Skip to main content
Free 90-day demos of PassTrack, Forms, and Suite. Run them on your own server. Get the demos
Draft for review. This agreement has not yet been reviewed by counsel and is published so districts can see our terms in advance. To execute an agreement now, contact us — we will also sign your district's own form, which most districts prefer.

Data Privacy Agreement

The terms under which Heronix Education Systems handles data belonging to a school or district. The short version: we never receive student data. The software runs on your servers, and the only thing we hold is the name, work email and school name of the staff member who downloaded it.

1. Why this agreement is short

Most vendor privacy agreements are long because the vendor holds the data. Ours is short because we do not.

Heronix software is installed on infrastructure the district owns and controls. Student records, attendance, hall passes, schedules, forms and everything else the software processes are written to the district's own servers and never transmitted to us. There is no Heronix cloud holding your students' information, because there is no Heronix cloud.

That is an architectural fact, not a policy promise. A policy can change; the software has no mechanism to send student data to us.

2. Roles under FERPA

Under the Family Educational Rights and Privacy Act, the district is the educational agency holding education records.

Heronix does not receive education records. We are not a recipient, a processor, or a school official with respect to them, because no education record is transmitted to us in the course of licensing, delivering or supporting the software. There is no disclosure to authorise and no redisclosure to restrict.

Were that ever to change, if a district asked us to host or process records on its behalf, it would require a separate written agreement designating Heronix a school official under 34 CFR 99.31(a)(1). No such arrangement exists today and none is offered.

3. What Heronix actually holds

The complete list, not a summary.

To download an evaluation copy, a staff member creates an account. That account holds three things:

  • their name;
  • their work email address;
  • their school or organization name.

Alongside it we record which build that account downloaded, so support can answer "which version am I running", and any bug report or review the person chooses to submit.

If a district later purchases, the order adds what an invoice requires: a billing address, and the state, which is also what determines our own sales-tax obligations. Nothing else.

That is the entire set. It is business contact information about adult staff. It contains no student data of any kind, because none is ever sent to us. Our privacy policy sets out how long each kind is kept, and how to export or delete it.

Where purchase records live. Invoices and the billing details behind them are held on our own servers in Florida — not with a payment processor, and not in a hosted accounting service — and are also printed and filed. The printed file is our permanent record. The digital copy is kept seven years to satisfy tax law, then sealed into an encrypted, compressed archive and removed from the live system, with the archive destroyed once it is no longer needed. A district that wants a copy of an invoice or a purchase history at any point can ask for one: we mail a printed copy, or scan and send it if it is needed sooner.

4. If student data reaches us anyway

We do not ask for student data, we operate no system that receives it, and no part of licensing, delivery or support requires it. Evaluation copies ship pre-loaded with synthetic sample data and instruct evaluators never to enter real student, staff or family information.

It remains possible for a district to send us something containing education records unprompted: a log file, a screenshot, a database extract attached to a support email. We would rather say what happens then than pretend it cannot occur.

  • We use it only for the issue it was sent about;
  • We do not copy it elsewhere, and we do not use it to train anything;
  • We delete it once the issue is closed, and in any event within 30 days;
  • We tell you it happened, and ask you not to send it again.

If you need to send diagnostic material, redact or synthesise it first and we will help you work out what is actually needed.

5. What we never do

  • We do not sell district or student data. There is no circumstance in which we would.
  • We do not use student data for advertising, profiling or marketing.
  • We do not use district or student data to train machine-learning models.
  • We do not disclose data to third parties for their own purposes.

6. Security

Because the data sits on district infrastructure, most of the security controls that protect it are the district's own. What we are responsible for:

  • The software ships with authentication, role-based access and audit logging, and is designed to run without internet access;
  • Releases are published with SHA-256 checksums so a district can verify a build is the one we produced;
  • Our own systems holding the business data in section 3 use encrypted credentials, multi-factor authentication on administrative changes, and encrypted transport;
  • We will notify an affected district without undue delay, and in any event within 72 hours, of becoming aware of a breach affecting their data.

7. Sub-processors

We use a small number of third-party services to run the website and deliver software. None of them receive student data, because we do not have any to give them:

  • Netlify — website hosting;
  • Cloudflare R2 — storage and delivery of software downloads;
  • Zoho Mail — email delivery;
  • Mercury (banking services provided by partner banks) — payment processing.

We will give notice before adding a sub-processor that would receive district data.

8. Term, and what happens at the end

This agreement runs for as long as the district holds a Heronix licence or an active account with us.

On termination the district keeps its data — it is already on their servers and no action by us is required or possible. Business data we hold under section 3 is deleted on request, except for orders and invoices, which are financial records retained as described in our privacy policy with identifying details removed. Licence keys themselves are kept without the identity attached to them, so that a key issued years earlier can still be recognized if the district calls about it.

9. State student-privacy laws

Several states impose specific contractual terms on educational technology vendors — including New York Education Law ยง 2-d, Illinois SOPPA, California SOPIPA and the Texas Education Code. Where a district is subject to one of these, we will sign the state-specific or district-specific rider required rather than asking the district to accept this document in its place.

10. Contact

Questions about this agreement, or a request to execute your district's own form, go to info@heronixedu.com or (352) 777-6076.

Heronix Education Systems LLC, Hernando County, Florida, United States.