FlashEDU Student Data Privacy Agreement
FlashMath's standard student data privacy agreement, following the Student Data Privacy Consortium's National Data Privacy Agreement structure. Covers data ownership, permitted use, AI provider restrictions, breach notification, and deletion.
Version 1.1 · Effective 2026-08-10 · Questions: education@flashmath.io
Article I: Purpose and Scope
- Purpose. This DPA describes the duties and responsibilities of the Parties to protect Student Data consistent with applicable federal and state privacy law, including the Family Educational Rights and Privacy Act ("FERPA," 20 U.S.C. § 1232g), the Children's Online Privacy Protection Act ("COPPA," 15 U.S.C. §§ 6501–6506), the Protection of Pupil Rights Amendment ("PPRA"), and applicable state student data privacy laws.
- Scope. This DPA applies to all Student Data collected, processed, transmitted, stored, or maintained by Company through the Services (as defined in Exhibit A) in connection with the Service Agreement, regardless of the format in which it is maintained.
- Term. This DPA is effective as of the DPA Effective Date and remains in effect for as long as Company maintains any Student Data received under the Service Agreement, notwithstanding termination or expiration of the Service Agreement.
Article II: Definitions
Terms used in this DPA have the meanings given below (see also Exhibit D for additional defined terms).
- "Student Data" means personally identifiable information, as defined by FERPA and applicable state law, of a student that is collected, created, or maintained by the LEA and provided to, or generated by, Company through the Services. Student Data includes, at minimum, the categories described in Exhibit B, and does not include de-identified or aggregated data from which no student can reasonably be identified.
- "De-Identified Data" means Student Data from which all direct and indirect identifiers have been removed, such that there is no reasonable basis to believe the remaining information can be used to identify a student, either alone or in combination with other reasonably available information.
- "Services" means the FlashEDU Service described in Exhibit A.
- "Authorized Employee" means an employee, contractor, or agent of Company who has a legitimate need to access Student Data to fulfill Company's obligations under the Service Agreement and who is bound by confidentiality obligations no less protective than this DPA.
- "Subprocessor" means a third party engaged by Company that has access to or processes Student Data to provide services to Company necessary to deliver the Services, as listed in the Subprocessor and Security Overview, incorporated by reference.
- "Security Breach" means the unauthorized acquisition of, or access to, Student Data maintained by Company that compromises the security, confidentiality, or integrity of the Student Data.
Article IV: Duties of Company
- Provide Services. Company will provide the Services as described in Exhibit A in a manner consistent with the LEA's obligations under FERPA, COPPA, and applicable state law.
- Employee Obligations. Company will require Authorized Employees to comply with all applicable provisions of FERPA and this DPA with respect to Student Data.
- No Unauthorized Disclosure. Company will not disclose Student Data to any third party except a Subprocessor bound by obligations at least as protective as this DPA, without the LEA's prior written consent, unless disclosure is required by law (subject to Article III.3(b)).
- Advertising Restrictions. Company affirms the restrictions in Article III.4.
- Data Security. Company will maintain a comprehensive data security program consistent with Exhibit C and industry-standard practices appropriate to the sensitivity of Student Data, including administrative, technical, and physical safeguards.
- Subprocessors. Company will ensure that any Subprocessor with access to Student Data is contractually bound to data protection obligations no less protective of Student Data than those in this DPA, and will maintain the current Subprocessor list referenced in Article II.5.
- No Unauthorized Uses. Company will not use Student Data for AI/machine-learning model training beyond what is necessary to provide the Services to the LEA, and will not permit any third-party AI provider used to deliver AI-assisted features (see Exhibit A) to use Student Data to train that provider's own general-purpose models.
- Return or Deletion. Upon expiration or termination of the Service Agreement, or upon the LEA's written request, Company will, at the LEA's election, delete or provide a mechanism for the LEA to export all Student Data in Company's possession within the timeframe described in Exhibit C, except for data Company is required to retain by law or that has been fully De-Identified.
- Advertising-Free Environment. Company will not permit third-party advertising to be displayed to students within the Services.
Article V: Duties of LEA
- The LEA will provide notice to parents/eligible students of its use of the Services and Company's role as a "school official" with a "legitimate educational interest" under FERPA, as required by the LEA's own policies and applicable law.
- The LEA is responsible for ensuring its own compliance with FERPA, COPPA, and applicable state student data privacy law with respect to its use of the Services, including obtaining any consents required under COPPA for students under 13.
- The LEA will designate an administrator responsible for account provisioning, roster management, and serving as point of contact for data privacy matters under this DPA.
- The LEA will use the Services in a manner consistent with its own data governance policies and applicable law.
Article VI.A: Data Security
Company will implement the data security measures described in Exhibit C, including encryption of Student Data in transit and at rest as described in Exhibit C; access controls limiting Student Data access to Authorized Employees on a need-to-know basis; and periodic security review of its systems.
Article VI.B: Data Breach and Notification
- In the event of a confirmed Security Breach affecting Student Data, Company will notify the LEA without unreasonable delay, and in no event later than the timeframe required by applicable law.
