CohortLedger
Legal / DPA

Data Processing Addendum.

Contractual terms a school adopts to formalize CohortLedger's role as a service provider, including named subprocessors, breach notification SLA, data retention windows, and the FERPA school-official posture.

Effective June 8, 2026

Effective date: June 8, 2026. Last reviewed: June 14, 2026.

Parties

This Data Processing Addendum (the “DPA”) is entered into between the school operator (the “School”, “Educational Agency”, or “Controller”) and Ravencord Inc., a Delaware C-corporation operating CohortLedger (“Ravencord”, “Service Provider”, or “Processor”). The DPA supplements the Terms of Service and the Privacy Policy. If there is a conflict, this DPA governs for matters of personal information and student data handling.

1. Defined terms

  • Personal Information means information that identifies or relates to an identified or identifiable individual processed by Ravencord on behalf of the School.
  • Student Records means Personal Information concerning a student, including records protected under FERPA.
  • Processing has the meaning given under applicable US state privacy laws.
  • Subprocessor means a third party engaged by Ravencord to Process Personal Information.
  • Security Incident means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Information processed by Ravencord.

2. Roles and FERPA designation

The School is the controller (or business) of Personal Information about its families and students. Ravencord is the processor (or service provider) and acts only on documented instructions from the School.

Where the School is subject to FERPA, the School hereby designates Ravencord as a school official with a legitimate educational interest in the relevant Student Records under 34 CFR § 99.31(a)(1)(i)(B). Ravencord performs an institutional service or function for which the School would otherwise use its own employees; Ravencord is under the direct control of the School with respect to the use and maintenance of Student Records; and Ravencord is subject to the use and re-disclosure requirements of 34 CFR § 99.33(a).

3. Purpose limitation

Ravencord will Process Personal Information only to provide the CohortLedger service to the School, including enrollment records, quarterly invoicing, attendance tracking, compliance reporting, audit-packet generation, and related support. Ravencord will not:

  • Sell Personal Information.
  • Share Personal Information for cross-context behavioral advertising.
  • Use Personal Information to build profiles for any purpose outside delivery of the service.
  • Use Student Records for advertising, marketing, or to train artificial intelligence or machine learning models, ours or any third party’s.
  • Combine Personal Information from the School with Personal Information from any other source for any purpose outside delivery of the service.

4. Categories of data

Personal Information Processed under this DPA includes the categories described in the Privacy Policy: operator account information, family contact information, and limited Student Records (name, grade level, attendance entries, ESA program assignment, per-quarter funding status). Sensitive categories such as health records, biometric data, social security numbers, and child photos are not Processed.

5. Subprocessors

Ravencord maintains the canonical, current list of Subprocessors at cohortledger.com/subprocessors. Today the Subprocessor list is:

  • Vercel Inc. (United States): frontend hosting and edge network.
  • Supabase Inc. (United States): primary database, authentication, file storage, edge functions.
  • Stripe, Inc. (United States): subscription billing and family balance processing.
  • Resend, Inc. (United States): transactional email and authentication SMTP backend.

Each Subprocessor is bound by contractual obligations no less protective than those imposed on Ravencord by this DPA. Ravencord remains liable for the acts and omissions of its Subprocessors with respect to Personal Information. Ravencord will provide the School at least thirty (30) days’ advance written notice before adding a new Subprocessor or activating a Planned Subprocessor against live data. The School may object on reasonable grounds; if the parties cannot resolve the objection within 15 days, the School may terminate the affected portion of the service.

6. Security commitments

Ravencord maintains administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, use, disclosure, alteration, and destruction, including:

  • TLS 1.2 or higher encryption for data in transit.
  • AES-256 or equivalent encryption at rest in the production database.
  • Role-based access controls, least-privilege administration, and multi-factor authentication on production access.
  • Audit logging of administrative actions affecting Personal Information.
  • Encrypted, regularly tested backups and a documented disaster recovery procedure.
  • Vulnerability management and security monitoring.
  • An annual written review of the information security program.
  • Confidentiality obligations on Ravencord personnel who access School data, surviving termination of employment.
  • Background checks on Ravencord personnel with production access, consistent with applicable employment law.

SOC 2 Type II certification is on the Ravencord roadmap and is targeted for completion in calendar 2027. Certificates and independent assessment summaries will be made available to Schools on request under reasonable confidentiality conditions once available.

7. Insurance

Ravencord maintains, or will obtain prior to commercial launch, commercial general liability, technology errors & omissions, and cyber liability insurance with limits appropriate to the scale of the service. Certificates of insurance are available to Schools on written request to legal@cohortledger.com.

