1. Parties & Definitions
This Student Data Privacy Agreement ("Agreement" or "DPA") is entered into between the local education agency or authorized organization listed in the executed Order Form ("District" or "LEA") and ConnectED.ai / Vavora Ventures, LLC("Operator" or "we").
Student Data means any information directly related to an identifiable student that is generated, transmitted, or stored in ConnectED.ai, including education records as defined under FERPA (20 U.S.C. § 1232g), and any data derived from those records through automated processing or AI inference.
Authorized Users means students enrolled at the District, school counselors/advisors employed or contracted by the District, and school administrators with a legitimate educational interest as defined in 34 CFR § 99.31(a)(1).
Eligible Student means a student who has reached age 18 or is attending a postsecondary institution, at which point FERPA rights transfer from parent to student.
Parent means a natural parent, guardian, or individual acting as a parent as defined in 34 CFR § 99.3, subject to the custody and eligibility provisions of Section 16.
2. Scope of Service
ConnectED.ai is an AI-powered college counseling and career readiness platform for high school students (grades 9–12). The platform enables students to:
- Build a college and career exploration plan
- Track application progress and FAFSA status
- Communicate with assigned school counselors or advisors
- Access AI-generated college recommendations and essay coaching
- Explore career pathways, salary data, and cost-of-living analysis
The Operator processes Student Data solely to deliver these services under the direction of the District, operating as a "school official" under 34 CFR § 99.31(a)(1) with a legitimate educational interest.
4. Prohibited Uses
The Operator expressly agrees not to:
- Sell or rent Student Data to any third party
- Use Student Data to advertise or market non-educational products or services to students, parents, or siblings
- Use Student Data to create or append to commercial profiles of students unrelated to the educational purpose
- Disclose Student Data to unauthorized parties, including data brokers, advertising networks, or social media platforms
- Use Student Data in aggregate or de-identified form in a way that could re-identify individual students
- Train AI/ML models on Student Data without a separate, written, district-authorized Data Use Agreement specifying the model, purpose, and opt-out mechanism
- Share Student Data with law enforcement except as required by a valid legal process (subpoena, court order) or a bona fide emergency under 34 CFR § 99.36
5. Access & Security Controls
The Operator maintains the following safeguards:
| Control | Implementation |
|---|---|
| Encryption in transit | TLS 1.3 enforced on all connections |
| Encryption at rest | AES-256 on PostgreSQL database and backups |
| Authentication | NextAuth.js with credential + OAuth flows; MFA available for admin accounts |
| Role-based access | 4-tier RBAC: Student, Advisor, School Admin, Super Admin — each scoped to their data |
| Audit logging | All access to student records by non-student users is logged with timestamp, user ID, and action |
| Least privilege | Advisors access only their assigned students; admins access only their school |
| Penetration testing | Annual third-party assessment; results shared with District on request |
| Vendor contracts | All subprocessors are bound by DPAs with equivalent protections |
6. Subprocessors & Onward Transfers
The Operator uses the following subprocessors that may have access to Student Data. Each is bound by contractual terms that provide equivalent protections to this Agreement:
| Subprocessor | Purpose | Data Minimization |
|---|---|---|
| Supabase / PostgreSQL | Hosted database | All student data; stored in US region |
| OpenAI (GPT-4o) | AI recommendations, essay coach, chat | Name, grade, GPA, interests, college list only — financial and living situation fields are never sent |
| Vercel | Application hosting and edge network | Request logs; no persistent student data |
| Nodemailer / SMTP | Transactional email (advisor notifications, account setup) | Email address and name only |
The Operator will provide 30 days' written notice before adding a new subprocessor that accesses Student Data. The District may object in writing; if the parties cannot agree, the District may terminate without penalty.
7. Parent / Eligible-Student Rights
Under FERPA (20 U.S.C. § 1232g) and Texas Education Code Chapter 26, parents have the following rights with respect to their child's education records held by the District (and, by extension, in ConnectED.ai as a school official):
Right to Inspect & Review (FERPA § 99.10)
Parents may request access to all education records within 45 days. Requests must be directed to the District. The Operator will fulfill District-directed data export requests within 5 business days.
Right to Request Amendment (FERPA § 99.20–99.22)
Parents may request correction of records believed to be inaccurate. Requests route to the District. If the District directs a correction, the Operator will apply it within 10 business days and log the change.
Right to Consent to Disclosures (FERPA § 99.30)
Student Data is not disclosed outside the school-official context without written consent, except for FERPA-exempt disclosures (health/safety emergencies, legal process). Each non-exempt disclosure is logged.
Right to Inspect the Disclosure Log (FERPA § 99.32)
The District may request the disclosure log at any time. The Operator maintains an immutable record of all external data flows, including which subprocessors received what data and why.
Right to Opt Out of Directory Information Designations
Districts may suppress individual directory fields (name, enrollment status, etc.) via the admin panel. Suppressed fields are excluded from all exports, reports, and AI prompts.
