Pathly Legal / Counselor Plans
Counselor Data Processing Addendum
This Addendum governs how Pathly handles data when an independent educational consultant, private counselor, coach, or advising practice subscribes to a Pathly Counselor plan. It supplements the Counselor Subscription Terms and the Terms of Service, and takes effect when you accept them at checkout.
- Version
- 1.0
- Effective
- July 30, 2026
- Applies to
- Counselor plans
- Prior versions
- Archive
The short version
This box is a plain-language summary. It is not part of the Addendum, and the numbered sections below control.
- Students own their Pathly accounts. You do not, and neither does Pathly.
- You can see a student's Pathly data only after that student connects you. They can disconnect you at any time.
- You never see a student's conversations with Pathly's AI. Not summaries of the content, not excerpts, not transcripts.
- Your own client roster and the notes you write in Pathly belong to you. Pathly processes them on your instructions and hands them back or deletes them when you leave.
- Pathly does not sell student data, does not advertise to students, and does not let AI providers train on student data.
01 Parties and definitions
This Counselor Data Processing Addendum (the "Addendum") is entered into between Pathly Labs, Inc., a Delaware corporation ("Pathly," "we," "us"), and the individual or entity that subscribes to a Pathly Counselor plan ("Counselor," "you"). It supplements and is incorporated into the Counselor Subscription Terms and the Terms of Service (together, the "Terms").
If you are accepting this Addendum on behalf of a practice, firm, or other entity, you represent that you are an employee, owner, contractor, or agent of that entity and that you have authority to bind it to this Addendum.
Definitions
| Term | Meaning |
|---|---|
| Platform | The Pathly student guidance platform, including the student experience, the counselor dashboard, and related services. |
| Student Account Data | Information a student provides to or generates within their own Pathly account, including profile details, assessment responses and scores, saved careers and colleges, roadmaps, and conversations with Pathly's AI. It also includes self-reported academic data entered on the student's profile by a connected counselor under Section 4.5. |
| Counselor Practice Data | Information you provide to or generate within your Counselor account, including your account and billing details, your roster of connected students, connection records, tags, and notes you write in Pathly. |
| Connection | The student-initiated link between a student's Pathly account and your Counselor account that grants you the dashboard visibility described in Section 4. |
| Personal Information | Information that identifies, relates to, describes, or could reasonably be linked to an identified or identifiable individual. |
| Subprocessor | A third-party service provider Pathly engages to process data on Pathly's behalf in providing the Platform. The current list is published at pathly.com/legal/subprocessors. |
| Security Incident | A confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Information processed by Pathly. Unsuccessful attempts, port scans, pings, and blocked login attempts are not Security Incidents. |
02 Scope and roles
2.1 Two categories of data, two different roles
Pathly's Counselor plans sit on top of student-owned accounts. That structure produces two distinct data relationships, and this Addendum treats them separately.
| Data | Controller | Pathly's role | Governed by |
|---|---|---|---|
| Student Account Data | Pathly, in a direct relationship with the student | Controller | The Pathly Privacy Policy and Student Terms |
| Counselor Practice Data | You | Processor, acting on your instructions | This Addendum |
You are not a controller of Student Account Data. Students create their own accounts, own them, and keep them. Your Connection grants you a defined, revocable view into a subset of that data, described in Section 4. It does not transfer control or ownership of it to you.
2.2 What this Addendum is not
You are not an educational agency or institution, and this Addendum does not designate Pathly as a "school official" with a "legitimate educational interest" under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g. Pathly does not receive education records from you. If you also work under contract with a school, district, or other educational institution, that relationship is governed by the separate Pathly Partner School Agreement and its Student Data and Privacy Addendum, not by this document.
2.3 Order of precedence
If this Addendum conflicts with the Terms, this Addendum controls as to the processing of Counselor Practice Data. If this Addendum conflicts with the Pathly Privacy Policy as to Student Account Data, the Privacy Policy and Student Terms control. Nothing in this Addendum reduces the privacy protections Pathly owes students directly.
03 How you get access to a student's data
3.1 Access begins with the student
You gain no visibility into any student's Pathly data by subscribing. Visibility exists only where a student has affirmatively connected your Counselor account, or where a parent or guardian has done so through a parent-managed account. Pathly presents the scope of what you will be able to see at the moment of connection and records the student's authorization, including timestamp and the version of the disclosure shown.
