SenseiEdu Data Processing Agreement (DPA)

Effective Date: May 15, 2026 · Last Updated: May 15, 2026 · Version 1.0

Governing Law: Delaware, United States

Parties: SenseiEdu ("Data Processor") and the contracting School ("Data Controller")

Contact: info@senseiedu.com

Private and Independent School Context

This DPA is designed for private, independent, and international schools. Such schools are generally not subject to FERPA or IDEA, which apply to publicly funded institutions. SenseiEdu voluntarily applies Student Data protection principles consistent with FERPA-equivalent standards as best practice.

Article 1. Definitions

"Controller" — the entity determining the purposes and means of processing Personal Data. In this Agreement: the School.

"Processor" — the entity processing Personal Data on behalf of the Controller. In this Agreement: SenseiEdu.

"Sub-processor" — any third party engaged by SenseiEdu to process Personal Data under this Agreement.

"Personal Data" — any information relating to an identified or identifiable natural person under applicable data protection law.

"Student Data" — any information relating to an identifiable student entered into the platform by Users on behalf of the School.

"Student Support Records" — records created within the platform by Users, including student support plans, progress reports, and notes.

"Processing" — any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.

"AI Features" — optional tools powered by OpenAI, including Chatbot assistance and AI-Assisted Section Drafting features.

"AI-Generated Output" — any content produced by AI-Assisted Section Drafting features based on User inputs.

"Data Breach" — a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

Article 2. Subject Matter and Duration

2.1 Subject Matter

This Agreement governs the processing of Personal Data, including Student Data and Student Support Records, by SenseiEdu as Processor on behalf of the School as Controller, strictly for the purpose of providing the Services.

2.2 Nature of Processing

SenseiEdu processes Personal Data only to the extent necessary to provide the Services, which includes:

  • Storage and retrieval of Student Data and Student Support Records entered by the School;
  • Creation and management of student support plans, progress reports, and internal notes;
  • AI-assisted drafting of content within student support plans and progress reports;
  • Management of user accounts and access permissions;
  • Platform security, monitoring, and performance operations;
  • Any other processing expressly authorized in writing by the School.

2.3 Scope of Student Support Records

Student Support Records are created directly by Users within the platform. External documents are not uploaded, stored, or managed within the platform.

2.4 Duration

This Agreement shall remain in force for the duration of the Principal Agreement and shall terminate automatically upon its expiration or termination, subject to post-termination obligations in Article 9.

2.5 Categories of Data Subjects

  • Students enrolled at the School, including minors;
  • School staff and authorized Users;
  • Parents or guardians, to the extent their information is referenced in Student Data.

2.6 Types of Personal Data Processed

  • Student names, grade levels, learning profiles, and evaluation data;
  • Student Support Records including support plans, progress reports, and internal notes;
  • Student roster data;
  • User (staff) names, email addresses, roles, and authentication data;
  • Technical data including IP addresses, session data, and audit logs.

Article 3. Obligations of SenseiEdu as Processor

3.1 Processing on Documented Instructions

SenseiEdu shall process Personal Data only on documented instructions from the School. SenseiEdu shall not process Personal Data for any purpose beyond what is necessary to provide the Services, unless required by applicable law.

3.2 Confidentiality

SenseiEdu shall ensure that all personnel authorized to process Personal Data are subject to binding confidentiality obligations and have received appropriate data protection training.

3.3 Security Measures

SenseiEdu shall implement and maintain appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption in transit (TLS 1.2 or higher) and at rest;
  • Role-based access controls limiting access to authorized personnel only;
  • Mandatory two-factor authentication for all User accounts;
  • Audit logging of all access to and processing of Personal Data;
  • Regular security assessments and vulnerability management;
  • Incident response and data breach management procedures;
  • Cloud infrastructure hosted on Microsoft Azure with enterprise-grade security controls.

3.4 Sub-processors

The School grants SenseiEdu general authorization to engage sub-processors. SenseiEdu shall:

  • Maintain and make available a current list of sub-processors (see Schedule B);
  • Notify the School of any intended addition or replacement with no less than 30 days' prior notice;
  • Impose data protection obligations substantially equivalent to this Agreement on each sub-processor;
  • Remain fully liable to the School for sub-processors' performance.

3.5 Data Subject Rights Assistance

SenseiEdu shall assist the School in fulfilling its obligations to respond to data subject rights requests under applicable law, including rights of access, rectification, erasure, restriction, portability, and objection.

3.6 Data Protection Impact Assessments

Where required by applicable law, SenseiEdu shall provide reasonable assistance to the School in conducting data protection impact assessments (DPIAs) and prior consultations with supervisory authorities.