Rights Transfer at Age 18 (FERPA § 99.5)
When a student turns 18 or enrolls in a postsecondary institution, FERPA rights transfer to the student. The platform enforces this via a scheduled account-state check. The IRS dependent-student exception may be applied by District request.
Texas Ed Code Ch. 26 — Full Written Records Access
Texas parents have broader rights than FERPA alone: access to all written records about their child, including attendance, assessment scores, discipline records, and any data ConnectED.ai holds. Requests are honored within the 45-day FERPA window.
8. District Rights & Controls
The District retains the following controls at all times:
- School-initiated deletion: The District admin can permanently delete a student's data from the platform at any time via the admin panel or a written request to info@vavoraventures.tech. Deletion is completed within 30 days, except where retention is required by Texas records-retention schedules (see Section 9).
- Bulk data export: The District can export all data for all its students in CSV format from the admin panel, or in PDF format per student.
- User provisioning: Only the District admin can create, modify, or deactivate student accounts. Students cannot self-register.
- Advisor assignment: The District admin controls which advisor is assigned to which student. Advisors cannot reassign themselves.
- Directory suppression: The District can suppress individual directory-information fields per student to honor opt-out requests.
- Audit log access: District admins and super admins can view the full disclosure log for their school.
9. Retention & Deletion
| Data Category | Default Retention | Basis |
|---|---|---|
| Active student profile & application data | Duration of district contract + 1 year | Service delivery |
| Post-graduation retained fields (name, graduating class, school, outcome metrics) | 3 years post-graduation | Proof-of-value, program improvement |
| Advisor–student message threads | Duration of contract + 1 year | Compliance & audit |
| Audit/disclosure logs | 7 years | FERPA § 99.32 compliance |
| Backups | 90 days rolling | Disaster recovery |
| Parent request records | 7 years | FERPA compliance documentation |
A parent deletion request cannot remove data the District is legally required to retain under Texas records-retention schedules (19 TAC § 61.1023). Deletion in ConnectED.ai is always "District-authorized" — the Operator does not accept direct deletion orders from parents without a corresponding District instruction.
After the contract ends, the Operator will return or delete all Student Data within 60 days and provide written certification of deletion upon request.
10. Breach Notification
In the event of a confirmed or reasonably suspected security breach involving Student Data, the Operator will:
- Notify the District's designated privacy officer within 48 hours of discovery, via the contact provided in the Order Form
- Provide a written incident report within 7 calendar days, including: nature of the breach, data elements involved, estimated number of students affected, remediation steps taken, and contact for questions
- Cooperate with the District's breach response and notifications to affected families under Texas Ed Code § 521.053 and any applicable state law
- Not make any public statements about the breach before coordinating with the District
11. AI & Inference on Student Data
ConnectED.ai uses OpenAI GPT-4o to power college recommendations, the AI advisor chat, and essay coaching. The following rules govern AI use of Student Data:
Data minimization
Only the minimum data needed for the specific AI task is sent to OpenAI. The following fields are never included in AI prompts: economic situation, living situation, household financial data, profile photographs, and detailed disciplinary records.
No model training on student data
We use OpenAI's API with the "zero data retention" and "no training" configuration. Student data submitted in API calls is not used to train OpenAI's models. This is governed by our OpenAI Data Processing Agreement.
AI disclosures are logged
Every request that includes Student Data sent to a third-party AI service is recorded in the disclosure log (Section 14), identifying the student (by ID, not name, in the log), the purpose, and the subprocessor.
No autonomous decisions with legal effect
AI outputs (college recommendations, risk flags, plan stalling indicators) are presented to advisors and students as guidance, not determinations. No fully-automated decision with a legal or similarly significant effect is made about a student without human review.
12. COPPA / Under-13 Students
COPPA (15 U.S.C. § 6501 et seq.) applies to online services that collect personal information from children under 13. ConnectED.ai is designed for high school students (grades 9–12), but some 9th-grade students may be 13 years old.
School consent model: Where a District provisions student accounts and has agreed to this DPA, the District provides consent on parents' behalf for purely educational use, under the COPPA school consent exception (16 CFR § 312.5(b)(1)). The District must confirm it has provided appropriate parental notice before provisioning any student under 13.
Operator obligations for under-13 students:
- Collect only what is necessary for the educational service
- Provide parents the ability to review, correct, and delete their child's data
- Not condition participation on disclosure of more information than necessary
- Not share data with third parties except as permitted by the school consent
- Maintain a written retention policy (see Section 9) per the 2025 COPPA amendments
- Obtain separate consent before any third-party disclosure not covered by the school consent
The Operator does not operate a direct-to-consumer offering for students under 13 outside the school-provisioned context.
13. PPRA Compliance
The Protection of Pupil Rights Amendment (20 U.S.C. § 1232h) requires advance parental notice and opt-out rights for surveys that touch eight protected categories: political affiliation, mental health, sexual behavior, illegal behavior, religious beliefs, income, biometric data, and critical appraisals of family members.
