Compliance at a Glance
Key requirements your district's IT security review will check for.
FERPA Compliant
NostaView operates as a school official under direct LEA control. No re-disclosure of education records. Annual FERPA notice guidance provided.
COPPA Compliant
No PII collected from contributors (no account required). School consent model documented. Parental deletion rights honored.
SDPA Available
Student Data Privacy Agreement ready for district signature. Modeled on SDPC national template. Countersigned PDF within 2 business days.
Data Security
AES-256 at rest, TLS 1.2+ in transit. Role-based access control. No data stored outside the United States. 24-hour breach notification.
No Data Sale
Student data is never sold, rented, or shared for commercial purposes. Revenue comes from school subscriptions only.
US-Based Storage
All student data stored on US infrastructure (Render Oregon, Cloudflare R2 US). No international transfers of student data.
Legal Documents
Review and download all NostaView legal documents. District IT and procurement teams typically need the SDPA and Privacy Policy.
Student Data Privacy Agreement (SDPA)
The primary document for US school district procurement. Covers FERPA, COPPA, data use limitations, no-sale commitment, security, breach notification, and state privacy laws. Modeled on the SDPC national template.
View full SDPA →Privacy Policy
Full data privacy practices including FERPA educational records treatment, COPPA compliance, data collection scope, sub-processors, retention schedule, and breach notification procedures.
View Privacy Policy →Data Processing Agreement (GDPR DPA)
For EU, UK, and EEA schools operating under GDPR or UK GDPR. Formalizes the controller-processor relationship with Standard Contractual Clauses and Schrems II safeguards.
View DPA →Terms of Service
The full service agreement covering subscription tiers, FERPA school official status, COPPA obligations, content ownership, liability limits, and governing law for US and international schools.
View Terms of Service →Acceptable Use Policy
Guidelines for appropriate use of the photo collection service, photo consent requirements, prohibited content, and enforcement procedures for school administrators and contributors.
View Acceptable Use →Cookie Policy
Details on cookies used by the platform, their purpose, duration, and how administrators and contributors can manage cookie preferences. No advertising or tracking cookies used.
View Cookie Policy →Data Practice Summary
Quick-reference table for vendor security reviews and questionnaires.
| Requirement | NostaView Practice | Status |
|---|---|---|
| FERPA compliance | School official status; no re-disclosure; educational purpose only | ✓ Yes |
| COPPA compliance | No PII from under-13 without school consent; anonymous QR upload flow | ✓ Yes |
| Student Data Privacy Agreement | SDPC-modeled SDPA available; signed copy provided within 2 business days | ✓ Yes |
| Data stored in the United States | Render (Oregon) + Cloudflare R2 (US region) | ✓ Yes |
| Encryption at rest | AES-256 | ✓ Yes |
| Encryption in transit | TLS 1.2+ | ✓ Yes |
| Data sale prohibition | Absolute prohibition; no exceptions; survives termination | ✓ No sale |
| Behavioral advertising prohibition | No advertising technology or targeting on student data | ✓ No advertising |
| Breach notification timeline | LEA notified within 24 hours of confirmed or suspected breach | ✓ 24 hours |
| Data deletion on termination | All student data deleted within 60 days; written certification provided | ✓ Yes |
| Parental deletion rights | Delete photos of specific students on request; completed within 30 days | ✓ Yes |
| Access controls | Role-based access; school data isolated by account; session timeouts | ✓ Yes |
| Facial recognition | Not used. No biometric data collected. | ✓ Not used |
| AI training on student data | No AI training on identifiable student photos without explicit LEA consent | ✓ Not done |
| Sub-processor disclosure | Full list in SDPA; 30-day notice of changes | ✓ Yes |
| Annual security review | Annual security review and penetration testing procedures | ✓ Yes |
IT & Procurement FAQ
Common questions from district IT security offices and procurement teams.
Ready to move forward?
Our team responds to IT security reviews and procurement requests within 2 business days.