Data Processing Agreement

Last updated: 11 October 2026

This agreement applies automatically to every organisation that uses ExamQR to process personal data of its candidates. No signature is needed; if you need a countersigned copy for your records, email support@examqr.com.

This Data Processing Agreement ("DPA") is between the organisation that holds an ExamQR account ("Customer", controller) and TEX VIETNAM TECHNOLOGY JOINT STOCK COMPANY ("TEX Vietnam JSC", processor), and forms part of the Terms of Service. It applies where TEX Vietnam JSC processes Customer Personal Data on behalf of Customer, and is designed to meet Article 28 of the EU General Data Protection Regulation ("GDPR"), the UK GDPR and similar laws ("Data Protection Law").

1. Details of the processing

Subject matterProviding the ExamQR Service: building tests, delivering and supervising exams, scoring and reporting.
DurationThe term of the Customer's use of the Service, plus the deletion period in section 9.
Nature and purposeHosting, storage, transmission, display, scoring and deletion of data, only to provide the Service to Customer and its candidates.
Data subjectsCustomer's candidates; Customer's staff and supervisors who use the Service.
Personal dataCandidate profile (name, code, group, and optionally birthday, gender, email, phone, address, notes, photo); sign-in password hashes; exam records (answers, timings, scores); IP address and device; proctoring alerts; screenshots when screen monitoring is on; staff names, usernames and emails.
Special categoriesBiometric data (face images and face measurements) only if Customer enables face check. Face check is off by default and is enabled only after Customer confirms it has the required consent.

2. Customer's instructions

TEX Vietnam JSC processes Customer Personal Data only on Customer's documented instructions, which are this DPA, the Terms and Customer's use and configuration of the Service, unless required otherwise by law (in which case it will inform Customer first, unless the law forbids it). It will tell Customer if it believes an instruction breaks Data Protection Law. Customer is responsible for the lawfulness of the data and instructions it provides, including informing candidates and obtaining any consent required.

3. Confidentiality

Only personnel who need access to provide or support the Service may access Customer Personal Data, and they are bound by confidentiality obligations.

4. Security

TEX Vietnam JSC implements the technical and organisational measures described on the Security page, which it may update provided the overall level of protection does not decrease.

5. Sub-processors

6. Data subject requests

Customer can view, correct, export and delete candidate data in the Service. If TEX Vietnam JSC receives a request from a data subject about Customer Personal Data, it will pass it to Customer without responding itself (other than to confirm the referral) and will provide reasonable help for Customer to respond.

7. Personal data breaches

TEX Vietnam JSC will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting Customer Personal Data. The notice will describe what is known (nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken), and will be updated as more becomes known.

8. Assistance

TEX Vietnam JSC will provide reasonable information and help for Customer's data protection impact assessments and prior consultations with supervisory authorities, to the extent they concern the Service.

9. Deletion and return

Proctoring alerts and screenshots are deleted automatically 90 days after the exam date. When Customer closes its account, TEX Vietnam JSC deletes Customer Personal Data within 30 days, and it expires from backups within a further 14 days, unless the law requires it to be kept. Before closing, Customer can export candidate lists and results.

10. Audits

TEX Vietnam JSC will make available the information necessary to demonstrate compliance with this DPA, primarily through written answers to Customer's reasonable security questionnaires. If that is not sufficient, Customer may carry out an audit, at its own cost, with at least 30 days' notice, no more than once a year, during business hours, subject to confidentiality and without access to other customers' data.

11. International transfers

Customer Personal Data is processed in the United States (hosting) and may be accessed from Vietnam (support and operations). For transfers of personal data subject to the GDPR to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs"), Module Two (controller to processor), which are incorporated by reference: Customer is the data exporter and TEX Vietnam JSC the data importer; clause 7 (docking) applies; option 2 of clause 9(a) applies with the notice period in section 5; the optional language in clause 11 does not apply; clauses 17 and 18 are governed by and subject to the courts of Ireland; Annex I is completed by section 1 of this DPA and Annex II by the Security page. For the UK, the UK International Data Transfer Addendum to the SCCs applies; for Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not allow it. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data; if it conflicts with the SCCs, the SCCs prevail.

13. Contact

TEX VIETNAM TECHNOLOGY JOINT STOCK COMPANY (CÔNG TY CỔ PHẦN CÔNG NGHỆ TEX VIỆT NAM; registered name without diacritics: CONG TY CO PHAN CONG NGHE TEX VIET NAM).
Registered address: No. 367-E16, Group 11, Dong Anh Town, Dong Anh District, Hanoi City, Vietnam.
Privacy contact: support@examqr.com.