data processing
agreement.
legally binding addendum governing the handling of institutional and personal data by LUCY OS as a processor.
Definitions & Roles
Under global privacy frameworks (GDPR, POPIA, FERPA), the subscribing Educational Institution acts as the 'Data Controller' (or Responsible Party). LUCY OS acts strictly as the 'Data Processor' (or Operator). We process personal and institutional data solely on your documented instructions.
Scope of Processing
LUCY OS processes student, parent, and staff data for the exclusive purpose of delivering our academic management, grading, and communication services. Processing duration strictly mirrors the active subscription term.
Security Measures
We enforce Row-Level Security (RLS) within our PostgreSQL clusters, ensuring mathematical tenant isolation. All data is encrypted at rest using AES-256 and in transit via TLS 1.3. We maintain strict access controls, regular vulnerability scanning, and automated threat monitoring.
Sub-Processors
LUCY OS engages specific sub-processors (e.g., Supabase for database hosting, Vercel for edge network delivery). We remain fully liable for the acts and omissions of our sub-processors and bind them to obligations no less protective than those contained in this DPA.
Data Subject Requests
As the Processor, we do not respond directly to data subject requests (e.g., right to be forgotten, access requests). We will immediately forward any such requests to the Institution and provide the technical tools necessary via the Admin dashboard for the Institution to fulfill its legal obligations.
Personal Data Breach
In the event of a confirmed security incident leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data, we will notify the Institution without undue delay (and in no event later than 48 hours after becoming aware). We will provide all necessary cooperation for the Institution's regulatory reporting.
Return & Deletion of Data
Upon termination or expiration of the Master Service Agreement, LUCY OS will, at the Institution's election, either delete or return all personal data. Once deleted, data is permanently cryptographically overwritten and unrecoverable from our active databases within 30 days.