# Course Pack data-processing and subprocessor schedule / Schedule trattamento e sub-responsabili

**Version 1.0 — 28 July 2026 — bind to the KISTU DPA before activation**

## Processing scope

KISTU processes customer-provided recordings, documents, metadata, instructions, derived transcripts, generated learning material, account references and support records to provide Course Pack. Data subjects may include uploaders, speakers, learners, employees, contractors, customers and people mentioned in source material. Special-category, criminal-offence or children’s data is not requested and must not be uploaded unless an approved customer-specific instruction and lawful basis cover it.

KISTU acts as processor for customer-directed source/content processing and as controller for account administration, service security, abuse prevention, billing records and direct support. The customer remains responsible for lawful instructions, notices, source authorization and data-subject request coordination for customer content.

## Governed providers

The active provider registry in KISTU Admin is authoritative. Course Pack may use enabled application-scoped profiles only for:

- Auth0: authentication and identity;
- AWS: object storage and related infrastructure;
- Sentry: minimized diagnostics when enabled.

OpenAI for transcription/content processing and Brevo for transactional email remain SYSTEM-level KISTU providers. Course Pack invokes only centrally governed KISTU services and never receives or duplicates those provider credentials.

Provider legal entity, purpose, region, data categories, retention, subprocessors and transfer mechanism must be complete in the registry before the profile can be enabled. Course Pack stores no provider secret and exposes no provider cost to customers.

## Security and deletion

Required controls include tenant-bound authorization, least privilege, encrypted transport and storage, validated/quarantined upload, server-side secrets, content-free audit where possible, versioned retention and a deletion receipt. Support bundles must redact source content and credentials.

---

KISTU tratta registrazioni, documenti, metadati, istruzioni, trascrizioni derivate, materiali generati, riferimenti account e record di supporto per erogare Course Pack. Gli interessati possono includere uploader, speaker, studenti, dipendenti, collaboratori, clienti e persone citate. Dati particolari, giudiziari o relativi a minori non sono richiesti e non devono essere caricati senza istruzione cliente approvata e base giuridica applicabile.

KISTU opera come responsabile per il trattamento dei contenuti diretto dal cliente e come titolare per account, sicurezza, prevenzione abusi, registri di fatturazione e supporto diretto. Il registro provider attivo in KISTU Admin è autoritativo. Course Pack può utilizzare profili application-scoped abilitati soltanto per Auth0, AWS e Sentry. OpenAI per trascrizione/elaborazione e Brevo per le email transazionali restano provider SYSTEM-level di KISTU: Course Pack invoca esclusivamente servizi centrali governati e non riceve né duplica tali credenziali. Entità, scopo, regione, categorie, retention, sub-responsabili e meccanismo di trasferimento devono essere completi prima dell’abilitazione.
