Legal
Data Processing Agreement
↓ Download PDFThis Data Processing Agreement ("DPA") is between PULSE4ED, LLC ("PULSE4ED," "Processor") and the school, district, or educational organization that has agreed to PULSE4ED’s Terms of Service ("School Partner," "Controller").
This DPA supplements and is incorporated into the Terms of Service. It governs PULSE4ED’s processing of Covered Data (defined below) on behalf of the School Partner in connection with the PULSE4ED Platform, including Principal PULSE and PLC Pulse.
By using the Platform, the School Partner agrees to the terms of this DPA. If the School Partner requires a countersigned DPA, please contact privacy@pulse4ed.com.
1. Definitions
- "Covered Data" means any personal information, education records, or other data about educators, staff, or (where applicable) students that the School Partner submits to the Platform or that PULSE4ED collects on behalf of the School Partner in connection with providing the Platform services.
- "Education Records" has the meaning given in FERPA (20 U.S.C. § 1232g) — records, files, documents, and other materials that contain information directly related to a student and are maintained by an educational agency or institution or by a person acting for or on behalf of such agency or institution.
- "FERPA" means the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99.
- "COPPA" means the Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506, and its implementing regulations.
- "Personal Information" means information that identifies or can reasonably be used to identify a natural person.
- "Processing" means any operation performed on Covered Data, including collection, storage, use, disclosure, transfer, and deletion.
- "Security Incident" means a confirmed breach of security leading to the unauthorized access, disclosure, alteration, or destruction of Covered Data.
- "Sub-Processor" means a third-party service provider that PULSE4ED engages to process Covered Data in connection with providing the Platform.
2. Scope & Roles
Controller. The School Partner acts as the data controller — it determines the purposes and means of processing Covered Data within the Platform.
Processor. PULSE4ED acts as the data processor — it processes Covered Data only on behalf of and under the documented instructions of the School Partner, as set out in this DPA and the Terms of Service.
Scope. This DPA applies to all Covered Data processed by PULSE4ED in connection with the Platform, including data entered by School Partner users into Principal PULSE and PLC Pulse.
3. Permitted Processing
PULSE4ED may process Covered Data only for the following purposes:
- Providing, operating, and improving the Platform features and services contracted by the School Partner.
- Generating AI-powered coaching feedback, coaching scripts, observation analyses, meeting summaries, and related outputs as directed by authorized School Partner users.
- Delivering transactional communications (password resets, coaching reminders, report deliveries, invited-user emails) on behalf of the School Partner.
- Generating data exports (Word, Excel, PDF) requested by School Partner users.
- Maintaining security, detecting and preventing fraud, and debugging errors in the Platform.
- Maintaining audit and activity logs as required by these Terms and applicable law.
- Complying with legal obligations.
PULSE4ED will not use Covered Data for: advertising; building user profiles for purposes unrelated to the Platform; selling or renting data to third parties; or any purpose not authorized by the School Partner or this DPA.
4. School Partner Obligations
The School Partner agrees to:
- Provide instructions for processing Covered Data that comply with applicable law, including FERPA, COPPA, and applicable state education privacy laws.
- Obtain all required parent/guardian consents, student consents (where students are 18+), and staff consents before uploading education records or personal information to the Platform.
- Obtain all required recording consents from educators and staff before using audio recording features, in compliance with applicable wiretapping and eavesdropping laws.
- Ensure that authorized users within the School Partner’s instance access the Platform only for legitimate educational purposes and in compliance with these Terms and applicable law.
- Notify PULSE4ED promptly if the School Partner becomes aware of any unauthorized access to its Platform accounts or any suspected misuse of Covered Data.
- Maintain appropriate policies and procedures within the school or district governing the use of third-party edtech platforms, including this Platform.
5. PULSE4ED Obligations
PULSE4ED agrees to:
- Process Covered Data only as permitted under Section 3 and as instructed by the School Partner in writing (including through configuration and use of Platform features).
