Privacy at a Glance
This summary highlights Adelfa Digital LLC's core privacy commitments. The complete Policy that follows controls if a summary and the detailed text differ.
| Commitment | What it means |
|---|---|
| School control | Schools and other organizational customers create and control accounts, permissions, data access, and authorized educational uses. |
| Student data | Adelfa uses identifiable student data only to provide school-authorized services and does not sell it, use it for targeted advertising, or build unrelated commercial profiles. |
| Parents and students | Parents, guardians, and students normally exercise record-access, correction, and deletion rights through the school that controls the record. |
| AI features | AI-assisted outputs are optional, school-directed, and advisory. Identifiable student data is not used to train public or general-purpose AI models without express written authorization. |
| Security and retention | Adelfa uses commercially reasonable safeguards, limits retention, offers a 30-day post-contract export period, and deletes data as described in customer agreements. |
| Website visitors | The public Website may collect contact-form information, communications, server logs, device information, and essential cookie data. Adelfa does not use the Website for behavioral advertising. |
Important school-record notice
When Adelfa processes information for a school, district, county office, union, nonprofit, or other organizational customer, that customer generally determines why and how the information is used.
Do not send live student records, health information, credentials, Social Security numbers, or other sensitive information through the public Website contact form unless Adelfa has expressly provided an approved secure method.
1. Scope of This Policy
This Policy applies to:
- visitors to the public Website and public informational pages;
- representatives of prospective, current, and former organizational customers;
- school employees, educators, administrators, counselors, nurses, and other authorized personnel;
- students, parents, guardians, and eligible students who access a Service through an institution-controlled account or portal;
- support contacts, vendors, professional advisers, and other persons who communicate with Adelfa; and
- information processed by Adelfa when operating, securing, supporting, and improving the Services.
This Policy does not govern a third-party website, application, integration, or service that is operated independently and has its own privacy notice. It also does not replace a school's own notices, policies, record-access procedures, or legal obligations.
2. Roles and Relationship to Educational Customers
For information submitted by or on behalf of an educational customer, the customer generally determines the educational or administrative purpose, the authorized users, the source records, the access rules, and the retention requirements. Adelfa acts as a school-directed service provider, contractor, or school official when applicable.
The customer creates or approves accounts and determines whether a parent, guardian, student, employee, or other person may access specific information. Adelfa does not independently decide custody rights, enrollment status, educational interest, or entitlement to records unless a signed agreement expressly assigns a limited verification function to Adelfa.
For personal information Adelfa collects directly for its own business purposes, such as Website inquiries, vendor contacts, billing administration, and security logs, Adelfa determines the purposes described in this Policy.
3. Definitions
"Authorized User" means a person whose access to a Service is approved by an organizational customer or by Adelfa for an authorized business purpose.
"Customer" means a school, school district, county office of education, public agency, union, nonprofit, education-related organization, business, sole proprietorship, or other entity that obtains Services from Adelfa.
"Customer Data" means information, records, files, content, configurations, credentials, logs, and materials submitted to, stored in, generated through, or transmitted by the Services for a Customer.
"De-Identified Data" means information processed so that it cannot reasonably identify, describe, be linked to, or be associated with a particular individual, student, parent, or household, considering reasonably available information.
"Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household, including information treated as personal information under applicable law.
"Student Data" means education records, pupil records, covered information, pupil-generated content, and other personal information concerning a current or former student that is processed through a Service.
"Subprocessor" means a third party that processes Customer Data on Adelfa's behalf to provide, host, secure, maintain, or support the Services.
4. Information Adelfa Collects
4.1 Website and Inquiry Information
When a person visits the Website, requests information, asks for a quote, or contacts Adelfa, Adelfa may collect:
- name, email address, telephone number, organization, job title, and professional role;
- the contents of messages, forms, attachments, project descriptions, and requested follow-up;
- communication preferences and records of correspondence; and
- information reasonably necessary to prevent spam, abuse, fraud, or unauthorized access.
4.2 Customer, Contract, and Billing Information
- customer and authorized representative names, work contact information, organization, title, and authority;
- proposals, statements of work, order forms, purchase orders, contracts, approvals, and implementation records;
- invoice details, tax-exempt documentation, payment status, and transaction confirmation;
- support plans, service configurations, domain and hosting information, and account administration records; and
- insurance, procurement, security review, and compliance information exchanged during contracting.
