Student Retainer — Data Processing Agreement
Effective date: 31 August 2026
Last updated: 3 September 2026
This agreement governs how we handle your students' personal information. It forms part of our Terms of Service and takes effect when you upload your exports.
It is written in plain English on purpose. It is still a binding contract, and every commitment in it is one we intend to keep rather than one we hope never gets tested.
1. The parties, and who is responsible for what
You — the course creator — are the controller of your students' personal information. You decide why it is collected and what happens to it. You are responsible for having a lawful basis to share it with us.
We — ABB Residential Limited (NZ company number 9297136), trading as Student Retainer — are your processor. We handle that information only to produce your report, only on your instructions, and for nothing else.
Under the New Zealand Privacy Act 2020 these roles are called "agency" and "agent". Under the GDPR they are "controller" and "processor". The substance is the same either way: it stays your data, and we act on your behalf.
2. What we process, and why
Purpose. To produce one Student Retention Scan report for you, and to discuss that report with you if you want to.
Duration. From the moment you upload until we delete the data under section 7.
Whose information. Students enrolled in your Thinkific courses.
What information. Described by category, because Thinkific changes its exports from time to time and a fixed list would go stale:
- Identity: first and last name, email address, Thinkific user ID, and the date the student's account was created.
- Enrolments: which courses, bundles and product types, enrolment and expiry dates, and counts of enrolments by kind — including communities, coaching and webinars, and digital downloads.
- Progress: percentage viewed and completed per course, individual lesson completions and their dates, time spent per lesson and per course, certificates earned and certificate expiry, and whether Thinkific counts the student as new or returning.
- Assessment results: quiz scores, counts of attempts started, completed and passed, and typical attempt duration.
- Activity: last sign-in date, and last activity date per course.
- Groups and custom fields: any group the student belongs to, and whatever custom fields you have defined on your own Thinkific site.
We receive more than we read. You send the complete Thinkific Analytics dashboard exports, because Thinkific offers no narrower version. Our analysis opens five of the files in them and uses a subset of the fields; section 3 of the Privacy Notice itemises which. Everything you send is held, protected and deleted under this agreement whether or not the analysis reads it.
What we never ask for. Payment details, physical addresses, or dates of birth.
3. Our commitments to you
We process only on your instructions. Your instructions are: the terms of service, this agreement, our privacy notice, and anything you tell us directly in writing. We will not process your students' data for any other purpose. If we ever believe an instruction from you would breach a privacy law, we will tell you and will not act on it until it is resolved.
We do not put your data into any AI system. Not your data, not your students'. The analysis is ordinary software following fixed rules, and the person who reviews your report reads it himself. Nothing you send us is used to train a model, ours or anyone else's. This is a contractual commitment, not a statement of current practice, and we will amend this agreement and tell you before it ever changes.
We never sell your students' data and never share it for any purpose other than producing your report. Your finished report is sent only to you.
Confidentiality, and exactly what "one person" means. Only one person handles your files, and nobody else has an account on the computer holding them. That person is bound by this agreement personally as well as through the company. We will not claim more than that: a file on a computer can be read by ordinary software running on that computer, so "one person" is a commitment about who we let near your data, not a technical barrier. Keeping your files away from any tool that would send them elsewhere is part of how we honour the AI commitment above.
We never contact your students. Under any circumstances, for any reason.
Security. As set out in Annex B. If we materially weaken any of those measures we will tell you.
4. Subprocessors
Your files and your report reach four places, and no others:
| Who | What they hold | Where |
|---|---|---|
| Tally BV | Your intake form and the two uploaded export files | European Union |
| ABB Residential Limited's own computer | A working copy of the exports, and your report while it is produced and for the 30 days after | New Zealand |
| Google LLC (Google Workspace) | The email delivering your report, which contains student names and email addresses | United States |
| Google LLC (Google Workspace), our Sent folder | Our own copy of that same email, for the same 30 days | United States |
What we can tell you about Tally, and what we cannot. Tally BV is a company under Belgian law with its registered office in Gent, and Tally states that its product is made and hosted in the European Union. We rely on Tally's own statement for the location; we have not independently verified where the files sit. Tally's data processing agreement is published at tally.so/help/data-processing-agreement. It discloses the categories of subprocessor Tally uses — hosting, payment and communication providers — and states that Tally is not required to disclose their individual identities. We therefore cannot name Tally's own subprocessors to you, because we do not know them either. If that is not acceptable for your students' data, do not upload.
