EverJoyBack to home

School District Data Processing Agreement

District-level DPA template for FERPA and SOPIPA compliance.

EverJoy School District Data Processing Agreement

Effective Date: July 1, 2026
Version: 2026-07
Entity: EverJoy Memory LLC d/b/a EverJoy ("Processor" or "EverJoy")


Data Processing Agreement

This Data Processing Agreement ("DPA") is entered into by and between:

District: [TODO: District legal name — complete per district contract], located at [TODO: District address — complete per district contract] ("District" or "Controller")

Processor: EverJoy Memory LLC, a [TODO: State of incorporation — confirm with counsel] LLC, with principal address at [TODO: Registered business address — confirm with counsel] ("EverJoy" or "Processor")

Effective Date: July 1, 2026

This DPA supplements and is incorporated into School Agreements between EverJoy and District schools, and governs EverJoy's processing of Personal Data on behalf of District.


1. Definitions

"Applicable Privacy Laws" means FERPA (20 U.S.C. § 1232g), COPPA (15 U.S.C. §§ 6501–6506), SOPIPA (Cal. Bus. & Prof. Code §§ 22584–22584.6), CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq.), and other applicable federal and state student and consumer privacy laws.

"Controller" means the entity that determines the purposes and means of processing Personal Data. District is Controller for District-provided education records; parents are Controllers for parent-uploaded content.

"Education Records" has the meaning under FERPA (20 U.S.C. § 1232g(a)(4)).

"Personal Data" means any information relating to an identified or identifiable student, parent, or school personnel processed by EverJoy under this DPA.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

"Processor" means EverJoy, which processes Personal Data on behalf of Controller.

"School Agreement" means the EverJoy School Agreement executed with individual District schools.

"Subprocessor" means a third party engaged by EverJoy to process Personal Data.

"Student" means a student enrolled at a District school participating in EverJoy.


2. Scope and Roles

2.1 Dual Controller Model

EverJoy operates a parent-directed service with a dual controller model:

Data CategoryControllerProcessor
Roster Data uploaded by schoolsDistrictEverJoy
Parent-uploaded MemoriesParentEverJoy
Capture artifacts (partner scan)Parent (via booklet authorization)EverJoy
Account/billing dataParentEverJoy
Aggregated analyticsEverJoyN/A

This DPA primarily governs District-provided Personal Data (Roster Data and school administrative data). Parent-controlled content is governed by the Privacy Policy and Parent Consent Agreement.

2.2 FERPA School Official Designation

EverJoy acts as a service provider to parents, not a school official under FERPA. District shares Roster Data solely for parent-initiated activation matching. EverJoy does not access parent-uploaded Education Records through District authorization.

District designates EverJoy as a school official with a legitimate educational interest under FERPA for the following purposes: [TODO: Specify FERPA school official purposes — complete per district]. EverJoy agrees to:

  1. Perform an institutional service or function for which District would otherwise use employees
  2. Remain under direct control of District regarding use and maintenance of Education Records
  3. Use Education Records only for authorized purposes
  4. Not disclose Education Records to third parties without District authorization (except subprocessors bound by equivalent obligations)

Initial designation: ☐ Option A ☐ Option B


3. Subject Matter and Duration

3.1 Subject Matter

Processing of Personal Data related to EverJoy's Partner Capture Network and school directory services at District schools.

3.2 Duration

This DPA remains in effect for the term of School Agreements with District schools, plus any retention period required by Applicable Privacy Laws or Section 10.

3.3 Nature and Purpose

Processing ActivityPurpose
Roster Data storageParent-initiated child activation matching
Activation verificationServer-side DOB matching (not exposed to parents)
Capture artifact storageMemory preservation for enrolled families
Aggregated reportingSchool/district participation metrics
Audit loggingSecurity and compliance

4. Categories of Data Subjects and Personal Data

4.1 Data Subjects

4.2 Categories of Personal Data

CategoryExamplesSource
Student identifiersName, school student ID, gradeDistrict roster upload
Student demographicsDate of birth (verification only)District roster upload
Student contentPhotos of schoolwork, artworkPartner capture (parent-authorized)
Parent identifiersName, emailParent account creation
Usage dataActivation timestamps, capture metricsSystem-generated

4.3 Special Categories

EverJoy does not intentionally process special categories of data (health, biometric, etc.). Photos of student work may incidentally contain such information; processing is limited to memory preservation purposes.


5. Processor Obligations

EverJoy shall:

5.1 Process Only on Instructions

Process Personal Data only on documented instructions from District (via School Agreements and this DPA), unless required by law. EverJoy will notify District before processing required by law unless prohibited.

5.2 Confidentiality

Ensure personnel authorized to process Personal Data are bound by confidentiality obligations.

