SDPC / Texas Student Privacy Alliance Aligned

Student Data Privacy Agreement

Effective: August 1, 2026  ·  Last updated: July 27, 2026

DPA or procurement questions? info@vavoraventures.tech

Note to District Procurement Teams: This agreement is designed to map directly onto the Texas Student Privacy Alliance (TX-SDPA) Exhibit A field set used in district vendor evaluation. Section 15 provides a field-by-field mapping. For custom DPA negotiations, contact info@vavoraventures.tech.

1. Parties & Definitions

This Student Data Privacy Agreement ("Agreement" or "DPA") is entered into between the local education agency or authorized organization listed in the executed Order Form ("District" or "LEA") and ConnectED.ai / Vavora Ventures, LLC("Operator" or "we").

Student Data means any information directly related to an identifiable student that is generated, transmitted, or stored in ConnectED.ai, including education records as defined under FERPA (20 U.S.C. § 1232g), and any data derived from those records through automated processing or AI inference.

Authorized Users means students enrolled at the District, school counselors/advisors employed or contracted by the District, and school administrators with a legitimate educational interest as defined in 34 CFR § 99.31(a)(1).

Eligible Student means a student who has reached age 18 or is attending a postsecondary institution, at which point FERPA rights transfer from parent to student.

Parent means a natural parent, guardian, or individual acting as a parent as defined in 34 CFR § 99.3, subject to the custody and eligibility provisions of Section 16.

2. Scope of Service

ConnectED.ai is an AI-powered college counseling and career readiness platform for high school students (grades 9–12). The platform enables students to:

  • Build a college and career exploration plan
  • Track application progress and FAFSA status
  • Communicate with assigned school counselors or advisors
  • Access AI-generated college recommendations and essay coaching
  • Explore career pathways, salary data, and cost-of-living analysis

The Operator processes Student Data solely to deliver these services under the direction of the District, operating as a "school official" under 34 CFR § 99.31(a)(1) with a legitimate educational interest.

3. Authorized Use of Student Data

The Operator may use Student Data only to:

  • Provide, maintain, and improve the contracted service
  • Personalize the educational experience (college/career recommendations)
  • Generate analytics and reports for District-authorized staff
  • Respond to the District's data requests and audits
  • Comply with legal obligations, including FERPA, COPPA, and Texas Education Code Chapter 26 and § 32.151
  • Detect and prevent fraud, abuse, and security threats directed at the service

The Operator will not use Student Data for any purpose not listed above without prior written authorization from the District.

4. Prohibited Uses

The Operator expressly agrees not to:

  • Sell or rent Student Data to any third party
  • Use Student Data to advertise or market non-educational products or services to students, parents, or siblings
  • Use Student Data to create or append to commercial profiles of students unrelated to the educational purpose
  • Disclose Student Data to unauthorized parties, including data brokers, advertising networks, or social media platforms
  • Use Student Data in aggregate or de-identified form in a way that could re-identify individual students
  • Train AI/ML models on Student Data without a separate, written, district-authorized Data Use Agreement specifying the model, purpose, and opt-out mechanism
  • Share Student Data with law enforcement except as required by a valid legal process (subpoena, court order) or a bona fide emergency under 34 CFR § 99.36

5. Access & Security Controls

The Operator maintains the following safeguards:

ControlImplementation
Encryption in transitTLS 1.3 enforced on all connections
Encryption at restAES-256 on PostgreSQL database and backups
AuthenticationNextAuth.js with credential + OAuth flows; MFA available for admin accounts
Role-based access4-tier RBAC: Student, Advisor, School Admin, Super Admin — each scoped to their data
Audit loggingAll access to student records by non-student users is logged with timestamp, user ID, and action
Least privilegeAdvisors access only their assigned students; admins access only their school
Penetration testingAnnual third-party assessment; results shared with District on request
Vendor contractsAll subprocessors are bound by DPAs with equivalent protections