Our website host, Cloudflare, receives none of your students' data and is not a subprocessor for it. The website is plain pages with no forms, no scripts and no cookies. Like any web host, Cloudflare does receive the ordinary request information a browser sends when someone views a page — IP address, browser, page and time — and it does not carry our email, which runs on Google Workspace.
If we want to add or change a subprocessor, we will tell you at least 30 days beforehand. You can object in writing during that period. If we cannot resolve your objection, you may end this agreement and we will delete your data. Because your export files are deleted within 14 days and your report within 30, that notice period will often be longer than the life of the data it concerns; it is written this way so the right exists for the cases where it matters.
We remain responsible to you for what our subprocessors do with your data.
5. Helping you meet your own obligations
Data subject requests. If one of your students asks to see, correct or delete their information, that request goes to you — you are their controller. Tell us and we will delete or correct our copies within two business days and confirm it in writing. If you need a copy of exactly what we hold about a particular student, ask and we will send it.
Breaches. If your students' data is ever exposed, lost or accessed without authority, we will tell you within 24 hours of becoming aware of it. We will tell you what happened, what data was involved, and what we are doing about it — not the minimum we can get away with. We will also notify the Office of the Privacy Commissioner where the Privacy Act requires it, and we will help you make any notification you have to make.
Demonstrating compliance. If you have questions about how we handle your data, ask them and we will answer in writing within 10 business days. We will provide the information you reasonably need to satisfy yourself, or your own auditor, that we are doing what this agreement says.
We do not offer a right to inspect our premises or systems. We are one person with a laptop, and a right of inspection is a promise we could not meaningfully honour. We would rather commit to answering honestly than to something that sounds impressive and means nothing.
6. Sending data across borders
Your exports go to Tally in the European Union, our working copy sits in New Zealand, and your report is emailed via Google in the United States. Here is what covers each leg.
This is the position as at 3 September 2026. Adequacy decisions are reviewed periodically and can be narrowed or withdrawn, and a company's certification can lapse. If you are reading this long after that date, these are the statements to re-check first, and the date at the top of this document tells you how stale they may be.
Into Tally — for an EEA creator, not a transfer at all. Tally BV is established in Belgium. If you or your students are in the EEA, uploading to Tally keeps that data inside the EEA.
From the EEA to us in New Zealand — covered by an adequacy decision. The European Commission recognises New Zealand as providing an adequate level of protection, and in January 2024 it concluded a review of the eleven adequacy decisions adopted before the GDPR and found that data can continue to flow to the countries and territories covered, New Zealand among them. Personal data moves from the EEA to New Zealand with no standard contractual clauses and no other additional safeguard.
From the UK to us in New Zealand — the same. The adequacy decisions in force when the UK left the EU were carried into UK law, and New Zealand is covered by UK adequacy regulations in their own right.
The report email, via Google in the United States — reliance on Google's certification. This is the one leg that does not rest on a country-level decision about a whole country. It rests on Google's own certification under the EU-US Data Privacy Framework and its UK Extension, which is granted per company and can lapse, be withdrawn, or be allowed to expire. We rely on Google maintaining it, in the same way we rely on Tally's statement about where it hosts. We have not audited it. If it ever lapsed, we would need another route for the report, and we would tell you before we used one.
Under the New Zealand Privacy Act, we are responsible for ensuring that anyone we disclose personal information to outside New Zealand protects it with comparable safeguards, as Information Privacy Principle 12 requires. We rely on the published terms of those two providers for this: Tally's data processing agreement, linked in section 4, and Google's terms for Google Workspace together with the certification above.