Pathly does not create Connections on your behalf, does not bulk-import rosters into Counselor accounts, and does not connect a student to you on the strength of an email address you supply alone.
3.2 The student can revoke at any time
A student may disconnect you from their account at any time, without notice to you and without giving a reason. When they do, your dashboard visibility ends immediately. Notes you have already written about that student remain in your account as Counselor Practice Data unless you delete them.
3.3 Your representations about each Connection
- You have a bona fide advising relationship with the student, established under your own client engagement agreement.
- For a student under 18, you have obtained whatever parent or guardian consent your engagement and applicable law require, and your own privacy notice discloses your use of a platform like Pathly.
- You will not solicit, accept, or maintain a Connection with a student you do not advise.
- You will tell a student to disconnect you, or you will remove them from your roster, when your engagement ends.
3.4 A student may be connected to more than one counselor
Students may connect a school counselor and an independent counselor at the same time. Each sees only the data their own role permits. Pathly does not disclose your notes, tags, or roster to a school counselor, to another independent counselor, or to a parent, and does not disclose theirs to you.
04 What you can see, and what you can enter
Counselor plan visibility is fixed by the Platform and enforced in the database, not configured per account. The tables below describe it. Pathly may add fields to the visible set only in accordance with Section 13.2. Section 4.5 covers the narrow set of fields a counselor can write to.
4.1 Roster view
| Field | Level of detail | Purpose |
|---|---|---|
| Student name | First name, plus last name if the student provided one | Identify the student |
| Graduation year | Full year | Grade-level planning |
| Onboarding status | Complete or incomplete | Track initial setup |
| Interest quiz status | Complete or incomplete | Track assessment progress |
| Assessment completion | Yes or no per assessment | Track progress |
| Roadmap created | Yes or no | Track planning milestone |
| Last active | Timestamp only | Monitor engagement |
| Career goal | Full text, if the student set one | Understand direction |
4.2 Student detail view
| Field | Level of detail | Purpose |
|---|---|---|
| Saved careers | Career titles only | Understand interests |
| AI career matches | Titles and match percentage | Support guidance |
| Roadmap progress | Goal and completion status | Track planning |
| Assessment scores | Values, personality, and EQ scores with tags | Personalize support |
| GPA | Self-reported value, if the student or a connected counselor entered one | Academic planning |
| Standardized test scores | Self-reported values, if the student or a connected counselor entered them | Academic planning |
| Chat activity | Message count only, no content | Gauge engagement |
| Engagement summary | Derived from metadata only, no conversation content | Prepare for a session |
| Conversation starters | Suggested prompts generated from metadata | Support sessions |
| Join date | Account creation timestamp | Platform tenure |
4.3 The line Pathly does not cross
You receive
- Progress, completion, and engagement signals
- Assessment scores and tags
- Stated goals and saved careers
- Metadata-derived engagement summaries
You never receive
- Student email addresses
- Conversation transcripts, in whole or in part
- Individual student messages or AI responses
- Topics or themes drawn from conversation content
- Raw answers to assessment questions
The engagement summary shown in the student detail view is generated from metadata only: message counts, timestamps, saved career interests, and assessment completion. The system that writes it does not read conversation content. Conversation content is never included in a counselor view or in any export available to you.
A student may choose to share a specific excerpt of a conversation with you. That is a manual act by the student, it is never automatic, and it never happens by default.
4.4 Technical enforcement
- Row-level security restricts each Counselor account to the students connected to it.
- Counselor accounts are role-restricted and cannot impersonate a student or view a student's account as the student sees it.
- Access to student detail views is logged for audit.
4.5 Academic data you can enter
The counselor dashboard is otherwise read-only, with one exception. You may enter a grade point average and standardized test scores on a connected student's profile.
- These are self-reported values. Pathly does not receive official transcripts, verified score reports, or data feeds from a school information system or a testing agency. A number you enter is an assertion, not a verified record.
- What you enter becomes Student Account Data. The student can see it, edit it, and delete it, exactly as if they had entered it themselves. You do not own it and cannot lock it.
- Accuracy is your responsibility. Enter a value only where the student or their parent or guardian gave it to you, or where your engagement authorizes you to hold it. Do not enter academic data obtained from a source the student has not authorized you to use.
- Nothing else is writable. You cannot alter assessment scores, roadmaps, saved careers, goals, conversations, or any other part of a student's account.
