SuperSchool
Log inGet started

U.S. K-12 data processing addendum

Effective: August 20, 2026. Last updated: August 24, 2026.

This U.S. K-12 Data Processing Addendum, or DPA, is between SuperSchool Inc. and the Customer that accepts the U.S. K-12 Terms of Service or another agreement that incorporates this DPA. It applies when SuperSchool processes Personal Data or Student Data for the Customer.

If SuperSchool and a school or district sign a separate data processing agreement, that agreement controls where it conflicts with this DPA.


1. Definitions

Applicable Privacy Law means FERPA, PPRA, COPPA where applicable, and U.S. state student-privacy and data-protection laws that apply to the Customer Data processed under the agreement.

Customer means the educator, school, district, or other K-12 educational organization that accepts the agreement.

Customer Data means information submitted to, stored in, or generated through the service for the Customer. It includes Personal Data and Student Data but excludes information SuperSchool receives outside the service in a personal capacity.

Personal Data means information that identifies or is reasonably linkable to an individual and is protected by Applicable Privacy Law.

Security Incident means unauthorized acquisition of, access to, use of, disclosure of, alteration of, or destruction of Customer Data in SuperSchool's possession or control. Unsuccessful attempts that do not compromise Customer Data are not Security Incidents.

Student Data means Personal Data about a current or former student that is processed for a K-12 educational purpose, including names, student identifiers, attendance information, assignments, work samples, test results, grades, evaluations, classroom communications, and education records protected by FERPA.

Subprocessor means a provider engaged by SuperSchool to process Customer Data in order to provide the service.

2. Roles and instructions

The Customer determines the educational purpose for processing Customer Data and the optional data sources it chooses to use. SuperSchool processes Customer Data only on the Customer's documented instructions, including the agreement, the Customer's configuration of the service, and lawful written instructions accepted by SuperSchool.

The Customer is the controller of Personal Data, or the equivalent role under Applicable Privacy Law. SuperSchool is the processor, service provider, or equivalent role.

Where SuperSchool processes education records protected by FERPA, the Customer designates SuperSchool as a school official with a legitimate educational interest. SuperSchool is under the Customer's direct control regarding the use and maintenance of education records and will use them only to perform the authorized educational service.

The Customer represents that it has the authority to instruct SuperSchool to process Customer Data. An individual educator may submit Student Data only when authorized under Applicable Privacy Law and school or district policy. If an educator is not authorized, the educator must not submit Student Data.

3. Permitted processing

SuperSchool may process Customer Data only to:

  • provide, operate, maintain, secure, and support the service;
  • respond to the Customer and authorized users;
  • verify or maintain the quality, security, and integrity of the service;
  • debug to identify and repair errors that impair existing intended functionality;
  • follow the Customer's lawful instructions; and
  • comply with applicable law.

SuperSchool will not:

  • sell Customer Data or disclose it for cross-context behavioral advertising;
  • use Customer Data to advertise to a student, parent, educator, or school;
  • use Customer Data for general product research or to develop new products or features;
  • build a commercial profile of a student except as expressly directed by the Customer for the authorized educational purpose;
  • use Customer Data to train or improve an AI model;
  • permit a Subprocessor to use Customer Data for its own training, advertising, or other internal purpose; or
  • retain, use, or disclose Customer Data outside the direct business relationship with the Customer, except as required by law.

SuperSchool does not own Student Data or obtain independent rights in it.

4. Customer choices and responsibilities

The Customer chooses whether to provide instructional materials, student work, school resources, classroom transcripts, or data from tool integrations. Each source is optional unless a separate order or school agreement states otherwise.

The Customer is responsible for:

  • determining that its use of the service is permitted by Applicable Privacy Law and policy;
  • providing required notices and obtaining required consent or approval;
  • authorizing users and removing access that is no longer appropriate;
  • configuring integrations and access according to its instructions;
  • not providing data that is unnecessary for the selected educational purpose; and
  • reviewing AI-generated output before relying on it.

For classroom capture, the Customer must determine that recording and transcription are authorized before enabling the feature. The Customer must not use classroom capture in counseling, health, disciplinary, privileged, or similarly sensitive settings.

5. Confidentiality and access

SuperSchool will limit access to Customer Data to personnel and Subprocessors who need it for the permitted processing. Personnel with access are bound by confidentiality obligations and receive appropriate privacy and security training. Access is authenticated, role-limited, and logged.