5.3 Security

Implement appropriate technical and organizational measures per the Security Policy (Volume 4), including:

5.4 Subprocessors

  1. District authorizes EverJoy's use of Subprocessors listed in Exhibit A
  2. EverJoy will notify District of new Subprocessors with 30 days' notice
  3. District may object to new Subprocessors on reasonable grounds
  4. EverJoy ensures Subprocessors are bound by equivalent data protection obligations
  5. EverJoy remains liable for Subprocessor performance

5.5 Data Subject Rights

Assist District in responding to data subject requests (access, correction, deletion, export) within 30 days of District request. Parents may also exercise rights directly via support@myeverjoy.com or privacy@myeverjoy.com.

5.6 Assistance

Assist District with:

5.7 Deletion and Return

Upon termination or District request, delete or return Personal Data per Section 10, unless retention is required by law.

5.8 Audit

Make available information necessary to demonstrate compliance and allow audits (no more than once annually, with reasonable notice, subject to confidentiality).

5.9 SOPIPA Compliance

For California students, EverJoy certifies compliance with SOPIPA:

5.10 COPPA Compliance

EverJoy operates as a parent-directed service with verifiable parental consent before collecting child Personal Data. District-provided Roster Data is used solely for parent-initiated activation.


6. Controller Obligations

District shall:

  1. Ensure lawful basis for sharing Roster Data with EverJoy
  2. Obtain any necessary consents or provide required notices to parents
  3. Upload accurate and current Roster Data
  4. Designate Authorized School Personnel
  5. Notify EverJoy of parent complaints or regulatory inquiries affecting Personal Data
  6. Not instruct EverJoy to process Personal Data in violation of Applicable Privacy Laws

7. Subprocessors

7.1 Authorized Subprocessors

EverJoy engages the Subprocessors listed in Exhibit A. District provides general authorization for these Subprocessors as of the Effective Date.

7.2 Subprocessor Requirements

Each Subprocessor:

  1. Processes Personal Data only per EverJoy's instructions
  2. Implements appropriate security measures
  3. Is bound by written agreement with equivalent data protection obligations
  4. Assists with data subject requests and security incidents

7.3 Notification of Changes

EverJoy will update Exhibit A and notify District at [TODO: District contact email — complete per district contract] at least 30 days before engaging new Subprocessors processing District-provided Personal Data.


8. Security Incidents and Breach Notification

8.1 Incident Definition

A "Security Incident" means unauthorized access, acquisition, use, disclosure, modification, or destruction of Personal Data.

8.2 Notification

EverJoy will notify District without undue delay and within 72 hours of confirming a Security Incident affecting District-provided Personal Data, including:

  1. Nature of the incident
  2. Categories and approximate number of data subjects affected
  3. Likely consequences
  4. Measures taken or proposed to address the incident

8.3 Cooperation

EverJoy will cooperate with District's investigation and regulatory notification obligations. EverJoy will not notify affected individuals or regulators without coordinating with District, except where required by law.

8.4 Incident Response

EverJoy maintains an incident response program per the Security Policy (Volume 4), including containment, investigation, remediation, and post-incident review.


9. International Transfers

Personal Data is processed in the United States. If EverJoy transfers Personal Data internationally, it will implement appropriate safeguards (Standard Contractual Clauses or equivalent) as required by Applicable Privacy Laws.


10. Data Retention and Deletion

10.1 Retention Periods

Data CategoryRetention
Roster DataDuration of School Agreement + 90 days
Capture artifacts~7 years (parent-controlled)
Audit logs~3 years
Consent records~7 years (revocation recorded)

10.2 Deletion upon Termination

Within 90 days of DPA termination (or earlier upon District request):

  1. Delete District-provided Roster Data
  2. Retain parent-controlled content per parent accounts (parents may delete independently)
  3. Retain audit logs and consent records as required by law
  4. Provide written certification of deletion upon District request

10.3 Parent-Initiated Deletion

Parents may delete Child Profiles and Memories independently. Such deletion removes associated capture artifacts and is not subject to District retention requirements.


11. California Privacy Rights (CPRA)

For California residents, EverJoy:

  1. Does not sell Personal Data
  2. Does not share Personal Data for cross-context behavioral advertising
  3. Processes sensitive Personal Data only as necessary for Service purposes
  4. Honors Global Privacy Control signals where applicable
  5. Responds to consumer rights requests within 45 days

District may direct parent rights requests to EverJoy at privacy@myeverjoy.com.


12. Liability and Indemnification

12.1 Liability

Each party's liability under this DPA is subject to the limitation of liability in the School Agreement, except for breaches of data protection obligations which shall not be subject to liability caps to the extent prohibited by Applicable Privacy Laws.

12.2 Indemnification

Each party will indemnify the other against claims arising from its breach of this DPA or violation of Applicable Privacy Laws in connection with Personal Data it controls.


13. Term and Termination

13.1 Term

This DPA remains in effect while any District school maintains an active School Agreement.

