Standard template · Version 2026-07-24 · Print or save as PDF for your vendor file.
Podz.ai Inc. (“Processor” / “Podz”)
and
[Customer Legal Name] (“Controller” / “Customer”)
| Effective Date | [YYYY-MM-DD] |
|---|---|
| Customer privacy notice email | [privacy@customer.edu] |
| Customer security notice email | [security@customer.edu] |
| Podz privacy / DPA | dpo@podz.ai |
| Podz security incidents | info@podz.ai |
| Governing law | [State / United States] |
| Venue | [County / State courts, or arbitration] |
1.1 Customer uses Podz’s responsibility-management and related services (the “Services”) under the Podz Terms of Service or a separate order / MSA (the “Main Agreement”).
1.2 This Data Processing Agreement (“DPA”) forms part of the Main Agreement and governs Podz’s processing of Customer Personal Data on behalf of Customer. If there is a conflict between this DPA and the Main Agreement on data-protection matters, this DPA controls.
1.3 Details of processing are set out in Schedule A.
“Customer Personal Data” means personal data or personally identifiable information that Customer (or its Authorized Users) submit to the Services, or that Podz processes on Customer’s behalf in providing the Services, including Student Data when Schedule D applies.
“Data Protection Law” means applicable laws relating to personal data, privacy, and security, including where applicable the GDPR, UK GDPR, CCPA/CPRA, FERPA, COPPA, and U.S. state student-privacy laws.
“Personal Data Breach” means a confirmed security incident resulting in unauthorized access to, or acquisition of, Customer Personal Data processed by Podz.
“Subprocessor” means a third party engaged by Podz to process Customer Personal Data in connection with the Services.
“Student Data” means Customer Personal Data that is education records or student personally identifiable information under FERPA or applicable state student-privacy law.
3.1 Customer is the controller (or, for U.S. education use under Schedule D, the educational agency / institution that owns or controls the Student Data).
3.2 Podz is the processor (or, under Schedule D, a service provider / “school official” with a legitimate educational interest solely to provide the Services). Podz processes Customer Personal Data only on documented instructions from Customer, including via Customer’s configuration and use of the Services.
3.3 Each party will comply with Data Protection Law applicable to its role.
4.1 Customer instructs Podz to process Customer Personal Data as necessary to: (a) provide, maintain, and support the Services; (b) prevent or address security or technical issues; (c) comply with law; and (d) as otherwise agreed in writing.
4.2 Customer is responsible for: (a) the accuracy and lawfulness of Customer Personal Data it submits; (b) providing any notices and obtaining any consents required; (c) configuring optional integrations (SMS, Slack, Gmail, AI assist) consistent with its policies; and (d) not submitting special-category or highly sensitive data unless Schedule A expressly covers it.
4.3 If Podz believes an instruction infringes Data Protection Law, it will notify Customer without undue delay and may suspend performance of that instruction until clarified.
5.1 Podz will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process such data only as needed to perform the Services.
6.1 Podz will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, as summarized in Schedule C and described at podz.ai/security.
6.2 Customer acknowledges that no method of transmission or storage is completely secure. Podz’s obligations are of reasonable care consistent with the nature of the Services and the sensitivity of the data Customer chooses to submit.
7.1 Customer authorizes Podz to engage Subprocessors listed in Schedule B (and at podz.ai/security).
7.2 Podz will impose data-protection obligations on Subprocessors that are no less protective in substance than this DPA, and remains responsible to Customer for Subprocessors’ performance of those obligations with respect to Customer Personal Data.
7.3 Notice of changes. Podz will provide Customer at least [30] days’ prior notice (email to Customer’s privacy notice address) before authorizing a new Subprocessor that will process Customer Personal Data, except for emergency replacements needed to maintain the Services. Customer may object on reasonable data-protection grounds within [15] days of notice. If unresolved, Customer may terminate the affected Services as its sole remedy for that objection.
7.4 Optional integrations (Twilio SMS, Slack, Gmail / Google Workspace, OpenAI, Google Gemini) process Customer Personal Data only if Customer enables or connects them.
8.1 Taking into account the nature of processing, Podz will provide reasonable assistance to Customer in responding to requests from data subjects or consumers under Data Protection Law.
