Completra

Press ⌘ P to print

Version 1.0 · Effective 5/21/2026 · This is the current version.

Data Processing Agreement (v1.0)


# Completra Data Processing Agreement

## 1. Parties

This Data Processing Agreement ("DPA") is entered into between Completra, Inc. ("Processor") and the school identified in the Completra subscription account ("Controller").

## 2. Scope of Processing

The Processor processes personal data on behalf of the Controller strictly for the purpose of providing the Completra software-as-a-service platform, including enrollment management, CRM functionality, communications, reporting, payment integrations, learning management, automation workflows, and related educational administrative functions.

## 3. Categories of Personal Data

The Processor may process the following categories of data:

- Student names, addresses, phone numbers, and email addresses
- Dates of birth and enrollment records
- Attendance records, grades, transcripts, certificates, and assessments
- Communication records including email, SMS, and voice metadata
- Payment metadata and transaction references
- Staff account information and audit logs
- Sensitive data including encrypted Social Security Numbers and government-issued identifiers where applicable

## 4. FERPA Compliance

Processor acknowledges its role as a "school official" with legitimate educational interests under FERPA.

Processor shall:
- Process education records solely on behalf of Controller
- Maintain appropriate administrative, technical, and organizational safeguards
- Not use student data for advertising purposes
- Not disclose student data except as instructed by Controller or required by law
- Maintain audit logging for administrative access to student records

## 5. CCPA / CPRA Compliance

Processor acts as a Service Provider and Contractor under the California Consumer Privacy Act and California Privacy Rights Act.

Processor shall:
- Process personal data solely for the purposes described in the Agreement
- Not retain or disclose personal data outside the scope of the Agreement
- Not sell personal data
- Not share personal data for cross-context behavioral advertising
- Provide reasonable assistance for verified consumer rights requests

## 6. TCPA Compliance

Processor supports Controller compliance with the Telephone Consumer Protection Act.

Processor shall:
- Maintain communication consent records
- Process STOP and unsubscribe requests
- Honor communication preferences
- Support quiet-hour restrictions where applicable

Controller remains responsible for obtaining legally sufficient consent before initiating communications through the platform.

## 7. PCI-DSS Compliance

Payment card information is processed exclusively through PCI-DSS compliant third-party providers including Stripe, PayPal, and Square.

Processor does not store:
- Full payment card numbers
- CVV values
- Raw payment credentials

Processor stores only limited payment metadata necessary for platform operations.

## 8. Security Measures

Processor maintains commercially reasonable security measures including:

- TLS encryption in transit
- AES-256 encryption at rest
- Column-level encryption for sensitive identifiers
- Role-based access controls
- Multi-factor authentication for privileged accounts
- Tenant-level data isolation
- Audit logging and monitoring
- Least-privilege access policies

Infrastructure providers may include:
- Supabase
- Vercel
- Cloudflare
- Stripe
- SignalWire
- and related subprocessors required to operate the Services

## 9. Subprocessors

Processor may utilize subprocessors necessary to provide the Services, including infrastructure, communications, payment, hosting, and support vendors.

Processor shall maintain written agreements with subprocessors imposing data protection obligations substantially similar to this DPA.

## 10. Data Breach Notification

Processor shall notify Controller without undue delay and no later than seventy-two (72) hours after confirming a Security Incident affecting Controller data.

Notification may include:
- Nature of the incident
- Categories of affected records
- Estimated affected individuals
- Potential consequences
- Mitigation and remediation efforts

## 11. Data Retention and Deletion

Processor retains personal data only as necessary to:
- Provide the Services
- Satisfy legal obligations
- Enforce contractual obligations
- Comply with educational retention requirements

Upon termination of Services:
- Controller may export its data
- Data may remain in a limited recovery period
- Data shall thereafter be securely deleted according to Processor retention schedules

## 12. Confidentiality

Processor shall ensure personnel authorized to process personal data are subject to confidentiality obligations.

All education records and personal data shall be treated as confidential information.

## 13. Limitation of Liability

Except for gross negligence, willful misconduct, breaches of confidentiality, or violations of applicable privacy laws, each party’s aggregate liability under this DPA shall not exceed the fees paid by Controller during the twelve (12) months preceding the event giving rise to liability.

## 14. Governing Law

This DPA shall be governed by the laws of the State of Georgia unless otherwise required by applicable law.

## 15. Acceptance

By accepting this agreement, Controller acknowledges that it has read, understood, and agreed to the terms of this Data Processing Agreement and represents that the accepting user has authority to bind the organization to this agreement.

## 16. Signature

This agreement is accepted electronically through the Completra signup wizard, with IP address, user agent, authenticated account ID, DPA version, and acceptance timestamp recorded in the platform's tenant_dpa_acceptances table.