# DATA PROCESSING ADDENDUM (DPA)

## For the Visual Performance Assessment (VPA™) Tools

---

**DRAFT TEMPLATE — ATTORNEY REVIEW REQUIRED BEFORE USE**

This template is a starting draft for Visual Minds Learning, LLC ("VML"). It must be reviewed, customized, and approved by your legal counsel before it is signed or used with any school, district, or clinical entity.

---

**DPA Date:** [Date]

**School District / Clinical Organization:**
________________________________________________________
Legal Name (the "Institution" or "Controller")
________________________________________________________
Address
________________________________________________________
City, State, ZIP
________________________________________________________
Contact Person / Title
________________________________________________________
Email

**Processor:**
Visual Minds Learning, LLC
[Street Address]
[City, State, ZIP]
United States
contact@visualmindslearning.com

**VML Contact for Data-Protection Questions:**
________________________________________________________
Name / Title
________________________________________________________
Email

---

## 1. Background and Purpose

This Data Processing Addendum ("DPA") supplements the Visual Minds Learning Terms of Service entered into between the Institution and Visual Minds Learning, LLC ("VML"). The purpose of this DPA is to set out the responsibilities of the parties for the protection of student and clinician information processed through the VPA™ tools, including the VPA™ Screener, VPA™ Mini, VPA™ Full, and any related reports, worksheets, or activity recommendations (the "Service").

The Institution uses the Service to support the clinical and educational work of its licensed personnel (e.g., occupational therapists, teachers of students with visual impairments, COVD optometrists, school psychologists, and related professionals). VML hosts the Service and processes information only on the documented instructions of the Institution.

---

## 2. Roles

**2.1 Controller.** The Institution is the data controller of all information it enters into the Service about a student or patient. The Institution decides what information is collected, how it is used, and how long it is kept in connection with the Institution's own evaluation, educational, or clinical records.

**2.2 Processor.** VML is the data processor. VML processes the information only to provide, secure, and improve the Service, and only on the documented instructions of the Institution. VML does not use student- or patient-level information for its own independent purposes or sell it to any third party.

**2.3 Clinician Responsibility.** Each clinician using the Service under the Institution's account must be appropriately licensed, credentialed, or authorized by the Institution to perform the evaluations or screenings in question. The Institution is responsible for ensuring that each clinician has obtained any required consents, authorizations, or parental permissions before entering information into the Service.

---

## 3. Definitions

- **"Student Information"** means any information entered into the Service about a student or patient, including student codes, initials, age, grade, classroom observations, screening scores, VPA™ performance-level ratings, notes, and any generated reports.
- **"Institution Personnel"** means employees, contractors, or agents of the Institution who are authorized to access the Service under the Institution's account.
- **"Service"** means the VPA™ tools, reports, worksheets, and related features provided by VML through visualmindslearning.com.
- **"Subprocessor"** means a third-party service provider that VML uses to host, secure, or support the Service.

---

## 4. Categories of Data Subjects and Data Processed

**4.1 Data Subjects.** The data subjects are students or patients whose information is entered into the Service by Institution Personnel. The Service is intended for professional use by adults and is not directed to children under 13 for independent use.

**4.2 Data Entered.** Institution Personnel are instructed to enter only the minimum information necessary for the VPA™ evaluation. This commonly includes:

- A non-identifying student code or initials (not full name, date of birth, social security number, or medical record number);
- Age, grade, or setting information;
- Observations and scores from the VPA™ tasks;
- Clinician notes related to the VPA™ administration;
- Generated VPA™ reports and recommended activities.

**4.3 Prohibited Data.** The Institution shall not use the Service to enter, store, or transmit full names, dates of birth, addresses, social security numbers, medical record numbers, full diagnostic reports, or any other information that is more identifying than necessary for the clinical or educational purpose. If the Institution operates in a HIPAA-covered setting, it shall not enter Protected Health Information (PHI) into the Service.

---

## 5. Processing Instructions and Use Limitations

**5.1 Documented Instructions.** VML shall process Student Information only:

- To provide the Service to the Institution and its authorized users;
- To secure, maintain, and support the Service;
- To comply with applicable law or the lawful order of a court or governmental authority (in which case VML shall notify the Institution to the extent permitted by law);
- As otherwise agreed in writing by the Institution.

**5.2 No Use for Other Purposes.** VML shall not use Student Information for advertising, profiling, or any other purpose unrelated to providing the Service.

**5.3 No AI Training on Student Data.** VML shall not use Student Information to train, fine-tune, or improve general-purpose artificial-intelligence models. Any use of anonymized or aggregated data for research, norming, or product improvement shall be governed by a separate written research-use agreement or data-use agreement where required by law.

