Data Privacy Agreement (Template)
Provider and security contact
Provider: Salesforce Hub LLC, 225 Arlington Avenue, Clifton, New Jersey 07011. General contact: info@datavot.com.
Security contact. The LEA may contact [name completed at signing], Security Contact, Salesforce Hub LLC, with any security question arising under this Agreement — at info@datavot.com, subject “Security — [School or District Name]”. This is the address to use to report a suspected incident, to ask about the security assessment described in §5, or to request a summary of the breach response plan. DataVot is operated by one person, so the security contact and the incident manager are the same individual; that is disclosed rather than presented as a team.
1Purpose & Scope
The Local Education Agency (“LEA” / “School”) uses the DataVot service — operated by Salesforce Hub LLC (“DataVot,” “Provider,” “we”) — to upload official assessment files (e.g., NJSLA CSVs) and produce dashboards, pivot-table reports, and analyses for authorized staff. This Agreement governs DataVot's handling of Student Data the LEA or its staff provide to, or generate within, the service.
2Definitions
- Student Data — personally identifiable information about a student provided to, or created by, the service (names, state/local IDs, scores, performance levels), including information protected by FERPA and New Jersey law.
- De-Identified Data — data from which identifiers are removed so a student cannot reasonably be re-identified.
- Sub-Processor — a third party engaged by DataVot to process Student Data on its behalf.
3Data Ownership & Control
The LEA — and, as applicable, students and parents — owns and controls all Student Data; DataVot claims no ownership and processes it only on the LEA's documented instructions. Under FERPA, DataVot acts as a “school official” with a legitimate educational interest, under the direct control of the LEA.
4Permitted Use; No Secondary Use
DataVot uses Student Data solely to provide and support the service for the LEA. DataVot will not sell Student Data; use it for targeted advertising or to build advertising/marketing profiles; use it to train advertising or unrelated commercial models; or use it for any other purpose, except as the LEA directs in writing or as required by law. De-Identified Data may be used only to operate, secure, and improve the service, with no attempt to re-identify.
5Security Measures
Technical safeguards.
- Encryption in transit (TLS) and at rest (AES-GCM), with stored rows compressed and encrypted.
- Role-based access — a teacher can be restricted by the LEA to specific schools within the district; where the LEA sets no restriction, the teacher sees the district's data set. District and system roles are separated.
- Dashboards return aggregated counts only — raw student rows never leave the server for dashboards.
- Authentication via signed, http-only session tokens, password hashing (bcrypt), and session invalidation on password change.
- Origin/CSRF protections and a strict Content-Security-Policy.
Administrative safeguards.
- Need-to-know access — only authorized DataVot personnel, bound by written confidentiality obligations, may access Student Data, and only as required to provide the service.
- Audited, consent-based support access — any DataVot support session acting on a school account requires explicit consent, is short-lived, is logged, and is shown to the acting user in a visible banner while active; an email record is generated to the System Admin for every session, and the LEA's own user is emailed directly as well when the school-notification setting is enabled. Passwords are never used or revealed.
- Security practices — personnel follow DataVot's data-handling and security procedures; access is removed promptly when no longer required.
Security framework, assessment and breach response. DataVot implements a cybersecurity framework based on the NIST Cybersecurity Framework, and conducts a security assessment at least annually and following any confirmed Data Breach. On ten days' written notice and execution of a confidentiality agreement, DataVot will provide the LEA with a copy of the assessment report, subject to reasonable redaction. It is a self-assessment; DataVot does not hold a SOC 2 or ISO 27001 certification and says so rather than implying otherwise. DataVot maintains a written data breach response plan and will provide the LEA with a summary of it on reasonable written request. The assessment is reviewed and re-run at least annually and after any confirmed Data Breach. Requests under this paragraph, and any security question, go to the security contact named in the preamble above.
Allocation of security responsibility. DataVot is responsible for the security of the Service and the infrastructure under its control, as described above. The LEA and its authorized users are responsible for safeguarding their account credentials, devices, and email accounts, for the use of strong, unique passwords, and for the timely provisioning and de-provisioning of user access. A security incident attributable to the loss, disclosure, weakness, or compromise of credentials, devices, or accounts under the LEA's control — rather than to a failure of DataVot's safeguards — does not constitute a breach of DataVot's obligations under this Agreement. DataVot will nonetheless cooperate with and assist the LEA in investigating and responding to any such incident.
6Sub-Processors
Each Sub-Processor is bound to data-protection obligations no less protective than this Agreement.
| Sub-Processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, edge compute, encrypted database storage, security and request processing | United States |
| Resend | Transactional email (no student records are sent by email) | United States |
7Data Minimization, Retention & Deletion
DataVot stores only the data the LEA uploads or generates. DataVot retains Student Data for the term of use and deletes or returns it on the LEA's request or within 30 days of termination, except where retention is required by law. On request, DataVot certifies deletion.
