Data Processing Agreement

Between ClearLaunchHQ LLC ("Processor") and the Teacher/School ("Controller")

Effective upon account creation — Last updated: August 23, 2026

1. Purpose and Scope

This Data Processing Agreement ("DPA") governs the processing of personal data by ClearLaunchHQ LLC ("we," "Processor") on behalf of teachers and schools ("Controller") in connection with the BeeCommons platform. This DPA is incorporated into and forms part of the BeeCommons Terms of Service.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable individual, including student names, guardian contact information, and student work product.
  • "Processing" means any operation performed on Personal Data, including storage, retrieval, transmission, and deletion.
  • "Student Data" means Personal Data relating to students enrolled in the Controller's class.
  • "Student-Submitted Content" means files or work samples uploaded by a student to their portfolio, or assignments submitted by a student through the platform.

3. Nature of Student Interaction

BeeCommons is structured so that students do not create accounts, do not submit personal information, and do not interact with the platform in any capacity beyond the following two actions, both of which are enabled and controlled exclusively by the teacher:

  • Portfolio uploads — a student may upload a photo or file of their work, visible only to their teacher and the parent or guardian the teacher has designated.
  • Assignment submissions — a student may submit a completed assignment, delivered only to their teacher.

All student accounts are created by the teacher. Students do not register independently, enter personal information, or access any platform features beyond those explicitly enabled by their teacher. The Processor does not collect personal information directly from students.

4. Scope of Processing

The Processor shall process Personal Data only for the following purposes:

  • Displaying student information within the teacher's dashboard
  • Facilitating communication between teachers and authorized family members
  • Storing student portfolio items and Student-Submitted Content
  • Providing behavior tracking and point systems as configured by the teacher
  • Delivering assignment submissions to the teacher

The Processor shall not process Personal Data for any purpose beyond what is necessary to provide the BeeCommons platform.

5. Prohibited Data Categories

The Platform is expressly not designed for and must not be used to process:

  • Academic records — grades, report cards, progress reports, standardized test scores, transcripts, or any other record of academic performance
  • Attendance records — absences, tardies, or truancy records
  • Disciplinary records — behavior incident reports, referrals, suspension or expulsion records, and behavior intervention plans
  • Special education and related services — Individualized Education Programs (IEPs), 504 Plans, disability eligibility determinations, service minutes, evaluation reports, or any records pertaining to a student's disability status, all of which are governed by both FERPA and the IDEA confidentiality provisions at 34 C.F.R. §§ 300.610–300.627
  • Language services — ELL/ESOL classification, screening results, or service placement
  • Health, medical, and mental health records of any kind maintained in connection with a student's education, including school nurse records, immunization histories, medication administration records, allergy and medical condition information, physical examination results, psychological and psychiatric evaluations, mental health assessments, and therapy notes
  • Legal and custodial records — custody arrangements, court orders, restraining orders, or guardianship determinations
  • Socioeconomic and status information — free or reduced-price lunch eligibility, and homeless (McKinney-Vento) or foster care status
  • Formal conference records — documented parent/teacher conference notes maintained as part of a student's education record
  • Directory information for opted-out families — a student's name, photograph, or other directory information where the family has opted out of directory disclosure under 34 C.F.R. § 99.37

This enumeration is illustrative rather than exhaustive. Any record protected by law or maintained as part of a student's official education record falls within this prohibition whether or not it appears above.

Note: The health, medical, and mental health records listed above are governed by FERPA when maintained by a school or school official. This prohibition applies regardless of whether any other federal or state health privacy law independently applies to the source of the information.

The Controller is solely responsible for ensuring that no prohibited data categories are entered into the platform. The Processor disclaims all liability for any breach, penalty, or claim arising from the Controller's entry of prohibited data.

6. FERPA Compliance

The Processor acknowledges that student education records entered into BeeCommons by the Controller may be subject to the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g and 34 C.F.R. Part 99. Where student data includes records relating to special education services, eligibility determinations, or disability status, such records are additionally governed by the Individuals with Disabilities Education Act (IDEA) confidentiality provisions at 34 C.F.R. §§ 300.610–300.627, which impose confidentiality requirements that run parallel to and in some respects exceed those of FERPA. The Processor's obligations under this DPA apply equally to IDEA-protected records.

