Data Protection
1Introduction
DataVot is committed to processing personal data lawfully, fairly, and transparently, and to handling student data in line with U.S. education privacy law — including FERPA, COPPA, and New Jersey's student-data privacy framework.
This page is intended for:
- Teachers and school administrators who want to understand how their data is handled.
- School and district administrators who need to assess our data practices before deploying DataVot in their institution.
- Anyone who needs to understand the basis on which we process data.
2Data Controller
“Controller” and “processor” below are the terms the New Jersey Data Privacy Act itself uses (N.J.S.A. 56:8-166.4 et seq.), not European ones — DataVot serves United States schools only, and this page is written to New Jersey and federal law throughout. For the personal data of registered users (teachers and school administrators), DataVot acts as the data controller:
| Controller name | Salesforce Hub LLC (operator of DataVot) |
| Service | DataVot — state assessment reporting for New Jersey schools |
| Contact email | info@datavot.com |
| Website | datavot.com |
As data controller, we determine the purposes and means of processing your account data and preferences.
3DataVot as Data Processor
When school staff upload official assessment files containing student personal data (e.g., student names, state or local identifiers, scores and performance levels), DataVot acts as a data processor on behalf of the teacher or school, who is the data controller for that student data. DataVot reads state assessment results and nothing else — it holds no enrollment, attendance, discipline or gradebook data. Under FERPA, DataVot acts as a “school official” performing services the school would otherwise perform itself.
- Account data (your name, email, password): DataVot is the controller.
- Uploaded assessment data (student assessment records): The teacher/school is the controller; DataVot is the processor.
As processor of uploaded data, we commit to:
- Processing uploaded data only for the purpose of delivering the Service (building tables and creating reports).
- Not disclosing uploaded data to any third party other than our sub-processors — Cloudflare (hosting, database, security and request processing), and Resend (transactional email delivery). Transactional email carries names, email addresses and school names, never uploaded student rows.
- Assisting schools in responding to parent or eligible-student requests under FERPA.
- Deleting or returning uploaded data upon request or account termination.
When we say your data is never shared with a third party, we mean that no outside company ever receives it for its own purposes — not to sell, not to advertise against, not to build a product from, and not to train a model on.
Cloudflare and Resend are not an exception to that. They are the servers your data sits on and the pipe an invitation email travels through — infrastructure we rent to run the service, not companies we hand your data to. Every piece of software runs on someone else’s hardware; a provider claiming otherwise would be hiding its suppliers rather than not having any, which is why ours are named above rather than left vague.
They process uploaded data only on our instructions and only to operate DataVot, they are contractually bound to protections no weaker than the ones we give you, and they may not use your data for anything of their own. Our Data Privacy Agreement names them in full and commits us to telling your school before any new sub-processor handles student data.
Schools requiring a formal Data Processing Agreement (DPA) or Data Privacy Agreement should contact us at info@datavot.com.
4What Personal Data We Process
We process the following categories of personal data:
| Category | Data elements | Sensitive? |
|---|---|---|
| Identity data | Name, email address | No |
| Authentication data | Bcrypt-hashed password, session token | No |
| Account metadata | Account creation date, role, school membership | No |
| Usage preferences | Display settings (dark mode, chart type, aggregation default) | No |
| Reports | Pivot configurations, field arrangement, filter settings | No (metadata only) |
| Uploaded file content | The contents of the assessment files a school uploads — typically student names or identifiers, scores and performance levels | Yes — student personal data |
| Technical logs | IP address, user-agent, timestamps (Cloudflare infra logs) | No |
5Retention Periods
We apply the principle of storage limitation. We do not keep data longer than necessary:
| Data type | Retention period | Basis for retention |
|---|---|---|
| Account data (name, email, password hash) | Duration of account; deleted within 30 days of a verified deletion request | Contract performance; deletion buffer |
| Reports | Until deleted by the user, or with the account on a deletion request | Service functionality |
| Unsaved uploaded file data | Browser session only — not persisted to database | Not stored |
| Uploaded data sets (official assessment results) | For the term of use; deleted or returned on request, or within 30 days of termination | Held for the school under our Data Privacy Agreement §7 |
| Cloudflare server logs | Up to 30 days | Security / Cloudflare standard |
| Application diagnostic logs (errors and actions reported by your browser) | Up to 90 days from the date of the entry | Diagnostics; expired on the shorter window because their value decays in days |
| Security and access audit trail (sign-in attempts and the IP address of a failed one, support access, administrative actions) | Up to 3 years from the date of the entry | Security audit trail — who accessed what, and when |
| Email communications | Retained as sent; not stored within DataVot | Email provider's policy |
Account deletion is handled on request rather than through a self-service button in the product. Email info@datavot.com to request deletion, and we will delete or anonymize the associated personal data within 30 days of verifying the request, except where law requires longer retention.