8Parent / Eligible-Student Rights
DataVot supports the LEA in fulfilling requests to access, correct, or delete Student Data. Such requests are authorized by the LEA; DataVot acts on the LEA's instruction.
9Data Incident Notification & Costs
DataVot will notify the LEA of any confirmed unauthorized access to or disclosure of Student Data without unreasonable delay and no later than 72 hours after confirmation, including the nature of the incident, the data involved, and remediation steps, and will cooperate with the LEA's notification obligations under New Jersey law and FERPA.
Remediation and monitoring costs. The Service processes state assessment records. The Provider does not collect, process, or store Social Security numbers, driver's license or State identification card numbers, financial account details, or payment credentials — the categories that trigger identity-theft remediation under N.J.S.A. 56:8-161 et seq. Unless otherwise agreed in writing or mandated by applicable law, the LEA shall remain solely responsible for the costs of notifying affected individuals and for any associated third-party identity-theft or credit-monitoring services.
10Compliance & Governing Law
DataVot complies with FERPA and COPPA (DataVot does not collect data directly from students), and its terms align with New Jersey's student data-privacy framework, including:
- SOPPA-NJ (P.L. 2020, c.131 / A4978) — requires a written contract with EdTech vendors and prohibits the sale of student data and targeted advertising. DataVot meets both.
- New Jersey Data Privacy Act (NJDPA), effective 2025 — DataVot supports the district's data-protection assessments and provides the technical detail needed to complete them.
Accounts are for adult educators only. This Agreement is governed by the laws of the State of New Jersey.
11Term, Termination & Survival
This Agreement takes effect on the date signed and remains in effect for as long as DataVot retains Student Data under it. Either party may terminate it by written notice if the underlying service agreement has lapsed or been terminated, and either party may terminate it if the other breaches any of its terms.
Change of control. DataVot will give the LEA written notice of any merger, acquisition, bankruptcy, or other transfer of the business or of Student Data. The LEA may terminate this Agreement if it reasonably believes the successor cannot uphold these terms, or that continuing under the successor would conflict with LEA policy or with state or federal law. Student Data is never treated as an asset transferable apart from this Agreement.
Effect of termination. On termination DataVot deletes or returns Student Data as set out in Section 7. Sections 3, 4, 6, 7, 9 and 10 survive termination as to any Student Data still retained, until that data is deleted or returned.
De-Identified Data. DataVot's permitted use of De-Identified Data under Section 4 survives termination. DataVot will not publish any document naming the LEA without the LEA's written approval of how De-Identified Data is presented, and de-identification follows NIST or U.S. Department of Education guidance.
12General Provisions
Priority of agreements. This Agreement governs the treatment of Student Data. Where it conflicts with DataVot's Terms of Service, Privacy Policy, an order form, a quotation, or any other writing, this Agreement takes precedence as to Student Data. All other provisions of those documents remain in effect.
Notices. Notices under this Agreement are given in writing, by email or first-class mail, to the representatives named in the signature block.
Entire agreement, severability and waiver. This Agreement is the entire agreement between the parties as to Student Data and supersedes prior discussions on that subject. If any provision is held unenforceable, the rest remains in force. A failure to enforce a provision is not a waiver of it. This Agreement binds each party's permitted successors.
13Exhibits & Schedule of Data
When executed on the NDPA form, this Agreement includes the standard exhibits: A — Description of Services; B — Schedule of Data; C — Definitions; D — General Offer of Terms (lets other districts adopt the same terms); and E — State-Specific (New Jersey) Terms.
Where Student Data is stored. Student Data is held only in the service's database, encrypted before it is written. The primary database instance is located in Cloudflare's Eastern North America region, and read replication is not enabled, so no copy of the database exists in any other region. DataVot will notify the LEA and disclose the countries concerned if either of those facts changes. Cloudflare reports placement by region rather than by country; a district requiring country-level assurance should raise it before signing, as it may require a differently provisioned database.
Exhibit B — Schedule of Data. DataVot processes only the fields the district uploads in its official assessment files (e.g., the NJSLA student data CSV). Typically:
| Data element | Collected |
|---|---|
| Student name (first / last) | If present in the district's file |
| State Student ID (SID) / Local ID | If present in the district's file |
| Grade level | Yes |
| Subject, test, administration, year, season | Yes |
| Scale score | Yes |
| Performance level | Yes |
| School / district name | Yes |
DataVot does not collect IP addresses for student profiling, behavioral data, demographics, disciplinary records, or any field outside the district's uploaded file. The exact list is confirmed against your file at signing.
14Signatures
By signing below, the parties agree to this Data Privacy Agreement, executed on DataVot DPA template version 1.1 (27 August 2026), with an effective date of [date].