Privacy & Compliance

Built for student-data privacy.

Schools entrust SpokenEdge with sensitive family and student information. The platform is designed around the privacy laws that govern education — so districts can adopt it with confidence.

FERPA COPPA GDPR · UK GDPR SDPC · NDPA Data never sold
FERPA

US Educational Records

For US schools, student data processed through SpokenEdge constitutes "education records" under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g. We operate as a "school official" with a legitimate educational interest.

  • Student records are used only to provide the contracted educational service.
  • We do not disclose education records to outside parties without consent, except as required by law.
  • Records are returned or securely destroyed upon request or subscription termination.
  • School administrators can review, correct, and request deletion of their students' records.
FERPA Status

SpokenEdge operates under the FERPA "school official" exception. Schools maintain ultimate control over their student records.

COPPA

Children Under 13

The Children's Online Privacy Protection Act (COPPA) applies to services directed at children under 13. Students are registered by school administrators — not by the children themselves. Under COPPA's school-consent exception, schools provide consent on behalf of parents for educational purposes.

  • We collect only the minimum information necessary to provide the service.
  • We do not direct advertising to children or build behavioural profiles.
  • Parents may request access, correction, or deletion via their school administrator.
COPPA Status

Student accounts are created and managed by school administrators, not directly by students or parents.

GDPR · UK GDPR

EU & UK Data Rights

If you are in the EU or UK, you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. We act as a data processor on behalf of the school, which remains the data controller.

For EU/UK schools, we are willing to enter into a Data Processing Agreement (DPA) satisfying GDPR Article 28 requirements. Contact info@spokenedge.com to request one.

SDPC · NDPA

US District Readiness

SpokenEdge is ready for the Student Data Privacy Consortium (SDPC) and its National Data Privacy Agreement (NDPA), as well as state-level district requirements. We can review and sign district data-privacy agreements as part of onboarding.

Security

Security by Design

Data is protected with layered technical and organisational controls:

Encrypted in transit & at rest
TLS 1.2+ everywhere, with encryption of stored data.
Role-based access
Granular permissions and multi-tenant isolation per school.
Tamper-evident audit logs
Every administrative action is captured for compliance review.
Secure authentication
Hashed passwords, short-lived sessions, and rate-limited endpoints.

For full detail, read our Privacy Policy and Terms of Service. For a DPA or district agreement, email info@spokenedge.com.

Request a Pilot ↗