Data Processing Addendum
Standard contractual terms for schools and school boards.
Last updated: September 6, 2026
Why this document matters
This DPA is a legally binding contract that puts our privacy commitments in writing. It demonstrates that if we fail to protect student data as promised, your institution has legal recourse. This is your "skin in the game" guarantee.
1. Parties
This Data Processing Addendum (“DPA”) is entered into between:
- “Institution” — the school, school board, or educational organization agreeing to these terms.
- “Argraide” — Argraide Inc., the provider of the educational technology platform.
2. Definitions
- “Student Data” means any information relating to a student that is collected, stored, or processed through the Platform.
- “Personal Information” has the meaning given under MFIPPA, FIPPA, PIPEDA, and other applicable privacy legislation.
- “Platform” means the Argraide educational technology service.
- “Processing” means any operation performed on Student Data.
3. Scope of Processing
Argraide processes the following categories of data:
| Data Category | Collected? | Notes |
|---|---|---|
| Student Names | NO | Random usernames only |
| Student Emails / Phone | NO | Sign-in is a username plus a three-emoji code the student chooses, stored as a bcrypt hash |
| Student Photos / Location | NO | Not collected |
| Learning Progress & Scores | YES | Per-question results, attempts, hints and time, linked to the anonymous account only; shown to the teacher |
| In-Activity AI Helper Summaries | YES* | *Only when the teacher has the helper on. An AI-written summary of the help session is kept for the teacher; the conversation is not stored. Teachers can turn the helper off per activity. |
| Live-Session Display Names & Responses | YES* | *Chosen by the participant, no account; visible to the facilitator; deleted automatically 30 days after the session |
| Teacher Nicknames for Students | YES* | *Encrypted in the teacher's browser with a key generated on their device; we store ciphertext only and cannot read it |
4. Data Location
All Student Data is stored exclusively in Canada, specifically in AWS's Montreal data center (ca-central-1).
Two kinds of requests are processed outside Canada, by the subprocessors listed in Section 7, and neither carries a student name, username, email or account identifier:
- AI model requests (United States): activity generation and translation use teacher-authored content only. The optional in-activity helper sends the student's typed question, the text visible on their screen and their progress in that activity. The Institution's teachers can switch the helper off for any activity, and an organization-wide switch is planned.
- Application delivery: pages are served through a global content delivery network that stores no Student Data.
Product analytics runs only on teacher-facing pages and receives no Student Data.
5. Security Measures
- Encryption in transit (TLS 1.2 or higher, 1.3 where supported)
- Encryption at rest (AES-256)
- Row-level security policies on all database tables
- Student emoji codes and teacher passwords stored as bcrypt hashes
- Teacher-defined nicknames encrypted in the teacher's browser (AES-256-GCM) with a device-generated key that never reaches Argraide
- Continuous dependency and access monitoring; an independent penetration test is planned and its summary is available to the Institution once complete
- Student activity records (progress, per-question results, helper summaries) are stored only against the anonymous account and deleted with it
6. Data Retention & Deletion
- Student Data is retained while the student account exists. A student can delete their own account at any time from their dashboard, which removes their progress records and helper summaries immediately.
- Live-session display names and responses are deleted automatically 30 days after the session.
- Institution may request deletion of any student, class or account at any time by contacting support@argraide.com.
- Deletion requests are processed within 72 hours.
7. Subprocessors
| Subprocessor | Purpose | Location | Student Data? |
|---|---|---|---|
| Supabase | Database, storage and authentication | Canada (Montreal) | Yes (progress records; encrypted at rest) |
| Vercel | Application hosting | Global CDN | No (stateless) |
| Stripe | Teacher payments and payouts | USA (PCI-DSS) | No |
| Google (Gemini) | AI activity generation, translation, images, read-aloud speech (activity text only), in-activity helper | USA | Helper only: student's typed question, on-screen text and activity progress, with no identifiers |
| OpenAI | AI activity generation and quality review | USA | No |
| Anthropic | AI activity generation and quality review | USA | No |
| PostHog | Product analytics, teacher pages only | USA / EU | No |
| Resend | Email to teacher accounts | USA | No |
| Google Maps | School lookup on teacher signup | USA | No |
Argraide holds evaluation API keys for two further model providers (DeepSeek, Moonshot AI). Neither is enabled for any task, neither can receive Student Data (the in-activity helper is restricted in code to Google, OpenAI and Anthropic), and the Institution is notified before either is used for activity generation.
8. Institution Rights
The Institution has the right to:
- Request a copy of all Student Data associated with their account
- Request deletion of all Student Data at any time
- Conduct or request a security audit (with 30 days notice)
- Receive breach notification within 72 hours of discovery
9. Liability & Indemnification
Argraide shall indemnify and hold harmless the Institution from any claims, damages, or expenses arising from Argraide's breach of this DPA or applicable privacy laws, including but not limited to MFIPPA, FIPPA, PIPEDA, and Ontario Bill 194.
10. Term & Termination
This DPA remains in effect for the duration of the service agreement. Upon termination,Argraide will delete all Student Data within 30 days unless legally required to retain it.
Need a customized DPA? Contact us at support@argraide.com