Data Processing Addendum
Last updated July 2026
This summary explains how Bublio processes personal data on behalf of a school. It supplements our Terms and Privacy Policy. Schools that require a signed DPA can request one from us.
Roles
The school is the controller of student personal data. Bublio is the processor and processes that data only to provide the service and on the school's documented instructions.
Scope of processing
- Categories of data: student names, class names, optional student ID numbers, exam answers/scores, and images of completed answer sheets.
- Data subjects: the school's students (and its teacher/admin users).
- Purpose: generating sheets, reading scans, grading, and reporting results.
- Duration: for as long as the school's account is active; deleted on account deletion.
Sub-processors
Bublio uses a limited set of sub-processors to run the service: our hosting provider (application & database), PayPal (payments), Resend (transactional email), and Anthropic (only when the optional AI reader/import is used). We'll give notice of material changes to this list.
Security & confidentiality
Data is encrypted in transit, passwords are hashed, and access is scoped to each school. Personnel with access are bound by confidentiality. We assist the school with data-subject requests and notify it without undue delay if we become aware of a personal-data breach affecting its data.
Data subject requests, export & deletion
School admins can access, correct, export, and delete data directly in the app. On request or on account deletion, Bublio deletes the school's data (including student information and scanned images).
International transfers
Where data is processed outside the school's country, Bublio and its sub-processors apply appropriate safeguards.
Contact
To request a signed DPA or ask about data processing, email sales@bublio.app.