- Company's notification will include, to the extent known at the time: the nature and scope of the breach, the categories and approximate number of students affected, the steps Company has taken or plans to take to mitigate the breach, and a contact for further information.
- Company will cooperate with the LEA's reasonable investigation and, where legally required, its own notification obligations to affected parents/students, regulators, or other authorities. This cooperation does not shift the LEA's own independent legal notification obligations.
- The Parties will cooperate in good faith to determine the content of any notification to parents/students and applicable regulators, provided that nothing in this Section prevents either Party from making any notification independently required by law.
Article VI.C: Data Retention and Deletion
- Company will retain Student Data only for as long as necessary to provide the Services during the term of the Service Agreement, plus a reasonable transition period described in Exhibit C.
- Upon a valid request by the LEA at any time, or automatically upon expiration or termination of the Service Agreement absent a contrary LEA instruction, Company will delete or de-identify Student Data within the period stated in Exhibit C, except data it is required by law to retain (for example, financial/tax records unrelated to individual students) or fully De-Identified Data.
Article VII: General Offer of Privacy Terms
Company may, at its option, extend the terms of this DPA to other LEAs that wish to procure the Services, via the General Offer of Privacy Terms described in Exhibit E. An LEA accepting the General Offer is bound by, and entitled to the protections of, this DPA as if it were an original signatory, without further negotiation of this DPA's terms (though the Service Agreement's commercial terms, including fees, remain subject to that LEA's own Order Form).
Article VIII: Miscellaneous
- Conflicts. In the event of a conflict between this DPA and the Service Agreement regarding the treatment of Student Data, this DPA controls. In the event of a conflict between this DPA and Exhibit C (state-specific terms), Exhibit C controls to the extent required by the applicable state's law.
- Amendment. This DPA may only be amended by written agreement of the Parties, except that Company may update the Subprocessor list referenced in Article II.5 with notice to the LEA as described in the Subprocessor and Security Overview.
- Survival. The obligations in Articles III, IV, VI, and this Article VIII survive termination or expiration of the Service Agreement for as long as Company retains any Student Data.
- Notices. Notices under this DPA must be sent to the contacts identified on the signature page and to Company at education@flashmath.io.
- Governing Law. This DPA is governed by the same law and venue as the Service Agreement, except as superseded by a state-specific requirement in Exhibit C.
Exhibit A: Description of Services
FlashEDU is a K-12 mathematics practice and assessment platform providing:
- Individual student practice sessions with adaptive difficulty.
- Optional real-time practice matches. By default, an LEA-managed student is matched only with other students of the same LEA. An LEA may opt in to a shared pool that matches its students with students of other participating LEAs. Students may also be matched with automated (non-human) opponents when no suitable opponent is available.
- Teacher-facing classroom management: rosters, assignments, progress reports, and printable conference one-pagers.
- Beginning-, middle-, and end-of-year benchmark placement assessments.
- AI-assisted features. "Coach Flash" provides AI-assisted practice coaching to students and is controlled by an LEA-level setting, which is enabled by default and may be turned off by the LEA at any time; turning it off stops Student Data being transmitted to AI providers for that feature. Separate AI-assisted tools support educators and administrators — for example generating practice content, summarizing class or district progress, drafting board and parent reports, mapping an uploaded roster file, and explaining why a student was flagged for attention. Educator-facing tools are controlled separately from the student coach, so disabling Coach Flash does not by itself disable them. Data transmitted to AI providers for these features may include student names or usernames, school and classroom names, teacher names, roster fields supplied by the LEA, and performance summaries — not only individual practice questions and answers.
- Optional virtual currency and cosmetic reward features earned through gameplay. Virtual currency cannot be purchased directly. FlashMath's consumer subscription products, which are sold outside the LEA relationship and are not part of the Services purchased by the LEA, do include virtual currency grants.
Exhibit B: Schedule of Data
Company collects the following categories of Student Data through the Services.
