Version: September 1, 2026
Execution required: This public document is our standard institutional addendum. It becomes binding only when it is incorporated into an order form or another written agreement accepted by both the customer and 825 Consulting LLC. Email outreach@counselorai.app to execute it.
This Data Processing Addendum ("DPA") is between the educational institution or other customer identified in the applicable order form ("Customer") and 825 Consulting LLC, doing business as CounselorAI ("Processor"). It supplements the applicable services agreement and governs Processor's handling of Covered Data on Customer's behalf.
Customer is the controller, business, educational agency or institution, or equivalent entity that determines the purpose of processing. Processor acts only as Customer's processor, service provider, or contractor for Covered Data, except for account, security, billing, and legal-compliance data that Processor must handle for its own legitimate business obligations.
| Subject matter | AI-assisted drafting, review, translation, analysis, quality control, authentication, metering, and support requested by Customer |
|---|---|
| Duration | The term of the services agreement plus the limited deletion, legal, security, billing, and backup periods described below |
| Nature and purpose | Receive, validate, transmit to approved service providers, generate output, return output, meter usage, secure access, and support Customer's authorized educational workflow |
| Data subjects | Students, applicants, family members, counselors, educators, staff, and authorized users |
| Covered Data | Contact and account data; student circumstances; education, application, scholarship, and financial-aid information; drafts and source facts; and other data Customer chooses to submit |
| Excluded data | Social Security numbers, account passwords, full payment-card data, protected health information, and any data not necessary for the authorized task |
Processor will process Covered Data only on Customer's documented instructions, including the services agreement, this DPA, configured account settings, and authorized API calls, unless law requires otherwise. Processor will notify Customer if it believes an instruction violates applicable law, unless prohibited from doing so.
Customer will:
Where Customer relies on FERPA's school-official exception, Processor will perform an institutional service or function for which Customer would otherwise use employees, will remain under Customer's direct control regarding the use and maintenance of education-record information, and will use that information only for the purpose for which Customer disclosed it.
Processor will not redisclose personally identifiable information from education records except to approved Subprocessors that need it to provide the Services and are bound to compatible restrictions, as Customer directs, or as law permits. Processor will not use education-record information for advertising, model training, building student profiles unrelated to the requested service, or another independent commercial purpose.
Customer determines legitimate educational interest, access eligibility, required notices, and the FERPA exception or consent supporting disclosure.
Processor will limit access to Covered Data to personnel and contractors who need access to provide or secure the Services and who are bound by confidentiality obligations. Processor will not disclose Covered Data to a third party except as this DPA permits or law requires.
Processor will maintain reasonable administrative, technical, and organizational safeguards appropriate to the processing risk. Current controls include:
Processor may update safeguards as technology and risk change, provided that protection is not materially reduced during the agreement term.
Customer gives general authorization for the Subprocessors below. Processor will bind each Subprocessor to data-protection obligations appropriate to its role and remains responsible for its own obligations under this DPA.
| Subprocessor | Service | Processing location or basis |
|---|---|---|
| Netlify, Inc. | Hosting, serverless request processing, routing, and operational infrastructure | United States and provider locations under Netlify's DPA |
| Anthropic, PBC | Commercial AI API and optional model web-search tooling | United States and provider locations under Anthropic's commercial terms and DPA |
| Supabase, Inc. | Account, key-hash, usage, billing, and optional response storage database | Customer-selected primary region and provider locations under Supabase's DPA |
| Stripe, LLC | Checkout, payments, refunds, disputes, and metering where enabled | Global payment network under Stripe's DPA and controller terms |
| Plus Five Five, Inc. (Resend) | Transactional email and counts-only operational notices | United States and provider locations under Resend's DPA |
Processor will post material Subprocessor changes on this page. Customers may subscribe by written request for direct notice. Customer may object on reasonable data-protection grounds within 30 days of notice. The parties will work in good faith on a reasonable alternative. If none is available, Customer may stop using the affected function.
Student profiles explicitly saved in the web workspace remain only in that browser for up to 24 hours and can be deleted sooner. Expired entries are removed while the workspace is open or the next time it loads. Generated history, counselor voice samples, signature images, and uploaded files remain only for the open browser-tab session.
The default API account setting does not retain request or response bodies in CounselorAI's database. When a written agreement expressly enables stored-response replay, generated responses are purged after 24 hours. Test-task fixtures and terminal status are retained for no more than 24 hours and contain no caller input or live model output.
Anthropic's standard commercial API retention is deletion of inputs and outputs within 30 days, subject to its published exceptions or a separately agreed setting. Other Subprocessors retain data according to their agreements and legal obligations.
At termination or Customer's written request, Processor will delete or return Covered Data in its control within 30 days, unless the Services already enforce a shorter period or law requires retention. Content-free account, usage, security, payment, refund, dispute, tax, and audit records may be retained as reasonably necessary for those purposes. Processor will not reconstruct deleted request content from those operational records.
Taking into account the nature of processing, Processor will reasonably assist Customer with requests to access, correct, delete, restrict, or export Covered Data. If Processor receives a request relating to Customer-controlled data, it will direct the requester to Customer unless law permits or requires a direct response.
Processor will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer's Covered Data and, where feasible, within 48 hours. Notice will include available information about the nature of the incident, affected data, likely consequences, containment, and a contact for follow-up. Processor will investigate, mitigate, preserve relevant evidence, and provide reasonable updates. This duty does not apply to unsuccessful attempts that do not compromise Covered Data.
Processor will provide information reasonably necessary to demonstrate compliance with this DPA and assist with legally required risk assessments or consultations, considering the nature of processing and information available. No more than once annually, Customer may request a reasonable security questionnaire or available independent reports. Additional audits require reasonable notice, confidentiality protections, minimal disruption, and Customer payment of reasonable costs, unless a confirmed breach or regulator requires otherwise.
Processor will notify Customer of a binding request for Covered Data unless law prohibits notice. Where legally permitted, Processor will direct the requester to Customer and challenge requests that are facially invalid or overbroad.
If applicable law requires a transfer mechanism, the parties will execute the then-current Standard Contractual Clauses, UK Addendum, or another lawful mechanism. This public DPA does not by itself select a GDPR transfer module or complete a transfer impact assessment.
If this DPA conflicts with the services agreement on privacy or security, this DPA controls. The services agreement's liability limits apply to this DPA unless prohibited by law or changed in an executed order form. This DPA remains effective while Processor handles Covered Data for Customer.
To request execution, a security review, Subprocessor notice, or privacy assistance, email outreach@counselorai.app.