Data Breach Policy
Updated: May 2026
The Company takes the security of your information seriously. In the event of a data breach involving personal data, we will promptly investigate and take appropriate steps to mitigate the impact. Affected individuals and institutions will be notified in accordance with applicable state and federal laws. Notification timeframe will not exceed 15 days after the event is detected. We maintain technical and organizational safeguards to help prevent unauthorized access, disclosure, or misuse of personal information.Â
The Company implements a range of administrative, technical, and physical safeguards to protect personal information, including:Â
- Encryption of data in transit and at rest
- Secure access controls to restrict information to authorized personnel onlyÂ
- Routine system monitoring for unauthorized activityÂ
- Firewall and intrusion detection systemsÂ
- Regular employee training on data protection, privacy practices, and PCI complianceÂ
- Data minimization practices to limit the collection of personal informationÂ
In the event of a breach, we follow documented incident response protocols to contain, assess, and notify affected parties in accordance with legal requirements.Â
Incident Response ChecklistÂ
- Identify & Contain
- Detect breach (automated alert, employee report, etc.)Â
- Immediately isolate affected systems
- Preserve logs and evidenceÂ
- Assess the ScopeÂ
- Determine what data was exposed (type, volume, PII)Â
- Identify affected individuals or school partnersÂ
- Assess risks (identity theft, reputational, regulatory)Â
- Notify StakeholdersÂ
- Alert internal leadership and legal counselÂ
- Notify affected schools, parents, or usersÂ
- Report to authorities if legally required (e.g., state AG, FTC)Â
- RemediateÂ
- Patch vulnerabilitiesÂ
- Reset compromised credentialsÂ
- Review third-party accessÂ
- Communicate TransparentlyÂ
- Draft and send notifications with clear guidance to affected partiesÂ
- Post incident FAQs if applicableÂ
- Document & ImproveÂ
- Complete a breach report and root cause analysisÂ
- Update policies or training based on findingsÂ
- Conduct a postmortem with the teamÂ