Aspire Data Security and Privacy

Purpose

This policy describes how Aspire Technology Partners, LLC. (Aspire) protects customer and personal data throughout its lifecycle—collection, processing, storage, transmission, sharing, retention, and disposal—and how we meet our privacy obligations. It is derived from Aspire’s internal Information Security Program and limits scope to Data Security and Privacy topics for external audiences.

Scope

This document applies to all data processed by Aspire in the course of delivering services, and to personnel, contractors, and approved third parties with authorized access to such data, regardless of medium (electronic or paper).

Key Definitions

  • Personally Identifiable Information (PII): Information that can identify an individual; includes New Jersey‑defined PII (name plus SSN, driver’s license, or financial account number).
  • Student Data: Personally identifiable information from student education records received from an educational agency, as defined by FERPA and New York Education Law §2-d.
  • APPR Data: Personally identifiable information from annual professional performance reviews of classroom teachers or principals, protected under New York Education Law §2-d.
  • Protected Health Information (PHI): Health information protected under HIPAA when Aspire operates in a HIPAA‑relevant capacity.
  • Cardholder Data (CHD): Payment card information governed by PCI DSS when Aspire’s services interact with cardholder data.
  • Governance & Policy Management (External Summary)

Governance & Policy Management (External Summary)

Aspire maintains administrative, technical, and physical safeguards; policies are reviewed at least annually and updated for legal, regulatory, and environmental changes. Internal governance bodies administer detailed standards and procedures (not published externally).

Data Classification

Aspire classifies data into four categories to determine protection:

Class Description Examples
Public Intended for broad disclosure; no special protection required beyond integrity of source. Website content, press releases.
Internal Business information not intended for public release. Internal memos, contact lists, procedures.
Confidential Unauthorized disclosure may adversely affect individuals or Aspire. Customer documents, personnel records, legally privileged information.
Restricted Use Highest sensitivity; legal and contractual protection required. NJ PII, PHI, PCI CHD, credentials, export-controlled data.

Data Handling & Protection Requirements

General Controls (apply to Internal/Confidential/Restricted Use):

  • Least Privilege Access: Access granted for authorized tasks only; based on business need; denied until explicitly approved.
  • Unique Authentication: Credentials are unique per user; any shared credential requires written authorization and periodic re‑
  • Secure Configuration & Malware Protection: Devices and systems implement preventative controls and are monitored.
  • Encryption: Data in transit is encrypted; Restricted data on mobile devices must be encrypted or protected by an approved equivalent measure.
  • Monitoring & Logging: Event monitoring supports security operations; access to logs is restricted; records retained per policy/legal requirements.

Handling by Class (excerpt):

  • Public: No confidentiality requirement; protect integrity of original sources.
  • Internal: Restrict external sharing without owner approval.
  • Confidential: Store/transfer securely; report any suspected unauthorized disclosure to Aspire’s security team.
  • Restricted Use: Apply highest safeguards; adhere to specific regulatory requirements (e.g., HIPAA, PCI DSS); stricter access approval and monitoring.

Privacy of Personal Information

  • Collection: Aspire collects PII only when the need is clearly established for business or legal purposes, and stores it only when appropriate and relevant to the purpose collected.
  • Access: Access to personal information is limited to personnel with a valid business use and need‑to‑know; such access is subject to policy and legal constraints.
  • Use & Disclosure: Aspire respects privacy and will not access, modify, or disclose personal information except as permitted by policy and law (e.g., compliance, incident response, valid legal orders).
  • Data Subject/Individual Requests: Aspire supports appropriate requests consistent with applicable laws and contracts (e.g., access or deletion where legally mandated). (Note: external articulation; details governed by law/contract.)
  • No Sale or Advertising (Student Data): Aspire does not sell or rent Student Data, does not use it for marketing, advertising, or targeted advertising, and does not build student profiles for any purpose other than the contracted services.

Student Data — New York Education Law §2-d (Education Services)

This section applies when Aspire delivers services to New York educational agencies under a student data privacy agreement, including services co-delivered with subprocessors. Where it is stricter than the general provisions of this policy, it controls for Student Data and APPR Data.

Collection scope: Aspire collects only the student data elements enumerated in the applicable agreement’s Schedule of Data (Exhibit B), and only the minimum needed to deliver the contracted services. Roster and directory feeds are filtered to the approved elements before storage.

