Legal

Data Processing Agreement (Template)

⚠️ Reference template — not legal advice. Review and adapt with your lawyer before signing.

This Data Processing Agreement (“DPA”) forms part of the agreement between the School (“Controller”) and The Multilingual Literacy Lab (“Processor”) for use of the Platform.

It reflects how the Platform actually handles data and is provided as a starting point. Have it reviewed and adapted by qualified counsel before signing.

1. Roles

The School is the Controller of student and staff personal data. The Processor processes that data only on the School's documented instructions to provide the service.

2. Subject matter & duration

Processing lasts for the term of the service agreement. On termination, data is deleted or returned per Clause 9.

3. Nature & purpose

Delivering literacy assessment, small-group formation, differentiated lessons, progress reporting, and family summaries.

4. Categories of data & data subjects

Data subjects: students, teachers, and school administrators. Data: school-safe student display names, grade/class/group, learning and assessment records, optional oral-reading recordings; staff names, emails, and roles. No advertising identifiers; minimal student personal data by design.

5. Processor obligations

Process only on documented instructions; ensure personnel are bound by confidentiality; not sell data or use it for advertising; assist the Controller in meeting its own obligations.

6. Subprocessors

The Processor uses: Vercel (hosting), Supabase (database, auth, storage), Resend (transactional email), and — only if the School enables it with its own key — an AI provider. The Processor imposes equivalent data-protection terms on subprocessors and remains responsible for their performance. The Controller is notified of material changes to this list.

7. Security

Technical and organizational measures include per-tenant Row-Level Security, encryption in transit (TLS), hashed passwords and PINs, and server-only administrative credentials.

8. Data subject requests & breaches

The Processor assists the Controller in responding to access, correction, deletion, and portability requests, and notifies the Controller without undue delay after becoming aware of a personal-data breach.

9. Deletion & return

On request or on termination, the Processor deletes or returns personal data within a reasonable period, subject to any legal retention requirements. In-app export and student-erasure tools are available to the Controller.

10. Audits & international transfers

The Processor makes available information reasonably necessary to demonstrate compliance. Where data is transferred across borders, appropriate safeguards are used consistent with applicable law.

For the School (Controller)

Name / Title

Date

For the Processor

Name / Title

Date

Last updated: 2026-08-27