Privacy Policy

Last updated: draft, not yet published.

This is a starting draft, not a reviewed legal document. It describes what the system technically does today as a basis for your own compliance review (including FERPA, if applicable to your use) — it is not a substitute for that review and hasn't been checked by counsel.

What data this collects

The product actively discourages entering student information — the request form reminds submitters not to include it — but the system does not scan or block free-text fields for student PII. Don't rely on it as a technical control for that; treat it as a policy your staff need to follow.

Multi-tenant isolation

Each customer organization's data is isolated at the database layer (row-level security), not just in the application. One organization cannot query or see another organization's data through the product.

Sub-processors

Retention and deletion

Removing a person, building, room, or asset marks it inactive (soft delete) rather than immediately erasing it, so history and the audit trail stay intact. [Add your organization's actual retention period and hard-deletion process before publishing.]

Contact

Questions about this policy: [add a real contact address before publishing].