Legal

Privacy Policy

SimplifiEd Connect · v1.0 DRAFT · Effective August 8, 2026

SimplifiEd Solutions, LLC ("we", "us", or "our") is committed to protecting the privacy and security of the personal information of users of SimplifiEd Connect (the "System" or "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in connection with the System. The System is designed to assist K–12 school districts and other educational institutions ("Districts" or "Clients") in governing, reviewing, approving, documenting, and managing the use and development of artificial intelligence-enabled, no-code, low-code, and other internally developed technology solutions.

The System is an administrative governance tool intended for use by District staff. It is not designed for, directed to, or intended to be used by students, and it is not intended to collect or store student education records. See Section 4 for details.

By using the System, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the System. This Policy applies to all users, including District administrators, technology and information security staff, instructional and curriculum leaders, data privacy officers, and other designated reviewers and staff. We may update this Policy from time to time, and changes will be posted here with the updated effective date. Continued use of the System after changes constitutes acceptance of the revised Policy.

1. Information We Collect

We collect personal information necessary to provide and improve the System. The types of information we collect depend on your role and how you interact with the System. Information is typically provided by Districts or by users under District-managed accounts.

Categories of Personal Information:

Identifiers: Names, work email addresses, work phone numbers, usernames, and credentials.

Professional and Role Information: Job title, department, school or site assignment, supervisor, role designation, and System permissions.

Governance Content: Information submitted about proposed or existing technology solutions, including solution descriptions, intended use, vendor and third-party service details, data handling descriptions, risk and impact assessments, review comments, approval decisions, supporting attachments, and District policy documents.

Usage Data: IP addresses, device information, browser type, log data, and interactions with the System (e.g., pages viewed, actions taken, time stamps).

Communications: Messages, notifications, review notes, or feedback submitted through the System.

AI-Specific Data: Where the System offers artificial intelligence-assisted features, the inputs you provide to those features and the resulting outputs.

Other Information: Any additional data uploaded by Districts or users, such as documents, screenshots, diagrams, or preferences.

We collect this information:

Directly from you or the District (e.g., during account creation, data entry, or form submissions).

Automatically through cookies, web beacons, and similar technologies for analytics and functionality.

From third parties, such as integrated identity or directory services, with District authorization.

We do not collect more information than is reasonably necessary for the System's purposes. We do not request, require, or design the System to receive student personal information or education records.

2. How We Use Your Information

We use collected information solely for legitimate operational and educational-administration purposes, including:

Providing and maintaining the System (e.g., managing accounts, routing review and approval workflows, maintaining the solution inventory, generating reports).

Sending notifications, reminders, and status updates related to submissions and reviews.

Improving the System through analytics and feedback.

Ensuring security and preventing fraud or misuse.

Complying with legal obligations, such as responding to subpoenas, public records requests directed to us, or audits.

Supporting District-directed activities, such as technology governance recordkeeping and reporting.

We do not use personal information for commercial marketing, targeted advertising, or any non-educational purposes without explicit consent. Information you submit is used only as directed by the District.

Aggregated and De-Identified Data

We may create anonymized and aggregated data derived from use of the System and use it for our legitimate business purposes, including internal research and development, benchmarking, analytics, improving or enhancing our products and services, and developing new products and services. Aggregated and de-identified data does not identify any individual, District, or specific solution, and we will not attempt to re-identify it.

Artificial Intelligence Features

Where the System offers artificial intelligence-assisted features, we may process your inputs to generate outputs and to operate those features. We do not use District content or personal information to train publicly available or third-party foundation models. Any use of data to improve our own models is limited to anonymized or de-identified data. Artificial intelligence outputs may be inaccurate or incomplete and are intended to support, not replace, human review and decision-making by District staff.

3. Sharing of Information

We share personal information only as necessary and with appropriate safeguards:

With Service Providers: We may share data with third-party vendors (e.g., cloud hosting, analytics, authentication, and email delivery providers) who assist in operating the System, bound by confidentiality and data protection obligations no less protective than those in this Policy.

With Districts/Clients: Districts control the data submitted within their instance of the System and may access, export, or share it as needed for their governance purposes.

For Legal Reasons: We may disclose information to comply with laws, protect rights, or respond to legal processes (e.g., court orders).

In Business Transfers: If we are acquired or merge, data may be transferred as part of the transaction, subject to this Policy.

With Consent: For any other sharing, we obtain explicit consent.

We do not sell personal information. Sharing is limited to what is required for the System’s functions, and we require third parties to protect data in compliance with applicable laws.