6. Subprocessors & Onward Transfers

The Operator uses the following subprocessors that may have access to Student Data. Each is bound by contractual terms that provide equivalent protections to this Agreement:

SubprocessorPurposeData Minimization
Supabase / PostgreSQLHosted databaseAll student data; stored in US region
OpenAI (GPT-4o)AI recommendations, essay coach, chatName, grade, GPA, interests, college list only — financial and living situation fields are never sent
VercelApplication hosting and edge networkRequest logs; no persistent student data
Nodemailer / SMTPTransactional email (advisor notifications, account setup)Email address and name only

The Operator will provide 30 days' written notice before adding a new subprocessor that accesses Student Data. The District may object in writing; if the parties cannot agree, the District may terminate without penalty.

7. Parent / Eligible-Student Rights

Under FERPA (20 U.S.C. § 1232g) and Texas Education Code Chapter 26, parents have the following rights with respect to their child's education records held by the District (and, by extension, in ConnectED.ai as a school official):

Right to Inspect & Review (FERPA § 99.10)

Parents may request access to all education records within 45 days. Requests must be directed to the District. The Operator will fulfill District-directed data export requests within 5 business days.

Right to Request Amendment (FERPA § 99.20–99.22)

Parents may request correction of records believed to be inaccurate. Requests route to the District. If the District directs a correction, the Operator will apply it within 10 business days and log the change.

Right to Consent to Disclosures (FERPA § 99.30)

Student Data is not disclosed outside the school-official context without written consent, except for FERPA-exempt disclosures (health/safety emergencies, legal process). Each non-exempt disclosure is logged.

Right to Inspect the Disclosure Log (FERPA § 99.32)

The District may request the disclosure log at any time. The Operator maintains an immutable record of all external data flows, including which subprocessors received what data and why.

Right to Opt Out of Directory Information Designations

Districts may suppress individual directory fields (name, enrollment status, etc.) via the admin panel. Suppressed fields are excluded from all exports, reports, and AI prompts.

Rights Transfer at Age 18 (FERPA § 99.5)

When a student turns 18 or enrolls in a postsecondary institution, FERPA rights transfer to the student. The platform enforces this via a scheduled account-state check. The IRS dependent-student exception may be applied by District request.

Texas Ed Code Ch. 26 — Full Written Records Access

Texas parents have broader rights than FERPA alone: access to all written records about their child, including attendance, assessment scores, discipline records, and any data ConnectED.ai holds. Requests are honored within the 45-day FERPA window.

8. District Rights & Controls

The District retains the following controls at all times:

  • School-initiated deletion: The District admin can permanently delete a student's data from the platform at any time via the admin panel or a written request to info@vavoraventures.tech. Deletion is completed within 30 days, except where retention is required by Texas records-retention schedules (see Section 9).
  • Bulk data export: The District can export all data for all its students in CSV format from the admin panel, or in PDF format per student.
  • User provisioning: Only the District admin can create, modify, or deactivate student accounts. Students cannot self-register.
  • Advisor assignment: The District admin controls which advisor is assigned to which student. Advisors cannot reassign themselves.
  • Directory suppression: The District can suppress individual directory-information fields per student to honor opt-out requests.
  • Audit log access: District admins and super admins can view the full disclosure log for their school.

9. Retention & Deletion

Data CategoryDefault RetentionBasis
Active student profile & application dataDuration of district contract + 1 yearService delivery
Post-graduation retained fields (name, graduating class, school, outcome metrics)3 years post-graduationProof-of-value, program improvement
Advisor–student message threadsDuration of contract + 1 yearCompliance & audit
Audit/disclosure logs7 yearsFERPA § 99.32 compliance
Backups90 days rollingDisaster recovery
Parent request records7 yearsFERPA compliance documentation

A parent deletion request cannot remove data the District is legally required to retain under Texas records-retention schedules (19 TAC § 61.1023). Deletion in ConnectED.ai is always "District-authorized" — the Operator does not accept direct deletion orders from parents without a corresponding District instruction.