Authorized educators may access the Customer Data made available to their accounts, including complete transcripts and student work. School administrators receive aggregate usage and class-level metrics by default. Administrator access to a complete transcript or student submission requires express authorization under the Customer's agreement and access controls.

6. Subprocessors

The Customer authorizes the Subprocessors listed at /privacy/subprocessors. SuperSchool will bind each Subprocessor that receives Customer Data to written obligations that are at least as protective as the relevant obligations in this DPA.

SuperSchool will provide at least 30 days' advance notice before appointing a new Subprocessor that will receive Student Data. During that period, the Customer may object on reasonable data-protection grounds. The parties will work in good faith to address the concern. If they cannot, the Customer may discontinue the affected feature or terminate the service without penalty.

SuperSchool remains responsible for a Subprocessor's processing of Customer Data to the extent required by law and this DPA.

7. Individual rights and education-record requests

The Customer is responsible for responding to requests from students, parents, eligible students, educators, or other individuals concerning Customer Data. SuperSchool will provide reasonable assistance needed for the Customer to respond, including access, correction, export, or deletion where technically feasible and legally required.

If SuperSchool receives a request concerning school-controlled Customer Data, SuperSchool will direct the requester to the Customer or notify the Customer, unless prohibited by law. SuperSchool will not independently disclose an education record to the requester without the Customer's instruction or legal authority.

SuperSchool will use available resource, class, date, and other metadata to help the Customer locate records relevant to a request. At the Customer's direction, SuperSchool will provide or delete the relevant source artifact and its derived outputs where technically feasible. SuperSchool does not guarantee that every spoken statement or handwritten reference can be reliably attributed to a particular student.

8. Return, retention, and deletion

Instructional materials, student work, school resources, transcripts, generated materials, and related class-level data are scheduled for deletion at the end of the school year in which they were created and permanently purged within 30 days.

The Customer may request deletion sooner. SuperSchool will make the affected Customer Data unavailable and permanently purge it from active systems, processing copies, and recoverable backups within 30 days after the request.

When the agreement ends, SuperSchool will, at the Customer's choice and where technically feasible, return eligible Customer Data and delete the remaining Customer Data within 30 days. Transient audio cannot be returned because it is never durably stored.

SuperSchool may retain limited information when required by law or reasonably necessary to establish, exercise, or defend legal claims. It will isolate that information, stop using it for the service, and delete it when the obligation ends. SuperSchool will notify the Customer if a legal obligation prevents or delays deletion unless the law prohibits notice.

Account, security, consent, transaction, and legal records that do not contain classroom transcripts or uploaded resources may be retained for the periods reasonably necessary for security, dispute resolution, and legal compliance. Security and diagnostic logs are normally retained for up to 90 days.

9. Security program

SuperSchool will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Data and the risk of processing. The current safeguards are described in Schedule 2.

SuperSchool will not materially reduce the overall security of the service during the term. On reasonable request, SuperSchool will provide the Customer with information needed to evaluate these safeguards, subject to confidentiality and reasonable limits that protect other customers and SuperSchool's systems.

10. Security incidents

SuperSchool will notify the Customer without undue delay and no later than 48 hours after confirming a Security Incident affecting the Customer's data, unless Applicable Privacy Law or a separate agreement requires earlier notice.

The notice will include, as information becomes available:

  • the nature and date of the incident;
  • the categories of Customer Data and individuals affected;
  • the measures taken or planned to contain and remediate it;
  • steps the Customer may take to reduce harm; and
  • a contact for follow-up.

SuperSchool will investigate, contain, remediate, preserve appropriate evidence, and reasonably assist the Customer with legally required notifications. SuperSchool will not notify students, parents, eligible students, regulators, or the public on the Customer's behalf unless instructed by the Customer or required by law.

Notice of a Security Incident is not an admission of fault or liability.

11. Legal demands

If SuperSchool receives a legally binding demand for Customer Data, it will, unless prohibited by law, notify the Customer and give the Customer an opportunity to seek protection. SuperSchool will disclose only the data legally required and will use reasonable efforts to obtain confidential treatment.

12. Compliance and audit assistance

SuperSchool will provide information reasonably necessary to demonstrate compliance with this DPA. No more than once per year, unless a Security Incident or regulator requires otherwise, the Customer may request a remote assessment of relevant documentation.

