CEAIH Trust Center
Data Processing Terms
This public summary explains CEAIH's approach when processing personal information for schools, governments, districts, and other organizations.
1. Roles
The customer generally determines the purposes and authorized use of organization-controlled personal information. CEAIH generally processes that information to provide the contracted services. The exact legal roles depend on applicable law and the agreement.
2. Processing instructions
CEAIH will process customer data according to the agreement, documented customer instructions, platform configuration, and applicable law. CEAIH may also process limited information for security, billing, legal compliance, and service administration where permitted.
3. Types of data and people
- Students, parents, guardians, educators, administrators, government users, curriculum professionals, and organization contacts.
- Identity, contact, enrollment, educational, assessment, attendance, communication, support, usage, security, and billing data.
- Uploaded content, generated resources, meeting information, provider configuration, and audit history.
4. Confidentiality and personnel
CEAIH will limit access to personnel and service providers who need information for authorized duties and who are subject to appropriate confidentiality obligations.
5. Security measures
- Role-based authorization and least-privilege access.
- Encryption of sensitive provider credentials and protected transmission.
- Authentication, verification, session, and security controls.
- Logging, monitoring, diagnostics, and audit records.
- Backup, recovery, vulnerability, and incident-response processes appropriate to service maturity and risk.
- Separation of organization data through ownership and authorization controls.
6. Subprocessors
CEAIH may use subprocessors for cloud hosting, databases, storage, AI, communications, identity, payments, monitoring, support, and related infrastructure. CEAIH will impose appropriate data-protection obligations and remain responsible as required by the agreement and law.
7. International transfers
Where personal information is transferred across borders, CEAIH will use an appropriate lawful mechanism and safeguards required for the relevant jurisdiction and contract.
8. Assistance with rights and compliance
Taking account of the nature of processing and available information, CEAIH will reasonably assist customers with verified privacy requests, security obligations, impact assessments, regulatory inquiries, and breach response as required by the applicable agreement.
9. Security incidents
CEAIH will maintain an incident-response process and notify affected institutional customers of a confirmed personal-data breach according to applicable contractual and legal timelines.
10. Return and deletion
At the end of services, CEAIH will return or delete customer data as provided by the agreement, subject to lawful retention, security, backup, dispute, and recordkeeping requirements.
11. Audit and assurance
CEAIH may provide reasonable security and compliance information under confidentiality protections. Audit rights, frequency, scope, cost, and safeguards should be defined in the signed agreement.