Parents Bill of Rights: Aspire complies with each educational agency’s Parents Bill of Rights for Data Privacy and Security, signs the agency’s supplemental information where required, and publishes its education-specific Data Security and Privacy Plan.

Data residency and frameworks: Student Data and APPR Data are stored only within the United States, Canada, and the European Union. Safeguards for these services follow the ISO 27000 series and the CIS Critical Security Controls, aligned with the NIST Cybersecurity Framework as referenced in 8 NYCRR Part 121.

Demonstrations and testing: Real Student Data is never used in demonstrations, sales presentations, or test environments. Demonstration environments contain only synthetic (fabricated) records that cannot be traced to any student.

Contact: Questions or complaints regarding Student Data may be directed to legal@aspiretransforms.com, Aspire Technology Partners, LLC, 25 James Way, Eatontown, NJ 07724.

Access Control (External Summary)

  • Access to protected data is provisioned, modified, and revoked per documented processes; changes are tracked and periodically reviewed (at least annually for protected systems).
  • Separation of duties is maintained to avoid excessive privileges; credentials are limited to job duties.

Logging, Monitoring & Security Operations (External Summary)

Aspire conducts event monitoring for security purposes only; records are protected against unauthorized access and regularly reviewed; retention aligns with legal and policy requirements.

Data Retention & Disposal

  • Retention: Aspire retains data per approved retention schedules; schedules are updated in collaboration with leadership to meet changing requirements.
  • Disposal:
    • Paper (non‑sensitive): recycle/trash.
    • Paper (Confidential/Restricted): shred.
    • Electronic (non‑sensitive): erasure/deletion.
    • Electronic (Confidential/Restricted or device end‑of‑life): secure digital destruction coordinated with IT.
  • Student Data (NY §2-d): Returned or securely destroyed within sixty (60) days of an educational agency’s request; on termination without direction, disposed of after ninety (90) days’ prior notice; destruction certified in writing, including destruction by subprocessors.

Third‑Party Access & Subprocessors

Third parties may access protected information only when required for an authorized task, after controls are implemented and appropriate agreements are signed (including confidentiality/security terms).  For Student Data, each subprocessor is bound by a written agreement no less stringent than Aspire’s data privacy agreements: use limited to the contracted service, no further disclosure, reasonable security, required confidentiality training, and no property, licensing, or ownership rights in Student Data or APPR Data. Aspire examines each subprocessor’s privacy and security measures before use and periodically thereafter; if a subprocessor materially fails to comply, Aspire will notify the affected educational agency, remove the subprocessor’s access, and retrieve or ensure secure deletion of affected data

Incident Response & Breach Notification

  • Aspire maintains an incident response plan addressing discovery, containment, investigation, remediation, communications, and post‑incident improvements; incidents involving protected data are treated as confidential and escalated per policy.
  • Aspire will notify affected parties and, where applicable, regulators when required by law or contract. For Student Data received from New York educational agencies, Aspire notifies the affected agency within seventy-two (72) hours of confirmation of an incident (unless notification would disrupt a law enforcement investigation), including — as available — the types of information affected, the known or estimated dates, the number of records affected, a description of the incident and investigation, and a point of contact.

Training & Awareness (External Summary)

Personnel with access to protected data complete security awareness training (including HIPAA/PCI‑relevant training where applicable). Personnel, assignees, and subprocessors with access to Student Data or APPR Data complete training on FERPA and New York State confidentiality requirements before access is granted, and annually thereafter.

Compliance Statement

Aspire’s practices are designed to support compliance with applicable laws/regulations (e.g., FERPA, COPPA, New York Education Law §2-d and 8 NYCRR Part 121, HIPAA, PCI DSS, and other applicable state privacy/security requirements) and Aspire will cooperate with customer due diligence and audits where contractually agreed. Upon request of the NYSED Chief Privacy Officer, Aspire will provide its relevant policies and procedures, undergo a required privacy and security audit performed by an independent third party, or provide an industry-standard independent audit report issued within the preceding twelve (12) months.

Policy Maintenance

This external policy is reviewed at least annually and updated as needed. It is a summary of Aspire’s internal controls; internal procedures and governance remain confidential.