Vosaic Data Processing Addendum
Last Updated: October 5, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Nelnet Business Solutions, Inc. d/b/a Vosaic (“Company”) and the customer that subscribes to or uses the Services (“Customer”), consisting of Company’s Terms of Use together with the subscription, order, or invoice terms accepted by Customer, or any written services agreement executed between the Parties (the “Agreement”). This DPA applies automatically, without further action by either Party, from the date Customer accepts the Agreement or first uses the Services, whichever is earlier, and applies only for so long as and to the extent that Company Processes Personal Information on Customer’s behalf in connection with the Services. Any capitalized terms used but not defined in this DPA have the meanings set out in the Agreement. Where Customer and Company have executed a separate, negotiated data processing agreement covering the Services, that agreement controls and this DPA does not apply.
STATEMENT OF PURPOSE: Under the Agreement, Company may be required to Process Personal Information provided and/or collected by Customer. This DPA addresses each Party’s compliance obligations under applicable Privacy Laws and applies only to the extent that the provision of Services by Company to Customer involves the Processing of Personal Information subject to such Privacy Laws on behalf of Customer. In such case, Customer appoints Company as a Processor or Service Provider, as the case may be, under the applicable Privacy Laws. To the extent Company does not Process Personal Information on Customer’s behalf in connection with the Services, this DPA imposes no obligations on either Party.
- Definitions.
- “Account Data” means information provided to Company by or on behalf of Customer to establish, administer, or maintain Customer’s account for accessing the Services, including administrator contact information, billing details, and authentication credentials.
- “Aggregate” means, unless defined under applicable Privacy Laws, to gather and express raw data in a summary form for statistical analysis.
- “Data Subject” means an identified or identifiable natural person to which the Personal Information pertains.
- “De-identify” means, unless defined under applicable Privacy Laws, to remove any personally identifiable information and other similar attributes from the data so that no individual identification can reasonably be made.
- “Feedback” means any suggestions, comments, feature requests, enhancement ideas, or other feedback provided by Customer regarding the Services.
- “EEA” means the European Economic Area.
- “EU” means the European Union.
- “e-Privacy Directive” means the EU Directive 2002/58/EC
- “European Data Protection Laws” means all applicable EU, EEA or national laws and regulations, the laws and regulations of the UK and Switzerland, relating to the privacy, confidentiality, security or protection of Personal Information, including, without limitation: the GDPR and laws or regulations implementing or supplementing the GDPR; the e-Privacy Directive, as replaced from time to time, and laws or regulations implementing or supplementing the e-Privacy Directive, including laws regulating the use of cookies, other tracking mechanisms and unsolicited e-mail communications; the UK Data Protection Act 2018 or any other law relating to data protection enacted in connection with the UK’s departure from the EU (including the GDPR as incorporated into the laws of the UK); and the Swiss Federal Act on Data Protection, as amended from time to time.
- “Extended EEA Country” means a Member State of the EEA, Switzerland or the UK, and Extended EEA Countries means the foregoing countries collectively.
- “GDPR” means the EU General Data Protection Regulation 2016/679.
- “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, as defined by the applicable Privacy Laws that may be Processed by Company in connection with the performance of the Agreement.
- “Privacy Laws” means, collectively, to the extent applicable to the Processing of Personal Information under this DPA: (i) European Data Protection Laws; (ii) the Gramm–Leach–Bliley Act, 15 U.S.C. § 6801 et seq., and implementing regulations (“GLBA”); and (iii) the Family Educational Rights and Privacy Act of 1974, 20 U.S.C. § 1232g, and its implementing regulations, 34 C.F.R. Part 99 (“FERPA”).
- “Standard Contractual Clauses” means, as applicable, the “standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council adopted by the European Commission decision of 4 June 2021” and published under document number C (2021) 3972 available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914&qid=1689513765256, as may be updated, amended or superseded from time to time.
- “Third Countries” means countries outside the Extended EEA Countries which have not been subject to an Adequacy Decision.
