Data Processing Addendum

Version: September 1, 2026

Execution required: This public document is our standard institutional addendum. It becomes binding only when it is incorporated into an order form or another written agreement accepted by both the customer and 825 Consulting LLC. Email outreach@counselorai.app to execute it.

1. Parties and scope

This Data Processing Addendum ("DPA") is between the educational institution or other customer identified in the applicable order form ("Customer") and 825 Consulting LLC, doing business as CounselorAI ("Processor"). It supplements the applicable services agreement and governs Processor's handling of Covered Data on Customer's behalf.

Customer is the controller, business, educational agency or institution, or equivalent entity that determines the purpose of processing. Processor acts only as Customer's processor, service provider, or contractor for Covered Data, except for account, security, billing, and legal-compliance data that Processor must handle for its own legitimate business obligations.

2. Definitions

3. Processing details

Subject matterAI-assisted drafting, review, translation, analysis, quality control, authentication, metering, and support requested by Customer
DurationThe term of the services agreement plus the limited deletion, legal, security, billing, and backup periods described below
Nature and purposeReceive, validate, transmit to approved service providers, generate output, return output, meter usage, secure access, and support Customer's authorized educational workflow
Data subjectsStudents, applicants, family members, counselors, educators, staff, and authorized users
Covered DataContact and account data; student circumstances; education, application, scholarship, and financial-aid information; drafts and source facts; and other data Customer chooses to submit
Excluded dataSocial Security numbers, account passwords, full payment-card data, protected health information, and any data not necessary for the authorized task

4. Customer instructions and responsibilities

Processor will process Covered Data only on Customer's documented instructions, including the services agreement, this DPA, configured account settings, and authorized API calls, unless law requires otherwise. Processor will notify Customer if it believes an instruction violates applicable law, unless prohibited from doing so.

Customer will:

5. FERPA terms

Where Customer relies on FERPA's school-official exception, Processor will perform an institutional service or function for which Customer would otherwise use employees, will remain under Customer's direct control regarding the use and maintenance of education-record information, and will use that information only for the purpose for which Customer disclosed it.

Processor will not redisclose personally identifiable information from education records except to approved Subprocessors that need it to provide the Services and are bound to compatible restrictions, as Customer directs, or as law permits. Processor will not use education-record information for advertising, model training, building student profiles unrelated to the requested service, or another independent commercial purpose.

Customer determines legitimate educational interest, access eligibility, required notices, and the FERPA exception or consent supporting disclosure.

6. Confidentiality and access

Processor will limit access to Covered Data to personnel and contractors who need access to provide or secure the Services and who are bound by confidentiality obligations. Processor will not disclose Covered Data to a third party except as this DPA permits or law requires.

7. Security measures

Processor will maintain reasonable administrative, technical, and organizational safeguards appropriate to the processing risk. Current controls include:

Processor may update safeguards as technology and risk change, provided that protection is not materially reduced during the agreement term.

8. Subprocessors

Customer gives general authorization for the Subprocessors below. Processor will bind each Subprocessor to data-protection obligations appropriate to its role and remains responsible for its own obligations under this DPA.

SubprocessorServiceProcessing location or basis
Netlify, Inc.Hosting, serverless request processing, routing, and operational infrastructureUnited States and provider locations under Netlify's DPA
Anthropic, PBCCommercial AI API and optional model web-search toolingUnited States and provider locations under Anthropic's commercial terms and DPA
Supabase, Inc.Account, key-hash, usage, billing, and optional response storage databaseCustomer-selected primary region and provider locations under Supabase's DPA
Stripe, LLCCheckout, payments, refunds, disputes, and metering where enabledGlobal payment network under Stripe's DPA and controller terms
Plus Five Five, Inc. (Resend)Transactional email and counts-only operational noticesUnited States and provider locations under Resend's DPA

Processor will post material Subprocessor changes on this page. Customers may subscribe by written request for direct notice. Customer may object on reasonable data-protection grounds within 30 days of notice. The parties will work in good faith on a reasonable alternative. If none is available, Customer may stop using the affected function.

9. Retention, return, and deletion

Student profiles explicitly saved in the web workspace remain only in that browser for up to 24 hours and can be deleted sooner. Expired entries are removed while the workspace is open or the next time it loads. Generated history, counselor voice samples, signature images, and uploaded files remain only for the open browser-tab session.

The default API account setting does not retain request or response bodies in CounselorAI's database. When a written agreement expressly enables stored-response replay, generated responses are purged after 24 hours. Test-task fixtures and terminal status are retained for no more than 24 hours and contain no caller input or live model output.

Anthropic's standard commercial API retention is deletion of inputs and outputs within 30 days, subject to its published exceptions or a separately agreed setting. Other Subprocessors retain data according to their agreements and legal obligations.

At termination or Customer's written request, Processor will delete or return Covered Data in its control within 30 days, unless the Services already enforce a shorter period or law requires retention. Content-free account, usage, security, payment, refund, dispute, tax, and audit records may be retained as reasonably necessary for those purposes. Processor will not reconstruct deleted request content from those operational records.

10. Data-subject and records requests

Taking into account the nature of processing, Processor will reasonably assist Customer with requests to access, correct, delete, restrict, or export Covered Data. If Processor receives a request relating to Customer-controlled data, it will direct the requester to Customer unless law permits or requires a direct response.

11. Security incidents

Processor will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer's Covered Data and, where feasible, within 48 hours. Notice will include available information about the nature of the incident, affected data, likely consequences, containment, and a contact for follow-up. Processor will investigate, mitigate, preserve relevant evidence, and provide reasonable updates. This duty does not apply to unsuccessful attempts that do not compromise Covered Data.

12. Compliance assistance and audits

Processor will provide information reasonably necessary to demonstrate compliance with this DPA and assist with legally required risk assessments or consultations, considering the nature of processing and information available. No more than once annually, Customer may request a reasonable security questionnaire or available independent reports. Additional audits require reasonable notice, confidentiality protections, minimal disruption, and Customer payment of reasonable costs, unless a confirmed breach or regulator requires otherwise.

13. Government and legal requests

Processor will notify Customer of a binding request for Covered Data unless law prohibits notice. Where legally permitted, Processor will direct the requester to Customer and challenge requests that are facially invalid or overbroad.

14. International transfers

If applicable law requires a transfer mechanism, the parties will execute the then-current Standard Contractual Clauses, UK Addendum, or another lawful mechanism. This public DPA does not by itself select a GDPR transfer module or complete a transfer impact assessment.

15. Conflict, term, and liability

If this DPA conflicts with the services agreement on privacy or security, this DPA controls. The services agreement's liability limits apply to this DPA unless prohibited by law or changed in an executed order form. This DPA remains effective while Processor handles Covered Data for Customer.

16. Contact and execution

To request execution, a security review, Subprocessor notice, or privacy assistance, email outreach@counselorai.app.