Data Processing Agreement
Draft — not yet effective · Last edited 2026-07-13
This is a working draft for review. It is not the final policy, it is not published, and it is not legal advice. The wording will change after review by counsel.
Purpose
This Data Processing Agreement governs how Slate processes student data on behalf of a school, in line with FERPA and applicable privacy law. A signed copy is available to school administrators on request.
Parties and roles
The school is the data controller (or the party with FERPA authority); Slate is the service provider processing data on the school's instructions.
Scope of processing
Slate processes the student information a school provides or a student generates, only to deliver and support the service.
School responsibilities
Provide accurate rosters, obtain any consents the law requires, and manage access within the school.
Slate responsibilities
Process data only on the school's instructions, keep it secure, assist with data-subject requests, and not sell student data or use it for targeted advertising.
Security
Encryption in transit and at rest, access controls, and logging. The Trust center describes our security posture.
Sub-processors
Slate uses vetted sub-processors (for example hosting, email, payment, and AI providers) and maintains a current list, with notice of changes.
Data-subject requests and audits
Slate assists the school in responding to access, correction, and deletion requests, and supports reasonable audits.
Data location, retention, and deletion
Data is stored in the United States. On termination, student data is returned or deleted per the school's instruction.
Term, liability, and governing law
This agreement runs for the license term. Liability and governing law (State of Texas) are set out in the signed copy.
Signature
A counter-signable PDF is provided to administrators; contact schools@slateapp.co.
Questions about this document? Write to legal@slateapp.co.