---

## 6. Subprocessors and Third-Party Providers

**6.1 Current Subprocessors.** VML uses the following categories of subprocessors to provide the Service:

- Cloud hosting, database, and authentication infrastructure (Lovable Cloud / Supabase);
- Payment processing (Stripe, Inc.) — only for billing information related to the Institution's account, not for Student Information;
- Analytics providers that receive only aggregate, non-identifiable usage data;
- Email delivery providers for account and support communications.

**6.2 Subprocessor Obligations (Flow-Down).** VML shall enter into written agreements with each subprocessor that processes Student Information. Those agreements shall impose data-protection, security, confidentiality, breach-notification, subprocessor, and audit obligations that are **substantially equivalent to, and no less protective than,** the obligations imposed on VML under this DPA. VML shall remain fully responsible to the Institution for any act or omission of a subprocessor that would constitute a breach of this DPA if performed by VML. On the Institution's written request, VML shall provide a current list of subprocessors that process Student Information and a summary of the material data-protection terms of the applicable subprocessor agreements.

**6.3 Changes to Subprocessors.** VML may update subprocessors from time to time. VML shall notify the Institution of any new subprocessor that will process Student Information and shall provide the Institution a reasonable opportunity (not less than 15 days) to object before the new subprocessor is used for Student Information. If the Institution reasonably objects on data-protection grounds and the parties cannot agree on a resolution, the Institution may terminate this DPA and its use of the Service with respect to the affected processing.

---

## 7. Data Security

**7.1 Security Measures.** VML shall implement and maintain appropriate technical and organizational security measures, including:

- Encryption of data in transit using TLS;
- Encryption of data at rest;
- Access controls limited to authorized VML personnel with a need to know;
- Regular monitoring and logging of access to the Service;
- Secure development and vulnerability-management practices.

**7.2 Institution Security Responsibilities.** The Institution shall:

- Maintain strong passwords and multi-factor authentication for Institution Personnel accounts;
- Restrict access to the Service to authorized personnel;
- Promptly notify VML of any suspected unauthorized access or security incident;
- Ensure that devices used to access the Service are secure and appropriately managed.

---

## 8. Confidentiality

VML shall ensure that any personnel who may access Student Information are bound by confidentiality obligations and process such information only as necessary to provide the Service.

---

## 9. Data Subject Rights and Access

**9.1 Institution Responsibility.** The Institution is responsible for responding to requests from students, parents, or patients to exercise their rights with respect to Student Information, including rights of access, correction, deletion, restriction, or portability under applicable law.

**9.2 VML Assistance.** VML shall provide reasonable assistance to the Institution in responding to such requests, including by providing tools to export, correct, or delete Student Information within the Service.

---

## 10. Data Retention, Return, and Deletion

**10.1 Retention During the Term.** VML shall retain Student Information for as long as the Institution's account is active and the information is needed to provide the Service.

**10.2 Deletion on Request.** The Institution may delete individual student records or reports from the Service at any time. VML shall delete such information from active systems within a commercially reasonable time (target: 30 days), and any residual backup copies shall be overwritten on VML's normal backup rotation.

**10.3 Return or Deletion on Termination.** Upon termination of the Institution's account or this DPA, VML shall, at the Institution's election, (a) return the Institution's Student Information in a commonly available format, or (b) delete the Student Information, except to the extent VML is required by law to retain it.

---

## 11. Data Breach Notification

VML shall notify the Institution without undue delay and in any case **within 72 hours** of becoming aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Student Information. Notification shall include, to the extent then known: the nature of the incident, the categories and approximate volume of Student Information involved, the likely consequences, the measures taken or proposed to address the incident, and a point of contact for further information. VML shall provide reasonable ongoing information to assist the Institution in meeting its own notification obligations under applicable law. VML represents that it maintains an incident-response plan, monitoring, and access logging designed to enable detection and reporting within this window; the Institution acknowledges that the 72-hour clock runs from VML's confirmation of a qualifying incident, not from the underlying event.

---

## 12. Audit and Inspection

**12.1 Audit Rights.** The Institution shall have the right to request information from VML regarding VML's compliance with the obligations in this DPA. VML shall respond to such requests within a reasonable time (target: 30 days) and shall provide, on the Institution's request: (a) a written summary of relevant technical and organizational security measures; (b) the current list of subprocessors that process Student Information; (c) copies of relevant third-party certifications, penetration-test summaries, or SOC-style attestations to the extent VML holds them; and (d) reasonable responses to security questionnaires (including the widely used school-district questionnaires such as the CoSN Trusted Learning Environment questionnaire, the K12SIX security assessment, and the Higher Education Community Vendor Assessment Toolkit / HECVAT-lite).

