Version: 2026-08 Last updated: 2026-08-30 Contact: [email protected]
This Data Processing Agreement ("DPA") supplements the Trace Terms of Service between Trace Education ("Trace", the "Processor" and "School Official") and the educational institution accepting it (the "School", the "Controller"). Acceptance is recorded when a school is created, and the accepting administrator receives the accepted version as a PDF by email.
Trace Education is registered as TraceEducation LLC, of 531 Main Street, New York, NY 10044.
1. Roles and scope#
- The School is the controller of student personal data and the holder of education records under FERPA.
- Trace processes student personal data only on the School's documented instructions, as a "school official" with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)) and, for students under 13, under the School's COPPA authorization to act as the parents' agent for school-directed educational use.
- Processing is limited to providing and securing the Trace service. Trace does not sell student data, does not share it for cross-context behavioral advertising, does not use it for advertising of any kind, and does not build advertising profiles.
- Trace does not use student data to train, fine-tune, or improve any AI model, and instructs its model router not to retain or train on it (see §4).
2. Nature and purpose of processing#
Delivery of an AI learning platform: account provisioning, class and assignment management, student projects and AI runs, content moderation and minor safety, credit and billing metadata, transactional email, and support.
3. Categories of data subjects and data#
- Data subjects: instructional staff, school administrators, and enrolled students.
- Data: identifiers (name, username, school email, account ID), date of birth (age gate only), coursework and learning records, project and version content, AI conversation and run content, moderation flags (category only, never message text), usage and billing metadata, and transactional email records.
- Not processed: home address, phone number, government ID, health, IEP or 504 status, free or reduced lunch status, race or ethnicity, discipline records, photographs, biometrics, or precise location. Trace has no SIS or LMS integration and receives no records from the School's own systems.
- Trace removes the signed-in student's direct identifiers and common identifier patterns before sending content to a model provider. Redaction does not recognize third-party names or change the copy Trace stores. See the Privacy Policy §4 for its limits.
4. Sub-processors#
Trace uses the sub-processors published at Subprocessors and, machine-readably, at GET /api/v1/privacy/subprocessors. Trace maintains that list, imposes data-protection terms on each sub-processor, and gives the School notice of material additions or changes with a reasonable opportunity to object.
Model inference is routed through OpenRouter. Every request Trace sends carries zero-retention instructions (data_collection: deny and zdr: true) on every egress path, including agent runs, chat, speech-to-text, text-to-speech, the SDK gateway, and safety review. Only models on Trace's published allowlist or the fixed safety-review model can be reached.
Trace applies one school-appropriate platform policy to every primary chat request. Tutor messages are reviewed by one low-reasoning DeepSeek V4 Flash call before storage or model egress, and final assistant replies receive the same review before they are returned or stored. The reviewer is developed by DeepSeek, a company headquartered in China, and is reached through OpenRouter under a provider policy that forbids retention or training on the text. Each review receives only its privacy-redacted candidate text, without conversation history, tools, embeddings, or internal model turns. Flagged content or content whose safety check is unavailable is withheld. While a tutor reply is being prepared, the model's reasoning summary is displayed to the signed-in student; it is not stored with the conversation and does not stand in for the review that gates the reply itself. Moderation records contain a validated category and scope metadata, not the message, reply, or reviewer explanation.
5. Security#
Trace maintains administrative, technical, and physical safeguards appropriate to the sensitivity of student data, including: TLS in transit with HSTS; hardened response headers; authorization checks against class membership and ownership on every request touching student records; tenant isolation; central session revocation; rate limiting and per-run token, step, and cost caps; fixed model and tool allowlists; a school policy on every primary chat request; dual tutor-input and final-output review; and audit logging retained 365 days. Encryption at rest is provided by the hosting and database vendor identified in §9. The Privacy Policy §11 describes the current state, including what is still being rolled out.
6. Data subject and parent rights#
On the School's or a parent's documented request, Trace will help the School access, correct, export, or delete a student's data, and will respond within 30 days.
Users can:
- Export their profile, projects, conversations and messages, runs, submissions, and credit ledger as JSON through
GET /api/v1/auth/account/export, or request the file from Trace. - Delete their account at
DELETE /api/v1/auth/account. Account deletion removes identifying information but does not erase every record. Identifying fields are overwritten, conversation message content is replaced, run inputs are cleared, project titles are replaced, sessions and API keys are revoked, memberships deactivated, and the WorkOS identity deleted. Run event payloads, project and version graph JSON, submissions and learning records, credit ledger rows, audit rows, and email delivery records are retained in de-identified form. Full erasure of a specific record is available on request and is performed manually.
School administrators must request per-student exports and deletions from Trace; these actions are not available in the school portal. Trace fulfills parent requests on the School's instruction within 30 days.
7. Retention and deletion#
Trace retains student data for the term of the School's agreement. On termination, or on the School's documented request, Trace will delete or return the School's student data within 60 days, and will confirm in writing when it is done. The School may instruct Trace to retain data beyond that period.
Per-category retention is set out in the Privacy Policy §7. Audit metadata contains no student content and expires after 365 days. Rate-limit counters expire after 24 hours. Other categories do not expire automatically and remain subject to the deletion limits in §6.
8. Incident response#
Trace will notify the School without undue delay after becoming aware of a personal-data breach affecting the School's data, and will provide the information reasonably necessary for the School's own notification obligations. Where New York Education Law § 2-d applies, notification will be made within seven calendar days of discovery; Trace applies that seven-day standard to all Schools rather than only to those in New York.
9. International transfers, hosting, and residency#
Hosting. Trace is operated from the United States. [Hosting vendor and region to be confirmed and named in the Subprocessors list.]
Model inference. OpenRouter routes prompts and responses to the provider serving the selected model. Model developers include Alibaba, DeepSeek, and Xiaomi, which are headquartered outside the United States. Depending on the model, content may be processed outside the United States and the EEA. Every request carries the zero-retention instruction in §4. Trace does not use student data for model training and instructs providers not to do so.
A School with inference residency requirements should raise them before signing. Trace can restrict available models for the School's deployment and will record any agreed restriction in the School's agreement.
Transfer mechanism. For personal data transferred out of the EEA or the UK, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914, modules as applicable) together with the UK International Data Transfer Addendum, which are incorporated into this DPA by reference. Trace applies the technical measures in §5 as supplementary measures.
10. Audit#
Trace will make available the information reasonably necessary to demonstrate compliance with this DPA, including the security description in §5, the sub-processor list, and responses to the School's security questionnaires. Trace will allow for reasonable audits on terms to be agreed, no more than once in any twelve-month period absent a security incident, at the School's expense and under confidentiality.
11. Changes to this DPA#
The current version is identified at the top of this document and recorded against the School's acceptance. Trace will notify the School before a new version takes effect for it, and will not apply a materially less protective version to data already collected without the School's agreement.
Prepared for review by qualified counsel before it is relied on in a specific jurisdiction.