← Back to home

Reliora — Privacy Policy

Last Updated: [INSERT DATE]

DRAFT — For review by a licensed attorney before publication, particularly regarding FERPA, COPPA, and state student-privacy law compliance. Bracketed items must be completed before use.

1. Overview

This Privacy Policy explains how [YOUR LEGAL ENTITY NAME] ("Reliora," "we," "us") collects, uses, discloses, and protects information in connection with the Reliora platform (the "Service"), which schools and districts (each, a "School") use to import student roster data and connect students with school counselors.

Reliora provides the Service to Schools under contract, including a Data Processing Agreement ("DPA"). Reliora acts on behalf of, and under the direction of, each School with respect to student education records, consistent with the Family Educational Rights and Privacy Act (FERPA). Where this Policy and a School's DPA differ, the DPA controls as to that School's data.

This Policy is directed primarily at School administrators and, where applicable, parents/guardians and eligible students. If you are a parent, guardian, or eligible student with questions about a specific student's data, please contact your School directly, as the School is the primary holder of education records; the School can also direct inquiries to Reliora.

2. Information We Collect

We collect the following categories of information in connection with the Service:

  • School and account information: school/district name, address, and administrator contact details.
  • Student roster (SIS) data: name, school-issued email or ID, grade level, and school affiliation, as uploaded by the School.
  • Counselor and staff information: name, role, contact details, and assigned students/schools.
  • Message content and metadata: messages sent between students and counselors, timestamps, urgency/category tags, and delivery status.
  • Technical information: device type, browser, IP address, and usage logs, collected automatically for security and troubleshooting.

3. How We Use Information

We use the information described above solely to:

  • Provide, operate, and maintain the Service, including routing student messages to the appropriate counselor;
  • Authenticate users and enforce access controls so each School's data remains isolated from other Schools;
  • Support crisis and urgent-message workflows as configured by the School;
  • Maintain the security, integrity, and reliability of the Service, including detecting and preventing misuse;
  • Communicate with School administrators regarding their account, including service and security notices;
  • Comply with legal obligations and respond to lawful requests from the School or, where legally required, from government authorities.

We do not use student data for advertising, do not sell student data, and do not use student data to build behavioral or marketing profiles outside the educational purpose described above.

4. Legal Basis for Processing Student Data

Reliora processes student education records as a "school official" with a legitimate educational interest, under the direct control of the School, and strictly for the purposes authorized by the School, consistent with FERPA's school official exception. Data is processed pursuant to a DPA executed with each School.

Where a student is under 13 years of age, data collection through the Service is undertaken as part of the School's educational program, consistent with the Children's Online Privacy Protection Act (COPPA) and its provisions for school-authorized consent. [INSERT: describe your specific consent mechanism if you collect data directly from students outside of School-provided consent.]

5. How Information Is Shared

We share information only as follows:

  • With the School: administrators and authorized counselors at the relevant School can access data as configured by that School's roles and permissions.
  • With service providers (subprocessors): companies that host infrastructure, provide cloud storage, or support technical operations, bound by confidentiality and data protection obligations at least as protective as those in our DPA. [INSERT list or link to current subprocessor list.]
  • For legal reasons: where required by law, subpoena, or court order, or to protect the safety of a student or others, including in emergency circumstances.
  • With School consent: for any other purpose the School has specifically authorized.

We do not sell personal information and do not share student data with third parties for their own marketing purposes.

6. Data Isolation Between Schools

Each School's data is logically segregated within the Service. Access controls and permission checks are enforced so that administrators, counselors, and students at one School cannot access another School's roster or message data through ordinary use of the Service.

7. Data Retention and Deletion

We retain School Data for as long as the School maintains an active account, and thereafter for [INSERT RETENTION PERIOD, e.g., 30/60/90 days] to allow for transition or export, unless a longer period is required by law or requested by the School. Upon a School's request, or upon contract termination, we will delete or return School Data within [INSERT TIMEFRAME] in accordance with the DPA, including from active systems and backups on the applicable backup rotation schedule.

8. Security

We use administrative, technical, and physical safeguards designed to protect information, including encryption of data in transit and at rest, role-based access controls, and audit logging of access to student records. No system is completely secure; in the event of a breach affecting personal information, we will notify affected Schools in accordance with the timeframe required by the DPA and applicable law (e.g., as required under state student-data-privacy statutes).

9. Sensitive Messages and Crisis Situations

The Service allows students to flag messages as urgent so they are routed to counselors accordingly. Reliora does not independently monitor message content for crisis indicators except as configured through features the School has enabled. Each School is responsible for its own protocols for reviewing and responding to student messages, including compliance with mandatory reporting laws. Reliora is not an emergency service; students in immediate danger should be directed to call 911 or the 988 Suicide & Crisis Lifeline.

10. Parent and Eligible Student Rights

Under FERPA, parents (or eligible students who have reached 18 or are attending a postsecondary institution) have the right to inspect, review, and request correction of education records. Because the School is the official holder of education records, requests to access, correct, or delete student data should be directed to the School, which may in turn coordinate with Reliora to fulfill the request.

11. Children's Privacy

The Service may be used by students under the age of 13 where the School has authorized their participation as part of its educational program. We do not knowingly collect personal information directly from children outside of a School-authorized context. [INSERT: additional COPPA-specific consent detail if applicable to your onboarding flow.]

12. International Users

[INSERT: if you serve schools outside the United States, add GDPR or other applicable regional disclosures here; otherwise state that the Service is intended for use by schools located in the United States.]

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify School administrators of material changes by email or in-app notice at least [INSERT NUMBER] days before the changes take effect.

14. Contact Us

Questions about this Privacy Policy, or requests related to student data, may be directed to: [INSERT: Privacy contact name/role, email address, mailing address.]