Skip to content

Data Processing Addendum (DPA)

Effective Date: July 23, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between the Customer (“Controller”) and Complete Content Management Services, Inc. (“CCMS,” “TUITIONsimple,” “Processor,” “we,” or “us”) for use of the TUITIONsimple platform (the “Service”). It describes how we process personal data on the Customer’s behalf. Where this DPA conflicts with the agreement on the subject of data processing, this DPA controls. Capitalized terms not defined here have the meaning given in our Privacy Policy and Terms of Service.

1. Definitions

“Customer Data” means personal data that the Customer or its authorized users enter into or generate through the Service. “Data Subject,” “Controller,” “Processor,” “Processing,” and “Personal Data Breach” have the meanings given under applicable data protection law.

2. Roles of the Parties

As between the parties, the Customer is the Controller and TUITIONsimple is the Processor with respect to Customer Data. Each party will comply with its obligations under applicable data protection law. The Customer is responsible for the accuracy, quality, and legality of Customer Data and for having a lawful basis and any necessary consents to provide it (including student and parent information).

3. Scope and Instructions

We process Customer Data only to provide and support the Service and only on the Customer’s documented instructions, including as set out in the agreement, this DPA, and the Customer’s configuration and use of the Service, unless required to act otherwise by applicable law (in which case we will inform the Customer where legally permitted).

4. Nature and Purpose of Processing

The subject matter is the provision of tutoring management software. Processing is carried out for the duration of the agreement. The purpose is scheduling, billing, session management, and related functions. The types of Customer Data may include names and contact details of administrators, tutors, parents, and students; tutoring session schedules and attendance; tutor assignments and rates; and billing and payment records. Data Subjects may include the Customer’s staff, tutors, parents, and students.

5. Confidentiality

We ensure that personnel authorized to process Customer Data are bound by appropriate obligations of confidentiality and process Customer Data only as instructed.

6. Security Measures

We implement appropriate technical and organizational measures designed to protect Customer Data, including selective field-level encryption for designated sensitive data, encryption of stored credentials and OAuth tokens, access controls, logging and monitoring, daily backups, and managed infrastructure security controls appropriate to the nature of the processing.

7. Subprocessors

The Customer authorizes us to engage subprocessors to support the Service. We engage subprocessors under written contracts requiring data protection obligations no less protective than those in this DPA, and we remain responsible for their performance. Current categories of subprocessors include cloud hosting infrastructure, email delivery, and analytics providers. Where a tutor connects a Google Calendar, Google acts as a provider of the calendar API used to deliver that optional feature, as described in our Privacy Policy. A current list of subprocessors is available on request, and we will provide a mechanism to notify the Customer of intended changes so the Customer may object.

8. Google User Data

To the extent processing involves data accessed through Google APIs when a tutor connects a Google Calendar, that data is used solely to create, update, cancel, and sync the tutor’s tutoring-session events, in accordance with the Google API Services User Data Policy, including its Limited Use requirements. See Sections 4 and 5 of our Privacy Policy for details.

9. International Transfers

We operate the Service and process Customer Data in the United States. Where Customer Data is transferred across borders, we will implement an appropriate transfer mechanism to the extent required by applicable law.

10. Assistance to the Controller

Taking into account the nature of the processing, we will provide reasonable assistance to the Customer, by appropriate technical and organizational measures and insofar as possible, in responding to Data Subject requests and in meeting the Customer’s obligations relating to security, breach notification, and data protection impact assessments.

11. Data Subject Requests

If we receive a request from a Data Subject relating to Customer Data, we will, where legally permitted, direct the Data Subject to the Customer and assist the Customer in responding as required.

12. Personal Data Breach Notification

We will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data and will provide information reasonably available to us to help the Customer meet its notification obligations.

13. Return and Deletion

Upon termination of the Service, we will delete or return Customer Data in accordance with the agreement, and delete existing copies except where retention is required by applicable law. OAuth tokens and event identifiers for a connected Google Calendar are deleted when the tutor disconnects the integration, the tutor’s account is removed, or the Customer’s account is closed.

14. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, subject to reasonable confidentiality and security requirements and the terms of the agreement.

15. Contact

Complete Content Management Services, Inc.
3641 SW 21st CT, Fort Lauderdale, FL 33312
Privacy: privacy@ccmssolutions.com
Support: support@ccmssolutions.com