This Data Security and Privacy Plan describes how Readflexes protects the personally identifiable information ("PII") of students and educators that it receives when a school or district uses the Readflexes service (the "Service"). It is provided as the "Data Security and Privacy Plan" referenced in student data privacy agreements, including the SDPC National Data Privacy Agreement (NDPA), and should be read together with the Readflexes Privacy Policy and any signed Data Privacy Agreement ("DPA"). Where a signed DPA and this Plan conflict, the signed DPA controls.
1. Compliance with applicable data privacy and security laws
Readflexes designs its handling of student and educator data to comply with the data privacy and security requirements that apply to its school and district customers, including:
- the Family Educational Rights and Privacy Act (FERPA), under which Readflexes operates as a "school official" with a legitimate educational interest;
- the Children's Online Privacy Protection Act (COPPA) — for students under 13, Readflexes relies on the school to provide the consent COPPA permits a school to give on a parent's behalf for an educational service;
- the Protection of Pupil Rights Amendment (PPRA);
- applicable state student-privacy laws and regulations, including the student-data-protection terms of the signed NDPA and its state supplements (for example, New York Education Law § 2-d and Part 121, and Massachusetts 603 CMR 23.00 and M.G.L. c. 71 §§ 34D–34H); and
- the terms of each signed DPA, which govern and control over any conflicting term in our general policies.
2. Technical safeguards and controls that protect PII
Readflexes runs on Google Cloud / Firebase infrastructure in the United States and applies administrative, technical, and physical safeguards designed to protect PII, including:
- Encryption in transit and at rest. All connections to the Service use HTTPS/TLS. Data stored in Google Cloud (Firestore, Realtime Database, Authentication) is encrypted at rest by Google Cloud's default encryption.
- Authentication and access controls. Access to accounts is controlled through Firebase Authentication. Sensitive operations are performed by server-side Cloud Functions that verify the requester's identity and authorization before acting, rather than trusting the client.
- Application-integrity protection. Firebase App Check and Google reCAPTCHA are used to verify that requests come from the legitimate application and to deter automated abuse.
- Least-privilege administration. Administrative access to production systems and to the Google Cloud project is limited to authorized personnel and used only as needed to operate and support the Service.
- Secrets management. API keys and other credentials are held server-side (for example, in Cloud Functions environment configuration) and are not exposed in client code.
- Infrastructure security. The Service relies on Google Cloud Platform, whose data centers and platform maintain independent third-party security certifications (including ISO/IEC 27001 and SOC 2). Readflexes inherits the physical and network security of that underlying infrastructure.
3. Alignment to a cybersecurity framework
Readflexes aligns its security practices with the NIST Cybersecurity Framework (CSF) — organizing controls around Identify, Protect, Detect, Respond, and Recover — and operates on Google Cloud infrastructure that is independently certified to ISO/IEC 27001 and SOC 2. Readflexes reviews and improves its safeguards over time as the Service and the threat landscape evolve.
4. Compliance with the LEA's Parents Bill of Rights
Readflexes supports and will comply with each customer LEA's Parents Bill of Rights for Data Privacy and Security. Consistent with those rights, Readflexes affirms that:
- student data will not be sold or used for any marketing or commercial purpose;
- parents and eligible students may, through the school or district, request access to and correction of student data;
- student data is protected by the safeguards described in this Plan, including encryption and access controls; and
- student data is stored and processed in the United States (see Section 8).
5. Training of personnel with access to data
All Readflexes personnel, assignees, and subprocessors who have access to student data or educator data are required to understand and follow this Plan and the confidentiality and data-protection obligations of any applicable DPA before being granted access, and to handle PII only as necessary to operate and support the Service. Access is granted on a need-to-know basis and removed when no longer required.
6. Subprocessors
Readflexes uses a small number of trusted subprocessors to operate the Service. Each is permitted to use data only to provide services to Readflexes and is bound by confidentiality and data-protection obligations (including, for Google, the Google Cloud Data Processing Addendum). Current subprocessors:
| Provider | Purpose | Data location |
|---|---|---|
| Google — Firebase (Authentication, Firestore, Realtime Database, Hosting, App Check) & Cloud Functions | Authentication, data storage, real-time multiplayer, hosting, and application backend | United States |
| Google — Analytics for Firebase | Usage and performance analytics | United States |
| Google — reCAPTCHA | Bot and abuse prevention | United States |
| Google — Classroom API | Roster import (only when authorized by the teacher) | United States |
| Google — Cloud Text-to-Speech | Generating spoken audio of words and prompts | United States |
| Unsplash | Image search for vocabulary sets (image queries only; no student identifiers sent) | United States |
Readflexes maintains this list as its providers change and requires each subprocessor to protect PII received in connection with the Service.
7. Managing data security and privacy incidents
Readflexes maintains an incident response process for events that implicate PII. If Readflexes determines that an unauthorized acquisition, access, use, or disclosure of PII has occurred, it will:
- investigate, contain, and remediate the incident and take reasonable steps to prevent recurrence;
- notify the affected LEA promptly, and in any event within the timeframe required by the applicable DPA and law (for example, in the most expedient time possible and without unreasonable delay);
- provide the LEA with the information reasonably needed for the LEA to meet its own notification obligations (nature of the incident, data involved, and steps taken); and
- cooperate with the LEA's reasonable investigation and response.
8. Data location, retention, return, and destruction
- Location. Student and educator data is stored on Google Cloud infrastructure located in the United States.
- Retention. Readflexes retains PII only for as long as needed to provide the Service, as directed by the school or district, or as required by law.
- Return and destruction. Upon request, or upon expiration or termination of the service relationship or applicable DPA, Readflexes will return and/or securely delete the student data in its possession in accordance with the LEA's direction and the terms of the DPA, subject to any legal retention obligations.
- No secondary use. Readflexes does not sell student data; does not use it for targeted advertising; does not build student profiles except to provide the educational Service; and does not use student PII to train third-party or external artificial- intelligence models.
9. Contact
Questions about this Data Security and Privacy Plan, or requests related to student data, may be directed to:
Email: readflexes@gmail.com