- “UK” means the United Kingdom.
- “UK International Data Transfer Addendum” means template Addendum B.1.0 issued by the UK ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses, available at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-data-transfer-agreement-and-guidance/, as may be updated, amended or superseded from time to time.
- “Usage Data” means technical and operational data generated through the use of the Services, including system logs, performance metrics, feature usage statistics, session data, error reports, and similar telemetry data that relates to the operation, support, or improvement of the Services.
- “Controller”, “Deidentified”, “Process”, “Processor”, “Service Provider” (and their derivatives) have the meanings ascribed to them in the applicable Privacy Laws.
- Roles and Responsibilities of the Parties.
- Company’s Obligations and Authority to Process Personal Information
- Company, with respect to Personal Information and, subject to applicable Privacy Laws, will Process Personal Information in accordance with Company’s instructions and Annex 1 of this DPA.
- Except as described in Section II(A)(5) below, Company shall not:
- Sell or Share Personal Information; retain, use or disclose Personal Information (i) for any purpose other than for the business purposes specified in the Agreement (“Business Purpose”), or (ii) outside of the direct business relationship between Customer and Company; or
- Combine Personal Information received pursuant to the Agreement with Personal Information received from or on behalf of another person(s), or collected from Company’s own interaction with individuals, unless permitted by Privacy Laws. For the avoidance of doubt, Company may De-identify or Aggregate Personal Information in accordance with the standards set forth in applicable Privacy Laws.
- Company shall comply with relevant obligations as a Service Provider and Processor under Privacy Laws and provide the level of privacy protection for Personal Information as is required by applicable Privacy Laws.
- To the extent required by Privacy Laws, Company will:
- notify Customer if Company makes a determination that it can no longer meet its obligations under this Addendum or applicable Privacy Laws;
- maintain internal records of Processing activities and will provide copies to the Customer upon written request;
- taking into account the nature of the Processing of Personal Information, reasonably assist Customer in fulfilling Customer’s obligations to respond to rights requests received from individuals pursuant to Privacy Laws;
- maintain reasonable and appropriate safeguards and other security measures appropriate to the risk of Processing designed to protect the security, integrity, and confidentiality of Personal Information from unauthorized access, destruction, acquisition, use, modification, or disclosure
- notify Customer without undue delay upon becoming aware of unauthorized access to, or acquisition, use, modification or disclosure of, Personal Information in Company’s possession that compromises the security, confidentiality or integrity of such Personal Information. Company shall provide such information as is required to enable Customer to satisfy Customer’s obligations under applicable law;
- upon Customer’s reasonable request, make available information in its possession necessary to demonstrate Company’s compliance with its obligations under this DPA, provided Company shall have no obligation to provide commercially confidential information;
- at no cost to Company, allow for and cooperate with reasonable assessments by Customer (or Customer’s designee), or alternatively arrange for such assessment by a qualified independent assessor of Company’s choosing, of Company’s policies and technical and organizational measures in support of relevant obligations under applicable Privacy Laws. Company shall provide a report of such assessment to Customer upon request;
- ensure that any Company personnel who Process Personal Information in the context of the Services are subject to a duty of confidentiality with respect to the Personal Information;
- where Company provides a third party with access to Personal Information or contracts any of its rights or obligations concerning Personal Information to any other person (“Sub-Processor”), Company will (i) to the extent required by applicable Privacy Laws, notify Customer of such engagement and, give Customer an opportunity to object before Personal Information is provided to the Sub-Processor; and (ii) enter into a written agreement with each such Sub-Processor that imposes obligations on the Sub-Processor that are similar in all material respects to those imposed on Company under Section II(A) of this DPA;
- reasonably assist Customer with its obligations with respect to data protection impact assessments required under applicable Privacy Law;
- at Customer’s direction, delete or return Personal Information at the end of the provision of Services, unless retention of the Personal Information is required by applicable law or Customer affirmatively requests a different time period;
- To the extent permitted by Privacy Laws, Company may retain, use, or disclose Personal Information obtained in the course of providing the Services:
- To retain and employ another Processor or Service Provider as a subcontractor, where the subcontractor meets the requirements for a Processor or Service Provider under Privacy Laws;
- For internal use by Company to build or improve the quality and functionality of its services, provided that the use does not include building or modifying household or consumer profiles to use in providing services to another business, or correcting or augmenting data acquired from another source;
- To detect data security incidents, or protect against fraudulent or illegal activity;
- To comply with federal, state, or local laws;
- To comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities;
- To cooperate with law enforcement agencies concerning conduct or activity that Company reasonably and in good faith believes may violate federal, state, or local law; or
- To exercise or defend legal claims.