An on-site audit is available only when documentation is insufficient to satisfy a legal requirement, must be scheduled in advance, may not expose another customer's information or create security risk, and will be conducted during normal business hours at the Customer's expense. A regulator's lawful audit rights are not limited by this paragraph.

13. State student-privacy laws

SuperSchool will comply with applicable state student-privacy duties for its role as a school service provider. If a state requires additional terms that cannot be satisfied by this DPA, the parties may enter a state-specific or district-specific addendum. A signed addendum controls for the covered processing.

14. General

This DPA begins when the agreement begins and continues while SuperSchool processes Customer Data for the Customer. If this DPA conflicts with the U.S. K-12 Terms, this DPA controls for privacy and security matters. A separately signed school agreement or DPA controls over this public DPA.

The liability and dispute terms in the agreement apply to this DPA unless a separate school agreement states otherwise.

15. Contact

  • Privacy questions and instructions: legal@superschool.us
  • Security and data incident notices: legal@superschool.us

Schedule 1: Processing details

Subject matter and purpose

SuperSchool processes Customer Data to provide educator-facing assistance grounded in the school and classroom context the Customer chooses to share, and for the limited operational purposes in Section 3.

Duration

Processing continues during the agreement. Content follows the school-year and 30-day deletion rules in Section 8.

People whose information may be processed

  • authorized educators, administrators, and school staff;
  • students whose information appears in Customer-selected content;
  • parents or guardians whose information appears in Customer-selected content; and
  • other individuals who communicate with the Customer or appear in authorized classroom content.

Data categories and processing by component

ComponentCustomer-selected dataProcessingDurable storage
AccountsName, school email, organization, role, authentication identifier, settingsAuthenticate, authorize, communicate, support, and secureAccount life, then deletion or de-identification within 30 days, subject to limited legal and security records
Instructional materials and student workLesson plans, curriculum, rubrics, assignments, slides, worksheets, scanned submissions, work samples, and other resourcesStore, retrieve, search, and generate requested educator-facing outputUntil school-year end or earlier request, then purge within 30 days
School resourcesCalendars, timetables, guidance, approved-tools lists, and selected operational resourcesStore, retrieve, search, and use as requested contextUntil school-year end or earlier request, then purge within 30 days
Classroom transcriptsClassroom audio, temporary processing transcript, retained transcriptTransiently transcribe audio, then store, retrieve, search, and use the resulting transcript for educator-requested featuresAudio is never durably stored. The transcript is retained until school-year end or earlier request, then purged within 30 days
Tool integrationsAuthorization tokens and data selected through a connected serviceAccess and import only what is needed for the configured functionTokens until disconnected or expired. Imported data follows the category into which it is stored
Generated materialsSummaries, drafts, class-level metrics, and other requested educator-facing outputGenerate, store, retrieve, and displayUntil school-year end or earlier request, then purge within 30 days
Usage and securitySign-in events, device and browser information, feature events, diagnostics, access recordsOperate, secure, support, verify quality and integrity, and debugNormally up to 90 days for security and diagnostic logs

Sensitive data

Customer-selected content may contain education records and information protected by student-privacy law. The service is not intended to receive medical records, counseling records, legally privileged material, payment-card data, government identifiers, or biometric identifiers.

Processing location

Customer Data is stored and primarily processed in the United States, subject to the provider details published at /privacy/subprocessors.


Schedule 2: Technical and organizational safeguards

SuperSchool will maintain safeguards that include:

  • encryption of Customer Data in transit using current industry-standard transport encryption;
  • encryption of durably stored Customer Data at rest;
  • authenticated, role-limited access to production systems and Customer Data;
  • logging of privileged access and transcript access;
  • separation of each customer's data through application authorization controls;
  • separation of production systems and data from development and automated tests;
  • secrets stored outside source control and rotated after suspected exposure;
  • limited personnel access based on a documented operational need;
  • provider review and written data-protection obligations before a provider receives Customer Data;
  • monitoring and investigation of authentication, authorization, provider, and deletion failures;
  • vulnerability remediation and a public responsible disclosure policy;
  • incident-response procedures for investigation, containment, remediation, evidence preservation, and notice;
  • recoverable backups protected by access controls and included in the 30-day deletion window;
  • testing of restoration and deletion processes without placing production classroom content in automated tests; and
  • business continuity measures appropriate to a service that is not represented as the Customer's system of record.
SuperSchool
Privacy policyK-12 termsK-12 DPAService providersReport a vulnerability

© 2026 SuperSchool · legal@superschool.us