Data Processing Agreement
Last updated 4 October 2026.
This Data Processing Agreement (“DPA”) forms part of the agreement between AkolagTech (“Processor”, “we”, “us”) and the company customer identified by its Skillermatic company workspace (“Customer”, “Controller”, “you”), and applies whenever AkolagTech processes personal data of the Customer’s staff/learners on the Customer’s behalf through Skillermatic. It incorporates Article 28 of the GDPR/UK GDPR and the processor obligations of the Nigeria Data Protection Act 2023 (“NDPA”).
1. How this DPA is accepted
A company admin accepts this DPA, together with the Terms of Service, by checking the box presented during company onboarding (“I agree to the Terms and the Data Processing Agreement on behalf of my company”). Skillermatic records the version of this DPA accepted and the date and time of acceptance against your company’s workspace. If your company needs a signed, countersigned copy of this DPA for its own records - for example, for a vendor-security review - email privacy@skillermatic.com and we will arrange one.
2. Subject matter, duration, nature, and purpose of processing
- Subject matter: the personal data of the Customer’s staff and learners that the Customer uploads to, or that is generated within, its Skillermatic company workspace.
- Duration: for as long as the Customer’s Skillermatic account is active, plus the retention and deletion periods in Section 9 below.
- Nature of processing: collection, storage, organization, retrieval, use, and deletion of the personal data described in Annex 1, carried out by automated means within Skillermatic’s AWS-hosted infrastructure.
- Purpose: to provide the Skillermatic training, compliance tracking, phishing-awareness simulation, certification, and reporting service to the Customer, and for no other purpose.
3. Processor obligations
AkolagTech will:
- Process personal data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law - in which case we will tell the Customer of that legal requirement first, unless the law prohibits this.
- Ensure that anyone authorized to process personal data on our behalf is bound by confidentiality.
- Implement the technical and organizational measures set out in Annex 2.
- Engage sub-processors only as described in Section 7 and Annex 3.
- Assist the Customer, taking into account the nature of the processing, with responding to data subject requests (Section 5) and with the Customer’s own data protection impact assessments and prior consultations with a supervisory authority, where applicable.
- Notify the Customer of a personal data breach without undue delay, and in any event within 72 hours of becoming aware of it where the applicable law requires that timeframe (Section 6).
- At the Customer’s choice, delete or return all personal data at the end of the provision of services, and delete existing copies, except where retention is required by law (Section 9).
- Make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in Section 8.
- Comply with the equivalent processor obligations under the NDPA, including acting only on the Customer’s instructions and assisting the Customer in meeting its own obligations as a data controller under the NDPA and GAID.
4. Customer (controller) obligations
The Customer confirms that it has a lawful basis for uploading its staff’s personal data into Skillermatic and for the processing described in this DPA, under the law that applies to it - which may include the GDPR/UK GDPR, the NDPA, or another applicable law - and that its instructions to AkolagTech comply with that law.
5. Assistance with data subject requests
If AkolagTech receives a request from one of the Customer’s staff or learners to exercise a data subject right (access, correction, deletion, and so on), we will promptly forward it to the Customer and provide reasonable assistance to help the Customer respond, since the Customer - not AkolagTech - decides how to respond as the controller. Skillermatic’s own account tools also let the Customer directly view, correct, and remove its people’s records without needing to contact us for routine requests.
6. Personal data breach notification
AkolagTech will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, and in any event within 72 hours where the law applicable to the Customer requires that timeframe, with the information reasonably available at the time, promptly supplemented as more becomes known - so the Customer can meet its own notification obligations to its supervisory authority (such as the NDPC, or an EU/UK data protection authority) and, if required, to the affected individuals.
7. Sub-processors
The Customer gives AkolagTech general written authorization to engage the sub-processors listed in Annex 3 to provide the service. AkolagTech will give the Customer at least 30 days’ advance notice - by email to the company admin, or by posting an update to this DPA with a new “Last updated” date - before adding or replacing a sub-processor that will process the Customer’s personal data, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Customer objects and the parties cannot resolve the objection, the Customer may terminate the affected part of the service.
8. Audits
On reasonable prior written notice, and no more than once per 12-month period (unless required sooner by a supervisory authority or following a security incident), AkolagTech will provide the Customer with the documentation reasonably necessary to demonstrate compliance with this DPA - starting with written information and, if that is not sufficient, cooperating in good faith on a reasonable audit of the relevant controls, conducted in a way that minimizes disruption to AkolagTech’s operations and to other customers’ data, and subject to confidentiality.