We still cannot tell where your students live, and we still do not ask. The exports do not reliably say. A timezone custom field, if you happen to have set one up, is a hint and nothing more, and most sites carry nothing of the kind. What has changed is that it no longer decides anything: every leg above is covered by something that does not depend on knowing where any individual student is. Tell us anyway if you have students in the EU or the UK — it is useful for us to know — but nothing about how their data is protected depends on you raising it.
7. Deletion
- The export files: deleted from Tally and from our computer within 14 days of your report being sent.
- Your report: kept for 30 days so we can discuss it with you, then deleted from our computer and from our Sent folder.
- On request: anything, at any time, completed within two business days, with written confirmation.
- If this agreement ends and you have not asked for anything: everything we still hold, within 14 days.
We delete by hand rather than automatically. We say so because it is true, and because it means these are commitments we keep rather than settings a system enforces. Nothing at Tally deletes itself either: a response stays until the response, the form or the account is deleted. So every deletion is two actions — the response at Tally, and the copy on our own computer — and both are on the person named in section 3.
What we can and cannot promise about copies. We keep no backup of your students' data ourselves. There is no cloud sync, no cloud backup, and no second machine. Two of our providers do hold a copy for a period after we delete, and we would rather name them than let this clause read as more absolute than it is:
- Tally keeps backups of its systems and publishes no retention window for them, so a deleted response may persist in Tally's backups for a period we cannot state.
- Google Workspace moves a deleted email to Trash, where Google removes it permanently after 30 days.
Neither is a copy we can reach, read, use or accelerate. Both are outside our control and inside our disclosure.
8. Your commitments to us
You confirm that:
- You have a lawful basis to share your students' information with us, and doing so is consistent with what you have told your students about how their data is used.
- The files are original, unmodified Thinkific exports.
- Your answers about your courses are accurate as far as you know — including which courses drip-release lessons, offer free previews, sit behind prerequisites, or use SCORM.
- The courses in your export do not include students under 18, and none of them covers a subject where being enrolled would itself reveal something private about a person.
- You will tell us if any of your students are in the EU or the UK. Nothing about how their data is protected depends on it — section 6 explains why — but it is useful for us to know.
If a claim is made against us because one of these was not true, you agree to cover the reasonable cost of dealing with it.
9. Term, and what happens if the documents disagree
This agreement starts when you upload. It ends when you tell us to stop, or when we tell you we cannot deliver, and the deletion clocks in section 7 run from that point.
If this agreement conflicts with our terms of service or our privacy notice on anything to do with your students' data, this agreement wins.
10. Law
New Zealand law governs this agreement, and the courts of New Zealand have jurisdiction. Nothing here limits any right you have under a privacy law that cannot be contracted out of.
11. Contact
alex@studentretainer.com
Annex A — Processing at a glance
| Subject matter | Producing one Student Retention Scan report |
|---|---|
| Duration | Upload until deletion under section 7 |
| Nature | Receiving two complete dashboard exports, reading five files from them, applying fixed rules, generating a report, human review, email delivery |
| Purpose | Identifying students the creator may want to contact |
| Data subjects | Students enrolled in the creator's Thinkific courses |
| Categories of data | As listed in section 2 |
| Special category data | Not requested and not knowingly accepted. See section 8, and the custom-field warning in section 3 of the privacy notice |
| Automated decision-making | None with legal or similarly significant effect. The report is advisory; the creator decides what to do |
Annex B — Security measures
- Files travel over encrypted connections between the creator, Tally and us. The final leg, the report leaving our mail server for the creator's, is encrypted where the creator's own mail provider supports it, which is outside our control.
- Files are stored encrypted at rest by Tally.
- The computer holding working copies is password-protected with full-disk encryption.
- One person handles the files. No shared accounts, no shared credentials, no second account on that machine. See section 3 for what that does and does not mean.
- Working copies are not synced to any cloud service and are not backed up to one.
- Files are deleted on the schedule in section 7, by hand, in both of the places they exist.
- No student data enters any AI system, and nothing is used to train a model.
- Breaches are notified to the creator within 24 hours of discovery.
- Two provider-side copies fall away on their own schedules rather than ours, and both are named in section 7.