Last Updated: [INSERT DATE]
DRAFT — For review by a licensed attorney before publication, particularly regarding FERPA, COPPA, and state student-privacy law compliance. Bracketed items must be completed before use.
This Privacy Policy explains how [YOUR LEGAL ENTITY NAME] ("Reliora," "we," "us") collects, uses, discloses, and protects information in connection with the Reliora platform (the "Service"), which schools and districts (each, a "School") use to import student roster data and connect students with school counselors.
Reliora provides the Service to Schools under contract, including a Data Processing Agreement ("DPA"). Reliora acts on behalf of, and under the direction of, each School with respect to student education records, consistent with the Family Educational Rights and Privacy Act (FERPA). Where this Policy and a School's DPA differ, the DPA controls as to that School's data.
This Policy is directed primarily at School administrators and, where applicable, parents/guardians and eligible students. If you are a parent, guardian, or eligible student with questions about a specific student's data, please contact your School directly, as the School is the primary holder of education records; the School can also direct inquiries to Reliora.
We collect the following categories of information in connection with the Service:
We use the information described above solely to:
We do not use student data for advertising, do not sell student data, and do not use student data to build behavioral or marketing profiles outside the educational purpose described above.
Reliora processes student education records as a "school official" with a legitimate educational interest, under the direct control of the School, and strictly for the purposes authorized by the School, consistent with FERPA's school official exception. Data is processed pursuant to a DPA executed with each School.
Where a student is under 13 years of age, data collection through the Service is undertaken as part of the School's educational program, consistent with the Children's Online Privacy Protection Act (COPPA) and its provisions for school-authorized consent. [INSERT: describe your specific consent mechanism if you collect data directly from students outside of School-provided consent.]
We share information only as follows:
We do not sell personal information and do not share student data with third parties for their own marketing purposes.
Each School's data is logically segregated within the Service. Access controls and permission checks are enforced so that administrators, counselors, and students at one School cannot access another School's roster or message data through ordinary use of the Service.
We retain School Data for as long as the School maintains an active account, and thereafter for [INSERT RETENTION PERIOD, e.g., 30/60/90 days] to allow for transition or export, unless a longer period is required by law or requested by the School. Upon a School's request, or upon contract termination, we will delete or return School Data within [INSERT TIMEFRAME] in accordance with the DPA, including from active systems and backups on the applicable backup rotation schedule.
We use administrative, technical, and physical safeguards designed to protect information, including encryption of data in transit and at rest, role-based access controls, and audit logging of access to student records. No system is completely secure; in the event of a breach affecting personal information, we will notify affected Schools in accordance with the timeframe required by the DPA and applicable law (e.g., as required under state student-data-privacy statutes).
The Service allows students to flag messages as urgent so they are routed to counselors accordingly. Reliora does not independently monitor message content for crisis indicators except as configured through features the School has enabled. Each School is responsible for its own protocols for reviewing and responding to student messages, including compliance with mandatory reporting laws. Reliora is not an emergency service; students in immediate danger should be directed to call 911 or the 988 Suicide & Crisis Lifeline.
Under FERPA, parents (or eligible students who have reached 18 or are attending a postsecondary institution) have the right to inspect, review, and request correction of education records. Because the School is the official holder of education records, requests to access, correct, or delete student data should be directed to the School, which may in turn coordinate with Reliora to fulfill the request.
The Service may be used by students under the age of 13 where the School has authorized their participation as part of its educational program. We do not knowingly collect personal information directly from children outside of a School-authorized context. [INSERT: additional COPPA-specific consent detail if applicable to your onboarding flow.]
[INSERT: if you serve schools outside the United States, add GDPR or other applicable regional disclosures here; otherwise state that the Service is intended for use by schools located in the United States.]
We may update this Privacy Policy from time to time. We will notify School administrators of material changes by email or in-app notice at least [INSERT NUMBER] days before the changes take effect.
Questions about this Privacy Policy, or requests related to student data, may be directed to: [INSERT: Privacy contact name/role, email address, mailing address.]