8.2 If Podz receives a request directly that identifies Customer, Podz will, unless prohibited by law, promptly redirect the requester to Customer or notify Customer.
8.3 Verified erasure timelines (unless a shorter period is required by law or Schedule D):
| Step | Timeline |
|---|---|
| Acknowledge verified privacy / erasure request | Within 10 business days |
| Complete erasure from production systems | Within 30 days of verification |
| Remove residual copies from encrypted backups | On normal backup rotation, typically within 90 days after production deletion |
8.4 Podz may retain Customer Personal Data when legally required (for example, certain billing or tax records) and will limit such retention to what the law requires.
9.1 Podz will notify Customer’s security and privacy notice contacts without undue delay and within seventy-two (72) hours after confirming a Personal Data Breach (or sooner if required by applicable law).
9.2 Notice will include, to the extent known: nature of the incident; categories of Customer Personal Data involved; approximate scope; mitigation steps underway; and a contact for follow-up. Information may be provided in phases.
9.3 Podz will reasonably cooperate with Customer’s investigation and any legally required notifications. Customer remains responsible for determining whether notice to individuals or regulators is required, except where law obligates Podz directly.
9.4 Suspected incidents may be reported to info@podz.ai.
10.1 Upon termination or expiration of the Services, or upon Customer’s written request, Podz will delete Customer Personal Data from production systems within 30 days, subject to Section 8.4, and purge backups on the schedule in Section 8.3.
10.2 Upon Customer’s written request made before deletion completes, Podz will make available a reasonable export of Customer Personal Data then available through the Services or standard support processes.
11.1 Upon reasonable written request (no more than once per twelve (12) months, unless following a Personal Data Breach or regulator request), Podz will provide information reasonably necessary to demonstrate compliance with this DPA, which may include completed security questionnaires, current subprocessor list, and summaries of relevant policies or controls.
11.2 Podz is not currently SOC 2 Type I or Type II certified. Podz will share audit-roadmap updates on request. On-site audits are available only by mutual written agreement, during business hours, without unreasonably disrupting operations, and at Customer’s expense unless a material breach of this DPA is found.
12.1 Primary production compute is operated in the United States (Google Cloud region us-central1). Customer Personal Data may be processed in the United States and, where Subprocessors are located elsewhere, in those locations.
12.2 Where Data Protection Law requires a transfer mechanism (for example, EU Standard Contractual Clauses), the parties will execute the appropriate module(s) or rely on another lawful mechanism. [Attach SCCs if Customer is subject to GDPR / UK GDPR.]
13.1 Podz will not: (a) sell Customer Personal Data; (b) use Customer Personal Data to deliver third-party advertising; or (c) use Customer Personal Data from Customer’s organization to train generalized foundation models.
13.2 Optional AI features may transmit prompts and relevant context to model providers only when Customer or its users invoke those features. Customer may disable or refrain from using AI features.
13.3 If Customer connects Google Workspace / Gmail APIs, Podz’s use of that data will adhere to Google’s API Services User Data Policy, including Limited Use.
14.1 This DPA takes effect on the Effective Date and continues until Podz ceases processing Customer Personal Data under the Main Agreement, except that provisions that by nature should survive (confidentiality, deletion, liability allocation as in the Main Agreement, and education obligations in Schedule D) survive termination.
15.1 Each party’s liability under this DPA is subject to the limitations and exclusions in the Main Agreement, except to the extent Data Protection Law prohibits such limitation.
15.2 Order of precedence for data-protection conflicts: (1) Schedule D (if applicable); (2) this DPA body; (3) Schedules A–C; (4) Main Agreement; (5) Privacy Policy.
16.1 Notices under this DPA must be sent to the emails listed above (or updated in writing).
16.2 This DPA may be executed in counterparts (including electronic signature), each of which is deemed an original.
16.3 Amendments must be in writing and signed or otherwise accepted by both parties, except that Podz may update Schedule B via the notice process in Section 7.3.
Customer
Signature: _______________________
Name: _______________________
Title: _______________________
Date: _______________________
Podz.ai Inc.
