QuikComply ("Service") is a scheduling tool used by a school district's special education staff to manage IEP meetings. This Privacy Policy explains what information the Service handles, why, and the choices available to school districts, their staff, and the families they serve.
The Service is provided to a school district by its own administrator, for use by that district's own staff. There is no public sign-up - every account is created by a District administrator for a specific staff member. The District decides what information to enter, who on its staff may access it, and how long to keep it; QuikComply acts on the District's behalf as a service provider, in the manner described in this policy.
If you are a parent, guardian, or student named in a meeting record, your school or district's staff entered that information as part of coordinating your IEP meeting. You did not create an account here, and this policy describes how that information is handled on the District's behalf, not a direct relationship between you and QuikComply.
| Category | Examples | Source |
|---|---|---|
| Student and family information | Name, date of birth, grade, school, disability category, SSID/SEIS/state or local student ID, IEP meeting details and required dates, parent/guardian name, email, and phone number | Entered by District staff, or uploaded via a SEIS/SIRAS/Aeries export, CSV, or other document |
| Staff account information | Name, school email address, role (admin or staff), password (stored as a one-way hash, never in plain text) | Entered by a District administrator when creating an account |
| Meeting and scheduling data | Dates, times, locations, attendee lists, staff availability, backup coverage assignments, and a record of when reminder or notification messages were sent | Generated by the Service as staff use it |
| Technical and log data | IP address, browser type, timestamps, and actions taken within the Service (e.g., which user edited a record and when) | Collected automatically for security, troubleshooting, and audit-logging purposes |
Every student record is encrypted before it is stored in the database - see Section 9 (Data Security).
We use the information described above solely to provide, maintain, and improve the Service for the District, including to:
We do not use Student Data for advertising, do not sell Student Data, and do not use Student Data to build a profile of a student for any purpose unrelated to the school purposes described above. See Section 11 (Children's Privacy and SOPIPA).
To the extent information we process constitutes an "education record" under FERPA (20 U.S.C. § 1232g), we act as a "school official" with a "legitimate educational interest" in that record, under the direct control of the District as to the use and maintenance of education records, consistent with 34 CFR § 99.31(a)(1). This means the District, not QuikComply, is the party responsible for determining what information may be disclosed and to whom, and QuikComply may use education records only for the purpose of providing the Service to the District.
For staff account information, our basis for processing is the legitimate business interest of operating the Service the District has arranged for its staff to use, and, where applicable, our contractual relationship with the District.
A District admin may connect one shared Google account to enable real email features and automatic ingestion of documents from a designated Google Drive folder. That access is used only to:
The Service does not integrate with Google Calendar in any way - no event is ever created, read, or synced on any Google Calendar, shared or personal. A reminder email instead attaches a standard .ics calendar file, which works with any calendar application.
The Service's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google account data is never sold, shared with advertisers, used for any purpose beyond what's described here, or used to train AI/ML models of any kind.
Case managers can optionally upload a document that isn't a SEIS export - an outside evaluation, an eligibility report, an IEP amendment, a scanned form - and have an OpenAI AI model read it and suggest values for the matching fields on a student record. This is opt-in per upload and only runs on a file a staff member actively chooses to submit.
Every student record is encrypted before it is stored in the database. A copy of the database or a stolen disk, on its own, is not readable without a separate encryption key that is never stored alongside it. Passwords are stored as one-way cryptographic hashes, never in plain text.
Access within the Service is role-based: staff accounts default to seeing only their own caseload, and only admin accounts can view the full roster, export data, or connect the District's Google account. Every meeting change is logged with who made it and when, so activity can be audited after the fact.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach affecting Student Data, we will notify the affected District without unreasonable delay so it can meet its own notification obligations under applicable law.
Student records are retained per the District's own record-retention policy, which the Service does not set. A District admin can deactivate or permanently delete a staff account at any time. To request deletion of a specific student's data, or of your own information, contact your District's administrator directly - the District controls the data held in its instance of the Service, not the Company.
Upon termination of a District's use of the Service, we will return or delete Customer Data in our possession as described in Section 7 (FERPA and Education Records) of the Terms of Service, except where retention is required by law or reasonably necessary for backup, archival, or legal-compliance purposes.
The Service is not directed to children and is not a consumer product that collects information directly from students. Student information is entered by school staff, acting under the District's authority, as part of the District's own special-education recordkeeping obligations - not collected by the Company directly from a child, and not subject to a separate parental-consent flow within the Service itself, consistent with FERPA's school-official exception described in Section 4.
Consistent with California's Student Online Personal Information Protection Act (SOPIPA, Cal. Bus. & Prof. Code § 22584 et seq.) and similar state student-privacy laws, we do not:
Because the District controls the Student Data and staff account data held in its instance of the Service, requests to access, correct, or delete that information should generally go to your District's QuikComply administrator, who can action most requests directly within the Service or by contacting us on the District's behalf. Where we receive a request directly from an individual, we will refer it to the relevant District unless doing so is not appropriate under the circumstances.
A District administrator can, at any time: export or review its full roster, correct any record, deactivate or delete a staff account, and disconnect any connected Google account.
The California Consumer Privacy Act, as amended (CCPA/CPRA), generally exempts personal information collected in the education context, and student records subject to FERPA, from certain of its requirements. To the extent the Service processes personal information about District staff (rather than students) that is subject to the CCPA/CPRA, those staff members' rights are addressed through the District as their employer, consistent with this Section and Section 12. We do not sell or share (as those terms are defined under the CCPA/CPRA) personal information.
The Service is intended for use by school districts and staff located in the United States, and Customer Data is stored and processed in the United States. The Service is not intended for use outside the United States, and we make no representation that it is appropriate or available for use in other locations.
We may update this policy from time to time. If we make a material change, or a change that affects how Google user data is handled, we will update the "Last updated" date above and notify District administrators. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.
Questions about how your District's instance of the Service handles data should go to your District's QuikComply administrator. Districts may contact the Company directly at [privacy/contact email].