Last Updated: December 1, 2024
Calimatic EdTech is committed to helping educational institutions maintain compliance with the Family Educational Rights and Privacy Act (FERPA). This page explains our FERPA compliance practices.
What is FERPA?
The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of student education records. FERPA applies to all schools that receive funds from the U.S. Department of Education.
Our Role Under FERPA
When educational institutions use Calimatic to manage student information, we act as a "school official" with a "legitimate educational interest" as defined by FERPA. We provide services that the school would otherwise use its own employees to perform.
Our Commitments
Direct Control
You maintain direct control over all student education recordsWe only access records as directed by you or as necessary to provide our servicesWe do not use student data for our own purposesData Security
We implement comprehensive security measures including:
Encryption of data in transit and at restAccess controls and authenticationRegular security audits and testingEmployee background checks and trainingSecure data centers with physical securityData Minimization
We only collect data necessary to provide our servicesWe help you identify and manage personally identifiable information (PII)We support data retention policies you establishBreach Notification
In the event of a data breach affecting student records:
We will notify you promptlyWe will cooperate with your investigationWe will take immediate steps to mitigate harmData Access and Correction
We support your obligations to:
Provide parents/students access to their recordsAllow amendment of inaccurate recordsMaintain accurate education recordsRe-disclosure Limitations
We do not disclose student information to third parties without your consentWe maintain records of disclosures as requiredOur subprocessors are contractually bound to FERPA complianceYour Responsibilities
As the educational institution, you are responsible for:
Determining what information to store in CalimaticManaging user access and permissionsResponding to parent/student record requestsProviding required FERPA notices to parents and studentsEnsuring consent is obtained when requiredData Processing Agreement
We offer a FERPA-compliant Data Processing Agreement (DPA) that includes:
Designation of Calimatic as a school officialPermitted uses and restrictions on student dataSecurity requirementsBreach notification proceduresData retention and deletion termsContact us to request a DPA for your institution.
Security Practices
Technical Safeguards
TLS/SSL encryption for all data transmissionAES-256 encryption for stored dataMulti-factor authentication supportRegular penetration testingAutomated security monitoringAdministrative Safeguards
Employee background checksAnnual security trainingAccess based on job functionIncident response proceduresRegular policy reviewsPhysical Safeguards
SOC 2 Type II certified data centers24/7 physical security monitoringBiometric access controlsEnvironmental controlsAudit and Compliance
Annual SOC 2 Type II auditsRegular internal compliance reviewsThird-party security assessmentsDocumented policies and proceduresStudent Data Pledge
Calimatic has signed the Student Privacy Pledge, committing to:
Not sell student personal informationNot use student data for targeted advertisingSupport parental access to student dataMaintain comprehensive security standardsUse data only for authorized purposesResources
For more information about FERPA:
[U.S. Department of Education FERPA Page](https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html)[FERPA General Guidance](https://studentprivacy.ed.gov)Contact Us
For FERPA-related inquiries or to request our DPA:
Caliber Technologies Inc
445 Minnesota Street, Suite 1500
St. Paul, MN 55101, USA
Email: compliance@calimaticedtech.com
Phone: +1 612-605-8567