Data Processing Agreement
Draft — August 2026
This is a draft template, not a signed agreement
This page describes the terms caseload.cloud is prepared to offer a school or district that requires a data-sharing or data processing agreement before staff can use an outside tool with student-related information. It isn't a substitute for review by your district's own counsel, and it isn't in effect until both sides sign an actual copy. If your district needs one, email hello@caseload.cloud and we'll work through it with you.
Parties
This Agreement is between the school or district ("District") and the operator of caseload.cloud ("Vendor"), for a teacher or staff member employed by the District who uses the Service with information related to the District's students.
Role under FERPA
Vendor acts as a "school official" with a legitimate educational interest under FERPA's outsourcing exception (34 CFR §99.31(a)(1)), performing an institutional function (caseload planning and IEP tracking) that the District would otherwise perform itself, under the District's direct control regarding the use and maintenance of education records.
Data covered
This Agreement covers information entered into caseload.cloud by District staff about District students, including but not limited to: student initials, grade, and disability category; IEP dates and goals; service logs; accommodations; and parent/guardian contact information ("Covered Data"). The District directs its staff to use student initials rather than full legal names.
Permitted use
Vendor will use Covered Data only to operate the Service for the District's staff. Vendor will not:
- Sell Covered Data or share it with third parties for their own purposes
- Use Covered Data for advertising, profiling, or marketing to students or families
- Use Covered Data to train machine learning models
- Share Covered Data across different customer accounts
Security measures
Vendor maintains the security measures described on the Security page, including encryption in transit and at rest, hashed credential storage, and per-account data isolation.
Subprocessors
Vendor uses the subprocessors listed on the Security page (currently: Google Cloud, Google Sign-In, Stripe, Resend) solely to operate the Service, and will notify the District before adding a new subprocessor that will process Covered Data.
Breach notification
Vendor will notify the District without undue delay, and in any case within 5 business days of confirming a breach, if it discovers unauthorized access to or disclosure of Covered Data.
Data deletion and return
District staff may delete individual student records at any time, and may permanently delete their entire account and all associated Covered Data at any time from within the Service. Upon termination of this Agreement or request from the District, Vendor will delete any remaining Covered Data within 30 days, except where retention is required by law.
Term and termination
This Agreement remains in effect while District staff have active accounts using the Service with Covered Data, and either party may terminate it with 30 days' written notice.
Contact
To execute a signed copy of this Agreement, email hello@caseload.cloud.