Pearl Education Student Data Privacy Notice

For school districts, state education agencies, schools, and parents/guardians. This notice explains how Pearl Education handles student data. It complements the Product Privacy Policy and the Data Privacy Agreement (DPA) or executed national/state student data privacy agreement (NDPA) between Pearl and your school. Where a signed DPA/NDPA exists, that agreement controls.

1. Pearl Education’s Role

Pearl (Trilogy Mentors Inc., DBA Pearl) provides its Products to schools, districts, state education agencies, and authorized program operators. Pearl processes student data on behalf of, and at the direction of, the school or district as a “school official” with a legitimate educational interest under FERPA (34 C.F.R. § 99.31(a)(1)). The school or district remains in control of student data; Pearl does not own it and uses it only to provide the Products and as permitted by the customer’s agreement.

2. Student Data Pearl Processes

The exact fields are configured by each school or district, and many are optional. They may include:

  • Identifiers: student name, email/username, local or student ID, school/district, and parent/guardian association.
  • Optional demographics (customer-elected): grade level, date of birth, and other fields the customer chooses to provide.
  • Enrollment and scheduling: program enrollment, session schedules, attendance and dosage, and tutor-student assignments.
  • Activity and usage: access logs, IP address, device/browser, and session attendance/completion.
  • Session content: instructional files, messages between authorized users (for example, student–instructor), and online classroom recordings where the school enables recording.
  • Assessment and outcomes (Insights+ / Data Hub): provider-submitted results and program outcome measures as configured by the customer.

 

Schools should not submit excluded sensitive data , such as Social Security numbers, government ID numbers, financial account numbers, or biometric records, unless expressly agreed in writing (MSA § 3.2; DPA Schedule 1, Part C).

3. How Student Data Is Used

Pearl uses student data only to provide and support the Products for the school’s educational purposes, to secure the Products, and to improve them. AI-enabled features operate solely on the school’s behalf to deliver the Services (see the AI Use Disclosure). Pearl may create and use de-identified and aggregated data for research and educational-improvement purposes as described in Section 7.

4. What Pearl Does Not Do

  • Pearl does not sell student data.
  • Pearl does not use student data for targeted or behavioral advertising, and does not build commercial profiles of students except as needed to provide the Products.
  • Pearl does not use identifiable student data to train AI models, and does not use identifiable student data to develop unrelated commercial products without the school’s separate written authorization (MSA § 5.7; DPA Art. IV).

5. Legal Framework

Pearl supports compliance with FERPA, the Protection of Pupil Rights Amendment (PPRA), the Children’s Online Privacy Protection Act (COPPA) (which applies to children under 13), and applicable state student-privacy laws (for example, Illinois SOPPA, California SOPIPA, and New York Education Law § 2-d). These laws generally place state-registration or public-posting duties on the school or district rather than the vendor; Pearl complies with its duties as a contractor/operator and signs the district’s required addenda (for example, a New York parents’ bill of rights supplement). See State Privacy Law Posture for more detail.

6. Consent and Parental Rights

  • Consent: For students under 13, the school or district provides or authorizes the disclosures and consent required under applicable law, consistent with FTC guidance and FERPA. At a school’s request, Pearl can provide an in-product mechanism to obtain and record verifiable parental consent (MSA §§ 5.4–5.5).
  • Access, correction, deletion: Parents, guardians, and eligible students exercise these rights through their school or district, which controls the records. Pearl supports the school and responds to a school’s request regarding a student’s data within 45 days. If a parent contacts Pearl directly, Pearl refers them to the school (DPA 2.2).
  • Student-generated content: At the school’s request, Pearl will transfer, or provide a mechanism to transfer, student-generated content consistent with the functionality of the Products (DPA 2.3).

7. De-Identified Data and Research

Pearl may create and use de-identified data for research, benchmarking, and educational-improvement purposes. Pearl applies a documented de-identification methodology (expert determination, or removal of direct and indirect identifiers with a documented reasonable-basis determination) before any such use, and maintains written documentation of that methodology. De-identified data does not identify any student, school, or organization. Any third party that receives de-identified research data must sign a data use agreement that prohibits re-identification and restricts use to the agreed research or educational purposes. Pearl does not sell research data for unrelated commercial purposes (MSA § 6; DPA Art. V).

8. Data Sharing and Subprocessors

Pearl shares student data only as needed to provide the Products, as the school directs, or as required by law. Subprocessors are bound by obligations no less protective than Pearl’s commitments, and Pearl remains responsible for their performance; a current subprocessor list is available on request (MSA § 4.4; DPA 2.5). All data is hosted in AWS U.S. regions. If law enforcement or a government entity requests student data, Pearl will notify the school in advance unless legally prohibited (DPA 2.4).

9. Security

Pearl maintains a written information security program with administrative, technical, and physical safeguards, including encryption in transit (TLS) and at rest (AES-256), least-privilege/role-based access, logging and monitoring, secure development practices, and vendor risk management (MSA § 4.3; DPA § 6.2). Pearl enforces multi-factor authentication (MFA) for its own administrative, source-code, and production access; for customer Authorized Users, MFA is available through the customer’s single sign-on (SSO) identity provider and is controlled by the customer (accounts that sign in with email and password do not yet have native MFA). Pearl conducts background screening of personnel with production access. Pearl’s security program is validated by independent third-party assessment: Pearl has completed a SOC 2 Type I examination (Security), with the report available under NDA on request, and a SOC 2 Type II examination is planned. See the Security Overview.

10. Breach Notification

If Pearl confirms a security incident affecting student data, Pearl will notify the school without undue delay and within 72 hours of confirmation, provide the information the school needs to meet its legal obligations, supplement within five business days as more is learned, cooperate in the response, and participate in a post-incident review on request. Where notification is legally required and the incident was not caused by the school, Pearl will bear the reasonable, documented cost of required notifications (MSA § 4.5; DPA Art. VII).

11. Retention, Return, and Deletion

Pearl retains student data only as long as needed to provide the Products or as required by law. On the school’s request during the service period and for 30 days after it ends, Pearl makes student data available for export. Unless the school requests earlier deletion, Pearl deletes student data no later than 60 days after that export period (or within 60 days of an earlier request), and certifies deletion in writing on request. Disaster-recovery backups are encrypted, used only for recovery, and overwritten on a rolling schedule not to exceed 7 days. Where state law or an executed state agreement sets different timelines (including enrollment-based deletion), those timelines control (MSA § 4.6; DPA Art. VIII).

12. Mobile Application

Pearl’s mobile app is for instructors and administrators only; students are not provided mobile app accounts. If Pearl introduces student-facing mobile functionality in the future, it will update this notice and the DPA schedule before that change applies (DPA Schedule 1, Part D).

13. Changes to This Notice

Pearl may update this notice to reflect changes in the Products or the law and will provide reasonable notice of material changes. Changes affecting an active agreement apply only as that agreement provides.

14. Contact

Districts and schools: contact your Pearl representative or privacy@poweredbypearl.com. Parents and guardians: please contact your school or district, which controls student records; the school will coordinate with Pearl as needed.