Legal
Data Processing Agreement.
Our standard DPA for educational institutions, published so your privacy office can review it before procurement. Executed per institution on institution plans.
Last updated: 4 August 2026 · Version: DPA-2026-08-04-R1
- 01
Purpose and scope
This Data Processing Agreement (DPA) is between Difinity Pty Ltd (ABN 82 686 692 759), the operator of Loam (Loam, we, us), and the educational institution named in the applicable order form or subscription agreement (the Institution). It forms part of the agreement between Loam and the Institution for the Loam service (the Agreement): our Terms of Service or a signed subscription agreement. If this DPA conflicts with the Agreement on the handling of personal information, this DPA prevails.
1.1. This DPA governs how Loam handles Personal Information that we hold or process on the Institution's behalf in providing the Loam service (Institution Personal Information), including Student Data.
1.2. This DPA applies for the term of the Agreement and until Loam no longer holds any Institution Personal Information.
- 02
Definitions
- Data Breach means unauthorised access to, unauthorised disclosure of, or loss of Institution Personal Information held by Loam.
- Personal Information has the meaning given in the Privacy Act 1988 (Cth).
- Privacy Laws means the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and any State or Territory privacy law that applies to the Institution, including, for NSW public schools, the Privacy and Personal Information Protection Act 1998 (NSW) and the Health Records and Information Privacy Act 2002 (NSW).
- Processing means any operation performed on Institution Personal Information, including collection, storage, use, disclosure, and deletion.
- Student Data means Institution Personal Information about students, including student work and evidence records.
- Subprocessor means a third party engaged by Loam that Processes Institution Personal Information.
- 03
Roles and instructions
3.1. As between the parties, the Institution controls the purposes for which Institution Personal Information is Processed. Loam Processes it as a service provider, only: (a) to provide, secure and support the service as described in the Agreement; (b) as configured by the Institution in the product; and (c) on the Institution's other documented instructions, unless required otherwise by law (in which case Loam will notify the Institution before Processing, where legally permitted).
3.2. Loam will notify the Institution if, in its opinion, an instruction would breach Privacy Laws, and may suspend the affected Processing until instructions are clarified.
3.3. Loam will not: sell Institution Personal Information; use it for advertising; use student work or evidence records to train artificial-intelligence or machine-learning models; or Process it for any purpose of its own beyond aggregated, de-identified usage statistics that identify no individual, institution or document content. In particular, Loam will not use keystroke-timing or cadence data to identify or verify the identity of any individual.
- 04
Details of Processing
The subject matter, duration, nature, purposes, categories of individuals and categories of Personal Information are set out in Schedule 1.
- 05
Personnel
Loam ensures that personnel authorised to Process Institution Personal Information: (a) are bound by confidentiality obligations; and (b) receive privacy and security training. Production access is logged. Loam has scheduled further work to narrow deploy and operational access.
- 06
Security
6.1. Loam will maintain appropriate technical and organisational measures to protect Institution Personal Information against misuse, interference, loss, and unauthorised access, modification or disclosure, including no less than the measures in Schedule 2, and will not materially degrade them during the term.
6.2. Loam will, on request, provide the Institution with security documentation reasonably sufficient to assess those measures.
- 07
Subprocessors
7.1. The Institution authorises the Subprocessors listed in Schedule 3 (also published on our subprocessors page).
7.2. Loam will give the Institution at least 30 days' written notice before adding or replacing a Subprocessor. If the Institution reasonably objects on privacy grounds, the parties will work in good faith to resolve the objection; if it cannot be resolved, the Institution may terminate the affected services and receive a pro-rata refund of prepaid fees.
7.3. Loam imposes data-protection obligations on each Subprocessor that are no less protective than this DPA, and remains responsible to the Institution for each Subprocessor's performance.
7.4. PostHog is used for consented analytics and masked replay on Loam's public marketing website only and is not used to Process Institution Personal Information. It is therefore listed transparently on our subprocessors page but is not an Institution-authorised Subprocessor under this DPA. A separate request the Service makes to load its own feature settings contains one fixed identifier and no Institution Personal Information.
7.5. Where the Institution or its Authorised Users choose to sign in using Google or Microsoft as an identity provider (including the Institution's own Google Workspace or Microsoft Entra tenant), that provider authenticates the person and returns identity information (provider name and issuer, immutable account identifier, provider-supplied name and email, email-verified flag, directory/organisation identifier, and sign-in timestamps) to Loam; it does not receive Student Data or other Institution Personal Information about writing, evidence records, classes or submissions. Loam lists Google and Microsoft transparently on our subprocessors page. They are not included in Schedule 3. The Institution or Authorised User initiates the sign-in, the exchange may use the provider's global infrastructure, and the identity information returned to Loam is stored in the selected region under clause 8.1.
