Aivo AI Learning Technologies Inc. ("AIVO," "we," "us") provides an AI‑powered adaptive learning platform to schools and districts. This Notice explains, in detail, how we protect student education records in accordance with the Family Educational Rights and Privacy Act ("FERPA"), 20 U.S.C. § 1232g, and its regulations, 34 CFR Part 99; the Individuals with Disabilities Education Act ("IDEA"), 34 CFR §§ 300.610–300.626, where IEP information is involved; the Protection of Pupil Rights Amendment ("PPRA") where applicable; and applicable state student‑privacy laws.
This Notice supplements our Privacy Policy and COPPA Compliance Notice. For any institution, a separately executed District Agreement and Data Processing Addendum ("DPA") govern and control over this Notice and over our general Terms with respect to that institution's student data.
1. Roles: The School Controls Education Records; AIVO Is a School Official
Under FERPA, the school or district owns and controls student education records. When a school uses AIVO, AIVO acts as a "school official" with a legitimate educational interest under the school‑official exception, 34 CFR § 99.31(a)(1)(i)(B), performing an institutional service or function for which the school would otherwise use its own employees.
2. School‑Official Criteria We Meet
Consistent with 34 CFR § 99.31(a)(1)(i)(B)(1)–(3), AIVO:
- performs an institutional service or function for which the school would otherwise use employees;
- is under the direct control of the school with respect to the use and maintenance of education records (the District Agreement establishes this control);
- uses education records only for the authorized purposes described in the District Agreement; and
- does not re‑disclose personally identifiable information from education records to any other party without the school's authorization, except as permitted by FERPA.
The school is responsible for (a) determining that AIVO meets these criteria, (b) specifying criteria for "legitimate educational interest" in its annual FERPA notification and including AIVO within its "school official" designation where appropriate, and (c) using reasonable methods to ensure AIVO accesses only the records in which it has a legitimate educational interest.
3. Student Data AIVO Processes
Depending on configuration, AIVO may process:
| Data type | Examples |
|---|---|
| Roster / directory‑type information | Name, grade level, class assignment, teacher of record, school/district identifier |
| Authentication information | Credentials or SSO identifiers (e.g., Clever, ClassLink, Google) |
| Learning records (education records) | Assessments, lessons attempted, responses, hints, AI‑tutor interactions, progress, mastery signals, Virtual Brain data |
| Special‑education indicators | Where the school provides them, IEP‑related indicators and accommodations used to personalize learning |
AIVO processes this information only to provide the Services to the school and its students. We do not sell student data, use it for behavioral advertising, build non‑educational profiles, or use personally identifiable student data to train third‑party AI foundation models.
4. Directory Information
FERPA permits schools to designate certain "directory information" that may be disclosed without consent unless a parent/eligible student opts out. AIVO does not independently designate or publicly disclose directory information. AIVO treats all student information it processes as protected and uses it only as the school's service provider, regardless of whether the school has designated some elements as directory information.
5. Use Limitations and No Re‑Disclosure
AIVO uses student education records solely to:
- provide and personalize the learning experience for the student;
- make progress and results available to authorized teachers, administrators, and (where applicable) parents and invited collaborators;
- maintain security and integrity and prevent abuse; and
- provide support, and improve the Services using aggregated or de‑identified data consistent with FERPA and applicable state law.
AIVO does not re‑disclose personally identifiable information from education records except as described in Section 6. Where AIVO re‑discloses on behalf of the school under FERPA, AIVO does so only on the school's instruction and consistent with the recordkeeping requirements of 34 CFR § 99.32, and AIVO will provide the school the information it needs to maintain the required record of disclosures.
6. Permitted Disclosures
AIVO discloses personally identifiable information from education records only:
- back to the school/district;
- to sub‑processors acting under AIVO's direction, bound by confidentiality, use‑limitation, and security obligations consistent with FERPA and the District Agreement (a re‑disclosure on the school's behalf within the school‑official framework);
- with the school's authorization (which may reflect parental/eligible‑student consent the school has obtained);
- to comply with a lawful subpoena or judicial order, where permitted, and — where the order does not prohibit it — after notifying the school so it can seek protective action; or
- in a health or safety emergency consistent with 34 CFR §§ 99.31(a)(10) and 99.36, on the school's instruction or as permitted by law.
