Privacy Policy

EmpowerEd Business Solutions, LLC (“EmpowerEd,” “Company,” “we,” “us,” or “our”) respects privacy and is committed to handling personal information responsibly. This Privacy Policy explains how we collect, use, disclose, retain, and protect information in connection with the EmpowerEd SPED website, online platform, related communications, and services (collectively, the “Services”).

This Privacy Policy applies to website visitors, prospective and current Customers, Users and Authorized Users, and other individuals who interact with EmpowerEd. It also explains how we process Student Data and other information that Customers enter into the platform. Capitalized terms not defined in this Privacy Policy have the meanings stated in the EmpowerEd SPED Terms and Conditions (“Terms”).

The Terms govern use of the Services. The Data Processing Agreement (“DPA”) governs EmpowerEd’s contractual processing of Customer-controlled data. This Privacy Policy is a notice describing our practices; it does not replace or override the Terms or DPA.

1. Scope and Our Data Roles

1.1 Website, Account, and Business Information

EmpowerEd generally determines the purposes for which website, Account, Subscription, support, business contact, and marketing information is processed. We use this information to operate our business, administer Accounts, communicate with Customers and Users, and promote our own products and services as described below.

1.2 Customer-Controlled Platform Data

Customers and Authorized Users determine what Student Data, Client information, service records, rates, Documentation, invoices, reports, notes, and other Customer Data they enter into the platform and the purposes for which they use the Service. EmpowerEd processes this information on Customer’s behalf under the Terms and DPA.

1.3 Customer Responsibility

Customers are responsible for ensuring that they have the rights, permissions, consents, contractual authority, and other lawful bases necessary to provide Customer Data to EmpowerEd. When Student Data originates from or relates to an educational agency or institution, Customer is responsible for confirming that its district contract, data-sharing agreement, policy, authorization, consent, or other lawful basis permits use of EmpowerEd.

2. Information We Collect

2.1 Information Provided for Accounts and Business Interactions

We may collect information that Customers, Users, prospective Customers, and other individuals provide directly, including:

  • Name, business name, professional role, email address, telephone number, and other business contact information.

  • Account credentials and authentication information.

  • Business profile, Subscription, Seat, and Authorized User information.

  • Billing address, transaction status, and limited payment-related records.

  • Information submitted through contact, demo, survey, newsletter, onboarding, or support forms.

  • Support correspondence, feedback, feature requests, and other communications with EmpowerEd.

  • Marketing preferences and records of engagement with our communications.

2.2 Customer-Controlled Platform Data

Customers and Authorized Users may enter or generate information through the platform, including:

  • Student names, identifiers, and Client or district associations.

  • Service dates, types, durations, descriptions, rates, and billing information.

  • Service logs, notes, Documentation, reports, invoices, and related operational records.

  • Disability-related, accommodation, educational-service, or other sensitive educational information that Customer chooses to enter.

  • Uploaded documents, attachments, signatures, and other files.

  • Customer business information and Client contact information.

  • Other information selected or generated by Customer through use of the Service.

2.3 Information Collected Automatically

When an individual visits our website or uses the platform, we and our service providers may automatically collect technical and usage information, such as:

  • IP address and general geographic region derived from it.

  • Browser, device, operating system, and language information.

  • Pages or screens visited, referring sources, dates, times, and interaction information.

  • Login, session, feature-use, and performance information.

  • Cookie, local-storage, or similar technology identifiers.

  • Application logs, error reports, security events, and diagnostic information.

We seek to configure analytics, monitoring, and diagnostic tools to avoid collecting the contents of Student Data or other sensitive Customer content except when reasonably necessary for security, support, troubleshooting, or operation of the Service.

2.4 Payment Information

Subscription payments may be processed by third-party payment processors, including Stripe. EmpowerEd does not receive or store full payment-card numbers on its servers. Payment processors handle payment information under their own privacy policies and terms. We may receive limited transaction information, such as payment status, billing contact, transaction identifier, and the last four digits or type of a payment method.

2.5 Information from Other Sources

We may receive information from referral partners, Customers, payment processors, service providers, and publicly available professional sources, such as business websites, professional directories, and professional or social-media profiles. We may use publicly available business information to identify and communicate with prospective or current Customers.

