top of page

TeachAid Data Processing Addendum

Last updated: August 10, 2026
Effective: September 9, 2026

Notice: This updated policy has been published in advance and will take effect on September 9, 2026. Until then, the current version remains in effect. [View the current policy.]

This Data Processing Addendum, or “DPA,” forms part of the written agreement between:

1000662662 Ontario Corporation, doing business as TeachAid, and the school, district, educational organisation or other customer identified in that agreement.

1. Scope

This DPA applies only where it is incorporated into an authorised enterprise, school, district, pilot, sandbox or other written customer agreement.

It applies when TeachAid processes personal information or Student Data on the customer’s behalf, together called “Protected Data.”
 

It does not apply merely because an individual educator:

  • Uses a school email address

  • Creates a self-serve account

  • Appears associated with a school domain

  • Uses an informal or unauthorised workspace
     

2. Priority

Where documents conflict concerning Protected Data, the following controls:

  1. A signed state, consortium, district or jurisdiction-specific student-data agreement

  2. An applicable jurisdiction-specific addendum

  3. This DPA

  4. The signed commercial agreement and order form

  5. TeachAid’s public Terms and policies
     

Mandatory law and stronger signed protections continue to apply.
 

3. Definitions

Applicable Law means privacy, data-protection, student-privacy, breach-notification and information-security law applicable to the processing.

Customer Data means information submitted to or collected through the Services for the customer, including Protected Data, curriculum materials, organisational configurations and customer-specific content.
 

Personal Data means information relating to an identified or identifiable person and includes equivalent terms under Applicable Law.

Security Incident means unauthorised access to, acquisition, use, disclosure, loss, alteration or destruction of Protected Data that compromises its confidentiality, integrity or availability. It excludes unsuccessful attempts that do not compromise Protected Data.

Student Data means Personal Data directly related to a current or former student that is processed through the Services, including education-record information.

Subprocessor means a third party engaged by TeachAid to process Protected Data on TeachAid’s behalf.

4. Roles and instructions

The customer determines the authorised educational and organisational purposes and acts as the controller, educational agency, public body or equivalent responsible organisation.

TeachAid acts as the customer’s processor, service provider, contractor or school official, as applicable.

TeachAid processes Protected Data only under documented instructions contained in:

  • The agreement

  • The order form

  • Authorised product settings

  • Written instructions accepted by TeachAid
     

TeachAid will notify the customer if it reasonably believes an instruction violates Applicable Law, unless prohibited from doing so.
 

TeachAid acts independently for its own billing, corporate records, account security, business contacts and legal compliance.
 

FERPA

Where FERPA applies, TeachAid will:

  • Perform an institutional service or function for which the customer would otherwise use employees

  • Remain under the customer’s direct control regarding the use and maintenance of education-record information

  • Use the information only for the authorised educational purpose

  • Follow applicable redisclosure restrictions

  • Assist with access and correction
     

The U.S. Department of Education states that a provider relying on the school-official exception must be under the school or district’s direct control regarding the use and maintenance of education-record information.
 

COPPA

Where COPPA applies:

  • The customer confirms that the use is school-authorised and educational

  • The customer confirms it has authority to provide consent where permitted

  • TeachAid will provide notice of its collection, use and disclosure practices

  • TeachAid will use the information only for the authorised educational purpose

  • TeachAid will not use the information for unrelated commercial purposes

  • TeachAid will support access, deletion and prevention of further collection
     

5. Customer responsibilities

The customer will:

  • Provide lawful instructions

  • Identify authorised users and administrators

  • Configure access appropriately

  • Obtain required institutional approval

  • Provide required notices

  • Obtain required authority or consent

  • Minimise Protected Data

  • Secure credentials, devices, networks, exports and administrator access

  • Promptly report suspected compromise
     

The customer will not instruct users to submit formal IEPs, diagnoses, medical or psychological records, behaviour or safety plans, government identifiers or similar high-risk records unless a signed amendment expressly governs that processing.
 

