All policies

Data Processing Agreement

Draft — not yet effective · Last edited 2026-07-13

This is a working draft for review. It is not the final policy, it is not published, and it is not legal advice. The wording will change after review by counsel.

Purpose

This Data Processing Agreement governs how Slate processes student data on behalf of a school, in line with FERPA and applicable privacy law. A signed copy is available to school administrators on request.

Parties and roles

The school is the data controller (or the party with FERPA authority); Slate is the service provider processing data on the school's instructions.

Scope of processing

Slate processes the student information a school provides or a student generates, only to deliver and support the service.

School responsibilities

Provide accurate rosters, obtain any consents the law requires, and manage access within the school.

Slate responsibilities

Process data only on the school's instructions, keep it secure, assist with data-subject requests, and not sell student data or use it for targeted advertising.

Security

Encryption in transit and at rest, access controls, and logging. The Trust center describes our security posture.

Sub-processors

Slate uses vetted sub-processors (for example hosting, email, payment, and AI providers) and maintains a current list, with notice of changes.

Data-subject requests and audits

Slate assists the school in responding to access, correction, and deletion requests, and supports reasonable audits.

Data location, retention, and deletion

Data is stored in the United States. On termination, student data is returned or deleted per the school's instruction.

Term, liability, and governing law

This agreement runs for the license term. Liability and governing law (State of Texas) are set out in the signed copy.

Signature

A counter-signable PDF is provided to administrators; contact schools@slateapp.co.

Questions about this document? Write to legal@slateapp.co.

    Data Processing Agreement · Slate