3. How We Use Information

3.1 Providing and Operating the Services

We may use information to:

  • Create, authenticate, administer, and secure Accounts.

  • Provide, host, maintain, support, troubleshoot, and improve the Services.

  • Organize Customer-entered information and generate service logs, calculations, reports, invoices, and other requested outputs.

  • Process subscriptions and payments.

  • Provide onboarding, support, and Customer communications.

  • Monitor availability, performance, usage, accessibility, and reliability.

  • Prevent fraud, misuse, unauthorized access, and security threats.

  • Maintain backups, business records, and continuity procedures.

3.2 Customer Instructions and Educational Purposes

We process Customer-controlled platform data in accordance with Customer’s instructions as reflected in the Terms, DPA, Customer’s configuration and use of the Service, and any other applicable written agreement. We use Student Data and FERPA Records only for authorized educational, documentation, billing, administrative, security, support, and Service-related purposes.

3.3 Marketing and Business Communications

We may use Account information, Business Contact Data, Subscription information, communications, publicly available professional information, and limited Service usage information to:

  • Communicate about existing and new EmpowerEd features, products, events, and services.

  • Identify products or services that may be relevant to a Customer’s business.

  • Conduct customer research, surveys, analytics, and engagement activities.

  • Identify and communicate with Customers, Users, or prospective Customers through email and professional or social-media channels.

  • Measure and improve our marketing and business-development activities.

We do not use Student Data, FERPA Records, service logs, notes, invoices, uploaded documents, or other sensitive Customer content to advertise or market to students, parents, Clients, or other third parties. We do not target advertising based on Student Data or build advertising profiles concerning students.

3.4 Legal Compliance and Protection

We may use information to comply with applicable law, respond to valid legal process, establish or defend legal claims, enforce our agreements, investigate suspected violations, protect the rights and safety of individuals, and preserve the security and integrity of the Services.

3.5 De-identified and Aggregated Information

We may create and use aggregated, anonymized, or de-identified information for analytics, security, research, benchmarking, product improvement, and other lawful business purposes, provided the information cannot reasonably identify a Customer, User, Client, student, parent, or other individual. We will not attempt to re-identify properly de-identified Student Data except as permitted by applicable law and subject to appropriate safeguards.

4. How We Disclose Information

4.1 Service Providers

We may disclose information to service providers that help us host, maintain, secure, support, and operate the Services, such as infrastructure, database and file-storage, authentication, transactional email, support, monitoring, analytics, backup, payment, and professional-service providers. These providers receive information appropriate to their functions and are subject to applicable contractual or legal restrictions.

4.2 Customers and Authorized Users

Customer Data may be displayed or made available to the Customer and its Authorized Users based on Account configuration, permissions, and Service functionality. Customer controls whom it authorizes to access its Account and Customer Data.

4.3 Payment Processors

We disclose payment and billing information to payment processors as necessary to complete transactions, administer Subscriptions, prevent fraud, and resolve billing issues.

4.4 Professional Advisers

We may disclose information to attorneys, accountants, auditors, insurers, security consultants, and other professional advisers when reasonably necessary for their services and subject to appropriate confidentiality obligations.

4.5 Legal, Safety, and Security Disclosures

We may disclose information when we reasonably believe disclosure is required by law or valid legal process; necessary to protect the rights, property, security, or safety of EmpowerEd, our Customers, Users, students, or others; or necessary to investigate fraud, misuse, or a security incident. Unless prohibited or impracticable, we will direct requests for Customer-controlled data to Customer or notify Customer as described in the DPA.

4.6 Business Transactions

Information may be disclosed in connection with a proposed or completed merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar business transaction, subject to applicable law and continued protection of Student Data and Customer-controlled data.

4.7 Marketing and Advertising Providers

We may disclose Business Contact Data or website interaction information to marketing, analytics, professional-networking, or advertising providers to communicate about and promote EmpowerEd’s own services, as described in this Privacy Policy and subject to applicable law and available opt-out rights. We do not provide Student Data or sensitive Customer-controlled content for advertising or audience matching.

