Data Processing Agreement

Last updated: October 6, 2026

This Data Processing Agreement (hereinafter, the "DPA") governs the processing of personal data that Eolymp carries out on behalf of the organization for which a space is created or administered on the website eolymp.com (hereinafter, the "Customer"). It forms part of the General Terms and Conditions of Use and Contracting Services (hereinafter, the "Conditions") and is accepted together with them. On request, the parties may also sign a copy of this DPA.

Parties

  • Processor: EOLYMP ACADEMY, S.L. (hereinafter, "Eolymp")

  • Registered office: Calle del PerĂº, 186bis - 08020, Barcelona, Spain

  • Registration details: Commercial Registry of Barcelona, Volume 48547, Folio 20, Section 8, Sheet 587753, Entry 1a

  • Tax ID: B-72828122

  • Email: support@eolymp.com

  • Controller: the Customer

Definitions

Capitalized terms not defined in this DPA, such as "Website", "Services" and "Users", have the meanings given to them in the Conditions. "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach" and "Supervisory Authority" have the meanings given to them in Regulation (EU) 2016/679 (hereinafter, "GDPR"). "Data Protection Law" refers to the GDPR and Organic Law 3/2018, of December 5, on Personal Data Protection and guarantee of digital rights (hereinafter, "LOPDGDD").

"Space" refers to the area of the Website administered by the Customer, including its members, contests, courses, problems and submissions. "Customer Personal Data" refers to the Personal Data that Eolymp processes on behalf of the Customer in providing the Services for the Space, as described in Annex I. "Sub-processor" refers to any third party engaged by Eolymp to process Customer Personal Data. "SCCs" refers to the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.

Processing of Customer Personal Data

For Customer Personal Data, the Customer is the Controller and Eolymp is the Processor. This DPA does not apply to the Personal Data that Eolymp processes as an independent Controller in accordance with its Privacy Policy, namely user accounts on the Website, which Users hold independently of any Space; billing and contract administration with the Customer; and access and security logs used to protect the Website.

Eolymp processes Customer Personal Data only on the documented instructions of the Customer, unless required to do so by EU or Member State law, in which case Eolymp will inform the Customer before processing, unless that law prohibits it. The instructions of the Customer consist of this DPA, the Conditions and the configuration and use of the Services by the Customer. Any additional instructions require the prior written agreement of the parties, including on any fees. Eolymp will inform the Customer without delay if, in its opinion, an instruction infringes Data Protection Law. Eolymp ensures that the persons authorized to process Customer Personal Data are bound by confidentiality.

The Customer is responsible for the lawfulness of the processing and for informing Data Subjects. Where the Customer invites users under fourteen (14) years of age into its Space, the Customer is responsible for obtaining the authorization of their legal representatives, in accordance with Article 8 of the GDPR, Article 7 of the LOPDGDD and the Conditions. The Customer will not submit special categories of Personal Data (Article 9 of the GDPR) or data relating to criminal convictions and offences (Article 10 of the GDPR) to the Services.

Where the Customer enables proctoring for a contest, the screen and, if so configured, the camera and microphone of each participant are recorded for the duration of their participation. The Customer is responsible for informing participants and for obtaining any consent required. Eolymp only stores the recordings and makes them available to the Customer; it does not view, analyze or otherwise use them. Recordings are deleted within fourteen (14) days after they are made.

Sub-processors

The Customer grants Eolymp a general authorization to engage Sub-processors. The Sub-processors listed at trust.eolymp.com when the Customer accepts this DPA are authorized. Eolymp will notify the Customer at least thirty (30) days before adding or replacing a Sub-processor.

The Customer may object to the change on reasonable data protection grounds within the notice period. If the parties cannot resolve the objection, the Customer may terminate the affected Services, and Eolymp will refund any fees paid in advance for the period after termination.

Eolymp imposes on each Sub-processor, by written contract, data protection obligations no less protective than those of this DPA, and remains liable to the Customer for the performance of each Sub-processor.

Security and Personal Data Breaches

Eolymp implements the technical and organizational measures described in Annex II. The information security management system of Eolymp is certified to ISO/IEC 27001:2022 on the date of this DPA, and Eolymp will maintain a security program consistent with that standard for as long as it processes Customer Personal Data.

Eolymp will notify the Customer of any Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware of it. The notification will include the information required by Article 33.3 of the GDPR, to the extent available, and Eolymp will provide further information as it becomes available. Eolymp will take reasonable measures to contain the breach and will assist the Customer in complying with its obligations under Articles 33 and 34 of the GDPR.