The student's edit stands. Pathly will not restore a counselor-entered value over a student's correction, and will not notify you to seek approval. A student's ability to correct information about themselves is not something a counselor subscription can override.
05 Your obligations
5.1 Confidentiality and permitted use
You will treat student data you access through Pathly as confidential and will use it only to advise the connected student. You will maintain safeguards appropriate to the sensitivity of that data in your own practice.
5.2 Prohibited uses
You will not
- Sell, rent, license, or otherwise disclose student data to any third party
- Use student data to build marketing or prospecting lists, including lists of the student's classmates, siblings, or family
- Use student data for any purpose beyond advising the connected student, including your own research or publication, unless the student and, where applicable, their parent or guardian consents in writing
- Enter academic data on a student's profile that you obtained from a source the student has not authorized you to use
- Extract, scrape, or bulk-export Platform data by automated means
- Maintain a Connection with a student you no longer advise
- Represent to a student, a parent, or a school that you have access to conversation content, or imply that you can monitor a student's conversations
5.3 Account security
- Counselor seats are named and individual. You will not share credentials.
- You will use multi-factor authentication where Pathly offers it.
- You will notify Pathly at security@pathly.com within 24 hours of discovering that your credentials or account may have been compromised.
5.4 Associates and staff
If your practice has associates, each person who needs access must hold their own seat. You are responsible for their compliance with this Addendum and for removing a seat promptly when someone leaves your practice or no longer needs access.
5.5 Your own legal duties
You remain responsible for your own compliance with applicable privacy and consumer protection laws, any professional or ethical standards that apply to your practice, your client engagement agreements, and your own privacy notice. Pathly does not provide legal advice about those obligations.
06 Pathly's obligations
As to Counselor Practice Data, Pathly will:
- Process it only to provide and support the Platform, to secure it, to comply with law, and on your documented instructions. Pathly will not process it for its own unrelated purposes.
- Not sell it, and not use it for third-party advertising.
- Maintain the safeguards described in Section 7.
- Ensure that personnel with access are bound by confidentiality obligations and access it only as needed to operate and support the Platform.
- Provide reasonable assistance if you receive a request from an individual to access, correct, or delete their Personal Information, or a regulatory inquiry relating to it.
- Return or delete it on termination, as described in Section 10.
As to Student Account Data, Pathly's commitments run directly to students under the Privacy Policy and Student Terms, and include the following: Pathly does not sell student data, does not use it for targeted advertising to students, does not build commercial marketing profiles of students, and does not permit AI providers to train models on it.
07 Security
Pathly's infrastructure and AI subprocessors hold SOC 2 Type II or comparable attestations, listed with verification links at pathly.com/legal/subprocessors. Pathly holds internal security reviews and is working toward independent certification; it does not hold a SOC 2 Type II attestation of its own today. Do not represent otherwise to your clients.
7.1 Technical safeguards
- Encryption in transit using TLS 1.2 or higher
- Encryption at rest using AES-256 or equivalent
- Row-level security so students reach only their own data and counselors reach only their connected students
- Role-based access control across student, counselor, and administrative roles
- Multi-factor authentication for administrative access to production systems
- Automated security monitoring and error tracking with personal information scrubbed from traces
- Secure development practices, including code review and dependency monitoring
7.2 Administrative safeguards
- Personnel and contractors with access to Platform data are bound by written confidentiality obligations
- Access is granted on a least-privilege basis and removed when no longer needed
- Unique credentials, with administrative access logged
- Documented incident response and notification procedures
- Review of security practices and subprocessor posture as the platform changes
7.3 Hosting and data location
Platform data is hosted in data centers operated by Pathly's infrastructure subprocessors, which maintain industry-standard physical access controls. Pathly configures services to use United States regions where the provider offers them. Pathly does not intentionally transfer Platform data outside the United States, though limited access from outside the United States may occur for vendor support or security operations.
08 AI processing
8.1 What Pathly uses AI for
Pathly uses third-party AI services by API to provide conversational guidance to students on colleges, careers, courses, and scholarships, and to retrieve information used in recommendations. Providers are selected in part on their security posture and are listed at pathly.com/legal/subprocessors.