3.7 Audit Rights

SenseiEdu shall make available to the School all information reasonably necessary to demonstrate compliance. Audits are subject to 30 days' advance written notice, conducted during business hours, with the auditor subject to confidentiality obligations.

Article 4. Obligations of the School as Controller

The School represents, warrants, and agrees that:

  • It has a lawful basis for collecting and entering Student Data and Personal Data into the platform;
  • It has provided all required notices to and obtained all required consents from students, parents, and guardians;
  • It has the authority to instruct SenseiEdu to process Personal Data on its behalf;
  • It will ensure only authorized personnel are granted access;
  • It is responsible for responding to data subject rights requests and regulatory inquiries;
  • It will maintain appropriate records of processing activities as required by applicable law.

Article 5. AI-Assisted Processing and Output Ownership

5.1 Scope

SenseiEdu provides AI-Assisted Section Drafting features and Chatbot assistance as part of the Services.

5.2 Processing Limitations

SenseiEdu represents and warrants that:

  • Student Data processed through AI features is used solely to generate the specific output requested by the User;
  • Identifiable Student Data is not used to train, fine-tune, or improve any AI model;
  • AI-Generated Outputs are recommendations only and require review by registered Users;
  • SenseiEdu does not make automated decisions about students with significant effects without human review.

5.3 AI Output Ownership

As between SenseiEdu and the School, the School owns all AI-Generated Outputs produced from its Users' inputs. SenseiEdu assigns to the School all rights, title, and interest in AI-Generated Outputs.

5.4 Third-Party AI Sub-processors

SenseiEdu uses OpenAI as its AI sub-processor. OpenAI is subject to a prohibition on using Student Data for model training, deletion of inputs within 30 days, and encryption of all data in transit and at rest.

5.5 Human Oversight

SenseiEdu does not engage in automated decision-making within the meaning of GDPR Article 22. All AI outputs require affirmative human review before being applied to any student record.

Article 6. Data Breach Notification and Response

6.1 Notification Obligations

In the event of a confirmed or reasonably suspected Data Breach, SenseiEdu shall:

  • Notify the affected School without undue delay, and within 72 hours where practicable;
  • Provide sufficient information for the School to fulfill its own notification obligations;
  • Take immediate steps to contain, investigate, and remediate the breach;
  • Cooperate fully with the School in any breach investigation;
  • Document the breach and all remedial actions taken.

6.2 Breach Notification Content

Notifications shall include: nature of the breach, categories and number of affected data subjects, contact details, likely consequences, and measures taken or proposed.

6.3 School Responsibilities

The School, as Data Controller, is responsible for notifying relevant supervisory authorities, students, parents, guardians, and other affected parties as required by applicable law.

Article 7. International Data Transfers

7.1 Transfer Mechanisms

Personal Data is stored and processed in the United States on Microsoft Azure infrastructure. The following transfer mechanisms apply:

  • EEA: Standard Contractual Clauses (SCCs), Module 2 (Controller to Processor);
  • United Kingdom: UK International Data Transfer Agreement (IDTA);
  • Switzerland: EU SCCs supplemented by Swiss-specific modifications (FADP);
  • Japan: Cross-border transfer agreement under APPI Article 28;
  • China: PIPL compliance — School responsible for determining applicable pathway;
  • Singapore: PDPA Transfer Limitation Obligation contractual safeguards;
  • UAE: Federal PDPL contractual safeguards (DIFC/ADGM as applicable);
  • Canada: PIPEDA and Quebec Law 25 safeguards;
  • Other Jurisdictions: Appropriate safeguards as required by applicable local law.

7.2 Supplementary Measures

For international data transfers, SenseiEdu confirms the technical measures described in Article 3.3 apply as supplementary safeguards under the Schrems II framework.

Article 8. Student Data Governance

8.1 Student Data Commitments

  • Student Data is used only for the purpose of providing the Services;
  • Student Data is not disclosed to any third party without prior written consent of the School;
  • Student Data is not used to build profiles of students for non-educational purposes;
  • Student Data is not sold, rented, or used for advertising purposes.

8.2 Accreditation Compliance

The School is responsible for ensuring that its use of SenseiEdu is consistent with its accreditation obligations, including those imposed by NAIS, CIS, IB, Cambridge, or other applicable accreditation bodies.

8.3 Parental and Student Rights

The School is responsible for honoring student, parent, and guardian data rights under applicable law, including rights to access, correct, and request deletion of student records. SenseiEdu shall provide reasonable technical assistance.

Article 9. Data Retention and Deletion

9.1 Deletion During Active Subscription

The School may delete specific Student Data at any time. Upon confirmation, active data is permanently deleted within 30 days, and backup copies within 90 days. Deleted data cannot be recovered.