In providing the Service:

  • The Processor acts solely as a service provider processing data on behalf of and under the direct control of the Controller, consistent with 34 C.F.R. § 99.31(a)(1)
  • The Processor does not have independent rights to student education records
  • The Processor maintains student data under the school's direct control regarding use and maintenance, and will not use student data for any purpose other than providing the Service to the Controller
  • The Processor will not disclose student education records to any third party except as necessary to provide the Service or as required by law
  • The Controller retains full ownership and control of all student data entered into the platform
  • Upon written request to support@beecommons.com, the Controller may request the return or permanent deletion of all student data associated with their account

7. COPPA Compliance

The Processor does not knowingly collect personal information directly from children under 13. All student accounts are created by the Controller (teacher). Student interaction with the platform is limited to uploading work samples and submitting assignments, both of which are controlled by and visible only to the teacher and designated parent.

The Controller is responsible for obtaining verifiable parental consent before creating student accounts or enabling student-facing features for children under 13, in accordance with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506.

8. Controller Responsibilities

The Controller agrees to:

  • Ensure legal authority to process the student data entered into BeeCommons, including compliance with FERPA, IDEA, COPPA, and applicable state privacy laws
  • Obtain required parental consent before enabling student portal access or portfolio sharing with families
  • Ensure that no data listed in Section 5 is entered into the platform under any circumstances
  • Promptly notify us at support@beecommons.com if they become aware that prohibited data has been entered into the platform

9. Security Measures

The Processor maintains the following technical and organizational measures to protect Personal Data:

  • Encryption of data in transit (TLS) and at rest
  • Row Level Security (RLS) ensuring each teacher accesses only their own data
  • Authentication via Supabase with email verification required for teacher accounts
  • Access controls limiting platform data to authenticated users only
  • Parent and student portal access limited to accounts created and controlled by the teacher

10. Sub-Processors

The Processor uses the following sub-processors to deliver the Service:

Sub-ProcessorPurposeLocation
SupabaseDatabase and authenticationUnited States (AWS)
VercelApplication hostingUnited States
ResendTransactional emailUnited States
AnthropicAI drafting of newsletters, lesson plans, and posts, using the Controller's own content. Student Data is transmitted in one circumstance only: on roster import, the column headings and first three rows of the uploaded file are sent to determine the file's layout. Anthropic does not use data submitted through its business API to train its models.United States

11. Data Retention and Deletion

Student Data belongs to a single class year and is not carried forward. A student's record exists only within the classroom of the teacher who entered it. When that student moves on to another classroom, no record follows them: their new teacher creates a new record under their own account and control, and the Processor does not link, merge, or transfer records between teachers or across years.

End of the school year

When a teacher begins a new school year using Fresh Start:

  • Student portfolio photos and files are permanently deleted immediately, including from underlying storage. They are not archived and cannot be recovered.
  • Student and guardian records are removed from the active roster. Guardian records are deleted along with the student they belong to.
  • A read-only snapshot of the year is retained for the teacher's own reference for two years, after which it is permanently deleted.

Other automatic deletion

  • Newsletters are retained through the school year in which they were sent and permanently deleted the following summer.
  • Files belonging to deleted students are swept from storage automatically, so nothing remains after the record it belonged to is gone.
  • Dormant accounts are deleted in full, including Student Data, after two years without a sign-in. The Controller is emailed 30 days beforehand, and signing in cancels the deletion.

Lesson plans are the Controller's own professional work, not Student Data, and are not deleted on any schedule. They carry forward between years and survive Fresh Start. They are removed only if the Controller deletes them or the account itself is deleted.

The Controller may delete student records, portfolio items, messages, and newsletters at any time, and may export their data from Settings before any of the above takes effect. Upon account deletion, all associated data is permanently removed within 30 days. The Controller may also request immediate deletion of all data by contacting support@beecommons.com.

12. Data Breach Notification

In the event of a confirmed breach affecting Personal Data, the Processor will notify the affected Controller within 72 hours of becoming aware of the breach, to the email address on file for their account. The notification will include the nature of the breach, the data affected, and the steps being taken to address it.

13. Governing Law

This DPA is governed by the laws of the United States. To the extent state law applies, the laws of Florida shall govern.

14. Contact

Questions regarding this DPA should be directed to:

ClearLaunchHQ LLC
BeeCommons
support@beecommons.com