Signature: _______________________
Name: _______________________
Title: _______________________
Date: _______________________
| Subject matter | Provision of the Podz Services (mandates, commitments, people directory, messaging, optional events/attendance, optional AI assist, related support) |
|---|---|
| Duration | Term of the Main Agreement + deletion period in Sections 8–10 |
| Nature and purpose | Hosting, storage, transmission, display, messaging, analytics necessary to operate the Services, and support |
| Categories of data subjects | Customer’s personnel, members, participants, and (if applicable) students, parents/guardians, and volunteers as configured by Customer |
| Categories of personal data | Account identifiers (name, email); optional phone; optional profile fields; org directory fields; user-generated content; usage and log data; integration identifiers if enabled |
| Special / sensitive data | None intended. Customer will not upload IEPs, health records, free/reduced-lunch status, government IDs, or similar unless expressly listed here: [None / describe] |
| Processing operations | Collection, storage, retrieval, transmission, deletion, and related operations to provide the Services |
Current list (also published at podz.ai/security):
| Subprocessor | Role | Status |
|---|---|---|
| Google Cloud Platform | Hosting, storage, scheduling | Core |
| Google Firebase | Authentication | Core |
| Bunny.net | CDN / media delivery | Core |
| SendGrid | Email delivery and inbound parse | Core |
| Stripe | Billing and payments | When Customer purchases |
| Google Analytics | Product / marketing analytics | Consent-gated where applicable |
| Twilio | SMS | Optional — Customer-enabled |
| Slack | Workspace messaging | Optional — Customer-connected |
| Google (Gmail / Workspace APIs) | Email automation | Optional — Customer-connected |
| OpenAI | AI assist | Optional — when AI features used |
| Google Gemini | AI assist | Optional — when AI features used |
Customer’s enabled optional integrations as of the Effective Date: [list or “none”].
| Area | Measures |
|---|---|
| Transport security | HTTPS / TLS for production traffic |
| Authentication | Firebase Authentication; session validation on API requests |
| Access control | Organization-scoped authorization; role-based admin/member controls enforced server-side |
| Hosting | Google Cloud; primary region us-central1 |
| Credentials | Integration credentials stored for the connecting organization only when authorized |
| Logging / monitoring | Application and infrastructure logs for security and operations |
| Personnel | Confidentiality obligations for authorized personnel |
| Secure development | Access controls on production systems; change deployment via controlled cloud pipelines |
Complete this Schedule when Customer is a K–12 school, district, or other educational agency / institution processing Student Data in the Services.
D.1 School official. To the extent Podz receives Student Data in education records under FERPA, Customer designates Podz as a “school official” with a legitimate educational interest, solely to provide the Services. Podz will use Student Data only for that purpose and will not redisclose Student Data except as directed by Customer or as permitted by FERPA and this DPA.
D.2 No sale; no targeted advertising. Podz will not sell Student Data and will not use Student Data to deliver third-party targeted advertising.
D.3 Parent / eligible student rights. Podz will reasonably assist Customer in fulfilling access, correction, and related requests regarding Student Data. Customer remains the primary point of contact for parents and eligible students.
D.4 Subprocessors. Student Data may be processed by Subprocessors in Schedule B only as needed to provide the Services. Optional integrations that export Student Data outside Podz (SMS, Slack, Gmail, AI) remain off unless Customer enables them.
D.5 Breach. Personal Data Breach notification under Section 9 applies to Student Data. Podz will cooperate with Customer’s obligations under FERPA and applicable state student-privacy breach laws.
D.6 Deletion. Upon written request at the end of a term, school year, or agreement, Podz will delete Student Data per Sections 8–10. Customer should export any records it must retain before requesting deletion.
D.7 COPPA. Podz is not directed to children under 13. Customer will not create accounts for children under 13 unless Customer has obtained any required parental consent and the parties have confirmed in writing: [Not applicable / parental consent approach: _____].
D.8 Data ownership. As between the parties, Customer retains all right, title, and interest in Student Data. Podz obtains only a limited license to process Student Data to provide the Services.
D.9 Prohibited data (default). Unless listed in Schedule A, Customer will not upload to the Services: IEPs or 504 plans, medical/health records, Social Security numbers, or special-population indicators not required for the Services.
Customer education contact: [Name, title, email]
Podz education / DPA contact: dpo@podz.ai
Template version 2026-07-24.
Markdown source in repo: docs/legal/dpa-template.md.