Skip to main content
Legal

Data Processing Agreement

Version 1.0.0 | Last updated: 24 February 2026

Note: This page summarises the key provisions of the TEX Data Processing Agreement. To execute a DPA for your school or organisation, contact privacy@texedu.app. The executed agreement will incorporate these provisions and any school-specific schedules.

1. Parties & Scope

This Data Processing Agreement ("DPA") is entered into between TEX Inc Pty Ltd ("TEX," "Processor") and the subscribing school or educational organisation ("School," "Controller") and supplements the Terms of Service and subscription agreement between the parties.

This DPA governs the processing of personal data that TEX performs on behalf of the School in connection with the provision of the TEX Edu. It applies to all personal data processed by TEX on behalf of the School, including student education records, staff data, and any other personal information submitted to the Platform.


2. Definitions

In addition to terms defined in the Terms of Service, the following definitions apply:

  • "Personal Data" means any information relating to an identified or identifiable natural person, including education records as defined under FERPA and personal information as defined under the Australian Privacy Act 1988.
  • "Education Records"means records directly related to a student and maintained by the School or by TEX acting for the School, as defined in FERPA (20 U.S.C. § 1232g).
  • "Processing" means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, and deletion.
  • "Data Breach" means any unauthorised access, acquisition, use, or disclosure of Personal Data that compromises the security, confidentiality, or integrity of such data.
  • "Sub-Processor" means any third party engaged by TEX to process Personal Data on behalf of the School.

3. Roles & Responsibilities

The School is the data controller (or, under FERPA, the educational agency or institution) and determines the purposes and means of processing Personal Data. The School is responsible for ensuring that all necessary consents, notices, and authorisations are in place for the lawful processing of Personal Data.

TEX is the data processor and processes Personal Data only on behalf of and under the documented instructions of the School. TEX shall not process Personal Data for any purpose other than to provide the services described in the subscription agreement.

TEX shall:

  • Process Personal Data only in accordance with the School's documented instructions.
  • Ensure that personnel authorised to process Personal Data are bound by obligations of confidentiality.
  • Implement and maintain appropriate technical and organisational security measures.
  • Assist the School in responding to data subject requests and regulatory inquiries.
  • Not sell, rent, trade, or otherwise make available Personal Data to any third party, except as necessary to provide the services or as required by law.
  • Not use Personal Data for marketing, advertising, or AI model training purposes.

4. FERPA — School Official Designation

This section applies to Schools subject to the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g.

The School designates TEX as a "school official" with a "legitimate educational interest" under FERPA §99.31(a)(1)(i)(B). This designation is based on the following criteria:

  • Institutional function: TEX performs services that the School would otherwise use its own employees to perform, including student career readiness management, opportunity tracking, skills assessment administration, and counselor workflow support.
  • Direct control:The School retains direct control over TEX's use and maintenance of Education Records through this DPA, the subscription agreement, and the School's administrative controls within the Platform.
  • Purpose limitation: TEX uses Education Records solely for the authorised purposes specified in this DPA and the subscription agreement.
  • Re-disclosure restrictions:TEX is subject to FERPA §99.33(a) re-disclosure restrictions and shall not re-disclose personally identifiable information from Education Records to any third party except as authorised by the School or permitted under FERPA.

Annual Notification Support

TEX will provide the School with the information necessary for the School to include TEX in its annual FERPA notification to parents regarding the School's criteria for determining who constitutes a school official and what constitutes a legitimate educational interest.

Directory Information

The Platform supports the School in managing directory information designations and opt-out preferences. TEX will not treat any student information as directory information unless the School has designated it as such within the Platform's privacy settings.

Parental Rights

TEX will provide reasonable assistance to the School in fulfilling its obligations to parents and eligible students under FERPA, including the right to inspect and review Education Records, the right to request amendment, and the right to consent to disclosures. The School is responsible for receiving and processing such requests directly.


5. GDPR Obligations

Where the General Data Protection Regulation (EU) 2016/679 or UK GDPR applies, the following provisions supplement the general obligations of this DPA:

  • Lawful basis: TEX processes Personal Data on behalf of the School under the lawful basis of contractual necessity (Article 6(1)(b)) and legitimate interest (Article 6(1)(f)).
  • Data Protection Impact Assessment: TEX will assist the School in conducting DPIAs where required and maintain its own DPIA for the Platform.
  • Cross-border transfers: Where Personal Data is transferred outside the EEA/UK, TEX relies on Standard Contractual Clauses (SCCs) or equivalent safeguards as approved by the relevant supervisory authority.
  • Data subject rights: TEX will assist the School in responding to data subject access requests (DSARs) within the timeframes required by GDPR.

6. Australian Privacy Act

TEX complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the School is an Australian entity:

  • TEX processes Personal Data in accordance with APPs 1–13.
  • Overseas disclosure of Personal Data (APP 8) is limited to the sub-processors listed in Section 8 and is subject to contractual safeguards requiring equivalent data protection.
  • TEX will notify the School and the Office of the Australian Information Commissioner (OAIC) of eligible data breaches in accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act.

