Last updated 6 September 2026
This addendum applies whenever a school, district or other education institution uses Bluestift with its students. It forms part of the agreement between us and sets out what we do with student data, and what we will never do with it.
The school is the controller of its students' personal data and decides what is collected and why. We are the processor and act only on the school's documented instructions — using the service as configured counts as those instructions.
For students who sign up on their own, outside any school, we are the controller and our privacy policy governs instead.
The school designates us a school official with a legitimate educational interest in student education records under 34 CFR § 99.31(a)(1). On that basis we commit that:
Inspect and review. A parent or eligible student exercises that right with the school. Staff can produce a student's record from the dashboard at any time. That record covers identity, enrolment, results, inferred understanding and staff notes — but not the student's own conversations with Raya, for the reason set out in §7.
Outside any school, a child under 13 can use Raya on their own under our privacy policy — no analytics, no model training, no public rooms, no purchase without a stated adult. The moment a school enrols them, this addendum and the school's consent govern instead.
By enrolling students under 13, the school confirms that it consents on behalf of their parents for the school's educational use, as the COPPA school-consent exception permits (16 CFR § 312.5(c)(6)), and that it has given parents notice of what we collect. We collect from children only what the service needs, never condition participation on more, and never use a child's data for advertising or profiling outside tutoring. On a parent's request, relayed by the school, we delete a child's data.
We use the providers listed on our sub-processors page, which also states, honestly, which of those agreements are already signed and which are still being put in place — we have only just launched. Whatever their status, we remain responsible to you for what those providers do.
We update that page and notify school administrators before a new sub-processor starts handling school data. A school may object on reasonable data protection grounds within 30 days; if we cannot offer an alternative, the school may terminate the affected part of the service and be refunded the unused balance.
Breach notification. If we suffer a personal data breach affecting a school's data, we notify that school without undue delay and in any event within 72 hours of becoming aware, with what we know and what we are doing about it.
We assist the school with data subject requests (access, correction, deletion, portability), with data protection impact assessments, and with regulator enquiries. Most requests are answerable directly from the dashboard; where they are not, write to hello@thebluestift.com. If a data subject comes to us directly, we refer them to the school rather than acting on our own.
We make available the information needed to demonstrate compliance with these obligations and allow for audits, on reasonable notice and without disrupting the service for other schools.
At any time during the term the school can export its students' records. When the contract ends, we delete school data within 90 days at the school's choice of deletion or return, except where a law requires us to keep something — payment records being the usual case.
Deletion is real. It reaches the learning content, the uploads, the assessment results and the inferred learning model, including the parts held in systems that no automatic cascade would have reached.
Where a sub-processor operates outside the EEA or the UK, transfers must be covered by the European Commission's Standard Contractual Clauses or an adequacy decision. The location of each provider, and the current status of that cover, is on the sub-processors page.