Legal

Data processing addendum

For institutions evaluating Teams & Classrooms or an Institution plan. Being asked for this and having nothing is how pilots die. so here's a draft ahead of the first ask, not after it.

Not reviewed by a lawyer yet TODO

This page is drafted from a code-derived data map (LEGAL-DISCLOSURE-MAP.md), not from a template — but generated and drafted legal prose is fluent and can still be wrong about what actually happens. Every section below with a TODO marker needs a qualified lawyer's review before this page governs anything. Do not treat it as final.

1. Roles

The institution is the controller. alcoia is the processor, acting only on the institution's documented instructions for the purpose of providing the service.

2. Subject matter, duration, nature and purpose

Processing of student reading-behaviour data (submitted receipts and, where enabled, aggregate class-level struggle indicators) for the duration of the institution's subscription, for the purpose of providing reading-comprehension tooling and reporting described in /for-educators.

3. Categories of data and data subjects

Data subjects: enrolled students and instructors. Categories: submitted reading receipts, aggregate anonymous struggle indicators by paragraph, account and roster data provided by the institution.

4. Processor obligations (GDPR Art. 28(3))

  • Process only on the institution's documented instructions
  • Ensure confidentiality of personnel with access
  • Implement Art. 32 security measures. see section 6
  • Engage sub-processors only from the authorised list below, with notice of changes
  • Assist with data-subject rights requests and breach notifications
  • Delete or return institutional data at termination
  • Make available information necessary to demonstrate compliance, and allow audits

5. Authorised sub-processors

Sub-processorPurpose
GroqLLM inference for questions and explanations
TODO: hosting providerApplication hosting
CreemPayment processing, merchant of record

Standard Contractual Clauses are annexed for any transfer outside the EEA/UK TODO: annex SCCs.

6. Security schedule

Encryption in transit for all API traffic; secrets (including the receipt-signing key and the LLM provider key) held outside source control with restricted access; the client-side design already minimises what reaches us. no video, image or raw gaze data is ever received. TODO: attach full security schedule and retention periods.

7. FERPA. US education customers

For US institutions, alcoia will accept a school-official designation under FERPA where applicable, subject to the legitimate-educational-interest and direct-control requirements. TODO: paper this into a signed exhibit per institution.

8. Requesting a signed copy

Contact legal@alcoia.com or use the pilot form. a signed DPA is provided before any pilot that involves student data.