Samio
← Home
US · FERPA / COPPA

U.S. School Official Agreement

Version 1.1 · Effective September 23, 2026

This is the U.S.-market data agreement for schools whose compliance regime is FERPA. It is the FERPA/COPPA equivalent of the EU Data Processing Agreement (Verwerkersovereenkomst): the Dutch DPA governs EU/EEA/UK schools; this agreement governs United States schools, where Samio Learning acts as a "School Official" under the direct control of the school. Provider: Geekcow Creative Studio, d/b/a Samio Learning · Papaverweg 34, 1032 KJ Amsterdam, Netherlands · Privacy contact: privacy@samiolearning.com · dpo@samiolearning.com.
Legally reviewed and approved for use (Geekcow Creative Studio). Schools whose compliance regime resolves to FERPA acknowledge this agreement in the school dashboard; a signable PDF (with signature block) is available to district signatories on request.

1. Parties

This agreement is between the School / Local Education Agency (the "School") and the Provider, Geekcow Creative Studio, d/b/a Samio Learning (the "Provider"). The School's name, address, and authorized signatory are completed per school on the signable version.

2. Recitals — School Official designation

In providing "Samio Learning" — a multi-subject adaptive learning platform for primary-school children — the Provider acts as a "School Official" with a legitimate educational interest in the School's education records, under the direct control of the School, as permitted by the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g and 34 CFR Part 99, including the school-official exception at 34 CFR § 99.31(a)(1). The Provider performs an institutional service the School would otherwise perform itself, uses education records only for authorized purposes, and is subject to 34 CFR § 99.33(a) governing use and re-disclosure. The School authorizes access under its own authority; it does not collect direct consent from students or parents for the Provider's access.

3. Definitions

"FERPA" — the Family Educational Rights and Privacy Act (34 CFR Part 99). "COPPA" — the Children's Online Privacy Protection Act (15 U.S.C. § 6501–6506) and the FTC COPPA Rule (16 CFR Part 312). "Education Records" — records directly related to a student and maintained by the School or by the Provider on the School's behalf (34 CFR § 99.3). "PII" — personally identifiable information from education records (34 CFR § 99.3). "Directory Information" — information the School designates that would not generally be considered harmful if disclosed (see §8). "De-identified Records" — records from which all PII has been removed (34 CFR § 99.31(b)).

4. Purpose & authorized use

The Provider processes School data solely to deliver the service: (a) delivering adaptive learning activities to students; (b) recording learning results and progress; (c) managing class groups and student assignments; (d) authenticating school staff; and (e) providing technical support. The Provider uses education records only for these purposes and only as directed by the School.

5. No sale of data; no advertising; no unauthorized use

The Provider does not sell student PII. The Provider does not use or disclose student PII for targeted advertising, does not build a profile of a student except in furtherance of the authorized educational purpose, and does not use student PII to develop or improve unrelated products. The Provider does not re-disclose PII except as directed by the School or as permitted by FERPA, and binds any sub-processor to the same restrictions (34 CFR § 99.33).

6. Ownership & control of education records

As between the parties, all education records and student PII remain under the ownership and control of the School. The Provider claims no ownership, maintains records on the School's behalf, and acts only on the School's instructions with respect to their use and maintenance.

7. Data return or destruction

On termination, or at the School's request, the Provider will return or destroy the School's PII, at the School's election. Because a district may be legally required to archive certain education records, the Provider's account-closure process removes personally identifiable information but retains de-identified education records (e.g., exercise results, grades, class structure) so the School can meet archival obligations. Deletion executes after a 30-day grace period (cancellable during that window); the executed mode ("anonymize" for U.S. schools) is recorded for audit. Staff accounts, session tokens, and device/IP records are deleted; students and the school record are de-identified rather than destroyed. The School may export a complete education-records bundle at any time (format FERPA_RECORDS_v1).

8. Directory information

The School may designate certain data elements as Directory Information under FERPA. Where designated, the platform may display class rosters / student profiles to classmates within the School by default (an opt-out model). A parent/eligible student may opt a student out; the Provider honors the opt-out via a per-student setting. Directory information is never displayed across unrelated schools, nor to parties outside the School's authorized users. (Contrast: under GDPR, peer visibility is opt-in and off by default; this opt-out model applies to U.S. schools only.)