Unsuccessful attempts that do not compromise Customer Personal Data are not Personal Data Breaches. A notification under this section does not constitute an acknowledgment of fault or liability by Eolymp.

Assistance and Audits

Eolymp assists the Customer in responding to requests from Data Subjects under Chapter III of the GDPR by providing functions in the Services to access, export, correct and delete Customer Personal Data. Any further assistance is provided by agreement, at the cost of the Customer. Eolymp will forward to the Customer any request it receives from a Data Subject concerning Customer Personal Data and will not respond to it unless authorized by the Customer. Eolymp will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 of the GDPR.

On request, Eolymp will make available the information necessary to demonstrate compliance with Article 28 of the GDPR, consisting of its current ISO/IEC 27001 certificate or an equivalent third-party certification, and written answers to one reasonable security questionnaire per year. Where a Supervisory Authority requires it, or that information is demonstrably insufficient to demonstrate compliance, the Customer may carry out a further audit by document review, with thirty (30) days' written notice, through an auditor bound by confidentiality and with the scope agreed in advance. The Customer bears the costs of the audit, including the reasonable costs of Eolymp.

International Transfers

Eolymp stores Customer Personal Data in the European Union. Eolymp will transfer Customer Personal Data outside the European Economic Area only where the transfer is covered by an adequacy decision or by the SCCs (Module 3) concluded with the recipient.

Where the Customer is established outside the European Economic Area, the SCCs (Module 4) are incorporated into this DPA by reference, with Clauses 17 and 18 referring to Spain and the Courts and Tribunals of the city of Barcelona.

Return and Deletion

During the term of the Services, the Customer can export and delete the content of its Space using the Services. Within ninety (90) days after the termination of the Services for the Space, Eolymp will delete Customer Personal Data from its production systems. Copies in backups are deleted as the backups expire, within twelve (12) months. Eolymp may retain Customer Personal Data where EU or Member State law requires it, only for as long as required.

Liability, Term and Applicable Law

The total liability of each party arising out of or in connection with this DPA is limited to the fees paid by the Customer for the Services in the twelve (12) months preceding the event giving rise to the claim. This limitation does not apply to liability towards Data Subjects under Article 82 of the GDPR, to wilful misconduct, or where applicable law does not permit it.

This DPA remains in force for as long as Eolymp processes Customer Personal Data. In the event of conflict, the SCCs prevail over this DPA, and this DPA prevails over the Conditions.

This DPA is governed by Spanish law. Eolymp and the Customer agree to submit any disputes that may arise in connection with this DPA, expressly waiving any other jurisdiction that may correspond to them, to the Courts and Tribunals of the city of Barcelona.

Annex I: Description of Processing

Item

Description

Controller

The Customer. Contact: the email address of the owner of the Space.

Processor

EOLYMP ACADEMY, S.L., support@eolymp.com

Data Subjects

Members of the Space of the Customer, including students (who may be minors), teachers, contest participants and Space administrators.

Category of Data

Name, username, email address and profile picture; member profile (display name, country and institution); group and team membership; submitted source code and answers, verdicts, scores and rankings; integrity flags; discussions and messages within the Space; where enabled by the Customer, prompts and responses of AI features; where enabled by the Customer, proctoring recordings of the screen, camera and microphone of contest participants.

Nature and Purposes of Processing

Hosting the Space; executing and judging submissions; computing results and scoreboards; providing courses, contests and communication features to the members of the Space; storing proctoring recordings and making them available to the Customer.

Duration

For the term of the Services for the Space, followed by deletion as described in the section "Return and Deletion". Proctoring recordings are deleted within fourteen (14) days after they are made.

Annex II: Technical and Organizational Measures

Area

Measures

Encryption

Encryption of data in transit and at rest.

Access Control

Single sign-on with multi-factor authentication for administrative access; time-limited credentials; least-privilege roles.

Tenant Separation

Every request and database query is scoped to a single Space.

Code Execution

Submitted code runs in an environment isolated from the rest of the platform.

Network

Web application firewall; application and data services not exposed to the internet.

Logging and Monitoring

Audit logging of infrastructure access; threat detection; centralized application logs and alerting.

Backup and Recovery

Automated database backups replicated to a second EU region; restores tested.

Vulnerability Management

Automated vulnerability scanning; periodic external penetration testing.

Personnel

Confidentiality obligations; security policies acknowledged by all staff.