Data Processing Agreement

Standard template · Version 2026-07-24 · Print or save as PDF for your vendor file.

How to use. Fill bracketed fields, attach Schedules A–D, and have authorized signatories execute. Education customers should complete Schedule D. This template is for negotiation and is not legal advice; both parties should have counsel review. Related public commitments: Security & trust and Privacy Policy. Questions: dpo@podz.ai.

Podz.ai Inc. (“Processor” / “Podz”)
and
[Customer Legal Name] (“Controller” / “Customer”)

Effective Date[YYYY-MM-DD]
Customer privacy notice email[privacy@customer.edu]
Customer security notice email[security@customer.edu]
Podz privacy / DPAdpo@podz.ai
Podz security incidentsinfo@podz.ai
Governing law[State / United States]
Venue[County / State courts, or arbitration]

1. Purpose and scope

1.1 Customer uses Podz’s responsibility-management and related services (the “Services”) under the Podz Terms of Service or a separate order / MSA (the “Main Agreement”).

1.2 This Data Processing Agreement (“DPA”) forms part of the Main Agreement and governs Podz’s processing of Customer Personal Data on behalf of Customer. If there is a conflict between this DPA and the Main Agreement on data-protection matters, this DPA controls.

1.3 Details of processing are set out in Schedule A.

2. Definitions

“Customer Personal Data” means personal data or personally identifiable information that Customer (or its Authorized Users) submit to the Services, or that Podz processes on Customer’s behalf in providing the Services, including Student Data when Schedule D applies.

“Data Protection Law” means applicable laws relating to personal data, privacy, and security, including where applicable the GDPR, UK GDPR, CCPA/CPRA, FERPA, COPPA, and U.S. state student-privacy laws.

“Personal Data Breach” means a confirmed security incident resulting in unauthorized access to, or acquisition of, Customer Personal Data processed by Podz.

“Subprocessor” means a third party engaged by Podz to process Customer Personal Data in connection with the Services.

“Student Data” means Customer Personal Data that is education records or student personally identifiable information under FERPA or applicable state student-privacy law.

3. Roles of the parties

3.1 Customer is the controller (or, for U.S. education use under Schedule D, the educational agency / institution that owns or controls the Student Data).

3.2 Podz is the processor (or, under Schedule D, a service provider / “school official” with a legitimate educational interest solely to provide the Services). Podz processes Customer Personal Data only on documented instructions from Customer, including via Customer’s configuration and use of the Services.

3.3 Each party will comply with Data Protection Law applicable to its role.

4. Customer instructions and responsibilities

4.1 Customer instructs Podz to process Customer Personal Data as necessary to: (a) provide, maintain, and support the Services; (b) prevent or address security or technical issues; (c) comply with law; and (d) as otherwise agreed in writing.

4.2 Customer is responsible for: (a) the accuracy and lawfulness of Customer Personal Data it submits; (b) providing any notices and obtaining any consents required; (c) configuring optional integrations (SMS, Slack, Gmail, AI assist) consistent with its policies; and (d) not submitting special-category or highly sensitive data unless Schedule A expressly covers it.

4.3 If Podz believes an instruction infringes Data Protection Law, it will notify Customer without undue delay and may suspend performance of that instruction until clarified.

5. Confidentiality

5.1 Podz will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process such data only as needed to perform the Services.

6. Security

6.1 Podz will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, as summarized in Schedule C and described at podz.ai/security.

6.2 Customer acknowledges that no method of transmission or storage is completely secure. Podz’s obligations are of reasonable care consistent with the nature of the Services and the sensitivity of the data Customer chooses to submit.

7. Subprocessors

7.1 Customer authorizes Podz to engage Subprocessors listed in Schedule B (and at podz.ai/security).

7.2 Podz will impose data-protection obligations on Subprocessors that are no less protective in substance than this DPA, and remains responsible to Customer for Subprocessors’ performance of those obligations with respect to Customer Personal Data.

7.3 Notice of changes. Podz will provide Customer at least [30] days’ prior notice (email to Customer’s privacy notice address) before authorizing a new Subprocessor that will process Customer Personal Data, except for emergency replacements needed to maintain the Services. Customer may object on reasonable data-protection grounds within [15] days of notice. If unresolved, Customer may terminate the affected Services as its sole remedy for that objection.

7.4 Optional integrations (Twilio SMS, Slack, Gmail / Google Workspace, OpenAI, Google Gemini) process Customer Personal Data only if Customer enables or connects them.