- Ensure that personnel authorized to process Covered Data are bound by appropriate confidentiality obligations.
- Implement and maintain the security measures described in Section 7.
- Notify the School Partner of any Security Incident as described in Section 8.
- Assist the School Partner in responding to data subject rights requests as described in Section 9.
- Delete or return Covered Data upon termination as described in Section 10.
- Provide information reasonably necessary for the School Partner to demonstrate compliance with this DPA, subject to confidentiality obligations and Section 15.
- Maintain a current list of Sub-Processors and notify the School Partner of material changes as described in Section 6.
6. Sub-Processors
The School Partner authorizes PULSE4ED to engage the following Sub-Processors to process Covered Data:
| Sub-Processor | Location | Purpose | Data Processed |
|---|---|---|---|
| OpenAI, L.L.C. | USA | AI coaching features, audio transcription, meeting summarization | Coaching transcripts, teacher context, classroom media, meeting data (no student PII beyond aggregate metrics) |
| Amazon Web Services (S3) | USA | File storage — audio recordings, photos, screenshots, PDFs, uploaded data files | All uploaded files; transfers via presigned URLs |
| Amazon Web Services (SES) | USA | Transactional email delivery | Recipient email addresses and message content |
| MongoDB Atlas (MongoDB, Inc.) | USA | Database hosting — structured application data | All structured Covered Data |
| Google LLC (Calendar API) | USA | Calendar sync (only if School Partner users connect Google Calendar) | Observation/coaching event details synced at user direction |
| Microsoft Corporation (Outlook API) | USA | Calendar sync (only if School Partner users connect Outlook Calendar) | Observation/coaching event details synced at user direction |
| Stripe, Inc. (future) | USA | Billing and subscription management | Payment information only; PULSE4ED will not store card details |
PULSE4ED will notify the School Partner at least 30 days in advance of adding or replacing any Sub-Processor that processes Covered Data. The School Partner may object to a new Sub-Processor within 14 days of notice. If the parties cannot resolve the objection, the School Partner may terminate the Platform subscription with a pro-rated refund.
7. Security
PULSE4ED implements the following technical and organizational security measures to protect Covered Data:
- Encryption in transit: All data transmitted between users and the Platform is encrypted via HTTPS/TLS.
- Password security: User passwords are hashed using bcrypt (salt factor 12). Plaintext passwords are never stored.
- Authentication tokens: Signed JSON Web Tokens (JWTs) with 7-day expiration. Calendar OAuth tokens are stored encrypted at rest.
- File transfer security: Uploaded files (audio, photos, PDFs) are transferred directly from the user’s browser to AWS S3 via presigned URLs, avoiding PULSE4ED application servers for the upload path.
- Access control: All API endpoints require authenticated sessions. Campus-scoped database queries prevent cross-tenant access to Covered Data.
- Input sanitization: Request bodies are sanitized to strip HTML and prevent cross-site scripting (XSS).
- Security headers: HTTP security headers (CORS policy, Content-Security-Policy, Helmet middleware) are enforced.
- CSRF protection: Calendar OAuth flows use time-limited state tokens to prevent cross-site request forgery.
- Audit logging: Key actions (observations created/deleted, sessions completed, reports published, user logins) are logged with timestamps for accountability.
- PII hashing in audit logs (PLC Pulse): PII-tagged fields in quarterly audit logs are stored as SHA-256 hashes rather than raw values.
PULSE4ED reviews and updates its security practices periodically. Upon written request, PULSE4ED will provide a summary of security practices relevant to the processing of Covered Data, subject to confidentiality obligations.
8. Security Incident Response
Notification. In the event PULSE4ED becomes aware of a confirmed Security Incident affecting Covered Data, PULSE4ED will notify the School Partner within 72 hours of confirmation, to the extent practicable. Notification will be provided to the primary account email on record.