ConnectED.ai does not administer surveys touching these categories. However, the platform's onboarding questionnaire collects economic context and living situation information. Districts must ensure:
- Parents receive advance notice of these questions as part of enrollment
- A documented opt-out mechanism exists (students can skip these fields)
- Any future survey added to the platform is reviewed for PPRA applicability before deployment
14. Disclosure & Audit Logging
FERPA § 99.32 requires that education records maintained by a school official include a log of every party that has requested or received access to the records. The Operator maintains this log as follows:
- Logged events: Every instance of an advisor or admin accessing a student's profile, messages, or plan; every export; every AI-assisted operation; every disclosure to a subprocessor
- Log fields: Timestamp, actor user ID and role, action type, student ID (not name), subprocessor (if applicable), legal basis
- Immutability: Audit logs are append-only and cannot be edited or deleted by any platform user, including super admins
- Retention: 7 years (see Section 9)
- District access: District admins can view the disclosure log for their students on request via the admin dashboard or CSV export
15. Texas SDPC Exhibit A Field Mapping
The Texas Student Privacy Alliance (TX-SDPA) standard agreement requires operators to complete Exhibit A, which identifies the specific student data elements collected and the purpose for each. Below is ConnectED.ai's completed mapping.
| TX-SDPA Field | Collected? | Purpose | Shared w/ AI? |
|---|---|---|---|
| Student name | Yes | Account identity, advisor communication | First name only |
| Student email | Yes | Login, notifications | No |
| Date of birth / age | Yes | FERPA rights determination (age 18 transfer) | No |
| Grade level | Yes | College planning, eligibility | Yes |
| GPA / class rank | Yes (optional) | College recommendation engine | Yes |
| SAT / ACT scores | Yes (optional) | College match | Yes |
| Intended major / career interests | Yes | College & career guidance | Yes |
| College application list & status | Yes | Application tracking | Yes (list only) |
| FAFSA status | Yes | Financial aid tracking, reporting | No |
| Economic situation / household income | Yes (optional) | Contextualize recommendations | No — never sent to AI |
| Living situation | Yes (optional) | Support need identification | No — never sent to AI |
| Advisor–student messages | Yes | Counseling communication | No |
| Counselor notes | Yes | Advisor workflow | No |
| IP address / device logs | Yes (Vercel) | Security & abuse prevention | No |
| Behavioral / disciplinary records | No | Out of scope | N/A |
| Health / medical records | No | Out of scope | N/A |
| Biometric data | No | Out of scope | N/A |
| Social Security Number | No | Out of scope | N/A |
16. Custody Orders & Access Restrictions
FERPA presumes both parents have access to education records unless a court order, state law, or legally binding document specifically revokes that access. Districts may upload custody or restraining order information to the admin panel to restrict a specific parent's access to a student's records on the platform.
The Operator will enforce District-submitted access restrictions within 24 hours of receipt. The restriction is applied to:
- Any data export or PDF snapshot generated for or by the restricted parent
- Any parent-facing read-only view provisioned by the District
- Any direct access request from the restricted parent to the Operator
The Operator does not independently evaluate or adjudicate custody disputes. All restriction decisions are made by the District. Identity verification for parent record requests follows the District's established procedures.
17. Governing Law
This Agreement is governed by the laws of the State of Texas, without regard to its conflict-of-law provisions. For Texas districts, the following statutes apply in addition to FERPA:
- Texas Education Code Chapter 26 (Parental Rights)
- Texas Education Code § 32.151 et seq. (Texas Student Privacy Act)
- Texas Business & Commerce Code Chapter 541 (TDPSA)
- Texas Government Code Chapter 552 (Public Information Act — for district obligations)
- 19 TAC § 61.1023 (Texas Student Records Retention Schedule)
Districts in other states should addend this Agreement with their applicable state student privacy statutes. Contact info@vavoraventures.tech for state-specific addenda (California SOPIPA/CCPA, New York Education Law 2-d, Illinois SOPPA).
18. Amendments
The Operator will provide 30 days' written notice of any material amendment to this Agreement. Districts may accept or negotiate. If no response is received within 30 days of notice, the amendment is deemed accepted for continued use of the service. Districts may terminate without penalty within the notice period.
19. Contact & DPA Requests
Privacy Officer: ConnectED.ai / Vavora Ventures, LLC
Email: info@vavoraventures.tech
DPA execution: Districts wishing to execute a signed DPA should email the address above with "DPA Request — [District Name]" in the subject line. We will respond within 5 business days with a countersigned copy or requested modifications.
Parent record requests: Parents must submit requests to their district, which will coordinate with ConnectED.ai. Direct parent requests to the Operator will be redirected to the District within 2 business days.
Data deletion requests: Districts may submit deletion requests to info@vavoraventures.tech or via the admin panel. Deletion is completed within 30 days.