Data Processing Agreement
Last updated: 11 October 2026
This agreement applies automatically to every organisation that uses ExamQR to process personal data of its candidates. No signature is needed; if you need a countersigned copy for your records, email [email protected].
This Data Processing Agreement ("DPA") is between the organisation that holds an ExamQR account ("Customer", controller) and TEX VIETNAM TECHNOLOGY JOINT STOCK COMPANY ("TEX Vietnam JSC", processor), and forms part of the Terms of Service. It applies where TEX Vietnam JSC processes Customer Personal Data on behalf of Customer, and is designed to meet Article 28 of the EU General Data Protection Regulation ("GDPR"), the UK GDPR and similar laws ("Data Protection Law").
1. Details of the processing
| Subject matter | Providing the ExamQR Service: building tests, delivering and supervising exams, scoring and reporting. |
|---|---|
| Duration | The term of the Customer's use of the Service, plus the deletion period in section 9. |
| Nature and purpose | Hosting, storage, transmission, display, scoring and deletion of data, only to provide the Service to Customer and its candidates. |
| Data subjects | Customer's candidates; Customer's staff and supervisors who use the Service. |
| Personal data | Candidate profile (name, code, group, and optionally birthday, gender, email, phone, address, notes, photo); sign-in password hashes; exam records (answers, timings, scores); IP address and device; proctoring alerts; screenshots when screen monitoring is on; staff names, usernames and emails. |
| Special categories | Biometric data (face images and face measurements) only if Customer enables face check. Face check is off by default and is enabled only after Customer confirms it has the required consent. |
2. Customer's instructions
TEX Vietnam JSC processes Customer Personal Data only on Customer's documented instructions, which are this DPA, the Terms and Customer's use and configuration of the Service, unless required otherwise by law (in which case it will inform Customer first, unless the law forbids it). It will tell Customer if it believes an instruction breaks Data Protection Law. Customer is responsible for the lawfulness of the data and instructions it provides, including informing candidates and obtaining any consent required.
3. Confidentiality
Only personnel who need access to provide or support the Service may access Customer Personal Data, and they are bound by confidentiality obligations.
4. Security
TEX Vietnam JSC implements the technical and organisational measures described on the Security page, which it may update provided the overall level of protection does not decrease.
5. Sub-processors
- Customer authorises the sub-processors listed in section 7 of the Privacy Policy that process Customer Personal Data: Cloudflare, Inc. (network delivery and security), OVHcloud (hosting), our email delivery provider (exam invitations and password emails to candidates), and Google LLC only for the services Customer enables (Sign in with Google, reCAPTCHA, and its public STUN server, which helps live video connect when Customer uses live supervision). The browsers of candidates and staff also load open-source scripts and styles from jsDelivr on the pages of the web application, including exam pages, and the live quiz loads avatar pictures from DiceBear; these services receive the IP address and, for DiceBear, the player's nickname, but no other Customer Personal Data. AI providers do not receive candidate data.
- TEX Vietnam JSC will give at least 30 days' notice by email before adding or replacing a sub-processor of Customer Personal Data. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees.
- TEX Vietnam JSC imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for their performance.
6. Data subject requests
Customer can view, correct, export and delete candidate data in the Service. If TEX Vietnam JSC receives a request from a data subject about Customer Personal Data, it will pass it to Customer without responding itself (other than to confirm the referral) and will provide reasonable help for Customer to respond.
7. Personal data breaches
TEX Vietnam JSC will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting Customer Personal Data. The notice will describe what is known (nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken), and will be updated as more becomes known.
8. Assistance
TEX Vietnam JSC will provide reasonable information and help for Customer's data protection impact assessments and prior consultations with supervisory authorities, to the extent they concern the Service.
9. Deletion and return
Proctoring alerts and screenshots are deleted automatically 90 days after the exam date. When Customer closes its account, TEX Vietnam JSC deletes Customer Personal Data within 30 days, and it expires from backups within a further 14 days, unless the law requires it to be kept. Before closing, Customer can export candidate lists and results.
10. Audits
TEX Vietnam JSC will make available the information necessary to demonstrate compliance with this DPA, primarily through written answers to Customer's reasonable security questionnaires. If that is not sufficient, Customer may carry out an audit, at its own cost, with at least 30 days' notice, no more than once a year, during business hours, subject to confidentiality and without access to other customers' data.
11. International transfers
Customer Personal Data is processed in the United States (hosting) and may be accessed from Vietnam (support and operations). For transfers of personal data subject to the GDPR to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs"), Module Two (controller to processor), which are incorporated by reference: Customer is the data exporter and TEX Vietnam JSC the data importer; clause 7 (docking) applies; option 2 of clause 9(a) applies with the notice period in section 5; the optional language in clause 11 does not apply; clause 17 (governing law): the law of Ireland; clause 18 (choice of forum and jurisdiction): the courts of Ireland; Annex I is completed by section 1 of this DPA and Annex II by the Security page. For the UK, the UK International Data Transfer Addendum to the SCCs applies; for Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection.
12. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not allow it. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data; if it conflicts with the SCCs, the SCCs prevail.
13. Contact
TEX VIETNAM TECHNOLOGY JOINT STOCK COMPANY (CÔNG TY CỔ PHẦN CÔNG NGHỆ TEX VIỆT NAM; registered name without diacritics: CONG TY CO PHAN CONG NGHE TEX VIET NAM).
Registered address: No. 367-E16, Group 11, Dong Anh Town, Dong Anh District, Hanoi City, Vietnam.
Privacy contact: [email protected].