If electronic payment services are later offered, payment-card or bank information may be collected directly by a payment processor. Adelfa does not intend to store complete payment-card numbers unless expressly disclosed and supported by appropriate controls.
4.3 Account and Authentication Information
- usernames, customer or school identifiers, role assignments, permissions, and account status;
- password hashes, multifactor-authentication status, recovery information, and sign-in records;
- session identifiers, login timestamps, failed login attempts, and security events; and
- records of account creation, approval, modification, suspension, and deletion.
4.4 Student, Parent, and School Information
Depending on the application and the Customer's instructions, the Services may process the following categories. Not every Service collects every category.
- student names, student identification numbers, grade level, school, program, class, schedule, and enrollment information;
- attendance, tardiness, credits, grades, GPA, academic pathways, assignments, preliminary grading information, and progress records;
- discipline, referral, behavior, social-emotional, counseling, intervention, reward, eligibility, and activity-participation records;
- health-office or nurse check-in information, accommodations, disability-related information, and other sensitive records when expressly authorized;
- parent, guardian, emergency-contact, and household contact information;
- staff names, roles, employment-related identifiers, schedules, approvals, and work contact information;
- student work, essays, reports, portfolios, files, photographs, audio, documents, and other uploaded or generated content;
- communications, notifications, acknowledgments, form submissions, and electronic signatures; and
- system-generated reports, audit trails, eligibility results, alerts, summaries, and other records produced through authorized use.
The Services are not intended to require Social Security numbers, financial-account details, or similarly high-risk identifiers unless a specific Customer agreement expressly authorizes the collection and establishes appropriate safeguards.
4.5 Technical, Device, Usage, and Log Information
- internet protocol address, approximate location derived from an IP address, browser type, operating system, device type, and language;
- pages viewed, features used, links selected, referring and exit pages, timestamps, session duration, and navigation events;
- error reports, application events, performance measurements, backup status, database events, and diagnostic records;
- security logs, authentication events, access logs, rate-limit events, and indicators of malicious or prohibited activity; and
- cookie identifiers and similar technical data used for essential operation, authentication, preferences, security, or limited analytics.
4.6 Support and Service Communications
- support requests, screenshots, attachments, diagnostic details, and correspondence;
- information provided during training, implementation, troubleshooting, or security reviews; and
- records of notices, maintenance communications, incident communications, and service changes.
4.7 AI-Assisted and Automated Outputs
When a Customer enables an authorized feature, the Services may generate preliminary grading suggestions, summaries, classifications, pattern descriptions, behavior-related profiles, recommendations, or rule-based eligibility results. These outputs may constitute Customer Data or Student Data when they relate to an identifiable person.
5. Sources of Information
Adelfa may receive information from:
- the individual who visits the Website, contacts Adelfa, or uses a Service;
- a Customer, school, district, teacher, administrator, counselor, nurse, or other authorized representative;
- a parent, guardian, student, eligible student, or other Authorized User;
- customer-authorized systems and integrations, such as student information systems, identity providers, learning systems, email services, or file imports;
- devices, browsers, servers, databases, security tools, and other technologies used to access or operate the Services;
- Adelfa's hosting, communications, security, support, accounting, and professional-service providers; and
- publicly available sources or government records when reasonably necessary for contracting, verification, or legal compliance.
6. How Adelfa Uses Information
Adelfa may use information to:
- provide, host, configure, personalize, maintain, and support the Services;
- create and administer accounts, authenticate users, enforce permissions, and provide authorized access;
- import, organize, display, calculate, analyze, transmit, export, and delete data as directed by a Customer;
- communicate about inquiries, proposals, contracts, implementation, training, support, maintenance, renewals, and incidents;
- process invoices, purchase orders, payments, accounting records, taxes, and business administration;
- monitor performance, troubleshoot errors, test recovery, prevent abuse, investigate security events, and protect students, users, Customers, and systems;
- develop and improve features using Customer-authorized data or De-Identified Data, consistent with applicable agreements;
- generate AI-assisted or rule-based outputs only for authorized educational, administrative, operational, or support purposes;
- comply with law, court orders, public-record obligations, audits, insurance requirements, and contractual duties;
- establish, exercise, or defend legal claims and enforce agreements; and
- complete a merger, financing, reorganization, acquisition, or sale subject to the protections described in this Policy.
