← Back to VindicaOS

Data Processing Agreement

Effective August 23, 2026 · Version 1.0

This Data Processing Agreement (“DPA”) is between the customer using VindicaOS (“Customer”) and Vindica Inc., a Delaware corporation (“Vindica”). It is incorporated into the Terms of Service and becomes binding automatically when Customer accepts the Terms or uses the Service. A countersigned copy is available on request.

1. Definitions and precedence

“Applicable Data Protection Law” means privacy, data protection, and education-record law applicable to a party’s processing under the Service. “Customer Personal Data” means personal data Customer submits to or generates in VindicaOS. “Process,” “controller,” “processor,” “data subject,” and “personal data breach” have the meanings given by applicable law. “Subprocessor” means a third party Vindica engages to process Customer Personal Data.

This DPA controls over conflicting terms about processing Customer Personal Data. The Terms otherwise remain in effect.

2. Roles, instructions, and purpose

Customer is controller, business, or educational agency and Vindica is processor, service provider, or contractor, as applicable. Vindica will process Customer Personal Data only on Customer’s documented instructions: the Terms, this DPA, configuration and feature use, support requests, and other written directions consistent with the agreement. Vindica will notify Customer if an instruction appears to violate applicable law, unless prohibited from doing so.

Subject and purposeProviding and securing the VindicaOS educational platform: account access, assessments, scoring, classroom tools, homework, reports, support, and customer-directed communications.
DurationThe Service term and the deletion periods in Section 10.
Data subjectsCustomer’s students, including minors; parents or guardians where Customer provides their details; instructors; administrators; and other authorized users.
DataNames or identifiers, work email and roles, grade/cohort/school, login codes, parent contact where provided, assessment responses and scores, activity, assignments, reports, teacher notes, support content, and technical/security data.
Sensitive dataNot required. Customer will not intentionally submit health, biometric, precise-location, government-ID, payment-card, or other special-category student data unless the parties first agree in writing to safeguards.

3. Education records and children

FERPA. To the extent FERPA applies and its requirements are met, Vindica performs institutional services that Customer would otherwise use employees to perform; is under Customer’s direct control regarding use and maintenance of education records through this DPA; will use education records only for the purposes authorized by Customer; and will not redisclose them except as permitted by Customer, this DPA, and FERPA. Vindica will not use education records to build profiles for unrelated purposes.

COPPA. When Customer provides school authorization in place of parental consent where COPPA permits, Vindica will process a child’s information only for the authorized educational purpose, provide required notice and access, maintain reasonable security, collect no more than reasonably necessary, retain it only as needed, and not use it for advertising or another commercial purpose. Vindica retains responsibility for duties COPPA places on it as an operator; Customer remains responsible for duties arising from its direct relationship and instructions.

4. Personnel and confidentiality

Vindica will limit access to personnel who need it to perform the agreement, ensure they are bound by confidentiality, provide appropriate privacy and security training, and remain responsible for their compliance.

5. Security

Vindica will maintain measures appropriate to the nature and risk of processing, including:

Customer is responsible for securely administering its users, devices, permissions, and exports and for promptly reporting suspected compromise.

6. Subprocessors

Customer generally authorizes the Subprocessors below. Vindica will contractually require protections appropriate to their processing and remains responsible for their performance to the extent required by law. Vindica will post or otherwise provide notice at least 15 days before adding a Subprocessor that will handle Customer Personal Data. Customer may object on reasonable data-protection grounds during that period; the parties will work in good faith on a solution, and Customer may discontinue the affected feature if none is reasonably available.

SubprocessorPurposeData / location
Supabase and its infrastructure providersDatabase, authentication, storageAccount and Customer Personal Data; provider-configured regions
NetlifyHosting, serverless functions, content deliveryRequest, technical, and feature data; global infrastructure
Google GeminiCustomer-requested AI-assisted featuresMinimum relevant prompt/content; provider infrastructure
AnthropicCustomer-requested AI support/content featuresMinimum relevant prompt/content; provider infrastructure
ResendTransactional emailRecipient and message content; provider infrastructure
StripeBillingBilling-contact and transaction data only; no student records

7. Data subject and regulator requests

Taking account of the processing, Vindica will reasonably assist Customer with verified requests to access, correct, export, restrict, or delete Customer Personal Data and with legally required assessments, consultations, and regulator inquiries. If Vindica receives a request concerning Customer Personal Data, it will refer it to Customer unless law permits or requires a direct response. Vindica may charge reasonable costs for unusually burdensome assistance not caused by its breach.

8. Government demands

Unless prohibited by law, Vindica will notify Customer before disclosing Customer Personal Data in response to a binding demand, challenge overbroad or unlawful demands where reasonable, and disclose only what is legally required.

9. Personal data breaches

Vindica will notify Customer without undue delay and, where feasible, within 72 hours after confirming a personal data breach affecting Customer Personal Data. Notice will include available information about the nature, affected data and people, likely consequences, mitigation, and a contact. Vindica will investigate, contain, remediate, preserve relevant evidence, and reasonably assist Customer with required notices. Notice is not an admission of fault.

10. Return, deletion, and retention

During the term and for 30 days after termination, Customer may request a reasonable export. On Customer’s valid request or after that period, Vindica will delete Customer Personal Data from active systems within 30 days unless law requires retention. Encrypted backups are isolated from ordinary use and overwritten on provider cycles, normally within 90 days. If restored for continuity or disaster recovery, deletion instructions will be reapplied. Vindica may retain minimal account, billing, security, and legal records as required by law or needed to establish claims.

11. Demonstrating compliance

On written request no more than once annually, Vindica will provide information reasonably necessary to demonstrate compliance, such as current security documentation and relevant third-party reports when available, subject to confidentiality. If that is insufficient and law requires more, Customer may arrange a narrowly scoped audit by an independent, non-competitor auditor on at least 30 days’ notice, during business hours, without accessing other customers’ information or disrupting the Service. Customer bears its costs unless the audit identifies a material Vindica breach.

12. International transfers

If Customer Personal Data protected by the EEA GDPR is transferred to a country without an adequacy decision, the 2021 European Commission Standard Contractual Clauses are incorporated as follows: Module Two (controller to processor); optional docking clause applies; Clause 9 Option 2 with the notice period in Section 6; Clause 11 optional language does not apply; Clause 17 Option 1 uses Irish law; Clause 18 selects courts of Ireland; and Annexes I–III are completed by Sections 2, 5, 6, and the parties’ account details. For UK restricted transfers, the then-current UK International Data Transfer Addendum is incorporated with the same selections. If another valid mechanism is required, the parties will cooperate to implement it. The SCCs or UK Addendum control over conflicting terms.

13. General

Each party will comply with Applicable Data Protection Law for its own processing. Liability under this DPA is subject to the Terms. Delaware law governs except where the SCCs, UK Addendum, or mandatory law require otherwise. Changes to this DPA will not materially reduce protections for Customer Personal Data during an active paid term without notice.

14. Contact and execution

Privacy and DPA questions, audit requests, and requests for a countersigned copy may be sent to kevinchoi@vindicaseneca.com. Electronic acceptance of the Terms executes this DPA for both parties; no separate signature is required.

© 2026 Vindica Inc. · VindicaOS is a Seneca product · Privacy · Terms