Architecture of Grace · Data Privacy Agreement
A student data privacy agreement in the shape Illinois districts use under the Student Online Personal Protection Act (105 ILCS 85). Ready to execute as written; your counsel may adapt it.
This Data Privacy Agreement ("Agreement") is entered into between:
The District: ("District"), an Illinois public school district or school, with its designated contact for this Agreement: , (name, email);
and the Operator: Architecture of Grace, James Anthony Ramsden, sole proprietor ("Operator"), operator of the website architectureofgrace.org and its associated learning materials and tools.
Effective date of this Agreement: .
In Local-Only Mode, no Covered Information is transmitted to anyone, including the Operator. In Sync Mode, the following categories — and no others — are transmitted, from the student's device directly to the District Sheet:
| Element | Description |
|---|---|
| Student code | A short code assigned by the District and typed by the student; not the student's name. Pseudonymous; re-identifiable only via the District's own roster mapping. |
| Grade | Grade level. |
| Class label | A class or group label chosen by the teacher. |
| Seasonal window | The administration window (e.g., fall, winter, spring). |
| Item responses | The student's structured responses to instrument items. |
| Domain scores | Domain scores computed on the device. |
| Timestamp | Row arrival time, added by the District's own script. |
The Service transmits no student names, free-text writing, journal entries, contact information, photographs, audio, location data, or persistent tracking identifiers in any mode. In all modes and at all times, the Operator receives no Covered Information whatsoever.
Covered Information is collected and used solely for K–12 school purposes: administering the District's chosen instruments, reporting results to the District's authorized staff, and informing instruction and student support. The Operator makes no use of Covered Information for any purpose, having none.
The Operator shall not, and the Service is designed so that the Operator cannot:
None. The Operator engages no subprocessors and shares Covered Information with no third parties, having no Covered Information to share. Google LLC acts as the District's own service provider under the District's existing Google Workspace agreement, not as a subprocessor of the Operator.
The Operator holds no Covered Information, so a breach of Covered Information at the Operator is not structurally possible. However, if the Operator becomes aware of a security flaw in the published Service or sync code that could result in unauthorized acquisition of Covered Information from a District Sheet, the Operator shall notify the District's designated contact (Section 1) within 72 hours of determining the flaw exists, describing the nature of the flaw, the categories of information potentially affected, and the corrective measures taken or recommended. Breaches arising within the District's own Google Workspace (e.g., compromised District credentials or Sheet sharing) are governed by the District's own incident procedures and its agreement with Google; the Operator shall reasonably cooperate with any District investigation on request.
All Covered Information resides in the District Sheet and on District-used devices, both under the District's direct control. The District may delete any or all of it at any time without the Operator's involvement or permission. Upon any request for deletion directed to the Operator, or upon termination of this Agreement, the Operator shall confirm in writing that it holds no Covered Information — which shall constitute full compliance, there being nothing further to delete. The Operator's published documentation describes the deletion procedures the District performs in its own systems.
The Operator shall not use de-identified or aggregated Covered Information for commercial purposes, including product marketing or sale to third parties. (The Operator receives neither identified nor de-identified student data; this section forecloses the possibility as a matter of commitment, not only of architecture.)
This Agreement takes effect on the date in Section 1 and continues until terminated by either party on thirty (30) days' written notice, or immediately by the District at any time. Because the District holds all data and all keys, termination requires no data return or destruction by the Operator; the District may disable Sync Mode at any moment by rotating or removing its own keys or undeploying its own script. Sections 5, 8, and 10 survive termination.
This Agreement is governed by Illinois law. It constitutes the parties' entire agreement concerning student data privacy for the Service and controls over any conflicting term in the Operator's general Terms of Use. Amendments must be in writing and signed by both parties. If any provision is unenforceable, the remainder stands.