Data Processing Agreement (DPA)
Effective Date: December 12, 2025
This Data Processing Agreement forms part of our Terms of Service and applies whenever Galactic Matrix - Unipessoal Lda processes personal data on behalf of an educational institution. It is drafted to meet the requirements of Article 28 of the General Data Protection Regulation (GDPR).
1. Scope and Applicability
This Data Processing Agreement ("DPA") applies to the processing of student and user personal data by Galactic Matrix - Unipessoal Lda (the "Processor") on behalf of educational institutions and educators (the "Customer") when using the ZunoTales platform.
2. Roles and Responsibilities
The Customer acts as the Data Controller, and Galactic Matrix - Unipessoal Lda acts as the Data Processor. The Customer is responsible for obtaining any necessary parental consent as required by applicable laws (e.g., COPPA, FERPA, GDPR).
3. Subject matter, duration, nature and purpose
The subject matter of the processing is the provision of the ZunoTales story-based learning platform. The nature and purpose of the processing are to create, store, narrate, translate and display personalised stories and learning activities for students, and to provide teaching and account-administration tools to the Customer. Processing continues for the duration of the Customer's subscription and ends as described in section 14.
3. Data Categories
Data processed under this agreement includes:
- Students' first names, ages or year groups, and profile preferences such as interests and reading level.
- Teacher/Educator names and contact details.
- User-generated story content and prompts.
- Classroom usage and performance analytics.
- Optional student photographs, where the Customer chooses to enable and upload them for illustration purposes.
The Services are not intended for the processing of special categories of personal data under Article 9 GDPR. The Customer must not instruct or permit such data, or national student identifiers, home addresses or health records, to be entered into the Services.
5. Processing on documented instructions
The Processor shall process personal data only on the Customer's documented instructions, including with regard to international transfers, unless required otherwise by applicable law; in that case the Processor shall inform the Customer of that legal requirement before processing, unless the law prohibits it. This DPA, the Terms of Service, and the Customer's use and configuration of the Services constitute the Customer's complete documented instructions. The Processor shall inform the Customer immediately if, in its opinion, an instruction infringes applicable data protection law.
6. Confidentiality of personnel
The Processor ensures that all personnel authorised to process personal data are bound by an appropriate duty of confidentiality, receive data protection training proportionate to their role, and are granted access only on a documented least-privilege basis.
4. Security Measures
Galactic Matrix - Unipessoal Lda implements industry-standard technical and organizational measures to protect data, including encryption at rest and in transit, secure access controls, least-privilege administrative access, and review of these measures whenever our systems or processing activities change materially.
8. No use of Customer data for AI training
The Processor does not train artificial intelligence models. The Processor uses third-party foundation models to generate story text, illustrations and narration, and contractually requires that student personal data and Customer content sent to those models are not used to train or improve them. Customer data is not used to develop, benchmark or improve any model, and is not disclosed to any AI provider for that purpose.
5. Sub-processors
The Processor utilizes trusted sub-processors to provide essential services, including Google Cloud (Firebase) for data storage and Google AI for generation. All sub-processors are bound by confidentiality and data protection obligations consistent with this DPA.
- Google Cloud Platform / Firebase — application hosting, database, authentication and file storage.
- Google Cloud AI (Gemini and Cloud Text-to-Speech) — story text and illustration generation, and audio narration.
- Stripe — payment processing for card subscriptions. Stripe receives no student data.
- Resend — transactional email delivery such as invitations and account notices. Resend receives no student data.
The Processor shall give the Customer at least 30 days' notice before adding or replacing a sub-processor that processes student personal data. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees.
10. International data transfers
Personal data is stored on infrastructure operated by Google Cloud. Where personal data is transferred outside the European Economic Area or the United Kingdom, the Processor ensures an appropriate transfer mechanism under Chapter V GDPR is in place — namely an adequacy decision where one applies, or otherwise the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK transfers), together with supplementary technical measures including encryption in transit and at rest. Details of the transfer mechanisms used are available on request from the Data Protection Officer.
11. Assistance with data subject rights
Taking into account the nature of the processing, the Processor shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights under Chapter III GDPR. Most requests can be satisfied by the Customer directly: educators and account owners can access, correct, export and delete student profiles and their associated stories from the dashboard. If the Processor receives a request directly from a data subject relating to Customer data, it will not respond substantively and will refer the request to the Customer without undue delay.
12. Data protection impact assessments
The Processor shall provide reasonable assistance to the Customer with data protection impact assessments and any prior consultation with a supervisory authority under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to the Processor.
6. Data Breach Notification
In the event of a confirmed security breach leading to the accidental or unlawful destruction, loss, or unauthorized disclosure of personal data, Galactic Matrix - Unipessoal Lda will notify the Customer without undue delay.
14. Return and deletion of data
On termination or expiry of the Services, the Customer may export its data from the dashboard. At the Customer's choice, the Processor shall delete or return all personal data processed on the Customer's behalf and delete existing copies, unless applicable law requires continued storage. Unless the Customer requests otherwise, data associated with a closed institution account is deleted within 90 days of termination. Deleting a student profile deletes that student's stories and associated data. Backups are purged on our ordinary backup rotation.
15. Retention
Personal data is retained while the Customer's account is active and thereafter as described in section 14. Transcripts of AI-guided conversations are deleted automatically after 12 months, and immediately if the relevant student profile or the account is deleted.
16. Audits and information
The Processor shall make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits shall take place on reasonable prior written notice, no more than once in any twelve-month period except following a personal data breach or where required by a supervisory authority, during business hours, subject to confidentiality obligations, and in a manner that does not disrupt the Processor's operations or the security of other customers' data. The Processor may satisfy an audit request by providing its security documentation and responding to a reasonable security questionnaire.
17. FERPA — school official designation
For Customers subject to the US Family Educational Rights and Privacy Act (FERPA), the Processor acts as a “school official” with a “legitimate educational interest” in student education records, under the direct control of the Customer with respect to their use and maintenance. The Processor uses education records only to provide the Services to the Customer, does not re-disclose them except as permitted by FERPA or instructed by the Customer, and does not use them for advertising or to build non-educational profiles of students.
18. Liability and order of precedence
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of Customer personal data. Where the Customer has entered into a separate written data processing agreement with Galactic Matrix - Unipessoal Lda, that agreement prevails. Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, except where those limitations cannot lawfully apply.
7. Contact Information
For inquiries regarding data processing, please contact our Data Protection Officer at dpo@zunotales.com.
20. Language
This DPA may be made available in languages other than English for your convenience. If there is any conflict between the English version and a translation, the English version prevails.
ZunoTales is operated by Galactic Matrix - Unipessoal Lda, NIPC 519268814, registered office: Rua Conde Moser, n.º 188, 2.º direito, 2765-428 Cascais, Portugal. Contact: contact@zunotales.com.