Legal & compliance · Updated v3.0 — August 2026

Data Processing Agreement (FERPA)

The FERPA-compliant processor agreement: the school is the data Controller, AskElira is the Processor acting only on the school’s instructions.

The v2.8 update conforms three sentences to what the product actually does. Attendance Data was defined as present/absent status used solely for same-day notifications; the Platform had begun computing chronic-absence measures from those same uploads, so §3.4 now states that second purpose, states that the measures are shown only to your own staff in your own dashboard and drive no automated contact, and states that where your uploads carry absences only we decline to state a rate rather than assume a denominator. Retention did not change. The definition also promised no reason for an absence while the code stored your status cell verbatim — so an ordinary export could put “Absent — Medical” beside a named child. That cell is now normalized to one of eight categories at upload and the text discarded, and the definition names those eight values. Separately, Slack and DeepSeek are now named alongside Anthropic as vendors that touch our own engineering systems and receive no school, guardian, or student data. No subprocessor was added, removed, or changed. The v2.7 update moves the subprocessor schedule out of the signed PDF and onto a published page. §5.3 is titled “Single Authoritative Schedule”, and that schedule was a table printed inside the document — so adding or leaving a single vendor meant a new PDF, three new signing templates, and, once any school had executed, an amendment per school. §5.3 now names schools.askelira.com/legal/subprocessors as the current schedule and incorporates it into the Agreement, and keeps the full tables in the document as a dated snapshot of that page. The protection did not move with it: a change still takes not less than 30 days’ advance written notice to your authorized representative and your Data Protection Officer, an opportunity to object, and termination without penalty if an objection cannot be accommodated — and the published page governs ONLY for changes that notice was actually given for. For anything else the table printed in your executed copy controls, so a quiet edit to our website cannot change what you signed. No subprocessor was added, removed, or changed in v2.7, and no data element, retention period, channel, or AI function changed. The Parents’ Bill of Rights supplement still NAMES every provider rather than referring a parent to a website, and now points at the same page so the two cannot drift. The v2.6 update does three things, and two of them correct statements that were not true of the shipped product. §3.5 said “No document, image, or file is ever transmitted to the AI model provider” while the platform was already reading school-uploaded event flyers and academic calendars with a model. That is now a standing permission for School Operational Documents — material your school itself authors or publishes — with a boundary stated once so no future document type needs its own exception: never a guardian- or student-submitted record, never a registration document, an IEP, a health record, or anything in the §3.1(a) list, and never a document identifying an individual student however it arrives. The function table gains that fourth row and the count is corrected. Second, “United States regional endpoint” becomes the defined term “US Processing Endpoint” — a named US region, or a United States-only multi-region or data zone the provider warrants never leaves the country — and the Order Form no longer limits us to a single endpoint at a time. Any endpoint a provider calls “global” is excluded by name, which the old wording only implied. This lets us change or add an AI model provider under the §5.3 notice-and-objection process instead of re-papering your agreement, with the residency promise unchanged. Third, the TCPA scripting §19 row corrects a citation: sender identity in every text was attributed to 47 CFR §64.1200(b)(1), which is a rule about prerecorded voice calls. The commitment is kept; the basis now names what actually governs a text. Fourth, the residency disclosure is corrected. It previously stated that no AskElira personnel access data from outside the United States. That was an absolute neither §2-d nor Part 121 requires, and it was not accurate: a small team administers the platform from wherever it is. It now says what is true — administration may happen from outside the United States, over an encrypted connection under enforced multi-factor sign-in, and that access creates no store, copy, or backup of your data outside the country, with all scheduled processing running on United States-hosted infrastructure. To make that second half true rather than aspirational, the scheduled jobs were moved off a staff machine onto the United States cloud host and the local operational file that had held guardian contact details was deleted. Fewer absolutes, and all of them keepable. The v2.5 update moved the AI model provider’s identity out of §3.5 and into the subprocessor schedule at §5.3(a). §3.5 no longer names a provider: it requires that every AI model provider be listed in that schedule, reached through a United States regional endpoint, and changed only under the §5.3 notice-and-objection process — so a change of provider is a scheduled change you get 30 days’ notice of, not a rewrite of the contract. A new paragraph separates the developer of a model from the provider that serves it, commits that no content ever reaches a model’s developer, and bars engaging a provider organised in a country designated a foreign adversary. v2.5 also corrects something §3.2 and §3.5 had wrong: they denied any document intake outright, while the platform has always received the registration documents families email your office, identified them from the file name and forwarded them to your staff. That denial was inaccurate, so it is replaced by a description of what actually happens. No AI function was added — §3.5 still transmits content in exactly three functions, and no document is ever opened, read, or sent to a model. §3.2 still describes two free-text inputs, no retention period or channel changed, and v2.5 added no AI model provider: Google Cloud Vertex AI was still the only one the schedule named. (For what the schedule names today, read it — it is published at /legal/subprocessors, and these version notes record what each packet version changed rather than the current list.) No school has executed any version of this packet, so v2.5 is the first and only version anyone signs.

