For organizations, this sets out who does what with personal information. It applies when included in a written agreement with Oyamu, covering instructions, safeguards, service providers and what happens to the data when the work ends.
When this addendum applies
This addendum applies only when incorporated into a written agreement between Oyamu LLC and an organization. For the personal information covered by that agreement, the organization determines the purposes of processing and Oyamu acts on its documented instructions.
Oyamu’s own account administration, billing, security and legal obligations are covered separately by the Privacy policy. A valid transfer agreement and mandatory law take priority over inconsistent terms.
Processing schedule
The agreed schedule identifies the organization, features, authorized instructions, contacts, affected people and data categories. Covered activities can include storing, organizing, displaying, securing and deleting records needed to deliver the ordered learning features.
Data can include learner and staff identifiers, contact details, membership, study activity, submissions, support records and access logs. The schedule also defines duration, locations, providers, security measures, retention and deletion. Unnecessary sensitive information and clinical records are outside scope unless expressly and lawfully agreed.
Customer instructions and responsibilities
The organization is responsible for a lawful basis, required notices and permission to supply the information. It must set appropriate access permissions and avoid collecting unrelated data. If Oyamu believes an instruction violates data-protection law, it will inform the organization and may suspend the affected processing while the issue is resolved.
School use must meet applicable education-record and child-privacy requirements. This addendum does not authorize advertising to students or unrelated commercial use of school records.
Processor commitments
Oyamu will process covered information only on documented lawful instructions, including transfer instructions, unless law requires otherwise. Where permitted, it will inform the organization before legally required processing. Authorized personnel must have appropriate confidentiality duties and access limits.
Covered institutional records must not be sold as a data product or used for independent behavioral advertising. Service-delivery instructions do not authorize training a general AI model; any such use requires separate lawful and contractual authority.
Security and incidents
The agreement’s security schedule specifies measures appropriate to the information and risks, including access control, confidentiality, encryption, recovery and supplier management.
Oyamu will notify the organization without undue delay after becoming aware of a personal-data breach affecting covered information. Available details will describe the incident, likely consequences, containment and a contact; further information may follow as facts become known. The agreement does not delay notices required by law.
Subprocessors
Approved subprocessors must be bound by the data-protection obligations required by law. The provider schedule identifies the relevant entities, purposes, locations and transfer safeguards. Oyamu remains responsible for applicable subprocessor obligations.
Where general authorization is agreed, the contract specifies advance notice of material provider changes and an opportunity to object on data-protection grounds. An unresolved justified objection is handled through the contract’s alternative-service or termination process and applicable prepaid-fee adjustment.
Rights requests and assistance
Oyamu will assist with applicable access, correction, deletion, restriction, objection and portability requests concerning covered information. Requests intended for the organization will be forwarded; Oyamu responds on its behalf only on instructions or where law requires.
Assistance also covers relevant security duties, incident response, impact assessments and regulator consultation, taking account of the processing and information available. Agreed charges cannot prevent legally required assistance.
Transfers and audits
Restricted international transfers require an applicable legal mechanism and any required assessment. Where needed, the parties must execute the relevant Standard Contractual Clauses, UK Addendum or other transfer instrument with accurate schedules.
Oyamu will provide information and permit audits required by the agreement and law, with appropriate protection for other customers and confidential security information. Scheduling and confidentiality arrangements cannot obstruct a regulator or urgent investigation.
Return, deletion and survival
At the end of covered processing, Oyamu will return or delete information on the organization’s instructions and according to the agreement, unless law requires retention. The schedule governs export, deletion, backup expiry and legal holds.
Information lawfully retained remains protected and limited to its retention purpose. Confidentiality, cooperation and other obligations survive as needed to meet the agreement and applicable law.
Contact Oyamu
Oyamu is operated by Oyamu LLC. For questions about this policy or your account, email support@oyamu.com. Include only what we need to understand your request. Do not send passwords, authentication codes or full payment-card details.