StackMentor
How it worksWhy StackMentor?PricingUpcomingFAQ
Back to Front Page

School Data Processing Addendum

Privacy PolicyTerms of ServiceRefundsSupportSecuritySubprocessorsSchool DPACustom Program PlanStudent Privacy

Version: July 30, 2026

This School Data Processing Addendum is intended to be attached to a signed school, bootcamp, or other institution agreement. It is not a completed contract until the institution and Julius Cherubini agree to the applicable Custom Program Plan Order or service agreement. The discussion fields are listed in the Custom Program Plan Order template.

1. Roles and instructions

The institution is the controller of institution-provided roster, course, assignment, material, student, and learning-service data. Julius Cherubini, operating StackMentor, is the processor. The processor processes that data only to provide the service, follow documented institution instructions, maintain security, provide support, prevent abuse, and comply with law.

Julius Cherubini remains an independent controller for direct account, billing, payment, security, support, and legal records needed to operate the service.

2. Order-specific schedule and precedence

The signed Custom Program Plan Order should identify the institution, service start and end dates, included schools or courses, seat entitlement, and any institution-specific processing instructions. Processing begins when the service term begins and continues until the service term ends, subject to agreed deletion and legal-retention periods.

The Custom Program Plan Order controls custom pricing, duration, payment, renewal, seat, support, and other commercial terms. This Addendum controls the processing of institution personal data. If the documents conflict on data protection, this Addendum controls.

A custom order does not authorize special-category data, children under 13, new integrations, or a new subprocessor unless the parties expressly agree to the necessary legal, product, and security changes in writing.

3. Processing details

The service may process student and staff names, email addresses, roles, course membership, assignments, course materials, code, messages, mentor responses, usage, technical context, and support records. It does not intentionally require special-category data. Institutions must not upload unnecessary health, disciplinary, financial, or other sensitive records.

Processing lasts from the service start date through the end of the Custom Program Plan Order and any agreed deletion or legal-retention period after termination.

4. Confidentiality and security

Persons authorised to process institution data must be subject to confidentiality duties. The processor will maintain access controls, role checks, protected credentials, secure session handling, provider safeguards, operational retention limits, and incident procedures appropriate to the service risk.

5. Subprocessors

The institution authorises the providers listed on the Subprocessor List. The processor will require subprocessors to protect institution data and will provide notice of material changes. The institution may object to a material change on reasonable data-protection grounds.

6. Assistance and incidents

The processor will reasonably assist the institution with access, correction, deletion, restriction, security, breach assessment, and data-protection-impact-assessment requests. Suspected institution-data incidents should be reported to support@stackmentor.dev. The processor will notify the institution without undue delay and target notification within 24 hours after confirming a likely incident.

7. Return and deletion

At the institution's request after termination, the processor will delete or return institution data, unless law requires retention. Backups and provider copies may remain temporarily under their normal backup or legal-retention process and will not be used for a new purpose.

8. International transfers

The institution acknowledges that Supabase production storage is in Ireland and that other provider or model-provider regions may vary. Where required, the parties will use an adequacy decision, standard contractual clauses, or another lawful transfer safeguard.

9. Evidence and audits

The processor will make available reasonable information needed to demonstrate compliance and will cooperate with proportionate audits, subject to confidentiality, security, and protection of other customers.