Adelfa will not use identifiable Student Data for an unrelated commercial purpose merely because the data is technically available to Adelfa.
7. School-Directed Student Data
7.1 Customer Ownership and Control
As between Adelfa and the Customer, the Customer owns and controls Customer Data. Adelfa does not acquire ownership of identifiable Student Data. Adelfa processes Student Data only for the school-authorized educational, administrative, operational, support, security, and compliance purposes described in the Customer agreement.
7.2 Parent, Guardian, and Student Requests
A parent, guardian, student, or eligible student who wants to inspect, correct, export, delete, or challenge a school record should normally contact the school or organization that controls the record. Adelfa will refer the request to the Customer and provide reasonable technical assistance. Adelfa may verify the requester's identity and authority, and will not disclose a school record directly when doing so would conflict with the Customer's instructions, custody information, school policy, or applicable law.
7.3 FERPA
When a Customer discloses education records under the Family Educational Rights and Privacy Act (FERPA) school-official framework, Adelfa will, to the extent applicable, perform the contracted institutional function, remain under the Customer's direct control regarding the use and maintenance of education records, use personally identifiable information only for the purpose for which it was disclosed, and limit redisclosure as required by law and the applicable agreement.
7.4 COPPA
Some Services may be used by children under 13 in a school-authorized educational context. When the Children's Online Privacy Protection Act (COPPA) applies, Adelfa will comply with its obligations as an operator. Adelfa may rely on school authorization only when legally permitted and only for the authorized educational use. Adelfa will seek direct verifiable parental consent when COPPA requires it and school authorization is not sufficient.
7.5 California Student Privacy
For covered K-12 Services, Adelfa will comply with applicable California pupil-record and operator requirements, including contractual controls, reasonable security, access and correction support, deletion procedures, restrictions on targeted advertising and sale, and limits on profiling unrelated to K-12 school purposes.
7.6 Sensitive School Records
Health-office, counseling, discipline, special education, disability, immigration, reproductive or sexual health, precise geolocation, and similarly sensitive records should be included only when needed for an authorized Service and expressly approved by the Customer. Adelfa may require additional safeguards, a separate schedule, or a signed amendment before processing unusually sensitive categories.
8. Artificial Intelligence and Automated Processing
8.1 Optional, Customer-Directed Features
A Customer decides whether to enable an AI-assisted feature, which users may access the feature, what data may be submitted, and the educational or administrative purpose. Adelfa does not independently activate an AI-assisted feature for a school without authorization.
8.2 Human Review
AI-assisted outputs may be incomplete, inaccurate, biased, inconsistent, or unsuitable for a particular student or context. Unless a signed agreement expressly provides otherwise, a qualified Customer representative must review an AI-assisted output before it materially affects a grade, discipline decision, placement, service, intervention, or other significant educational outcome.
8.3 De-Identification and Model Training
When an external or general-purpose AI provider is used, Adelfa will seek to de-identify Student Data before transmission whenever the feature can function without identifiable information. Adelfa will not use identifiable Student Data to train, fine-tune, evaluate, or improve a public or general-purpose AI model without the Customer's express written authorization and any legally required consent.
8.4 Rule-Based Eligibility
A Service may automatically apply objective criteria configured or approved by a Customer, such as grade, GPA, attendance, credit, deadline, or discipline thresholds, to display eligibility for athletics, dances, activities, rewards, attendance recovery, or similar programs. The Customer defines the rules, source records, exceptions, review procedures, and override authority. Authorized staff should have a means to review and correct inaccurate data or configuration.
8.5 Transparency and Contesting Results
Customers are responsible for notices, policies, review procedures, and appeal or correction processes required for their use of AI-assisted or automated features. A student or parent who questions an output should contact the school or organization responsible for the underlying decision.
9. Cookies, Similar Technologies, and Tracking Choices
9.1 Essential Technologies
The Website and Services may use cookies, session identifiers, local storage, and similar technologies that are reasonably necessary for authentication, security, preferences, load balancing, form operation, fraud prevention, and basic functionality. Disabling essential technologies may prevent a Service from working correctly.
