Data Processing Agreement (DPA)
Last updated: July 2026
This agreement applies when an organization (the controller) uses QuizJhor (the processor) to process participant data — names, roll/ID, answers, results, and the optional contact phone. It forms part of our Terms.
Parties
Processor: QuizJhor (কুইজঝড়) (legal entity details to be added)
Controller: The organization holding the QuizJhor workspace — they own the roster data and its lawful basis.
Nature of processing
Running live quizzes/assessments, producing results and merit lists, issuing certificates, and sending result SMS to nominated phones on the controller's instruction. We do not sell this data; quizzes, rosters, answers and results are never used for advertising.
Subprocessors
- Vercel — application hosting (Singapore)
- Supabase — database & realtime (Singapore)
- Resend — transactional email (login codes, receipts, result reports at the host's request) (USA)
- bKash — payments — wallet details never touch our servers (Bangladesh)
- SSLCommerz — payments — card details never touch our servers (Bangladesh)
- BulkSMSBD — result SMS to guardians (when the host enables it) (Bangladesh)
- Anthropic — AI quiz generation — host-supplied sources; not used for model training (USA)
- OpenAI — AI generation / voice transcription (as configured) (USA)
- OpenRouter — AI generation / voice routing (as configured) (USA)
- Groq — voice transcription (as configured) (USA)
- Google (Gemini API) — voice transcription (as configured) (USA)
- Google (Firebase Cloud Messaging) — mobile-app push notifications (when permitted) (Global)
- Meta (Conversions API) — ad measurement: buyer purchase events, hashed, server-side — never student data (USA)
- Google (Analytics / Tag Manager) — visit measurement on marketing pages — never on student screens; off by default in the EEA/UK (USA)
- Meta (Pixel) — visit measurement on marketing pages — never on student screens; off by default in the EEA/UK. The Pixel also sends events to Meta's own gateway (hosted on Google Cloud) (USA)
- YouTube (Google) — blog videos — load only when you press play (privacy-enhanced nocookie mode); posters are served through our own server (Global)
- Vimeo — blog videos — load only when you press play (USA)
- Google Sign-In — sign-in — only if you choose it (Global)
- LinkedIn Sign-In — sign-in — only if you choose it (Global)
Security measures
Database-level lockdown (RLS enabled on every table, public/anon access revoked — re-applied automatically after every database change), per-organization scoped queries on the server, TLS encryption, hashed tokens/OTPs, role-based access. Privileged internal actions that modify customer data require fresh-OTP verification and a written reason; viewing customer data is also role-gated and is written to an audit log recording who viewed whose account and when. Details
Retention & deletion
Game/assessment data is deleted automatically after 90 days; expired codes and logs are pruned regularly. Verifiable certificates are long-lived (revocable on request). Account deletion is available with a 7-day cancellation window: /account/delete
Data-subject rights
Participants' access/correction/deletion requests go to the controller (the organization) first; we assist the controller. Requests to stop result SMS can also come directly to us.
Incident notification
On a confirmed security breach affecting participant data, we will notify affected organizations without undue delay, including impact and remediation.
Contact
If the Bangla and English texts differ, the Bangla text controls. This agreement is governed by the laws of Bangladesh.