Student Data Privacy Policy
Purpose And Scope
This Policy describes how Evansville Regional Economic Partnership, Inc. (EREP) (“Company”) collects, uses, safeguards, shares, and deletes Student Data when providing erepio (“Services”). This Policy applies to all student users authorized by the School and to student personal information processed on behalf of the School.
Role: We act as a school official under FERPA with a legitimate educational interest and as a COPPA “operator” relying on verifiable parental consent obtained by the School or the School’s authorization, as permitted by law. The School is the data controller/owner of Student Data.
Quick Summary for Families & Teachers
What we collect: Only what’s needed for learning (name, school email, coursework, usage).
Why: To run the service, support teachers, personalize learning, and keep accounts secure.
We never: Sell data, target ads to students, or use data for non-educational profiles.
Who sees it: The School, educators, and our vetted service providers under contract.
Security: Encryption, access controls, audits, staff training.
Your rights: Parents/eligible students can request access, correction, or deletion through the School.
Contact: hello@erepio.com
Definitions
· Student Data: Any information that identifies or can reasonably be linked to an identified student, including personally identifiable information (PII) under FERPA.
· De-identified Data: Data that cannot reasonably identify a student, using reasonable technical and administrative safeguards.
· School Official: The Company qualifies as a school official for FERPA purposes, performing a service the School would otherwise use its own employees to perform and subject to the School’s control.
Collection & Categories of Student Data We Process
We collect Student Data when a School or student employer interacts with our Services, such as when a School enters Student Data in our Service.
Depending on the Service configuration and the School’s direction, we may process:
· Identifiers: name, student ID, school email/username, grade level, class roster association, (optional) birth month and year.
· Contact (limited): school-issued email; we do not collect home addresses or phone numbers unless strictly required and authorized.
· Education Records: coursework, submissions, assessments, teacher/supervisor feedback, graduation date, diploma track, attendance metadata.
· Usage Data: app interactions, device/browser type, app crash logs, IP address (for security and fraud prevention), timestamps.
· Accommodations/Supports (optional): if directed by the School and necessary to provide the Service.
· Parental/Guardian Information: for parental access features and digital sign-offs.
We do not collect biometric data, precise geolocation, or student financial information unless explicitly directed by the School and contractually authorized.
Lawful Basis & Compliance
· FERPA: We process education records as a school official with a legitimate educational interest, solely for School purposes.
· COPPA: For students under 13, we rely on consent authorization from the School (or parent/guardian as arranged by the School).
· PPRA: We do not conduct surveys or collect protected information without School authorization and required notices/consents.
· State Laws: We will comply with applicable state student privacy laws and district policies specified in the Agreement or State Law Addendum.
Purpose Limitation (What We Do With Student Data)
We use Student Data only to:
1. Provide, maintain, and support the Service.
2. Personalize learning experiences and enable teacher- and school-configured features.
3. Provide analytics and reporting to the School or district (not for advertising).
4. Ensure security, detect abuse/fraud, and improve reliability and accessibility.
5. Comply with law and enforce the Agreement.
Prohibited Uses:
· No targeted advertising to students or families.
· No selling Student Data.
· No building student profiles for non-educational purposes.
· No use beyond the School’s instructions and this Policy.
Data Minimization & Retention
· We collect only data necessary to deliver the Service as configured by the School.
· Retention: We retain Student Data only for the duration of the Agreement and a limited period thereafter for back-ups and lawful compliance.
· Deletion: Upon School’s written request or termination, we will delete or return Student Data within 30 days and certify completion within 60 days, subject to legal holds.
· Transfer: If a student transfers to a new school district, we will remove the Student Data from the District’s school ID, archive the Student Data until the student’s new school district is identified, and transfer the Student Data to the student’s new school district.
Access & Control (Student/Parent Rights)
We support the School in fulfilling rights under FERPA and applicable laws:
· Access/Review/Correction: We will assist the School in providing parents/eligible students access to Student Data and correcting inaccuracies upon the School’s verified request.
· Export/Portability: We provide reasonable export formats (e.g., CSV, JSON, PDF) upon School request.
