Passr Technologies' Privacy Policy

Last updated: Apr 6, 2022

Summary

Thank you for choosing to be part of Our community at Passr Technologies LLC ("Company," “Passr,” "we," "us," or "our"). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this privacy notice or Our practices with regard to your personal information, please contact us at admin@passr.app.

This privacy notice describes how We might use your information if you:

In this privacy notice, if We refer to:

The purpose of this privacy notice is to explain to you in the clearest way possible what information We collect, how We use it, and what rights you have in relation to it. If there are any terms in this privacy notice that you do not agree with, please discontinue use of Our Services immediately. Please read this privacy notice carefully, as it will help you understand what We do with the information that We collect.

Contents

  1. Information Collection & Use
  2. Information Access & Management
  3. Information Security & Protection
  4. Information Retention
  5. Children's Privacy
  6. Contact
  7. Update Policy

1. Information Collection & Use

Summary: We collect only the information about Districts, Schools, Administrators, Faculty, Staff and Students We need in order to operate Our Services.

Prior to use of Our Services, We only collect school and district related information provided during communications and correspondence with authorized school officials. This information includes, but is not limited to, school and district names, school and/or district faculty names, email addresses, phone numbers, message content and information relating to the school and/or district's current Services and Information Technology systems. We do not collect or save any personally identifiable information about students during initial communications.

During use of Our Services, We collect and track information, content and activity, provided by the school, and their authorized individuals, during use of Our Services ("School Data"). Additionally, schools may choose to authorize Our Services' access to one or more third-party application partners. Passr has access to only data specified by the authorizing party, only for the duration of the authorization, and only for the purpose of operating Our Services for the School. This information includes, but is not limited to, first and last names, emails, phone numbers, cross-service identifiers, and profile pictures. We use School Data for the sole purposes of:

School Data contains personally identifiable information about students ("Student Data"). Student Data enters Our Service in one of three ways:

  1. Imported from an authorized third party service
  2. Entered by an authorized school official
  3. Entered by the student

Passr's access to Student Data is determined by the school and their desired use of Our Services. We only import and collect Student Data specified by the school, on behalf of the school, under direction and supervision of the school. Furthermore, We only import and collect data required to provide the agreed upon Services. Student's access to Our Services are prohibited until appropriate parental consents are obtained and verified, regardless of age. We allow the School to consent on behalf of parents and/or guardians, if the School demonstrates proper parent and/or guardian notification. We use Student Data for the sole purposes of:

A subset of Student Data is information collected from children under the age of 13 ("Children Data"). We do not knowingly collect Children Data without first obtaining the consent of an authoritative body (school or parent), as outlined above. If you believe We have inadvertently collected personal information of a child under the age of 13, without the proper consent, please alert us immediately at admin@passr.app so that We may delete that information as soon as possible.

Operation of, and interaction with, Our Services, generates personally identifiable information and activity ("Usage Data"). This information is not provided by the school, or a third party, but is instead collected during the use of, and interaction with, Our Services. This data includes, but is not limited to, device type, device operating system, browser type, IP address, internet service provider, interaction timestamps, approximate location and unique device-user-session identifiers. Any use of Our Services, including interaction with Our Application (web or mobile), correspondence, and surveys, may generate Usage Data. We use Usage Data for the sole purposes of:

Our Website uses cookies to (1) authenticate users, (2) validate user access and (3) identify users across multiple devices. We do not share any information collected in cookies with third parties. Users may prefer to disable, reject or block cookies in their browser or operating system of choice. However, please note, disabling, rejecting or blocking cookies may result in diminished functionality and access to Our Services, as cookies are a critical component of Our authentication and security practices.

2. Information Collection & Management

Summary: All information collected during the use and operation of Our Service is, by default, protected. Information is only shared with appropriate and authorized parties on a need-to-access basis.

We do not share any information imported, collected, derived, tracked or otherwise obtained from the use of Our Service ("Service Data"), with any individual or third-party outside of the School, excluding the exceptions noted below. Additionally, data access within the school is controlled on a per-user basis, determined by a user's role and permissions configured by the authorized school officials with the highest level of access to Our Services ("School System Administrators").

