Privacy Policy

iTANU Assessment Management System

Effective Date: January 1, 2025

Last Updated: January 1, 2025

Version: 1.0


1. Introduction

Welcome to iTANU AMS (Assessment Management System). We are committed to protecting your privacy and the privacy of students using our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational assessment platform.

In accordance with the ECNO Student Digital Privacy Standard, we communicate our privacy notices, terms of use, and contracts in clear, specific, and unambiguous language that explains to users how their personal information is being used, processed, disclosed, and retained by us and any third parties.

Easy Access to Privacy Policy: Links to this Privacy Policy and our Terms of Use are easily accessible:

iTANU AMS is designed for educational institutions, teachers, and students. We comply with applicable privacy laws and standards including:

By using our platform, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.


2. Information We Collect

In accordance with the ECNO Student Digital Privacy Standard, we explicitly state all data elements we collect and the specific purpose for collecting each element. We collect only the personal information required to operate our educational assessment service.

2.1 Information You Provide Directly

For Teachers and Administrators:

For Students:

For Parents/Guardians (K-12 Students):

2.2 Information Collected Automatically

Usage Data:

Technical Data:

What We Do NOT Collect:

In accordance with the ECNO Student Digital Privacy Standard, we explicitly do NOT collect the following information:

Covert Collection Prohibition:

We never collect personal information covertly (without user knowledge). All audio and video recordings are made only with explicit user action (e.g., clicking a record button) and clear indication that recording is active. Users are always aware when audio/video is being captured.

2.3 Information from Third Parties

Learning Management Systems (LMS):

If your school uses an LMS integration (Canvas, Google Classroom, Moodle), we may receive:

AI Services:


3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Educational Services

Statistical Analysis and Profiling:

3.2 Platform Operations

3.3 Improvement and Development

3.4 Legal and Compliance


4. How We Share Your Information

Use, Retention, Disclosure:

We do not sell your personal information. We share information only in the following circumstances:

4.1 With Your Educational Institution

4.2 With Service Providers (Third-Party Vendors)

We work with trusted service providers who help us operate our platform:

All service providers are contractually required to:

4.3 With Your Consent

4.4 Legal Requirements

We may disclose information if required by law, including:

4.5 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership.


5. Data Security

We maintain a comprehensive security program that is reasonably designed to protect the security, privacy, confidentiality, and integrity of student personal information against risks (e.g., unauthorized access or use, unintended or inappropriate disclosure) through the use of administrative, technological, and physical safeguards appropriate to the sensitivity of the information.

5.1 Technical Safeguards

Defined Technical Safeguards:

5.2 Administrative Safeguards

Defined Administrative Safeguards:

5.3 Physical Safeguards

Defined Physical Safeguards:

5.4 Vendor Security Requirements

5.5 Successor Entity Requirements

5.6 Breach Protocols

Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data to the best of our ability.


6. Your Privacy Rights

6.1 FERPA Rights (U.S. Students and Parents)

Under FERPA, you have the right to:

How to Exercise Your FERPA Rights:

6.2 GDPR Rights (EU Residents)

If you are located in the European Union, you have the following rights:

How to Exercise Your GDPR Rights:

6.3 PIPEDA Rights (Canadian Residents)

If you are located in Canada, you have the following rights under PIPEDA (Personal Information Protection and Electronic Documents Act):

Your PIPEDA Rights:

PIPEDA Principles We Follow:

Provincial Privacy Laws:

How to Exercise Your PIPEDA Rights:

6.4 COPPA Rights (Children Under 13)

For children under 13, we comply with COPPA:

How Parents Can Exercise COPPA Rights:

6.5 General Rights (All Users)

All users have the right to:

6.6 Access and Correction Rights

We provide mechanisms for users to access, correct, erase, and download content they created in a usable format:


7. Children's Privacy (COPPA Compliance)

iTANU AMS is designed for educational use and may be used by children under 13. We take special care to protect children's privacy:

7.1 Parental Consent

7.2 Limited Data Collection

7.3 Student Content Ownership and Control

7.4 Generic Accounts and Minimal Information

7.5 Student Privacy and Profile Protection

7.6 Parental Rights

Parents have the right to:

Contact Information for Parents:


8. Third-Party Services

We use the following third-party services that may process your data:

8.1 OpenAI

8.2 MongoDB Atlas

8.3 Amazon Web Services (AWS)

8.4 Cloudflare

Third-Party Disclosure:

We identify all third parties to which we disclose personal information for processing, the specific data elements involved, and a summary of protections/assurances in place:

Third Party Data Elements Disclosed Purpose Protections/Assurances
OpenAI Audio recordings, transcripts, assessment responses, rubrics AI-powered evaluation and transcription Contractual requirement: No training on data, data protection standards, encryption, deletion after processing
MongoDB Atlas All platform data (assessments, user accounts, profiles) Database hosting and storage SOC 2, GDPR, FERPA, PIPEDA certified; Encryption at rest and in transit; Located in Canada
AWS Audio files, backups, system logs Cloud infrastructure and file storage SOC 2, GDPR, FERPA, PIPEDA certified; Encryption at rest and in transit; Located in Canada
Cloudflare Network traffic, IP addresses, usage data CDN and security services GDPR compliant; DDoS protection; No storage of personal data

All third-party service providers are contractually required to:


9. Data Retention

We retain your information only as long as necessary for educational and legal purposes:

9.1 Student Educational Records

9.2 User Account Data

9.3 System Data

9.4 Deletion Process

When data is deleted:

Secure Destruction and Anonymization:

Note: Some data may be retained longer if required by law (e.g., FERPA requires 7-year retention of educational records) or if there is a legal hold.


10. International Data Transfers

iTANU AMS stores your data primarily in Canada. Our primary data storage providers (MongoDB Atlas and AWS) are located in Canada. However, some data processing may occur in other jurisdictions:

10.1 Data Transfers

10.2 GDPR Compliance

10.3 PIPEDA Compliance (Canada)

10.4 Your Rights


11. Cookies and Tracking Technologies

11.1 Cookies We Use

11.2 Cookie Management


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements:

12.1 Notification of Changes

12.2 Continued Use


13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your privacy rights, please contact us:

Privacy Officer / Data Protection Officer:

For FERPA Requests:

For GDPR Requests:

For PIPEDA Requests (Canadian Residents):

For COPPA Requests (Parents):

For Security Incidents:

Response Times:


14. Additional Information

14.1 School District Policies

14.2 Links to Other Websites

14.3 California Privacy Rights

14.4 Canadian Privacy Rights


15. Definitions

Educational Records: Records directly related to a student and maintained by an educational institution (as defined by FERPA).

Personal Information (PII): Information that can be used to identify an individual, including name, email, student ID, and assessment responses.

Processing: Any operation performed on personal data, including collection, storage, use, and deletion.

Data Controller: The entity that determines the purposes and means of processing personal data (iTANU).

Data Processor: An entity that processes personal data on behalf of the data controller (e.g., OpenAI, AWS).