7. Data Security

TEX implements and maintains technical and organisational measures appropriate to the nature, scope, and purposes of processing, including:

  • Encryption: AES-256 encryption at rest; TLS 1.3 for all data in transit.
  • Access controls: Role-based access control (RBAC) with 14 distinct roles; principle of least privilege enforced for all personnel.
  • Multi-tenant isolation: Row-level security (RLS) policies ensure complete data isolation between school tenants.
  • Authentication: Secure authentication via Supabase Auth with support for SSO (Google, Microsoft Azure AD) and multi-factor authentication.
  • Audit logging: Comprehensive audit trails for data access and modifications.
  • Infrastructure: Hosted on Vercel and Supabase (AWS-backed), both SOC 2 Type II compliant. Data stored in the Sydney, Australia region by default.
  • Vulnerability management: Regular dependency updates, automated security scanning, and third-party penetration testing.

8. Sub-Processors

TEX uses the following sub-processors to provide the Platform services. Each sub-processor is contractually bound to data protection obligations equivalent to those in this DPA:

Sub-ProcessorPurposeData Location
Supabase (AWS)Database hosting & authenticationSydney, AU
VercelApplication hosting & file storageSydney, AU (edge)
OpenAIAI features (no model training on school data)United States
ResendTransactional email deliveryUnited States
SentryError monitoring (anonymised)United States
PostHogProduct analytics (anonymised)EU

TEX will provide the School with at least 30 days' prior written notice before engaging any new sub-processor or making material changes to existing sub-processors. The School may object to a new sub-processor on reasonable data protection grounds within 14 days of notification. If the objection cannot be resolved, the School may terminate the affected services without penalty.


9. Data Subject Rights

TEX will assist the School in responding to requests from data subjects (including parents and eligible students under FERPA) exercising their rights, including:

  • Right of access / right to inspect and review (FERPA, GDPR Article 15, APP 12)
  • Right to rectification / amendment (FERPA, GDPR Article 16, APP 13)
  • Right to erasure / deletion (GDPR Article 17)
  • Right to data portability (GDPR Article 20)
  • Right to restriction of processing (GDPR Article 18)
  • Right to object to processing (GDPR Article 21)
  • Right to consent to disclosures (FERPA §99.30)

The School is responsible for receiving and evaluating data subject requests. TEX will respond to requests for assistance within 5 business days and provide the necessary data or system access to enable the School to fulfil its obligations.


10. Data Return & Deletion

Upon termination or expiry of the subscription agreement, TEX will, at the School's written direction:

  • Return: Export all School Data, including Education Records, in a standard machine-readable format (CSV/JSON) within 30 days of the termination date.
  • Delete: Securely delete all School Data from TEX systems and sub-processor systems within 30 days of the termination date, except where retention is required by applicable law.
  • Certification: Upon request, provide written certification that all School Data has been deleted or returned in accordance with this section.

During the 30-day post-termination window, the School may access the Platform in read-only mode to verify data export completeness.


11. Breach Notification

In the event of a confirmed Data Breach, TEX will:

  • Notify the School without unreasonable delay and no later than 24 hours after becoming aware of the breach.
  • Provide sufficient information for the School to assess its notification obligations under FERPA, GDPR (Article 33/34), and/or the Australian NDB scheme.
  • Include in the notification: (a) nature and scope of the breach, (b) categories and approximate number of affected records, (c) likely consequences, (d) measures taken or proposed to address the breach.
  • Cooperate fully with the School's investigation and remediation efforts.
  • Provide follow-up reports as additional information becomes available.

12. Audit Rights

The School has the right to audit TEX's compliance with this DPA, subject to the following:

  • Audits may be conducted no more than once per calendar year, with at least 30 days' advance written notice.
  • TEX will make available all information reasonably necessary to demonstrate compliance, including security documentation, processing records, and sub-processor agreements.
  • Where a third-party audit or certification (e.g., SOC 2 Type II) is available, TEX may provide the audit report in lieu of an on-site audit, provided the report addresses the School's concerns.
  • The School may engage a qualified third-party auditor, subject to reasonable confidentiality obligations.

13. Term & Termination

This DPA takes effect on the date the School begins using the Platform and continues for the duration of the subscription agreement. Obligations relating to data security, confidentiality, data return, and deletion survive termination.

Either party may terminate this DPA if the other party materially breaches its obligations and fails to cure the breach within 30 days of written notice. The School may terminate immediately if TEX fails to comply with a mandatory data protection obligation that cannot be cured.


14. Contact

To request a copy of this DPA for execution, or for questions about data processing practices:

Privacy Officer: privacy@texedu.app
Legal enquiries: legal@texedu.app
Mailing address: TEX Inc Pty Ltd, [Address to be provided]