Contracting
Data Processing Agreement and FERPA Addendum
This is the data processing agreement we offer to every institution, published in full and pre-agreed. There is nothing to negotiate unless you want to change something, and nothing here is contingent on paying us, because there is nothing to pay.
It is written to be signed as-is. If your counsel needs redlines, send them; we would rather amend this public version so the next institution inherits the improvement.
To execute: print this page, or email [email protected] and we will return a signature-ready PDF or execute through your own paper.
---
# Data Processing Agreement and FERPA Addendum
Processor: Champlin Enterprises, LLC, an Illinois limited liability company ("Processor", "we") Controller: the institution identified in the signature block ("Institution", "you") Service: the Career Readiness Report platform at careerreadinessreport.com Effective: on execution, or on the Institution's first upload of Personal Data, whichever is earlier
This Agreement supplements the Terms of Service and Privacy Policy. Where this Agreement conflicts with either, this Agreement controls as to the processing of Personal Data.
1. Definitions
Personal Data means information relating to an identified or identifiable person that the Institution or its students, raters or staff submit to the Service.
Education Records has the meaning given in FERPA, 20 U.S.C. § 1232g and 34 CFR Part 99.
Processing, Controller, Processor, Data Subject and Personal Data Breach have the meanings given in the GDPR.
Sub-processor means a third party engaged by the Processor to process Personal Data.
2. Roles and scope
The Institution is the Controller. The Processor is a Processor and, under California law, a service provider. The Institution determines the purposes and means of processing; the Processor acts only on the Institution's documented instructions.
The subject matter is the provision of the Service. The duration is the term of the Institution's account plus the deletion periods in Section 10. The nature and purpose is the collection, storage, analysis and reporting of career readiness competency assessments. The categories of Data Subject are students, institutional staff, and external raters such as internship supervisors, employers, mentors and faculty. The categories of Personal Data are those set out in the Privacy Policy.
3. Processor obligations
The Processor shall:
- Process Personal Data only on the Institution's documented instructions, including
as to international transfers, unless required otherwise by law, in which case the Processor will inform the Institution before processing unless legally prohibited.
- Ensure that personnel authorized to process Personal Data are bound by an obligation
of confidentiality.
- Implement the technical and organizational measures described in Section 6 and at
- Respect the conditions in Section 7 for engaging Sub-processors.
- Taking into account the nature of processing, assist the Institution by appropriate
measures in responding to Data Subject requests.
- Assist the Institution in ensuring compliance with its obligations regarding security,
breach notification, data protection impact assessments and prior consultation.
- At the Institution's election, delete or return all Personal Data at the end of the
engagement, per Section 10.
- Make available to the Institution the information reasonably necessary to demonstrate
compliance with this Agreement.
The Processor shall not sell Personal Data, share it for cross-context behavioral advertising, retain, use or disclose it for any purpose other than performing the Service, retain or use it outside the direct business relationship, or combine it with personal information from another source except as necessary to perform the Service.
4. FERPA school official addendum
The Processor acknowledges that Personal Data may include Education Records and that the Institution discloses them under the school official exception, 34 CFR § 99.31(a)(1)(i)(B). The Processor accepts designation as a school official with a legitimate educational interest and, as a condition of that designation, agrees that it:
- Performs an institutional service or function for which the Institution would
otherwise use its own employees.
- Is under the direct control of the Institution with respect to the use and
maintenance of Education Records.
- Uses Education Records only for the purpose of providing the Service, and for no
other purpose, expressly including no marketing, no advertising, no profiling, and no product development on identifiable data.
- Does not redisclose personally identifiable information from Education Records to
any third party except as the Institution directs in writing, as permitted by 34 CFR § 99.33(b), or as required by law. Where disclosure is legally compelled, the Processor will notify the Institution before disclosing unless legally prohibited from doing so.
- Maintains a record of disclosures as required by 34 CFR § 99.32 and makes it
available to the Institution.
- Will cooperate with the Institution in permitting a parent or eligible student to
inspect and review, and to seek correction of, Education Records held by the Processor, with such requests handled through the Institution.
- Understands that the Institution must include the Processor's designation in its
annual FERPA notification, and that the Institution determines whether that designation is consistent with its notification.
- Will, on termination, delete or return Education Records per Section 10 and retain
no copy except as required by law.
The Processor further agrees that the misuse or unauthorized redisclosure of Education Records may result in the Institution being barred from access under 34 CFR § 99.33(e), and accepts responsibility for its own compliance accordingly.
5. Student privacy commitments
Independent of any statute, the Processor commits that it will not: sell student data; use student data for targeted advertising; create a profile of a student for any purpose other than the Institution's use of the Service; use student data to train third-party AI models; or make a material change to these commitments retroactively as to data already collected.