6School Data Processing Agreements
Schools deploying DataVot for their teachers are responsible for ensuring they have appropriate legal authority to use the Service and that their use complies with applicable education data protection laws (e.g., FERPA, COPPA, and state student-privacy statutes).
Before you ask, our Security Overview answers most of what a district questionnaire covers — encryption, access control, two-factor authentication, the audit trail, where the data lives, and DataVot rated against every category of the NIST Cybersecurity Framework, including what we have not met. If your school or district requires a formal Data Privacy Agreement (DPA) or a security/privacy questionnaire to be completed before using DataVot, please contact us:
United States & New Jersey schools: We are ready to sign your district's Data Privacy Agreement before any pilot begins. In New Jersey this is typically the National Data Privacy Agreement (NDPA) provided through the New Jersey Student Privacy Alliance (NJSPA) (managed by NJETA with the SDPC). If your district is an NJSPA member, we sign the district's NDPA at no membership cost to us. DataVot acts as a “school official” under FERPA and aligns with New Jersey's privacy framework — SOPPA-NJ (written vendor contract; no sale of student data; no targeted advertising) and the New Jersey Data Privacy Act (NJDPA). We can also complete your security/technical questionnaire as part of the same review. See our DPA for details.
Request a DPA / Privacy Questionnaire
📧 Email: info@datavot.com
Subject line: “School DPA Request — [School Name]”
We will return a signed DPA (or a completed copy of your district's agreement) and the technical security questionnaire within 10 business days.
7Children's Data, FERPA & COPPA
DataVot accounts are for adults (educators) only. We do not knowingly create accounts for children, and the Service is not directed to or intended for use by students.
Student data uploaded by school staff: While DataVot does not interact with students directly, staff upload official assessment files that include student names, identifiers, scores and performance levels. This is equivalent to a school analyzing its own state results in a spreadsheet application. The school is the data controller for that student data.
For schools subject to FERPA: DataVot acts as a “school official” within the meaning of FERPA when teachers upload student records. We use student data solely to provide the educational service requested and do not disclose it to third parties.
For schools subject to COPPA: We do not collect personal information directly from children under 13. Teachers uploading files containing student data are responsible for their school's COPPA compliance.
8Data Breaches
In the event of a personal data breach, we will:
- Contain and assess the breach as quickly as possible.
- Notify affected schools and users without unreasonable delay and no later than 72 hours after we confirm the breach, where it is likely to result in a significant risk to affected individuals, as required by applicable law and any written agreement with the school.
- Notify the relevant authorities where required by applicable law.
- Document all breaches in an internal breach register, including those that do not require notification.
If you discover or suspect a data breach involving DataVot, please report it immediately to info@datavot.com with the subject line “Security Incident”.
9Contact
All data protection inquiries are handled directly by the service operator. For any data protection or privacy questions, please contact:
DataVot — Data Protection Contact
📧 Email: info@datavot.com
Subject: “Data Protection Inquiry”
🌐 Service: datavot.com
School DPA requests: within 10 business days. Security incidents: as soon as reasonably possible.