Legal

Data Processing Addendum

Effective 1 January 2026. Applies where MAST Study processes personal data on behalf of a corporate customer (Controller).

1. Scope

This DPA forms part of the Corporate Subscription Agreement between Customer (Controller) and MAST Study (Processor) and applies whenever MAST Study processes personal data of Customer's learners on Customer's instructions.

2. Subject matter & duration

Hosting and operation of the MAST Study learning platform, for the duration of the underlying agreement plus any retention period specified in our Privacy Notice.

3. Nature & purpose

Delivery of professional learning, assessments, certification and analytics, including authentication, progress tracking and certificate issuance.

4. Categories of data & data subjects

Learner identifiers (name, email), role, learning activity, assessment results, certificate metadata. Data subjects are Customer's employees, contractors and authorised learners.

5. Processor obligations

  • Process personal data only on documented instructions from Customer.
  • Ensure personnel are bound by confidentiality.
  • Implement appropriate technical and organisational measures (Annex A).
  • Use sub-processors only under written contract with equivalent obligations.
  • Assist Customer with data subject requests, DPIAs and breach notifications.
  • Notify Customer of confirmed personal data breaches without undue delay and within 72 hours where feasible.
  • Delete or return personal data on termination, subject to legal retention obligations.

6. Sub-processors

A current list of sub-processors is maintained at the request of Customer's Data Protection Officer (dpo@maststudy.com). Customer will be notified of additions or replacements and may object on reasonable data protection grounds.

7. International transfers

Where personal data is transferred outside the UAE/EEA/UK, the EU Standard Contractual Clauses (Module 2 or 3, as applicable) and UK Addendum are incorporated by reference.

8. Audit

Customer may, on reasonable notice and no more than once per year, request information demonstrating compliance, including current SOC 2 / ISO 27001 reports of our sub-processors. On-site audits are limited to confirmed material breaches.

Annex A — Technical & organisational measures

Row-Level Security on all customer data tables; least-privilege role-based access; TLS in transit; encryption at rest at the hosting provider; access logging; quarterly access reviews; SDLC with code review; vulnerability scanning; documented incident response.