School Data Confidentiality & Assurance Letter
1Purpose
DataVot helps schools turn official assessment and reporting CSV files into reusable Data Sets and Reports. When a school provides data to DataVot, we use that data only to configure, operate, support, and improve the reporting experience for that school.
This letter applies to data provided by a school, charter school, charter network, district, or authorized school representative, including pilot data, historical CSV files, uploaded official data sets, saved reports, account records, and support communications.
2School Ownership and Control
The school remains the owner and controller of its school data. DataVot does not claim ownership of school-provided data, student records, assessment files, report outputs, or any school-created report designs.
DataVot acts as a service provider or processor for school-provided data. We process school data only on behalf of the school and only for the purposes described in this letter, our Privacy Policy, our Data Protection page, and any written agreement with the school.
3Limited Use of School Data
DataVot will use school data only to:
- Import and validate school-provided CSV files.
- Create and maintain official Data Sets and Reports for the school.
- Recalculate system-shared reports against the school's matching official data set.
- Provide onboarding, troubleshooting, account support, and authorized support sessions.
- Maintain system security, audit logs, abuse prevention, and service reliability.
DataVot will not use school data for advertising, student profiling, unrelated analytics, model training, or any purpose unrelated to providing and supporting the DataVot service for the school.
4No Sale, Publication, or Public Disclosure
We do not share school data with advertisers, data brokers, marketing services, or unrelated third parties. We do not publish school-specific results, student-level information, or identifiable report data without the school's written permission.
We may disclose information only when required by law, when necessary to protect the security of the service, or to authorized subprocessors that help us operate DataVot under confidentiality and data protection obligations.
5Security Commitments
DataVot uses administrative, technical, and organizational safeguards designed to protect school data, including:
- HTTPS/TLS encryption for data transmitted between the browser and DataVot.
- AES-GCM encryption at rest for uploaded student data, with the encryption key held separately from the database, so a copy of the database alone decrypts nothing.
- Two-factor authentication, required for DataVot's own System Admins and available to School Admins.
- HTTP-only, Secure, SameSite session cookies for authentication.
- Bcrypt hashing for passwords; passwords are never stored in plain text.
- Role-based access controls for System Admin, School Admin, and Teacher users.
- Tamper-evident audit logging for sensitive actions, including support access activity: each entry commits to its own content and to the entry before it, under a key the database does not hold.
- Short-lived, consent-based support sessions for System Admin Act As access.
- CSV storage controls and upload validation to reduce accidental exposure or unsafe file handling.
The full detail behind each of these — the evidence for every control, where the database runs, and the limits we have not closed — is published in our Security Overview.
Where responsibility lies. DataVot is responsible for protecting the service and the data it holds. Each school and its staff remain responsible for the security of their own accounts — including the use of strong, unique passwords, the safeguarding of login credentials, and the security of the devices used to access DataVot. Where student data is exposed as a result of a weak, shared, or compromised staff credential, or a compromised staff device, the cause lies outside DataVot's control and does not represent a failure of our safeguards. In any such event, DataVot will continue to support the school in investigating and responding to the incident.
6Access Controls and Support Access
School users access DataVot based on their assigned role. School Admins manage official Test Data Sets, Reports, Users, and related school-level settings. Teachers can access reports according to the permissions configured for their school.
System Admin Act As access is support-only. It requires explicit consent, creates an audited short-lived support session, and displays a visible support banner for as long as the session is active. Every support session generates an email record to the System Admin. Schools that want their own user emailed directly as well can turn on the school-notification setting, in which case the target user receives the notice with the System Admin copied.
7Subprocessors
DataVot uses infrastructure and email providers only as needed to operate the service. Current subprocessors include:
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | Hosting, edge compute, encrypted database storage, security and request processing | Application data, uploaded data when saved, account data, logs |
| Resend | Transactional email (no student records are sent by email) | Email address and email content for invitations, password resets, verification and support notices |
DataVot uses no advertising or data-broker subprocessors, and no third-party analytics or cross-site tracking script runs in the application. Our hosting provider’s privacy-preserving, cookieless web analytics may be enabled at the network level to count page requests; it sets no cookie, builds no cross-site profile, and never receives school or student data.
8Retention and Deletion
DataVot retains school data only for as long as needed to provide the service, maintain school reports, complete a pilot, comply with legal obligations, or support security and audit requirements.
A school may request export, deletion, or return of its school data by contacting DataVot. Unless a longer period is required by law or a written agreement, DataVot will delete or de-identify school data within 30 days of account termination, pilot completion, or a verified deletion request — the same window committed to in our Data Privacy Agreement — and will certify the deletion on request.
9Pilot Data and Historical CSV Files
During a pilot, a school may provide historical CSV files, such as assessment data from 2024, 2025, and 2026. DataVot will use those files only to build pilot Data Sets, Reports, and demonstrations for that school.
If the school prefers, DataVot can begin with de-identified or sample files before processing identifiable student-level data. Pilot participation does not give DataVot permission to publish the school's data, use it in public marketing, or share it with another school.
We will sign your data privacy agreement before the pilot begins. In New Jersey this is typically the National Data Privacy Agreement (NDPA) provided through the New Jersey Student Privacy Alliance (NJSPA) (managed by NJETA with the SDPC); if your district is an NJSPA member, we sign it at no membership cost to us. DataVot acts as a “school official” under FERPA, aligns with SOPPA-NJ and the New Jersey Data Privacy Act, and never sells student data or uses it for advertising. See our Data Privacy Agreement, or email info@datavot.com with the subject “School DPA Request — [School Name]”.
10Security Incident Notice
If DataVot becomes aware of a confirmed security incident involving school data, we will investigate promptly, take reasonable containment steps, and notify affected school contacts without unreasonable delay and no later than 72 hours after confirming the incident, as required by applicable law and any written agreement with the school.
11Contact
Questions about this letter, school data handling, or a requested school agreement can be sent to info@datavot.com.
Sincerely,
Salesforce Hub LLC (makers of DataVot)
225 Arlington Avenue, Clifton, New Jersey 07011
info@datavot.com