Notification contents. PULSE4ED’s notification will include, to the extent then known: (a) a description of the nature of the Security Incident; (b) the categories and approximate volume of Covered Data affected; (c) the likely consequences; (d) the measures taken or proposed to address the incident; and (e) a contact point for further information.
Cooperation. PULSE4ED will cooperate with the School Partner’s reasonable requests to investigate, remediate, and notify affected individuals or regulators as required by applicable law. The School Partner is responsible for any notifications to parents, students, regulatory bodies, or other parties required under FERPA, applicable state law, or other legal obligations.
No admission. A Security Incident notification under this Section does not constitute an admission of fault or liability.
9. Data Subject Rights
PULSE4ED will provide reasonable assistance to the School Partner in responding to verifiable requests from individuals (including educators and parents/guardians) to access, correct, export, or delete their personal information or education records on the Platform. This includes:
- Access and export: Platform users can export their own coaching records and PLC data from within the app. PULSE4ED can assist with broader data exports upon written request.
- Correction: Platform users can update most profile and record information directly in the app. Corrections to immutable audit log entries require written request and review.
- Deletion: PULSE4ED will process verified deletion requests within 30 days. Deletion of records referenced in immutable activity logs (Principal PULSE) will anonymize the record content; the log entry (event type, timestamp) will be retained for audit integrity unless legally required to be deleted.
- FERPA rights: Parents and eligible students may have rights under FERPA to inspect, review, and request correction of education records. PULSE4ED will cooperate with the School Partner to facilitate these rights. The School Partner is the first point of contact for FERPA requests and is responsible for determining whether a requestor’s rights apply.
10. Retention & Deletion
During the relationship. PULSE4ED retains Covered Data for as long as the School Partner’s account is active or as necessary to provide the Platform services.
Upon termination. Within 60 days of account termination or written request, PULSE4ED will either delete or return Covered Data, at the School Partner’s election, except where retention is required by applicable law or where data is contained in immutable audit logs maintained for compliance purposes.
Audio recordings. Audio recordings in PLC Pulse are subject to campus-configurable retention periods (default 90 days). Campus administrators can adjust retention settings within the app.
Backups. Covered Data may persist in encrypted database backups for up to 90 days following deletion from active systems. Backup data is not accessible for normal business operations and is purged on a rolling schedule.
Legal holds. Notwithstanding the above, PULSE4ED may retain Covered Data subject to a valid legal hold, court order, or government authority. PULSE4ED will notify the School Partner of any such legal hold to the extent permitted by law.
11. FERPA Compliance
PULSE4ED acknowledges that, to the extent the Platform processes Education Records, PULSE4ED acts as a "school official with a legitimate educational interest" within the meaning of FERPA, 34 C.F.R. § 99.31(a)(1)(i)(B), as designated by the School Partner.
PULSE4ED agrees to:
- Use Education Records only for the purpose of providing Platform services to the School Partner.
- Not re-disclose Education Records to third parties except as permitted by FERPA and as described in this DPA (Sub-Processors) or as directed in writing by the School Partner.
- Not use Education Records to build personal profiles of students for non-educational purposes, for advertising, or for any purpose other than providing the Platform.
- Implement appropriate technical and organizational safeguards to protect Education Records.
- Return or destroy Education Records upon request or termination as described in Section 10.
- Notify the School Partner of any Security Incident affecting Education Records as described in Section 8.
The School Partner is responsible for designating PULSE4ED as a school official with a legitimate educational interest in its own FERPA policies, obtaining appropriate authorizations before uploading Education Records, and ensuring compliance with all applicable FERPA requirements within its institution.
12. COPPA
The Platform is designed for use by adult educators and school administrators. PULSE4ED does not knowingly collect personal information directly from children under 13 on the Platform.
If student work samples, assessment data, or other materials that may constitute personal information of students under 13 are uploaded to the Platform, the School Partner is responsible for: (a) obtaining verifiable parental consent as required by COPPA; (b) ensuring that the upload complies with COPPA and applicable state law; and (c) ensuring that only the minimum necessary student data is shared, consistent with FERPA.
