Skip to main content
ClassQuip

Effective date: October 7, 2026

Last updated: October 7, 2026

Data Processing Addendum (DPA)

Supplement to the ClassQuip Agreement governing Student Data processing for Districts as Controller and ClassQuip as Processor.

Introduction

This Data Processing Addendum (“DPA”) supplements the Master Services Agreement, Terms of Service, and any executed Order Forms (collectively, the “Agreement”) entered into by and between ClassQuip Inc., a Delaware corporation (“ClassQuip,” “Processor,” or “we”), and the Local Educational Agency, school district, or educational institution (“District,” “Customer,” or “Controller”).

This DPA governs the processing of Student Data and Personally Identifiable Information (PII) in connection with the ClassQuip platform at classquip.com.

1. Regulatory framework & status

1.1 School official designation — The parties acknowledge and agree that ClassQuip operates as a designated School Official under the Family Educational Rights and Privacy Act (FERPA, 34 CFR § 99.31(a)(1)(i)(B)) with a legitimate educational interest in performing outsourced institutional services. ClassQuip remains under the direct control and direction of the District with respect to the use, maintenance, and handling of education records and Student Data.

1.2 Statutory compliance — ClassQuip warrants that its data handling, security architecture, and sub-processor management strictly comply with all applicable federal and state student privacy statutes, including: the Family Educational Rights and Privacy Act (FERPA); the Children’s Online Privacy Protection Act (COPPA); the Student Online Personal Information Protection Act (SOPIPA); state student privacy laws (including CA AB 1584/SOPIPA, NY Education Law 2-d, IL SOPPA, and applicable state NDPA standards); and the Student Privacy Pledge framework.

2. Processing mandates & prohibitions

2.1 Authorized instructions only — ClassQuip shall collect, process, store, and transmit Student Data strictly on behalf of the District and in accordance with the documented instructions of the District. ClassQuip shall not process Student Data for any purpose other than delivering the contracted virtual classroom services, compliance logging, and AI-assisted instructional tools.

2.2 Express prohibitions — ClassQuip explicitly agrees and covenants that it shall NOT: sell, rent, lease, or monetize Student Data under any circumstances (no data sales); use Student Data to create behavioral profiles of students or serve targeted advertisements within or outside the platform (no behavioral advertising); use Student Data, lesson content, room audio/video, or prompt inputs to train, fine-tune, or retrain public, commercial, or third-party Artificial Intelligence models or Large Language Models (LLMs) (no unapproved model training); or link Student Data with non-educational commercial data sources (no cross-context profiling).

3. Technical safeguards & AI anonymization

3.1 Encryption — In transit: all communications and media traffic are encrypted using TLS 1.3 for API/web endpoints and SRTP (Secure Real-time Transport Protocol) for WebRTC streaming. At rest: database records and S3 object stores are encrypted using industry-standard AES-256 encryption.

3.2 AI privacy layer (PII scrambler) — Before any user prompt, lesson plan generation request, or poll request is transmitted to LLM sub-processors, payload data passes through ClassQuip’s proprietary PII anonymization layer. This process strips and converts all student, teacher, and school identifiers into synthetic reference codes. Synthetic codes are re-mapped back to session data locally within ClassQuip’s AWS infrastructure so that third-party AI processors never receive raw PII.

4. Sub-processor management & notice workflow

4.1 Approved sub-processors — The District provides general authorization for ClassQuip to engage sub-processors to support infrastructure, AI processing, and platform analytics. ClassQuip’s core sub-processors are: Amazon Web Services (AWS) for cloud hosting and WebRTC infrastructure (US-East/West regions); OpenAI LLC for generative AI processing (operating under enterprise non-retention agreements; receiving anonymized payloads); and PostHog Inc. for application performance and telemetry monitoring (configured with PII stripping).

4.2 Notice & objection workflow — ClassQuip will provide the District with at least thirty (30) days’ advance written notice (via email or administrator portal update) before adding or replacing any sub-processor handling Student Data. The District may object to the appointment of a new sub-processor on reasonable privacy or security grounds by providing written notice within fourteen (14) days of receiving ClassQuip’s notification. Upon receipt of such objection, ClassQuip will work in good faith with the District to find a mutually acceptable technical resolution or alternative.

5. Security incident & breach notification

5.1 Breach notification SLA — In the event of a confirmed security breach, unauthorized access, or accidental disclosure affecting Student Data, ClassQuip will notify the affected District’s designated administrators in writing within twenty-four (24) to forty-eight (48) hours of confirmation.

5.2 Incident remediation & report — The notification shall include, to the extent known at the time: a description of the nature and scope of the security incident; the categories of Student Data affected; immediate remediation actions taken by ClassQuip to contain and resolve the breach; and contact information for ClassQuip’s lead security team handling the incident. ClassQuip will cooperate fully with the District in investigating the breach and fulfilling the District’s legal obligations to notify affected parents, students, and regulatory authorities.

6. District audit rights & compliance verification

Upon written request, ClassQuip shall provide the District with annual documentation verifying its security and privacy compliance posture. This may include summaries of third-party security assessments or penetration tests; proof of alignment with SOC 2 / NIST security standards; and completion of standard higher-education or K-12 security questionnaires (e.g., HECVAT or CAEK-12).

If the provided documentation is insufficient to verify compliance with this DPA, the District (or an independent certified third-party auditor approved by ClassQuip) may conduct a reasonable, mutually agreed-upon audit of ClassQuip’s data protection practices, subject to strict confidentiality non-disclosure terms and without causing unreasonable operational disruption.

7. Data return, deletion & contract termination

7.1 Deletion & export window — Upon termination or expiration of the Master Services Agreement, or upon written request from an authorized District administrator, ClassQuip shall provide the District with a complete, secure export of all Student Data and compliance logging files in a standard machine-readable format, and permanently delete, overwrite, and purge all Student Data stored on primary databases, AWS S3 object stores, and secondary backups within thirty (30) days.

7.2 Certification of destruction — Upon completion of the purge process, ClassQuip will provide written certification to the District confirming that all Student Data has been securely erased in compliance with NIST SP 800-88 guidelines.

8. State-specific addenda & NDPA execution

To ensure seamless compliance across all state jurisdictions, ClassQuip agrees to execute state-specific Data Privacy Agreements or exhibits—including the National Data Privacy Agreement (NDPA) and California Student Privacy Alliance (CSPA) exhibits—upon written request from any contracting District or state educational coalition.

9. Contact information

For inquiries, security notifications, or DPA execution requests, please contact: ClassQuip Inc., Attention: Data Privacy & Security Officer. Email: privacy@classquip.com. Website: classquip.com.