Skip to main content

Legal / Schools

Data Processing Agreement

Version 1.0. Effective March 27, 2026.

For school districts and educational institutions

1. Relationship of the Parties

This Data Processing Agreement ("DPA") is entered into between the school district or educational institution ("School") and Gregarious ("Processor"). The School is the Data Controller. Gregarious acts as a Data Processor and designated "school official" under FERPA, processing student education records solely on behalf of and under the direction of the School.

Gregarious has a legitimate educational interest in the student data it processes, limited to providing the adaptive learning, assessment, and creative portfolio services described in this agreement.

This DPA is incorporated by reference into the Gregarious School Service Agreement and the Gregarious Terms of Service. In the event of conflict between this DPA and those documents, this DPA governs with respect to student data.

2. Subject Matter and Duration

Gregarious processes student data on behalf of the School for the purpose of providing the Gregarious adaptive learning platform, including adaptive mastery sprints, Studio creative tools, teacher dashboards, parent reporting, and school administration features.

This DPA takes effect on the date the School Service Agreement is executed and remains in force for the duration of that agreement. Upon termination, the data retention and deletion obligations in Section 5 apply.

3. Data Categories and Purpose

CategoryData FieldsPurposeRetention
Account InformationEmail address, display name, role, school affiliationAuthentication, access control, and school/class linkingDuration of account plus 30 days after deletion request
Educational RecordsQuiz answers, mastery scores, skill ratings, session historyAdaptive learning, progress tracking, teacher reporting2 years from last activity, then automatically deleted
Creative WorkStudio projects (stories, games, code, music)Student portfolio, class gallery, learning demonstrationDuration of account; exportable on request
Usage DataTimestamps, session duration, streak data, EP earnedEngagement metrics, daily goals, gamification2 years from last activity
Consent RecordsConsent type, timestamp, IP address (hashed)Legal compliance (FERPA, COPPA), audit trail7 years (legal compliance requirement)
Research Data (optional)Weekly survey responses, anonymized usage patternsEdTech Fatigue Study (separate consent required)3 years post-study, then securely destroyed

4. Data We Never Collect

Gregarious does not and will never collect the following categories of data:

  • Social Security numbers or government-issued IDs
  • Financial or payment information from students
  • Health or medical records (including IEP/504 plan contents)
  • Biometric data (fingerprints, facial recognition, voice prints)
  • Geolocation or GPS data
  • Browsing history outside of Gregarious
  • Device fingerprints or advertising identifiers
  • Social media account information

5. FERPA Design

Gregarious operates under the "school official" exception to FERPA's consent requirements (34 CFR 99.31(a)(1)). Under this designation:

  • --The School maintains ownership and control of all student education records
  • --Gregarious uses student data only for the educational purposes authorized by the School
  • --Student data is not disclosed to any third party without the School's written consent
  • --Parents and eligible students retain all rights under FERPA, including access and correction rights
  • --All access to student data is logged in an immutable audit trail accessible to the School

6. Data Retention and Deletion

  • Active accounts: Educational data is retained for the duration of the account plus 2 years from last activity to support longitudinal growth analysis.
  • Account deletion: Upon request from the School, parent, or eligible student, all personally identifiable data is permanently deleted within 30 calendar days.
  • School contract termination: Upon termination of this agreement, all School data will be exported (if requested) and permanently deleted within 60 calendar days.
  • De-identified data: Aggregate, de-identified data that cannot be linked to any individual may be retained for platform improvement and research purposes.

7. Subprocessors

Gregarious uses the following third-party services to process data. Each maintains industry-standard security certifications. The School will be notified at least 30 days before any new subprocessor is added.

Supabase

SOC 2 Type II

Purpose: Database, authentication, and real-time services

Data processed: All user data (encrypted at rest with AES-256, in transit with TLS 1.3)

Location: United States (AWS us-east-1, Virginia)

Anthropic (Claude API)

SOC 2 Type II

Purpose: AI-powered educational feedback and Socratic tutoring

Data processed: Anonymized student responses only. Student names are stripped before any API call. Zero-data-retention (ZDR) is enabled so Anthropic does not store inputs or outputs.

Location: United States

Vercel

SOC 2 Type II

Purpose: Application hosting, CDN, and serverless functions

Data processed: Application code and static assets. No student PII stored on Vercel infrastructure.

Location: United States (us-east-1)

8. Security Measures

Encryption in transit

TLS 1.3 for all data transmission

Encryption at rest

AES-256 for all stored data via Supabase

Access control

Role-based access with Row-Level Security at the database layer

Authentication

Secure session management with Supabase Auth; optional MFA for admins

Audit logging

All access to student data logged with actor, action, resource, and timestamp

AI privacy

Student names stripped from all AI API calls; ZDR headers enforced

Penetration testing

Annual third-party pen test scheduled for Q3 2026

Breach notification

Affected parties notified within 72 hours of discovering a breach

9. Breach Notification

In the event of a data breach affecting student records, Gregarious will:

  • --Notify the School within 72 hours of discovery
  • --Provide a description of the breach, including categories and approximate number of records affected
  • --Describe the measures taken or proposed to address the breach
  • --Provide a dedicated point of contact for the duration of the incident response
  • --Cooperate fully with the School and relevant authorities in any investigation
  • --Provide a final incident report within 15 business days of the breach notification

10. Data Export and Portability

The School, parents, and eligible students may request a complete export of their data at any time. Exports are provided in standard formats (CSV, JSON) within 10 business days of the request. Export requests should be directed to cgb003@gmail.com.

Need a signed copy for your district?

StudentTeacherParentAdmin