| Category | Examples | Collected From |
|---|---|---|
| Application/Behavioral Metadata | Practice session activity and results, match history, ratings/statistics, progression metrics (XP, levels, achievements), virtual currency/item inventory activity | Generated by student use of the Services |
| Identifiers | First name, last name, or student identifier as provided by the LEA; username; account credentials, including a stored copy of an LEA-managed student's password, protected so that only the student's teacher or an LEA administrator can retrieve it behind that staff member's own PIN, so a forgotten password can be recovered | Provided by LEA/educator |
| External Identifiers | Where the LEA connects a roster or single sign-on integration, the identifier issued by that system; where a user links an optional third-party account, that account identifier | Provided by LEA/educator, or by the user |
| Demographic | Grade level. No date of birth is collected for a teacher-provisioned student account. Where a student self-registers and joins a class by class code, a date of birth and email address are collected for age verification | Provided by LEA/educator, or by the student on self-registration |
| Enrollment | Classroom or group assignment | Provided by LEA/educator |
| Accommodation Indicators | Delivery flags recording how a student takes practice — untimed, read aloud, large text, reduced distractions — as entered by LEA staff to reflect an IEP or 504 plan. No diagnosis, treatment record, or medical history is collected | Provided by LEA/educator |
| Safety and Moderation Records | User-submitted reports, including a snapshot of the reported message, the reporter-supplied description, and moderation notes; account restriction status and the staff-entered reason for it | Generated by user and staff use of the Services |
| AI-Generated Reports | Narrative summaries about a student generated for educators and parents, including attention explanations, classroom digests, weekly parent summaries and board report narratives | Generated by the Services from the categories above |
| Device/Technical | IP address, device type, browser, operating system, log files, timestamps, crash/error diagnostics, in-app usage events | Collected automatically |
| AI-Assisted Feature Inputs | The practice question, the student's submitted answer and any text the student writes to the coach; and, for educator-facing tools, student names or usernames, school and classroom names, teacher names, roster fields supplied by the LEA, and performance summaries. Coach Flash conversations are not retained; usage counts are | Generated by student/educator use of AI-assisted features |
| Voice Feature Data | Student voice features are off by default and operate only where the LEA enables them; the educator voice assistant is available to LEA staff based on staff role. Voice features transmit the audio spoken by the user to the AI provider to be interpreted, and audio generated by the Services is cached for reuse. Session records of duration and how the call ended are retained for 30 days; conversation transcripts are not | Generated by student/educator use of voice features |
Company does not collect, through the Services: Social Security numbers, biometric data, precise geolocation, criminal records, LEA disciplinary records, medical diagnoses, treatment records or health history, or any category of data not listed above. The accommodation indicators described above record only how a student takes practice, and account restriction records reflect conduct within the Services only.
Exhibit C: Data Security Requirements and State-Specific Terms
C.1 Data Security Requirements
- Encryption of Student Data in transit using industry-standard transport security (TLS 1.2 or higher).
- Encryption of Student Data at rest to the AES-256 standard, covering the systems that store Student Data, the credentials and secrets used to access it, and backups.
- Access to Student Data restricted to authorized personnel with a legitimate educational interest, under role-based access controls. On the LEA side, access is scoped by role so that district administrators, school administrators and teachers see only the Student Data within their responsibility. Company personnel access is limited by role and requires multi-factor authentication.
- Administrative actions affecting Student Data are recorded in a protected, tamper-evident audit trail retained for the life of the account, and security and access logs are retained for a period sufficient to support incident investigation.
- Periodic review of security practices; prompt remediation of identified vulnerabilities affecting Student Data.
- Deletion or de-identification of Student Data within 90 days of Service Agreement termination or expiration, or the LEA's written request, whichever is earlier, except data Company is legally required to retain and the audit trail this Agreement is required to keep, in which the student's identifying information is removed rather than the record deleted.
C.2 State-Specific Terms
This section holds the state-specific rider required by the contracting LEA's home state. The New York rider is set out below; a rider for another state is added to the executed copy as that state's law requires.
New York — Education Law § 2-d / Part 121
If the LEA is a New York educational agency, the following additional terms apply, consistent with NY Education Law § 2-d and 8 NYCRR Part 121:
- Company will provide the LEA's designated Data Protection Officer with a completed Parents' Bill of Rights supplemental information addendum, consistent with the LEA's Parents' Bill of Rights for Data Privacy and Security.
- Company will not use Student Data for any purpose other than those explicitly authorized in this DPA.
- Company will notify the LEA of a Security Breach in the most expedient way possible and without unreasonable delay, in accordance with NY Education Law § 2-d(6).
- Company will complete and provide the LEA any additional supplemental information required by the New York State Education Department's model Parents' Bill of Rights, upon request.
- Officers or employees of Company who have access to Student Data will receive training on applicable data privacy and security requirements, at least annually.
Exhibit D: Additional Definitions
- "FERPA" means the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and its implementing regulations at 34 CFR Part 99.
- "COPPA" means the Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506, and its implementing FTC regulations at 16 CFR Part 312.
- "Education Record" has the meaning given in FERPA, 34 CFR § 99.3.
- "School Official" has the meaning given in the LEA's annual FERPA notification of rights, consistent with 34 CFR § 99.31(a)(1).
- "Operator" has the meaning given in applicable state student data privacy statutes modeled on California's SOPIPA (Cal. Bus. & Prof. Code § 22584 et seq.).
Exhibit E: General Offer of Privacy Terms
Company offers the same privacy protections, terms, and conditions described in this DPA to any other LEA that wishes to accept them for its own procurement of the Services (an "Accepting LEA"). The General Offer excludes Exhibit C's state-specific terms, which are governed by the Accepting LEA's own state requirements, and excludes the Service Agreement's commercial terms, which remain subject to a separate Order Form.
To accept the General Offer, an Accepting LEA's authorized representative should request the acceptance form from education@flashmath.io and return it signed. Acceptance binds Company and the Accepting LEA to this DPA as of the date of Company's countersignature, without further negotiation of this DPA's terms.