8. Assistance; data-subject and consumer requests

8.1 Taking into account the nature of processing, Podz will provide reasonable assistance to Customer in responding to requests from data subjects or consumers under Data Protection Law.

8.2 If Podz receives a request directly that identifies Customer, Podz will, unless prohibited by law, promptly redirect the requester to Customer or notify Customer.

8.3 Verified erasure timelines (unless a shorter period is required by law or Schedule D):

StepTimeline
Acknowledge verified privacy / erasure requestWithin 10 business days
Complete erasure from production systemsWithin 30 days of verification
Remove residual copies from encrypted backupsOn normal backup rotation, typically within 90 days after production deletion

8.4 Podz may retain Customer Personal Data when legally required (for example, certain billing or tax records) and will limit such retention to what the law requires.

9. Personal Data Breach

9.1 Podz will notify Customer’s security and privacy notice contacts without undue delay and within seventy-two (72) hours after confirming a Personal Data Breach (or sooner if required by applicable law).

9.2 Notice will include, to the extent known: nature of the incident; categories of Customer Personal Data involved; approximate scope; mitigation steps underway; and a contact for follow-up. Information may be provided in phases.

9.3 Podz will reasonably cooperate with Customer’s investigation and any legally required notifications. Customer remains responsible for determining whether notice to individuals or regulators is required, except where law obligates Podz directly.

9.4 Suspected incidents may be reported to info@podz.ai.

10. Return and deletion

10.1 Upon termination or expiration of the Services, or upon Customer’s written request, Podz will delete Customer Personal Data from production systems within 30 days, subject to Section 8.4, and purge backups on the schedule in Section 8.3.

10.2 Upon Customer’s written request made before deletion completes, Podz will make available a reasonable export of Customer Personal Data then available through the Services or standard support processes.

11. Audits and information

11.1 Upon reasonable written request (no more than once per twelve (12) months, unless following a Personal Data Breach or regulator request), Podz will provide information reasonably necessary to demonstrate compliance with this DPA, which may include completed security questionnaires, current subprocessor list, and summaries of relevant policies or controls.

11.2 Podz is not currently SOC 2 Type I or Type II certified. Podz will share audit-roadmap updates on request. On-site audits are available only by mutual written agreement, during business hours, without unreasonably disrupting operations, and at Customer’s expense unless a material breach of this DPA is found.

12. International transfers

12.1 Primary production compute is operated in the United States (Google Cloud region us-central1). Customer Personal Data may be processed in the United States and, where Subprocessors are located elsewhere, in those locations.

12.2 Where Data Protection Law requires a transfer mechanism (for example, EU Standard Contractual Clauses), the parties will execute the appropriate module(s) or rely on another lawful mechanism. [Attach SCCs if Customer is subject to GDPR / UK GDPR.]

13. Use limitations (including AI and advertising)

13.1 Podz will not: (a) sell Customer Personal Data; (b) use Customer Personal Data to deliver third-party advertising; or (c) use Customer Personal Data from Customer’s organization to train generalized foundation models.

13.2 Optional AI features may transmit prompts and relevant context to model providers only when Customer or its users invoke those features. Customer may disable or refrain from using AI features.

13.3 If Customer connects Google Workspace / Gmail APIs, Podz’s use of that data will adhere to Google’s API Services User Data Policy, including Limited Use.

14. Term

14.1 This DPA takes effect on the Effective Date and continues until Podz ceases processing Customer Personal Data under the Main Agreement, except that provisions that by nature should survive (confidentiality, deletion, liability allocation as in the Main Agreement, and education obligations in Schedule D) survive termination.

15. Liability; order of precedence

15.1 Each party’s liability under this DPA is subject to the limitations and exclusions in the Main Agreement, except to the extent Data Protection Law prohibits such limitation.

15.2 Order of precedence for data-protection conflicts: (1) Schedule D (if applicable); (2) this DPA body; (3) Schedules A–C; (4) Main Agreement; (5) Privacy Policy.

16. General

16.1 Notices under this DPA must be sent to the emails listed above (or updated in writing).

16.2 This DPA may be executed in counterparts (including electronic signature), each of which is deemed an original.

16.3 Amendments must be in writing and signed or otherwise accepted by both parties, except that Podz may update Schedule B via the notice process in Section 7.3.

Signature blocks

Customer

Signature: _______________________

Name: _______________________

Title: _______________________

Date: _______________________

Podz.ai Inc.

