Skip to content

Website legal draft · July 27, 2026

Data processing addendum framework

This framework identifies the terms a customer DPA must settle. It is not an offer, signed addendum, or authorization to process real student or guardian data.

1. Parties, roles, and precedence

The final addendum must identify the correct AcademyTempo legal entity and customer, define their controller, business, processor, service-provider, school-official, or comparable roles by jurisdiction, and state how the addendum interacts with the order form and service agreement.

2. Processing details and instructions

A signed schedule must state the service purpose, duration, data subjects, approved data categories, sensitive-data exclusions, customer instructions, authorized users, locations, and features.

AcademyTempo should process customer personal data only on documented instructions, except where law requires otherwise, and should notify the customer when legally permitted if an instruction appears unlawful.

3. Minor and education data

No public page authorizes real minor-data processing. The customer must establish its authority, notices, consents, and school-official or comparable basis before providing data.

The final agreement must prohibit sale, cross-context behavioral advertising, unrelated profiling, provider model training, and use outside the contracted educational or academy purpose.

4. Confidentiality and security

Authorized personnel and contractors must be bound by confidentiality. The final security exhibit must describe approved technical and organizational measures, risk review, access controls, tenant isolation, encryption, logging limits, vulnerability handling, business continuity, and incident exercises.

The current technical boundary is described on the Security page, which is not a substitute for a signed exhibit.

5. Subprocessors and transfers

The final addendum must incorporate an approved provider register, written flow-down obligations, change notice, a reasonable objection process, processing locations, and any required transfer mechanism.

The current draft register is available on the Subprocessors page.

6. Requests, assessments, and audits

AcademyTempo should provide reasonable assistance with verified individual requests, customer privacy assessments, regulator or school inquiries, and evidence-based audits, subject to confidentiality, security, scope, frequency, and cost protections in the final agreement.

7. Security incidents

The final agreement must define a security-incident standard, prompt customer notice without inventing one universal statutory deadline, required notice contents, containment and cooperation duties, evidence preservation, subprocessor coordination, and allocation of communication authority.

8. Return, deletion, and retention

The final addendum must state exact retention classes, deletion triggers, legal holds, backup treatment, customer export timing, provider deletion, and deletion evidence. These periods remain unapproved launch blockers.

9. Required schedules before signature

  • Processing description and approved feature list.
  • Data-category and data-subject inventory.
  • Technical and organizational measures.
  • Subprocessor register and processing locations.
  • Retention and deletion schedule.
  • Customer instructions, contacts, jurisdictions, and authority evidence.

A pilot inquiry may be started through the privacy contact path without including student information.