Tutorify.ai
Why Features Benefits How it works Security
Book a walkthrough

Legal

Data Privacy Agreement

Effective date: [DATE]

⚠️ Template — not legal advice. DPAs carry real legal weight and vary by state and institution. Have qualified counsel review and adapt before signing. Many U.S. institutions require their own DPA form (e.g., a state or SDPC/NDPA-based agreement) — be ready to sign theirs too. Fill every [bracketed] field.

This DPA is entered into between [INSTITUTION NAME] (the "Institution") and Tutorify AI Inc. ("Tutorify" or "Provider") and supplements the Terms of Service / subscription agreement between the parties. Where this DPA conflicts with those terms regarding data protection, this DPA governs.

1. Roles of the parties

The Institution is the controller and owner of the data it makes available through the Service. Tutorify acts as the Institution's service provider and, with respect to education records, a "school official" under FERPA (34 CFR § 99.31(a)(1)) with a legitimate educational interest, performing an institutional service under the Institution's direct control. Tutorify processes data only on the Institution's documented instructions.

2. Scope and nature of processing

Purpose: to provide the Service — a course-grounded AI teaching assistant, AI-assisted assessment generation, rubric-based grading for instructor review, LMS grade sync, and analytics. Duration: the term of the subscription plus the deletion window in Section 9.

3. Categories of data subjects and data

Data subjects: the Institution's students, instructors, and administrative staff. Data types: name, institutional email, role, course enrollment, and institution identifiers; uploaded course materials; student submissions; and AI-interaction data. [Add or remove categories to match your actual processing. Avoid collecting special-category or unnecessary data.]

4. Provider obligations

Tutorify will: (a) process personal data only on the Institution's documented instructions; (b) ensure personnel are bound by confidentiality; (c) implement the security measures in Annex A; (d) not use student data to train external AI models, and not sell or use it for advertising; (e) assist the Institution in responding to data-subject and parent/eligible-student requests; (f) assist with the Institution's security and compliance obligations; and (g) make available information reasonably necessary to demonstrate compliance.

5. FERPA-specific commitments

Tutorify will not re-disclose education records except as directed by the Institution or permitted by FERPA; will use education records only for the purposes authorized by the Institution; will not determine the purpose of processing on its own; and will support the Institution in honoring the access and correction rights of parents and eligible students. Any de-identified data used to improve the Service will be de-identified in accordance with FERPA and will not be re-identified.

6. Sub-processors

Tutorify may engage sub-processors (including LLM and infrastructure providers) to deliver the Service, listed in Annex B. Tutorify imposes data-protection obligations on each sub-processor no less protective than this DPA, remains responsible for their performance, and will give the Institution [30] days' notice of new sub-processors with a right to object on reasonable data-protection grounds.

7. Security incidents

Tutorify will notify the Institution without undue delay and no later than [72 hours / specify] after becoming aware of a personal-data breach affecting the Institution's data, provide known details, and cooperate on investigation and remediation.

8. Audits

On reasonable notice and no more than [once per year] (or after a breach), Tutorify will provide relevant certifications and, where reasonably required, respond to security questionnaires or support an audit of its compliance, subject to confidentiality and without disrupting operations.

9. Return and deletion

On expiry or termination, and at the Institution's choice, Tutorify will return and/or delete the Institution's personal data within [30–90 days], and delete existing copies except where retention is required by law. Tutorify will confirm deletion in writing on request.

10. International transfers

[Complete only if data may be processed outside the Institution's country. Specify mechanisms such as Standard Contractual Clauses and any residency commitments; otherwise remove.]

11. Term

This DPA remains in effect for as long as Tutorify processes the Institution's personal data.

Annex A — Security measures

  • Encryption of data at rest and in transit (AES-256)
  • SAML 2.0 SSO, multi-factor authentication, and role-based access controls
  • Least-privilege internal access with logging and monitoring
  • Network protections, vulnerability management, and regular patching
  • Secure software-development practices and change management
  • Backup and disaster-recovery procedures
  • Personnel confidentiality obligations and security training
  • Controls built to the SOC 2 framework [state audit status accurately]

Annex B — Sub-processors

Sub-processorPurposeLocation
[LLM provider(s)]AI model inference[region]
[Cloud/hosting provider]Hosting & storage[region]
[Other][purpose][region]

List every sub-processor with access to Institution data. Keep this table in sync with the public sub-processor list referenced in the Privacy Policy.

Signatures

Institution: Date:
Tutorify AI Inc.: Date:

← Back to home

Tutorify.ai
Privacy Policy Terms of Service Data Privacy Agreement hello@tutorify.ai

Tutorify AI · [Mailing address to be added]

© 2026 Tutorify AI. AI teaching assistant for higher education.