Tally
for districts and IT

Data Processing Agreement

Tally will execute your district’s standard DPA, a consortium agreement (NDPA / SDPC), or the template below — whichever your process requires. State-specific addenda are supported.

Most DPA review stalls on data inventories and deletion procedures. Tally’s answers are unusually short, because no student data is retained after a grading run and student identities never reach our servers at all.

REQUEST A SIGNED DPA DATA SAFETY DETAILS

You do not need a signed DPA to pilot Tally. The free tier runs on your existing Google Workspace accounts and stores no student data, so a single-teacher trial requires no procurement action. Sign when you are ready to deploy more widely.

starting the process

What to send us

1
Your agreement form
Your district’s standard DPA, your consortium agreement and its identifier (NDPA / SDPC), or a note that you would like to start from our template below.
2
Any state addendum required
New York Ed Law 2-d, Illinois SOPPA, Texas Student Data Privacy Agreement, California SOPIPA, or your state equivalent. Name it explicitly — addenda are usually the long pole in review.
3
Scope of deployment
Which schools or organizational units, roughly how many teachers, and your target start date so we can prioritize.
4
Your reviewer’s questions
If your security team has a questionnaire, send it with the DPA rather than after. Most of it is already answered on the data safety page.
the substance of our standard agreement

Template terms

These are the operative commitments in Tally’s standard DPA, in plain language. The executed agreement contains the full legal text; nothing below is softened in it.

A
Roles
The district is the data controller and owner of all student data. Tally acts as a service provider and school official under FERPA, operating solely under the district’s direction. Tally claims no ownership of any student data at any time.
B
Permitted use
Student work is processed for one purpose: producing a draft grade and feedback for the teacher who requested it. No advertising, no targeted marketing, no profile building, no sale of data, and no use of student work to train any AI model.
C
Data actually processed
Anonymized answer text and the teacher’s rubric, transmitted for the duration of a grading call. Student names, email addresses, Google account identifiers, course identifiers, and submission identifiers are removed in the browser before transmission and are never received by Tally infrastructure.
D
Retention and deletion
Answer text is held in memory only and discarded once a grade is returned. Teacher-created rubrics persist until deleted by the teacher. All records associated with a district are deleted within 30 days of a written request or contract termination, and written confirmation of deletion is provided.
E
Subprocessors
A current list is published on the data safety page. Tally provides 30 days’ written notice before adding any subprocessor that touches grading data, and the district may object.
F
Security controls
TLS 1.2+ in transit; encryption at rest for stored rubrics and counters; provider API keys held as platform secrets only; input validation rejecting any payload containing an identifier; least-privilege OAuth scopes limited to Google Classroom.
G
Incident response
Written notification to affected districts without undue delay and no later than 72 hours after confirmation of a security incident, including scope, data categories involved, and remediation taken.
H
Audit and access rights
The district may request architecture documentation, the subprocessor list, and the retention schedule at any time. Because no student data is retained, data-subject access requests are satisfied by the district’s own Classroom records.
I
AI-specific terms
A single AI provider is used and is named publicly. That provider does not train on API inputs or outputs. All AI-generated scores post as drafts requiring teacher approval; originality checks are advisory and never automatically affect a grade.
J
Termination
Either party may terminate with written notice. On termination, district records are deleted within 30 days. Grades already written to Classroom are unaffected — they live in the district’s own Google environment, not in Tally.
pre-answered

Questions reviewers usually ask next

Q
Where is data processed?
On edge infrastructure in the United States. No student identity is present in those requests.
Q
Do you carry a third-party security assessment?
Tally’s infrastructure is out of scope for a Google API Services assessment (CASA) because Google-scoped student data never reaches it — a boundary enforced by code-level validation, not policy. Architecture and threat-model notes are available to district reviewers on request.
Q
What happens if Tally shuts down?
Nothing is stranded. Grades already live in your Classroom gradebook, and there is no student data held by Tally to migrate or delete.
Q
Can we revoke access instantly?
Yes. Removing Tally from your Workspace trusted-app list cuts all Classroom access domain-wide immediately, regardless of what any individual teacher previously approved. No action by Tally is required or possible to prevent it.

Contact

DPA requests, security review, and district agreements: help@gradewithtally.com

Tally is developed by ofGeneration, LLC. This page summarizes our standard terms and is not itself a contract.