After the contract ends, the Operator will return or delete all Student Data within 60 days and provide written certification of deletion upon request.

10. Breach Notification

In the event of a confirmed or reasonably suspected security breach involving Student Data, the Operator will:

  • Notify the District's designated privacy officer within 48 hours of discovery, via the contact provided in the Order Form
  • Provide a written incident report within 7 calendar days, including: nature of the breach, data elements involved, estimated number of students affected, remediation steps taken, and contact for questions
  • Cooperate with the District's breach response and notifications to affected families under Texas Ed Code § 521.053 and any applicable state law
  • Not make any public statements about the breach before coordinating with the District

11. AI & Inference on Student Data

ConnectED.ai uses OpenAI GPT-4o to power college recommendations, the AI advisor chat, and essay coaching. The following rules govern AI use of Student Data:

Data minimization

Only the minimum data needed for the specific AI task is sent to OpenAI. The following fields are never included in AI prompts: economic situation, living situation, household financial data, profile photographs, and detailed disciplinary records.

No model training on student data

We use OpenAI's API with the "zero data retention" and "no training" configuration. Student data submitted in API calls is not used to train OpenAI's models. This is governed by our OpenAI Data Processing Agreement.

AI disclosures are logged

Every request that includes Student Data sent to a third-party AI service is recorded in the disclosure log (Section 14), identifying the student (by ID, not name, in the log), the purpose, and the subprocessor.

No autonomous decisions with legal effect

AI outputs (college recommendations, risk flags, plan stalling indicators) are presented to advisors and students as guidance, not determinations. No fully-automated decision with a legal or similarly significant effect is made about a student without human review.

12. COPPA / Under-13 Students

COPPA (15 U.S.C. § 6501 et seq.) applies to online services that collect personal information from children under 13. ConnectED.ai is designed for high school students (grades 9–12), but some 9th-grade students may be 13 years old.

School consent model: Where a District provisions student accounts and has agreed to this DPA, the District provides consent on parents' behalf for purely educational use, under the COPPA school consent exception (16 CFR § 312.5(b)(1)). The District must confirm it has provided appropriate parental notice before provisioning any student under 13.

Operator obligations for under-13 students:

  • Collect only what is necessary for the educational service
  • Provide parents the ability to review, correct, and delete their child's data
  • Not condition participation on disclosure of more information than necessary
  • Not share data with third parties except as permitted by the school consent
  • Maintain a written retention policy (see Section 9) per the 2025 COPPA amendments
  • Obtain separate consent before any third-party disclosure not covered by the school consent

The Operator does not operate a direct-to-consumer offering for students under 13 outside the school-provisioned context.

13. PPRA Compliance

The Protection of Pupil Rights Amendment (20 U.S.C. § 1232h) requires advance parental notice and opt-out rights for surveys that touch eight protected categories: political affiliation, mental health, sexual behavior, illegal behavior, religious beliefs, income, biometric data, and critical appraisals of family members.

ConnectED.ai does not administer surveys touching these categories. However, the platform's onboarding questionnaire collects economic context and living situation information. Districts must ensure:

  • Parents receive advance notice of these questions as part of enrollment
  • A documented opt-out mechanism exists (students can skip these fields)
  • Any future survey added to the platform is reviewed for PPRA applicability before deployment

14. Disclosure & Audit Logging

FERPA § 99.32 requires that education records maintained by a school official include a log of every party that has requested or received access to the records. The Operator maintains this log as follows:

  • Logged events: Every instance of an advisor or admin accessing a student's profile, messages, or plan; every export; every AI-assisted operation; every disclosure to a subprocessor
  • Log fields: Timestamp, actor user ID and role, action type, student ID (not name), subprocessor (if applicable), legal basis
  • Immutability: Audit logs are append-only and cannot be edited or deleted by any platform user, including super admins
  • Retention: 7 years (see Section 9)
  • District access: District admins can view the disclosure log for their students on request via the admin dashboard or CSV export

15. Texas SDPC Exhibit A Field Mapping

The Texas Student Privacy Alliance (TX-SDPA) standard agreement requires operators to complete Exhibit A, which identifies the specific student data elements collected and the purpose for each. Below is ConnectED.ai's completed mapping.

