1. Application and roles
This Education Data Addendum applies when a school, district, higher-education institution, training provider, or other authorized organization ("Institution") uses Phasoric to process covered learner, educator, roster, course, assignment, or education evidence data ("Education Data"). It supplements the Terms, Privacy Policy, and DPA. The Institution determines the educational purpose, people, authority, legal basis, access, and retention; Phasoric processes Education Data only to provide the Institution-authorized service.
2. Authorized use
Phasoric will use Education Data only to deliver, secure, support, and improve the Institution-authorized features; comply with lawful instructions; and meet legal obligations. Phasoric will not sell Education Data, use it for personalized advertising, create an advertising profile, or use private Education Data to train a general-purpose model.
The Institution will provide required notices and permissions, configure lawful identity and roster sources, limit data to what is necessary, assign appropriate roles, and ensure that educators and other authorized people review consequential output.
3. Learner safeguards and human review
Education workflows should prefer institution identifiers or pseudonymous learner references over unnecessary direct identifiers. Phasoric intelligence must not infer or expose sensitive learner attributes beyond authorized evidence. Generated grades, grouping, intervention, placement, discipline, accessibility, or similar recommendations are drafts for an authorized educator; they must not become a final decision solely through automation.
Phasoric does not invite a learner who cannot form a direct contract to self-register for an independent hosted account. Learner access, where offered, must be provisioned or authorized by the Institution under its policies and applicable law.
4. Access, disclosure, and service providers
Access is limited by Institution-managed roles, workspace authorization, and feature scope. Phasoric discloses Education Data only to authorized users, providers needed to operate the selected service, or as required by law. The DPA and confidential provider schedule govern subprocessors. A user-directed Google, Microsoft, Dropbox, or GitHub connection is enabled only under Institution authorization.
5. Retention, access requests, and deletion
The Institution controls retention during the service, subject to product capabilities and law. Phasoric will support export, correction, access, and deletion requests through the Institution and will not knowingly respond to a learner or guardian in a way that bypasses the Institution's lawful process. On termination or instruction, Education Data is returned or deleted under the DPA and Privacy Policy; the Institution remains responsible for local devices, connected providers, and independently retained copies.
6. Security and incidents
The Security Policy and DPA safeguards apply to Education Data. Phasoric will notify the Institution without undue delay after confirming a personal-data breach affecting its Education Data and will provide available facts needed for the Institution's response. The Institution must promptly report suspected compromise, remove departed users, and keep its identity and integration configuration current.
7. Conflicts and requests
A signed Institution agreement or education-data schedule controls where it provides additional or different protections. Nothing in this public addendum certifies compliance with a particular institution's obligations or replaces its legal review. Contact privacy@phasoric.com for an education privacy review or signed terms.
