IEP Note TakerPrivacy & DPA

Security & compliance

How we handle IEP meeting data

Districts evaluate documentation tools on trust, not features alone. We sell our FERPA package — not a vendor certification. These practices are how IEP Note Taker is designed for FERPA-minded teams and audit readiness.

  1. 01

    School official / DPA

    We operate under a Data Processing Agreement that limits use of student education records to authorized purposes only — documenting IEP meetings for the district that contracted us. We do not sell student data or use it for advertising.

  2. 02

    No training on customer data

    Meeting content used to produce documentation drafts is processed under zero-retention / no-training commitments for enrolled organizations. Capture vendors are likewise configured so customer audio is not used to train their models.

  3. 03

    Consent before documenting

    An IEP session is not documented until a parent, guardian, or authorized host has recorded consent. Decline stops capture and nothing is retained.

  4. 04

    Access controls + audit logs

    Staff access is scoped by district and school role. Every view, export, approve, and delete of student meeting data is written to an audit log.

  5. 05

    Retention / deletion

    After the structured record is generated, raw meeting media is purged from the capture provider. IEP documentation remains in your district workspace until you delete it.

  6. 06

    Human review before distribution

    AI output is a draft only. Staff must review and approve before documentation is shared with families or used as a final record. Nothing is auto-sent.

  7. 07

    US data residency

    Capture and processing default to US regions. EU residency is not enabled for K–12 US deployments.

Human review is required before documentation is shared with families. Drafts are never auto-sent. For contractual language, see Privacy & DPA.