Legal & data protection
The standard terms that govern how school data is handled on the coreDIRECTED platform. Each is executed with a school as part of its written agreement; they are published here so any school, parent, or assessor can read exactly what we commit to.
Data Processing Agreement (GDPR)
techDIRECTED as processor, the school as controller: instructions, security, subprocessing, international transfers, data subject assistance, breach notification, audits, and return and deletion, drafted against GDPR Article 28(3). Includes the description of processing and the technical and organisational measures.
Student Data Privacy Agreement
The student-data instrument: FERPA school-official designation where FERPA applies, and the same protections by contract everywhere else. No sale, no advertising, no profiling beyond the school's purposes, and no use of student data to train AI models. Covers parent rights, children under 13, security, subprocessors, incidents, and layered return and deletion.
Related
techDIRECTED privacy policy covers the company's own website and internal tools. Platform customer data is governed by the agreements above.