refund any fees paid in advance for the remaining period. We impose data-protection obligations on sub-processors no less protective than this DPA and remain responsible to you for their performance.
5. International transfers
Our databases, course content and profile images are stored in Cloudflare’s Western Europe region; requests are processed at Cloudflare locations close to the user. Where data is transferred outside the UK or EEA, the transfer is made under the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses contained in the sub-processor’s data-processing terms (Annex 3), together with supplementary measures where needed. We will not transfer your data to a country without adequate safeguards.
6. Return and deletion
- During the service, organisation administrators can request an export of their Licences’ launch and completion data, and can delete member accounts. Publishers can delete Course versions and Courses, which removes the content from storage.
- Within 30 days of termination of the service (or earlier on your written request), we will make your data available for export and then delete it, unless we must keep it to comply with law. Copies in point-in-time backups are overwritten within a further 30 days.
- We will delete specific Learner records within 30 days of a verified request from you, for example to satisfy an erasure request you have received.
7. Information and audit
On request we will provide the information reasonably needed to demonstrate compliance with this DPA, including our security documentation and our sub-processors’ current reports and certifications (for example Cloudflare’s and Stripe’s SOC 2 / ISO 27001 reports). Where that is not enough to meet a legal obligation, you (or an independent auditor bound by confidentiality) may audit our processing once in any 12-month period on at least 30 days’ written notice, during business hours, in a way that does not disrupt the service or breach our obligations to other customers, at your cost. We will cooperate with a supervisory authority’s inquiry.
8. Liability and precedence
Each party’s liability under this DPA is subject to the exclusions and limits in the Terms. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. Where a signed agreement between us contains its own processor terms, that agreement prevails over this DPA.
Annex 1 — Details of processing
| Subject matter | Delivery of the Customer’s licensed Courses to its Learners through their LMS, and the recording and reporting of launch and completion data. |
| Duration | The term of the Terms, plus the deletion period in section 6. |
| Nature and purpose | Hosting and streaming course content; validating licences at launch; relaying SCORM/xAPI data between the Course and the LMS; storing launch, progress and completion records; producing usage and completion reports for the Client and the Publisher; sending service emails to organisation administrators. |
| Categories of data subject | Learners of the Customer (employees, students, contractors or members of the public, as the Customer decides); the Customer’s staff who administer the portal. |
| Categories of personal data | Learner identifier and name as supplied by the LMS; per-launch session identifier; host name of the launching LMS page; browser user agent; launch time; completion and success status, score and time spent; SCORM data-model values saved by the Course, including suspend_data (which may contain free text); transient IP address for rate limiting. Portal staff: name, email, role, invitation records. |
| Special categories | None intended; the Customer must not submit any (section 3). |
| Frequency | Continuous, as Learners launch Courses. |
Annex 2 — Technical and organisational measures
- Encryption. TLS for all traffic (HTTPS only, including between the LMS, the Learner’s browser and the Platform). Data at rest is encrypted by the hosting provider (Cloudflare D1 and R2).
- Content gating. Course files are held in private storage and served only through signed, short-lived links bound to a specific licence and course version; the licence is re-checked on every HTML document request, so suspension or expiry takes effect at the next page load.
- Access control. Role-based, tenant-scoped authorisation on every API endpoint (platform admin, publisher, client administrator, client member); publishers cannot see other publishers’ tenants; clients see only their own organisation. Operator access to production is limited to the founder, via individually authenticated accounts.
- Authentication. Passwords are stored as salted hashes (scrypt via Better Auth); sessions expire; users can review and revoke their sessions; invitation links expire after 7 days and can be revoked.
- Abuse protection. Per-IP rate limits on the public launch endpoints and on the demo form; licence enforcement at launch (status, dates, seats, launch caps, domain allow-list); refusals are logged for investigation.
- Secrets and configuration. Credentials are held in the hosting provider’s encrypted secret store, never in code; production and preview environments use separate databases, storage and secrets.
- Logging and monitoring. Request and error logs at the hosting provider; a health endpoint for external uptime monitoring; operator alerts for signups, licence grants and failures.
- Resilience and backup. Multi-region hosting provider with point-in-time database recovery for up to 30 days; course content stored with high durability object storage.
- Development practice. Changes go through version control and code review, automated type-checking, linting and tests before deployment; dependencies are kept current.
- Incident response. Security incidents are triaged on discovery; affected Customers are notified within 48 hours (section 2) with mitigation steps and follow-up findings.
- Data minimisation. IP addresses are not stored against launch records; analytics identify users by opaque id only; learner names are stored only as the LMS supplies them.
Annex 3 — Sub-processors
| Sub-processor | Purpose | Location of processing | Safeguards |
|---|---|---|---|
| Cloudflare, Inc. (101 Townsend St, San Francisco, CA, USA) and its affiliates | Hosting (Workers), database (D1), object storage (R2) for course content and profile images, transactional email delivery, CDN / network security | Storage: Western Europe (databases, course content, profile images). Processing: Cloudflare’s global network, nearest location to the user. | Cloudflare Data Processing Addendum with UK IDTA Addendum and EU SCCs; ISO 27001, SOC 2 Type II |
| Stripe Payments Europe Ltd / Stripe, Inc. | Subscription billing for Publishers; marketplace payments (Publisher as merchant of record via Stripe Connect); billing portal | Ireland, USA | Stripe Data Processing Agreement with SCCs / UK Addendum; PCI DSS Level 1 |
| LOST END FOUND LTD — self-hosted analytics (Umami) | Pseudonymous product analytics (page views, events, opaque account id) | Server operated by us: Hetzner Online GmbH, Nuremberg, Germany (EU) | Cookieless, pseudonymous; no third-party access |
No other third party receives your data. The current list is always at scormbridge.app/dpa; notice of changes is given under section 4.