- 08
Data location and overseas disclosure
8.1. Loam hosts each Institution's Personal Information, including backups, with Amazon Web Services in the data centre for the region the Institution selects: AWS Asia-Pacific (Sydney) for Australia, AWS Europe (Frankfurt) for Europe, or AWS US East (N. Virginia) for the United States. The Institution's stored records, including backups, remain in the selected region.
8.2. Except as stated in clause 8.3, Loam will not store the Institution's Personal Information outside the selected region without the Institution's prior written consent, except where required by law (in which case Loam will notify the Institution where legally permitted). Difinity's operations personnel are in Australia. In the Australian operations system they can see only opaque Loam identifiers for the student, teacher, school and support request, together with the name, work email address and support messages of a teacher or school administrator who contacts us. They cannot see or receive a student's name, email address, date of birth, writing, replay, evidence record or other directly identifying student details or student content. Student content and direct student identifiers remain in the institution's selected region. For the Europe region, this access is an international transfer to Australia. This DPA does not itself incorporate the EU Standard Contractual Clauses or the UK International Data Transfer Addendum. If either instrument is required for the Institution's use, the parties must execute it separately in writing. The access control sharply limits the information available in Australia, but it does not by itself end the EU or UK transfer analysis. An opaque identifier can remain personal data if Difinity can link it back to a person, and teacher or school-administrator support information remains personal data. We therefore treat the Australian operations path as requiring a documented transfer assessment unless qualified counsel concludes otherwise.
8.3. Billing exception. To provide subscription billing on institution plans, Loam discloses the Institution's billing contact details (name, work email, billing address) and payment-transaction data to Stripe (Schedule 3), which processes them in the United States and on its global infrastructure. Student Data is never disclosed to Stripe. By executing this DPA the Institution authorises this disclosure for billing purposes only; Loam takes the steps required under APP 8.1 for this disclosure and remains accountable for Stripe's handling of it.
8.4. Comprehension-check inference. Where the Institution's administrator switches on the optional AI comprehension check, an excerpt of a student's own in-progress draft (the last ~600 words), carrying no student name, email or other identifier, is Processed by AWS Bedrock (Schedule 3) within the geography of the region selected under clause 8.1, and is not stored outside that region. For the Australia region that geography is Australia; for the United States region, the United States; and for the Germany region, the European Union, which may include EU member states other than Germany. By executing this DPA the Institution authorises this Processing for the comprehension-check purpose only, and only while the Institution has the feature switched on; the Institution may withdraw that authorisation at any time by switching the feature off. Clause 8.2 is not engaged, because no Institution Personal Information is stored outside the selected region.
- 09
Assistance to the Institution
9.1. Loam will provide reasonable assistance so the Institution can meet its obligations under Privacy Laws, including: (a) responding within 10 business days to Institution requests concerning access to, correction of, or deletion of Institution Personal Information; (b) providing export tools for student work and evidence records; and (c) reasonable cooperation with the Institution's privacy impact assessments and security reviews.
9.2. If an individual contacts Loam directly about Institution Personal Information, Loam will refer them to the Institution and notify the Institution, unless Privacy Laws require Loam to respond directly.
9.3. The Institution remains responsible for the lawfulness of its own collection and use of Institution Personal Information, including any notices to, and consents from, students, parents and guardians that its policies or Privacy Laws require.
- 10
Data Breach
10.1. Loam will notify the Institution without undue delay, and in any event within 72 hours, after becoming aware of a Data Breach. The notice will describe, to the extent known: the nature of the breach; the categories and approximate volumes of information and individuals affected; the likely consequences; and the measures taken or proposed.
10.2. Loam will investigate, take reasonable steps to mitigate and remediate, and keep the Institution informed.
10.3. Loam will not notify affected individuals or regulators about a Data Breach affecting Institution Personal Information without the Institution's prior agreement, unless the Privacy Act 1988 (Cth) or another law requires Loam to do so, and where it does, Loam will coordinate the content and timing of notifications with the Institution so far as lawfully possible.
- 11
Audit
11.1. Loam will, on request (no more than once per 12 months), complete the Institution's reasonable security questionnaire and provide current security documentation.
11.2. The Institution may audit Loam's compliance with this DPA on at least 30 days' written notice, no more than once per 12 months, during business hours, at the Institution's cost, subject to Loam's confidentiality and security requirements. Audits must not access another institution's data.
- 12
Return and deletion
12.1. The Institution may export student work and evidence records at any time during the Agreement, and for 30 days after its termination or expiry.
12.2. After that export window, Loam will delete Institution Personal Information from live systems within 90 days. The Institution's Personal Information may remain in encrypted, whole-database backup copies until those age out on Loam's rolling backup schedule. In all regions, nightly backups are retained for 30 days and monthly backups are retained for 1 year, unless the law requires longer retention. On request, Loam will confirm deletion in writing.
