FundView Data Handling Exhibit
Effective date: August 10, 2026
This exhibit is part of the FundView Master Subscription Agreement. It covers what district data FundView holds, where it lives, who can reach it, how long it is kept, and what happens if something goes wrong.
Where this exhibit and the Agreement address the same data-handling topic, this exhibit controls.
Capitalized terms have the meanings given in the FundView Master Subscription Agreement.
1. What data the Service holds
The Service is a school finance tool. The data it holds for the District is, honestly described:
- District financial records. Fund balances, revenues, expenditures, cash-flow models, tax rates, assessed values, debt schedules, capital and bus plans. Most of this is public record by nature under Indiana law.
- Payroll-adjacent aggregates. Salary and benefit totals at the fund and category level. The Service does not hold individual employee payroll records.
- Enrollment counts. Aggregate district-level and fund-level counts only. The Service holds no student-level records by design.
- Staff seat information. Names and district email addresses of the District's authorized users.
- Uploaded documents. Documents the District chooses to upload (for districts with the Document Layer). Uploads pass through an intake screening step and a human review queue before they enter the document library; Section 8 covers what happens if a document containing student records slips through.
2. Architecture: one deployment per district
Each district runs on its own dedicated deployment: its own application instance and its own database, physically separate from every other customer. There is no shared multi-tenant database. This is the Service's architecture, not a configuration option, and it is why the return and deletion commitments in Section 7 are simple to keep: the District's entire environment can be exported and then deleted as a unit.
3. Data location
District Data is stored and processed in the United States.
4. Subprocessors
WRG uses the following Subprocessors to deliver the Service:
| Subprocessor | Role |
|---|---|
| Supabase | Database hosting (PostgreSQL) and file storage, running on Amazon Web Services infrastructure |
| Vercel | Application hosting |
| Anthropic | AI processing (narratives, analysis, assistant) via commercial API |
| Resend | Transactional email delivery |
| Sign-in only, via the District's own Google Workspace (OAuth); the Service does not send District financial data to Google |
4.1. Changes to this list. WRG will notify the District in writing before adding or replacing a Subprocessor that will process District Data. The District has 30 days from that notice to object in writing on reasonable grounds. If the District objects, the parties will discuss the concern in good faith; if it is not resolved, the District may terminate the affected module or Order Form and receive a pro-rata refund of prepaid unused fees.
4.2. Emergency replacements. If WRG must replace a Subprocessor immediately to address a security or availability emergency, WRG may do so and will notify the District promptly afterward, with the same objection right running from that notice.
4.3. WRG remains responsible for its Subprocessors' handling of District Data.
5. Security posture
Stated plainly and without inflation:
- Sign-in is through the District's own Google Workspace accounts (single sign-on); WRG does not hold District user passwords.
- Access within the Service is role-gated, and database row-level security policies scope access to the District's data.
- Data is encrypted in transit and at rest through the hosting platforms listed in Section 4.
- Paid features are controlled by fail-closed entitlements: a feature that is not enabled for a deployment refuses to serve rather than defaulting open.
- Changes made in the Service are recorded in an audit trail, so the District can see who changed what and when.
- WRG reviews the security and privacy terms of each Subprocessor in Section 4 before engaging it.
- WRG is a single-principal operation. Administrative access to the District's deployment is held by the WRG principal and is limited to what is needed to run, support, and troubleshoot the Service. If WRG adds personnel or contractors, they will be bound by equivalent confidentiality and access obligations.
- WRG does not hold a SOC 2 attestation and this exhibit does not claim one.
6. AI processing
District Data processed by the Service's AI features (including narrative generation, analysis, the assistant, and extraction of data from uploaded documents and PDF reports) is sent to Anthropic's commercial API.
- Under Anthropic's Commercial Terms of Service (effective June 17, 2025), Anthropic may not train its models on customer content.
- Anthropic's published data-retention documentation states that API inputs and outputs are automatically deleted within 30 days of receipt or generation, subject to the exceptions Anthropic publishes: services with longer retention under the customer's control, separately agreed retention arrangements, retention needed to enforce Anthropic's usage policy, and compliance with law.