We may offer integration with third-party identity, directory, collaboration, or ticketing services (for example, single sign-on and staff directory providers). If your District chooses to integrate, you will need to grant access to certain staff account information, such as names, work email addresses, and role or group membership. These integrations are limited to administrative account data and are not designed to transfer student records.

4. Student Data and Children’s Privacy

The System is an administrative tool for District staff. It is not directed to children, is not intended for use by students, and is not designed to collect, store, or process student education records or student personal information.

No Student Records

Districts and their users should not upload, input, or otherwise transmit student education records or student personal information into the System. A description of a technology solution that processes student data — for example, a risk assessment describing what data a proposed tool would handle — is not itself student data and is appropriate for the System; the underlying student records are not.

If student personal information is submitted into the System notwithstanding this Policy, it remains under the control and direction of the District, and the District remains responsible for compliance with applicable student privacy laws with respect to that information. Upon becoming aware of such information, we will work with the District to remove it or, where the District directs that it be retained, will handle it as described below.

FERPA

The Family Educational Rights and Privacy Act (FERPA) safeguards student education records. Because the System is not designed to process education records, we do not ordinarily act as a school official with access to education records. To the extent a District designates us a "school official" with a legitimate educational interest and education records are nonetheless present in the System, we act solely as a processor under District direction, use such records only to provide the System, and do not disclose them for non-educational purposes. Parents/guardians and eligible students exercise rights of inspection, review, and amendment through the District.

COPPA

The Children's Online Privacy Protection Act (COPPA) protects the online privacy of children under 13. The System is not intended for use by, nor directed to, children under 13, and we do not knowingly collect personal information from children under 13. Districts are responsible for ensuring that only authorized adult staff are provided access to the System. If we become aware that we have collected personal information from a child under 13, we will delete it promptly.

For more on COPPA, visit the FTC's website; for FERPA, refer to the U.S. Department of Education's guidance.

5. Data Security

We implement reasonable administrative, technical, and physical safeguards to protect personal information, including encryption, access controls, and regular audits. However, no system is completely secure, and we cannot guarantee absolute security. In the event of a data breach, we will notify affected parties and authorities as required by law.

Data is stored on secure servers, primarily in the United States, but may be transferred internationally.

Retention

We retain data only as long as necessary for the purposes outlined, or as required by law or District instructions. Upon expiration or termination of a District's subscription, we will make the District's data available for export for 30 days upon written request, subject to the technical capabilities of the System. After that period, we may delete the data in the ordinary course of business, except where retention is required by law.

6. Consent, Control and Your Rights

We work directly with Districts to establish agreements that outline how information is collected and used. These agreements are intended to ensure compliance with applicable federal and state privacy laws and to provide transparency.

Certain data collection is essential to operate the System — for example, account identifiers, permissions, and audit logs of governance decisions — and cannot be disabled while an account remains active, because the System could not perform its recordkeeping and access-control functions without it. Optional analytics and non-essential cookies can be managed as described in Section 7.

Depending on your location and role, you may have rights regarding your personal information, including:

Access: Request a copy of your data.

Correction: Update inaccurate information.

Deletion: Request removal of data, subject to legal retention requirements, District instructions, and the integrity of governance audit records.

Opt-Out: Withdraw consent for optional uses or sharing, where applicable.

Non-Discrimination: Exercise rights without penalty.

Because Districts control the data within their instance of the System, we recommend that staff users direct requests to their District first. Districts may request removal of specific records by contacting us at the address in Section 10. We will verify identity and respond within a reasonable timeframe (generally 30–45 days). Additional rights may apply under state laws such as the CCPA/CPRA for California residents.

7. Cookies and Tracking Technologies

We use cookies and similar technologies for essential functions, analytics, and personalization. You can manage cookies through your browser settings, though disabling essential cookies may prevent the System from functioning. We do not use tracking technologies for targeted advertising.

8. International Users

If you are outside the U.S., your data may be transferred to and processed in the U.S. By using the System, you consent to such transfers and processing under U.S. laws, which may differ from those of your jurisdiction.

9. Changes to This Privacy Policy

We may update this Policy to reflect changes in our practices or legal requirements. We will notify users via email or prominent notice in the System at least 30 days before significant changes take effect.

10. Contact Us

For questions, requests, or concerns about this Policy or your data, contact our Data Protection Officer at evan@simplifiedsolutions.tech.

If you are a District staff user, we recommend contacting your District first, as the District controls the data within its instance of the System.

This Policy is governed by U.S. laws. Thank you for trusting us with your information.