Noted Exceptions to Information Access:

  1. We may share information with trusted third-party services and contractors if:
    1. The school requests access on the third-party's behalf
    2. The school authorizes and defines the third-party's scope of access
    3. The third-party's data-security and confidentiality practices are thoroughly vetted and approved
  2. We may share information with law enforcement or other third-party services when compelled to do so via a court order or other similar legal process
  3. We may share anonymized and aggregated information with research or educational institutions if:
    1. We receive express permission from the School
    2. We receive no monetary compensation for the providing the information
    3. No individual or school is reasonably identifiable in the information shared
  4. We may share data of varying levels of anonymity with authorized employees in order to:
    1. Troubleshoot a technical issue impeding use of Our Services
    2. Communicate with users (Identifiable information of Student's contacting Us will promptly be anonymized after communication has completed)

All Service Data collected and used by Passr is at the discretion of the School Administrators. They retain the right to update the roles of any and all individuals under their purview at any time, remove any and all collected-information, including but not limited to imported School Data, provide Our Services access to third-party services and information, and revoke Our Services' access to third-party services and information.

Student Data, including data of students under 13, is authorized, and therefore, at the discretion of the School and School System Administrators. They may revoke and or alter Our permissions to that information at any time. If Our access to Student Data is altered, Our Services will reflect that change, including removing information from Our system, in a reasonable time.

Promotional and non-essential communications can be stopped by using the 'unsubscribe' feature in the bottom of the communication. All communications relating to the operation, maintenance and functionality of Our Services have potential information security implications and we, therefore, do not allow unsubscription from this type of communication at this time.

In the event of a merger, acquisition, change of control or other data transfer event, We will not transfer any information unless the new party agrees to (1) security practices and standards equal to, or more strict, than our own, (2) continue providing the agreed upon Services. In these instances, We will provide you with advanced notice, as well as the opportunity to opt-out of the information transfer.

3. Information Security & Protection

Summary: We employ modern cloud infrastructure and comprehensive data access policies to securely store your data in the United States.

Our servers and databases operate in the United States. Therefore, all information entered or otherwise collected through the use of Our Services is processed in the United States. If you use Our Services outside of the United States, We consent to having your data transferred to the United States for processing and storage.

We employ strict administrative policies, technical systems and physical procedures to protect your information. Access to all Our systems, servers and databases is limited through user/password credentials and two-factor authentication measures. Access to School and Student Data, sensitive or otherwise, is limited to employees whose job functions require access to that information. All systems interacting publicly (ex. Browsers to Server) are forced to encrypt information using the industry-standard Secure Socket Layer (SSL) standard. Once information reaches Our systems, We employ a range of tools, systems and policies to protect your information. These systems include, but are not limited to, encryption of all data (at-rest and in-transit) with advanced encryption techniques, exhaustive data-access roles and permissions for all employees and contractors, firewall protected VPCs, IP access fencing and endpoint protection and monitoring.

For security purposes, We cannot publicly disclose all security measures in-place. If you would like to know more or have specific questions, please contact Us at admin@passr.app.

In the unlikely event of an unauthorized data access incident, We will promptly notify the affected School(s) and launch an internal investigation to (1) identify the cause of the incident and (2) implement preventative measures, policies and systems. Additionally, We will comply and cooperate with any reasonable outside investigations into the data-incident.

4. Information Retention

Summary: We retain information for a commercially reasonable period of time, but delete all de-anonymized Student Data immediately after deactivation.

Upon deactivation of a School or District, all personally identifiable Student Data will immediately and irrevocably be purged from our system. Following 12 months of deactivation, all remaining Service Data relating to the deactivated School will be irrevocably purged from our system. This retention period allows Us to comply with any potential legal or regulatory audits. We may retain aggregated and anonymized information for an indefinite time frame in order to improve Our Services and their functionality.

If you have any questions regarding Our data-retention policy, please reach out to us at admin@passr.app.

5. Children's Privacy

Summary: Access and use of children's information is authorized by the School and handled with the highest level of security.

Information of students under 13 (“Children Data”), is authorized, and therefore, at the discretion of the School and School System Administrators. They may revoke and or alter Our permissions to that information at any time. If Our access to Student Data is altered, Our Services will reflect that change, including removing information from Our system, in a reasonable time.

We do not knowingly collect Children Data without first obtaining the consent of an authoritative body (school or parent), as outlined above. If you believe We have inadvertently collected personal information of a child under the age of 13, without the proper consent, please alert us immediately at admin@passr.app so that We may delete that information as soon as possible.

6. Contact

If you have questions or comments about this notice, you may contact Us through any of the following means:

7. Update Policy

We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If We make material changes to this privacy policy, We will notify you directly via an email notification.