Genie

School DPA

Data Processing Agreement (template)

School officials reviewing a data processing agreement

This is a sample FERPA-minded template for institutional review only. It is not a signed agreement. Institutions must review it with legal counsel and execute a signed version before sharing student education records.

Parties

Institution ("School") and Service Provider (Genie Student Aid Hub, developed by One27). Contact: elementone27@gmail.com.

Definitions

  • Personal Data — information relating to an identified or identifiable natural person, including student education records under FERPA (20 U.S.C. § 1232g).
  • School Official / Legitimate Educational Interest — as defined in the Institution's FERPA annual notification.

FERPA compliance

If the Institution designates the Service Provider as a school official, the Provider agrees to use records only to provide the Service, not to re-disclose except as FERPA permits, to allow inspections as required, and to return or destroy records upon termination.

Scope of processing

Processing is limited to the Institution's instructions for AI-assisted financial aid reference. Data subjects may include students and parents. Categories, if voluntarily submitted, may include names and enrollment or aid details. Do not submit SSNs, ITINs, FTI, or full financial account numbers. The Service is designed to operate with anonymized scenarios and does not require PII. Photo analysis, when enabled, is for award letters and policy documents — never tax returns.

Sub-processors

  • xAI — language model, vision, and voice inference
  • Vercel Inc. — hosting
  • Neon — application database (accounts, plan, usage counters)
  • Stripe — payment processing
  • Google — optional sign-in
  • DuckDuckGo — live web search for current federal/news pages

X/Twitter is used only as a public contact handle, not as a processor of education records. Material changes will be notified with an opportunity to object where required.

Security, retention, incidents

  • Encryption in transit (TLS 1.2+), access controls, incident response
  • Breach notification within 72 hours where feasible
  • No persistent storage of chat messages in this version; operational logs up to 30 days
  • Deletion confirmation within 30 days upon written request

Rights, audits, term

The Institution remains responsible for data-subject rights under FERPA, CCPA, and similar laws. The Provider will reasonably assist. The Institution may request compliance information and, with notice, support audits. This template is effective upon first use of a signed version and ends on cessation or written notice, at which point data is deleted or returned.

Governing law

Laws of California; disputes in Los Angeles County courts.

Execution

To execute a signed DPA, email elementone27@gmail.com from an institutional address.