Privacy Policy
1. Who controls the information
The School that deploys RSIS determines why and how institutional data is processed and is the primary contact for privacy requests. Authorized hosting, email, learning, payment, support, and technology providers may process data for the School under applicable agreements. RSIS is not a data broker and School data must not be used for unrelated advertising.
2. Information collected
- Identity and contact: names, identifiers, student or employee numbers, usernames, addresses, emails, phones, relationships, guardians, photographs, and emergency contacts.
- Education: applications, enrollment, programs, classes, attendance and participation, grades, assessments, responses, learning activity, accommodations, IEP/504 services, transcripts, discipline, and credentials.
- Finance and aid: charges, receipts, refunds, payment terms, account balances, financial-aid eligibility and reconciliation data, payroll, tax configuration, purchasing, and accounting records. Avoid storing full card or bank credentials unless a separately approved payment service and controls are configured.
- Employment and operations: job, department, evaluation, payroll profile, contract, time, task, workflow, communications, safety, support, compliance, and controlled-document records.
- Sensitive and regulated: disability, health, special education, Title IX, safety, demographic, immigration/eligibility, tax, consent, and disclosure-accounting data when authorized and necessary.
- Technical and evidence: device/browser data, IP address, timestamps, authentication and audit events, uploads, signatures, delivery/receipt evidence, assessment response time, and paste-event indicators.
3. Sources
Data comes from students, applicants, parents/guardians, employees, suppliers, School personnel, authorized records and integrations, learning activity, public support or survey forms, and legally authorized agencies or service providers.
4. Purposes and authority
The School uses information to provide education; manage admissions, enrollment, attendance, assessment, student services, financial aid, billing and records; employ and pay staff; communicate; provide safety and support; approve documents and transactions; meet accreditation, reporting, audit, retention, and legal duties; secure RSIS; investigate misuse; and improve services. Depending on context, authority may include performance of the educational relationship or contract, consent, protection of vital interests, compliance with law, public or institutional duties, and legitimate operational interests that do not override protected rights.
5. Education records and FERPA
Parents and eligible students have FERPA rights described in the School’s annual notice, including rights to inspect and review education records, seek amendment, consent to most disclosures, and file a complaint with the U.S. Department of Education. FERPA permits certain disclosures without consent, subject to conditions. RSIS records disclosures, exceptions, consent, and revocation where configured. Contact the School—not a software screen alone—to exercise rights or challenge an official record. Directory information is handled only under the School’s approved notice and opt-out rules.
6. Children and COPPA
For online services directed to children under 13, the School and its operators must apply COPPA as applicable, including notice, verifiable parental consent or a valid exception, parent access/deletion choices, data minimization, security, and limited retention. School authorization may cover only an educational context for the School’s benefit and not an operator’s unrelated commercial use. Public forms should collect only information necessary for the stated educational purpose.
7. How information may be shared
Information may be disclosed to authorized School officials with legitimate educational or business interests; parents, eligible students, or representatives as permitted; service providers acting for the School; financial-aid and education agencies; auditors, accreditors, health or safety responders, law enforcement, courts, and regulators when legally authorized; and other recipients with valid consent or legal authority. Each user must verify identity, authority, purpose, minimum necessary scope, and required documentation before disclosure. RSIS data must not be sold or used for targeted advertising based on education records.
8. Gmail, Moodle, and links
If enabled by the School, Gmail may route notices and signed documents and Moodle may provide learning services. Information sent to those services is limited by School configuration, contracts, permissions, and the providers’ terms. Administrators should use institution-managed accounts, least privilege, approved retention, and appropriate data-processing agreements.
9. Cookies, sessions, and local/offline data
RSIS uses necessary browser storage for authentication, remembered login, preferences, and continuity. Remembered login persists until expiration or invalidation and should be used only on private devices. Mobile or desktop clients may temporarily store authorized transactions offline and synchronize later; the School must secure device storage and remote access. RSIS does not require advertising cookies.
10. Security
RSIS provides role permissions, authentication, audit logging, soft deletion, integrity evidence, and purpose-bound AES-256-GCM field encryption when configured with an available key. Encryption reduces risk but cannot guarantee absolute security. The School is responsible for production key custody and rotation, TLS, database/network hardening, backups, monitoring, incident response, vendor review, training, and timely access removal. Report suspected incidents immediately.
11. Retention and deletion
The School retains records according to applicable education, financial-aid, tax, employment, safety, accreditation, litigation-hold, and state schedules. Transactional records may be marked inactive rather than physically deleted to preserve required evidence. Data no longer needed must be securely deleted or de-identified when lawful; a deletion request may be denied where retention or record-integrity duties apply.
12. Choices and rights
Subject to identity verification, role, and applicable law, individuals may request access, correction, consent withdrawal or revocation, restriction, deletion, a copy, or information about disclosures. Consent revocation is prospective and does not invalidate processing or disclosures already lawful. Parents’ rights transfer to the student under FERPA when the student becomes eligible, subject to exceptions. State and international laws may provide additional rights. The School will not retaliate for exercising protected rights.
13. Accessibility
The School should provide accessible notices and effective communication, including alternate formats and reasonable modifications where required. Report a barrier through the School’s accessibility contact. Accessibility requests do not reduce privacy protections.
14. Automated indicators
Adaptive assessments, writing analysis, participation calculations, risk flags, and similar tools provide decision support. The School should disclose material use, validate results, limit data, and provide appropriate human review and challenge procedures. Paste-event detection is an indicator, not proof of plagiarism or AI use.
15. Incidents, changes, and contact
The School will investigate suspected breaches and provide notices required by applicable law. Material policy revisions receive a new effective date and, where required, renewed notice or consent. Privacy questions and requests should be directed to the School’s published privacy official. FERPA complaints may also be directed to the U.S. Department of Education’s Student Privacy Policy Office.