9. Parental rights & access

The Provider assists the School in responding to a parent's or eligible student's request to inspect, review, correct, or amend education records, by making the relevant records available to the School. Requests from parents are directed to and handled by the School; the Provider supports the School but does not adjudicate parental requests directly.

10. COPPA — children under 13

The service is directed to primary-school children, including children under 13. For School use, the Provider relies on the School to provide consent on behalf of parents for the collection of students' personal information for a school-authorized educational purpose, consistent with FTC COPPA guidance for the school setting. Students do not have personal accounts, email addresses, or passwords; access is via a class code and selection from a name list. The Provider collects only the data elements in Appendix A.

11. Data security

The Provider maintains administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of student PII (see Appendix B). Safeguards include encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, credential-less student access, audit logging, rate limiting, and least-privilege service credentials.

12. Sub-processors

The Provider uses a limited set of sub-processors for U.S.-school data, each bound by contract to the confidentiality and use restrictions in this agreement: MongoDB Atlas (database hosting), Redis (rate limiting/caching), Backblaze B2 (audio storage, no PII), DeepSeek (AI content, no student PII), Mailjet (staff email), PayPal (billing, not student data), Google reCAPTCHA/OAuth (bot protection / optional SSO), and Microsoft Azure AD (optional SSO). Kennisnet (Entree Federatie) and Edu-V are Dutch-specific and are NOT used for U.S. schools. The current list is published at the sub-processors page; the Provider notifies the School of material changes.

13. Data breach notification

On confirming a security incident involving unauthorized access to or disclosure of student PII, the Provider notifies the School's designated contact without undue delay and within 72 hours of confirmation, including the nature of the incident, the categories of data and individuals affected, likely consequences, and measures taken. The Provider cooperates with the School's own notification obligations under applicable state breach-notification law.

14. Data location

FERPA is geography-agnostic: it does not restrict where data is hosted, provided the data is secure and under the School's direct control. The declared primary region for U.S. schools is the United States (dataResidency = "us"); actual hosting is operationally managed. The Provider does not represent that U.S.-school data is hosted in the EU, and makes no EU-residency commitment for U.S. schools.

15. Term & termination

This agreement takes effect on acknowledgement by the School (recorded in the platform as the School Official Agreement acceptance) and continues while the School uses the service. On termination, §7 (Data return or destruction) applies.

16. State-specific addenda

For public-school sales, the Provider is prepared to execute state-level data-privacy agreements as required, including the National Data Privacy Agreement (NDPA) and New York Education Law § 2-d (and its Parents' Bill of Rights). Where a state addendum conflicts with this agreement, the state addendum controls for that School.

Appendix A — Data elements

- Students — first name, age, class group, grade level, subject stage, exercise results, progress (XP/level/streak), optional avatar description. No SSN, no student email, no student password; access via class code + name selection. - Guardians (optional) — name, email, phone, relationship; only if the School enables parent-share. - Staff (teachers/admins) — name, email, role, password hash. - Billing — school billing contact and address (school-level, not student data). - Technical — IP address, device/browser signals for device approval, rate limiting, bot protection; deleted on closure. The Provider does not process health, biometric, or other special-category data.

Appendix B — Security measures

- Access control — role-based (owner/admin/teacher); scope-based API authorization; JWT with short expiry + refresh-token rotation; credential-less student access; optional device approval. - Passwords — bcrypt (12 rounds) for staff; single-use expiring reset/invite tokens; optional SSO so no password is stored. - In transit / at rest — HTTPS/TLS 1.2+; AES-256 at rest (MongoDB Atlas); Helmet security headers (CSP, HSTS, X-Frame-Options); CORS allow-listing. - Abuse prevention — Redis-backed rate limiting; reCAPTCHA v3 on registration/login. - Data minimization — students have no accounts/email/password; only first name + age stored; secrets never returned in API responses. - Monitoring & audit — audit logging of logins, credential changes, CRUD mutations, deletions, billing events, device approvals; dependency scanning. - Retention — exercise results ~2 years; audit logs 12 months; invoices 7 years (legal); on closure, PII removed and de-identified education records retained. - Incident response — detection → classification (within 4h) → School notification (within 72h) → cooperation → post-incident review.