Education Privacy Addendum
agrawal-llc-docs education SaaS privacy addendum. Use this URL (not master Privacy alone) for education-product OAuth Privacy fields after counsel approval.
1. Roles
| Role | Who |
|---|---|
| Controller (or “school official” under FERPA where applicable) | The school / academy / Customer tenant |
| Processor | Saaniya Software LLC |
We process student, parent, and staff personal data only to provide the education product under the Customer’s instructions and any signed DPA.
2. Categories of personal data
- Student: name, student ID, class enrollment, attendance, assignments, grades as configured
- Parent / guardian: name, email, phone (if Customer enables)
- Staff: name, email, role, class assignments
- Auth: OAuth subject ID, email, profile photo if scope granted
- Usage: login times, feature logs
Excluded today: PHI / clinical records; regulated medical-financial document pipelines. We do not sell student PII.
3. FERPA / school-official framing (U.S.)
Where applicable, Saaniya Software LLC operates as a “school official” with a legitimate educational interest only under the school’s authorization and written agreement. We:
- perform institutional services the school would otherwise use employees for;
- remain under the school’s control for use and maintenance of education records;
- use education records only for authorized purposes and do not disclose them to unauthorized parties.
Non-U.S. schools: substitute the local education-privacy regime; flag to counsel per country before signing.
4. Parental rights
Parents and eligible students typically have rights to inspect/review records, request amendment, opt out of directory information, and file complaints under FERPA. Exercise those rights through the school; we assist the school under the DPA.
5. COPPA / children under 13
Where applicable, we support COPPA compliance for students under 13 through school-authorized collection only. Direct-to-child products without a school contract will not launch without counsel COPPA language. OAuth should not knowingly onboard users under 13 outside a school contract.
6. OAuth / SSO scopes
Exact live scopes must match the OAuth consent screen before External publishing. Typical sign-in scopes include openid, email, profile. Classroom / Drive / Graph scopes only if enabled and listed here after go-live.
7. AI features in classroom context
If AI-assisted features process student records, we remain processor—not controller. Student PII is not sent to a general-purpose AI provider unless that provider is listed as a subprocessor and covered by the DPA.
8. Retention and return
We retain data as needed to provide the Services and as required by law or school agreement. Upon termination, student data will be deleted or returned to the school within the period stated in the DPA (target: within 30 days), subject to legal retention holds. Wisconsin public-records rules may require longer retention where they apply.
9. Security (summary)
- TLS in transit; encryption for backups / snapshots where configured
- Role-based access and row-level security where used
- Least-privilege operator access
10. Contact
Saaniya Software LLC
Privacy: saaniyasoftware@nasneeraj.com
For student-record requests, contact your school administrator first.