1. Parties, scope, and order of precedence
This Data Processing Addendum (“Addendum”) is between Caleb Media Studio LLC, which operates CampusLayer (“CampusLayer,” “we,” “us”), and the school, district, or educational institution that has agreed to use CampusLayer (the “Institution”). It applies to all Institution Data that CampusLayer processes to provide CampusLayer Connect, CampusLayer Assistant, and related services (the “Services”).
This Addendum supplements the Terms of Service and the Privacy Policy. If the Institution and CampusLayer sign a separate agreement, including a state or consortium student data privacy agreement, that signed agreement controls where it conflicts with this Addendum, and this Addendum controls where it conflicts with the Terms of Service or Privacy Policy.
2. Definitions
- Institution Data means any information about the Institution, its staff, or its students that CampusLayer receives from the Institution, its users, or a system the Institution or its users connect to CampusLayer, including Student Data.
- Student Data means personally identifiable information from students’ education records within the meaning of the Family Educational Rights and Privacy Act (“FERPA”), 20 U.S.C. § 1232g and 34 C.F.R. Part 99, and “covered information” under applicable state student privacy laws, including section 1006.1494, Florida Statutes.
- Subprocessor means a third party that CampusLayer engages to process Institution Data on CampusLayer’s behalf to provide the Services.
- Security Incident means a confirmed unauthorized access to, or acquisition, disclosure, or loss of, Institution Data in CampusLayer’s custody.
3. Roles and the Institution’s control
The Institution owns and controls Institution Data. CampusLayer processes it only on the Institution’s behalf and under its direction. For FERPA purposes, the Institution designates CampusLayer as a “school official” with a “legitimate educational interest” under 34 C.F.R. § 99.31(a)(1)(i)(B): CampusLayer performs a service the Institution would otherwise use its own employees for, is under the Institution’s direct control with respect to the use and maintenance of Student Data, and uses Student Data only for the purposes authorized here and does not redisclose it except as permitted by 34 C.F.R. § 99.33.
The Institution exercises that control through the Services, including by choosing who has access, which roles may use AI features, which categories of data may reach an AI model, and which connected-system capabilities are available. These controls are described in the Security Overview.
4. Permitted purposes
CampusLayer processes Institution Data only to:
- provide, secure, support, and maintain the Services the Institution uses;
- carry out actions that the Institution or its authorized users request;
- prevent, detect, and respond to fraud, abuse, and security threats;
- meter usage for operating and billing the Services, without the content of requests; and
- comply with law, as described in section 11.
5. Prohibited uses
CampusLayer will not:
- sell, rent, or trade Institution Data;
- use Student Data, or information derived from it, for targeted advertising;
- build a profile of a student for any purpose other than the Institution’s educational purposes;
- use Institution Data to train or improve AI models, or permit a Subprocessor to do so;
- disclose Student Data to any third party except a Subprocessor under section 7, as the Institution directs, or as required by law under section 11; or
- use Institution Data for any commercial purpose unrelated to providing the Services to the Institution.
6. Data minimization and AI processing
CampusLayer collects only the Institution Data reasonably necessary to provide the Services. Data from connected systems such as Microsoft 365 or Canvas is retrieved when a user asks for it, with that user’s own permissions, and is not copied into a standing CampusLayer database.
Before any data from a connected system is sent to an AI model, CampusLayer applies the Institution’s data policy to each field according to what that field contains. Fields that hold student identifiers, government identifiers, home addresses, guardian contact details, credentials, or cross-system identity links are never sent to an AI model. Fields that hold names and email addresses are replaced with placeholders. Grades, attendance, accommodations, IEP and 504 records, discipline, health, counseling, and demographic information are withheld unless the Institution changes that setting.
Free text, meaning what a user types and text the Institution allows to be sent such as email subject lines, email message text, and calendar event titles, is screened before it reaches an AI model: names of people in the Institution’s CampusLayer records, email addresses, phone numbers, and long identifier numbers are replaced with placeholders or removed. Names that are not in those records, such as nicknames or people outside the Institution, may not be recognized, and CampusLayer does not guarantee that every mention is detected. Files a user attaches are sent as provided. The Institution can withhold any free-text category in its data policy.