8.2 What is sent to AI providers
Included in requests
- Student first name, for conversational tone
- School name and location, where the student provided one
- Grade level, calculated from graduation year
- Stated interests and goals
- Assessment results
- Recent conversation history, limited to the last 10 messages
Never included
- Student email addresses
- Student last names
- Student or account identifiers
- Demographic information such as race, ethnicity, or gender
- Financial or family financial information
- Full conversation history
8.3 Training and retention
- Pathly does not permit AI providers to train their models on Platform data, and uses the provider settings and contractual terms available to it to disable training and minimize retention.
- AI providers use the data in a request solely to generate a response to that request.
- Pathly does not train proprietary models on individual student conversations. De-identified, aggregated patterns may inform prompt design and product improvement.
8.4 What is stored
The context assembled and sent to an AI provider is not retained by Pathly as a separate artifact. The student's messages and the AI's responses are stored so the student can review their own history. That record is accessible to the student. It is not accessible to you, to a school counselor, to a parent, or to a Pathly administrator outside of a documented support or security need.
Notes you write in Pathly are stored as Counselor Practice Data. Where a Pathly feature sends your notes to an AI provider, that feature is identified in the product, and the training and retention commitments in Section 8.3 apply to it.
09 Subprocessors
You authorize Pathly to engage the Subprocessors listed at pathly.com/legal/subprocessors, and their affiliates, to process data in providing the Platform. That page is the current list and is maintained as part of this Addendum.
9.1 Requirements Pathly imposes on Subprocessors
- A written data processing agreement limiting use to providing services to Pathly
- Encryption in transit and at rest
- Retention limited to what the service requires
- Prompt notification to Pathly of security incidents
- Deletion or return of data on termination
- Compliance with applicable privacy laws
9.2 Changes
Pathly will give at least 30 days' notice before a new Subprocessor begins processing, by updating the subprocessor page and emailing the address on your account. You may subscribe to change notices on that page.
If you object to a new Subprocessor on specific privacy or security grounds, tell us at legal@pathly.com within 15 days and we will work in good faith to address it. If we cannot, your remedy is to terminate your Counselor subscription before the change takes effect and receive a pro-rata refund of prepaid, unused fees. Counselor plans do not carry a right to veto a Subprocessor.
Moving between the AI providers already listed on the subprocessor page is not the addition of a new Subprocessor. Pathly will reflect such a change on that page. Adding an AI provider that is not listed follows the 30-day process above.
10 Retention and deletion
10.1 Student accounts survive your subscription
Student accounts belong to students. If you cancel, downgrade, or are terminated, student accounts are not deleted, are not suspended, and do not lose functionality. Students continue using Pathly at no cost. What ends is your access.
10.2 What happens when your subscription ends
- Your dashboard access ends at the end of the paid term.
- Connections to your account are dissolved, and connected students are notified that the connection has ended.
- Your Counselor Practice Data is available for export for 30 days after the term ends, then deleted from production systems within 30 days and purged from backups on the standard 7-day backup rotation.
10.3 Your export
While your subscription is active you can export your Counselor Practice Data and generate the student summaries and reports your plan includes. Once your subscription ends, the 30-day window covers your Counselor Practice Data only: your notes, tags, client list, and account records. Student Account Data cannot be exported after your subscription ends, because your access to it existed only through a live connection. Section 10.3 of the Counselor Subscription Terms covers this in full. Nothing you can export ever includes student email addresses, conversation content, or raw assessment answers.
10.4 Deleting your account
You may delete your Counselor account from account settings or by writing to legal@pathly.com. Deletion is preceded by a 15-day grace period during which you can restore the account. After that, Counselor Practice Data is permanently deleted from production systems within 2 business days and purged from backups within the 7-day rotation.
10.5 Student deletion
A student may delete their account at any time, independent of your subscription, on the same grace period and timelines. Pathly will not delay or condition a student's deletion request on your engagement with them.
10.6 De-identified data
De-identified and aggregated data that cannot reasonably be used to identify an individual may be retained indefinitely for platform improvement and research. It is not used for targeted advertising.
10.7 Legal holds
If data is subject to a legal hold, litigation, or regulatory requirement, Pathly will notify you where permitted, preserve the affected data beyond the periods above, and delete it promptly once the obligation lifts.
11 Security incidents
11.1 Notice to you
Pathly will notify you without undue delay, and no later than 72 hours after confirming a Security Incident affecting your Counselor Practice Data or the data of a student connected to you. Notice goes to the email address on your account.
