Legal
Data Privacy Agreement
This DPA is entered into between [INSTITUTION NAME] (the "Institution") and Smart Ed. LLC ("Tutorify" or "Provider") and supplements the Terms of Service / subscription agreement between the parties. Where this DPA conflicts with those terms regarding data protection, this DPA governs.
1. Roles of the parties
The Institution is the controller and owner of the data it makes available through the Service. Tutorify acts as the Institution's service provider and, with respect to education records, a "school official" under FERPA (34 CFR § 99.31(a)(1)) with a legitimate educational interest, performing an institutional service under the Institution's direct control. Tutorify processes data only on the Institution's documented instructions.
2. Scope and nature of processing
Purpose: to provide the Service — a course-grounded AI teaching assistant, AI-assisted assessment generation, rubric-based grading for instructor review, LMS grade sync, and analytics. Duration: the term of the subscription plus the deletion window in Section 9.
3. Categories of data subjects and data
Data subjects: the Institution's students, instructors, and administrative staff. Data types: name, institutional email, role, course enrollment, and institution identifiers; uploaded course materials; student submissions; and AI-interaction data.
4. Provider obligations
Tutorify will: (a) process personal data only on the Institution's documented instructions; (b) ensure personnel are bound by confidentiality; (c) implement the security measures in Annex A; (d) not use student data to train external AI models, and not sell or use it for advertising; (e) assist the Institution in responding to data-subject and parent/eligible-student requests; (f) assist with the Institution's security and compliance obligations; and (g) make available information reasonably necessary to demonstrate compliance.
5. FERPA-specific commitments
Tutorify will not re-disclose education records except as directed by the Institution or permitted by FERPA; will use education records only for the purposes authorized by the Institution; will not determine the purpose of processing on its own; and will support the Institution in honoring the access and correction rights of parents and eligible students. Any de-identified data used to improve the Service will be de-identified in accordance with FERPA and will not be re-identified.
6. Sub-processors
Tutorify may engage sub-processors (including LLM and infrastructure providers) to deliver the Service, listed in Annex B. Tutorify imposes data-protection obligations on each sub-processor no less protective than this DPA, remains responsible for their performance, and will give the Institution 30 days' notice of new sub-processors with a right to object on reasonable data-protection grounds.
7. Security incidents
Tutorify will notify the Institution without undue delay and no later than 72 hours after becoming aware of a personal-data breach affecting the Institution's data, provide known details, and cooperate on investigation and remediation.
8. Audits
On reasonable notice and no more than once per year (or after a breach), Tutorify will provide relevant certifications and, where reasonably required, respond to security questionnaires or support an audit of its compliance, subject to confidentiality and without disrupting operations.
9. Return and deletion
On expiry or termination, and at the Institution's choice, Tutorify will return and/or delete the Institution's personal data within 30 days, and delete existing copies except where retention is required by law. Tutorify will confirm deletion in writing on request.
10. Term
This DPA remains in effect for as long as Tutorify processes the Institution's personal data.
Annex A — Security measures
- Encryption of data at rest and in transit (AES-256) with customer-managed keys, configured and verified from infrastructure-as-code
- Single sign-on from the Institution's LMS via LTI 1.3 (OpenID Connect), so that user authentication and any multi-factor requirement remain with the Institution's identity provider
- Role-based access controls derived from LMS enrollment context (system administrator, organization administrator, instructor, student)
- Least-privilege internal access with centralized logging, monitoring, and an audit trail of access to institutional data
- Network protections, vulnerability management, and regular patching
- Secure software-development practices and change management
- Backup, restoration testing, and disaster-recovery procedures
- Minimization of personal data before AI model inference
- Personnel confidentiality obligations and security training
Annex B — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, storage, database, encryption key management | United States |
| Google Workspace | Business email and document collaboration for support correspondence | United States |
No AI inference provider appears in this Annex because model inference runs on infrastructure operated by Tutorify. Institutional and student data is not transferred to a third-party inference provider or to a consumer AI product. The current list is published in the Trust Center; institutions are notified 30 days before a sub-processor is added.