Signature: _______________________

Name: _______________________

Title: _______________________

Date: _______________________

Schedule A — Details of processing

Subject matterProvision of the Podz Services (mandates, commitments, people directory, messaging, optional events/attendance, optional AI assist, related support)
DurationTerm of the Main Agreement + deletion period in Sections 8–10
Nature and purposeHosting, storage, transmission, display, messaging, analytics necessary to operate the Services, and support
Categories of data subjectsCustomer’s personnel, members, participants, and (if applicable) students, parents/guardians, and volunteers as configured by Customer
Categories of personal dataAccount identifiers (name, email); optional phone; optional profile fields; org directory fields; user-generated content; usage and log data; integration identifiers if enabled
Special / sensitive dataNone intended. Customer will not upload IEPs, health records, free/reduced-lunch status, government IDs, or similar unless expressly listed here: [None / describe]
Processing operationsCollection, storage, retrieval, transmission, deletion, and related operations to provide the Services

Schedule B — Authorized subprocessors

Current list (also published at podz.ai/security):

SubprocessorRoleStatus
Google Cloud PlatformHosting, storage, schedulingCore
Google FirebaseAuthenticationCore
Bunny.netCDN / media deliveryCore
SendGridEmail delivery and inbound parseCore
StripeBilling and paymentsWhen Customer purchases
Google AnalyticsProduct / marketing analyticsConsent-gated where applicable
TwilioSMSOptional — Customer-enabled
SlackWorkspace messagingOptional — Customer-connected
Google (Gmail / Workspace APIs)Email automationOptional — Customer-connected
OpenAIAI assistOptional — when AI features used
Google GeminiAI assistOptional — when AI features used

Customer’s enabled optional integrations as of the Effective Date: [list or “none”].

Schedule C — Technical and organizational measures (summary)

AreaMeasures
Transport securityHTTPS / TLS for production traffic
AuthenticationFirebase Authentication; session validation on API requests
Access controlOrganization-scoped authorization; role-based admin/member controls enforced server-side
HostingGoogle Cloud; primary region us-central1
CredentialsIntegration credentials stored for the connecting organization only when authorized
Logging / monitoringApplication and infrastructure logs for security and operations
PersonnelConfidentiality obligations for authorized personnel
Secure developmentAccess controls on production systems; change deployment via controlled cloud pipelines

Schedule D — Education / FERPA addendum

Complete this Schedule when Customer is a K–12 school, district, or other educational agency / institution processing Student Data in the Services.

D.1 School official. To the extent Podz receives Student Data in education records under FERPA, Customer designates Podz as a “school official” with a legitimate educational interest, solely to provide the Services. Podz will use Student Data only for that purpose and will not redisclose Student Data except as directed by Customer or as permitted by FERPA and this DPA.

D.2 No sale; no targeted advertising. Podz will not sell Student Data and will not use Student Data to deliver third-party targeted advertising.

D.3 Parent / eligible student rights. Podz will reasonably assist Customer in fulfilling access, correction, and related requests regarding Student Data. Customer remains the primary point of contact for parents and eligible students.

D.4 Subprocessors. Student Data may be processed by Subprocessors in Schedule B only as needed to provide the Services. Optional integrations that export Student Data outside Podz (SMS, Slack, Gmail, AI) remain off unless Customer enables them.

D.5 Breach. Personal Data Breach notification under Section 9 applies to Student Data. Podz will cooperate with Customer’s obligations under FERPA and applicable state student-privacy breach laws.

D.6 Deletion. Upon written request at the end of a term, school year, or agreement, Podz will delete Student Data per Sections 8–10. Customer should export any records it must retain before requesting deletion.

D.7 COPPA. Podz is not directed to children under 13. Customer will not create accounts for children under 13 unless Customer has obtained any required parental consent and the parties have confirmed in writing: [Not applicable / parental consent approach: _____].

D.8 Data ownership. As between the parties, Customer retains all right, title, and interest in Student Data. Podz obtains only a limited license to process Student Data to provide the Services.

D.9 Prohibited data (default). Unless listed in Schedule A, Customer will not upload to the Services: IEPs or 504 plans, medical/health records, Social Security numbers, or special-population indicators not required for the Services.

Customer education contact: [Name, title, email]
Podz education / DPA contact: dpo@podz.ai

Template version 2026-07-24. Markdown source in repo: docs/legal/dpa-template.md.