Effective Date: May 15, 2026 · Last Updated: May 15, 2026 · Version 1.0
Governing Law: Delaware, United States
Parties: SenseiEdu ("Data Processor") and the contracting School ("Data Controller")
Contact: info@senseiedu.com
Private and Independent School Context
This DPA is designed for private, independent, and international schools. Such schools are generally not subject to FERPA or IDEA, which apply to publicly funded institutions. SenseiEdu voluntarily applies Student Data protection principles consistent with FERPA-equivalent standards as best practice.
Article 1. Definitions
"Controller" — the entity determining the purposes and means of processing Personal Data. In this Agreement: the School.
"Processor" — the entity processing Personal Data on behalf of the Controller. In this Agreement: SenseiEdu.
"Sub-processor" — any third party engaged by SenseiEdu to process Personal Data under this Agreement.
"Personal Data" — any information relating to an identified or identifiable natural person under applicable data protection law.
"Student Data" — any information relating to an identifiable student entered into the platform by Users on behalf of the School.
"Student Support Records" — records created within the platform by Users, including student support plans, progress reports, and notes.
"Processing" — any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.
"AI Features" — optional tools powered by OpenAI, including Chatbot assistance and AI-Assisted Section Drafting features.
"AI-Generated Output" — any content produced by AI-Assisted Section Drafting features based on User inputs.
"Data Breach" — a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
Article 2. Subject Matter and Duration
2.1 Subject Matter
This Agreement governs the processing of Personal Data, including Student Data and Student Support Records, by SenseiEdu as Processor on behalf of the School as Controller, strictly for the purpose of providing the Services.
2.2 Nature of Processing
SenseiEdu processes Personal Data only to the extent necessary to provide the Services, which includes:
2.3 Scope of Student Support Records
Student Support Records are created directly by Users within the platform. External documents are not uploaded, stored, or managed within the platform.
2.4 Duration
This Agreement shall remain in force for the duration of the Principal Agreement and shall terminate automatically upon its expiration or termination, subject to post-termination obligations in Article 9.
2.5 Categories of Data Subjects
2.6 Types of Personal Data Processed
Article 3. Obligations of SenseiEdu as Processor
3.1 Processing on Documented Instructions
SenseiEdu shall process Personal Data only on documented instructions from the School. SenseiEdu shall not process Personal Data for any purpose beyond what is necessary to provide the Services, unless required by applicable law.
3.2 Confidentiality
SenseiEdu shall ensure that all personnel authorized to process Personal Data are subject to binding confidentiality obligations and have received appropriate data protection training.
3.3 Security Measures
SenseiEdu shall implement and maintain appropriate technical and organizational measures to protect Personal Data, including:
3.4 Sub-processors
The School grants SenseiEdu general authorization to engage sub-processors. SenseiEdu shall:
3.5 Data Subject Rights Assistance
SenseiEdu shall assist the School in fulfilling its obligations to respond to data subject rights requests under applicable law, including rights of access, rectification, erasure, restriction, portability, and objection.
3.6 Data Protection Impact Assessments
Where required by applicable law, SenseiEdu shall provide reasonable assistance to the School in conducting data protection impact assessments (DPIAs) and prior consultations with supervisory authorities.
3.7 Audit Rights
SenseiEdu shall make available to the School all information reasonably necessary to demonstrate compliance. Audits are subject to 30 days' advance written notice, conducted during business hours, with the auditor subject to confidentiality obligations.
Article 4. Obligations of the School as Controller
The School represents, warrants, and agrees that:
Article 5. AI-Assisted Processing and Output Ownership
5.1 Scope
SenseiEdu provides AI-Assisted Section Drafting features and Chatbot assistance as part of the Services.
5.2 Processing Limitations
SenseiEdu represents and warrants that:
5.3 AI Output Ownership
As between SenseiEdu and the School, the School owns all AI-Generated Outputs produced from its Users' inputs. SenseiEdu assigns to the School all rights, title, and interest in AI-Generated Outputs.
5.4 Third-Party AI Sub-processors
SenseiEdu uses OpenAI as its AI sub-processor. OpenAI is subject to a prohibition on using Student Data for model training, deletion of inputs within 30 days, and encryption of all data in transit and at rest.
5.5 Human Oversight
SenseiEdu does not engage in automated decision-making within the meaning of GDPR Article 22. All AI outputs require affirmative human review before being applied to any student record.
Article 6. Data Breach Notification and Response
6.1 Notification Obligations
In the event of a confirmed or reasonably suspected Data Breach, SenseiEdu shall:
6.2 Breach Notification Content
Notifications shall include: nature of the breach, categories and number of affected data subjects, contact details, likely consequences, and measures taken or proposed.
6.3 School Responsibilities
The School, as Data Controller, is responsible for notifying relevant supervisory authorities, students, parents, guardians, and other affected parties as required by applicable law.
Article 7. International Data Transfers
7.1 Transfer Mechanisms
Personal Data is stored and processed in the United States on Microsoft Azure infrastructure. The following transfer mechanisms apply:
7.2 Supplementary Measures
For international data transfers, SenseiEdu confirms the technical measures described in Article 3.3 apply as supplementary safeguards under the Schrems II framework.
