Legal
Informational copy. A binding DPA becomes effective only through a signed order form, a separately signed DPA, or an electronic acceptance flow restricted to an authorized organization representative.
Download (text)Data Processing Addendum (with Student Data Addendum)
Effective Date: [Effective Date] · Version: 1.0
This Data Processing Addendum ("DPA") is entered into by and between Public Leaders Advisory ("Provider") and the customer entity identified in the applicable order form or signature block ("Customer"). It supplements the parties' Terms of Service, order form, or other principal services agreement ("Agreement"). If there is a conflict regarding personal-information processing, this DPA controls to the extent of that conflict.
1. Scope. This DPA applies when Provider processes personal information on behalf of Customer in connection with the Service.
2. Roles. Customer determines whether to submit personal information to the Service and is responsible for its lawful collection and use. Provider processes personal information only to provide the Service, maintain security and integrity, prevent abuse, comply with law, and as otherwise instructed by Customer through documented use and written directions consistent with the Agreement.
3. Processing Details. Subject matter: provision of the Public Leaders Advisory software service. Duration: the term of the Agreement and any limited post-termination retention required for backup, security, legal, or dispute-resolution purposes. Nature: hosting, storage, organization, retrieval, transmission, support, AI-assisted processing, security monitoring, logging, export, deletion, and related operations. Categories of data: account data, workspace data, notes, uploads, technical logs, billing metadata, support communications, and other data submitted by Customer or its authorized users. Categories of individuals: Customer personnel, organization users, and any third parties whose information Customer chooses to submit.
4. Provider Restrictions. Provider shall process Customer personal information only for the limited purposes described; shall not sell it; shall not share it for cross-context behavioral advertising; shall not retain, use, or disclose it outside the direct business relationship except as permitted by law and the Agreement; shall not combine it with information from other sources except as needed to provide the Service; and shall notify Customer if it can no longer meet its obligations.
5. Confidentiality. Provider shall ensure personnel with access are bound by confidentiality obligations.
6. Security Measures. Provider shall maintain reasonable administrative, technical, and physical safeguards appropriate to the information, including, where appropriate, access controls, logical segregation by customer or workspace, authentication controls, encrypted transmission, logging and monitoring, vulnerability and patch management, backup and recovery, and incident response.
7. Security Incident Notice. Provider shall notify Customer without unreasonable delay after confirming a Security Incident affecting Customer personal information, describing, to the extent known, the nature, categories of affected data, known or suspected impact, remediation, and contact for follow-up. Notice is not an admission of fault.
8. Subprocessors. Customer authorizes Provider to use subprocessors (hosting, email, payment, AI). Provider shall maintain a current list available on request, impose materially protective obligations, and remain responsible for their performance.
9. AI Processing. Where Customer uses AI-assisted features, Customer instructs Provider to transmit prompts and reasonably necessary context to Provider's AI subprocessor solely to generate the requested outputs. Provider shall require the AI subprocessor, by contract where available, to process such data only to provide the service, not use it to train models for the provider's general benefit where such restriction is available, apply confidentiality and security protections, and limit retention.
10. Assistance with Requests. Taking into account the nature of processing, Provider shall provide reasonable assistance to Customer in responding to verified requests by data subjects, parents, students, users, or regulators where required by law.
11. Deletion and Return. Upon termination or Customer's written request, Provider shall delete or return Customer personal information, except where retention is required by law, for security logging, backup rotation, legal hold or dispute preservation, or under documented organization settings.
12. Audit and Information Rights. Upon reasonable written request not more than annually, Provider shall make available information reasonably necessary to demonstrate compliance, which may include security summaries, certifications, policies, or questionnaire responses.
13. Organization Responsibility. Customer is responsible for determining whether use of the Service is appropriate for its data, providing required notices and obtaining permissions, configuring retention and access controls, ensuring authorized-user compliance, and not submitting prohibited data unless expressly authorized.
14. Student Data Addendum. This Section applies only if Customer is a school, district, county office of education, charter school, or other educational agency and the parties expressly authorize student-data processing in writing. (A) Provider processes pupil records only for legitimate school purposes authorized by Customer, acting as a service provider. (B) Pupil records remain the property of the educational agency. (C) Provider shall not engage in targeted advertising based on pupil records, create pupil profiles except for authorized school purposes, sell pupil records, or disclose or use them except as authorized. (D) Provider shall support Customer in responding to requests to inspect, review, correct, or delete pupil records. (E) Provider shall implement reasonable security and notify Customer of unauthorized access without unreasonable delay. (F) Upon request or termination, Provider shall delete or return pupil records except where retention is required by law or for short-term backup, security, or preservation. (G) If this Addendum is not expressly activated in writing, Customer shall not submit pupil records to the Service.
15. Order of Precedence. If this DPA conflicts with the Agreement on data-processing obligations, this DPA controls. Where Section 14 applies, it controls for pupil records.
16. Signatures. Provider: Public Leaders Advisory __________ Date ______ . Customer: __________ Date ______ .