District-level DPA template for FERPA and SOPIPA compliance.
EverJoy School District Data Processing Agreement
Effective Date: July 1, 2026
Version: 2026-07
Entity: EverJoy Memory LLC d/b/a EverJoy ("Processor" or "EverJoy")
This Data Processing Agreement ("DPA") is entered into by and between:
District: [TODO: District legal name — complete per district contract], located at [TODO: District address — complete per district contract] ("District" or "Controller")
Processor: EverJoy Memory LLC, a [TODO: State of incorporation — confirm with counsel] LLC, with principal address at [TODO: Registered business address — confirm with counsel] ("EverJoy" or "Processor")
Effective Date: July 1, 2026
This DPA supplements and is incorporated into School Agreements between EverJoy and District schools, and governs EverJoy's processing of Personal Data on behalf of District.
"Applicable Privacy Laws" means FERPA (20 U.S.C. § 1232g), COPPA (15 U.S.C. §§ 6501–6506), SOPIPA (Cal. Bus. & Prof. Code §§ 22584–22584.6), CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq.), and other applicable federal and state student and consumer privacy laws.
"Controller" means the entity that determines the purposes and means of processing Personal Data. District is Controller for District-provided education records; parents are Controllers for parent-uploaded content.
"Education Records" has the meaning under FERPA (20 U.S.C. § 1232g(a)(4)).
"Personal Data" means any information relating to an identified or identifiable student, parent, or school personnel processed by EverJoy under this DPA.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
"Processor" means EverJoy, which processes Personal Data on behalf of Controller.
"School Agreement" means the EverJoy School Agreement executed with individual District schools.
"Subprocessor" means a third party engaged by EverJoy to process Personal Data.
"Student" means a student enrolled at a District school participating in EverJoy.
EverJoy operates a parent-directed service with a dual controller model:
| Data Category | Controller | Processor |
|---|---|---|
| Roster Data uploaded by schools | District | EverJoy |
| Parent-uploaded Memories | Parent | EverJoy |
| Capture artifacts (partner scan) | Parent (via booklet authorization) | EverJoy |
| Account/billing data | Parent | EverJoy |
| Aggregated analytics | EverJoy | N/A |
This DPA primarily governs District-provided Personal Data (Roster Data and school administrative data). Parent-controlled content is governed by the Privacy Policy and Parent Consent Agreement.
EverJoy acts as a service provider to parents, not a school official under FERPA. District shares Roster Data solely for parent-initiated activation matching. EverJoy does not access parent-uploaded Education Records through District authorization.
District designates EverJoy as a school official with a legitimate educational interest under FERPA for the following purposes: [TODO: Specify FERPA school official purposes — complete per district]. EverJoy agrees to:
Initial designation: ☐ Option A ☐ Option B
Processing of Personal Data related to EverJoy's Partner Capture Network and school directory services at District schools.
This DPA remains in effect for the term of School Agreements with District schools, plus any retention period required by Applicable Privacy Laws or Section 10.
| Processing Activity | Purpose |
|---|---|
| Roster Data storage | Parent-initiated child activation matching |
| Activation verification | Server-side DOB matching (not exposed to parents) |
| Capture artifact storage | Memory preservation for enrolled families |
| Aggregated reporting | School/district participation metrics |
| Audit logging | Security and compliance |
| Category | Examples | Source |
|---|---|---|
| Student identifiers | Name, school student ID, grade | District roster upload |
| Student demographics | Date of birth (verification only) | District roster upload |
| Student content | Photos of schoolwork, artwork | Partner capture (parent-authorized) |
| Parent identifiers | Name, email | Parent account creation |
| Usage data | Activation timestamps, capture metrics | System-generated |
EverJoy does not intentionally process special categories of data (health, biometric, etc.). Photos of student work may incidentally contain such information; processing is limited to memory preservation purposes.
EverJoy shall:
Process Personal Data only on documented instructions from District (via School Agreements and this DPA), unless required by law. EverJoy will notify District before processing required by law unless prohibited.
Ensure personnel authorized to process Personal Data are bound by confidentiality obligations.
Implement appropriate technical and organizational measures per the Security Policy (Volume 4), including:
Assist District in responding to data subject requests (access, correction, deletion, export) within 30 days of District request. Parents may also exercise rights directly via support@myeverjoy.com or privacy@myeverjoy.com.
Assist District with:
Upon termination or District request, delete or return Personal Data per Section 10, unless retention is required by law.
Make available information necessary to demonstrate compliance and allow audits (no more than once annually, with reasonable notice, subject to confidentiality).
For California students, EverJoy certifies compliance with SOPIPA:
EverJoy operates as a parent-directed service with verifiable parental consent before collecting child Personal Data. District-provided Roster Data is used solely for parent-initiated activation.
District shall:
EverJoy engages the Subprocessors listed in Exhibit A. District provides general authorization for these Subprocessors as of the Effective Date.
Each Subprocessor:
EverJoy will update Exhibit A and notify District at [TODO: District contact email — complete per district contract] at least 30 days before engaging new Subprocessors processing District-provided Personal Data.
A "Security Incident" means unauthorized access, acquisition, use, disclosure, modification, or destruction of Personal Data.
EverJoy will notify District without undue delay and within 72 hours of confirming a Security Incident affecting District-provided Personal Data, including:
EverJoy will cooperate with District's investigation and regulatory notification obligations. EverJoy will not notify affected individuals or regulators without coordinating with District, except where required by law.
