Data Breach Policy
Last modified: August 2025
The Company takes the security of your information seriously. In the event of a data breach involving personal data, we will promptly investigate and take appropriate steps to mitigate the impact. Affected individuals and institutions will be notified in accordance with applicable state and federal laws. Notification timeframe will not exceed 15 days after the event is detected. We maintain technical and organizational safeguards to help prevent unauthorized access, disclosure, or misuse of personal information.
The Company implements a range of administrative, technical, and physical safeguards to protect personal information, including:
- Encryption of data in transit and at rest
- Secure access controls to restrict information to authorized personnel only
- Routine system monitoring for unauthorized activity
- Firewall and intrusion detection systems
- Regular employee training on data protection, privacy practices, and PCI compliance
- Data minimization practices to limit the collection of personal information
In the event of a breach, we follow documented incident response protocols to contain, assess, and notify affected parties in accordance with legal requirements.
Incident Response Checklist
- Identify & Contain
- Detect breach (automated alert, employee report, etc.)
- Immediately isolate affected systems
- Preserve logs and evidence
- Assess the Scope
- Determine what data was exposed (type, volume, PII)
- Identify affected individuals or school partners
- Assess risks (identity theft, reputational, regulatory)
- Notify Stakeholders
- Alert internal leadership and legal counsel
- Notify affected schools, parents, or users
- Report to authorities if legally required (e.g., state AG, FTC)
- Remediate
- Patch vulnerabilities
- Reset compromised credentials
- Review third-party access
- Communicate Transparently
- Draft and send notifications with clear guidance to affected parties
- Post incident FAQs if applicable
- Document & Improve
- Complete a breach report and root cause analysis
- Update policies or training based on findings
- Conduct a postmortem with the team