Skip to content

Trust

Legal and trust documents

Everything Futureful publishes about how it treats people and their information, with the date each one took effect. Below them, the documents we do not publish yet, and why.

Current as of
Keep a copy

What we do not publish, and why

A reviewer working through a questionnaire deserves to learn our gaps from us rather than find them later. Each of these is a real gap with a real reason, and none of them is closed by writing a page.

A VPAT or a WCAG conformance claim
We have not commissioned an independent audit, and a self-declared VPAT is a representation we would be making about work nobody outside this team checked. The accessibility page says what we actually built and what fails our deploy instead.
A signed Data Processing Agreement
A DPA is a contract, not a web page. We will sign one per district or employer rather than publish a template that our practice has not been measured against. Ask and a human answers.
A security program page
A page of that kind warrants a written program with a named coordinator, a recurring assessment and a breach notification window. Those are things to operate, not to assert. We publish the sub-processor register, which is derived from the code, rather than a summary of controls we do not yet run.
A GDPR or UK data posture
Futureful operates in the United States and stores data there. We have not made the transfer commitments that serving people in the EU or UK would require, so we do not claim them.

Asking us something

Privacy questions, a records request, a district agreement, or a security review all go to the same place and a person reads it.

info@futureful.app

Futureful · Legal index · Rev A