· Deletion: We will delete specific student records at the School’s direction.
All requests must be submitted by the School to prevent unauthorized disclosure.
Security Safeguards
We implement administrative, technical, and physical safeguards appropriate to the sensitivity of Student Data, including:
· Encryption in transit (TLS 1.2+) and at rest ([AES-256] or equivalent).
· Role-based access control (RBAC), least privilege, SSO/SAML/OAuth (if enabled).
· Network segmentation, vulnerability management, logging/monitoring.
· Secure software development lifecycle (secure coding, code review, dependency scanning).
· Annual security risk assessments and workforce privacy/security training.
· Data residency: AWS-Ohio Region.
· Backups & DR: Regular backups with AWS snapshots and GitHub Respository.
Subprocessors (Vetted Service Providers)
We may use vetted subcontractors (subprocessors) to support hosting, storage, email delivery, analytics for the School’s purposes, and support services.
· All subprocessors are bound by written agreements requiring equal or stronger privacy and security obligations.
· The School may object to a new subprocessor on reasonable grounds; we will work in good faith to resolve or offer alternatives.
Data Sharing & Disclosue
We disclose Student Data only to:
· The School/District and authorized educators/administrators.
· Student employers/supervisors/parents or legal guardians
· Subprocessors under strict contractual obligations.
· Legal compliance: If required by law, court order, or to protect safety; where legally permissible, we will provide prior notice to the School.
· Successor entities: In the event of a merger/acquisition, only if the successor assumes equivalent privacy/security commitments and provides notice to the School.
We do not share Student Data with third parties for advertising or marketing
De-identified & Aggregate Data
We may use de-identified or aggregate data to improve the Service, conduct research, and produce insights that cannot reasonably identify a student.
· We apply technical controls (e.g., suppression, aggregation, k-anonymity-like thresholds when appropriate) and administrative controls (policies, contractual prohibitions) to prevent re-identification.
· We do not attempt to re-identify de-identified data.
Cross-Border Data Transfers
If Student Data is transferred across borders, we will use appropriate safeguards (e.g., standard contractual clauses, regional hosting options where available) and disclose data locations by country to the School
Incident Response & Breach Notification
· We maintain an incident response plan with continuous monitoring, triage, and remediation.
· In the event of a confirmed security incident involving Student Data, we will notify the School without undue delay and no later than 48 hours after confirmation, providing known details, scope, mitigations, and recommended actions.
· We will cooperate with the School’s notification obligations and law enforcement where applicable.
Product Changes & Policy Updates
· Material changes to features that affect Student Data will be communicated to the School with 3 days notice.
· We will notify the School of material Policy updates and, where required, obtain acknowledgment or agreement.
Training & Accountability
All Company personnel with access to Student Data are subject to confidentiality obligations and receive privacy and security training at onboarding and at least annually. Access is promptly revoked upon role change or termination.
Government & Law Enforcement Requests
We will redirect requests to the School where legally permissible. If we are compelled to disclose, we will limit disclosure to the minimum required and notify the School in advance unless legally prohibited.
Service Agreement Incorporaiton
This Policy forms part of the Service Agreement between Company and School (“Agreement”). In case of conflict, the stricter privacy/security document controls.
School Responsibilities (Summary)
To ensure compliance and effectiveness, the School agrees to:
· Provide appropriate consent/authorization (e.g., COPPA for <13) and required notices to parents/guardians.
· Configure and manage user access/rostering and identity systems securely.
· Submit privacy rights requests to the Company on behalf of parents/eligible students.
· Review and approve subprocessor list that follows:
Category
Core Infrastructure & Hosting
Core Infrastructure & Hosting
Core Infrastructure & Hosting
Communication & Security
Communication & Security
Service
PostgreSQL (database framework)
Redis
AWS S3
AWS SES
JWT stack
Purpose
Primary system for record handling
Permission caching and API throttling
Private object storage with signed URL access (AWS_Region: us-east-2)
Email delivery (AWS_REGION: us-east-2)
Authentication and authorization token handling for security and token management