Privacy

 

Hughes Technology, LLC, - Education

Data Privacy and Security Policy

Document ID: HT-PP-26.1.1
Effective date: July 1, 2026
Policy owner: Management-designated Privacy and Security Lead
Privacy and security email: Support@HughesEducation.net
Telephone and mailing address: 844.437.6123 - PO Box 389, Mountain Home AR 72654

1. Purpose and scope

Hughes Technology, LLC provides education technology services to school districts, education agencies, and other education customers. This policy explains how we collect, use, protect, share, retain, and delete information in those services.

It applies to customer-provided records, information submitted by authorized users, and personal information generated through the covered services, including relevant student, parent, educator, and staff information. It applies to personnel and service providers handling that information on our behalf.

The covered products, categories of information, and material processing details are identified in the applicable service privacy schedule. Each schedule supplements this policy and is available with the service's privacy notice. This policy does not, by itself, describe unrelated public-site advertising, employment records, or separate consumer products.

Applicable law governs. Executed customer agreements may impose additional or more protective requirements, which we honor. This policy does not amend those agreements or eliminate protections that apply to information already collected.

2. Customer control and our role

Customer records remain under the customer's control, subject to the rights of students, parents, staff, and others under applicable law. We do not claim ownership of those records. We process them for authorized service purposes and according to lawful customer instructions.

Where a district relies on FERPA's school-official exception, we act under its direct control concerning the use and maintenance of education records and observe the applicable restrictions on use and redisclosure. Other disclosure arrangements must have an appropriate lawful basis.

3. Information we collect

Depending on the contracted service, information may include:

  • Account details, user roles, district or school affiliations, and contact information.

  • Student identifiers, enrollment, attendance, grades, assessment results, behavior records, and other education records authorized for the service.

  • Evaluation, intervention, disability-related, health-related, or family information when necessary for an expressly authorized feature.

  • Uploaded documents, customer communications, support requests, and reports or other outputs created through the service.

  • Limited technical records, such as sign-in events, device or browser information, IP addresses, errors, and service-use events needed for operation, support, and security.

Information comes from customers, their authorized integrations, authorized users, and operation of the service. We limit collection to information reasonably needed for the authorized purposes. A category listed here does not mean every product collects it.

Customers should avoid submitting unnecessary sensitive information. If we identify an unnecessary or unauthorized transfer, we restrict its use and work with the customer to remove, return, or reject it securely.

4. How we use information

We use customer information to provide configured services, generate customer-requested analyses and reports, assist authorized users, resolve errors, maintain security, and meet applicable legal obligations. Support and quality checks involving identifiable records remain limited to authorized service purposes and authorized personnel.

We do not sell or rent customer personal information, use it for targeted advertising, or build student profiles for unrelated commercial purposes. We do not place advertising trackers in authenticated education services. Necessary session, security, and operational technologies are described in the service privacy schedule.

De-identified or aggregate information may be used only where permitted by law and the customer agreement. We assess whether individuals could reasonably be identified, including through small groups or combined datasets. Replacing a name with a code does not by itself make data anonymous. We do not attempt to re-identify information that has been de-identified.

Sharing identifiable records for external research or university validation requires a separate lawful basis and any required written agreements or authorization. This policy does not authorize such sharing on its own. Customer names, logos, and identifiable case studies require the customer's written permission before promotional publication.

5. Artificial intelligence

AI features may help authorized users search records, summarize information, prepare drafts, or identify matters for review. Before a feature processes customer records, we document its purpose, the information involved, the provider, and applicable retention and access arrangements.

We do not use customer records to train or fine-tune AI models, and we do not permit AI providers to use those records for their own model training or unrelated product improvement. Provider terms and available settings must support these restrictions before customer records are submitted.

Authorized processing may include inference and creation of customer-specific search indexes or embeddings. These remain protected customer information and follow the same access, isolation, retention, and deletion requirements. They are not available to other customers.

We minimize information sent to AI providers and remove or mask identifiers where practicable for the task. Where identifiable content is necessary, including document processing, we disclose that processing in the applicable service information and obtain the authorization required by law and the agreement. A user acknowledgement does not replace legally required consent or district authorization.

Personnel may not place customer records in personal AI accounts, unapproved AI tools, or unapproved coding-agent environments.

AI outputs may contain errors. We identify AI-generated recommendations and drafts and require appropriate human review before consequential educational use. AI does not replace the educators, parents, committees, or other people responsible for eligibility, placement, discipline, or other decisions. We provide customers a way to report problematic outputs. Available AI controls and any effect of disabling AI on service functionality are disclosed for the relevant product.

6. Security safeguards

We maintain administrative, technical, and organizational safeguards appropriate to the sensitivity of the information and the risks of the service. Our documented security practices include:

  • Authorized access based on job responsibilities, customer scope, and least privilege; individual accounts for people and restricted service accounts for system processes.

  • Multi-factor authentication for privileged access; protected credentials; and prompt removal of access when it is no longer authorized.

  • Encryption of customer personal information during transmission over external networks and while stored, including backups.

  • Controls in the application and underlying data access design to prevent unauthorized access between customers, with documented isolation verification before production use and after material relevant changes.

  • Separation of production from ordinary development and testing, use of synthetic or appropriately de-identified test information, and restricted handling of any necessary recovery validation.

