Privacy Policy

Last updated: 26 July 2026. This document is a product privacy notice for school customers. Have counsel review before relying on it in contracts.

1. Roles

Schools that use MyCampus are the data controllers (or equivalent) for student and staff records they enter. MyCampus operates as a data processor/ school official providing the CRM and LMS service under the school's instructions.

2. Data we process

  • Account identity: name, email, role, school affiliation
  • Education records: classes, attendance, assignments, grades, gradebook assessments, report cards, rankings, transcripts
  • Communications: in-app messages and notifications
  • Optional guardian links when schools provision parent accounts
  • Technical logs and append-only audit events for security

3. Purposes

We process data only to provide, secure, support, and improve the educational service for the school. We do not sell student data, use it for targeted advertising, or build advertising profiles (SOPIPA commitments).

4. Legal bases (GDPR)

Controllers typically rely on public-interest / contract / legitimate interest bases for school operations. Our processing is governed by a Data Processing Agreement (DPA) with each school customer.

5. Sharing

We use subprocessors listed at /subprocessors. We do not disclose education records except as instructed by the school, required by law, or via school-generated share links that the school controls.

6. Retention

Retention follows the school's instructions and docs/compliance/RETENTION.md. Schools may request export or deletion of data under their control from Privacy settings (admins) or via contract offboarding.

7. Your rights

Depending on applicable law (including GDPR), individuals may request access, rectification, erasure, restriction, portability, or objection. Students and parents should usually contact their school first. Signed-in users can export their own data from Privacy settings.

8. FERPA / SOPIPA

For U.S. schools, MyCampus is intended for use under FERPA's school official exception as documented in the customer DPA / FERPA addendum. For California K-12 operators, we commit to SOPIPA operator obligations (no sale, no targeted ads, reasonable security, delete on school request). Parents may access linked children's published records via guardian accounts, or through school administrators.

9. Security

See Trust Center and Security overview. Report vulnerabilities per SECURITY.md.

10. Contact

Privacy inquiries: use the demo/contact channel on the marketing site, or your school administrator for student-record requests.