- Notwithstanding any provision to the contrary, Customer agrees that Company may create, use, and disclose De-identified or Aggregated data derived from Personal Information Processed in connection with the Services for its own business purposes, including research, analytics, and improvement of its services, provided such data cannot reasonably be used to identify any individual. Company shall own all rights in such De-identified or Aggregated data and shall maintain it in a manner consistent with applicable Privacy Laws. Company agrees not to attempt to re-identify such data unless permitted or required by applicable law.
- Notwithstanding Section II(A)(1) above, Usage Data, Account Data, and Feedback are not Processed on Customer’s behalf and are not subject to Sections II(A)(1) through II(A)(5); Company acts as Controller with respect to Usage Data, Account Data, and Feedback and Processes them in accordance with its published privacy statement. Company may collect, use, and disclose Usage Data, Account Data, and Feedback for its legitimate business purposes, including: (a) operating, maintaining, and improving the Services; (b) developing new products, features, and services; (c) generating benchmarking, analytics, and industry insights (provided such outputs do not identify Customer or any individual); (d) providing technical support and communicating with Customer; and (e) ensuring security and preventing fraud.
- Customer represents and warrants that: Customer has complied in all material respects with applicable Privacy Laws in relation to all Personal Information disclosed or otherwise made available to Company, including without limitation (i) ensuring the accuracy, quality and legality of the Personal Information, and (ii) providing any notices and obtaining any consents necessary to enable Company to Process Personal Information pursuant to the Agreement and this Addendum; and
- Institution acknowledges and agrees that, unless otherwise expressly agreed to in writing by the Parties, the Services are not directed to children below the applicable age threshold for valid consent under Privacy Laws and are not designed to collect or solicit Personal Information directly from such children. While the Services may receive or Process Personal Information about such children, Institution acknowledges that such information is intended to be provided by adults acting on behalf of the child, such as parents, guardians, or authorized Institution personnel. Accordingly, Institution agrees that it shall be solely responsible for complying with its obligations under applicable Privacy Laws relating to children’s data (such as the federal Children’s Online Privacy Protection Act of 1998, 15 U.S.C. §§ 6501-6506, and its implementing regulations, 16 C.F.R. Part 312 (“COPPA”)), including but not limited to providing required notices and obtaining any required parental consent in Institution’s capacity as agent for parents. Company shall not be responsible for obtaining such consent unless the Parties have expressly agreed in writing.
- If COPPA applies to Personal Information Processed by Company as part of its provision of the Services to Institution:
- Company will Process Personal Information only for educational purposes;
- Institution represents and warrants that it has reviewed (i) Company’s direct notice of its collection, use and disclosure practices with respect to Personal Information collected online from children under age 13 (“COPPA Direct Notice”), available at https://factsmgt.com/childrens-online-privacy-protection/; and (ii) Company’s Privacy Policy, available at https://factsmgt.com/privacy-policy/. Institution covenants that it will make available Company’s COPPA Direct Notice and Company’s Privacy Policy to parents of children under 13 from whom Company collects Personal Information pursuant to the Services (hereinafter, “Participating Parents”).
- Institution acts as an agent on behalf of all Participating Parents to authorize the collection, use and disclosure of Personal Information collected online from children under age 13.