- 13
Liability
Each party's liability under or in connection with this DPA is subject to the exclusions, limitations and caps in the Agreement, which apply in aggregate across the Agreement and this DPA together.
- 14
Term
This DPA starts when the Agreement starts (or when signed, if later) and continues until Loam no longer holds Institution Personal Information.
- 15
General
15.1. This DPA is governed by the laws of New South Wales, Australia.
15.2. Any variation must be in writing and signed by both parties. If any provision is unenforceable, it is severed and the rest remains in force.
To execute this DPA for your institution, email hello@loam.ink and we will send a signature copy.
- S1
Schedule 1: Details of Processing
- Subject matter: provision of the Loam proof-of-process writing service.
- Duration: the term of the Agreement, plus the export and deletion periods in clause 12.
- Nature and purposes: hosting and operating the sealed editor; recording, countersigning, verifying and replaying evidence chains; class, assignment and submission management; authentication; support; security and abuse prevention; invoicing the Institution.
- Categories of individuals: students; teachers and school administrators; the Institution's staff contacts.
- Categories of Personal Information: name, school email address, role, class membership; student work (text, titles, embedded images, links and attached files) and its evidence records (timestamped edit deltas, hash links, server countersignatures, editor events and session signals such as word/keystroke counts, blocked-paste events and basic device characteristics: screen size, timezone, processor count, automation-environment reports); technical logs (IP address, user agent, timestamps); staff business contact and billing details.
- Sensitive information: none is sought or required by the service. Students should not be directed to include sensitive information in assignments.
- Retention: on institution plans, student work and evidence records are retained as the Institution directs, with a default retention period of 7 years from submission, configurable by the Institution to its records policy, applicable while the Agreement is on foot; the export and deletion periods in clause 12 apply on termination or expiry.
The measurable periods for account, identity, session, log, correspondence, billing and backup records are stated in section 11 of the Privacy Policy. On termination, clause 12 of this DPA and the Institution's order form control where they require earlier return or deletion. A legal hold may delay deletion only for the records and period the law requires.
- S2
Schedule 2: Security measures
- End-to-end TLS for data in transit across all regions, and encryption at rest, including backups.
- Tamper-evident evidence storage: SHA-256 hash-chained records with server (HMAC) countersignatures, so alteration is detectable, including by Loam.
- Passwords stored only as salted argon2 hashes; secure, httpOnly session cookies.
- Per-institution workspace isolation with tenant-scoped access controls.
- Production access is logged. Further work to narrow deploy and operational access is scheduled.
- Encrypted nightly backups retained for 30 days and encrypted monthly backups retained for 1 year in each region.
- Documented data-breach response plan.
- Personnel confidentiality obligations and security training.
- S3
Schedule 3: Approved Subprocessors
- Amazon Web Services (AWS): cloud hosting, storage and encrypted backups. Data processed: all service data, including Student Data. The Institution's selected region (Sydney, Frankfurt or N. Virginia).
- Amazon SES (AWS): transactional email: invitations, password resets, notifications. Data processed: names and email addresses of message recipients. The Institution's selected region (Sydney, Frankfurt or N. Virginia).
- AWS Bedrock (AWS): AI comprehension-check processing of submitted student text, an opt-in feature the Institution's administrator switches on. Data processed: excerpt of a student's own in-progress draft (the last ~600 words), and no more; no Student identifiers. The geography of the institution's selected region: within Australia for the Australia region; within the United States for the United States region; and within the European Union, which may include EU member states other than Germany, for the Germany region.
- Stripe (Stripe, Inc. and its affiliates): subscription billing for institution plans: payments, invoices and the billing portal (see clause 8.3). Data processed: Institution billing contacts and payment-transaction data only; never Student Data. United States and Stripe's global infrastructure; Stripe's Data Processing Agreement applies (stripe.com/legal/dpa).
AWS Bedrock is engaged only for the opt-in comprehension-check feature. It is off by default; the Institution's administrator must switch it on. When on, an excerpt of a student's own in-progress draft (the last ~600 words) is sent to an AWS Bedrock foundation model processing in the same geography as the region selected under clause 8.1 (see clause 8.4), with a fixed instruction and no student name, email or other identifier. This Bedrock processing never leaves that geography: for the Australia region it takes place within Australia; for the United States region, within the United States; and for the Germany region, within the European Union, which may include EU member states other than Germany. This is inference, not training, and does not affect Loam's undertaking in clause 3.3 never to use Student Data to train an artificial-intelligence or machine-learning model.
The current list, and our commitment to at least 30 days' advance written notice before we add or replace a Subprocessor or change the country or geography in which a Subprocessor Processes Institution Personal Information, is maintained on our subprocessors page.
Difinity personnel. Difinity personnel are part of Difinity, not a third-party Subprocessor. They are bound by confidentiality and role-based access controls. Australian operations personnel have only the limited access described in clause 8 (Data location and overseas disclosure) above.