Data Processing Agreement
For University Partnerships
Template Version: May 11, 2026
URL: www.keivos.com/dpa
1. Parties
This Data Processing Agreement ("DPA") is entered into between:
Data Controller: [UNIVERSITY NAME] ("University" or "Institution")
Data Processor: Keivos LLC, a Utah limited liability company with its principal place of business at 336 East University Pkwy #1095, Orem, Utah 84058 ("Keivos" or "Processor")
This DPA supplements and is incorporated into the service agreement between the parties and governs the processing of student education records and personally identifiable information ("Student Data") under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g, and applicable state student privacy laws.
2. Definitions
"Education Records" means records directly related to a student that are maintained by the Institution or by a party acting for the Institution, as defined under FERPA.
"Personally Identifiable Information" or "PII" means information that can be used to identify a student, including but not limited to name, email address, academic data, and student identification numbers.
"Student Data" means Education Records and PII of students enrolled at the Institution who use the Keivos platform.
"School Official" means a party to whom the Institution has determined has a legitimate educational interest in accessing Student Data, as provided under FERPA's school official exception (34 CFR § 99.31(a)(1)).
"Sub-Processor" means a third-party service provider engaged by Keivos to process Student Data in connection with the Services. The current Sub-Processor list is published at www.keivos.com/subprocessors.
3. School Official Designation
The Institution designates Keivos as a "School Official" with "legitimate educational interest" under FERPA for the purpose of providing the educational technology services described herein. This designation permits Keivos to access Student Data without additional student consent under the FERPA school official exception, provided that Keivos: (a) performs institutional services or functions that the Institution would otherwise perform itself; (b) is under the direct control of the Institution with respect to the use and maintenance of Student Data; and (c) complies with all conditions of use as set forth in this DPA.
4. Purpose and Scope of Data Processing
Keivos will process Student Data solely for the following educational purposes:
- Enabling students to track pre-medical academic progress, extracurricular activities, and medical school applications
- Providing university pre-health advisors with student progress data for personalized academic guidance
- Generating aggregate, anonymized analytics to support university advising programs
- Facilitating secure communication between students and their university advisors
- Calculating academic readiness metrics (King Score) to support student self-assessment
- Providing an optional in-app AI chat assistant for student questions (see Section 9 for Sub-Processor details)
Keivos shall NOT use Student Data for any purpose other than those specified above, including but not limited to: advertising, marketing, creating commercial profiles, selling or renting data, or training artificial intelligence models.
5. Categories of Data Processed
| Data Category | Specific Elements | Purpose |
|---|---|---|
| Identity | Name, email address | Account management, advisor communication |
| Academic | GPA, MCAT score, King Score, graduation year | Academic tracking and advising |
| Activities | Category, hours, descriptions, supervisor info | Extracurricular tracking |
| Applications | School list, application status, interviews, outcomes | Application cycle management |
| Communications | Messages between students and advisors | Academic guidance |
| Consent | Consent status, timestamps, version | FERPA compliance |
6. Data Security Measures
Keivos implements and maintains the following security measures:
- AES-256 encryption for messages and sensitive data fields at rest
- TLS 1.2+ encryption for all data in transit
- Encrypted API payloads for all cross-system data transfers
- API key authentication for all programmatic access
- Row-Level Security (RLS) policies on every database table containing Student Data, enforcing per-record authorization at the database layer
- Role-based access controls ensuring advisors access only their university's students
- Comprehensive audit logging of all access to Student Data, retained for seven (7) years
- Secure secrets management for all credentials and encryption keys
- Primary backend infrastructure (Supabase) is SOC 2 Type 2 and ISO/IEC 27001:2022 certified and HIPAA-eligible; web application hosting (Base44) is SOC 2 Type II and ISO 27001 certified
- Regular security assessments and vulnerability remediation
7. Access Controls and Data Isolation
Student Data from the Institution is logically isolated from data of other institutions through Row-Level Security policies on every relevant database table, in addition to application-layer access controls. Advisors registered under the Institution's account may only access Student Data for students who have: (a) selected the Institution as their university; and (b) provided explicit data sharing consent. Keivos administrative staff access Student Data only for system maintenance, security monitoring, and customer support, and such access is logged in the audit trail.