- Any Personal Information collected by Company pursuant to the Services is under the direct control of Institution with regard to Company’s use and maintenance of the Personal Information.
- Company further acknowledges and agrees, by and through its designated representative signing or acknowledging this DPA, that it has authority to authorize the collection of Personal Information. Institution shall ensure that the instructions Institution provides to Company in relation to the Processing of Personal Information do not (i) violate Privacy Laws or any other applicable laws; or (ii) put Company in breach of its obligations under applicable law.
- If applicable, pursuant to FERPA, if Company will have access to education records, as such term is used under FERPA, Customer hereby designates Company as a “school official” with a “legitimate educational interest” that performs an institutional service or function for which Customer would otherwise use employees. Customer further warrants that it owns the Personal Information within the education records that is subject to FERPA and Company will use and disclose such information only in accordance with the terms of the Agreement and this DPA for the purpose and benefit of the Customer.
- If applicable, pursuant to GLBA, if Customer provides or grants Company access to nonpublic personal information, as such term is defined in the applicable provisions of the GLBA (“NPI”), Company will:
- maintain the confidentiality of all NPI received from or on behalf of Customer;
- implement appropriate safeguards to protect the security and confidentiality of NPI in accordance with applicable GLBA requirements; and
- not use or disclose NPI except as necessary to perform services under the Agreement or as otherwise permitted by GLBA and implementing regulations.
- Customer acknowledges and agrees that Company does not require protected health information as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“PHI”) in order to provide the Services. Customer shall not submit PHI to the Services unless the Parties have executed a Business Associate Agreement covering the Services, in which case that Business Associate Agreement governs Company’s handling of PHI and this DPA does not apply to PHI. No marketing material, product description, or compliance page published by Company constitutes agreement to receive PHI absent an executed Business Associate Agreement.
- The Services enable Customer and its authorized users to create, upload, and review audio and video recordings of identifiable individuals. As between the Parties, Customer is solely responsible for determining who may be recorded and for providing all notices and obtaining all consents, authorizations, and permissions required under applicable law (including any applicable recording, wiretap, two-party consent, or biometric law) before any recording is created, uploaded to, or Processed through the Services.
- Customer may take reasonable and appropriate steps to ensure that Company uses Personal Information in a manner consistent with Customer’s obligations under applicable Privacy Laws. Customer may, upon notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.
- The Parties acknowledge and agree that the Personal Information that Customer discloses to Company is provided to Company for the limited Business Purposes specified in the Agreement.
- If, and to the extent, the Processing of Personal Information subject to European Data Protection Laws of Extended EEA Countries involves transfers by the Customer from the Extended EEA Countries to the Company in jurisdictions that have not received an Adequacy Decision from the relevant data protection authorities, the Company and the Customer shall implement the applicable Standard Contractual Clauses and the UK International Data Transfer Addendum. These instruments will be deemed executed by both Parties as of the Effective Date of the Agreement, incorporated herein by reference, and interpreted in accordance with Annex 2 of this DPA, unless an alternative lawful transfer mechanism under applicable Data Protection Laws applies.
- Company’s Obligations and Authority to Process Personal Information
- This DPA supersedes and replaces all prior or existing terms, conditions, and provisions of the Agreement (or any other agreement between the Parties) that relate to data privacy, data protection, or the Processing of Personal Information, to the extent of any conflict or overlap with the terms of this DPA. This DPA does not modify the limitation of liability, indemnification, insurance, or other general terms and conditions of the Agreement, which govern the Parties’ respective liabilities under this DPA. This DPA shall remain in effect unless and until a subsequent data processing addendum or similar agreement between the Parties, specifically addressing the same subject matter, expressly supersedes and replaces the terms herein.
