Data Processing Agreement.
The processor terms for institutions running Noplag under their own contract. This page summarizes the DPA; the signable version is attached to enterprise agreements and available on request. Where it conflicts with this summary, the signed DPA controls.
This page summarizes the Data Processing Agreement that governs Noplag's processing of personal data on behalf of an institution. It applies whenever your institution is the controller — LMS deployments, enterprise agreements, and managed self-host. The signable version is attached to enterprise agreements and available on request; where it conflicts with this summary, the signed DPA controls.
Parties and roles
Under the DPA your institution is the data controller and Noplag Labs, Inc. is the processor. Noplag processes personal data only to provide the plagiarism and AI-detection service you've contracted for, and only on your documented instructions. Any sub-processor we use is engaged under back-to-back terms.
Scope and subject-matter of processing
The DPA covers the personal data contained in the documents your users submit and the account or roster identifiers needed to operate the service — typically a name or an opaque LMS user ID, the submission text, and check metadata. Processing lasts for the term of your agreement and the wind-down period that follows.
Processing on documented instructions
We process personal data only as needed to deliver the service and as instructed in your agreement, and we tell you if an instruction would breach data-protection law. We never use institutional submissions to train models, and institutional checks are excluded from the cross-customer Noplag Database unless the institution opts in.
Confidentiality
Everyone we authorize to process your data is bound by confidentiality obligations and is granted access on a least-privilege, logged basis. Access is scoped to the people and systems that need it to run and support the service.
Security measures (Article 32)
We maintain technical and organizational measures appropriate to the risk: encryption in transit and at rest, role-based access control with audit logging, tenant isolation, reproducibility stamps on every report, and a tested incident-response process. The current measures are described at noplag.com/security and form an annex to the DPA.
Sub-processors (Article 28)
We publish the current sub-processor list at noplag.com/legal/sub-processors and give advance notice of any addition or change so you can object. Each sub-processor is bound by data-protection terms at least as protective as the DPA, and we remain responsible to you for their performance.
Assistance with data-subject requests
We help you respond to access, erasure, rectification, portability, and objection requests from your users — through self-serve tooling where possible and, where needed, by acting on your instruction. Requests that reach us directly about institution-initiated checks are referred back to you as the controller.
Breach notification
We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own notification obligations to authorities and data subjects, and we cooperate on remediation.
Deletion and return on termination
On termination, and at your choice, we delete or return the personal data we process for you and delete existing copies, except where the law requires retention. Deletion cascades to the corpus index and fingerprint store, completed within 30 days.
Audits and compliance
We make available the information needed to demonstrate Article 28 compliance and to allow for audits — our documented security measures, a data-flow diagram, and the current sub-processor list, with bespoke audits available for enterprise agreements on reasonable terms. As a relaunching open-core company we don't yet hold a SOC 2 report or other formal attestations and don't claim to; the Apache 2.0 engine lets your team verify the data flow in code instead.
International transfers
Where personal data is transferred outside the EEA or UK, the DPA incorporates the relevant Standard Contractual Clauses and, where applicable, the UK Addendum and the EU-US Data Privacy Framework. The EU-residency endpoint and self-host deployment remove the transfer question for institutions that require it.
How to execute the DPA
Request the signed DPA at dpo@noplag.com, or have your account manager attach it to your order form. We counter-sign and return it; for enterprise agreements it's included by default.
If you run the Apache 2.0 engine inside your own network, submissions never reach us, there's no international transfer, and the DPA's processor scope shrinks to your managed-services terms. Ask us which deployment fits your data-protection requirements.