7. Parent and Eligible‑Student Rights (Through the School)
FERPA gives parents and "eligible students" (students 18 or older, or attending a postsecondary institution) the rights to inspect and review education records, to seek amendment of records believed inaccurate or misleading, and to consent to certain disclosures. Because the school controls the education record, these rights are exercised through the school. AIVO will:
- make a student's data available to the school so it can fulfill inspection/access requests (generally within the timeframe FERPA allows the school, not more than 45 days);
- correct or delete student data at the school's direction following an amendment decision; and
- return or delete student data on termination or on the school's instruction (Section 11).
Parents/eligible students should contact their school; AIVO will support the school in responding.
8. Special‑Education and IEP Data (IDEA)
AIVO is designed for neurodiverse learners and can support IEP‑aligned goals. Where a school provides IEP‑related indicators or a learner uses accommodations:
- AIVO treats this information as sensitive and applies heightened safeguards;
- AIVO uses it only to personalize the learning experience and to support the school's IEP‑related tracking, as configured by School Personnel;
- access is limited to authorized School Personnel, IEP‑team members invited by the school, and, where the school permits, the student's parent;
- AIVO handles this information consistent with IDEA's confidentiality protections (34 CFR §§ 300.610–300.626) in addition to FERPA, under the school's direction; and
- AIVO does not use special‑education data for any commercial purpose, advertising, or model training, and does not disclose it except as in Section 6.
9. PPRA (Surveys and Sensitive Topics)
To the extent the Protection of Pupil Rights Amendment applies to any survey or collection involving the protected categories it covers, AIVO supports the school's PPRA obligations and does not administer such surveys to students except as configured and authorized by the school in accordance with PPRA.
10. Security and Breach Notification
AIVO protects student data with administrative, technical, and physical safeguards, including encryption in transit and at rest for sensitive data, role‑based and least‑privilege access controls, multi‑factor authentication for administrative access, monitoring and logging, regular security testing, and an incident‑response and breach‑notification program. In the event of a security incident affecting a school's student data, AIVO will notify the affected school without undue delay, provide the information the school needs to meet its own notification obligations, and cooperate as required by the District Agreement and applicable law (including state student‑data‑breach laws). See the Security page.
11. Data Return and Destruction on Termination
On expiration or termination of a District Agreement, or upon the school's instruction, AIVO will return and/or securely destroy the student personal information in its possession in accordance with the District Agreement, subject to limited retention required by law and to retention of aggregated or de‑identified data. AIVO will, on request, provide the school written certification of destruction within the period specified in the District Agreement.
12. De‑Identified and Aggregated Data
AIVO may create and use de‑identified or aggregated data — data that does not reasonably identify a student — to operate, secure, analyze, and improve the Services and for research consistent with FERPA (34 CFR § 99.31(b)) and applicable state law. AIVO applies recognized de‑identification techniques, commits to maintain and use such data only in de‑identified form, and contractually prohibits re‑identification by recipients. AIVO does not attempt to re‑identify de‑identified data except to test its de‑identification.
13. State Student‑Privacy Laws and the Student Privacy Pledge
In addition to FERPA, AIVO's handling of student data is designed to align with state student‑privacy laws — for example, California's Student Online Personal Information Protection Act ("SOPIPA"), New York Education Law § 2‑d, and similar laws in other states — and with the principles of the Student Privacy Pledge, including commitments not to sell student personal information, not to use it for targeted advertising, not to build non‑educational profiles, to maintain a comprehensive security program, and to support deletion. Specific obligations to a given institution are set out in the applicable District Agreement/DPA, which may incorporate state‑required terms (such as state‑specific data‑privacy agreements or the National Data Privacy Agreement (NDPA) where applicable, and any state "parents' bill of rights" exhibit).
14. Subcontractors / Sub‑Processors
AIVO may use sub‑processors (for example, cloud hosting, error monitoring, and AI model providers). AIVO requires each sub‑processor to be bound by confidentiality, use‑limitation, and security obligations consistent with FERPA, IDEA (where applicable), and the District Agreement, and AIVO remains responsible for their handling of student data. A current sub‑processor list (provider, function, data categories, location) is available through the Trust Center, and schools may request advance notice of changes as provided in the District Agreement.
