Data Processing Agreement.
The terms under which Missiora processes personal data on behalf of organisational customers. This is a plain-English template of our standard DPA — a signable copy is available on request.
This page is a template summary provided for evaluation. It is not a signed contract and does not itself create legal obligations. A formal, signable DPA is available to organisational customers — request one below or email hello@missiora.com.
1. Parties & roles
This DPA is between Missiora (the “Processor”) and the customer organisation (the “Controller”). For the learner personal data an organisation uploads or generates through Missiora, the organisation is the data controller and Missiora acts as data processor. For Missiora's own account and billing data, Missiora is the controller.
Missiora is currently operated as a UK sole trader. We are not yet incorporated as a limited company; formal business registration details will be added as the business grows. This does not affect our data-protection obligations, which apply regardless of legal form.
2. Subject matter & duration
Missiora processes personal data only to provide the platform (interview practice, employability measurement, reporting and related features) for the duration of the customer agreement, plus any limited period needed for deletion or legal compliance.
3. Nature & purpose of processing
- Delivering AI interview practice, scoring and feedback
- Measuring and reporting employability / readiness
- Providing dashboards and analytics to authorised staff of the Controller
- Account management, support and service communications
4. Types of personal data
- Identity & contact details (name, email)
- Uploaded content (CVs, job descriptions)
- Interview audio, transcripts and generated results
- Usage and progression data within the platform
5. Categories of data subjects
Primarily learners, students, apprentices and candidates enrolled by the Controller, and the Controller's authorised staff users (e.g. tutors, administrators).
6. Missiora's obligations as processor
- Process on instructions. We process personal data only on the Controller's documented instructions, including for transfers, unless required by law.
- Confidentiality. Persons authorised to process data are bound by confidentiality.
- Security. We implement appropriate technical and organisational measures (see our Security Overview).
- Sub-processors. We use vetted sub-processors under data-protection terms and will inform the Controller of intended changes. A current list is available on request.
- Assistance. We assist the Controller with data-subject requests and with security, breach-notification and impact-assessment obligations, so far as applicable.
- Deletion / return. On termination we delete or return personal data at the Controller's choice, subject to legal retention.
- Audit. We make available information reasonably necessary to demonstrate compliance.
7. Sub-processors
To deliver the service, Missiora uses trusted sub-processors — for example managed cloud hosting, AI model providers, transactional email and payment processing. Each acts under contractual data-protection terms. A current sub-processor list is available to customers on request.
8. International transfers
Where personal data is transferred outside the UK/EEA, we rely on an appropriate safeguard (such as adequacy or Standard Contractual Clauses / the UK Addendum). We can confirm current arrangements on request.
9. Personal data breaches
We will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provide information reasonably required to meet the Controller's own notification obligations.
10. Data-subject rights
We assist the Controller in responding to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability and objection). Learners can also contact hello@missiora.com and we will route requests appropriately.
A formal, signable DPA (with completed schedules and current sub-processor list) is being finalised. We're happy to provide our latest version and sign your DPA where reasonable during procurement.
Request a signable DPA
Tell us about your organisation and we'll send our current DPA and sub-processor list.