FERPA Policy
report insights llc family educational rights and privacy act (ferpa) compliance policy this document is provided for informational purposes only and does not constitute legal advice report insights llc recommends that all educational institutions, practitioners, and agencies consult with their own legal counsel to ensure full compliance with ferpa and any applicable state laws 1\ purpose and scope this policy outlines how report insights llc ("we," "our," or "the company") complies with the family educational rights and privacy act (ferpa) as an educational technology vendor, we provide software services to schools, school districts, and other educational institutions (each a " school "), to private practitioners who are licensed to practice in psychological and educational services (each a “ practitioner ”), and to agencies that hire licensed professionals who practice in psychological and educational services (each “ agency ”) while ferpa directly regulates educational institutions receiving federal funding, the company acts as a "school official" with a "legitimate educational interest" when handling student education records we strictly adhere to ferpa’s requirements regarding the collection, use, maintenance, and protection of student data 2\ definitions student data any personally identifiable information (pii) derived from an education record maintained by a school we collect and process only the minimum student data necessary to provide the requested services education record records directly related to a student and maintained by an educational agency or institution this includes names, grades, student ids, and usage data tied to individual profiles school official exception a ferpa provision allowing schools to share student data with third party vendors without prior parental consent, provided the vendor performs an institutional service for which the school would otherwise use employees 3\ data ownership and direct control institutional ownership all student data uploaded, generated, or processed through our software remains the sole property of the partnering school, practitioner, or agency direct control we process student data under the direction and on behalf of the school/practitioner/agency no commercial exploitation we will never sell, rent, lease, or use student data for targeted advertising, profiling, behavioral tracking, or commercial marketing ai constraints student data will not be used to train, fine tune, or improve commercial artificial intelligence or machine learning models without explicit authorization 4\ permitted uses and disclosures we will only use student data to fulfill our contractual obligations and deliver the requested educational services we do not disclose student data to third parties except in the following limited scenarios to sub processors or contractors necessary for running our application infrastructure, provided they are bound by the same ferpa compliance standards to the school’s authorized personnel (e g , school psychologists), practitioner’s authorized personnel (e g , psychologist), or agency authorized personnel (e g , psychologist) to comply with a valid legal subpoena, court order, or regulatory requirement, after notifying the school, practitioner, or agency where legally permissible 5\ security and technical safeguards we implement robust administrative, technical, and physical security controls to prevent unauthorized access or disclosure encryption data is encrypted at rest using aes 256 and in transit using tls 1 2 or higher access controls role based access control (rbac) restricts internal employee access to student data based on the principle of least privilege employee training all company staff with system access must complete annual ferpa data privacy training data isolation multi tenant architecture guarantees that each school's data is logically segregated from other customers 6\ data access, corrections, and deletion parent/student rights ferpa grants parents and eligible students (age 18+) the right to review and amend their records because we hold data on behalf of the school, practitioner, or agency any consumer requests must be submitted directly to the school, practitioner, or agency we will assist the school, practitioner, or agency in fulfilling these requests within 45 days data retention we retain student data only as long as necessary to provide the service under our active contract data deletion upon contract expiration, termination, or a written request from the school, practitioner, or agency, we will permanently destroy or return all student data within \[e g , 30 or 60] days, except for anonymized aggregated metadata used for systemic platform optimizations 7\ breach notification and incident response in the event of an unauthorized disclosure, system compromise, or data breach affecting student data we will notify the affected school’s primary contact immediately, and no later than 72 hours after discovering the incident the notification will include the nature of the breach, the specific categories of data impacted, and our mitigation steps we will cooperate fully with the school’s, practitioner’s, or agency’s investigation and assist in any mandatory legal notifications to parents or state agencies 8\ updates to this policy we will not modify this policy or our terms of service in a way that reduces protections for student data without providing explicit, advance notice to our partnering schools, practitioners, or agencies material changes require affirmative consent or contract updates to ensure that the school, practitioner, or agency remains ferpa compliant (updated 7/13/26)
