← Back to home
📄

Data Processing Agreement

This agreement governs how ShortHand processes student data on behalf of schools and districts, in compliance with FERPA, COPPA, and applicable state privacy laws.

Last updated: March 2026

Need a signed DPA?

Email us at hello@getshorthand.app with your district name and we'll return a countersigned copy within 2 business days. The full agreement terms are below.

1️⃣
Definitions
"School" or "District" means the educational institution entering into this agreement.

"ShortHand" means GetShortHand LLC, the operator of the ShortHand application.

"Student Data" means any personally identifiable information (PII) related to students that is entered into ShortHand by school personnel, including but not limited to: student names, behavioral notes, mood check-ins, parent contact information, and class assignments.

"Authorized Users" means teachers and school staff who have been granted access to ShortHand by the School.
2️⃣
Scope and Purpose
ShortHand processes Student Data solely to provide the services described in the ShortHand application: classroom note-taking, behavior tracking, AI-assisted report generation, and related teacher productivity features.

ShortHand acts as a "School Official" under FERPA with a legitimate educational interest, processing Student Data only on behalf of and under the instructions of the School.
3️⃣
ShortHand's Obligations
ShortHand agrees to:

Not sell Student Data to any third party for any purpose.

Not use Student Data for advertising or to build profiles on students outside the School's educational context.

Not share Student Data with third parties except subprocessors necessary to operate the service (listed in Section 6).

Implement appropriate security measures including encryption at rest (AES-256), encryption in transit (TLS), and row-level access controls.

Notify the School within 72 hours of becoming aware of a data breach affecting Student Data.

Delete or return Student Data upon request or termination of the agreement within 30 days.

Allow audit rights — provide documentation upon reasonable request to demonstrate compliance with this agreement.
4️⃣
School's Obligations
The School agrees to:

• Ensure that Authorized Users have appropriate authorization to enter Student Data into ShortHand.

• Obtain any consents required by applicable law before entering Student Data into the system.

• Notify ShortHand promptly if it becomes aware of any unauthorized access to Student Data.
5️⃣
Data Retention and Deletion
Student Data is retained only as long as the Authorized User's account is active.

Teachers can delete all Student Data at any time from within the app (Settings → Danger Zone → Factory Wipe).

Teachers can permanently delete their account and all associated data (Settings → Danger Zone → Delete My Account).

Upon written request from the School, ShortHand will delete all Student Data associated with the School's Authorized Users within 30 days.
6️⃣
Subprocessors
ShortHand uses the following subprocessors to deliver the service. Each has been evaluated for FERPA compliance:

Supabase — database and authentication. Data stored in AWS us-east-1. SOC 2 Type II certified.

Groq — AI language model processing for report generation. Groq does not use customer data to train models and offers a DPA. Data is not retained after the API response.

Vercel — application hosting. SOC 2 Type II certified.

Google — optional Google Classroom integration only. Used solely to import class rosters when the teacher explicitly connects their account.
7️⃣
FERPA Compliance
ShortHand acknowledges that Student Data shared by a School may be subject to FERPA (20 U.S.C. § 1232g).

ShortHand agrees to use Student Data only for the purposes for which it was disclosed — providing classroom management services to Authorized Users — and for no other purpose.

ShortHand will not re-disclose Student Data to any party other than the School or its Authorized Users without prior written consent from the School.
8️⃣
COPPA Compliance
ShortHand is a teacher-facing tool. Teachers — not students — create accounts and enter data.

Students do not create accounts, log in, or directly interact with ShortHand.

ShortHand does not knowingly collect personal information directly from children under 13. Any student information in the system was entered by a teacher on behalf of the School.
9️⃣
Term and Termination
This agreement is effective upon the School's first use of ShortHand and remains in effect until terminated.

Either party may terminate this agreement with 30 days written notice.

Upon termination, ShortHand will delete all Student Data associated with the School's accounts within 30 days, unless retention is required by law.
✉️
Contact
To request a countersigned DPA, report a concern, or ask questions about this agreement:

hello@getshorthand.app

ShortHand / GetShortHand LLC