9.2 Analytics and Performance
Adelfa may use limited first-party or service-provider analytics to understand Website traffic, diagnose errors, and improve performance. Adelfa does not use analytics data to target advertising to students or to build unrelated commercial profiles. If Adelfa introduces a materially different third-party analytics or advertising technology, Adelfa will update this Policy and provide consent or opt-out tools when required.
9.3 Do Not Track
Some browsers transmit a "Do Not Track" signal. Because there is no universally accepted technical standard for interpreting these signals, the Website does not currently respond to browser Do Not Track signals as a separate request. Adelfa's practices remain governed by this Policy.
9.4 Global Privacy Control and Opt-Out Preference Signals
Adelfa does not sell or share personal information for cross-context behavioral advertising. To the extent an applicable privacy law requires recognition of a legally valid opt-out preference signal, such as Global Privacy Control, Adelfa will process the signal as required for the browser or device from which it is received.
9.5 Third-Party Collection Across Services
Infrastructure, security, email, form-protection, analytics, or integration providers may collect technical information when their service is used. They may not use Customer Data or Student Data for unrelated advertising or commercial profiling when acting as Adelfa's provider. A third-party service selected or enabled directly by a Customer may operate under its own privacy policy.
10. How Adelfa Discloses Information
Adelfa may disclose information to the following categories of recipients:
- the Customer and Authorized Users, according to Customer-controlled permissions and workflows;
- hosting, domain, database, backup, content-delivery, email, communications, security, monitoring, support, accounting, and other service providers that need the information to perform a contracted function;
- customer-authorized student information systems, identity providers, learning platforms, communication systems, and other integrations;
- professional advisers, including attorneys, accountants, auditors, insurers, and consultants, subject to appropriate confidentiality duties;
- government agencies, courts, law enforcement, regulators, or other persons when disclosure is required by law or reasonably necessary to protect rights, safety, students, users, Customers, or systems;
- a successor or prospective successor in a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, subject to confidentiality and continued protection of previously collected Student Data; and
- another recipient when the Customer or the affected individual provides valid authorization and the disclosure is permitted by law.
Adelfa requires a Subprocessor that processes Customer Data to use the information only for limited, specified purposes and to maintain privacy, confidentiality, and security obligations appropriate to the data and service.
11. No Sale, No Targeted Advertising, and No Unrelated Profiling
Adelfa does not knowingly:
- sell or rent Student Data;
- sell or share personal information for cross-context behavioral advertising;
- use Student Data or persistent identifiers to target advertisements to a student;
- build or amass a commercial profile of a student for a purpose unrelated to an authorized K-12 school purpose;
- market unrelated products or services to students or families based on Student Data; or
- combine identifiable Student Data with data from advertising networks, data brokers, or unrelated consumer services for a noneducational purpose.
Adelfa may communicate with adult customer representatives about Adelfa's own services, proposals, renewals, or related educational technology offerings. Recipients may opt out of nonessential promotional email as described below.
12. De-Identified and Aggregated Information
Adelfa may create and use aggregated or properly De-Identified Data for security, diagnostics, capacity planning, performance measurement, product improvement, research on service effectiveness, and development of educational software. Adelfa will maintain measures designed to prevent re-identification and will not attempt to re-identify De-Identified Data except when reasonably necessary to test whether de-identification methods are effective and when permitted by law and contract.
Adelfa will not publicly release a small-cell report, case study, benchmark, or other analysis if the information could reasonably identify a student, family, employee, or Customer without authorization.
13. Data Retention, Return, and Deletion
13.1 General Retention Standard
Adelfa retains personal information only for as long as reasonably necessary for the disclosed purpose, the Customer agreement, security, legal compliance, dispute resolution, or another permitted purpose. Retention depends on the type of information, sensitivity, operational need, legal requirements, and the risk of continued retention.
13.2 Customer and Student Data
Customer and Student Data is retained during the applicable service term according to the Customer agreement and configured retention rules. Unless a signed agreement provides otherwise, a Customer will have 30 days after expiration or termination to request or complete an available data export. Adelfa will then delete or render inaccessible the applicable data from active systems, subject to legal holds and limited administrative records.
