Template — review with counsel before signing.
This document is a starting point for Mr. A's Writing Tools and a school
district that wants a written DPA covering student data handling. Specific
state requirements (Illinois SOPPA, California SB 1177, New York Ed. Law
§2-d, and others) may need additions or substitutions; consult your
district's legal counsel before execution. Send completed/signed copies to
aaron@writingtools.org.
This Data Processing Agreement (the "DPA") is entered into between:
Mr. A's Writing Tools ("Service Provider," "we," or "us"), the operator of the AI-coached writing platform at writingtools.org; and
[School / District / LEA name] ("School," "you," or "the LEA").
This DPA takes effect on the date last signed below (the "Effective Date") and supplements the Service Provider's Terms of Service and Privacy Policy. In the event of conflict between this DPA and those documents, this DPA controls with respect to the processing of Student Data.
2. Definitions
"Student Data" means information about an identified or identifiable Student that the School (or a Student or parent on its behalf) provides to or generates within the Service. Includes the Student's name, email, grade level, written submissions, scores, feedback, and activity logs.
"FERPA" means the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g.
"COPPA" means the Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506.
"School Official" has the meaning given under FERPA § 99.31(a)(1) and the Service Provider qualifies as a "school official with a legitimate educational interest" when processing Student Data on the School's behalf.
"Sub-processor" means a third party engaged by the Service Provider to process Student Data on its behalf.
3. Scope & Nature of Processing
The Service Provider processes Student Data solely to deliver the AI-coached writing platform: collecting written submissions, generating step-by-step coaching feedback aligned to academic standards, tracking student progress, and surfacing teacher dashboards.
The Service Provider does not:
Sell Student Data, ever, under any circumstance;
Use Student Data for advertising or to build advertising profiles;
Use Student Data to train third-party large language models for general use outside the Service;
Disclose Student Data to third parties except as expressly permitted in this DPA.
4. Categories of Data & Data Subjects
Data subjects: students enrolled in classes created by School-affiliated teachers; teachers employed by the School; parents linked to those students.
Categories of Student Data processed:
Identifiers: name, email, grade level, Google account ID (when SSO is used);
Engagement metadata: timestamps, session duration, paste-detection signals, AI integrity flags;
Voluntary self-identification (when provided): English Learner level, home language, interests.
The Service Provider does not knowingly collect biometric data, geolocation data, government identifiers, financial information, or health information.
5. Purpose Limitation & Permitted Uses
The Service Provider will process Student Data only for the following purposes:
Delivering the educational service to the School and its Students;
Maintaining, securing, and improving the Service in ways that are not directed to identifiable individuals;
Generating aggregate, de-identified analytics that cannot reasonably be re-identified;
Evaluating and improving the accuracy of automated scoring, using (a) aggregate statistics containing no Student Data, and (b) a limited number of individual writing excerpts that have been de-identified, human-reviewed, and stored with no link to any Student, School, or class. Such excerpts are used solely for scoring quality assurance, are never used to train third-party AI models, and are never disclosed to third parties for their own purposes. The School may opt out of excerpt retention by written notice, without affecting the Service;
Complying with legal obligations (subpoenas, court orders, statutory requirements).
Any other use requires the School's prior written consent.
6. Security Measures
The Service Provider maintains administrative, physical, and technical safeguards reasonably designed to protect Student Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These include:
Encryption in transit: all client-server traffic uses TLS 1.2 or higher;
Encryption at rest: the production database is encrypted at rest by the cloud provider; data at rest with the AI sub-processor is encrypted using AES-256 per the sub-processor's published security posture;
Access control: role-based authorization (student / teacher / parent / superuser); session timeouts; soft-delete with grace period for parent-requested deletion;
Audit logging: account/data deletion events are recorded in an internal audit log retained for compliance review;
Authentication: Google OAuth 2.0 with no plaintext password storage by the Service Provider;
Application security: Content Security Policy, X-Frame-Options, HSTS, output escaping, parameterized queries, and rate limiting on submission and authentication endpoints;
Vendor diligence: Sub-processors are vetted for educational-technology-appropriate security practices.
The Service Provider periodically reviews and updates these measures.
