This Addendum forms part of the Terms of Service between Isabek Mamatkulov, Bishkek, Kyrgyz Republic ("Processor", "we") and the consulting company using Taalim ("Controller", "you"). It describes how we process personal data about students on your behalf.
You can give this document to your own clients when they ask how student information is handled.
1. Roles
You are the controller of Student Data. You decide which students are entered into the Service, what information is collected about them, which documents are uploaded, and for what purpose.
We are the processor. We process Student Data only to provide the Service to you.
Where we process information about you and your staff for our own purposes, such as billing and account administration, we act as a controller and our Privacy Policy applies.
2. Scope and duration
This Addendum applies for as long as we process Student Data for you, which is the term of the Terms of Service plus the 30-day export window described in section 12 of those Terms.
The subject matter, nature, purpose, data categories, and data subject categories are set out in Annex I.
3. Our obligations
a. Documented instructions. We process Student Data only on your documented instructions. Your use of the Service, and this Addendum, are your instructions. If we believe an instruction breaches applicable data protection law, we will tell you. If we are required by law to process Student Data otherwise, we will inform you first unless the law forbids it.
b. Confidentiality. Every person we authorise to process Student Data is bound by confidentiality. At present that is a single operator.
c. Security. We implement the technical and organisational measures set out in Annex II and will not materially weaken them during the term.
d. Subprocessors. You give general authorisation for the subprocessors listed in Annex III. We remain responsible for their performance. We will give you at least 30 days' notice before adding or replacing a subprocessor. If you object on reasonable data protection grounds within that period, we will work with you to find a solution, and if we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.
e. Assisting with data subject requests. If a student contacts us directly, we will not respond to the substance of the request. We will refer them to you and tell you promptly. The Service gives you the tools to view, correct, export, and delete student records yourself. Where you need more, we will provide reasonable assistance.
f. Assisting with your obligations. Taking into account the nature of processing, we will give you reasonable assistance with security obligations, breach notification, data protection impact assessments, and consultations with supervisory authorities.
g. Personal data breach. If we become aware of a personal data breach affecting Student Data, we will notify you without undue delay and in any event within 72 hours of becoming aware of it. The notification will describe what happened, the categories and approximate volume of data and students affected, the likely consequences, and the steps taken or proposed. We will keep you updated as we learn more. You are responsible for notifying supervisory authorities and affected students where the law requires it.
h. Deletion and return. On termination, you have 30 days to export Student Data from the Service. At the end of that period we delete it from live systems, and from backups within a further 30 days as backups cycle. We may keep records we are required to keep by law, and records of acceptance of the Terms.
i. Records and audit. We maintain records of the processing carried out on your behalf. On reasonable written request, no more than once in any 12 months, we will provide the information reasonably necessary to demonstrate compliance with this Addendum. If documentation is genuinely insufficient, an on-site audit may be arranged with at least 30 days' notice, during business hours, without disrupting the Service, subject to confidentiality, and at your cost.
4. International transfers
Student Data is processed outside the Kyrgyz Republic by the subprocessors in Annex III, including in the United States and the European Union. Where required by applicable law, transfers are made under an appropriate transfer mechanism, and we will enter into standard contractual clauses on request.
5. Liability
Liability under this Addendum is subject to the limitations in section 14 of the Terms of Service.
6. Order of precedence
If this Addendum conflicts with the Terms of Service in relation to the processing of Student Data, this Addendum prevails.
Annex I. Details of the processing
Subject matter. Provision of the Taalim platform for managing university applications, tutoring, and scholarship search.
Duration. The term of the Terms of Service, plus the export and deletion periods in section 3(h).
Nature and purpose. Storage, organisation, retrieval, display, and transmission of student information so that the Controller can advise students on university applications; generation of AI-assisted university matches, essay feedback, and tutoring; sending notifications; and secure storage of application documents.
Categories of data subjects.
- Students, including minors under the age of 18. This is the primary category and is the reason this Addendum exists.
- Consultants and administrators employed by the Controller.
Categories of personal data.
- Identity and contact data: name, date of birth, email address, phone number, country and city.
- Education data: school, graduation year, grades, standardised test scores, language test results, target countries and programs, application status and history.
- Free-text content: personal statements and essays, tutoring conversations, practice answers, and consultant notes.
- Identity documents: passports and national identity documents, and passport photographs.
- Financial documents: bank statements, sponsorship letters, and affidavits of support.
- Technical data: IP address, browser user agent, session identifiers, document download records.
Sensitivity note. Identity documents and financial documents are not always classified as "special category" data, but in practice they carry the highest risk of harm to a student if disclosed. We treat them as the most sensitive material in the system, and Annex II describes the additional handling they receive.
Frequency. Continuous for the duration of the agreement.
Annex II. Technical and organisational measures
Only measures actually in place are listed.
Access control and tenant isolation
- Row-level security at the database level isolates each company's workspace.
- Application routes verify the caller's relationship to a student record before returning or accepting any data.
- Privileged database credentials are used only inside server-side routes and are never exposed to a browser.
Document handling
- Uploaded files are held in a private storage bucket with no public access and no direct client access. There are no storage-level policies permitting client reads; the application's authenticated routes are the only path to a file.
- Download links are generated per request, expire after 60 seconds, and force the file to be saved rather than rendered, which defuses scripted-content tricks in PDF and HTML-masquerading files.
- Uploads are validated by inspecting the file's actual byte signature rather than trusting its declared name or extension. Only PDF, JPEG, PNG, WebP, and DOCX are accepted.
- File names are sanitised and stored under randomly generated paths.
- Per-student quotas cap file size at 15MB and total storage at 250MB across a maximum of 50 files.
Data minimisation and retention
- Documents are classified by category, and the categories covering identity documents, financial documents, and photographs are treated as high-sensitivity.
- High-sensitivity documents carry a 180-day retention clock and are then permanently deleted by an automated purge, leaving only a record that a document of that category existed and was purged.
- Uploading a high-sensitivity document requires the uploader to confirm, per file, that the specific application requires it and that the necessary consent exists. That confirmation is recorded against the file with the identity of the person who made it.
- Where a file's name indicates identity or financial content, the same confirmation is required regardless of the category chosen, so that mislabelling does not bypass the control.
Logging and accountability
- Every document download is recorded with the document, the student, the acting user, their role, their IP address, and the time.
- Acceptance of the Terms and Privacy Policy is recorded per user with the document version, timestamp, and IP address.
Transmission and storage security
- All traffic is served over TLS.
- Data is encrypted at rest by the hosting and storage provider.
Known limitations, disclosed deliberately
- No antivirus or malware scanning is performed on uploads.
- Documents are not encrypted with an application-level key separate from the storage provider, so a compromise of the storage provider account would expose file contents.
- No security certification, SOC 2 audit, or third-party penetration test has been carried out.
- The Service is operated by one person, so there is no separation of duties.
We disclose these so you can make an informed decision rather than discover them later.
Annex III. Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | United States / European Union |
| Anthropic | AI tutoring, essay feedback, matching | United States |
| AI tutoring and matching (Gemini) | United States | |
| Resend | Transactional email | United States |
| Sentry | Error monitoring | United States |
| Telegram | Optional notification bot | International |
| Railway | Application hosting | United States |
Uploaded document contents are sent to no subprocessor other than Supabase, which stores them.
Questions about this Addendum: privacy@taalimapp.com