PULSE4ED will cooperate with the School Partner to promptly delete any content determined to include personal information of children under 13 collected without appropriate consent.
13. State Privacy Laws
In addition to FERPA and COPPA, PULSE4ED acknowledges its obligations under applicable state student data privacy laws, including but not limited to:
- California: Student Online Personal Information Protection Act (SOPIPA); California Consumer Privacy Act (CCPA/CPRA) to the extent applicable.
- Texas: Texas Student Data Privacy Consortium (TSDPC) and related state education agency requirements.
- New York: Education Law § 2-d and the Parents’ Bill of Rights for Data Privacy and Security.
- Other states: PULSE4ED will cooperate in good faith with School Partners subject to other state student data privacy laws.
School Partners subject to specific state law requirements that differ from this DPA should contact privacy@pulse4ed.com to discuss state-specific addenda.
14. AI Data Processing
Transparency. PULSE4ED is transparent about what data is sent to AI providers. A full description of AI features and the data processed is in our Privacy Policy, Section 4.
OpenAI API Data Use. Data sent to OpenAI is processed under OpenAI’s API data usage policies, which state that API inputs and outputs are not used to train OpenAI’s models by default. PULSE4ED processes data under OpenAI’s enterprise-grade API with a data processing agreement in place.
Minimization. PULSE4ED sends only the data necessary for each AI feature to function. Teacher context (name, subject, grade, coaching tier) is necessary for contextual coaching output. Student names, IDs, and other FERPA-protected student identifiers beyond aggregate metrics are not required and should not be included.
School Partner control. AI features are opt-in at the user level. School Partners may instruct PULSE4ED to disable AI features for their instance by contacting privacy@pulse4ed.com.
15. Audits & Assessments
Upon written request, PULSE4ED will provide the School Partner with documentation reasonably necessary to demonstrate compliance with this DPA, which may include:
- A summary of PULSE4ED’s security practices and controls.
- The current Sub-Processor list (as maintained in Section 6).
- Responses to written security questionnaires (subject to PULSE4ED’s reasonable time and resource constraints).
On-site audits require at least 30 days’ advance written notice, are subject to reasonable scheduling, must not interfere with Platform operations, and must be conducted under a mutually agreed confidentiality arrangement. Audit costs are borne by the School Partner unless the audit reveals a material breach of this DPA.
16. Term & Termination
This DPA is effective as of the date the School Partner agrees to the Terms of Service and remains in effect for as long as PULSE4ED processes Covered Data on behalf of the School Partner.
This DPA terminates automatically upon expiration or termination of the School Partner’s subscription or written agreement with PULSE4ED. Obligations relating to Security Incident notification, data deletion, and confidentiality survive termination.
17. General Provisions
Order of precedence. In the event of a conflict between this DPA and the Terms of Service regarding the processing of Covered Data, this DPA controls. In the event of a conflict between this DPA and a separately executed written School Partner Agreement, the written School Partner Agreement controls.
Entire agreement. This DPA, together with the Terms of Service and any written School Partner Agreement, constitutes the entire agreement between the parties regarding the processing of Covered Data.
Severability. If any provision of this DPA is found unenforceable, the remaining provisions remain in full force and effect.
Amendments. PULSE4ED may update this DPA to reflect changes in law, regulatory guidance, or Sub-Processor relationships. Material changes will be communicated as described in the Terms of Service. Continued use of the Platform after the effective date of an amendment constitutes acceptance.
Governing law. This DPA is governed by the laws of the State of Texas, consistent with the Terms of Service.
18. Contact
For questions about this DPA, to request a countersigned DPA, or to request state-specific addenda:
PULSE4ED, LLC
Privacy & Compliance Team
Email: privacy@pulse4ed.com
General inquiries: info@pulse4ed.com