8. Data Breach Notification
In the event of a confirmed data breach involving Student Data, Keivos will: (a) notify the Institution within 72 hours of confirmation; (b) provide a written incident report detailing the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken to address and mitigate the breach; (c) cooperate with the Institution's investigation and remediation efforts; and (d) assist the Institution in meeting its notification obligations to affected students and regulatory authorities. Keivos maintains a written Breach Notification Plan that defines severity classifications, response timelines, and assigned responsibilities, and conducts an annual tabletop exercise to validate the plan.
9. Sub-Processors
Keivos engages the following sub-processors that may have access to Student Data:
- Supabase, Inc. — primary backend (PostgreSQL database, authentication, file storage, Edge Functions). United States. SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA-eligible.
- Base44, Inc. — web application hosting for the Keivos Hub, Advisor Dashboard, Student Web app, and public website. United States. SOC 2 Type II, ISO 27001.
- Resend, Inc. — transactional email delivery (account, trial, license, and notification emails). United States. SOC 2 Type 2.
- Apple Inc. — iOS app distribution and in-app purchase processing. Apple does not receive academic Student Data; it receives only Apple ID and purchase transaction data.
- Google LLC (Firebase Cloud Messaging) — Android push notification delivery (device tokens and notification content). United States. SOC 2, ISO 27001, ISO 27017, ISO 27018.
- Anthropic, PBC — AI inference for the optional in-app chat assistant ("Ask Keivos"). Student queries and limited context are transmitted only when the student uses this feature. Per Anthropic's Commercial Terms, data is not used to train models. United States. SOC 2 Type 2.
- Stripe, Inc. — web and Android payment processing. Stripe does not receive academic Student Data; it receives only payment transaction data. United States. PCI DSS Level 1.
Keivos will notify the Institution at least 30 days prior to engaging any new sub-processor that will have access to Student Data, by updating www.keivos.com/subprocessors and by emailing the Institution's designated contact. The Institution may object to such engagement within 15 days. All sub-processors are bound by data processing obligations no less protective than those in this DPA.
10. Data Retention and Deletion
Student Data is retained for seven (7) years following the student's last activity on the platform. Messages are retained for three (3) years. Audit logs are retained for seven (7) years. Students may request deletion at any time through the app. Upon termination of the service agreement between Keivos and the Institution, Keivos will, at the Institution's election, delete or return all Student Data within 90 days. Keivos may retain anonymized, aggregated data that cannot be used to identify individual students.
11. Student Rights
Keivos supports the following student rights: (a) Right to Access — students may download a copy of all their data through the app; (b) Right to Correct — students may update their profile information at any time; (c) Right to Delete — students may request permanent deletion of all their data, which cascades to the advisor dashboard; (d) Right to Revoke Consent — students may revoke data sharing consent at any time, immediately ceasing data visibility to advisors.
12. Compliance and Audit
Keivos will cooperate with the Institution in conducting audits or assessments of Keivos's compliance with this DPA. The Institution may request documentation of security practices, audit logs, and compliance certifications on reasonable notice. Keivos will make available the SOC 2 Type 2 and ISO/IEC 27001:2022 reports of its primary infrastructure provider (Supabase), and the SOC 2 Type II and ISO 27001 reports of its web hosting provider (Base44), upon request and subject to appropriate confidentiality terms.
13. Prohibited Uses of Student Data
Keivos shall not:
- Sell, rent, lease, or disclose Student Data to any third party for commercial purposes
- Use Student Data for targeted advertising or behavioral profiling
- Use Student Data to create or contribute to commercial profiles of students
- Mine or analyze Student Data for purposes unrelated to the educational services
- Use Student Data to train artificial intelligence or machine learning models, including those of any sub-processor
- Retain Student Data beyond the specified retention period without authorization
- Disclose Student Data to any sub-processor not identified in Section 9 (or in an updated published list) without prior notice as required by Section 9
14. Term and Termination
This DPA remains in effect for the duration of the service agreement between the parties. Either party may terminate this DPA with 90 days' written notice. Upon termination, the data retention and deletion provisions of Section 10 shall apply. Sections 6 (Security), 8 (Breach Notification), 10 (Retention), and 13 (Prohibited Uses) shall survive termination.
15. Governing Law
This DPA shall be governed by the laws of the State of Utah. To the extent of any conflict between this DPA and the service agreement, this DPA shall control with respect to the processing of Student Data.
16. Signatures
IN WITNESS WHEREOF, the parties have executed this Data Processing Agreement as of the date last signed below.
For the Institution:
For Keivos LLC:
336 East University Pkwy #1095, Orem, Utah 84058
Keivos LLC • keivos.com | keivos.com/dpa
