Data Privacy and Security Policy

Effective Date: April 1, 2026

Last Updated: March 31, 2026

Introduction and Purpose

This Data Privacy and Security Policy ("Policy") describes how American Allied Health, Inc. ("Company," "we," "us," or "our") collects, uses, stores, shares, and protects personal information obtained from and about our users, including students and school administrators (collectively, "Account Holders" or "you"). We are committed to safeguarding the privacy and security of all personal information entrusted to us and to maintaining transparency about our data practices.

This Policy applies to all personal information collected through our website, applications, products, and services (collectively, the "Services"). By using our Services, you acknowledge that you have read and understood this Policy.

Scope and Applicability

This Policy applies to all Account Holders who access or use our Services, as well as to the personal information of students whose data is provided to us by students, educational institutions, school districts, parents, or guardians. We recognize the sensitive nature of student data and are committed to handling such information in accordance with applicable federal and state laws, including the Family Educational Rights and Privacy Act ("FERPA"), the Children's Online Privacy Protection Act ("COPPA"), and applicable state student privacy laws.

Definitions

For purposes of this Policy, the following terms have the meanings set forth below:

Personal Information means any information that identifies, relates to, describes, or could reasonably be linked to a particular individual, including but not limited to name, address, email address, telephone number, date of birth, and government-issued identification numbers.

Student Data means Personal Information that is directly related to a student and maintained by an educational institution or by a party acting for such institution, including education records as defined under FERPA.

Sensitive Data means Personal Information that warrants heightened protection due to its nature, including Student Data, financial information, health information, biometric data, and precise geolocation data.

De-identified Data means data that cannot reasonably be used to identify an individual and for which we have implemented technical safeguards and business processes to prevent re-identification.

Data Collection Practices

Categories of Information We Collect

We collect the following categories of Personal Information in connection with providing our Services:

Account and Registration Information. When you create an account or register for our Services, we collect information such as your name, email address, username, role (e.g., student, teacher, administrator, or parent), and affiliated school or district.

Student Information. When educational institutions or parents provide Student Data to us, we may receive information such as student name, student identification number, grade level, date of birth, and educational records as necessary to provide our Services.

Technical Information. We collect technical data such as IP address, device type, operating system, browser type, and unique device identifiers to ensure the proper functioning and security of our Services.

Communications. We retain records of communications you send to us, including support requests, feedback, and inquiries.

Methods of Collection

We collect Personal Information through the following methods: directly from you when you provide it to us during registration or use of our Services; from educational institutions, school districts, or other authorized parties who provide Student Data on behalf of students; automatically through cookies, log files, and similar technologies when you access our Services; and from third-party service providers who assist us in delivering our Services.

Children's Privacy

We are committed to protecting the privacy of children. We do not knowingly collect Personal Information directly from children under the age of 13 without verifiable parental consent or the authorization of an educational institution acting in place of the parent pursuant to FERPA. When we receive Student Data from educational institutions concerning children under 13, we rely on the institution to obtain any necessary parental consent. If we learn that we have collected Personal Information from a child under 13 without proper authorization, we will take steps to delete such information promptly.

Use of Information

We use the Personal Information we collect for the following purposes:

Providing and Improving Services. We use your information to operate, maintain, and improve our Services; to personalize your experience; to respond to your requests; and to develop new features and functionality.

Educational Purposes. We use Student Data solely for legitimate educational purposes as directed by the educational institution. Such purposes include supporting classroom instruction, and assessing student progress.

Communication. We use your contact information to send service-related communications, including account notifications, technical updates, security alerts, and support messages.

Compliance. We use information to comply with applicable laws, regulations, and legal processes, and to enforce our terms and conditions and other agreements.

Analytics and Research. We may use De-identified Data for analytics, research, and reporting purposes to understand usage trends and improve our Services. We do not use Student Data for advertising, marketing, or profiling purposes.

Data Storage and Retention

Storage Location and Infrastructure

We store Personal Information on secure servers located in the United States. We use commercially reasonable physical, technical, and administrative safeguards designed to protect the confidentiality, integrity, and availability of stored data.

Retention Periods

We retain Personal Information only for as long as necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Specific retention periods vary based on the type of data and applicable legal requirements.

Student Data. We retain Student Data for the duration of our contractual relationship with the educational institution, plus a reasonable period thereafter to allow for data retrieval or as required by applicable law. Upon request, we will delete or return Student Data within a reasonable timeframe, typically not exceeding 60 days, unless retention is required by law.

Account Information. We retain Account Holder information for as long as your account remains active and for a reasonable period thereafter to comply with legal obligations and resolve disputes.

Data Deletion

Account Holders may request deletion of their Personal Information by contacting us as described in the "Contact Information" section below. We will respond to such requests in accordance with applicable law and this Policy. Certain information may be retained as required by law or for legitimate business purposes, such as maintaining records for audit or compliance purposes.