13.2 Termination

Either party may terminate this DPA if:

  1. All School Agreements with District schools have terminated
  2. The other party materially breaches and fails to cure within 30 days
  3. Required by Applicable Privacy Laws

13.3 Survival

Sections 5.7 (Deletion), 8 (Security Incidents), 10 (Retention), and 12 (Liability) survive termination.


14. General Provisions

14.1 Order of Precedence

In case of conflict: (1) this DPA, (2) School Agreement, (3) EverJoy Terms of Service and Privacy Policy.

14.2 Amendment

Amendments require written agreement. EverJoy may update Exhibit A (Subprocessors) with notice per Section 7.3.

14.3 Governing Law

This DPA is governed by the laws of California and Applicable Privacy Laws.


Signatures

DISTRICT

[TODO: District legal name — complete per district contract]

By: _________________________________
Name: [SIGNATORY NAME]
Title: [TITLE]
Date: _________________________________

EVERJOY (PROCESSOR)

EverJoy Memory LLC

By: _________________________________
Name: [SIGNATORY NAME]
Title: [TITLE]
Date: _________________________________


Exhibit A: Authorized Subprocessors

SubprocessorPurposeLocationData Processed
Supabase, Inc.Database, authentication, file storageUnited StatesAll Personal Data
Stripe, Inc.Payment processingUnited StatesParent billing data (no student content)
OpenAI, LLCAI processing (with parent consent)United StatesMemory content, OCR text, growth signals
PostHog, Inc.Product analyticsUnited States/EEAUsage events (no child content)
Postmark (ActiveCampaign)Transactional emailUnited StatesParent email addresses
SendGrid (Twilio)Email fallbackUnited StatesParent email addresses
Vercel, Inc.Application hostingUnited StatesRequest logs, IP addresses

EverJoy will maintain an updated subprocessor list at privacy@myeverjoy.com or [SUBPROCESSOR LIST URL].


Exhibit B: Technical and Organizational Measures

See Security Policy (Volume 4) for complete details. Summary:

Control CategoryMeasures
Access controlRLS, role-based access, family/school scoping
AuthenticationSupabase Auth, email verification, session management
EncryptionTLS 1.2+ in transit; AES-256 at rest (cloud provider)
Storage securityPrivate buckets, signed URLs (1h UI / 15min AI)
Audit loggingAppend-only logs, 3-year retention
Incident response72-hour notification, containment procedures
PersonnelBackground checks, confidentiality agreements, training
DevelopmentSecure SDLC, code review, dependency scanning

Exhibit C: Data Flow Diagram

District School
    │
    ├── Roster Upload (admin) ──► EverJoy Database (RLS-protected)
    │                                    │
    │                                    ▼
    │                           Parent Activation (DOB match)
    │                                    │
    ▼                                    ▼
Capture Partner ── Scan ──► Artifact Storage ◄── Parent Memory Inbox
    (QR/barcode)              (private bucket)        (parent-controlled)
                                    │
                                    ▼
                            AI Processing (optional, parent consent)
                                    │
                                    ▼
                            OpenAI API (gpt-4o-mini)


Exhibit D: Security Incident Response Plan

D.1 Incident Severity Levels

LevelCriteriaResponse TimeNotification
P1 — CriticalConfirmed breach of child dataImmediateDistrict within 72 hours
P2 — HighSuspected unauthorized access1 hourDistrict within 72 hours if confirmed
P3 — MediumVulnerability with exploit potential4 hoursInternal; District if affected
P4 — LowPolicy violation, minor issue24 hoursInternal

D.2 Incident Response Team

RoleResponsibility
Incident CommanderOverall coordination
Security LeadTechnical investigation
Legal CounselRegulatory notification
Customer SuccessDistrict/parent communication
EngineeringContainment and remediation

D.3 Notification Content

District notification includes:

  1. Description of incident
  2. Categories of data affected
  3. Approximate number of students affected
  4. Actions taken to contain
  5. Remediation steps
  6. Contact for questions

D.4 Regulatory Notification

EverJoy notifies regulators as required:


Exhibit E: Data Subject Request Procedures

E.1 Request Types

RequestControllerProcessor ActionTimeline
AccessDistrict (roster) / Parent (content)Provide data export30 days
CorrectionDistrict / ParentUpdate records15 days
DeletionDistrict / ParentExecute erasure workflow30 days
ExportParentGenerate portable export45 days

E.2 District-Initiated Requests

District submits requests to privacy@myeverjoy.com with:

E.3 Parent-Initiated Requests

Parents submit directly to support@myeverjoy.com or privacy@myeverjoy.com.

EverJoy notifies District of parent deletion requests affecting roster-linked data.


Exhibit F: Annual Compliance Audit

EverJoy provides District with annual compliance summary:

  1. Subprocessor list (current)
  2. Security incident summary (if any)
  3. Data subject request statistics
  4. Policy version changes
  5. Certification of SOPIPA/FERPA compliance

District may request additional audit information with 30 days' notice.


District DPA version 2026-07. Execute alongside School Agreement(s). Legal review required.

Back to home