8. Data subject rights

The School is responsible for verifying the identity of a data subject (typically a parent acting on behalf of a child) and for handling the underlying access, correction, or deletion request. Ravencord will provide the tools and reasonable support needed to fulfill verified requests, including export and deletion functionality in the dashboard, within fifteen (15) business days of a documented School request, or sooner where applicable law requires.

9. Security incident notification

Ravencord will notify the School in writing of any Security Incident affecting Personal Information within seventy-two (72) hours of confirmation. The notice will include: (a) the nature of the incident; (b) the categories and approximate number of data subjects and records affected; (c) the likely consequences; (d) the measures Ravencord has taken or proposes to take; and (e) the contact point for further information. Ravencord will provide updates as the investigation progresses and reasonable assistance to the School in fulfilling its own notification obligations under applicable US state breach notice laws.

10. Audit rights

On reasonable written notice (at least thirty (30) days in advance) and no more than once per calendar year, except in case of a confirmed Security Incident, the School may request documentation of Ravencord’s security and privacy controls. Ravencord will provide a summary of controls and any relevant independent assessments under reasonable confidentiality conditions. Where the School is legally required to conduct an on-site audit, the parties will coordinate timing and scope to minimize disruption.

11. Data retention, return, and deletion

Ravencord retains Personal Information for the duration of the School’s subscription. On termination or expiration:

  • 90-day export window. For 90 days after termination, the School may export records through the dashboard or by written request, at no additional charge.
  • Deletion within 30 days of the export window closing. Ravencord will delete or anonymize Personal Information within 30 days after the end of the 90-day export window, except where (a) the School requests extended retention in writing (which may be subject to a reasonable storage fee), (b) applicable law requires longer retention (typically 4 to 7 years for ESA-funded tuition records), or (c) data is held in encrypted backups that will be purged on the normal 30-day backup rotation.
  • Certificate of destruction. A written certificate of destruction is available on request.

12. Aggregated and de-identified data

Notwithstanding the restrictions above, Ravencord may use aggregated and de-identified data that cannot reasonably be linked to any individual, family, or school, to operate and improve the CohortLedger service, including measuring feature usage, calculating service-level statistics, and informing roadmap decisions. Ravencord will not attempt to re-identify aggregated data and will not share it with third parties in a form that could reasonably be re-identified.

13. International transfers

Personal Information Processed under this DPA is hosted in the United States. Ravencord does not transfer Personal Information outside the United States as part of normal service operations.

14. State-specific addenda

  • New York. Schools operating in New York must execute the New York Parents Bill of Rights Addendum under NY Education Law § 2-d before transmitting Student Records.
  • Illinois. Ravencord operates consistent with the obligations imposed on online service operators under the Illinois Student Online Personal Protection Act (SOPPA, 105 ILCS 85), including the prohibitions on advertising, sale, and targeted profiling, and will provide a SOPPA-compliant counterpart on request.
  • California.Ravencord operates consistent with the Student Online Personal Information Protection Act (SOPIPA, Cal. Bus. & Prof. Code § 22584) and the CCPA/CPRA service-provider provisions, including the prohibition on targeted advertising and sale of Student Records.
  • Connecticut, Colorado.Ravencord operates consistent with Connecticut’s student-data-privacy and CTDPA obligations and the Colorado Privacy Act service-provider obligations; state-specific addenda are available on request to legal@cohortledger.com.

15. Term and survival

This DPA is effective when the School signifies acceptance (through dashboard click-through during signup or by executing a written counterpart) and remains in force for the duration of the underlying subscription. Sections 1 (Defined Terms), 6 (Security Commitments) only as to data still in Ravencord’s possession, 9 (Security Incident Notification) as to incidents occurring during the term, 11 (Data Retention, Return, and Deletion), 12 (Aggregated and De-identified Data), 16 (Confidentiality), and 17 (No Third-Party Beneficiaries) survive termination.

16. Confidentiality

Each party will treat the other’s confidential information with at least the same care it uses for its own confidential information, and will not disclose it except to personnel and advisors with a need to know and bound by equivalent confidentiality obligations. This DPA does not require disclosure of trade secrets.

17. No third-party beneficiaries

Except as expressly stated, this DPA confers no rights or remedies on any person other than the School and Ravencord.

18. How to sign

For Schools that need a signed DPA, including the New York Parents Bill of Rights Addendum or any other state-specific counterpart, email legal@cohortledger.com with the school’s legal name, state, and a contact. We return a counter-signed PDF within two business days.