5. Sale, Sharing, and Targeted Advertising

We do not sell Student Data, FERPA Records, or Customer-controlled platform content. We do not use or disclose Student Data, service logs, Documentation, invoices, notes, uploaded files, or other sensitive Customer content for targeted advertising, cross-context behavioral advertising, or the creation of advertising profiles.

We do not sell personal information for money. We may use cookies, advertising technologies, or matched-audience services involving website interaction information or Business Contact Data to promote EmpowerEd’s own products and services. Under some state privacy laws, certain uses or disclosures associated with these activities may be considered a “sale,” “sharing,” or targeted advertising even when no money is exchanged.

We may also communicate directly with Customers, Users, and prospective Customers through email and professional or social-media channels. We do not use Student Data or sensitive Customer-controlled content for these communications.

If we engage in advertising activities subject to applicable privacy law, we will provide any required notice, cookie controls, consent mechanism, or opportunity to opt out. 

6. FERPA and Student Information

6.1 Customer-Directed Processing

Customers may enter Student Data while providing contracted educational services. EmpowerEd processes that Student Data as a downstream technology service provider to Customer and does not independently determine what Student Data Customer enters or whether Customer has authority to disclose it.

6.2 Customer Authorization

Before entering Student Data, Customer must ensure that its contract, data-sharing agreement, district policy, written authorization, valid consent, or another lawful basis permits Customer to use EmpowerEd. An educational agency or institution does not need to subscribe directly to EmpowerEd, but Customer must possess the authority needed to use the Service for the applicable Student Data.

6.3 FERPA Restrictions

To the extent Student Data constitutes personally identifiable information from education records governed by the Family Educational Rights and Privacy Act (“FERPA”), EmpowerEd will use and maintain the information only for authorized purposes and will not redisclose it except as permitted by the Terms, DPA, applicable authorization, and law. Additional contractual terms governing FERPA Records appear in the DPA.

6.4 Record Requests

A parent, guardian, eligible student, Client, or educational institution seeking access to, correction of, or deletion of Student Data should ordinarily contact the Customer, contractor, agency, school, or educational institution responsible for the record. EmpowerEd may direct the requester to the appropriate Customer and will provide reasonable assistance with a verified request as required by applicable law or an accepted written agreement.

7. Children and Student Information

The Services are intended for use by adults, businesses, independent contractors, agencies, educational service providers, and their authorized personnel. Students and children are not permitted to create Customer or User Accounts.

Customers may enter Student Data relating to children while documenting and administering educational services. EmpowerEd receives this information from Customers and Authorized Users, not directly from students through student Accounts. EmpowerEd does not use Student Data to market or advertise to children or to create advertising profiles concerning children.

If we learn that a child has directly provided personal information through an unauthorized Account or interaction, we will take appropriate steps consistent with applicable law. A parent or guardian who believes a child has directly submitted information to EmpowerEd may contact us using Section 16.

8. Cookies, Analytics, and Similar Technologies

We and our service providers may use cookies, local storage, logs, and similar technologies that are necessary to operate and secure the website and platform, maintain login sessions, remember preferences, prevent fraud, diagnose technical problems, and support Service functionality.

We may also use analytics technologies to understand website and platform traffic, interactions, performance, and general usage trends. Analytics providers may receive technical information such as IP address, browser or device information, pages or features accessed, approximate location, and dates and times of interactions.

We do not use cookies or similar technologies to target advertising based on Student Data, FERPA Records, service logs, notes, invoices, uploaded files, or other sensitive Customer-controlled content. Advertising technologies, if used, are intended for the public website and should not be configured to collect sensitive content from authenticated platform pages.

Users may be able to block or delete cookies through their browser or device settings. Blocking cookies may prevent certain website or platform features, including login and session functionality, from operating correctly.

Because there is not a uniform industry standard for traditional “Do Not Track” signals, our Services do not currently respond to those signals. We will recognize legally required opt-out preference signals for activities to which applicable law requires them to apply.

9. Data Retention, Archiving, and Deletion

9.1 Retention During an Active Subscription

We retain Customer Data during an active Subscription as reasonably necessary to provide the Service, preserve Customer records, maintain security and continuity, and fulfill the purposes described in this Privacy Policy, the Terms, and DPA.