AI requests are sent to the AI provider listed on the Subprocessors page with the provider’s response storage turned off. Unless zero data retention is in place with that provider, the provider may retain requests for up to 30 days for abuse monitoring under its own data processing terms. CampusLayer will state on the Subprocessors page whether zero data retention is in place.
7. Subprocessors
The Institution authorizes CampusLayer to use the Subprocessors listed on the Subprocessors page. CampusLayer requires each Subprocessor, by written agreement, to protect Institution Data with obligations no less protective than this Addendum in all material respects, and remains responsible for each Subprocessor’s performance.
CampusLayer will give at least 30 days’ notice before adding or replacing a Subprocessor that processes Student Data, by updating the Subprocessors page and notifying the Institution’s administrators. The Institution may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Institution may stop using the affected Services and CampusLayer will delete the related Institution Data under section 10.
Systems that the Institution or its users choose to connect, such as Microsoft 365, Canvas, or a student information system, are not CampusLayer Subprocessors. Their handling of data is governed by the Institution’s own agreements with those providers.
8. Security
CampusLayer maintains administrative, technical, and physical safeguards appropriate to the sensitivity of Institution Data, including the measures described in the Security Overview. These include separation of each Institution’s data, database-enforced access controls, encryption in transit, encryption of stored connection credentials, least-privilege access, and audit logging of security-relevant actions.
CampusLayer personnel may access an Institution’s workspace only to set it up during an Institution-approved provisioning period, which ends when setup is completed, or as the Institution otherwise authorizes. Every such access is logged and visible to the Institution’s administrators. Personnel with access to Institution Data are bound by confidentiality obligations.
9. Security Incidents
CampusLayer will notify the Institution without undue delay, and no later than 72 hours after confirming a Security Incident affecting the Institution’s data. The notice will describe, to the extent known, what happened, the data and individuals affected, the steps taken to contain it, and a contact for further information. CampusLayer will cooperate with the Institution’s investigation and with any notices to individuals or authorities that the Institution is required to give, and will not notify affected individuals directly unless the Institution asks it to or the law requires it.
10. Return and deletion
Within 90 days after the Institution’s written request, or after the Institution’s use of the Services ends, CampusLayer will delete the Institution’s Data, or return it in a commonly used format first if the Institution asks. When the Institution notifies CampusLayer that a student is no longer enrolled, or that a course or program has ended, CampusLayer will delete that student’s covered information within 90 days of the notice, unless a parent or guardian has expressly consented to its retention or the law requires otherwise.
Deletion covers backups as they expire on their normal rotation. CampusLayer may keep aggregated usage records that contain no personal information, and records it is required by law to keep, which remain protected under this Addendum for as long as they are kept. On request, CampusLayer will confirm deletion in writing.
11. Requests from parents, students, and authorities
If CampusLayer receives a request from a parent, guardian, eligible student, or staff member to access, correct, or delete Institution Data, it will refer the request to the Institution and help the Institution respond. CampusLayer will notify the Institution before disclosing Institution Data in response to a subpoena, court order, or other legal demand, unless the law prohibits that notice, and will disclose only what the demand requires.
12. Children
Where Services are used by children under 13, the Institution provides any consent required by the Children’s Online Privacy Protection Act on behalf of parents, for the educational purpose of the Services only. CampusLayer uses children’s information solely for that educational purpose and for no other commercial purpose. CampusLayer Assistant is available only to staff roles; student accounts cannot be given access to it.
13. Data location
CampusLayer stores Institution Data in the United States. Subprocessors may process data in other locations only as described on the Subprocessors page and in their own data processing terms.
14. Information and audits
Once a year, or after a Security Incident, CampusLayer will answer the Institution’s reasonable written security and privacy questionnaire and provide the information reasonably necessary to show that it is meeting this Addendum. CampusLayer does not currently hold SOC 2 or ISO 27001 certification. Its hosting and database Subprocessors do, and their reports are available from them under their own terms.
15. Term and liability
This Addendum lasts for as long as CampusLayer processes Institution Data. Sections 5, 9, 10, and 11 continue until all Institution Data has been deleted. Each party’s liability under this Addendum is subject to the limitations in the Terms of Service or the parties’ signed agreement. This Addendum is governed by the law that governs the Terms of Service, except where an Institution’s governing law must apply under applicable law.
16. Contact and signed copies
Institutions that need a signed copy of this Addendum, or that require their own state or consortium data privacy agreement, can request one through the CampusLayer contact page.