Data Processing Agreement
A template DPA you can download, complete and sign for your institution.
Download the template
A fill-in-the-blanks DPA covering parties, processing, security, sub-processors, incident notification and deletion.
Download DPA template (PDF)What the agreement covers
1. Parties
The Institution (the data controller) and the operator of the MindGuard service (the data processor), which processes personal data on the Institution’s documented instructions.
2. Subject matter and duration
The Processor provides the MindGuard decision-support service, processing student roster data, consent records and analysis events for the duration of the subscription term.
3. Nature and purpose of processing
Processing is limited to identifying early signs of distress in consented digital content, recording and enforcing consent, and surfacing summaries for review by the Institution’s trained counsellors. Analysis runs only on content for which consent is active.
4. Categories of data subjects
Students (including minors, processed under parental or guardian consent), parents and guardians, and institution staff who administer or use the service.
5. Consent and lawfulness
The Institution is responsible for obtaining all consents required by law, including parental consent for minors. The Processor provides the consent, reminder, expiry and revocation workflow and records every consent event in an immutable audit trail.
6. Confidentiality and security
The Processor implements encryption at rest, least-privilege access, signed single-use consent tokens, rate limiting and append-only audit logging. Personnel who access personal data are bound by confidentiality obligations.
7. Sub-processors
Sub-processors may be engaged for infrastructure and transactional email. The Processor maintains a sub-processor list and notifies the Institution of material changes.
8. Data subject rights
The Processor assists the Institution in responding to access, rectification, erasure, restriction and portability requests, and notifies the Institution of any direct requests without undue delay.
9. Security incident notification
The Processor notifies the Institution without undue delay of any personal-data breach, with the nature, affected categories and remediation steps.
10. Data minimisation and retention
Only content a data subject explicitly shares is analysed, and analysed content is not stored between sessions. Roster and consent records are retained for the subscription term plus a transition period, and deleted on request or off-boarding.
11. Deletion and return
On termination the Institution may export roster and consent records. On written request the Processor deletes or returns all personal data, unless retention is required by law.
12. Audit
The Processor makes available, on reasonable request and subject to confidentiality, information necessary to demonstrate compliance with this Agreement.
13. Governing law
Specified by the parties. The template includes signature blocks for both the Institution and the Processor.