Data Processing Agreement

Draft — August 2026

This is a draft template, not a signed agreement

This page describes the terms caseload.cloud is prepared to offer a school or district that requires a data-sharing or data processing agreement before staff can use an outside tool with student-related information. It isn't a substitute for review by your district's own counsel, and it isn't in effect until both sides sign an actual copy. If your district needs one, email hello@caseload.cloud and we'll work through it with you.

Parties

This Agreement is between the school or district ("District") and the operator of caseload.cloud ("Vendor"), for a teacher or staff member employed by the District who uses the Service with information related to the District's students.

Role under FERPA

Vendor acts as a "school official" with a legitimate educational interest under FERPA's outsourcing exception (34 CFR §99.31(a)(1)), performing an institutional function (caseload planning and IEP tracking) that the District would otherwise perform itself, under the District's direct control regarding the use and maintenance of education records.

Data covered

This Agreement covers information entered into caseload.cloud by District staff about District students, including but not limited to: student initials, grade, and disability category; IEP dates and goals; service logs; accommodations; and parent/guardian contact information ("Covered Data"). The District directs its staff to use student initials rather than full legal names.

Permitted use

Vendor will use Covered Data only to operate the Service for the District's staff. Vendor will not:

  • Sell Covered Data or share it with third parties for their own purposes
  • Use Covered Data for advertising, profiling, or marketing to students or families
  • Use Covered Data to train machine learning models
  • Share Covered Data across different customer accounts

Security measures

Vendor maintains the security measures described on the Security page, including encryption in transit and at rest, hashed credential storage, and per-account data isolation.

Subprocessors

Vendor uses the subprocessors listed on the Security page (currently: Google Cloud, Google Sign-In, Stripe, Resend) solely to operate the Service, and will notify the District before adding a new subprocessor that will process Covered Data.

Breach notification

Vendor will notify the District without undue delay, and in any case within 5 business days of confirming a breach, if it discovers unauthorized access to or disclosure of Covered Data.

Data deletion and return

District staff may delete individual student records at any time, and may permanently delete their entire account and all associated Covered Data at any time from within the Service. Upon termination of this Agreement or request from the District, Vendor will delete any remaining Covered Data within 30 days, except where retention is required by law.

Term and termination

This Agreement remains in effect while District staff have active accounts using the Service with Covered Data, and either party may terminate it with 30 days' written notice.

Contact

To execute a signed copy of this Agreement, email hello@caseload.cloud.