Data Sharing and Disclosure

We do not sell, rent, or trade Personal Information. We share Personal Information only in the following circumstances:

With Educational Institutions. We share Student Data with the educational institutions that have provided such data to us or on whose behalf we process the data.

With Service Providers. We share Personal Information with third-party vendors, contractors, and service providers who perform services on our behalf, such as hosting, data analytics, customer support, and email delivery. These service providers are contractually obligated to use Personal Information only for the purposes of providing services to us and to maintain appropriate security measures.

For Legal Compliance. We may disclose Personal Information when required by law, subpoena, court order, or other legal process, or when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or other similar transaction, Personal Information may be transferred as part of that transaction. We will provide notice before Personal Information becomes subject to a different privacy policy.

De-identified or Aggregated Data. We may share De-identified Data or aggregated data that cannot reasonably be used to identify any individual for any lawful purpose.

Security Measures

We implement reasonable administrative, technical, and physical safeguards designed to protect Personal Information from unauthorized access, use, disclosure, alteration, and destruction. Our security measures include the following:

Administrative Safeguards

We maintain written security policies and procedures. We designate personnel responsible for data security oversight. We conduct periodic internal reviews of our data security practices. We require employees with access to Personal Information to complete privacy and security training. We limit access to Personal Information to authorized personnel who require such access to perform their job functions.

Technical Safeguards

We encrypt Personal Information in transit using industry-standard Transport Layer Security (TLS) encryption. We encrypt Sensitive Data at rest using strong encryption algorithms. We implement access controls, including unique user authentication and role-based permissions. We maintain firewalls, intrusion detection systems, and antivirus software to protect against external threats. We conduct regular vulnerability assessments and apply security patches in a timely manner. We implement secure software development practices.

Physical Safeguards

We store data on servers maintained in secure facilities with restricted physical access. We require our hosting and data center providers to maintain appropriate physical security measures.

Incident Response

We maintain an incident response plan to address potential security incidents. In the event of a suspected security breach, we will promptly investigate and take appropriate remedial measures.

User Rights

We respect your rights regarding your Personal Information. Depending on your jurisdiction and applicable law, you may have the following rights:

Right to Access. You may request confirmation of whether we process your Personal Information and request a copy of such information.

Right to Correction. You may request that we correct inaccurate or incomplete Personal Information.

Right to Deletion. You may request that we delete your Personal Information, subject to certain exceptions required by law or legitimate business purposes.

Right to Data Portability. You may request a copy of your Personal Information in a structured, commonly used, and machine-readable format.

Right to Withdraw Consent. Where processing is based on your consent, you may withdraw that consent at any time.

Parental Rights. Parents and guardians have the right to review their child's Personal Information, request correction or deletion, and refuse further collection or use of their child's information.

To exercise any of these rights, please contact us using the information provided in the "Contact Information" section below. We will respond to your request within a reasonable timeframe and in accordance with applicable law. We may require verification of your identity before processing your request.

For Student Data maintained on behalf of educational institutions, please direct your request to the appropriate school or district, as they are the custodians of such records under FERPA.

Breach Notification Procedures

In the event of a security breach involving Personal Information, we will take the following steps:

Investigation. We will promptly investigate the nature and scope of the breach to determine what information was affected and how the breach occurred.

Containment. We will take immediate steps to contain the breach and prevent further unauthorized access.

Notification to Affected Parties. We will notify affected Account Holders and educational institutions without unreasonable delay and in accordance with applicable law. Notification will include a description of the incident, the types of information involved, the steps we are taking to address the breach, and recommendations for affected individuals to protect themselves.

Notification to Regulators. We will notify relevant regulatory authorities as required by applicable law.

Remediation. We will implement appropriate measures to remediate the breach and prevent similar incidents in the future.

Documentation. We will maintain records of all security breaches and our response actions.

We encourage you to report any suspected security incidents or vulnerabilities to us immediately by contacting us at the address provided below.

Third-Party Links and Services

Our Services may contain links to third-party websites or integrate with third-party services. This Policy does not apply to the practices of third parties. We encourage you to review the privacy policies of any third-party websites or services you access through our Services.

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes to this Policy, we will notify you by posting the updated Policy on our website with a revised "Last Updated" date. We encourage you to review this Policy periodically to stay informed about our data practices.

Governing Law and Compliance

This Policy is governed by the laws of the State of Arkansas, without regard to conflict of law principles. We are committed to complying with applicable federal, state, and local laws and regulations governing the privacy and security of Personal Information, including FERPA, COPPA, and applicable state student privacy laws.

Contact Information

If you have questions about this Policy, wish to exercise your privacy rights, or have concerns about our data practices, please contact us at:

American Allied Health, Inc., Email: Privacy@AmericanAlliedHealth.com

We will respond to inquiries within a reasonable time and in accordance with applicable law.

Are you Ready to
Get Certified?
Join over 30,000+ members already growing with American Allied Health
Register Now