Data Processing Agreement
Last updated October 3, 2026
Pilot draft. Schools sign a copy of this document with us before any student data is shared; contact us for the current version.
This agreement covers personal data Tutor Platform (“we”) processes on behalf of a school or business (“the School”) under the School Terms.
1. Roles
For School data, the School decides why and how it is used and we process it only to provide the service. For a student's own Tutor Platform account (their study plan, tutor conversations, reports), the student is our customer and our Privacy Policy applies.
2. What we process
- From the School's learning platform: student name, email and platform user id; enrollments and percent complete; lessons completed; quiz answers and scores; course structure, lesson text and quiz questions.
- From the School directly: staff names and emails, roster emails it invites, and its settings.
- Generated by the service: which students joined, their pass dates, whether they share progress, and AI usage counts.
3. Purpose
Only to run the service for the School and its students: tailoring the tutor and study plan, the school portal, mapping course content to the ACS, billing, and keeping the service secure. Never for advertising, selling data, or training AI models.
4. Security
- Data is encrypted in transit (TLS) and at rest by our hosting and database providers; LMS API keys and secrets are additionally encrypted by us.
- Each School's data is kept separate in our code and database queries, with automated tests that one School's material never reaches another's tutor.
- Access is limited to the people who run the service. Staff accounts at the School see only their own School.
- We confirm learning-platform events against the platform's API where it doesn't sign them, and alert the School when its connection stops working.
5. Subprocessors
We use the providers on our subprocessor list, each bound to protect the data. We'll give at least 30 days' notice of new subprocessors that handle School data, and the School may object and end the agreement.
6. Students' requests
We'll help the School answer requests from its students to see, correct or delete their School data. Students can also export or delete their ownTutor Platform account themselves in Settings.
7. Breaches
We'll tell the School without undue delay, and within 72 hours of confirming a breach that affects its data, with what we know and what we're doing about it.
8. Deletion
When the School's plan ends, we delete its School data within 30 days (backups roll off on our providers' schedules), except what we must keep for billing records or the law.