Both statements were verified against Anthropic's published sources on August 10, 2026. Both are living documents maintained by Anthropic, and WRG re-verifies them when this exhibit is updated.
WRG does not use District Data to train artificial intelligence models of its own.
7. Breach notice, data return, and deletion
7.1. Breach notice. WRG will notify the District without unreasonable delay, and in any case within 72 hours of discovering, or being notified of, a security breach involving unauthorized acquisition of District Data. The notice will describe what is known about the scope, the data affected, and the steps WRG is taking, and WRG will supplement the notice as its understanding develops. As the owner of its data, the District is responsible for any notifications to affected individuals and to the Indiana attorney general that Indiana law requires; WRG will reasonably assist.
Worth saying plainly: Indiana's breach-notification statute is built around personal information such as Social Security numbers and financial account numbers, and the data FundView holds is district financial information and staff work email addresses, which largely does not fall inside that definition. The statute would therefore do little work in a FundView incident. The 72-hour commitment above is a voluntary contractual standard, and it is the thing actually protecting the District here, not the statute.
7.2. Export during the term. The District may export its data from within the Service at any time, without asking WRG and without charge. This right is deliberately unconditional: the District's records in FundView remain subject to the District's own obligations under the Indiana Access to Public Records Act and its records-retention duties, and the District must never be dependent on WRG's cooperation or availability to meet them.
7.3. Return on termination. For 60 days after expiration or termination, the District may request a complete export of its deployment: a full database dump plus all stored files and documents. WRG will deliver the export within 30 days of the request, in standard formats (SQL dump and native file formats), at no charge.
7.4. Deletion. Within 30 days after the return window closes, or earlier at the District's written request once it confirms it has the export it needs, WRG will delete the District's deployment, including its database and stored files. Because each district's deployment is separate (Section 2), deletion is the removal of the District's entire environment, not a row-by-row cleanup of a shared system.
7.5. Backups. Data in routine encrypted backups held by the hosting provider is not erased at the same instant as the live deployment. It ages out on the provider's ordinary backup rotation, after which it is gone. No vendor performs surgical deletion from point-in-time backup snapshots, and WRG will not claim to. In the interim those backups are not restored, mined, or accessed for any purpose other than disaster recovery. This is normal backup practice and is stated here so nothing is hidden.
7.6. Certification. WRG will provide written confirmation of deletion on the District's request.
7.7. Legal holds. Return and deletion are subject to preservation obligations imposed by law or legal process. WRG will tell the District if a hold prevents deletion and will delete when the hold lifts.
8. FERPA posture
8.1. The Service is not marketed as a FERPA service and by design does not receive or maintain student education records as defined in 34 CFR 99.3. Enrollment data is held as aggregate counts only.
8.2. The document upload path is the one place student records could enter the Service inadvertently. Uploads pass through PII intake screening and a human review queue before entering the document library; that control is part of the Service's design.
8.3. If the District identifies a document in the Service that contains student education records, WRG will delete it promptly on the District's notice. If the District ever intends to transmit education records to the Service deliberately, the parties will first agree in writing on FERPA handling terms.
9. Student data privacy agreements
Some districts maintain a standard student data privacy agreement and ask every education vendor to sign one. In Indiana this is usually the Student Data Privacy Consortium's National Data Privacy Agreement, which all nine Indiana Educational Service Centers participate in through the Indiana Alliance.
FundView holds no student education records by design, so most of what those agreements govern has no subject matter here, and this exhibit covers the same ground for the data FundView actually holds. WRG will not decline the ask. WRG will complete the District's form, state honestly on the schedule of data that no student data is collected, and say plainly which provisions apply to a financial-data product and which do not.
10. Records retention
The District remains the custodian of its own records for purposes of Indiana records-retention law. The Service stores and organizes copies of District Data to provide its features; it does not become the District's system of record or assume the District's retention obligations. The export rights in this exhibit exist so the District can always satisfy its own retention and public-records duties.
Questions
Email support@fundviewk12.com. Willow Run Group, LLC, 22696 County Road 32, Goshen, Indiana 46526.