9. Deletion and return of data
At the end of the provision of services - account closure or contract termination - AkolagTech will delete the Customer’s personal data from its production systems within 30 days, except for data AkolagTech is required to retain for legal, tax, or billing-record purposes. Because Skillermatic’s database uses point-in-time recovery with a 35-day backup window, residual copies in backups are purged on the normal backup-rotation schedule, within 35 days. On request made before account closure, AkolagTech will instead export the Customer’s data in a structured, commonly-used format before deletion.
10. International transfers
Skillermatic’s infrastructure runs in AWS’s US East (N. Virginia) region. Where the Customer’s personal data is transferred from the EU, the UK, or Nigeria to the United States, the Standard Contractual Clauses issued by the European Commission (and, for the UK, the UK International Data Transfer Addendum) are incorporated into this DPA by reference and apply to that transfer, together with the technical and organizational measures in Annex 2. For transfers out of Nigeria, AkolagTech relies on the NDPA’s permitted transfer mechanisms described in our Privacy Notice.
11. Liability
Each party’s liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
12. Order of precedence
If there is a conflict between this DPA and the Terms of Service on a data protection matter, this DPA controls.
Annex 1 - Data categories and data subjects
Data subjects: the Customer’s employees, contractors, and other staff enrolled as learners in the Customer’s Skillermatic workspace, and the Customer’s own company admin user or users.
Categories of personal data:
- Identity and contact data: name, work email address.
- Employment data: department, job role/title.
- Training data: course enrolments, lesson progress, quiz attempts and scores, assignment due dates and completion status, and certificates issued (learner name, course, company name, issue and expiry dates).
- Phishing simulation data: whether a simulated email was opened, a link clicked, or the email reported - never a password or any credential.
- Audit log data: a record of actions taken on the account, such as who assigned or changed what, and when.
- Technical data incidental to providing the service: IP address and request metadata captured in server and access logs, used only for security and operability.
Special category data: none is intentionally collected. The Customer agrees not to upload special category or sensitive personal data (such as health or biometric data) into free-text fields unless it has separately confirmed with AkolagTech that doing so is supported.
Annex 2 - Technical and organizational measures
These measures reflect how Skillermatic is actually built and operated:
- Encryption in transit. All traffic to Skillermatic is served over TLS via Amazon CloudFront, with modern TLS versions and a restrictive content security policy, HSTS, and other security headers enforced at the edge.
- Encryption at rest. The production database (Amazon DynamoDB) and file storage (Amazon S3) are encrypted at rest. Course video is stored in a private S3 bucket, never public, and served only through signed CloudFront URLs/cookies.
- Tenant isolation. Every company’s data is logically separated by a tenant identifier that is resolved only from the caller’s authenticated session - never from anything the caller’s request sends - and checked again before any record is returned, so one company can never read or write another company’s data, even by guessing an identifier. This is enforced in application code, not merely by policy, and is covered by automated tests that specifically try to breach it.
- Authentication. Sign-in is handled by Amazon Cognito. Multi-factor authentication (MFA) is available and encouraged for administrator accounts. Self-service signup is protected against automated/bot signups by Cloudflare Turnstile, checked on our servers before an account is created.
- Least-privilege access. Production systems that process Customer data run with narrowly scoped permissions - for example, the core application component that reads and writes training data has no general internet access at all, and the component that sends email or talks to payment providers is limited to the exact, named actions it needs, never broad read/write access.
- Network isolation. The core application runs in private network segments with no direct inbound or outbound path to the public internet; it can reach only the database and file storage, over private AWS network paths.
- Audit logging. Key account actions are recorded in an audit log scoped to the Customer’s own workspace.
- Backups and resilience. The production database has point-in-time recovery enabled, allowing restoration from any point in the preceding 35 days, and deletion protection to prevent accidental data loss.
- Change management. Infrastructure is defined as code and changes go through automated checks - including automated tests of the security and tenant-isolation behavior above - before being applied.
- Confidentiality. Personnel with access to production systems are bound by confidentiality obligations.
- Incident response. See Section 6 of this DPA for breach notification commitments.
Annex 3 - Sub-processors
- Amazon Web Services, Inc. (AWS) - cloud hosting, database, file storage, authentication, and email delivery. Location: United States (us-east-1).
- Cloudflare, Inc. - bot/abuse protection on signup (Turnstile). Location: global network.
- Paystack (Paystack Payments Limited) - payment processing, only if and when the Customer’s billing is enabled. Location: Nigeria.
- Stripe, Inc. - payment processing, only if and when the Customer’s billing is enabled. Location: United States / global.
AkolagTech will give at least 30 days’ advance notice before adding or replacing a sub-processor on this list, as described in Section 7 above.
Accepted on behalf of the Customer by the person who completed company onboarding and checked the acceptance box, as recorded by Skillermatic - the version and timestamp are stored against the Customer’s workspace. Need a countersigned copy for your own records? Email privacy@skillermatic.com.