Effective date: February 27, 2026
These terms summarize how Sukma supports institution-managed deployments. They are intended to help procurement, academic leadership, and technology teams understand ownership, operational responsibility, and governance boundaries before contract execution.
In institution-managed environments, student-related records remain under institutional control. Sukma provides the software, workflows, and governance features used to process those records within the agreed deployment scope.
Sukma acts as a service provider. We process institution-managed session data, user data, and course data under institutional instructions, configured controls, and contract terms.
• Owner and admin controls for policy, retention, and evidence workflows
• Role-based access over compliance-critical operations
• Auditable records for policy changes, access reviews, and purge requests
• Institution-configurable retention and deletion controls for governed conversation records and session artifacts
Session conversation retention can be configured between 7 and 90 days. After the configured retention period, governed conversation payloads can be redacted while metadata and evidence history remain available for traceability, review, and institutional accountability. Explicit purge operations can remove governed conversation records, audience queries, examples, assessments, whiteboards, and session summaries for the selected organization scope.
A Data Processing Agreement draft is available for institutions that require documented processing instructions, security commitments, subprocessor treatment, and incident notification terms.
• Sukma is FERPA-ready for institution-managed deployments
• Sukma operates with SOC audit-ready controls and evidence workflows
• Formal certification or attestation claims are not made before external audit outcomes
These terms apply to institution-managed use. Independent personal accounts are governed by the Terms of Service and Privacy Notice.