FERPA Policy
Report Insights LLC
Family Educational Rights and Privacy Act (FERPA) Compliance Policy
This document is provided for informational purposes only and does not constitute legal advice. Report Insights LLC recommends that all educational institutions, practitioners, and agencies consult with their own legal counsel to ensure full compliance with FERPA and any applicable state laws.
1. Purpose and Scope
This Policy outlines how Report Insights LLC ("we," "our," or "the Company") complies with the Family Educational Rights and Privacy Act (FERPA). As an educational technology vendor, we provide software services to schools, school districts, and other educational institutions (each a "School"), to private practitioners who are licensed to practice in psychological and educational services (each a “Practitioner”), and to agencies that hire licensed professionals who practice in psychological and educational services (each “Agency”).
While FERPA directly regulates educational institutions receiving federal funding, the Company acts as a "School Official" with a "Legitimate Educational Interest" when handling Student Education Records. We strictly adhere to FERPA’s requirements regarding the collection, use, maintenance, and protection of Student Data.
2. Definitions
- Student Data: Any Personally Identifiable Information (PII) derived from an Education Record maintained by a School. We collect and process only the minimum Student Data necessary to provide the requested services.
- Education Record: Records directly related to a student and maintained by an educational agency or institution. This includes names, grades, student IDs, and usage data tied to individual profiles.
- School Official Exception: A FERPA provision allowing schools to share Student Data with third-party vendors without prior parental consent, provided the vendor performs an institutional service for which the school would otherwise use employees.
3. Data Ownership and Direct Control
- Institutional Ownership: All Student Data uploaded, generated, or processed through our software remains the sole property of the partnering School, Practitioner, or Agency.
- Direct Control: We process Student Data under the direction and on behalf of the School/Practitioner/Agency.
- No Commercial Exploitation: We will never sell, rent, lease, or use Student Data for targeted advertising, profiling, behavioral tracking, or commercial marketing.
- AI Constraints: Student Data will not be used to train, fine-tune, or improve commercial artificial intelligence or machine learning models without explicit authorization.
4. Permitted Uses and Disclosures
We will only use Student Data to fulfill our contractual obligations and deliver the requested educational services. We do not disclose Student Data to third parties except in the following limited scenarios:
- To sub-processors or contractors necessary for running our application infrastructure, provided they are bound by the same FERPA compliance standards.
- To the School’s authorized personnel (e.g., school psychologists), Practitioner’s authorized personnel (e.g., psychologist), or Agency authorized personnel (e.g., psychologist).
- To comply with a valid legal subpoena, court order, or regulatory requirement, after notifying the School, Practitioner, or Agency where legally permissible.
5. Security and Technical Safeguards
We implement robust administrative, technical, and physical security controls to prevent unauthorized access or disclosure:
- Encryption: Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
- Access Controls: Role-Based Access Control (RBAC) restricts internal employee access to Student Data based on the principle of least privilege.
- Employee Training: All Company staff with system access must complete annual FERPA data privacy training.
- Data Isolation: Multi-tenant architecture guarantees that each School's data is logically segregated from other customers.
6. Data Access, Corrections, and Deletion
- Parent/Student Rights: FERPA grants parents and eligible students (age 18+) the right to review and amend their records. Because we hold data on behalf of the School, Practitioner, or Agency any consumer requests must be submitted directly to the School, Practitioner, or Agency. We will assist the School, Practitioner, or Agency in fulfilling these requests within 45 days.
- Data Retention: We retain Student Data only as long as necessary to provide the service under our active contract.
- Data Deletion: Upon contract expiration, termination, or a written request from the School, Practitioner, or Agency, we will permanently destroy or return all Student Data within [e.g., 30 or 60] days, except for anonymized aggregated metadata used for systemic platform optimizations.
7. Breach Notification and Incident Response
In the event of an unauthorized disclosure, system compromise, or data breach affecting Student Data:
- We will notify the affected School’s primary contact immediately, and no later than 72 hours after discovering the incident.
- The notification will include the nature of the breach, the specific categories of data impacted, and our mitigation steps.
- We will cooperate fully with the School’s, Practitioner’s, or Agency’s investigation and assist in any mandatory legal notifications to parents or state agencies.
8. Updates to this Policy
We will not modify this Policy or our Terms of Service in a way that reduces protections for Student Data without providing explicit, advance notice to our partnering Schools, Practitioners, or Agencies. Material changes require affirmative consent or contract updates to ensure that the School, Practitioner, or Agency remains FERPA-compliant.
(Updated 7/13/26)