7. Sub-processors
The Service Provider engages Sub-processors to deliver the Service, described by function below. The current vendor identities and processing locations are maintained in the Service Provider's sub-processor list, which is incorporated into this DPA by reference.
Google Classroom (optional integration; disabled by default) — where a teacher links one of their classes to a Google Classroom course, the Service Provider posts the assignment title, description, due date, and a workspace link into that course, and writes the resulting grade back to the Classroom gradebook. Students are matched to the course's existing roster by school email address or Google account identifier. No student writing content is transmitted. Linking requires a Google permission prompt separate from ordinary sign-in. Data posted in this way lands in the School's own Google Workspace for Education tenant and is governed by the School's existing agreement with Google. The School may direct that this integration be disabled, and may also control it through its own Google Workspace administration.
Teacher-connected AI assistant (optional integration; disabled by default) — a teacher may connect an outside AI assistant to their own account in order to ask questions about their own classes. Nothing is transmitted unless that teacher completes a consent screen naming the data categories. What is sent: class names, student display names, grade level, assignment titles and due dates, completion status, scores, and last-active dates, for the connecting teacher's own classes only. What is not sent: student writing content, student email addresses, passwords, or login credentials, or any data from another teacher's classes. Access is limited to the classes that teacher owns or co-teaches, is re-verified on every request, ends immediately on disconnection or on removal of the teacher role, and every request is logged against that teacher's account. Data sent through such a connection arrives in the teacher's or School's own account with that provider and is governed by the agreement between that account holder and the provider; the Service Provider makes no representation as to that provider's training, retention, or residency practices. The School may instruct the Service Provider in writing to disable this feature for its teachers, and the Service Provider will do so.
AI sub-processor — AI inference for coaching-feedback generation. Student writing content and assignment context are transmitted; submissions are associated only with an opaque token internal to the Service (no student names, email addresses, or account identifiers). United-States-based processing. Per the Service Provider's written agreement with the vendor, inputs are not used to train, fine-tune, or otherwise improve AI models. Default safety retention is up to thirty (30) days for abuse monitoring, after which content is deleted. The vendor maintains SOC 2 Type 2, ISO/IEC 27001:2022, and ISO/IEC 27701:2019 certifications, with AES-256 encryption at rest and TLS 1.2+ in transit, and a signed DPA incorporated into its Services Agreement.
Identity provider (OAuth) — sign-in only; no Student Data flows back beyond what is required to authenticate.
Application hosting and database provider — runs the Service infrastructure under encryption-at-rest defaults.
Error monitoring (when enabled) — configured to scrub Student Data from event payloads.
The Service Provider will provide reasonable advance notice of changes to its Sub-processor list. The School may object to a new Sub-processor in writing, in which case the parties will work in good faith to find an alternative.
The two optional integrations above are characterised as integration partners rather than Sub-processors: the Service Provider has not engaged them to process Student Data on its behalf. In each case a teacher connects an account that the teacher or the School already holds with that provider, data moves at the teacher's direction, and the receiving provider processes it under its own agreement with the teacher or the School. They are disclosed here, and on the Service Provider's sub-processor list, so that the School can decide whether to permit them. Because both are authorised using the Google account a teacher signs in with, the School should require its teachers to sign in using School-issued accounts.
AI Sub-Processor — FERPA Flow-Down
The Service Provider's engagement of an AI sub-processor for coaching-feedback generation is consistent with FERPA's school official exception (§ 99.31(a)(1)). The AI sub-processor acts under the direct control of the Service Provider, which in turn processes Student Data on the School's behalf. The Service Provider's written agreement with the sub-processor prohibits secondary use, redisclosure, and retention beyond what is necessary to deliver the service, and limits processing to the purposes described in this DPA.
AI Sub-Processor — California Flow-Down
The Service Provider's written agreement with its AI sub-processor extends the obligations of California's Student Online Personal Information Protection Act (SOPIPA, Bus. & Prof. Code § 22584) and AB 1584 (Ed. Code § 49073.1) to processing performed on the Service Provider's behalf, including the prohibitions on (i) targeted advertising directed at students, (ii) creating student profiles for any purpose other than the educational service, and (iii) selling Student Data.