13.3 Backups
Deleted data may remain temporarily in protected backups until the backup expires or is securely overwritten through the normal rotation. Backup copies are not restored to active use except for disaster recovery, security, legal compliance, or another authorized purpose.
13.4 Typical Retention Periods
| Category | Typical period or criteria |
|---|---|
| Website inquiries and correspondence | Typically up to 24 months after the last meaningful interaction, unless a longer period is needed for a proposal, contract, legal matter, or request. |
| Customer contracts, invoices, and business records | For the contract term and generally up to seven years afterward, or longer when required by law, audit, insurance, or dispute needs. |
| Account and authentication records | For the account or service term and a reasonable period afterward for security, audit, and legal purposes. |
| Technical and security logs | Generally 12 to 24 months, unless a shorter period is configured or a longer period is needed to investigate an incident or comply with law. |
| Customer and Student Data | As directed by the Customer agreement, followed by the 30-day export period and deletion process described above. |
| De-Identified or aggregated data | As long as it remains de-identified and useful for a permitted purpose. |
14. Security and Security Incidents
14.1 Safeguards
Adelfa maintains a risk-based information security program designed to protect personal information against unauthorized or illegal access, acquisition, use, alteration, loss, destruction, or disclosure. Depending on the Service and risk, safeguards may include access controls, multifactor authentication for administrators, encryption, secure configuration, logging, backups, patching, malware protection, vulnerability management, confidentiality requirements, and incident-response procedures.
14.2 Shared Responsibility
Security also depends on Customers and Authorized Users. Customers are responsible for approving access, maintaining accurate user roles, promptly disabling unnecessary accounts, using supported devices and networks, protecting credentials, and notifying Adelfa of suspected misuse or unauthorized access.
14.3 No Absolute Guarantee
No system, transmission, or storage method can be guaranteed to be completely secure. Adelfa does not promise that a security incident, data loss, or service interruption will never occur.
14.4 Security Incident Notification
When Adelfa discovers a Security Incident involving Customer Data in Adelfa's custody or control, Adelfa will notify the affected Customer without unreasonable delay and, in any event, within 72 hours after confirming the incident or within any shorter period required by law. Adelfa will provide reasonably available information and cooperation needed for the Customer to assess the incident and meet its own notice obligations, including California's requirement to notify affected individuals within 30 calendar days after discovery of a breach. When Adelfa is itself required by law or a signed agreement to notify affected individuals or authorities, Adelfa will do so within the legally required timeframes, including those in California Civil Code sections 1798.29 and 1798.82.
15. Privacy Choices and Requests
15.1 Website and Business Contact Information
A person may ask Adelfa to access, correct, or delete personal information Adelfa controls directly by emailing legal@adelfadigital.com. The request should describe the information and the requested action. Adelfa may need to verify identity, authority, or the email address associated with the information.
15.2 School-Controlled Records
Requests involving school-controlled Student Data should be submitted to the school or organization. Adelfa will assist the Customer as required by law and contract. Adelfa may be unable to fulfill a direct request when the Customer must make the legal or educational determination.
15.3 Email Preferences
A recipient may opt out of nonessential promotional email by using the unsubscribe method provided in the message or by contacting Adelfa. Adelfa may continue to send transactional, security, legal, support, and service-related communications.
15.4 Cookie Choices
Browser settings may allow users to delete or block cookies. Blocking essential cookies may prevent login or other features from functioning. If Adelfa later deploys a consent-management tool for nonessential cookies, users may also manage choices through that tool.
15.5 Limits and Exceptions
Adelfa may deny or limit a request when permitted by law, including when Adelfa cannot reasonably verify the request, the information is controlled by a Customer, deletion would interfere with another person's rights, the information must be retained for security or legal reasons, or an exemption applies. Adelfa will explain a denial when required.
16. California and Other State Privacy Rights
Some state privacy laws apply only to organizations that meet statutory thresholds and may exclude or exempt certain education records, nonprofit activity, public-agency records, employee information, or information processed by a service provider. Where an applicable law grants rights, and subject to its exceptions, a resident may have the right to:
- know or confirm whether Adelfa processes personal information and obtain access to specified information;
- request correction of inaccurate personal information;
- request deletion of personal information;
- obtain a portable copy of certain information;
- opt out of the sale or sharing of personal information, targeted advertising, or certain profiling;
- limit certain uses or disclosures of sensitive personal information when the right applies;
- use an authorized agent to make a request; and
- receive equal service and not be discriminated against for exercising a privacy right.
