School Data Protection Addendum

Version 1.0 · Last revised: August 13, 2026

This School Data Protection Addendum supplements the VyNext School Customer Agreement and applies when VyNext processes nonpublic School Data on behalf of a School, including student information or education records where applicable.

1. Purpose and Scope

This School Data Protection Addendum supplements the VyNext School Customer Agreement and applies to school-controlled information processed by VyNext on behalf of the school, including education records and student personal information where applicable.

2. Roles

The school is the controller of school-controlled personal information. VyNext acts as a processor on the school’s behalf and subject to applicable law, including FERPA where education records are involved.

3. Processing and Use

VyNext processes school-controlled information only to provide the services requested by the school and as necessary to operate, secure, and support the platform. VyNext does not sell school-controlled student personal information or use it for behavioral advertising.

4. Security

VyNext maintains administrative, technical, and organizational safeguards appropriate to the information processed. Security incident handling will follow applicable law and contractual obligations.

5. Data Retention and Deletion

VyNext retains school-controlled information as reasonably necessary to provide services and comply with legal, accounting, security, and dispute-resolution requirements, then deletes or anonymizes it when no longer necessary.

6. Security Incidents and Breach Cooperation

VyNext will investigate suspected unauthorized access to or acquisition, disclosure, alteration, or loss of protected School Data and will take reasonable measures to contain, remediate, and recover from confirmed security incidents. VyNext will notify the School without unreasonable delay when a confirmed incident affecting the School’s protected data triggers a notification obligation under applicable law or this Addendum.

VyNext will provide information reasonably available concerning the nature of the incident, affected information, known impact, containment or remediation measures, and other information reasonably necessary for the School to evaluate its obligations. The School and VyNext will reasonably cooperate regarding investigation, legally required notifications, remediation, and response. Neither party will make a statement on behalf of the other without authorization except where required by law.

7. School Requests, Export, Return, and Deletion

VyNext will reasonably assist the School with requests concerning School-controlled data where the School cannot reasonably fulfill the request using available Platform tools. Where applicable information is controlled by the School, VyNext may refer an individual requester to the School or coordinate with the School before acting.

Upon termination or a valid School request, VyNext will make reasonable efforts to return or provide an export of eligible School-controlled data using the export capabilities and reasonably usable formats then available. After the applicable offboarding period, VyNext may delete or de-identify School Data no longer reasonably necessary, subject to retention required or reasonably necessary for transactions, accounting, refunds, disputes, fraud prevention, security, audit trails, backups, legal obligations, and enforcement of agreements.

Information retained after termination remains protected under this Addendum for as long as VyNext continues to process it. Backup copies may persist until overwritten through ordinary backup lifecycle processes where immediate deletion is not reasonably practicable.

8. Subprocessors and Transfers

VyNext may use service providers to help operate the platform, including providers for hosting, infrastructure, authentication, payment processing, transactional email, security, monitoring, analytics, and support. VyNext will require providers that process protected School Data on its behalf to maintain protections appropriate to the services they perform.

VyNext will maintain a list or other disclosure of material subprocessors that process protected School Data and make it available through an appropriate published or contractual channel as the production vendor list is finalized. VyNext will not authorize a subprocessor to use protected School Data for behavioral advertising or unrelated commercial purposes merely because it receives the information to provide services to VyNext.

9. School Responsibilities

The School is responsible for determining what School Data it provides to VyNext, limiting data to information appropriate for enabled features, assigning authorized staff access, and using the Platform consistently with applicable student-privacy and records requirements. The School should not place highly sensitive or unnecessary student information into fields or features that are not designed to receive it.

Questions?

Questions about data protection may be submitted through the VyNext Contact Us page.