Data Privacy Agreement

FERPA Data Privacy Agreement (“DPA”)

Last updated: July 20, 2026

This is a reference copy. The executed DPA is signed by educational institutions during onboarding.

This Data Privacy Agreement (“Agreement” or “DPA”) is entered into by and between the educational institution accepting this Agreement (“Institution”) and TrustRoom Connect, Inc. (“Provider” or “TrustRoom”).

This Agreement governs the collection, use, storage, and protection of Student Data by Provider in connection with the Services described herein, and supplements the Business Associate Agreement (BAA-001) executed between the parties. This Agreement is designed to ensure compliance with the Family Educational Rights and Privacy Act (“FERPA”), 20 U.S.C. § 1232g, and its implementing regulations at 34 CFR Part 99, as well as applicable state student privacy laws.

1. Definitions

Unless otherwise defined herein, capitalized terms shall have the meanings set forth below or as defined in FERPA and its implementing regulations at 34 CFR Part 99.

  • Education Records. Records that are directly related to a student and maintained by an educational agency or institution or by a party acting for the agency or institution, as defined in 34 CFR § 99.3.
  • Student Data. Any data, whether personally identifiable or otherwise, that is collected, generated, or maintained by Provider in the course of performing the Services on behalf of Institution, including but not limited to Education Records, metadata, and user-generated content.
  • Personally Identifiable Information (PII). Information that, alone or in combination, is linked or linkable to a specific student and would allow a reasonable person in the school community to identify the student with reasonable certainty, as described in 34 CFR § 99.3.
  • School Official. A party to whom the Institution has determined meets the criteria under 34 CFR § 99.31(a)(1)(i)(B) for access to Education Records without prior written consent.
  • Legitimate Educational Interest. The interest that an authorized representative has in accessing Education Records in order to fulfill his or her professional responsibility for the Institution.
  • Services. The platform services provided by TrustRoom to Institution including clinical documentation, secure messaging, care plan management, clinical analytics, AI-assisted clinical insights, and related technology services.
  • De-Identified Data. Data from which all personally identifiable information has been removed such that the remaining information does not reasonably identify a specific student, in accordance with FERPA (34 CFR § 99.31(b)) and the HIPAA Safe Harbor method (45 C.F.R. § 164.514(b)(2)).

2. School Official Designation

Institution designates Provider as a School Official with a Legitimate Educational Interestin accessing Education Records, pursuant to 34 CFR § 99.31(a)(1)(i)(B), subject to compliance with all of the following criteria:

  • Institutional Service. Provider performs an institutional service or function for which the Institution would otherwise use its own employees.
  • Direct Control. Provider is under the direct control of the Institution with respect to the use and maintenance of Education Records.
  • Legitimate Educational Interest. Provider accesses Education Records solely in furtherance of the Legitimate Educational Interest for which it has been designated.
  • Use and Redisclosure Restrictions. Provider shall use Education Records only for the purposes for which the disclosure was made and shall not redisclose PII from Education Records to any third party without prior written consent, unless an exception under 34 CFR § 99.31 applies, subject to the redisclosure restrictions of 34 CFR § 99.33(a).

Institution represents that its annual notification under 34 CFR § 99.7 includes criteria that permit the designation of Provider as a School Official.

3. Scope of Services and Data

Provider operates a HIPAA-compliant behavioral health SaaS platform. The Services include:

  • Clinical documentation (progress notes, intake assessments, treatment plans)
  • Secure messaging between clinicians and students
  • Care planning and outcome tracking
  • Clinical analytics and reporting
  • AI-assisted clinical insights (note generation, message analysis, care plan suggestions)
  • Session scheduling and attendance tracking

Provider shall collect and process only the minimum Student Data necessary to perform the Services. Provider shall not collect additional categories of Student Data without prior written approval from Institution.

4. Data Ownership and Control

  • Ownership. Institution retains complete ownership of all Student Data. Provider acquires no rights, title, or interest in Student Data except the limited right to process it in accordance with this Agreement.
  • Control. Institution maintains exclusive control over decisions regarding the collection, use, and disclosure of Student Data.
  • No Independent Rights. Provider has no independent rights in Student Data. Upon termination, Provider’s limited right to process Student Data shall immediately cease.

5. Permitted Uses and Restrictions

5.1 Authorized Uses

  • Providing the Services described in Section 3 and the Service Agreement
  • Maintaining and improving the security and integrity of the platform
  • Complying with applicable law, including FERPA and HIPAA
  • Generating De-Identified Data for aggregate reporting, in accordance with 34 CFR § 99.31(b)

5.2 Prohibited Uses

Provider shall NOT use Student Data for any of the following purposes:

  • Advertising. Provider shall not use Student Data to inform, influence, or enable advertising, marketing, or any commercial purpose unrelated to the Services.
  • Profiling. Provider shall not use Student Data to create profiles of students for purposes unrelated to the Services.
  • Sale or Rental. Provider shall not sell, rent, lease, trade, or otherwise transfer or monetize Student Data to any third party.
  • Shadow Profiles. Provider shall not use Student Data to create or maintain profiles of students who are not active users of the Services.

5.3 AI Model Training Prohibition

Provider shall not use Student Data for purposes of AI model training, machine learning model development, or similar activities. Provider’s AI-powered clinical features use inference-only models that do not retain or learn from Student Data.

6. Data Security

Provider shall implement and maintain administrative, physical, and technical safeguards designed to protect Student Data from unauthorized access, acquisition, destruction, use, modification, or disclosure. These safeguards shall be no less rigorous than those required under HIPAA (45 C.F.R. Part 164, Subpart C).

