Legal / Schools
Data Processing Agreement
Version 1.0. Effective March 27, 2026.
For school districts and educational institutions
1. Relationship of the Parties
This Data Processing Agreement ("DPA") is entered into between the school district or educational institution ("School") and Gregarious ("Processor"). The School is the Data Controller. Gregarious acts as a Data Processor and designated "school official" under FERPA, processing student education records solely on behalf of and under the direction of the School.
Gregarious has a legitimate educational interest in the student data it processes, limited to providing the adaptive learning, assessment, and creative portfolio services described in this agreement.
This DPA is incorporated by reference into the Gregarious School Service Agreement and the Gregarious Terms of Service. In the event of conflict between this DPA and those documents, this DPA governs with respect to student data.
2. Subject Matter and Duration
Gregarious processes student data on behalf of the School for the purpose of providing the Gregarious adaptive learning platform, including adaptive mastery sprints, Studio creative tools, teacher dashboards, parent reporting, and school administration features.
This DPA takes effect on the date the School Service Agreement is executed and remains in force for the duration of that agreement. Upon termination, the data retention and deletion obligations in Section 5 apply.
3. Data Categories and Purpose
| Category | Data Fields | Purpose | Retention |
|---|---|---|---|
| Account Information | Email address, display name, role, school affiliation | Authentication, access control, and school/class linking | Duration of account plus 30 days after deletion request |
| Educational Records | Quiz answers, mastery scores, skill ratings, session history | Adaptive learning, progress tracking, teacher reporting | 2 years from last activity, then automatically deleted |
| Creative Work | Studio projects (stories, games, code, music) | Student portfolio, class gallery, learning demonstration | Duration of account; exportable on request |
| Usage Data | Timestamps, session duration, streak data, EP earned | Engagement metrics, daily goals, gamification | 2 years from last activity |
| Consent Records | Consent type, timestamp, IP address (hashed) | Legal compliance (FERPA, COPPA), audit trail | 7 years (legal compliance requirement) |
| Research Data (optional) | Weekly survey responses, anonymized usage patterns | EdTech Fatigue Study (separate consent required) | 3 years post-study, then securely destroyed |
4. Data We Never Collect
Gregarious does not and will never collect the following categories of data:
- Social Security numbers or government-issued IDs
- Financial or payment information from students
- Health or medical records (including IEP/504 plan contents)
- Biometric data (fingerprints, facial recognition, voice prints)
- Geolocation or GPS data
- Browsing history outside of Gregarious
- Device fingerprints or advertising identifiers
- Social media account information
5. FERPA Design
Gregarious operates under the "school official" exception to FERPA's consent requirements (34 CFR 99.31(a)(1)). Under this designation:
- --The School maintains ownership and control of all student education records
- --Gregarious uses student data only for the educational purposes authorized by the School
- --Student data is not disclosed to any third party without the School's written consent
- --Parents and eligible students retain all rights under FERPA, including access and correction rights
- --All access to student data is logged in an immutable audit trail accessible to the School
6. Data Retention and Deletion
- Active accounts: Educational data is retained for the duration of the account plus 2 years from last activity to support longitudinal growth analysis.
- Account deletion: Upon request from the School, parent, or eligible student, all personally identifiable data is permanently deleted within 30 calendar days.
- School contract termination: Upon termination of this agreement, all School data will be exported (if requested) and permanently deleted within 60 calendar days.
- De-identified data: Aggregate, de-identified data that cannot be linked to any individual may be retained for platform improvement and research purposes.
7. Subprocessors
Gregarious uses the following third-party services to process data. Each maintains industry-standard security certifications. The School will be notified at least 30 days before any new subprocessor is added.
Supabase
SOC 2 Type IIPurpose: Database, authentication, and real-time services
Data processed: All user data (encrypted at rest with AES-256, in transit with TLS 1.3)
Location: United States (AWS us-east-1, Virginia)
Anthropic (Claude API)
SOC 2 Type IIPurpose: AI-powered educational feedback and Socratic tutoring
Data processed: Anonymized student responses only. Student names are stripped before any API call. Zero-data-retention (ZDR) is enabled so Anthropic does not store inputs or outputs.
Location: United States
Vercel
SOC 2 Type IIPurpose: Application hosting, CDN, and serverless functions
Data processed: Application code and static assets. No student PII stored on Vercel infrastructure.
Location: United States (us-east-1)
8. Security Measures
Encryption in transit
TLS 1.3 for all data transmission
Encryption at rest
AES-256 for all stored data via Supabase
Access control
Role-based access with Row-Level Security at the database layer
Authentication
Secure session management with Supabase Auth; optional MFA for admins
Audit logging
All access to student data logged with actor, action, resource, and timestamp
AI privacy
Student names stripped from all AI API calls; ZDR headers enforced
Penetration testing
Annual third-party pen test scheduled for Q3 2026
Breach notification
Affected parties notified within 72 hours of discovering a breach
9. Breach Notification
In the event of a data breach affecting student records, Gregarious will:
- --Notify the School within 72 hours of discovery
- --Provide a description of the breach, including categories and approximate number of records affected
- --Describe the measures taken or proposed to address the breach
- --Provide a dedicated point of contact for the duration of the incident response
- --Cooperate fully with the School and relevant authorities in any investigation
- --Provide a final incident report within 15 business days of the breach notification
10. Data Export and Portability
The School, parents, and eligible students may request a complete export of their data at any time. Exports are provided in standard formats (CSV, JSON) within 10 business days of the request. Export requests should be directed to cgb003@gmail.com.
Need a signed copy for your district?
Questions about our DPA? Contact cgb003@gmail.com