- Company may update this DPA from time to time. Company will post the current version at https://vosaic.com/page/vosaic..., together with its effective date, and will make prior versions available on request. Company will provide reasonable advance notice of any material change through the Services, by email to Customer’s administrative contact, or through the notice mechanism described in Section II(A)(4)(i). No update will materially reduce the protections applicable to Personal Information Processed on Customer’s behalf during Customer’s then-current subscription term. Updates required to reflect changes in Privacy Laws, or in the Standard Contractual Clauses or other approved transfer mechanism, take effect on the date required by the applicable law or instrument. Customer’s continued use of the Services after the effective date of an update constitutes acceptance of the updated DPA.
- Notices, requests, and inquiries under this DPA may be directed to Company at AskPrivacy@nelnet.net. Customer is responsible for maintaining current administrative and security contact information within the Services so that Company can deliver the notices required under this DPA. Upon Customer’s reasonable written request, Company will provide a countersigned copy of this DPA reflecting the version in effect on the date of Customer’s acceptance.
List of Annexes attached to this DPA
Annex 1 – SCOPE OF THE DATA PROCESSING
Annex 2 – STANDARD CONTRACTUAL CLAUSES
ANNEX 1: SCOPE OF THE DATA PROCESSING
This Annex 1 forms part of the DPA between Customer and Company.
Subject matter and duration of the Processing of Personal Information
Company Processes Personal Information on behalf of Customer for the purpose of providing the Services pursuant to the Agreement and as further Instructed by Customer in its use of the Services.
The duration of the Processing is equal to the duration of the Agreement, or until otherwise Instructed by Customer.
The categories of Data Subjects to whom the Personal Information relates
Data Subjects include the following, as determined by Customer's use of the Services: Customer's employees, contractors, consultants, and administrators; students, trainees, and other individuals recorded, observed, coached, or evaluated using the Services; and any other individuals appearing in or identified within content submitted to the Services by or on behalf of Customer.
The types of Personal Information to be Processed
Personal Information Processed depends on Customer’s use of the Services and may include: name, email address, phone number, job title, employer, IP address, device identifiers; audio and video recordings of identifiable individuals and the images, voices, speech, and conduct captured within them; automated transcripts of those recordings; and observation, coaching, assessment, and evaluation notes, tags, and scores associated with them.
The Processing concerns the following categories of Sensitive Data[1]:
The Parties acknowledge that audio and video recordings created through or uploaded to the Services necessarily contain images and voices of identifiable individuals, and that Processing such recordings is the intended purpose of the Services. Except for that content, Customer shall not submit Sensitive Data to the Services unless expressly permitted under the Agreement or a separate written addendum. To the extent Customer submits Sensitive Data, Customer is solely responsible for ensuring a lawful basis for such Processing and for applying any required safeguards (e.g., encryption, explicit consent).
[1]Sensitive Data means Personal Information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, government-issued identifiers, financial account information, precise geolocation data, data concerning health, sex life or sexual orientation.
The nature and purpose of the Processing of Personal Information
Company shall Process Personal Information for the following Business Purposes, in accordance with the Agreement:
- Helping to ensure security and integrity, to the extent the use of Personal Information is reasonably necessary and proportionate for these purposes.
- Debugging to identify and repair errors that impair existing intended functionality.
- Performing Services on behalf of Customer, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of Customer.
- Undertaking internal research for technological development and demonstration.
- Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Customer, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Customer.
ANNEX 2
STANDARD CONTRACTUAL CLAUSES
- Incorporation and interpretation of the Standard Contractual Clauses
- In circumstances where Customer is acting as a Data Controller, and in relation to transfers by Customer of Personal Information which are subject to the European Data Protection Laws to Company in Third Countries, the Parties agree that Module Two (Transfer controller to processor) shall apply.
- In circumstances where Customer is acting as a Data Processor, and in relation to transfers by Customer of Personal Information which are subject to the European Data Protection Laws to Company in Third Countries, the Parties agree that Module 3 (Transfer processor to processor) of the Standard Contractual Clauses shall apply.