9.2 Post-Termination Deletion

  • Active Data: deleted within 30 days following the 30-day read-only export period;
  • Backup Copies: deleted within 90 days of account termination;
  • Security Logs: retained up to 12 months for legal compliance, then deleted;
  • AI-Generated Outputs: treated as Student Data and deleted accordingly;
  • Anonymized Data: may be retained indefinitely as it cannot be linked to any individual.

9.3 Confirmation of Deletion

Upon written request, SenseiEdu will provide written confirmation of deletion within 30 days of completing the deletion.

9.4 Free Trial Deletion

SenseiEdu may permanently delete Free Trial accounts and all associated data if the School does not convert to a paid subscription, or if the account has been inactive for 180 consecutive days, following 14 days' written notice.

Article 10. Liability and Indemnification

10.1 Processor Liability

SenseiEdu shall be liable to the School for damages caused by processing that does not comply with this Agreement or applicable data protection law.

10.2 Controller Liability

The School shall be liable for damages caused by its own non-compliance with applicable data protection law.

10.3 Indemnification

Each party agrees to indemnify and hold harmless the other party from third-party claims arising from that party's material breach of this Agreement or applicable data protection law.

Article 11. Governing Law and Dispute Resolution

11.1 Governing Law

This Agreement shall be governed by the laws of the State of Delaware, United States, except where mandatory data protection law requires another jurisdiction's law.

11.2 Jurisdiction

Any dispute shall be resolved by binding arbitration in accordance with the Principal Agreement, except where mandatory provisions of applicable law require otherwise.

11.3 Regulatory Cooperation

Each party shall cooperate in good faith with relevant supervisory authorities in connection with any regulatory investigation.

Article 12. General Provisions

12.1 Order of Precedence

In the event of conflict: (1) applicable mandatory law; (2) SCCs/IDTA where applicable; (3) this DPA; (4) the Order Form; (5) the Terms and Conditions; (6) the Privacy Policy.

12.2 Amendments

This Agreement may be amended only by written agreement signed or electronically accepted by both parties. Material changes will be communicated with no less than 30 days' prior notice.

12.3 Severability

If any provision is found invalid, it shall be modified to the minimum extent necessary; remaining provisions continue in full force.

Schedule A — Details of Processing Activities

Subject Matter: Processing of Student Data and Student Support Records to deliver student support platform services.

Duration: For the term of the Principal Agreement between SenseiEdu and the School.

Nature of Processing: Storage, retrieval, structuring, display, AI-assisted drafting, sharing within School account, and deletion.

Purpose: Student support planning, progress reporting, internal notes, and staff collaboration.

Data Subjects: Students (including minors), school staff and authorized Users, and incidentally parents and guardians.

Types of Personal Data: Student names, grade levels, learning profiles, evaluation data; support plans, progress reports, and internal notes; roster data; User names, email addresses, roles, and authentication data; IP addresses, session data, and audit logs.

Special Categories: May include data relating to learning differences, disabilities, behavioral profiles, or health information. The School is responsible for establishing a valid legal basis under Article 9(2) GDPR.

Processing Location: United States (Microsoft Azure infrastructure). Cross-border transfers subject to Article 7.

Schedule B — Approved Sub-processors

Microsoft Azure — Cloud hosting, infrastructure, and platform security monitoring. SOC 2, ISO 27001, and GDPR compliance.

Google Workspace — Single Sign-On authentication. Processes User names, email addresses, and domain only. No Student Data shared.

OpenAI — AI-assisted drafting features. Subject to prohibition on model training with Student Data; deletion of inputs within 30 days; encryption in transit and at rest.

Google Analytics — Website usage analytics. Anonymized usage data from the public website only. No Student Data shared.

Schedule C — EU Standard Contractual Clauses

Where Personal Data originates from the EEA, the Standard Contractual Clauses (Module 2: Controller to Processor) approved by European Commission Decision 2021/914 are incorporated by reference.

Clause 9: Option 2 — General written authorization. Notice period: 30 days.

Clause 17: Governing Law — The law of Ireland.

Clause 18: Jurisdiction — Courts of Ireland.

Annex I.A: Data Exporter: The School. Data Importer: SenseiEdu.

Annex II: Technical Measures as described in Article 3.3.

Schedule D — UK International Data Transfer Agreement (IDTA)

Where Personal Data originates from the United Kingdom, the IDTA issued by the UK ICO is incorporated by reference.

Exporter: The School. Importer: SenseiEdu.

Selected SCCs: EU SCCs Module 2 (Schedule C), used as Approved EU SCCs for IDTA purposes.

Review Date: Annually or upon material change to processing activities or applicable law.

© 2026 SenseiEdu. All Rights Reserved.