DRAFT — pending legal review, not legal advice.
This document is a starting template. It has not been reviewed by a licensed attorney and does not constitute legal advice. Do not execute this DPA without qualified counsel review.
Last updated: 2026-09-20
This Data Processing Agreement (“DPA”) is entered into between the accredited educational institution that adopts the Vanguard SIM Service (the “Institution” or “Controller”) and Vanguard SIM (“Vanguard SIM” or “Processor”). It supplements and forms part of the parties’ order form and the Terms of Service (together, the “Agreement”). Capitalized terms not defined here have the meanings given in the Agreement or, where applicable, in the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and the California Consumer Privacy Act (“CCPA”).
The Institution is the Controller of personal data relating to its students, faculty, and staff. Vanguard SIM is a Processor acting on the Institution’s documented instructions. Under FERPA, Vanguard SIM operates as a “school official” with a “legitimate educational interest,” as described in the FERPA Statement. Under the CCPA, Vanguard SIM acts as a “service provider.”
Vanguard SIM will process personal data solely to provide the Service and to comply with the Institution’s documented instructions. Processing continues for the term of the Agreement and any retention period specified in Section 10.
Data subjects: enrolled students, instructors, teaching assistants, and IT administrators of the Institution who use the Service.
Categories of data:
Vanguard SIM does not knowingly process special-category data (health, biometric, financial-account, or government-ID data). If the Institution needs to instruct Vanguard SIM to process any special-category data, the parties will execute a written addendum first.
Vanguard SIM will process personal data only to:
Vanguard SIM will not (a) “sell” or “share” personal data as those terms are defined by the CCPA, (b) use personal data for cross-context behavioral advertising, (c) use student submissions to train foundation models, or (d) combine personal data received from the Institution with data received from other sources except as necessary to provide the Service.
The Institution provides general written authorization for Vanguard SIM to engage the sub-processors listed below to support the Service. Vanguard SIM will impose data-protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance.
| Sub-processor | Purpose | Region |
|---|---|---|
| Anthropic, PBC | LLM inference for gameplay, feedback, and grading assistance | United States |
| Supabase, Inc. | Database, authentication, and file storage | United States |
| Vercel, Inc. | Application hosting and edge delivery | United States |
| Stripe, Inc. (if applicable) | Payment processing for institutional or seat purchases | United States |
| Email delivery provider | Transactional email and contact-form transport | United States |
Vanguard SIM will give the Institution at least thirty (30) days’ notice of any change to this list, and the Institution may object on reasonable data-protection grounds. If the Institution’s objection cannot be resolved, the Institution may terminate the affected portion of the Service.
Vanguard SIM implements and maintains technical and organizational measures designed to protect personal data, including:
Vanguard SIM will notify the Institution’s designated contact without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Institution data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, containment and remediation steps taken or planned, and a point of contact. Vanguard SIM will cooperate reasonably with the Institution’s own breach-response and regulatory-notice obligations.
To the extent that personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland is transferred to Vanguard SIM or its sub-processors in the United States, the parties incorporate by reference the European Commission’s Standard Contractual Clauses (Module Two: controller to processor, and Module Three: processor to processor as applicable) and, for UK transfers, the UK International Data Transfer Addendum. The Institution appoints Vanguard SIM to sign the SCCs with sub-processors on its behalf where required.
Taking into account the nature of the processing, Vanguard SIM will assist the Institution by appropriate technical and organizational measures to respond to (a) data-subject requests under FERPA, GDPR, UK GDPR, CCPA, or other applicable law, and (b) the Institution’s obligations to conduct data-protection impact assessments and to consult supervisory authorities. Vanguard SIM will notify the Institution if it receives a request directly from a data subject or a governmental authority and (except where prohibited by law) will not respond except as directed by the Institution.
During the term, personal data is retained for twenty-four (24) months after the end of each course offering unless the parties agree otherwise in writing. On termination or expiry of the Agreement, at the Institution’s election, Vanguard SIM will (a) return personal data to the Institution in a commonly used machine-readable format, or (b) securely delete personal data from active systems within thirty (30) days of the request.
Personal data remaining in encrypted backups is not restored and rolls off with the standard backup schedule (a maximum of ninety (90) days). Vanguard SIM may retain de-identified, aggregated data indefinitely, provided it cannot be reasonably re-identified.
Vanguard SIM will make available to the Institution the information reasonably necessary to demonstrate compliance with this DPA and will allow, on reasonable prior notice and no more than once per calendar year (except after a Personal Data Breach), an audit conducted by the Institution or a qualified independent auditor bound by confidentiality. Where available, third-party audit reports (for example, SOC 2 reports of sub-processors) will be provided in lieu of direct on-site audits of shared infrastructure.
Vanguard SIM will ensure that all personnel authorized to process personal data are bound by written confidentiality obligations or statutory duties of confidentiality that survive termination of engagement.
In the event of conflict, this DPA controls over the Terms of Service with respect to the processing of personal data. An institution-specific addendum executed by both parties controls over this DPA to the extent of any inconsistency.
Notices, sub-processor objections, and data-subject requests routed by an Institution should be sent to legal@vanguardsim.com.