  • Supported software, secure configuration, risk-based vulnerability remediation, and review of material changes affecting customer information.

  • Security logging, investigation of suspicious activity, and protection of logs against unauthorized access or alteration.

  • Protected work devices, confidentiality obligations, personnel guidance and training, and restrictions on local copies and personal accounts.

  • Documented backup, recovery, retention, and incident-response procedures, with periodic verification appropriate to risk.

Technical methods may evolve while maintaining the protections required by this policy, law, and customer agreements. No system can eliminate every security risk; that limitation does not reduce our responsibilities under this policy.

7. Service providers and data locations

We use approved providers for functions such as hosting, storage, communications, support, and authorized AI processing. We assess providers before permitting access to customer personal information and obtain written terms addressing confidentiality, limited use, appropriate security, permitted onward disclosure, incident cooperation, and retention or deletion.

We confirm that arrangements meet applicable legal and contractual requirements. If they do not, we resolve the gap or do not use the provider for the affected information. A provider's general reputation or certification is not a substitute for that review. We remain responsible for our own duties when using providers.

We maintain a list of material providers, their functions, and relevant data categories and locations. The service privacy schedule identifies or links to this information and specifies authorized storage and processing locations, including material AI and support arrangements. We comply with applicable location restrictions and required notice, consent, or objection procedures when providers or processing locations change.

8. Requests and disclosures

Customers and their authorized users can request access, correction, export, or deletion through the contact listed in this policy or the agreed support channel. We verify authority before releasing or changing records and provide reasonable assistance consistent with applicable requirements. Available self-service functions vary by product.

Parents and eligible students should ordinarily contact their school or district about education records. If a request reaches us, we coordinate with the responsible customer and support the response. Where law gives a person rights directly against us, we address those rights rather than requiring the person to rely solely on the district. Requests to stop further collection are handled where applicable.

We disclose customer information only to authorized recipients, approved providers acting for permitted purposes, or as otherwise required or permitted by applicable law and the agreement. For legal demands, we assess validity, limit disclosure, and notify the customer beforehand when legally permitted and practicable, while meeting any mandatory notice requirements.

9. Retention, return, and deletion

We retain customer personal information only for the documented purposes and periods in the applicable retention schedule, customer agreement, or law. The service privacy schedule states the relevant retention periods or triggers and deletion timeframes, including backup expiration.

On an authorized deletion request or service termination, we return or delete information as required by applicable law and the customer agreement. If neither specifies a deadline, we act without unreasonable delay under the disclosed schedule and communicate the expected completion date. Customers have a reasonable opportunity to export their records before termination-related deletion, unless an earlier action is required.

Deletion procedures address active records, uploaded files, generated outputs, caches, search indexes, and relevant provider-held copies. Restricted backups expire under the disclosed schedule only where that treatment is legally and contractually permitted. They are not used for ordinary processing, and applicable deletion instructions are reapplied if a backup is restored.

Any retained information required for a legal obligation or preservation hold is limited to that purpose, protected, and deleted when the obligation ends. We do not retain records indefinitely for possible future use. On request or where required, we provide accurate deletion confirmation, identifying any lawful residual retention and its expected end date.

10. Security incidents

We maintain incident-response procedures to assess suspected incidents, contain harm, preserve relevant evidence, restore services, and coordinate notifications. We identify responsible personnel and an escalation route, including coverage for urgent incidents outside normal business hours.

We notify affected customers without undue delay when we discover unauthorized access, acquisition, use, or disclosure affecting their personal information. Where applicable law or the customer agreement requires immediate notice or a specific deadline or broader trigger, that requirement applies. We do not delay a required notice until the investigation is complete.

Initial notices include the information reasonably available at the time, such as the incident's nature, potentially affected information, actions taken, and a response contact. We provide material updates as facts become available and cooperate with applicable individual and regulatory notices. Any legally authorized delay is documented.

11. Children's information

For services subject to COPPA, we provide required notices and obtain required consent before covered collection. We rely on school authorization only where legally permitted for the educational service. We remain responsible for the duties that apply to us. Relevant product notices explain collection, recipients, retention, and how to exercise applicable rights.

12. Accountability and assurance

Management assigns responsibility for privacy and security and maintains an internal review program. We assess risks, review this policy and supporting practices at least annually and after material changes, and record identified gaps and corrective actions. Required testing and assessments are performed under applicable law and agreements.

Our standard is company-defined and internally assessed. Any reference to an external security framework identifies guidance or a specifically documented assessment scope; it is not a claim of certification. Provider certifications do not certify Hughes Technology. We describe independent assessments and company-held certifications only when completed and applicable to the stated scope.

We honor audit and assurance obligations in customer agreements and applicable law. Other requests are addressed through relevant documentation or an agreed review scope, with safeguards for confidentiality, system security, and other customers' information.

13. Policy changes and contact

We date material revisions and provide notice as required by law and customer agreements. We obtain any required consent before changing the use of information. A revision does not automatically authorize new uses of previously collected records or reduce existing contractual protections.

For questions, rights requests, or security concerns, contact the Privacy and Security Lead using the verified email, telephone number, or mailing address at the beginning of this policy.

Approved by: Security board of advisors
Approval date: June, 2026