11.2 What the notice will include
- The nature of the incident, the date or window, and its current status
- The categories of data and the approximate number of records affected
- Steps taken to investigate, contain, and prevent recurrence
- Whether law enforcement or a regulator has been notified
- What, if anything, you should do
Pathly will provide updates at least every 7 days, and sooner on material developments, until the incident is resolved. Material developments include a significant change in scope, identification of root cause, completion of containment, and regulatory or law enforcement involvement.
11.3 Who notifies students
Because Pathly is the controller of Student Account Data, Pathly is responsible for notifying affected students, their parents or guardians, and regulators where the law requires it. You do not carry that obligation for a Pathly-side incident, and you should not make notifications on Pathly's behalf. You remain responsible for notifications arising from an incident in your own systems, including a compromise of your Pathly credentials.
11.4 Your obligation
Tell Pathly at security@pathly.com within 24 hours of discovering that your Pathly credentials or Counselor account may have been compromised, or that student data you accessed through Pathly may have been exposed from your own systems.
12 Compliance and documentation
12.1 What Pathly publishes
Pathly maintains the following as its standing documentation for Counselor plans, and updates them as practices change:
- This Addendum, with a version archive
- Data inventory, listing what the Platform collects, why, and how long it is kept
- Subprocessor list, with provider security documentation links
- The Privacy Policy and Student Terms
Counselor plans are served by this published documentation. Pathly does not complete bespoke security questionnaires, issue individual attestations, or negotiate custom terms on Counselor plans. Schools, districts, and organizations that require negotiated terms should contact partnerships@pathly.com about a Partner School Agreement.
12.2 Your executed copy
A copy of this Addendum as accepted by you, showing the version, the date and time of acceptance, and Pathly's signature, is available in your account under Legal at any time after acceptance. Pathly also emails it to you at acceptance.
12.3 Applicable law
Pathly's practices are designed to meet the requirements of the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501 to 6506, the Protection of Pupil Rights Amendment (PPRA), 20 U.S.C. § 1232h, and applicable state student and consumer privacy laws. The Platform requires users to be at least 13 years old and is designed for students in grades 9 through 12. Pathly is not directed to children under 13 and does not knowingly collect their personal information.
FERPA governs education records held by educational agencies and institutions. As described in Section 2.2, it does not apply to this Addendum. It does apply to Pathly's Partner School relationships, which are governed separately.
12.4 Regulatory inquiries
If you receive a regulatory inquiry that concerns data you accessed through Pathly, tell us promptly at legal@pathly.com. Pathly will cooperate reasonably and provide documentation as needed.
13 Term, changes, and survival
13.1 Term
This Addendum takes effect when you accept the Terms and continues while you hold an active Counselor subscription, including renewals.
13.2 Changes
Pathly may update this Addendum. For a change that materially reduces your rights or Pathly's obligations, or that expands what a counselor can see, Pathly will give at least 30 days' notice by email and on this page before it takes effect. If you do not accept a material change, you may terminate before it takes effect and receive a pro-rata refund of prepaid, unused fees. Continued use after the effective date is acceptance. Non-material changes, such as clarifications or contact updates, take effect on posting. Every version is dated and kept in the archive.
13.3 Survival
Section 5.1 and 5.2 (confidentiality and prohibited uses), Section 10 (retention and deletion), Section 11 (security incidents, as to incidents discovered during the term), and Section 12.4 (regulatory inquiries) survive termination. Limitation of liability and confidentiality provisions survive per the Terms.
13.4 Liability
Liability under this Addendum is governed by the limitation of liability provisions of the Terms, including their stated exceptions. Nothing in this Addendum limits either party's liability for its own gross negligence or willful misconduct.
13.5 Contact
Privacy and this Addendum: legal@pathly.com. Security matters: security@pathly.com. Pathly Labs, Inc., South Carolina.
Acceptance
You accept this Addendum when you check the box agreeing to the Counselor Subscription Terms at checkout, or when you access the Counselor dashboard. No handwritten or electronic signature is required.
The signature blocks below are provided for reference only. This Addendum becomes legally binding on your acceptance of the Terms as described above. Pathly records the version accepted, the date and time, and the account that accepted it, and makes an executed copy available in your account under Legal.
Counselor
Name:
Title:
Entity:
Date:
Pathly Labs, Inc.
Name: Alan Brusky
Title: Chief Executive Officer
Entity: Pathly Labs, Inc.
Date: July 30, 2026