Where the Service generates AI-assisted narrative content, the Processor's agreement with its model provider prohibits training on content submitted through the API, the output is labeled as AI-generated, and the Institution may disable the feature entirely.
6. Security measures
The Processor implements: encryption in transit (TLS 1.2 minimum) and at rest, with additional application-layer encryption of sensitive fields; multi-tenant isolation enforced in the data-access layer and covered by automated tests; role-based access control with optional SAML 2.0 or OpenID Connect single sign-on that the Institution may set as required; least-privilege, individually attributed, multi-factor-authenticated administrative access; append-only audit logging of authentication, export, administrative action and record modification, readable by the Institution for its own records; encrypted backups with restore access held to the same least-privilege set; and risk-ranked patching of components.
Current measures and their limitations, including the absence of a SOC 2 report, ISO 27001 certification, completed third-party penetration test and cyber liability insurance, are published at /security and /trust/hecvat. The Processor will not represent to the Institution that it holds a certification it does not hold.
7. Sub-processors
The Institution provides general authorization for the Sub-processors listed at /security, currently Liquid Web (hosting), Cloudflare (DNS, TLS, DDoS protection), Mailgun operated by Sinch (email) and Anthropic (AI narrative generation).
The Processor will give the Institution notice before adding or replacing a Sub-processor that processes Personal Data, and the Institution may object on reasonable data-protection grounds. If the objection cannot be resolved, the Institution may terminate and export its data without penalty.
The Processor imposes on each Sub-processor data protection obligations no less protective than those in this Agreement and remains fully liable to the Institution for a Sub-processor's performance.
8. Personal Data Breach
The Processor will notify the Institution's designated administrators without undue delay, and in any event within seventy-two (72) hours, of confirming a Personal Data Breach affecting the Institution's Personal Data. The notice will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a point of contact.
The Processor will provide the information the Institution reasonably needs to meet its own notification obligations to Data Subjects, regulators, or under state breach notification law. Notification to students, regulators or the public is the Institution's decision, because the Institution is the Controller.
9. Audit and information rights
The Processor will respond to reasonable security questionnaires and will make available the information necessary to demonstrate compliance, including a review call with the Institution's information security staff.
The Institution may audit the Processor's compliance no more than once per year, on thirty days' notice, during business hours, in a manner that does not compromise other institutions' data, at the Institution's expense, and subject to confidentiality. A regulator's audit right is not limited by this Section.
10. Return and deletion
The Institution may export all of its data at any time in open formats, delete an individual student's records at any time, and delete its account and all associated records at any time.
On termination, at the Institution's election, the Processor will return or delete all Personal Data. Deletion from live systems occurs promptly and from encrypted backups within the normal backup rotation. Anonymized aggregate statistics that can no longer be linked to any individual or institution may be retained. Export access remains available for at least thirty days after termination, and for the full ninety-day notice period if the Processor discontinues the Service.
11. International transfers
All processing occurs in the United States. Where the Institution enrolls Data Subjects in the European Economic Area, the United Kingdom or Switzerland, the parties incorporate the European Commission's Standard Contractual Clauses, Module Two (Controller to Processor), Implementing Decision (EU) 2021/914, together with the UK International Data Transfer Addendum where applicable. Annex I is populated by Section 2 of this Agreement, Annex II by Section 6, and Annex III by Section 7. On request, the Processor will execute the SCCs as a standalone document.
12. Liability and public institutions
Liability under this Agreement is subject to the limits in the Terms of Service, except that nothing limits liability that cannot be limited by law.
Section 9 of the Terms of Service applies to this Agreement in full. If the Institution is a public institution or an agency or instrumentality of a state: there is no indemnification obligation on the Institution; governing law and venue are the Institution's; no sovereign or governmental immunity is waived; no arbitration or class-action waiver applies; changes require affirmative acceptance; and the Institution's public records law prevails.
13. Term and general
This Agreement remains in effect while the Processor processes Personal Data for the Institution. Sections 4, 5, 8, 10 and 12 survive termination.
If a provision is unenforceable, the remainder stands. This Agreement may be executed in counterparts, including electronically.
---
Execution
Institution
| Field | Entry |
|---|---|
| Institution name | |
| Signature | |
| Printed name | |
| Title | |
| Date | |
| Administrator contact for breach notice |
Processor
| Field | Entry |
|---|---|
| Entity | Champlin Enterprises, LLC |
| By | Kevin Champlin |
| Title | Principal |
| Date | On countersignature |
| Contact for notices | [email protected] |
---
Published version 1.0, effective July 27, 2026. We version this document publicly. If we amend it, the prior version stays available and your executed copy governs your institution until you accept a change.