Data StateStandardImplementation
At RestAES-256GCP-managed encryption
In TransitTLS 1.3HTTPS enforced; minimum TLS 1.2
BackupsAES-256GCP-managed encryption keys
SecretsAES-256Google Secret Manager

7. Subprocessors

  • Provider shall notify Institution at least thirty (30) calendar days in advance before engaging a new subprocessor that will process Student Data.
  • Institution may object in writing to Provider’s engagement of a new subprocessor within the thirty-day notice period.
  • Provider shall impose data protection obligations on each subprocessor that are materially equivalent to those imposed on Provider under this Agreement.

8. Data Breach Notification

  • Initial Notification. Provider shall notify Institution of any confirmed or reasonably suspected Breach involving Student Data within twenty-four (24) hours of discovery, by both email and telephone.
  • Formal Written Notification. Provider shall deliver formal written notification within seventy-two (72) hours of discovery, including the nature and scope, data elements involved, number of students affected, steps taken to investigate and remediate, and designated point of contact.
  • Parallel HIPAA Notification. Where Student Data also constitutes PHI, Provider shall comply with both this Section and the HIPAA Breach notification requirements. The more protective (shorter) timeline shall apply.
  • Cooperation. Provider shall cooperate fully with Institution in investigating and remediating the Breach.

State-Specific Requirements

StateStatuteKey Requirement
New YorkEd. Law § 2-dNotification to Chief Privacy Officer; Parents’ Bill of Rights
CaliforniaSOPIPAProhibition on targeted advertising; reasonable security
IllinoisSOPPAMandatory DPA; public transparency
ColoradoHB 16-142330-day breach notification
ConnecticutPA 16-18924-hour superintendent notification

9. Data Retention, Return, and Destruction

9.1 Retention During Contract

Clinical records (which may also constitute PHI) are retained for a minimum of fifteen (15) years in compliance with HIPAA record retention requirements and applicable state law.

9.2 Data Return Upon Termination

Within thirty (30) calendar days of termination, Provider shall make available a complete export of all Student Data in a machine-readable, industry-standard format (JSON, CSV, PDF) at no additional charge to Institution.

9.3 Data Destruction

  • Within ninety (90) calendar days following Institution’s confirmed receipt of the exported data, Provider shall securely delete all Student Data from production systems, backup systems, and disaster recovery systems.
  • Deletion shall be performed using methods consistent with NIST Special Publication 800-88 (Guidelines for Media Sanitization).
  • Provider shall deliver a Certificate of Data Destruction to Institution certifying the completion of data destruction.

9.4 Retention Exceptions

  • De-Identified Data from which all PII has been removed
  • Audit log entries, retained for six (6) years per 45 C.F.R. § 164.530(j)
  • Data that Provider is required by law to retain

10. Student and Parent Rights

  • Right of Access. Provider shall make Student Data available to Institution so it can fulfill obligations under 34 CFR § 99.10 (right to inspect and review Education Records).
  • Right to Request Amendment. Provider shall amend, correct, or delete Student Data as directed by Institution under 34 CFR § 99.20.
  • Disclosure Records. Provider shall maintain records of disclosures as required under 34 CFR § 99.32.

11. COPPA Compliance

TrustRoom’s Services are designed for university counseling centers and clinical training programs and are not generally directed to children under 13 years of age. In the event that students under 13 are enrolled (e.g., through early-enrollment or dual-enrollment programs), Institution is solely responsible for obtaining verifiable parental consent as required by the Children’s Online Privacy Protection Act (“COPPA”), 15 U.S.C. §§ 6501–6506.

12. Audit Rights

  • Institution may audit Provider’s compliance with this Agreement upon thirty (30) calendar days’ prior written notice.
  • Provider shall provide access to relevant documentation, audit logs, access records, and evidence of subprocessor compliance.
  • If an audit reveals a material deficiency, Provider shall remediate at its own expense within a reasonable timeframe.

13. Relationship to Business Associate Agreement

  • This DPA supplements and does not replace the Business Associate Agreement (BAA) between the parties.
  • Certain Student Data may simultaneously constitute both Education Records under FERPA and Protected Health Information under HIPAA. In such cases, both this Agreement and the BAA shall apply.
  • Where the requirements of FERPA and HIPAA conflict, the more protective standard shall apply.
  • The parties acknowledge the treatment records exception under 34 CFR § 99.3, which excludes from “Education Records” certain treatment records. Such records remain governed by HIPAA and the BAA only.

14. Term and Termination

  • Term. This Agreement shall be co-terminus with the Service Agreement between the parties.
  • Termination for Material Breach. Either party may terminate if the other materially breaches and fails to cure within thirty (30) calendar days after written notice.
  • Termination for Cause. Institution may terminate immediately if Provider experiences a data breach and fails to comply with notification requirements, uses Student Data in a prohibited manner, or becomes subject to regulatory action impairing its ability to protect Student Data.
  • Survival. Data Ownership, Permitted Uses, Data Security, Breach Notification, Data Retention and Destruction, and Audit Rights survive termination.

15. General Provisions

  • Governing Law. This Agreement shall be governed by federal law, including FERPA and HIPAA, and to the extent not preempted, the laws of the applicable state.
  • Amendment. This Agreement may be amended only by a written instrument signed by both parties.
  • Severability. If any provision is held invalid, the remaining provisions shall remain in full force and effect.
  • Entire Agreement. This Agreement, together with the Service Agreement, the BAA, and all Exhibits, constitutes the entire agreement between the parties with respect to student data privacy and security.

Contact Information

For questions about this Agreement:

TrustRoom Connect, Inc.

Email: privacy@trustroomconnect.com

Mailing Address: 21241 Ventura Blvd. Ste #177, Woodland Hills, CA 91364