Data processing framework

The schedule behind the privacy promise.

This published framework describes NexioraAI’s intended processor commitments. It becomes binding only when the school-specific schedules and legal terms are completed and signed.

Last updated · July 13, 2026

01

Roles and instructions

The school acts as Controller and NexioraAI as Processor for school personal data. Processing is limited to documented instructions needed to authenticate users, operate the selected modules, provide support, protect the service, and meet agreed legal obligations.

02

People and data

Data subjects may include students, guardians, teachers, administrators, and staff. Data may include identity, membership, academic records, assessment content and results, learning materials, activity, support, audit, and limited device or network data.

03

Security commitments

Controls include role-aware access, tenant separation, configured encryption, audit evidence, secure-development gates, backup and recovery procedures, incident response, personnel confidentiality, and vendor review proportionate to risk.

04

Requests, incidents, and deletion

NexioraAI assists with lawful access, correction, export, restriction, and deletion requests. Suspected personal-data breaches are reported without undue delay within the executed contractual window. On termination, data is returned or deleted under the agreed schedule, legal holds, and backup expiry.

05

Subprocessors and transfers

The executed schedule names cloud, database, identity, AI, email, and monitoring providers actually used, including purpose, region, safeguards, and change notice. Cross-border transfers require an approved mechanism.

06

Evidence and execution

Schools can request security evidence under confidentiality. Legal entity, hosting region, retention, subprocessors, governing law, liability, and notification window must be completed before signature.

Complete the school-specific DPA schedule.

The public framework is not executable. School legal and privacy teams must complete the legal entity, region, retention, subprocessor, transfer, incident, deletion, liability, and governing-law fields.

Request the school-specific schedule