For Texas Districts · Updated August 10, 2026
Built to sign the Texas NDPA.
What the TX-NDPA and Texas law require of a student-data vendor, and what AgenTeach provides — requirement by requirement, with links to the published artifacts your review team will ask for.
Our position, in one sentence: AgenTeach signs the SDPC Texas Student Data Privacy Agreement (TX-NDPA v1r6) with its standard protections intact — we do not use Exhibit H to weaken them — and the platform was engineered so that each obligation below is met by a working control, not a promise to build one later.
Requirement by requirement
Sources are cited for your convenience; the signed DPA is always the controlling document.
| What Texas requires | What AgenTeach provides |
|---|---|
| The district owns all student data. The vendor takes no license beyond providing the service.TX-NDPA Art. II | Ownership is stated in our public Terms §4 and Privacy Policy §2: all student data belongs to the LEA. We operate as a FERPA school official under the district's direct control. |
| Protections extend to all "LEA Data" — not just student records: staff, guardian, and operational data too.TX-NDPA Exhibit G §1 | We apply DPA protections to teacher and staff accounts, guardian contact data, and operational records under the same security, breach-notice, and deletion commitments as student data. |
| No sale, no targeted advertising, no profiling.TX-NDPA Art. IV · TEC §32.152 | Committed in our published Privacy Policy and Terms. There are no advertising, analytics, or session-replay trackers anywhere in the product (verified in code review, July 2026), and student data is never used to train AI models. |
| Transparent data inventory. Districts must know exactly which data elements the vendor touches.TX-NDPA Exhibit B | A field-level data table is published in Privacy Policy §3; an Exhibit B-aligned data inventory is part of our district procurement pack, available on request. |
| Reasonable security procedures and practices.TX-NDPA Art. V §3 · TEC §32.155 | Encryption in transit and at rest, tenant isolation by district and school on every request, least-privilege read-only Google Classroom scopes, application-layer token encryption, a database-enforced append-only audit trail (including sensitive-read logging), US-only storage and processing, a managed web application firewall, and security scanning in CI. Full detail: Security & Privacy Architecture. |
| Sensitive records deserve extra care. IEP/504, medical, and counseling-adjacent content carries heightened risk.TX-NDPA Art. V · FERPA | Every note, evidence item, and communication input is automatically classified by sensitivity. The most sensitive class is gated: it cannot be included in outbound communications without explicit, per-item teacher confirmation. |
| Breach notification to the district within 72 hours of confirmation, with Texas statutory clocks honored.TX-NDPA Art. V §4, Exhibit G §4 · Tex. Bus. & Com. Code §521.053 | Written notice to your designated DPA representative and district cybersecurity coordinator within 72 hours of confirmation — our target is same business day. We track the Texas statutory clocks (individual notice, Texas AG portal thresholds, consumer reporting agencies) and honor law-enforcement delays, documented in writing. |
| Support the district's own SB 820 / TEA reporting duty. The district must report incidents up its chain "as soon as practicable" — the vendor must feed it facts fast.TEC §11.175 | Our standing District Notification Data Sheet commits to what you get and when — see the timeline below. Because our audit trail is tenant-scoped and append-only, we can enumerate affected students and records per record type, with sensitivity-level breakdown. |
| Deletion within 60 days of district request.TX-NDPA Art. IV §6 · TEC §32.156 | Student erasure is honored within 60 days — typically immediately — and hard-deletes every linked record including stored file content, with written confirmation of destruction. Routine windows are enforced by an automated daily purge per our published Retention & Deletion Schedule. |
| Return of data in a usable format.TX-NDPA Art. IV §6 | Complete per-student export packages — every linked record plus correction history and audit metadata. Export is never blocked by a legal hold, so your counsel can always obtain records even while deletion is suspended. |
| Parent and eligible-student rights flow through the district.TX-NDPA Art. II | We support district-routed access, correction, and deletion requests within 30 days. Corrections to sent records are preserved in an append-only correction history, so the record of what changed is never silently lost. |
| Subprocessor transparency and flow-down.TX-NDPA Art. II §5 | Our full Subprocessor List is public — three services from two vendors (Microsoft and Google), all bound by data protection agreements, with hosting and AI processing pinned to US regions. Districts under agreement receive advance notice of any change. |
| Litigation and investigation holds.District discovery & records-preservation duties | District-directed legal holds at student, school, or whole-district scope, live in the product. A hold blocks deletion (never export) until released, and its full lifecycle is permanently auditable. |
| No biometric identifiers.Tex. Gov't Code ch. 560 | AgenTeach collects no biometric data of any kind — and we commit to a documented biometrics assessment before shipping any future audio- or image-analysis feature. |
If an incident ever touches your district
This is the reporting cadence we commit to, so your cybersecurity coordinator can meet the district's TEC §11.175 duties without chasing us:
| When | What your district receives |
|---|---|
| ≤ 72 hours from confirmation target: same business day | Written notice to your DPA representative and cybersecurity coordinator: incident description, affected data categories, date or date range, law-enforcement delay status, and our incident contact. |
| ≤ 5 business days | Affected-student and affected-record counts by record type, with sensitivity-level breakdown and explicit flagging of any IEP/504, medical, or counseling-adjacent content. |
| Every 72 hours until closure | Updated counts, containment status, and remediation steps. |
| At closure | A written incident summary suitable for your board and TEA reporting. |
Incident contact: security@agentea.ch. We cooperate with your SB 820 reporting chain, local law enforcement, and any TEA or Texas AG inquiry.
For your review team
Published and linkable today: Privacy Policy, Terms of Service, Subprocessor List, Retention & Deletion Schedule, and the Security & Privacy Architecture overview. Available on request as part of our district procurement pack: an Exhibit B-aligned data inventory, our AI-use statement, an incident-response overview, and support for HECVAT/CAIQ-style security questionnaires.
In the spirit of the rest of this site: we describe third-party certifications and registry listings as roadmap items until they are formally complete, and we would rather show you a working control than a badge.
This page is a plain-language summary for procurement and technology teams. It is not legal advice, and statutory citations are provided for convenience — the signed DPA between AgenTeach and your district is always the controlling document.
Reviewing AgenTeach for your district?
We'll walk your privacy, security, and curriculum teams through anything on this page — with the artifacts to back it up.