Data Classification And Handling

This page describes how Pearl Education categorizes the data in its Products and the safeguards applied to each category. It is written for district and state-agency evaluators reviewing how Customer Content and Student Data are handled.

How Pearl Categorizes Data

Pearl’s agreements define three main categories (MSA §1):

  • Customer Content — data submitted to, imported into, or created in the Products by or on behalf of the customer and its Authorized Users. Customer Content includes Student Data and is owned and controlled by the customer (MSA §1.3, §4.1). Student Data is personally identifiable information about a student, including information that is an “education record” under FERPA (MSA §1.14).
  • Statistical Data — usage and measurement data about how the Products are provided and used, in aggregated or De-identified form only; it never identifies a customer, School, or individual (MSA §1.13).
  • De-identified Data — data from which identifying information has been removed or obscured so there is no reasonable basis to identify any individual, School, or organization, applying FERPA standards (MSA §1.4; de-identification methodology per MSA §6.3).

How these categories may be used: Pearl does not sell Student Data, does not use it for targeted or behavioral advertising directed at students, and does not build commercial student profiles except as needed to provide the Services (MSA §5.7; DPA §4.2). Pearl may create and use De-identified and Statistical Data for research, benchmarking, and service improvement, consistent with its agreements (MSA §6; DPA Art. V).

Who Can Access What (Least Privilege)

  • Access to Customer Content is governed by least-privilege, role-based access controls (MSA §4.3; DPA §6.2).
  • The Products are multi-tenant; each customer’s data is logically separated and isolated through application-level role-based access controls.
  • Pearl limits access to Student Data to personnel who need it to perform the Services, binds them to confidentiality, and trains them on federal and state student-privacy requirements before granting access (DPA §4.3). Pearl staff complete annual FERPA training.
  • Pearl enforces multi-factor authentication (MFA) for its own administrative, source-code, and production access (DPA §6.2). For customer Authorized Users, MFA is available through the customer’s single sign-on (SSO) identity provider and is controlled by the customer; accounts that sign in with an email address and password do not currently have native MFA (planned on Pearl’s roadmap).
  • Subprocessors that process Customer Content are bound by obligations no less protective than the agreement, and the subprocessor list is available on request (MSA §4.4; DPA §2.5).

Encryption Standards

Customer Content is encrypted in transit using TLS and at rest using AES-256 (MSA §4.3; DPA §6.2). Account passwords are salted and hashed. All data is hosted in AWS US regions only (us-east-1 primary, with us-west-1 used for disaster recovery).

Excluded Data Categories (Do Not Submit)

Customers should not submit the following categories unless the parties expressly agree in writing that the Services require them (MSA §3.2; DPA Schedule 1, Part C):

  • Social Security or taxpayer identification numbers
  • Driver’s license, state ID, or passport numbers
  • Financial account, credit, or debit card numbers
  • PINs and passwords for non-Pearl accounts
  • Biometric records
  • Health or medical records beyond program accommodations the customer elects to record

Special Handling Notes

  • Online classroom session recordings (audio, video, screenshare, whiteboard) are processed only where the customer enables recording (DPA Schedule 1, Part A).
  • The mobile app is limited to adult Authorized Users (instructors, program staff, administrators); students are not given mobile app accounts (DPA Schedule 1, Part D).
  • Pearl does not store customer data on employee devices.