Data Processing Agreement
Last updated July 2026
This Data Processing Agreement ("DPA") describes how Young's Digital Atelier LLC, a subsidiary of Young's Multimedia Holdings LLC ("YDABlocks," "we," "us"), processes student data on behalf of a school or district ("Customer") that has agreed to our Terms of Service. It supplements, and does not replace, the Privacy Policy.
If your district participates in the Student Data Privacy Consortium (SDPC),the National Data Privacy Agreement (NDPA) executed through the SDPC Resource Registry is the version we sign for you, and it governs instead of this page. This page is our own standing agreement for districts and organizations that reach us outside that process, so the substance of a DPA — what we do with student data and what we don't — is available and checkable even before a district-specific document is on file.
1. Roles
For student data processed under this agreement, Customer is the data controller and YDABlocks is the data processor (also described, under FERPA, as a "School Official" performing an outsourced institutional function). We process student data only under Customer's direction and only for the educational purpose Customer authorized when it began using YDABlocks.
2. What is processed
The categories of student data processed, and why, are the same ones described in the Privacy Policy's "What we collect" section: roster information provided by Customer (student first name, grade level, class enrollment), the learning activity a student generates inside YDABlocks, and Richard conversation content. We do not collect categories of student data beyond what that page lists, and we do not repurpose student data for anything outside the authorized educational use.
3. Confidentiality and security
Everyone with access to student data is bound to confidentiality. Our technical and organizational security measures — encryption in transit and at rest, the Arming Gate access-control system, and our incident response process — are described in full on the Security Practices page, incorporated here by reference rather than restated.
4. Sub-processors
The complete, current list of sub-processors we use, and confirmation of what each one does and does not receive, is maintained on the Sub-processors page rather than fixed in this document, so it never goes stale here. As that page states, student identifying data is not handed off to any sub-processor. If we ever engage a sub-processor that would change that, we will update that page and notify Customer in advance where our agreement requires it.
5. No sale, no ad-targeting, no model training on student data
- We do not sell student data, under any circumstance.
- We do not use student data for behavioral advertising or to target ads to students.
- Student data is not used to train any AI model, ours or a third party's.
- We do not build a profile of a student beyond what is needed to deliver the authorized educational service.
6. Data subject rights
Where Customer is responsible for responding to a parent's or eligible student's request to access, correct, or delete their information, we will assist Customer in fulfilling that request using the tools and timelines described in Data Retention & Deletion and Children's & Student Privacy.
7. Retention and deletion
Student data follows the school-year retention lifecycle described in Data Retention & Deletion: active through the school year, then compressed and cryptographically hashed for three years, then permanently destroyed. Customer may request earlier deletion at any time. If Customer's contract with us ends, we cease using Customer's student data and delete or return it within the window specified in our agreement — commonly 30 to 45 days — except for any hashed records already inside that three-year window, which continue on schedule unless Customer requests earlier deletion.
8. Security incident notification
If a security incident affecting Customer's student data occurs, we will notify Customer within the timeframe required by applicable law and our agreement — commonly within 30 days — per the process described on the Security Practices page.
9. Location of processing
Student data is processed and stored on infrastructure located in the United States. We do not transfer student data outside the United States.
10. Audit and demonstration of compliance
On reasonable request, we will provide Customer with information reasonably necessary to demonstrate our compliance with this DPA, consistent with our obligation to protect the confidentiality and security of our systems and other customers' data.
11. Precedence
Where Customer has its own required data privacy agreement — a state or consortium template, or district-specific terms — and we have separately executed it, that document governs in place of this page for that Customer. This page is our own standing agreement, offered so the substance of a DPA doesn't wait on paperwork neither side has started yet.
12. Contact
DPA questions, or to request execution of a district-specific version: privacy@ydablocks.com (or send it through the contact form, which needs no mail app)