6. Processing details

TeachAid processes Protected Data to:

  • Provide and secure the Services

  • Authenticate users

  • Operate interactive activities

  • Store student responses

  • Generate customer-requested curriculum materials

  • Support enterprise workspaces

  • Provide curriculum mapping

  • Administer licences

  • Provide support and training

  • Follow customer instructions

  • Meet legal obligations
     

The categories of people may include:

  • Educators

  • Administrators

  • Staff

  • Students

  • Parents or guardians where information is included in an authorised request

  • Customer representatives
     

The categories of information may include:

  • Adult names, work emails, roles and organisation

  • Authentication and usage information

  • Educator prompts and uploads

  • Curriculum documents and maps

  • Shared organisational content

  • Student first names or nicknames

  • Student activity responses, notes and drawings

  • Limited technical and security information
     

TeachAid does not require formal IEPs, diagnoses, health information, government identifiers or other high-risk records to provide the standard Services.
 

Processing continues for the agreement term and applicable return, retention and deletion periods.
 

7. Ownership and permitted use

The customer retains ownership and control of:

  • Protected Data

  • Student Data

  • Education records

  • Curriculum documents

  • Curriculum maps

  • Organisational configurations

  • Customer-created content
     

TeachAid may use Protected Data only to:

  • Provide the contracted Services

  • Secure and support the Services

  • Improve the reliability and effectiveness of the contracted Services

  • Follow customer instructions

  • Comply with law
     

TeachAid will not use Protected Data for:

  • Another customer

  • Sale or rental

  • Targeted advertising

  • Marketing

  • Commercial student profiling

  • General-purpose AI-model training

  • Unrelated commercial purposes
     

TeachAid will not disclose Protected Data except:

  • To authorised customer users

  • To approved Subprocessors

  • As directed by the customer

  • Where legally required
     

TeachAid will not attempt to re-identify properly de-identified Student Data.
 

8. Personnel and access

TeachAid limits access to personnel and contractors who require it for an authorised operational purpose.
 

People with access to Protected Data must:

  • Be subject to confidentiality obligations

  • Receive appropriate privacy and security training

  • Use the information only for authorised purposes

  • Have access removed when no longer required
     

TeachAid applies role-based access and least privilege.
 

Support and engineering access must be based on a legitimate need and controlled through authorised company-managed accounts.
 

TeachAid does not permit routine browsing of customer content.
 

9. Security

TeachAid maintains administrative, technical and organisational measures appropriate to the nature and sensitivity of Protected Data.

These measures include:

  • Encryption in transit and at rest

  • Multi-factor authentication for privileged access

  • Role-based access and least privilege

  • Logical customer and tenant separation

  • Production and development separation

  • Restricted administrative access

  • Security and error monitoring

  • Secure credential and token handling

  • Protected backups

  • Independent backup copies

  • Separation preventing one account from deleting production and every backup

  • Periodic restoration testing

  • Incident-response procedures

  • Secure development and vulnerability management

  • Workforce confidentiality and training

  • Access removal following role change or departure
     

TeachAid maintains production data, backup copy one and an independent backup copy two for relevant production and customer data, including uploaded files.

TeachAid does not provide managed IT, remote-monitoring or customer-device backup services.

TeachAid’s security program is informed by the NIST Cybersecurity Framework and recognised industry practices.

This is not a representation that TeachAid is SOC 2, ISO 27001 or CMMC certified.

TeachAid may update controls to address evolving risks, provided the overall protection of Protected Data is not materially reduced.

10. Subprocessors

The customer authorises TeachAid to use the Subprocessors identified at teachaid.ca/subprocessors.

TeachAid will:

  • Maintain written terms with Subprocessors

  • Require confidentiality and data-protection safeguards

  • Limit access to what is needed for the service

  • Require processing only for authorised purposes

  • Remain responsible to the extent required by law and contract

  • Provide notice of material changes where required

  • Address a Subprocessor’s material non-compliance
     

For its standard DPA, TeachAid will provide at least 30 days’ advance notice before a new Subprocessor materially processes Protected Data.

The customer may raise reasonable documented privacy or security concerns during that period. The parties will work in good faith to address them.

A signed state or district agreement may require different notice, objection, update or approval procedures and will control.

TeachAid will update the public list at least annually and more often where a controlling agreement requires it.

11. AI processing

TeachAid uses OpenAI as its production AI provider.

