Standard questions from district vendor-vetting. Every answer is architecture — backed by THE_SIZZLE_BIBLE.md — not aspiration. We sign the standard NDPA (with Exhibit E) or your district's DPA.
One table. Prepared answers. Cite the bible part that makes each one true.
| # | District question | Our answer | Backed by |
|---|---|---|---|
| 1 | Do you sign a Data Privacy Agreement? | Yes. We sign the National Data Privacy Agreement (NDPA) or your district's standard DPA. | Part K, Schedule B |
| 2 | What student data do you collect? | In our default Zero-Roster Mode: none. The school uploads nothing; families self-enter their own contact info and self-select teachers, so no information from education records reaches us. In opt-in Invitation Mode: only the family contact list the school chooses to upload, used solely to send conference invitations. | Schedule B; I-2 Zero-Roster |
| 3 | Where is student data stored? | Any Invitation Mode data lives only in SchoolConferenceGo's own database, never in our central systems, never commingled with other products. | G-1 |
| 4 | Do you sell data or use it for advertising? | Never. No data sales, no advertising profiles, no ads shown to families anywhere, no third-party ad trackers on any page. | K-3 §2; G-4 |
| 5 | Do students or parents create accounts? | No. Parents book without accounts; students never interact with the system. Only school staff hold accounts. | G-1 |
| 6 | How is data secured? | Encryption in transit, role-based access, signature-verified integrations, no card data on our servers (Stripe-hosted payment only), rate limiting on public endpoints, secrets never in code. | G-2, G-3 |
| 7 | Subprocessors? | Stripe (payments), Clerk (staff authentication only), Resend (email), Mobile Text Alerts (SMS), RavenDB Cloud and hosting infrastructure. Current list maintained at /privacy. | K-3 §4 |
| 8 | Data retention and deletion? | Retained while your account exists (read-only if lapsed, never deleted over billing); full deletion within 30 days of request; full export available anytime in open formats. | G-5; K-1 §4 |
| 9 | Breach notification? | Prompt disclosure to org owners for any incident affecting your data; NDPA breach timelines honored where signed. | K-3 §8; F-6 |
| 10 | FERPA compliance posture? | Zero-Roster Mode avoids FERPA disclosure by design; Invitation Mode operates under the school-official exception, under your direction and control, with the DPA. We also honor state student-privacy laws (e.g., NY Ed Law 2-d, CA SOPIPA) in every state we serve. | Schedule B |
| 11 | COPPA? | Not applicable by design: services are directed to adults, no under-18 accounts exist, and we collect no information from children. | K-3 §7 |
| 12 | Insurance / W-9 / vendor forms? | Provided on request. | J-5 |
Districts usually initiate the National Data Privacy Agreement through their state SDPC alliance. We complete the vendor package (including Exhibit B data elements and Exhibit E General Offer) so the first request turns around in days — then other districts in that state can adopt by one-page subscription.
Full legal text lives at /privacy and /terms. Attorney review applies to NDPA exhibits before first signature.