memore

Legal · memore.tech

Data Processing Agreement

Last updated: 19 August 2026

This Data Processing Agreement (the "DPA") governs our processing of personal data that you put into Memore about other people — most often your students. It forms part of the Terms of Service between you and Shoon's LLC ("Memore", "we", "us"), and applies automatically when you use the Services. No signature is required; if your organisation needs a countersigned copy, write to legal@memore.tech.

In one sentence: for the data you record about your students, you decide why and how it is used and we act only on your instructions. This DPA is the Article 28 contract that makes that lawful.

1Which data this covers, and who is responsible

Memore handles two different kinds of personal data, and our role differs between them. This distinction is the point of this document.

DataYour roleOur role
Customer Data — what you record about your students and their households: names, contact details, lesson history, attendance, private notes, materials, recordings, transcripts, vocabulary, payment and balance records.ControllerProcessor, acting on your instructions under this DPA
Your account data — your own name, email, password, timezone, settings, billing, support correspondence, and how you use the product.Data subjectController, under the Privacy Policy

Where the other party to a relationship also holds their own Memore account, they are a data subject in their own right and we are the controller of their account data, exactly as we are of yours. Data you have both contributed to a shared record — a shared glossary, a lesson both of you can read — remains available to each of you if the other leaves.

"Data Protection Law" means the EU GDPR, the UK GDPR and the Data Protection Act 2018, the Swiss FADP, and any other data protection law applicable to the processing, each as amended.

2Details of the processing

Required by Article 28(3):

ItemDetail
Subject matterProvision of the Memore platform to you.
DurationFor as long as your account is active, plus the retention periods in section 9.
Nature and purposeHosting, storage, organisation, retrieval, transmission, backup, transcription, and AI-assisted generation of teaching material, in each case to deliver the features you use.
Types of personal dataIdentification and contact data; scheduling and attendance data; free-text notes authored by you; educational performance and progress data; audio, video and image recordings and their transcripts; financial records of lessons and payments; and any other personal data you choose to enter.
Categories of data subjectsYour students; where applicable their parents or guardians; and other people you enter into the product.
Special category dataNot required by the product and not to be entered. See section 3.

3Your obligations as controller

You are responsible for the lawfulness of what you ask us to process. In particular you must:

4Our obligations as processor

We will:

5Security

We implement appropriate technical and organisational measures under Article 32, described in the Annex below, and keep them under review. We do not reduce the overall level of security during the term of this DPA.

6Sub-processors

You give general authorisation for us to engage sub-processors to deliver the Services. The current list, with what each does and where it processes, is published in section 10 of the Privacy Policy and is part of this DPA.

We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

We will publish any material new or replacement sub-processor at least 30 days before it begins processing Customer Data. The published list is the authoritative notice of sub-processor changes. Where a replacement is needed urgently to keep the Services secure or available, we may engage it immediately and will publish the change as soon as reasonably practicable. If you reasonably object on data protection grounds within 30 days of publication, tell us and we will work with you on a reasonable alternative; if none is available, you may terminate the affected Services without penalty and receive a pro-rata refund of any prepaid fees.

7Assisting you

Taking into account the nature of the processing and the information available to us, we will assist you with:

8Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide the information available to us so you can meet your own Article 33 and 34 obligations. Notification is not an admission of fault. Reporting to a supervisory authority and to affected individuals is your decision as controller.

9Deletion and return

You may export Customer Data at any time while your account is active. On termination we delete Customer Data in accordance with the retention schedule in the Privacy Policy, save where Data Protection Law requires us to keep it. Deleted data is removed from backups on their normal rotation.

10Audit

We will make available the information reasonably necessary to demonstrate compliance with this DPA, in the first instance through this document, the Privacy Policy, the sub-processor list and the security description. Where that is genuinely insufficient for your own compliance obligations, we will respond to a reasonable written information request no more than once a year, and will cooperate with an audit where Data Protection Law obliges us to. Audits must be at your cost, on 30 days' written notice, during business hours, subject to confidentiality, and must not disrupt the Services or risk another customer's data.

11International transfers

Shoon's LLC is established in the United States and our sub-processors operate in the European Union and the United States. Where Customer Data is transferred out of the EEA, the United Kingdom or Switzerland:

If a transfer mechanism is invalidated, we will adopt a valid alternative without undue delay.

12Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Law does not permit that. Nothing in this DPA limits a data subject's rights.

If this DPA conflicts with the Terms of Service, this DPA prevails for the processing of Customer Data. If this DPA conflicts with the Standard Contractual Clauses, the Clauses prevail.

13Annex — technical and organisational measures

Measures in place at the date above:

14Contact

Privacy and data protection: legal@memore.tech. Memore is operated by Shoon's LLC.

Terms of ServicePrivacy PolicyData Processing AgreementCookie PolicyCookie settingsHelp centreBlogFAQ© memore · 2026