EverJoy maintains an incident response program per the Security Policy (Volume 4), including containment, investigation, remediation, and post-incident review.
Personal Data is processed in the United States. If EverJoy transfers Personal Data internationally, it will implement appropriate safeguards (Standard Contractual Clauses or equivalent) as required by Applicable Privacy Laws.
| Data Category | Retention |
|---|---|
| Roster Data | Duration of School Agreement + 90 days |
| Capture artifacts | ~7 years (parent-controlled) |
| Audit logs | ~3 years |
| Consent records | ~7 years (revocation recorded) |
Within 90 days of DPA termination (or earlier upon District request):
Parents may delete Child Profiles and Memories independently. Such deletion removes associated capture artifacts and is not subject to District retention requirements.
For California residents, EverJoy:
District may direct parent rights requests to EverJoy at privacy@myeverjoy.com.
Each party's liability under this DPA is subject to the limitation of liability in the School Agreement, except for breaches of data protection obligations which shall not be subject to liability caps to the extent prohibited by Applicable Privacy Laws.
Each party will indemnify the other against claims arising from its breach of this DPA or violation of Applicable Privacy Laws in connection with Personal Data it controls.
This DPA remains in effect while any District school maintains an active School Agreement.
Either party may terminate this DPA if:
Sections 5.7 (Deletion), 8 (Security Incidents), 10 (Retention), and 12 (Liability) survive termination.
In case of conflict: (1) this DPA, (2) School Agreement, (3) EverJoy Terms of Service and Privacy Policy.
Amendments require written agreement. EverJoy may update Exhibit A (Subprocessors) with notice per Section 7.3.
This DPA is governed by the laws of California and Applicable Privacy Laws.
DISTRICT
[TODO: District legal name — complete per district contract]
By: _________________________________
Name: [SIGNATORY NAME]
Title: [TITLE]
Date: _________________________________
EVERJOY (PROCESSOR)
EverJoy Memory LLC
By: _________________________________
Name: [SIGNATORY NAME]
Title: [TITLE]
Date: _________________________________
| Subprocessor | Purpose | Location | Data Processed |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | United States | All Personal Data |
| Stripe, Inc. | Payment processing | United States | Parent billing data (no student content) |
| OpenAI, LLC | AI processing (with parent consent) | United States | Memory content, OCR text, growth signals |
| PostHog, Inc. | Product analytics | United States/EEA | Usage events (no child content) |
| Postmark (ActiveCampaign) | Transactional email | United States | Parent email addresses |
| SendGrid (Twilio) | Email fallback | United States | Parent email addresses |
| Vercel, Inc. | Application hosting | United States | Request logs, IP addresses |
EverJoy will maintain an updated subprocessor list at privacy@myeverjoy.com or [SUBPROCESSOR LIST URL].
See Security Policy (Volume 4) for complete details. Summary:
| Control Category | Measures |
|---|---|
| Access control | RLS, role-based access, family/school scoping |
| Authentication | Supabase Auth, email verification, session management |
| Encryption | TLS 1.2+ in transit; AES-256 at rest (cloud provider) |
| Storage security | Private buckets, signed URLs (1h UI / 15min AI) |
| Audit logging | Append-only logs, 3-year retention |
| Incident response | 72-hour notification, containment procedures |
| Personnel | Background checks, confidentiality agreements, training |
| Development | Secure SDLC, code review, dependency scanning |
District School
│
├── Roster Upload (admin) ──► EverJoy Database (RLS-protected)
│ │
│ ▼
│ Parent Activation (DOB match)
│ │
▼ ▼
Capture Partner ── Scan ──► Artifact Storage ◄── Parent Memory Inbox
(QR/barcode) (private bucket) (parent-controlled)
│
▼
AI Processing (optional, parent consent)
│
▼
OpenAI API (gpt-4o-mini)
| Level | Criteria | Response Time | Notification |
|---|---|---|---|
| P1 — Critical | Confirmed breach of child data | Immediate | District within 72 hours |
| P2 — High | Suspected unauthorized access | 1 hour | District within 72 hours if confirmed |
| P3 — Medium | Vulnerability with exploit potential | 4 hours | Internal; District if affected |
| P4 — Low | Policy violation, minor issue | 24 hours | Internal |
| Role | Responsibility |
|---|---|
| Incident Commander | Overall coordination |
| Security Lead | Technical investigation |
| Legal Counsel | Regulatory notification |
| Customer Success | District/parent communication |
| Engineering | Containment and remediation |
District notification includes:
EverJoy notifies regulators as required:
| Request | Controller | Processor Action | Timeline |
|---|---|---|---|
| Access | District (roster) / Parent (content) | Provide data export | 30 days |
| Correction | District / Parent | Update records | 15 days |
| Deletion | District / Parent | Execute erasure workflow | 30 days |
| Export | Parent | Generate portable export | 45 days |
District submits requests to privacy@myeverjoy.com with:
Parents submit directly to support@myeverjoy.com or privacy@myeverjoy.com.
EverJoy notifies District of parent deletion requests affecting roster-linked data.
EverJoy provides District with annual compliance summary:
District may request additional audit information with 30 days' notice.
District DPA version 2026-07. Execute alongside School Agreement(s). Legal review required.