- The Parties acknowledge that the information required to be provided in the Standard Contractual Clauses, including the appendices, is set out in Appendix 1 attached to this Annex 2.
- If there is a conflict between the provisions of this Agreement and the terms of this Annex 2, the terms of this Annex 2 will prevail.
- If any provision or part-provision of this DPA or the Agreement causes the Standard Contractual Clauses to become an invalid export mechanism in the relevant Extended EEA Country, it shall be deemed deleted but that shall not affect the validity and enforceability of the rest of this Agreement and the parties shall negotiate in good faith to agree a replacement provision that, to the greatest extent possible, achieves the intended commercial result of the original provision.
- Notwithstanding anything to the contrary, where the applicable Extended EEA Country where the data exporter is established or from where the transferred personal data originated is the UK, the UK International Data Transfer Addendum shall amend the Standard Contractual Clauses in respect of such transfers and Part 1 of the UK International Data Transfer Addendum shall be populated as set out below:
- Table 1. The “start date” will be the date this DPA enters into force. The “Parties” are Customer as exporter Company as importer.
- Table 2. The “Addendum EU SCCs” are the modules and clauses of the Standard Contractual Clauses selected in relation to a particular transfer particular transfer in accordance with paragraphs 1.a., 1.b., and 1.c. of this Annex 2.
- Table 3. The “Appendix Information” is as set out in Appendix 1 to this Annex 2.
- Table 4. Exporter party may end the UK International Data Transfer Addendum in accordance with its relevant Section.
- Where the applicable Extended EEA Country in which the data exporter is established, or from which the transferred personal data originated, is not a Member State of the European Union, references in the Standard Contractual Clauses to:
- “Member States of the European Union” shall mean that Extended EEA Country;
- “the GDPR” shall mean the Data Protection Laws of the Extended EEA Country; and
- “supervisory authority” shall mean the data protection authority of that Extended EEA Country, as identified in Appendix I(C) below.
Appendix 1 – Completion of the Standard Contractual Clauses
A. LIST OF THE PARTIES | |
Data Exporter: | Name and address: Customer, as set out in the Agreement Contact details: Customer, as set out in the Agreement Activities relevant to the data transferred under these Clauses: Receipt of Company Services, as set out in the Agreement and this DPA |
Data Importer: | Name and address: Company, as set out in the Agreement Contact details: Company, as set out in the Agreement Activities relevant to the data transferred under these Clauses: Receipt of Company Services, as set out in the Agreement and this DPA |
B. DETAILS OF PROCESSING/TRANSFER | |
CATEGORIES OF DATA SUBJECTS | As described in Annex 1 |
CATEGORIES OF PERSONAL DATA | As described in Annex 1 |
SPECIAL CATEGORIES OF DATA (IF APPLICABLE) | As described in Annex 1 |
FREQUENCY OF THE TRANSFER | As regular as is required to provide the Services |
NATURE AND PURPOSE OF THE PROCESSING | As described in Annex 1 |
RETENTION | As described in Annex 1 |
TRANSFER TO (SUB)PROCESSORS | As set out in Annex 1 |
C. COMPETENT SUPERVISORY AUTHORITY | |
The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses. Where an EU Representative has not been appointed by data exporter, the competent supervisory authority shall be the supervisory authority of Ireland. | |
D. GOVERNING LAW AND CHOICE OF FORUM | |
GOVERNING LAW | For the purposes of Clause 17 of the Standard Contractual Clauses the Parties select OPTION 1: the law of Ireland. a) |
CHOICE OF FORUM | For the purposes of Clause 18 of the Standard Contractual Clauses: the Parties select the courts of Ireland. |
E. OTHER | |
Where the Standard Contractual Clauses identify optional provisions (or provisions with multiple options) the following will apply: For Clause 7 (Docking Clause), the optional provision will not apply, unless the Parties otherwise agree in writing. For Clause 9(a), option 2 (General Written Authorization) will apply and the time period for prior notice of Sub-Processor changes contained in this DPA will apply (if any). | |