Article 8. Student Data Governance
8.1 Student Data Commitments
8.2 Accreditation Compliance
The School is responsible for ensuring that its use of SenseiEdu is consistent with its accreditation obligations, including those imposed by NAIS, CIS, IB, Cambridge, or other applicable accreditation bodies.
8.3 Parental and Student Rights
The School is responsible for honoring student, parent, and guardian data rights under applicable law, including rights to access, correct, and request deletion of student records. SenseiEdu shall provide reasonable technical assistance.
Article 9. Data Retention and Deletion
9.1 Deletion During Active Subscription
The School may delete specific Student Data at any time. Upon confirmation, active data is permanently deleted within 30 days, and backup copies within 90 days. Deleted data cannot be recovered.
9.2 Post-Termination Deletion
9.3 Confirmation of Deletion
Upon written request, SenseiEdu will provide written confirmation of deletion within 30 days of completing the deletion.
9.4 Free Trial Deletion
SenseiEdu may permanently delete Free Trial accounts and all associated data if the School does not convert to a paid subscription, or if the account has been inactive for 180 consecutive days, following 14 days' written notice.
Article 10. Liability and Indemnification
10.1 Processor Liability
SenseiEdu shall be liable to the School for damages caused by processing that does not comply with this Agreement or applicable data protection law.
10.2 Controller Liability
The School shall be liable for damages caused by its own non-compliance with applicable data protection law.
10.3 Indemnification
Each party agrees to indemnify and hold harmless the other party from third-party claims arising from that party's material breach of this Agreement or applicable data protection law.
Article 11. Governing Law and Dispute Resolution
11.1 Governing Law
This Agreement shall be governed by the laws of the State of Delaware, United States, except where mandatory data protection law requires another jurisdiction's law.
11.2 Jurisdiction
Any dispute shall be resolved by binding arbitration in accordance with the Principal Agreement, except where mandatory provisions of applicable law require otherwise.
11.3 Regulatory Cooperation
Each party shall cooperate in good faith with relevant supervisory authorities in connection with any regulatory investigation.
Article 12. General Provisions
12.1 Order of Precedence
In the event of conflict: (1) applicable mandatory law; (2) SCCs/IDTA where applicable; (3) this DPA; (4) the Order Form; (5) the Terms and Conditions; (6) the Privacy Policy.
12.2 Amendments
This Agreement may be amended only by written agreement signed or electronically accepted by both parties. Material changes will be communicated with no less than 30 days' prior notice.
12.3 Severability
If any provision is found invalid, it shall be modified to the minimum extent necessary; remaining provisions continue in full force.
Schedule A — Details of Processing Activities
Subject Matter: Processing of Student Data and Student Support Records to deliver student support platform services.
Duration: For the term of the Principal Agreement between SenseiEdu and the School.
Nature of Processing: Storage, retrieval, structuring, display, AI-assisted drafting, sharing within School account, and deletion.
Purpose: Student support planning, progress reporting, internal notes, and staff collaboration.
Data Subjects: Students (including minors), school staff and authorized Users, and incidentally parents and guardians.
Types of Personal Data: Student names, grade levels, learning profiles, evaluation data; support plans, progress reports, and internal notes; roster data; User names, email addresses, roles, and authentication data; IP addresses, session data, and audit logs.
Special Categories: May include data relating to learning differences, disabilities, behavioral profiles, or health information. The School is responsible for establishing a valid legal basis under Article 9(2) GDPR.
Processing Location: United States (Microsoft Azure infrastructure). Cross-border transfers subject to Article 7.
Schedule B — Approved Sub-processors
Microsoft Azure — Cloud hosting, infrastructure, and platform security monitoring. SOC 2, ISO 27001, and GDPR compliance.
Google Workspace — Single Sign-On authentication. Processes User names, email addresses, and domain only. No Student Data shared.
OpenAI — AI-assisted drafting features. Subject to prohibition on model training with Student Data; deletion of inputs within 30 days; encryption in transit and at rest.
Google Analytics — Website usage analytics. Anonymized usage data from the public website only. No Student Data shared.
Schedule C — EU Standard Contractual Clauses
Where Personal Data originates from the EEA, the Standard Contractual Clauses (Module 2: Controller to Processor) approved by European Commission Decision 2021/914 are incorporated by reference.
Clause 9: Option 2 — General written authorization. Notice period: 30 days.
Clause 17: Governing Law — The law of Ireland.
Clause 18: Jurisdiction — Courts of Ireland.
Annex I.A: Data Exporter: The School. Data Importer: SenseiEdu.
Annex II: Technical Measures as described in Article 3.3.
Schedule D — UK International Data Transfer Agreement (IDTA)
Where Personal Data originates from the United Kingdom, the IDTA issued by the UK ICO is incorporated by reference.
Exporter: The School. Importer: SenseiEdu.
Selected SCCs: EU SCCs Module 2 (Schedule C), used as Approved EU SCCs for IDTA purposes.
Review Date: Annually or upon material change to processing activities or applicable law.
© 2026 SenseiEdu. All Rights Reserved.