School DPA — summary
This page is a plain-language summary for administrators. It is not legal advice; your counsel should review and execute a formal DPA if required.
Subprocessors
Core hosting (e.g. Vercel), database (e.g. Neon/Postgres), optional KV for rate limits, email (e.g. Resend), and AI inference (Anthropic) may process data according to their terms. Restrict environment variables and access to production systems to school-authorized staff.
Student data
Student accounts avoid email and legal name by default. Schools remain responsible for roster policies, parental consent, and retention. Export or deletion workflows should be aligned with your district policy.