About this agreement
This is Naven’s standard data processing agreement for schools, districts and other organizations. It is
a template: it binds nobody until both parties complete and sign it, and a district may use its own state’s
standard agreement instead (for example the California Student Data Privacy Agreement). To start, use the
form on Naven for organizations or write to shervin@shapoury.com.
1 · Parties and purpose
This agreement is between [Organization name] (“the Organization”) and Naven, operated by
Shervin Shapoury (“the Provider”). The Provider provides messaging, calling and channels
(“the Service”) to the Organization’s users. This agreement governs the Provider’s handling of
personal information the Organization provides or that the Provider collects from the Organization’s users
through the Service (“Organization Data”), including education records and student data.
2 · Ownership and control
- Organization Data belongs to the Organization. The Provider acquires no rights to it except those needed to
provide the Service.
- For a school or educational agency, the Organization designates the Provider a “school official” with
a legitimate educational interest under FERPA (34 C.F.R. § 99.31(a)(1)(i)(B)). The Provider is under
the Organization’s direct control for the use and maintenance of education records.
- Requests from parents, guardians or eligible students to inspect, correct or delete records are made to the
Organization. The Provider assists the Organization in responding within 10 business days of the
Organization’s request, so the Organization can meet its own deadlines.
- Where the Organization consents under COPPA on behalf of parents for users under 13, it does so only for
accounts it creates for its own students, for its educational purposes, and the Provider uses that data for
no other purpose.
3 · Use of Organization Data
- The Provider uses Organization Data only to provide, secure and maintain the Service for the Organization.
- The Provider does not sell, rent or trade Organization Data; does not use it for targeted advertising; does not
build profiles of students except to provide the Service; and does not use it to train AI models.
- The Provider does not disclose Organization Data except to the sub-processors listed at
navenapp.com/subprocessors, under written terms that restrict them to the same purposes, or as the law
requires. The Provider gives the Organization at least 30 days’ notice of a new sub-processor, and the
Organization may object and end this agreement.
- Organization Data is stored in the United States.
4 · Safeguards and incidents
- The Provider maintains administrative, technical and physical safeguards appropriate to the Service, as
described in Exhibit A, including a written information security program that names the individual
responsible for it, reviewed at least annually.
- The Provider notifies the Organization without undue delay, and in any case within 72 hours of confirming it,
of any unauthorized acquisition of or access to Organization Data, with what is known about its scope, and
cooperates with the Organization’s response and any notice the law requires.
- The Provider does not warrant that the Service is free from vulnerabilities or that unauthorized access cannot
occur; its obligations are those stated in this section.
5 · Term, deletion and return
- This agreement lasts as long as the Provider holds Organization Data.
- On the Organization’s written request, and within 60 days after the agreement ends, the Provider deletes
Organization Data, or returns it in a machine-readable format first if the Organization asks, and confirms
in writing. De-identified data may be kept only if it cannot reasonably be re-identified and is used for
nothing but improving the Service.
- A student may export content they created before deletion, at the Organization’s direction.
6 · State and provincial terms
Where the Organization is subject to state or provincial law with required terms — for example California
Education Code § 49073.1 and Business and Professions Code § 22584, New York Education Law
§ 2-d, Illinois SOPPA, or British Columbia’s FIPPA — the parties attach that law’s
required terms or standard addendum as Exhibit B, and Exhibit B prevails where it conflicts with this agreement.
7 · General
- This agreement prevails over the Service’s Terms of Service where they conflict about Organization Data.
- Neither party’s liability under this agreement is increased beyond what the parties agree in writing.
- Changes to this agreement must be in writing and signed by both parties.
Exhibit A · Safeguards in place
- All traffic is served over HTTPS; TLS 1.0 and 1.1 are refused; HSTS is set for a year.
- Administrative access is limited to the Provider’s developer, behind an emailed code, a passkey and a
password; secrets are kept in the hosting provider’s secret store, not in code.
- Database rules restrict each user to their own conversations; uploads are keyed to their uploader.
- Sign-in codes, parent links and PINs are stored only as one-way hashes.
- Accounts, and everything that names them, can be deleted on request; deletion is logged without identifying data.
- Messages are screened automatically before delivery; the service is not end-to-end encrypted.
- The service has not had an external security audit.
Signatures
| Organization | Provider (Naven) |
| Name | | |
| Title | | |
| Signature | | |
| Date | | |