TX-SDPA FieldCollected?PurposeShared w/ AI?
Student nameYesAccount identity, advisor communicationFirst name only
Student emailYesLogin, notificationsNo
Date of birth / ageYesFERPA rights determination (age 18 transfer)No
Grade levelYesCollege planning, eligibilityYes
GPA / class rankYes (optional)College recommendation engineYes
SAT / ACT scoresYes (optional)College matchYes
Intended major / career interestsYesCollege & career guidanceYes
College application list & statusYesApplication trackingYes (list only)
FAFSA statusYesFinancial aid tracking, reportingNo
Economic situation / household incomeYes (optional)Contextualize recommendationsNo — never sent to AI
Living situationYes (optional)Support need identificationNo — never sent to AI
Advisor–student messagesYesCounseling communicationNo
Counselor notesYesAdvisor workflowNo
IP address / device logsYes (Vercel)Security & abuse preventionNo
Behavioral / disciplinary recordsNoOut of scopeN/A
Health / medical recordsNoOut of scopeN/A
Biometric dataNoOut of scopeN/A
Social Security NumberNoOut of scopeN/A

16. Custody Orders & Access Restrictions

FERPA presumes both parents have access to education records unless a court order, state law, or legally binding document specifically revokes that access. Districts may upload custody or restraining order information to the admin panel to restrict a specific parent's access to a student's records on the platform.

The Operator will enforce District-submitted access restrictions within 24 hours of receipt. The restriction is applied to:

  • Any data export or PDF snapshot generated for or by the restricted parent
  • Any parent-facing read-only view provisioned by the District
  • Any direct access request from the restricted parent to the Operator

The Operator does not independently evaluate or adjudicate custody disputes. All restriction decisions are made by the District. Identity verification for parent record requests follows the District's established procedures.

17. Governing Law

This Agreement is governed by the laws of the State of Texas, without regard to its conflict-of-law provisions. For Texas districts, the following statutes apply in addition to FERPA:

  • Texas Education Code Chapter 26 (Parental Rights)
  • Texas Education Code § 32.151 et seq. (Texas Student Privacy Act)
  • Texas Business & Commerce Code Chapter 541 (TDPSA)
  • Texas Government Code Chapter 552 (Public Information Act — for district obligations)
  • 19 TAC § 61.1023 (Texas Student Records Retention Schedule)

Districts in other states should addend this Agreement with their applicable state student privacy statutes. Contact info@vavoraventures.tech for state-specific addenda (California SOPIPA/CCPA, New York Education Law 2-d, Illinois SOPPA).

18. Amendments

The Operator will provide 30 days' written notice of any material amendment to this Agreement. Districts may accept or negotiate. If no response is received within 30 days of notice, the amendment is deemed accepted for continued use of the service. Districts may terminate without penalty within the notice period.

19. Contact & DPA Requests

Privacy Officer: ConnectED.ai / Vavora Ventures, LLC

Email: info@vavoraventures.tech

DPA execution: Districts wishing to execute a signed DPA should email the address above with "DPA Request — [District Name]" in the subject line. We will respond within 5 business days with a countersigned copy or requested modifications.

Parent record requests: Parents must submit requests to their district, which will coordinate with ConnectED.ai. Direct parent requests to the Operator will be redirected to the District within 2 business days.

Data deletion requests: Districts may submit deletion requests to info@vavoraventures.tech or via the admin panel. Deletion is completed within 30 days.