How Incluxa supports FERPA
Questions? Email privacy@incluxa.com. See also our Privacy Policy and Data Processing Agreement.
For K–12 schools and LEAs: This page explains how INCLUXA handles student education records under FERPA. The district agreement must be signed by your Owner in Settings → Schools before IEP automation, the teacher dashboard or LMS connections can be used. Questions: privacy@incluxa.com.
1. What is FERPA?
The Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99, is a federal law that protects the privacy of student education records. FERPA applies to all educational institutions that receive funding from the U.S. Department of Education — including virtually all public K–12 schools and most private schools.
FERPA gives parents (and students who have reached age 18 or attend a post-secondary institution — "eligible students") specific rights regarding their children's education records, including the right to inspect, correct, and control disclosure of those records.
INCLUXA is designed to support schools' FERPA obligations when using our accessibility services. This page explains our obligations and yours.
2. Our Role: Data Processor
Under FERPA and applicable data protection law, INCLUXA operates as a data processor (a "school official" under FERPA). The school — the Local Education Agency (LEA) or educational institution — remains the data controller for all student education records.
What this means in practice: The school decides what student data to share with INCLUXA, for what purpose, and retains full legal responsibility for compliance with FERPA, COPPA, IDEA, and applicable state law. INCLUXA processes student data only on the school's documented instructions.
INCLUXA does not independently determine the purposes or means of processing student education records. We process only what the school provides, for the accessibility services the school has contracted.
3. School Official Status (34 C.F.R. § 99.31(a)(1))
FERPA permits schools to disclose education records — without prior parental consent — to "school officials" who have a "legitimate educational interest" in the records. 34 C.F.R. § 99.31(a)(1).
Schools that execute a Data Processing Agreement (DPA) with INCLUXA formally designate INCLUXA as a school official for the purpose of providing accessibility services. Our legitimate educational interest is:
- Reading IEP documents to extract accessibility accommodation types
- Configuring accessibility features on behalf of enrolled students
- Providing teachers and administrators with accommodation compliance dashboards
This designation is limited. INCLUXA accesses education records only to the extent necessary to deliver contracted accessibility services — and for no other purpose.
Schools must include INCLUXA in their Annual FERPA Notice if they designate us as a school official. The annual notice must identify the criteria used to determine who constitutes a school official and what constitutes a legitimate educational interest. Contact privacy@incluxa.com for suggested FERPA notice language.
4. What Education Records We Access
| Record Type | What We Access | What We Do NOT Access |
|---|---|---|
| Student identifier | Opaque ID (a school-assigned ID, lti-{user id} or moodle-{id}) — not the student's name or SSN | Name, SSN, government-issued ID |
| IEP document | Full document text for extraction — automatically redacted before the AI step; the file itself is deleted right after parsing | The full IEP text is not kept; only a short supporting quote from the redacted IEP is stored (encrypted at rest), plus the uploaded file name |
| Accommodation types | Extracted accommodation types (e.g., "TextToSpeech", "LargeFont") with a short description | Diagnoses, grades or assessment results as data fields |
| Accessibility preferences | Feature toggle states and values set by or for the student | Assessment scores, grades, disciplinary records |
| Usage telemetry | Per-activation events: student ID, tool, session, timestamps and duration (dashboards show aggregates) | Keystrokes, content viewed, browsing behavior |
5. IEP Document Processing
IEP documents contain some of the most sensitive student education records. INCLUXA applies multiple layers of protection:
- Secure Upload. IEP files are uploaded to INCLUXA's encrypted storage over TLS 1.2+. Files are never cached at CDN level.
- Automated PII Redaction. Before any content leaves our systems, an automated redaction engine processes the document text. It identifies and replaces: student names →
[STUDENT]; dates of birth →[DATE]; parent/guardian names →[GUARDIAN]; phone numbers →[PHONE]; email addresses →[EMAIL]; street addresses →[ADDRESS]; SSNs →[SSN]; and other direct identifiers. Redaction is pattern- and label-based, so it can miss identifiers written in unusual formats. The number of redactions is logged (for audit purposes) but the original values are never logged. - AI Extraction (Redacted Text Only). The redacted document text is sent to Claude AI (Anthropic, PBC) to identify accommodation types. Anything the redaction misses could reach Anthropic and could appear in the stored quote, which is why a teacher reviews every suggestion before it is applied.
- Immediate File Deletion. Upon completion of processing (whether successful or failed), the source IEP file is permanently and irreversibly deleted from our storage. This deletion is logged in our immutable audit trail.
