Privacy Policy

Last updated: September 20, 2026 · Version 2.0

QuikComply ("Service") is a scheduling tool used by a school district's special education staff to manage IEP meetings. This Privacy Policy explains what information the Service handles, why, and the choices available to school districts, their staff, and the families they serve.

Template notice This document follows the conventional structure of a privacy policy for a K-12 education-technology service and reflects the Service's actual, current data practices as of the date above. Bracketed placeholders like [Company Legal Name] mark information the operator should fill in. Because the Service processes education records protected by FERPA, and may be subject to state student-privacy laws such as California's Student Online Personal Information Protection Act (SOPIPA), the operator should have this policy reviewed by qualified legal counsel before relying on it.

1. Roles: District, Staff, and QuikComply

The Service is provided to a school district by its own administrator, for use by that district's own staff. There is no public sign-up - every account is created by a District administrator for a specific staff member. The District decides what information to enter, who on its staff may access it, and how long to keep it; QuikComply acts on the District's behalf as a service provider, in the manner described in this policy.

If you are a parent, guardian, or student named in a meeting record, your school or district's staff entered that information as part of coordinating your IEP meeting. You did not create an account here, and this policy describes how that information is handled on the District's behalf, not a direct relationship between you and QuikComply.

2. Information We Collect

CategoryExamplesSource
Student and family informationName, date of birth, grade, school, disability category, SSID/SEIS/state or local student ID, IEP meeting details and required dates, parent/guardian name, email, and phone numberEntered by District staff, or uploaded via a SEIS/SIRAS/Aeries export, CSV, or other document
Staff account informationName, school email address, role (admin or staff), password (stored as a one-way hash, never in plain text)Entered by a District administrator when creating an account
Meeting and scheduling dataDates, times, locations, attendee lists, staff availability, backup coverage assignments, and a record of when reminder or notification messages were sentGenerated by the Service as staff use it
Technical and log dataIP address, browser type, timestamps, and actions taken within the Service (e.g., which user edited a record and when)Collected automatically for security, troubleshooting, and audit-logging purposes

Every student record is encrypted before it is stored in the database - see Section 9 (Data Security).

3. How Information Is Used

We use the information described above solely to provide, maintain, and improve the Service for the District, including to:

We do not use Student Data for advertising, do not sell Student Data, and do not use Student Data to build a profile of a student for any purpose unrelated to the school purposes described above. See Section 11 (Children's Privacy and SOPIPA).

5. Google Account Access

A District admin may connect one shared Google account to enable real email features and automatic ingestion of documents from a designated Google Drive folder. That access is used only to:

The Service does not integrate with Google Calendar in any way - no event is ever created, read, or synced on any Google Calendar, shared or personal. A reminder email instead attaches a standard .ics calendar file, which works with any calendar application.

The Service's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google account data is never sold, shared with advertisers, used for any purpose beyond what's described here, or used to train AI/ML models of any kind.

6. AI-Assisted Document Import

Case managers can optionally upload a document that isn't a SEIS export - an outside evaluation, an eligibility report, an IEP amendment, a scanned form - and have an OpenAI AI model read it and suggest values for the matching fields on a student record. This is opt-in per upload and only runs on a file a staff member actively chooses to submit.

7. Cookies and Similar Technologies

The Service uses only strictly-necessary cookies required for it to function: a session cookie that keeps you logged in, and a CSRF (cross-site request forgery) token that protects against a specific class of attack on the login and form-submission process. The Service does not use third-party advertising cookies, analytics trackers, or cross-site tracking technologies of any kind.

8. Sharing and Third-Party Service Providers

We do not sell Customer Data or Student Data. We share information only with the following categories of service providers, solely as necessary to operate the Service, and only under contractual terms that limit their use of that information to the purpose described:

We may also disclose information where required to comply with a valid legal process (such as a subpoena or court order), to protect the rights, property, or safety of the Company, our users, or the public, or in connection with a merger, acquisition, or sale of assets, subject to the confidentiality obligations described in this policy carrying over to the successor entity.

9. Data Security

Every student record is encrypted before it is stored in the database. A copy of the database or a stolen disk, on its own, is not readable without a separate encryption key that is never stored alongside it. Passwords are stored as one-way cryptographic hashes, never in plain text.

Access within the Service is role-based: staff accounts default to seeing only their own caseload, and only admin accounts can view the full roster, export data, or connect the District's Google account. Every meeting change is logged with who made it and when, so activity can be audited after the fact.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach affecting Student Data, we will notify the affected District without unreasonable delay so it can meet its own notification obligations under applicable law.

10. Data Retention and Deletion

Student records are retained per the District's own record-retention policy, which the Service does not set. A District admin can deactivate or permanently delete a staff account at any time. To request deletion of a specific student's data, or of your own information, contact your District's administrator directly - the District controls the data held in its instance of the Service, not the Company.

Upon termination of a District's use of the Service, we will return or delete Customer Data in our possession as described in Section 7 (FERPA and Education Records) of the Terms of Service, except where retention is required by law or reasonably necessary for backup, archival, or legal-compliance purposes.

11. Children's Privacy and SOPIPA

The Service is not directed to children and is not a consumer product that collects information directly from students. Student information is entered by school staff, acting under the District's authority, as part of the District's own special-education recordkeeping obligations - not collected by the Company directly from a child, and not subject to a separate parental-consent flow within the Service itself, consistent with FERPA's school-official exception described in Section 4.

Consistent with California's Student Online Personal Information Protection Act (SOPIPA, Cal. Bus. & Prof. Code § 22584 et seq.) and similar state student-privacy laws, we do not:

12. Your Rights and Choices

Because the District controls the Student Data and staff account data held in its instance of the Service, requests to access, correct, or delete that information should generally go to your District's QuikComply administrator, who can action most requests directly within the Service or by contacting us on the District's behalf. Where we receive a request directly from an individual, we will refer it to the relevant District unless doing so is not appropriate under the circumstances.

A District administrator can, at any time: export or review its full roster, correct any record, deactivate or delete a staff account, and disconnect any connected Google account.

13. Additional Notice for California Residents

The California Consumer Privacy Act, as amended (CCPA/CPRA), generally exempts personal information collected in the education context, and student records subject to FERPA, from certain of its requirements. To the extent the Service processes personal information about District staff (rather than students) that is subject to the CCPA/CPRA, those staff members' rights are addressed through the District as their employer, consistent with this Section and Section 12. We do not sell or share (as those terms are defined under the CCPA/CPRA) personal information.

14. International Users and Data Location

The Service is intended for use by school districts and staff located in the United States, and Customer Data is stored and processed in the United States. The Service is not intended for use outside the United States, and we make no representation that it is appropriate or available for use in other locations.

15. Changes to This Policy

We may update this policy from time to time. If we make a material change, or a change that affects how Google user data is handled, we will update the "Last updated" date above and notify District administrators. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.

16. Contact Us

Questions about how your District's instance of the Service handles data should go to your District's QuikComply administrator. Districts may contact the Company directly at [privacy/contact email].