AI Sub-Processor — Identifier Minimization
The Service Provider does not transmit student names, email addresses, or account identifiers to its AI sub-processor for coaching-feedback generation. Submitted content is associated only with an opaque token internal to the Service. The optional teacher-connected AI assistant described in Section 7 is the sole exception: it transmits student display names and progress data (never student writing content, email addresses, or credentials), only after the connecting teacher approves, and only for that teacher's own classes. The School may direct that it be disabled.
8. Data Subject Rights
The School retains all rights of access, correction, and deletion over Student Data and is the entity responsible for responding to requests from Students or parents under FERPA, COPPA, and applicable state law.
The Service Provider will, on the School's reasonable written request, assist the School in:
Providing access to a Student's records;
Correcting inaccurate Student Data;
Deleting Student Data per Section 11.
Parent-initiated deletion requests received directly by the Service Provider are honored as a 30-day soft-delete with grace period; the Service Provider notifies the relevant teacher's School where applicable.
9. Breach Notification
If the Service Provider becomes aware of an unauthorized acquisition or disclosure of unencrypted Student Data, or any other security incident that materially compromises the confidentiality, integrity, or availability of Student Data ("Security Incident"), the Service Provider will:
Notify the School without undue delay and in any event within seventy-two (72) hours of confirmed discovery;
Provide the School with information reasonably needed to assess and respond to the incident, including the nature of the data involved, the affected Students (when identifiable), and remediation steps taken;
Cooperate with the School in any required notifications to parents, regulators, or other third parties.
The Service Provider's notification of a Security Incident is not an acknowledgement of fault or liability.
10. Audit & Review
Once per calendar year and on reasonable written notice, the School (or its independent auditor bound to comparable confidentiality) may request a written summary of the Service Provider's data-protection practices, including a description of security controls, the current Sub-processor list, and any material changes since the last review. The Service Provider will respond within thirty (30) days.
On-site audits are not available for Service Providers of this scale; written documentation, security questionnaires, and vendor-attestation forms are the typical mechanisms.
11. Return & Deletion of Data
On termination of the underlying service relationship, or at any time upon the School's written request, the Service Provider will, at the School's election:
Return all Student Data to the School in a structured, commonly used, machine-readable format (CSV/JSON ZIP exports as currently supported by the Service); and/or
Delete all Student Data from production systems within thirty (30) days, with database backups purged on the next routine rotation cycle (typically within sixty (60) days).
The Service Provider will provide written confirmation that deletion has occurred. De-identified, aggregated analytics that cannot reasonably be re-identified may be retained, as may de-identified writing excerpts retained for scoring quality assurance under Section 5, which carry no link to any Student and therefore cannot be located or returned by reference to a Student record.
12. Term & Termination
This DPA remains in effect for as long as the Service Provider processes Student Data on the School's behalf. Either party may terminate this DPA with thirty (30) days' written notice. Termination triggers the data-return-or-deletion process in Section 11.
Sections 6 (Security Measures — for data not yet returned/deleted), 9 (Breach Notification — for incidents predating termination), 11 (Return & Deletion), 13 (Liability), and 14 (Governing Law) survive termination.
13. Liability & Indemnification
Each party is responsible for its own negligent or wrongful acts to the extent permitted by applicable law. The Service Provider's aggregate liability under this DPA is capped at the greater of (a) the fees paid by the School to the Service Provider in the twelve (12) months preceding the event giving rise to the claim, or (b) one thousand U.S. dollars ($1,000) for free-tier accounts.
Nothing in this DPA limits liability for fraud, willful misconduct, or any other liability that cannot be limited under applicable law.
Note for review: Liability caps in school-vendor agreements are commonly negotiated. Districts often require uncapped liability for breach of confidentiality or violations of student privacy law; align this section with your district's standard before signing.
14. Governing Law
This DPA is governed by the laws of the State in which the School is located, without regard to its conflict-of-laws principles. The parties consent to the exclusive jurisdiction of the state and federal courts located in that State for any dispute arising out of or related to this DPA.
15. Signatures
By signing below, each party agrees to be bound by this Data Processing Agreement.