Roles

The school is the Controller; AskElira is the Processor and a FERPA “school official” with a legitimate educational interest, acting only on the school’s documented instructions.

Exactly what data is processed (complete enumeration)

Guardian name, phone, email, and preferred language; student name; seat and application status, including the school system’s own student and application record identifiers; grade level and campus; waitlist position; registration-paperwork checklist status (which required documents are in or missing — never the documents themselves); an IEP yes/no flag, plus a yes/no for whether an IEP file was attached; on the attendance product, one attendance category for a school day, drawn from a fixed vocabulary of eight values (present, tardy, half day, excused absence, unexcused absence, out-of-school suspension, not enrolled, no session) that your own status text is normalized to at upload — and, as §1 says, never the reason for an absence, never medical documentation, and never the free text your export carried, which is discarded at upload rather than stored; enrollment notes school staff share with the service (SSN-shaped text automatically redacted before storage); the question text a guardian sends the assistant, whichever channel they use (widget, text, or WhatsApp); and the outcome and a brief summary of each enrollment call and message. No IEP document content, disability category beyond the flag, service plan, or protected health information is ever stored or processed; no academic records or report-card grades; Social Security numbers are never stored — SSN-shaped text is redacted on sight.

No AI training on your data

Protected Data is never used to train, fine-tune, or improve any AI/ML model beyond delivering the contracted service, and is never sold or used for marketing.

Subprocessors

A limited, disclosed set: Twilio (SMS + keypad IVR voice, and the WhatsApp Business API), Meta Platforms (the WhatsApp network itself, where you enable that channel — Twilio stays the provider of record, but Meta receives the message content and warrants no United States processing, so it is disclosed in its own right), Turso (database), Vercel (hosting), Google Cloud (Vertex AI, marked in the schedule as an AI model provider, at a US Processing Endpoint — family Q&A assistant, staff support assistant, school-document reading — plus Sheets), Amazon Web Services (Amazon Bedrock, the second AI model provider, at a US Processing Endpoint with zero data retention — the staff-note send/hold review), AgentMail/Amazon SES (email), Resend (standby outbound email, used only where the primary provider will not accept a message for transport), SchoolMint (school-authorized integration). From v2.5 the schedule is the only place an AI model provider is named, so you can see at a glance who processes what and where. Each is bound by written data-protection terms covering confidentiality, security, breach notification and deletion on our instruction; where a provider publishes standard terms we cannot negotiate, we do not represent that those terms are identical to what we owe you. Not less than 30 days’ notice before any change, and an opportunity to object. From v2.7 the current schedule is published at /legal/subprocessors and incorporated into the DPA; the table printed in your executed copy is that schedule as of your version, and the published page governs only for changes you were given notice of. Schedule v1.3 names a second AI model provider — Amazon Web Services (Amazon Bedrock), at a US Processing Endpoint. It is named and authorized so that a change of source is disclosed in advance; Google Cloud carries every model request at present.

Breach notice, retention & deletion

Automated security monitoring (scheduled hourly checks, run as a cloud-scheduled job on our production hosting platform) with prompt breach notification — our operational standard is notice to the school within 48 hours of detection. Guardian and student personal data is deleted within 90 days of going inactive; all data is deleted or returned on termination. Consent and opt-out records are retained only as long as legally required. No live student data connects until the DPA is executed and countersigned.

Want the full document?
Download the complete PDF, or have our team walk your legal/data-privacy staff through it.
Download full PDFBook a walkthrough