Privacy Policy

Effective: 14 August 2026 · Version: 1.0

Important. This is a system-use privacy notice for the School operating RSIS. It supplements, and does not replace, the School’s annual FERPA notice, directory-information notice and opt-out, COPPA notices/consents, employee notice, financial-aid notices, state notices, and other legally required disclosures. The School must configure its identity and contacts and obtain legal review before production use.

1. Who controls the information

The School that deploys RSIS determines why and how institutional data is processed and is the primary contact for privacy requests. Authorized hosting, email, learning, payment, support, and technology providers may process data for the School under applicable agreements. RSIS is not a data broker and School data must not be used for unrelated advertising.

2. Information collected

3. Sources

Data comes from students, applicants, parents/guardians, employees, suppliers, School personnel, authorized records and integrations, learning activity, public support or survey forms, and legally authorized agencies or service providers.

4. Purposes and authority

The School uses information to provide education; manage admissions, enrollment, attendance, assessment, student services, financial aid, billing and records; employ and pay staff; communicate; provide safety and support; approve documents and transactions; meet accreditation, reporting, audit, retention, and legal duties; secure RSIS; investigate misuse; and improve services. Depending on context, authority may include performance of the educational relationship or contract, consent, protection of vital interests, compliance with law, public or institutional duties, and legitimate operational interests that do not override protected rights.

5. Education records and FERPA

Parents and eligible students have FERPA rights described in the School’s annual notice, including rights to inspect and review education records, seek amendment, consent to most disclosures, and file a complaint with the U.S. Department of Education. FERPA permits certain disclosures without consent, subject to conditions. RSIS records disclosures, exceptions, consent, and revocation where configured. Contact the School—not a software screen alone—to exercise rights or challenge an official record. Directory information is handled only under the School’s approved notice and opt-out rules.

6. Children and COPPA

For online services directed to children under 13, the School and its operators must apply COPPA as applicable, including notice, verifiable parental consent or a valid exception, parent access/deletion choices, data minimization, security, and limited retention. School authorization may cover only an educational context for the School’s benefit and not an operator’s unrelated commercial use. Public forms should collect only information necessary for the stated educational purpose.

7. How information may be shared

Information may be disclosed to authorized School officials with legitimate educational or business interests; parents, eligible students, or representatives as permitted; service providers acting for the School; financial-aid and education agencies; auditors, accreditors, health or safety responders, law enforcement, courts, and regulators when legally authorized; and other recipients with valid consent or legal authority. Each user must verify identity, authority, purpose, minimum necessary scope, and required documentation before disclosure. RSIS data must not be sold or used for targeted advertising based on education records.

8. Gmail, Moodle, and links

If enabled by the School, Gmail may route notices and signed documents and Moodle may provide learning services. Information sent to those services is limited by School configuration, contracts, permissions, and the providers’ terms. Administrators should use institution-managed accounts, least privilege, approved retention, and appropriate data-processing agreements.

9. Cookies, sessions, and local/offline data

RSIS uses necessary browser storage for authentication, remembered login, preferences, and continuity. Remembered login persists until expiration or invalidation and should be used only on private devices. Mobile or desktop clients may temporarily store authorized transactions offline and synchronize later; the School must secure device storage and remote access. RSIS does not require advertising cookies.

10. Security

RSIS provides role permissions, authentication, audit logging, soft deletion, integrity evidence, and purpose-bound AES-256-GCM field encryption when configured with an available key. Encryption reduces risk but cannot guarantee absolute security. The School is responsible for production key custody and rotation, TLS, database/network hardening, backups, monitoring, incident response, vendor review, training, and timely access removal. Report suspected incidents immediately.

11. Retention and deletion

The School retains records according to applicable education, financial-aid, tax, employment, safety, accreditation, litigation-hold, and state schedules. Transactional records may be marked inactive rather than physically deleted to preserve required evidence. Data no longer needed must be securely deleted or de-identified when lawful; a deletion request may be denied where retention or record-integrity duties apply.

12. Choices and rights

Subject to identity verification, role, and applicable law, individuals may request access, correction, consent withdrawal or revocation, restriction, deletion, a copy, or information about disclosures. Consent revocation is prospective and does not invalidate processing or disclosures already lawful. Parents’ rights transfer to the student under FERPA when the student becomes eligible, subject to exceptions. State and international laws may provide additional rights. The School will not retaliate for exercising protected rights.

13. Accessibility

The School should provide accessible notices and effective communication, including alternate formats and reasonable modifications where required. Report a barrier through the School’s accessibility contact. Accessibility requests do not reduce privacy protections.

14. Automated indicators

Adaptive assessments, writing analysis, participation calculations, risk flags, and similar tools provide decision support. The School should disclose material use, validate results, limit data, and provide appropriate human review and challenge procedures. Paste-event detection is an indicator, not proof of plagiarism or AI use.

15. Incidents, changes, and contact

The School will investigate suspected breaches and provide notices required by applicable law. Material policy revisions receive a new effective date and, where required, renewed notice or consent. Privacy questions and requests should be directed to the School’s published privacy official. FERPA complaints may also be directed to the U.S. Department of Education’s Student Privacy Policy Office.