Adelfa does not sell personal information or share it for cross-context behavioral advertising, and does not use sensitive personal information for purposes that require a right to limit under the California Consumer Privacy Act. If those practices change, Adelfa will update this Policy and provide legally required controls.
To submit a request, email legal@adelfadigital.com. Adelfa may ask for information reasonably necessary to verify identity, residence, authority, or the scope of the request. An authorized agent may be required to provide written authorization, and Adelfa may also verify the request directly with the individual. Where an appeal right applies, the response will explain how to appeal.
Even when a particular comprehensive state privacy law does not apply to Adelfa, Adelfa may voluntarily honor a reasonable request when doing so is consistent with Customer instructions, security, record integrity, and applicable law.
17. Children and Minors
The public Website is intended for adult representatives of schools, organizations, and prospective customers. Adelfa does not offer direct consumer purchases to children, students, or parents through the Website.
Students, including children under 13, may use a school-authorized Service. Their accounts are ordinarily created or controlled by a school or organizational Customer. Adelfa uses their information only for authorized educational and operational purposes and does not condition participation on providing more personal information than is reasonably necessary for the applicable activity.
Consistent with the amended federal COPPA Rule, Adelfa retains personal information collected online from a child under 13 only for as long as reasonably necessary to fulfill the specific, school-authorized purpose for which it was collected, and never indefinitely. When that information is no longer reasonably necessary, Adelfa deletes it in accordance with Section 13, the applicable customer agreement, and Adelfa's written data-retention policy.
A California minor who is a registered user and wants removal of content the minor posted should generally contact the school controlling the account or email legal@adelfadigital.com. Removal from public view does not necessarily require complete deletion from protected backups, legal records, or records that another law requires the school or Adelfa to retain.
18. Third-Party Services and Links
The Services may link to or integrate with third-party systems selected by Adelfa or a Customer. A third party may have its own terms and privacy policy. Adelfa is not responsible for an independently operated third party's privacy practices, but Adelfa will use contractual protections for Subprocessors that process Customer Data on Adelfa's behalf.
A current list of authorized Subprocessors for a Customer may be included in the Student Data Privacy and Security Addendum, customer agreement, or provided upon request to legal@adelfadigital.com.
19. United States Services and Data Location
Adelfa currently offers the Services for customers and users located in the United States. Unless a signed agreement states otherwise, Adelfa intends to host and process production Customer Data in the United States. A person accessing the Website or Services from another country understands that information may be transferred to and processed in the United States.
20. Changes to This Policy
Adelfa may update this Policy to reflect changes in law, Services, technology, security practices, or business operations. Adelfa will post the revised Policy with a new effective date. When a change is material, Adelfa will provide additional notice through the Website, Service, email, or Customer communication as appropriate.
A change to this online Policy will not materially reduce a Customer's contractual student-data protections during an active paid term unless the Customer agrees in writing or the change is required by law or reasonably necessary to address an urgent security risk.
21. Accessibility
Adelfa intends to make this Policy available in a readable and accessible format. A person who needs this Policy in an alternative format or has difficulty accessing it may contact legal@adelfadigital.com. Product-specific accessibility requirements, testing standards, and remediation obligations are established separately for each project or Customer agreement.
22. Contact Information
Questions, requests, and privacy notices may be sent to:
Adelfa Digital LLC
Attn: Privacy and Legal
Fresno County, California
Email: legal@adelfadigital.com
Website: https://adelfadigital.com
For routine technical support, users should use the support channel provided by their school or Customer rather than the legal email address.