Depending on the authorised feature, TeachAid may send:

  • Educator prompts

  • Selected customer uploads

  • Curriculum standards

  • District frameworks and customisations

  • Generated content

  • Context required to produce the requested output
     

TeachAid and its AI provider will not use Customer Data or Student Data to train general-purpose AI models.

Student names, answers, notes and drawings are not sent to AI providers.

TeachAid does not enable optional response storage for general production use. Limited provider abuse-monitoring records may be retained for up to 30 days under the provider’s business API terms.

Customer use of AI curriculum-generation or mapping features constitutes an instruction to process the selected content through the approved AI provider.


A customer requiring a different AI configuration must obtain a written order form or amendment before submitting affected content.
 

12. Rights and education-record requests

TeachAid will assist the customer with verified requests for:

  • Access

  • Correction

  • Deletion

  • Export

  • Portability

  • Parent or guardian rights

  • Eligible-student rights

  • Regulatory inquiries
     

Where TeachAid receives a request directly concerning customer-controlled information, TeachAid will ordinarily refer the requester to the customer and notify the customer.
 

The customer is responsible for verifying identity and authority for education-record requests.

TeachAid will provide Protected Data in a reasonably accessible format.

TeachAid will complete verified standard requests within 30 days, or sooner where law or a controlling agreement requires.

Where a controlling signed agreement requires five-day assistance, annual review, student-generated-content transfer or another process, TeachAid will follow that requirement.

13. Security incidents

TeachAid maintains a written incident-response procedure covering:

  • Identification

  • Containment

  • Investigation

  • Evidence preservation

  • Eradication

  • Recovery

  • Notification

  • Post-incident review
     

TeachAid will notify the customer:

  • Without undue delay; and

  • No later than 24 hours after confirming a Security Incident affecting the customer’s Protected Data
     

The initial notice may be preliminary.

As information becomes available, TeachAid will provide:

  • The nature of the incident

  • Known or estimated dates

  • Affected systems and information

  • Known or likely consequences

  • Containment and remediation measures

  • A contact for continuing questions

  • Continuing updates
     

TeachAid will cooperate with required investigations, mitigation and notices.

The customer normally controls communications to students, families, educators and personnel unless law requires TeachAid to notify them directly.

A jurisdiction-specific agreement may require additional content, expense allocation or response obligations and will control.
 

14. Audits and assessments

TeachAid will provide reasonable information needed for customer privacy and security reviews, including available:

  • Policies and procedures

  • Questionnaire responses

  • Internal review summaries

  • Subprocessor information

  • Retention information

  • Incident-response information

  • Independent reports
     

No more than once annually, and following a material Security Incident, the customer may audit safeguards relevant to the Services, subject to:

  • Reasonable notice

  • Confidentiality

  • Protection of other customers

  • Reasonable limits on disruption
     

TeachAid may first satisfy a request through documentation, remote review or an independent assessment, except where a controlling signed agreement requires broader access.
 

TeachAid will reasonably assist with privacy-impact assessments, data-protection impact assessments and regulatory inquiries.

15. Government and legal requests

TeachAid will review government and law-enforcement requests for legal validity.

TeachAid will disclose only information legally required.

TeachAid will notify the customer before compelled disclosure unless prohibited by law.

Where legally permitted and reasonable, TeachAid will challenge an overbroad request or direct the requesting authority to the customer.

A signed agreement requiring a specific advance-notice period will control.
 

16. Return, retention and deletion

During the agreement and for at least 30 days after termination, the customer may request a standard export of Customer Data in a reasonably accessible format.

TeachAid will delete Protected Data from active systems within 30 days after:

  • A verified customer instruction

  • Contract termination

  • The end of an agreed retention period

This does not apply where:

  • Law requires retention

  • A legal hold applies

  • A controlling agreement provides another process

  • Temporary retention is necessary to complete an authorised transfer
     

Backup copies remain protected, are unavailable for ordinary use and expire under the applicable backup schedule.

Unless a controlling agreement requires a shorter period, deleted Protected Data ages out of backups within 60 days. If a backup is restored, the deletion instruction is reapplied.

TeachAid will delete or instruct applicable Subprocessors to delete Protected Data.

TeachAid will provide written deletion confirmation where requested or required.