- Accommodation Storage. The accommodation types (e.g.,
TextToSpeech,LargeFont), a short description and a supporting quote from the redacted IEP (encrypted at rest) are stored — linked to the opaque student ID, not the student's name. The uploaded file name is also kept, including in the upload audit log.
Result: We store an opaque student ID, the accommodation types, a short description and a supporting quote from the redacted IEP (encrypted at rest), plus the uploaded file name. The IEP file itself is deleted right after parsing. Teachers review every suggestion before anything is applied.
6. Sub-Processors & AI
The following sub-processors may handle student education records as part of delivering INCLUXA's accessibility services:
| Sub-Processor | Role | Data Accessed | Location |
|---|---|---|---|
| Microsoft Azure | Cloud hosting, encrypted database, blob storage | All student data (encrypted at rest, AES-256) | United States |
| Anthropic, PBC (Claude AI) | IEP accommodation extraction | Redacted IEP text (anything the redaction misses could be included) | United States |
| Cloudflare | WAF, DDoS protection, TLS termination | IP addresses only (no education record content) | Global |
| Sentry | Error monitoring | Error context only — student IDs excluded from error reports | United States |
INCLUXA maintains Data Processing Agreements with all sub-processors that handle student data. Contact privacy@incluxa.com for a complete sub-processor list and copies of applicable DPAs.
7. Disclosure & Re-Disclosure Prohibition
INCLUXA will not disclose student education records to any third party except:
- To sub-processors listed in Section 6, as necessary to deliver contracted services
- As explicitly authorized in writing by the school's Data Processing Agreement
- As required by a court order or other applicable law — in which case INCLUXA will notify the school prior to disclosure unless legally prohibited from doing so
INCLUXA will never:
- Sell, rent, or trade student education records
- Use student data for advertising, marketing, or any commercial purpose
- Disclose student data to other INCLUXA customers or to the public
- Use student data to build profiles for purposes unrelated to accessibility service delivery
8. Breach Notification
In the event of any unauthorized access to, or accidental or unlawful destruction, loss, alteration, or disclosure of, student education records:
- INCLUXA will notify the affected school(s) within 24 hours of becoming aware of the incident
- Notification will include: the nature of the incident, the categories of records involved, the approximate number of students affected, the likely consequences, and the measures taken or proposed to address the incident
- INCLUXA will cooperate fully with the school's incident response and any regulatory investigation
- We will provide regular updates until the incident is fully resolved and remediated
To report a suspected security incident: security@incluxa.com
9. Parent & Eligible Student Rights
Under FERPA, parents (and eligible students) have the right to:
- Inspect and review education records maintained by INCLUXA on behalf of the school
- Request amendment of records believed to be inaccurate, misleading, or in violation of privacy rights
- Request deletion of their child's data
- Receive a copy of their child's data, on request
These rights are exercised through the school, which is the data controller. Schools submit requests to INCLUXA at privacy@incluxa.com with the subject line "FERPA Data Request — [School Name]". INCLUXA responds and acts within 30 days. All deletion requests are confirmed in writing.
Schools can also delete a student's IEP data themselves from the IEP screen. That removes the IEP documents, accommodations, mappings and IEP-applied settings only. Other student data (usage logs, recommendations, effectiveness metrics, the accessibility profile and teacher assignments) is removed by the district's retention setting or on request via privacy@incluxa.com. Audit logs, which may contain student IDs and file names, are kept for 2 years.
Parents and students: Please contact your school's FERPA coordinator to exercise your rights. Your school will coordinate the request with INCLUXA on your behalf.
10. District Agreement (DPA)
A signed district agreement (SDPC National DPA v2.0 + the state exhibit for your state) is required before a school uses IEP automation, the teacher dashboard or LMS connections. The agreement:
- Formally designates INCLUXA as a school official under 34 C.F.R. § 99.31(a)(1)
- Establishes the controller/processor relationship
- Lists authorized sub-processors and their roles
- Records the district's retention period (1–120 months), which applies to all student data
- Defines security requirements and incident response obligations
- Provides mechanisms for parent and eligible student rights requests
- Records the school's consent on parents' behalf for educational use, consistent with long-standing FTC COPPA guidance
The agreement is included at no additional cost on the Schools plan. Your Owner signs it in Settings → Schools; contact privacy@incluxa.com to review the full text before signing.
11. Contact
| FERPA / student privacy | privacy@incluxa.com |
|---|---|
| DPA requests | privacy@incluxa.com |
| Security incidents | security@incluxa.com |
| Legal inquiries | legal@incluxa.com |