Appendix A. Personal Information Categories and Practices
This table summarizes categories Adelfa may collect, sources, principal purposes, and typical recipient categories. The exact practices depend on the Service, Customer instructions, and contract.
| Category | Examples | Sources | Purposes | Recipient categories |
|---|---|---|---|---|
| Identifiers and contact information | Name, email, phone, organization, job title, student or employee identifier, account ID | Individual, Customer, authorized integration | Inquiry response, account administration, service delivery, communications | Customer and Authorized Users; communications, hosting, and support providers |
| Customer and commercial records | Contracts, purchase orders, invoices, payment status, implementation records | Customer, accounting or payment provider | Contracting, billing, procurement, audit, legal compliance | Customer contacts; accounting, payment, legal, insurance, and audit providers |
| Account and authentication data | Username, role, permissions, password hash, MFA status, login and recovery records | Customer, user, identity provider, Service | Authentication, access control, security, audit | Customer administrators; identity, hosting, security, and support providers |
| Education and student records | Enrollment, attendance, grades, GPA, credits, referrals, discipline, counseling, eligibility, rewards, student work | Customer, school personnel, student, parent, SIS or other integration | Authorized educational and administrative Services | Customer and Authorized Users; approved Subprocessors and integrations |
| Sensitive school information | Health-office, disability, accommodation, special education, counseling, discipline, or similar information | Customer and authorized personnel or integrations | Only the specific authorized school purpose | Strictly limited Customer users and approved providers with a need to know |
| Content and communications | Messages, forms, files, photographs, documents, acknowledgments, support attachments | Individual, Customer, Authorized User | Service operation, support, recordkeeping, authorized communication | Customer users; email, storage, hosting, and support providers |
| Device, usage, and log data | IP address, browser, device type, pages, events, errors, access logs, cookie identifiers | Browser, device, servers, security and monitoring tools | Operation, analytics, troubleshooting, security, abuse prevention | Hosting, analytics, monitoring, security, and support providers |
| AI-assisted and automated outputs | Preliminary grading suggestions, summaries, classifications, patterns, eligibility results | Customer-authorized inputs and configured rules | Authorized educational support, reporting, and workflow automation | Customer and Authorized Users; approved AI or processing providers when authorized |
| Inferences and de-identified data | Aggregated usage patterns, performance trends, de-identified metrics | Derived from Service activity or Customer Data | Security, diagnostics, capacity planning, product improvement, effectiveness research | Internal personnel and service providers; public release only when re-identification risk is appropriately controlled |
Appendix B. Selected Legal Framework
This Appendix identifies principal authorities considered in preparing the draft. It is provided for review and does not state that every law applies to every Service or circumstance.
California Online Privacy Protection Act (CalOPPA). California Business and Professions Code sections 22575-22579. Requires covered commercial websites and online services to post a privacy policy addressing collected categories, third-party categories, review processes if offered, policy changes, effective date, Do Not Track practices, and certain third-party tracking.
California Consumer Privacy Act, as amended. California Civil Code sections 1798.100 et seq. and applicable regulations. Provides privacy notices and consumer rights for covered businesses, subject to thresholds and exemptions.
Family Educational Rights and Privacy Act (FERPA). 20 U.S.C. section 1232g and 34 C.F.R. Part 99. Governs education records and permits qualifying contractors to act within the school-official framework under school control and purpose limitations.
Children's Online Privacy Protection Act and Rule (COPPA). 15 U.S.C. sections 6501-6506 and 16 C.F.R. Part 312. Applies to covered online collection from children under 13 and includes notice, consent, access, security, minimization, and retention requirements. The Rule was substantially amended effective June 23, 2025, with a compliance deadline of April 22, 2026, adding written information-security-program, written data-retention-policy, and expanded notice requirements.
California pupil-record contracts. California Education Code section 49073.1. Requires specified terms when a local educational agency contracts with a third party for digital storage, management, and retrieval of pupil records.
California K-12 pupil online privacy protections. California Business and Professions Code sections 22584 et seq. Restricts sale, targeted advertising, unrelated profiling, and certain disclosures, and requires reasonable security and deletion practices for covered operators.
California data breach notification laws. California Civil Code sections 1798.29 and 1798.82. Require notice to affected California residents within 30 calendar days after discovery of a breach (as amended effective January 1, 2026), notice to the Attorney General within 15 calendar days after individual notification when more than 500 California residents are notified, and prompt notice to the owner or licensee of breached data that a business maintains but does not own.
California Consumer Privacy Act regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits. Finalized in 2025, with phased compliance beginning January 1, 2026. These regulations apply only to businesses that meet CCPA thresholds; they are identified here for monitoring because AI-assisted features and significant automated decisions may become subject to notice, opt-out, and risk-assessment requirements if Adelfa meets those thresholds in the future.