**12.2 No Physical Audit.** The Institution acknowledges that VML operates through cloud infrastructure providers and does not maintain a physical data center. Accordingly, the Institution's audit rights shall be limited to reasonable documentation, questionnaires, and, where mutually agreed in writing, remote review sessions. The Institution's audit rights shall not include on-site inspections of VML's hosting providers' facilities. The Institution shall determine, in its own risk-assessment process, whether these documentation-based audit rights satisfy its internal and regulatory requirements before signing this DPA.

---

## 13. FERPA, HIPAA, and COPPA

**13.1 FERPA — School Official Designation.** Where the Institution is a school or school district subject to the Family Educational Rights and Privacy Act (FERPA), VML shall be considered a "school official" with a legitimate educational interest only to the extent the Institution has direct control over VML's use of the information and this DPA serves as the required written agreement. VML shall process education records only for the purposes described in this DPA and shall not re-disclose education records except as permitted by FERPA or this DPA.

**13.2 HIPAA.** VML is not a HIPAA-covered entity and does not offer the Service under a Business Associate Agreement. If the Institution is a HIPAA-covered entity, the Institution shall not enter PHI into the Service. VML's obligations under this DPA are not intended to satisfy HIPAA requirements.

**13.3 COPPA.** The Service is not directed to children under 13 for independent use, and VML does not knowingly collect personal information directly from children. The Institution shall ensure that any information about a child entered by Institution Personnel is done in compliance with applicable parental consent and child-privacy requirements.

---

## 14. Consent and Authorization

The Institution represents that it has obtained, or will obtain, all consents, authorizations, and permissions required by applicable law, professional standards, and the Institution's own policies before Institution Personnel enter Student Information into the Service. This includes, where applicable, written parental consent under the Individuals with Disabilities Education Act (IDEA) or Section 504 before a formal evaluation that incorporates the VPA™.

---

## 15. Term and Termination

**15.1 Term.** This DPA begins on the date entered above and continues as long as the Institution uses the Service.

**15.2 Survival.** The obligations in Sections 7 (Security), 8 (Confidentiality), 10 (Retention and Deletion), 11 (Breach Notification), 12 (Audit), 13 (FERPA/HIPAA/COPPA), 16 (Limitation of Liability), and 17 (Governing Law) shall survive termination of this DPA.

**15.3 Termination for Material Breach.** Either party may terminate this DPA upon written notice if the other party materially breaches its data-protection obligations and fails to cure the breach within 30 days of written notice.

---

## 16. Limitation of Liability

The Institution acknowledges that VML's aggregate liability for claims arising out of or relating to this DPA is subject to the limitation-of-liability provisions in the Terms of Service, which cap VML's aggregate liability at the fees paid by, or on behalf of, the Institution to VML in the twelve (12) months preceding the event giving rise to the claim. The Institution has evaluated that cap against its own risk profile and confirms that it is acceptable in light of the categories of Student Information processed under this DPA (non-identifying student codes/initials, age, and clinical observations — no full PHI or direct identifiers). Nothing in this DPA limits liability that cannot be limited under applicable law (such as for fraud, willful misconduct, or personal injury caused by negligence).

---

## 17. Governing Law

This DPA shall be governed by the laws of the **State of Mississippi**, USA, without regard to conflict-of-laws rules, and any dispute shall be resolved exclusively in the state or federal courts located in Mississippi.

**Public-entity carve-out.** Where the Institution is a U.S. public school district, state agency, or other governmental entity that is prohibited by applicable state law from agreeing to a foreign choice of law, venue, or indemnification, then, to the extent so prohibited: (a) the laws of the Institution's home state shall govern this DPA, (b) any dispute shall be resolved in the courts of competent jurisdiction in the Institution's home state, and (c) any indemnification obligation of the Institution shall be limited to the maximum extent permitted by that state's law.

---

## 18. Entire Agreement and Amendment

This DPA, together with the Terms of Service and Privacy Notice, constitutes the entire agreement of the parties regarding the processing of Student Information. This DPA may be amended only by a written instrument signed by both parties.

---

**IN WITNESS WHEREOF**, the parties have executed this Data Processing Addendum as of the date first written above.

**Institution (Controller):**

________________________________________
Printed Name

________________________________________
Title

________________________________________
Signature

________________________________________
Date

**Visual Minds Learning, LLC (Processor):**

________________________________________
Printed Name

________________________________________
Title

________________________________________
Signature

________________________________________
Date

---

**Exhibit A — Permitted VPA™ Use and Data-Minimization Checklist**

Before each VPA™ session, the administering clinician confirms:

- [ ] The required consent, authorization, or parental permission is in place.
- [ ] Only a non-identifying student code or initials will be used in the Service.
- [ ] No full names, dates of birth, addresses, social security numbers, or medical record numbers will be entered.
- [ ] The evaluation is within the clinician's scope of practice and the Institution's authorization.
- [ ] The generated report will be handled in accordance with the Institution's own records and privacy policies.
