Back to Home

DRAFT — pending legal review, not legal advice.

This document is a starting template. It has not been reviewed by a licensed attorney and does not constitute legal advice. Do not execute this DPA without qualified counsel review.

Data Processing Agreement

Last updated: 2026-09-20

This Data Processing Agreement (“DPA”) is entered into between the accredited educational institution that adopts the Vanguard SIM Service (the “Institution” or “Controller”) and Vanguard SIM (“Vanguard SIM” or “Processor”). It supplements and forms part of the parties’ order form and the Terms of Service (together, the “Agreement”). Capitalized terms not defined here have the meanings given in the Agreement or, where applicable, in the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and the California Consumer Privacy Act (“CCPA”).

1. Roles of the Parties

The Institution is the Controller of personal data relating to its students, faculty, and staff. Vanguard SIM is a Processor acting on the Institution’s documented instructions. Under FERPA, Vanguard SIM operates as a “school official” with a “legitimate educational interest,” as described in the FERPA Statement. Under the CCPA, Vanguard SIM acts as a “service provider.”

2. Scope, Subject Matter, and Duration

Vanguard SIM will process personal data solely to provide the Service and to comply with the Institution’s documented instructions. Processing continues for the term of the Agreement and any retention period specified in Section 10.

3. Categories of Data Subjects and Data

Data subjects: enrolled students, instructors, teaching assistants, and IT administrators of the Institution who use the Service.

Categories of data:

  • Identifiers: name, institutional email, user ID, LTI or SSO identifiers.
  • Course and section enrollment identifiers.
  • Simulation content: submissions, team artifacts, response text, and LLM prompts and outputs generated during gameplay, feedback, and grading.
  • Scoring events, rubric outputs, and grades.
  • Technical data: IP address, browser and device metadata, timestamps, error traces.

Vanguard SIM does not knowingly process special-category data (health, biometric, financial-account, or government-ID data). If the Institution needs to instruct Vanguard SIM to process any special-category data, the parties will execute a written addendum first.

4. Purposes of Processing

Vanguard SIM will process personal data only to:

  • Authenticate users and provide the Service;
  • Score submissions, generate AI feedback, and pass grades back to the Institution’s LMS;
  • Operate, secure, monitor, and improve the Service;
  • Comply with legal obligations and enforce the Agreement.

Vanguard SIM will not (a) “sell” or “share” personal data as those terms are defined by the CCPA, (b) use personal data for cross-context behavioral advertising, (c) use student submissions to train foundation models, or (d) combine personal data received from the Institution with data received from other sources except as necessary to provide the Service.

5. Sub-Processors

The Institution provides general written authorization for Vanguard SIM to engage the sub-processors listed below to support the Service. Vanguard SIM will impose data-protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance.

Sub-processorPurposeRegion
Anthropic, PBCLLM inference for gameplay, feedback, and grading assistanceUnited States
Supabase, Inc.Database, authentication, and file storageUnited States
Vercel, Inc.Application hosting and edge deliveryUnited States
Stripe, Inc. (if applicable)Payment processing for institutional or seat purchasesUnited States
Email delivery providerTransactional email and contact-form transportUnited States

Vanguard SIM will give the Institution at least thirty (30) days’ notice of any change to this list, and the Institution may object on reasonable data-protection grounds. If the Institution’s objection cannot be resolved, the Institution may terminate the affected portion of the Service.

6. Security Measures

Vanguard SIM implements and maintains technical and organizational measures designed to protect personal data, including:

  • Encryption in transit: TLS 1.2 or higher for all traffic to and from the Service.
  • Encryption at rest: AES-256 through Supabase for all persisted data, including database contents and file storage.
  • Row-level security (RLS): every application table in Supabase has RLS enabled to isolate tenant and course-scoped access.
  • Administrative access allowlist: privileged operations are restricted to a named list of administrators authenticated with strong credentials.
  • Least-privilege service accounts with rotating credentials, and secrets scoped to environment.
  • Audit logging of privileged actions and authentication events.
  • Change management: code review, dependency scanning, and staged deployments through Vercel.
  • Business continuity: automated backups managed by Supabase with a documented recovery procedure.
  • Personnel: confidentiality obligations for all personnel with access to personal data; access is granted only on a need-to-know basis and revoked promptly on role change.

7. Personal Data Breach Notification

Vanguard SIM will notify the Institution’s designated contact without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Institution data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, containment and remediation steps taken or planned, and a point of contact. Vanguard SIM will cooperate reasonably with the Institution’s own breach-response and regulatory-notice obligations.

8. International Transfers

To the extent that personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland is transferred to Vanguard SIM or its sub-processors in the United States, the parties incorporate by reference the European Commission’s Standard Contractual Clauses (Module Two: controller to processor, and Module Three: processor to processor as applicable) and, for UK transfers, the UK International Data Transfer Addendum. The Institution appoints Vanguard SIM to sign the SCCs with sub-processors on its behalf where required.

9. Assistance to Controller

Taking into account the nature of the processing, Vanguard SIM will assist the Institution by appropriate technical and organizational measures to respond to (a) data-subject requests under FERPA, GDPR, UK GDPR, CCPA, or other applicable law, and (b) the Institution’s obligations to conduct data-protection impact assessments and to consult supervisory authorities. Vanguard SIM will notify the Institution if it receives a request directly from a data subject or a governmental authority and (except where prohibited by law) will not respond except as directed by the Institution.

10. Retention, Return, and Deletion

During the term, personal data is retained for twenty-four (24) months after the end of each course offering unless the parties agree otherwise in writing. On termination or expiry of the Agreement, at the Institution’s election, Vanguard SIM will (a) return personal data to the Institution in a commonly used machine-readable format, or (b) securely delete personal data from active systems within thirty (30) days of the request.

Personal data remaining in encrypted backups is not restored and rolls off with the standard backup schedule (a maximum of ninety (90) days). Vanguard SIM may retain de-identified, aggregated data indefinitely, provided it cannot be reasonably re-identified.

11. Audit and Documentation

Vanguard SIM will make available to the Institution the information reasonably necessary to demonstrate compliance with this DPA and will allow, on reasonable prior notice and no more than once per calendar year (except after a Personal Data Breach), an audit conducted by the Institution or a qualified independent auditor bound by confidentiality. Where available, third-party audit reports (for example, SOC 2 reports of sub-processors) will be provided in lieu of direct on-site audits of shared infrastructure.

12. Confidentiality

Vanguard SIM will ensure that all personnel authorized to process personal data are bound by written confidentiality obligations or statutory duties of confidentiality that survive termination of engagement.

13. Order of Precedence

In the event of conflict, this DPA controls over the Terms of Service with respect to the processing of personal data. An institution-specific addendum executed by both parties controls over this DPA to the extent of any inconsistency.

14. Contact

Notices, sub-processor objections, and data-subject requests routed by an Institution should be sent to legal@vanguardsim.com.