Data Processing Agreement
This summary describes the Data Processing Agreement (DPA) GradeLogic™ enters into with institutions. It is the contract that establishes GradeLogic™ as a processor — and, under FERPA, a "school official" acting under the institution's direct control.
Roles & scope
The institution (or instructor) is the controller of student assessment data; GradeLogic™ is the processor. The DPA covers all assessment content processed through paid cloud operations. Most student data never leaves the controller's browser and is therefore outside the processing scope entirely.
Purpose limitation
GradeLogic™ processes data only on the controller's documented instructions and solely to provide the requested service. We do not use assessment content for advertising, for indefinite analytics, or to train AI models, and we do not re-disclose it.
Confidentiality & security
Personnel are bound by confidentiality obligations. We maintain technical and organizational measures appropriate to the risk, including encryption in transit and restricted, content-free logging. See our Security Overview. We notify the controller without undue delay after becoming aware of a personal-data breach.
Subprocessors
We engage the subprocessors described on our Subprocessor List, impose equivalent data-protection obligations on them, and remain responsible for their performance. We give notice of changes so the controller may object.
That page describes the categories of recipient. The individual model providers and their current processing locations are commercially confidential and are named to the controller on request — write to privacy@gradelogic.ai. A controller entitled to object to a change of processor should ask to be placed on the notification list at the same time, since a change within a category is not announced on the public page.
Which provider serves a given operation also depends on the processing setting on the instructor's account, described below.
Processing location & provider retention
Assessment content is processed through an AI gateway operating from the United States, and then by a model provider. That first transfer happens for every operation regardless of any setting. Whether the model provider is restricted to the European Economic Area, and whether it may retain what it is sent, follows a per-account setting (Settings › AI Configuration). The default is the strict combination: EEA-restricted, no retention.
Two limits the controller should understand before relying on it. First, the setting sits on the instructor's account, not on the institution — so where an institution requires a particular posture, that requirement has to reach the instructor who holds the account, or be agreed with us in writing so that we can hold the account to it. Second, we may place an account on a managed configuration that we determine; such a configuration can be stricter or less strict than the default, including permitting provider retention. We will tell a controller which configuration applies to accounts under its agreement on request.
Assistance & rights
We assist the controller, taking into account the nature of processing, in responding to data subject (and, where applicable, parent/eligible-student) requests and in meeting security, breach-notification, and assessment obligations.
Retention & deletion
GradeLogic does not create a persistent server-side copy of approved assessment payloads. Redacted payloads are processed only to complete the requested operation and return its result. The result of an operation is retained for approximately seven days so that a repeated request replays the stored result instead of re-running and re-charging it, and is then deleted. On termination, we delete or return remaining controller data, unless Union or Member State law requires retention of a specific record. Any retained record is isolated from ordinary use, access-restricted, kept only for the applicable statutory period, and then deleted or anonymized. Billing, credit-ledger, attestation, and operation-usage records are not categorically exempt from deletion: only the portions that qualify as legally required records, or that are temporarily necessary to establish, exercise, or defend legal claims, may be retained.
FERPA addendum
For institutions subject to FERPA, the DPA includes terms under which GradeLogic™:
- acts as a "school official" with a legitimate educational interest, under the institution's direct control;
- uses education records only to perform the contracted service;
- does not re-disclose education records except as permitted by FERPA and authorized by the institution;
- does not use education records to train AI models or for any unrelated purpose;
- returns or destroys education records on the institution's request.
See the FERPA Support Overview for context.
How to execute
To request the executable DPA for signature, contact privacy@gradelogic.ai with your institution's details.