9.2 Archiving

The Service may allow Customers to Archive records that are no longer current or needed for active use, including student, Client or district, service type, rate, and service-log records. Archived information remains stored as Customer Data and is not permanently deleted.

9.3 Deletion Requests

The Service does not currently provide routine Customer-controlled permanent deletion of individual platform records. If Customer, an applicable educational agency or institution, or another legally authorized requester believes permanent deletion is required, a verified request may be submitted to EmpowerEd. We will review and respond to the request as required by applicable law, including applicable student-privacy laws, and any accepted written agreement. We may require information necessary to verify the requester’s identity, authority, and the records involved.

9.4 Post-Termination Retention

Following cancellation or termination, Customer Data may be retained for up to one hundred twenty (120) days before permanent deletion, consistent with the Terms and DPA, unless a shorter period is legally required or a longer period is required or permitted for legal compliance, preservation, security, dispute resolution, or another lawful purpose.

9.5 Backups and Business Records

Information stored in backups may remain until overwritten or deleted through ordinary backup cycles and will remain protected while retained. We may retain payment, transaction, security, support, legal, and business records for periods reasonably necessary to comply with law, maintain accurate records, resolve disputes, enforce agreements, and establish or defend claims.

10. Data Security

We maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, acquisition, use, alteration, disclosure, or destruction. Safeguards may include access controls, authentication, encryption, monitoring, backups, secure development practices, incident-response procedures, personnel confidentiality, and service-provider oversight, as appropriate to the Service and information involved.

No system, storage environment, or electronic transmission is completely secure. We therefore cannot guarantee absolute security. Customers are responsible for security within their control, including Account credentials, User permissions, devices, networks, and information exported or disclosed outside the Service.

11. Privacy Choices and Requests

11.1 Account Information

Customers and Users may review or update certain Account information through available Service functionality or by contacting us.

11.2 Marketing Communications

Recipients may unsubscribe from promotional emails by using the unsubscribe mechanism in the message or contacting us. Even after opting out of promotional communications, Customers and Users may continue to receive transactional, security, billing, support, legal, and other nonpromotional communications relating to the Services or Account.

11.3 Cookies and Advertising Choices

Users may manage cookies through available website controls and browser or device settings. If applicable law provides a right to opt out of sale, sharing, or targeted advertising, we will provide an appropriate method for exercising that right.

11.4 Applicable Privacy Rights

Depending on residence and applicable law, an individual may have rights to request access to, correction of, deletion of, or information about certain personal information, or to opt out of certain processing. These rights are subject to legal definitions, exceptions, verification requirements, and applicability thresholds.

11.5 Requests Concerning Customer-Controlled Data

Requests concerning Student Data or other Customer-controlled platform data should ordinarily be directed to the applicable Customer or educational institution. EmpowerEd generally cannot determine independently whether a requester is entitled to a particular education record or whether the record should be changed. We will assist the responsible Customer or educational institution as required by applicable law and the DPA.

11.6 Submitting a Request

Privacy requests may be submitted using the contact information in Section 16. We may request information reasonably necessary to verify identity, authority, Account relationship, and the scope of the request. We will not discriminate against an individual for exercising a privacy right protected by applicable law.

12. Third-Party Websites and Services

The Services may link to or interoperate with websites and services operated by third parties. Their privacy practices are governed by their own policies and terms. We are not responsible for third-party services that Customer chooses to access or use outside EmpowerEd, except to the extent otherwise required by applicable law or expressly agreed in writing.

13. United States Operations

EmpowerEd is based in the United States. Information may be processed in the United States and in other locations where our service providers operate, subject to applicable law and contractual protections.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, the Services, technology, or applicable law. We will post the revised Privacy Policy with an updated effective date and provide additional notice when required by applicable law or when changes are material. The Terms govern any contractual acceptance required for continued use of the Services.

15. Contact Information

Questions, privacy requests, and concerns about this Privacy Policy or our information practices may be directed to:

EmpowerEd Business Solutions, LLC
Email: admin@empoweredsped.com
Website: https://www.empoweredsped.com