Data Processing Agreement
Effective August 23, 2026 · Version 1.0
1. Definitions and precedence
“Applicable Data Protection Law” means privacy, data protection, and education-record law applicable to a party’s processing under the Service. “Customer Personal Data” means personal data Customer submits to or generates in VindicaOS. “Process,” “controller,” “processor,” “data subject,” and “personal data breach” have the meanings given by applicable law. “Subprocessor” means a third party Vindica engages to process Customer Personal Data.
This DPA controls over conflicting terms about processing Customer Personal Data. The Terms otherwise remain in effect.
2. Roles, instructions, and purpose
Customer is controller, business, or educational agency and Vindica is processor, service provider, or contractor, as applicable. Vindica will process Customer Personal Data only on Customer’s documented instructions: the Terms, this DPA, configuration and feature use, support requests, and other written directions consistent with the agreement. Vindica will notify Customer if an instruction appears to violate applicable law, unless prohibited from doing so.
| Subject and purpose | Providing and securing the VindicaOS educational platform: account access, assessments, scoring, classroom tools, homework, reports, support, and customer-directed communications. |
|---|---|
| Duration | The Service term and the deletion periods in Section 10. |
| Data subjects | Customer’s students, including minors; parents or guardians where Customer provides their details; instructors; administrators; and other authorized users. |
| Data | Names or identifiers, work email and roles, grade/cohort/school, login codes, parent contact where provided, assessment responses and scores, activity, assignments, reports, teacher notes, support content, and technical/security data. |
| Sensitive data | Not required. Customer will not intentionally submit health, biometric, precise-location, government-ID, payment-card, or other special-category student data unless the parties first agree in writing to safeguards. |
3. Education records and children
FERPA. To the extent FERPA applies and its requirements are met, Vindica performs institutional services that Customer would otherwise use employees to perform; is under Customer’s direct control regarding use and maintenance of education records through this DPA; will use education records only for the purposes authorized by Customer; and will not redisclose them except as permitted by Customer, this DPA, and FERPA. Vindica will not use education records to build profiles for unrelated purposes.
COPPA. When Customer provides school authorization in place of parental consent where COPPA permits, Vindica will process a child’s information only for the authorized educational purpose, provide required notice and access, maintain reasonable security, collect no more than reasonably necessary, retain it only as needed, and not use it for advertising or another commercial purpose. Vindica retains responsibility for duties COPPA places on it as an operator; Customer remains responsible for duties arising from its direct relationship and instructions.
4. Personnel and confidentiality
Vindica will limit access to personnel who need it to perform the agreement, ensure they are bound by confidentiality, provide appropriate privacy and security training, and remain responsible for their compliance.
5. Security
Vindica will maintain measures appropriate to the nature and risk of processing, including:
- TLS encryption in transit and provider-managed encryption at rest.
- Logical tenant isolation and role-based access controls.
- Unique staff accounts, protected credentials, and least-privilege production access.
- Logging, monitoring, backups, vulnerability and dependency maintenance, and incident-response procedures.
- Secure development and change-control practices appropriate to the Service.
- Periodic review of access, safeguards, and material providers.
Customer is responsible for securely administering its users, devices, permissions, and exports and for promptly reporting suspected compromise.
6. Subprocessors
Customer generally authorizes the Subprocessors below. Vindica will contractually require protections appropriate to their processing and remains responsible for their performance to the extent required by law. Vindica will post or otherwise provide notice at least 15 days before adding a Subprocessor that will handle Customer Personal Data. Customer may object on reasonable data-protection grounds during that period; the parties will work in good faith on a solution, and Customer may discontinue the affected feature if none is reasonably available.
| Subprocessor | Purpose | Data / location |
|---|---|---|
| Supabase and its infrastructure providers | Database, authentication, storage | Account and Customer Personal Data; provider-configured regions |
| Netlify | Hosting, serverless functions, content delivery | Request, technical, and feature data; global infrastructure |
| Google Gemini | Customer-requested AI-assisted features | Minimum relevant prompt/content; provider infrastructure |
| Anthropic | Customer-requested AI support/content features | Minimum relevant prompt/content; provider infrastructure |
| Resend | Transactional email | Recipient and message content; provider infrastructure |
| Stripe | Billing | Billing-contact and transaction data only; no student records |
7. Data subject and regulator requests
Taking account of the processing, Vindica will reasonably assist Customer with verified requests to access, correct, export, restrict, or delete Customer Personal Data and with legally required assessments, consultations, and regulator inquiries. If Vindica receives a request concerning Customer Personal Data, it will refer it to Customer unless law permits or requires a direct response. Vindica may charge reasonable costs for unusually burdensome assistance not caused by its breach.
8. Government demands
Unless prohibited by law, Vindica will notify Customer before disclosing Customer Personal Data in response to a binding demand, challenge overbroad or unlawful demands where reasonable, and disclose only what is legally required.
9. Personal data breaches
Vindica will notify Customer without undue delay and, where feasible, within 72 hours after confirming a personal data breach affecting Customer Personal Data. Notice will include available information about the nature, affected data and people, likely consequences, mitigation, and a contact. Vindica will investigate, contain, remediate, preserve relevant evidence, and reasonably assist Customer with required notices. Notice is not an admission of fault.
10. Return, deletion, and retention
During the term and for 30 days after termination, Customer may request a reasonable export. On Customer’s valid request or after that period, Vindica will delete Customer Personal Data from active systems within 30 days unless law requires retention. Encrypted backups are isolated from ordinary use and overwritten on provider cycles, normally within 90 days. If restored for continuity or disaster recovery, deletion instructions will be reapplied. Vindica may retain minimal account, billing, security, and legal records as required by law or needed to establish claims.
11. Demonstrating compliance
On written request no more than once annually, Vindica will provide information reasonably necessary to demonstrate compliance, such as current security documentation and relevant third-party reports when available, subject to confidentiality. If that is insufficient and law requires more, Customer may arrange a narrowly scoped audit by an independent, non-competitor auditor on at least 30 days’ notice, during business hours, without accessing other customers’ information or disrupting the Service. Customer bears its costs unless the audit identifies a material Vindica breach.
12. International transfers
If Customer Personal Data protected by the EEA GDPR is transferred to a country without an adequacy decision, the 2021 European Commission Standard Contractual Clauses are incorporated as follows: Module Two (controller to processor); optional docking clause applies; Clause 9 Option 2 with the notice period in Section 6; Clause 11 optional language does not apply; Clause 17 Option 1 uses Irish law; Clause 18 selects courts of Ireland; and Annexes I–III are completed by Sections 2, 5, 6, and the parties’ account details. For UK restricted transfers, the then-current UK International Data Transfer Addendum is incorporated with the same selections. If another valid mechanism is required, the parties will cooperate to implement it. The SCCs or UK Addendum control over conflicting terms.
13. General
Each party will comply with Applicable Data Protection Law for its own processing. Liability under this DPA is subject to the Terms. Delaware law governs except where the SCCs, UK Addendum, or mandatory law require otherwise. Changes to this DPA will not materially reduce protections for Customer Personal Data during an active paid term without notice.
14. Contact and execution
Privacy and DPA questions, audit requests, and requests for a countersigned copy may be sent to kevinchoi@vindicaseneca.com. Electronic acceptance of the Terms executes this DPA for both parties; no separate signature is required.