15. Audit Cooperation and Data‑Governance Support
On reasonable request and subject to the District Agreement, AIVO will provide schools with information reasonably necessary to verify AIVO's compliance with this Notice and the District Agreement — such as security documentation, the sub‑processor list, and responses to security/privacy questionnaires — and will reasonably cooperate with the school's data‑governance and audit requirements without compromising the security or confidentiality of other customers' data.
16. For Schools and Districts: How to Engage
Schools and districts evaluating or using AIVO can:
- request our DPA, security documentation, and sub‑processor list;
- configure roster, SSO, and IEP‑indicator settings to match district policy;
- designate authorized administrators and manage access; and
- contact our compliance team with FERPA, IDEA, or state‑law questions.
Contact: [email protected]
17. Changes to This Notice
We may update this Notice to reflect changes in law or practice. For institutions, the District Agreement governs how changes affecting student data are handled. The "Last updated" date indicates the latest revision.
18. Contact
[email protected] Aivo AI Learning Technologies Inc., 1400 Van Buren Street NE, Suite 200, Minneapolis, MN 55413, USA
# Annexes
Annex A — State Student‑Privacy Law Matrix (Representative)
Many states have student‑data‑privacy statutes in addition to FERPA. Specific obligations to a district are set in the District Agreement/DPA, which may incorporate state‑required exhibits. This matrix is a non‑exhaustive guide.
| State | Law | Notable requirements AIVO supports |
|---|---|---|
| California | SOPIPA; AB 1584 | No targeted ads; no sale; no non‑educational profiling; security; deletion on request; contract terms for district agreements |
| New York | Education Law § 2‑d; Part 121 | Parents' Bill of Rights exhibit; data‑security and breach terms; data‑element inventory; subcontractor oversight |
| Colorado | Student Data Transparency and Security Act | Public listing of data elements; security; deletion; subcontractor flow‑down |
| Illinois | SOPPA | Breach notification to schools within statutory time; data inventory; parent rights; contract provisions |
| Connecticut | Public Act on student data privacy | Standardized contract exhibit; breach notice; deletion |
| Texas | Ed Code student‑privacy provisions | No sale/targeted ads; security; deletion |
| Other states | Various | Generally: no sale, no targeted ads, security, deletion, subcontractor oversight, breach notice |
| Multi‑state | NDPA / SDPC | AIVO can execute the National Data Privacy Agreement and state‑specific exhibits where a district uses them |
AIVO will negotiate and execute the state‑specific data‑privacy agreement a district requires and flow down equivalent obligations to sub‑processors.
Annex B — Health or Safety Emergency Disclosure Procedure
Consistent with 34 CFR §§ 99.31(a)(10) and 99.36, if AIVO becomes aware of an articulable and significant threat to the health or safety of a student or others, AIVO will:
- Escalate internally to designated compliance personnel;
- Coordinate with the school/district, which determines disclosure as the controller, except where immediate action is necessary and permitted by law;
- Disclose only to appropriate parties (e.g., the school, law enforcement, or medical personnel) the information necessary to address the emergency;
- Record the threat, the parties to whom information was disclosed, and the information disclosed, and provide that record to the school for its § 99.32 recordkeeping; and
- Limit the disclosure to the period of the emergency.
Annex C — Data Flow Summary (School Deployment)
| Step | Flow | Controls |
|---|---|---|
| Provisioning | School/SSO → AIVO (roster, identifiers, optional IEP indicators) | Encrypted transport; least‑privilege; school‑configured scope |
| Use | Student ↔ AIVO learning experience | Education records created/maintained on the school's behalf |
| AI processing | AIVO → AI model provider (scoped prompt content) | No training on student data; data minimization |
| Reporting | AIVO → authorized School Personnel / collaborators / parents | Role‑based access; school‑configured permissions |
| Sub‑processing | AIVO → vetted sub‑processors | Confidentiality, use‑limitation, security; FERPA flow‑down |
| Offboarding | AIVO → return/delete student data | Certification of destruction on request |
Annex D — School Recordkeeping Support (§ 99.32)
Where FERPA requires the school to maintain a record of disclosures, AIVO will provide, on request, the information needed to populate that record for any disclosure AIVO makes on the school's behalf — including the parties who received personally identifiable information and their legitimate interests — except for disclosures to school officials, disclosures with consent, directory‑information disclosures, and disclosures to the parent/eligible student, which are treated as FERPA provides.