A signed state or district agreement may require:

  • Annual necessity reviews

  • A disposition directive

  • Advance deletion notice

  • A different export or deletion period

  • A separate certification process

That agreement will control.
 

Once Protected Data has been securely deleted, it may no longer be recoverable.
 

17. De-identified and aggregated information

TeachAid may use properly de-identified or aggregated information only for purposes permitted by Applicable Law and the agreement, such as:

  • Security

  • Reliability

  • Capacity planning

  • Service effectiveness

  • Improvement of the contracted educational service
     

TeachAid will not attempt to re-identify the information.
 

TeachAid will not identify the customer in a publication, case study or public report without written permission.
 

TeachAid will not transfer de-identified Student Data to another party except as permitted by the applicable agreement and law.
 

18. International processing

Core databases, files and primary backups are located in Canada.
 

Approved Subprocessors may process limited Protected Data in other jurisdictions identified in the subprocessor list.
 

A specific storage or processing-location commitment applies only where stated in the applicable order form, jurisdiction-specific agreement or deployment.
 

Where Applicable Law requires an international-transfer safeguard, the parties will use the applicable:

  • European Commission Standard Contractual Clauses

  • UK International Data Transfer Addendum or other lawful UK mechanism

  • Contractual, technical and organisational safeguards
     

Where the EU GDPR applies, this DPA contains the processor terms required by Article 28. GDPR Article 28 requires processor contracts to address instructions, confidentiality, security, subprocessors, rights assistance, deletion and audits.
 

European Economic Area

Where required, the European Commission Standard Contractual Clauses adopted under Decision 2021/914 are incorporated as follows:

  • Module Two applies where the customer is a controller and TeachAid is a processor

  • Module Three applies where the customer is a processor and TeachAid is a subprocessor

  • The docking clause applies

  • General written authorisation for Subprocessors applies

  • TeachAid will provide 30 days’ notice of relevant changes

  • The optional independent dispute-resolution clause does not apply

  • The law and courts selected will be those of Ireland unless the parties lawfully select another eligible jurisdiction

  • The agreement, this DPA, the subprocessor list and TeachAid’s security documentation complete the applicable annexes
     

United Kingdom

Where UK restricted-transfer rules apply, the UK International Data Transfer Addendum is incorporated into the applicable Standard Contractual Clauses. The commercial agreement, this DPA, the subprocessor list and security documentation complete its required tables.
 

19. Regional student-privacy requirements

Where applicable, TeachAid will support compliance with:

  • FERPA

  • COPPA

  • PPRA

  • New York Education Law §2-d and Part 121

  • Applicable United States state student-privacy laws

  • Canadian federal and provincial privacy laws

  • EU GDPR

  • UK GDPR

  • New Zealand Privacy Act 2020
     

TeachAid does not represent that one public DPA replaces a jurisdiction-specific agreement where the law or customer requires one.

New York requirements prohibit commercial or marketing use of Student PII and require contractual privacy and security safeguards.

For New Zealand customers, TeachAid’s 24-hour customer notice supports the customer’s duty to assess and notify serious breaches as soon as practicable; the New Zealand Privacy Commissioner generally expects notification within approximately 72 hours of awareness.

20. Change of control

This DPA binds permitted successors.

If TeachAid is involved in a merger, acquisition, reorganisation or sale of substantially all relevant assets, TeachAid will require the successor to assume applicable obligations.

TeachAid will provide change-of-control notice where required by the controlling agreement.

Where a controlling agreement gives the customer a right to object or terminate based on the successor, TeachAid will honour that right.
 

21. Term, liability and contact

This DPA remains effective while TeachAid processes Protected Data, including during return, retention and deletion periods.

Liability, indemnity, insurance, governing law and dispute terms are governed by the signed commercial agreement unless mandatory law or a controlling student-data agreement provides otherwise.

TeachAid contact:

Nadeem Aljaber
1000662662 Ontario Corporation dba TeachAid
515 Winston Road, Unit 23
Grimsby, Ontario L3M 0C8
Canada
nadeem@teachaid.ca

Term

Controller

Definition

The school, district, or educational agency that determines data purposes

  • Twitter
  • Instagram
  • LinkedIn

bottom of page