FERPA Posture and Data-Handling Memorandum
Effective date: April 28, 2026
Purpose
This memorandum describes how QuantegyAI processes information that may constitute Education Records or personally identifiable information from Education Records under the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99.
Summary posture
QuantegyAI operates as a School Official under 34 C.F.R. § 99.31(a)(1) when processing Personal Data of Institution students, performing institutional services or functions for which the Institution would otherwise use its own employees, under the direct control of the Institution as to the use and maintenance of the records, and subject to the redisclosure requirements of 34 C.F.R. § 99.33. The technical surfaces described in this memorandum support the access and amendment rights of eligible students under 34 C.F.R. §§ 99.10–99.12 and the recordkeeping obligations of educational agencies and institutions under 34 C.F.R. § 99.32.
1. Categories of records processed
QuantegyAI processes the following categories of records on behalf of the Institution:
- Directory-style identifiers limited to: email address, display name, age-attestation timestamp, cohort membership, and (where the Institution provides them) internal student identifiers.
- Learning interactions: item administrations, responses, response times, the skill and competency tags associated with each item, IRT and BKT outputs, mastery estimates, and readiness band.
- Authentication and security metadata: session timestamps, source IP, browser user-agent, password hash.
- Audit events: timestamped records of sensitive actions, with actor, target (where applicable), source IP, and request correlation ID.
2. Mapping engineered features to FERPA obligations
The Services are designed so that the Institution can satisfy its FERPA obligations using features built into the platform. The mapping is:
Right of access — 34 C.F.R. § 99.10
Every authenticated user has access to a profile-export endpoint, which streams a single JSON file containing the user's complete record: profile, subscription, sessions, responses, per-skill mastery, and the audit events the user is the actor of. The export is strictly user-scoped (no cross-account contamination), is rate-limited to one per hour per user, and is itself audited as a profile.exported event. The export satisfies a parent's or eligible student's request to inspect and review the student's Education Records as held by the Services.
Right to seek amendment — 34 C.F.R. § 99.20
Self-service rectification is available for display name and email through the profile-settings UI. Amendments to other categories of information are handled by the Institution and forwarded to QuantegyAI through the privacy contact email; QuantegyAI implements the amendment within fifteen calendar days unless the parties agree otherwise. Hearings under 34 C.F.R. § 99.21 remain the responsibility of the Institution.
Disclosure of personally identifiable information — 34 C.F.R. § 99.31
Disclosure under the School Official exception is the basis on which QuantegyAI receives information; QuantegyAI does not disclose Personal Data to any party other than its named subprocessors and as required by law. The Institution's data-processing addendum governs the conditions under which QuantegyAI may disclose information to its subprocessors.
Recordkeeping requirements — 34 C.F.R. § 99.32
The audit_events table records every disclosure-relevant action that QuantegyAI controls, including login successes and failures, signup, teacher-invite creation and redemption, cohort creation and management, viewing of student detail by a teacher (cohort.student_viewed), profile export, profile deletion, and tier changes. Each row carries the actor, the target (where applicable), the source IP, the action verb, and a request correlation ID. The Institution can request a per-student or per-cohort export of audit events relevant to its recordkeeping under § 99.32 through its privacy contact.
Right to request destruction — soft delete
An eligible student can soft-delete their account at any time through the profile-settings UI (password re-entry required). Soft deletion scrubs the email, display name, and password hash on the user row, sets a deleted_at timestamp, invalidates the current session, and bounces any other live sessions on their next request. The remaining responses and audit events are retained in de-identified form to support content-governance statistics, to satisfy the Institution's FERPA-aligned retention obligations, and to preserve referential integrity. The Institution can elect a harder destruction posture under the data-processing addendum if its record-retention policy so requires.
Annual notification — 34 C.F.R. § 99.7
The Institution remains responsible for its annual notification of rights under § 99.7. QuantegyAI provides on request a description of its processing activities and subprocessors that the Institution may incorporate into its notification.
3. De-identified data
QuantegyAI retains de-identified learning interactions and aggregate item statistics for content governance, engine improvement, and institutional reporting. De-identification follows 34 C.F.R. § 99.31(b)(1) and the U.S. Department of Education's IES guidance on student-level data: direct identifiers (email, display name, internal student identifier) are scrubbed; quasi-identifiers (age-attestation timestamp, cohort, exam, response timestamps) are retained only to the extent that no reasonable reader, in possession of other information that QuantegyAI does not control, could re-identify any individual student. Statistical disclosure controls (small-cell suppression on cohort-scale displays) are applied to teacher-facing dashboards.
4. Data minimization
QuantegyAI does not collect demographic information beyond the categories described in this memorandum and does not require the Institution to provide more identifying information than is necessary to authenticate students and to render Institution-specific reporting. The signup flow does not request gender, race, ethnicity, national origin, religion, sexual orientation, or other special-category data.
5. Security measures
Security measures are described in detail in our institutional Data Processing Addendum and are summarized in our Privacy Policy. They include transport-layer security with HSTS in production; a nonce-based Content Security Policy that prohibits inline scripts and inline styles; salted bcrypt password hashing with constant-time verification; per-IP rate limits and per-email login lockout; a comprehensive set of HTTP security headers; trusted-host enforcement; CSRF protection on every state-changing form; structured logging with per-request correlation IDs; and an append-only audit log.
6. Texas-specific considerations
Texas educator-preparation programmes are regulated by the Texas Education Agency and the State Board for Educator Certification. Institutional records that incorporate QuantegyAI outputs (mastery estimates, readiness assessments) are governed by the Institution's record-retention schedule; QuantegyAI's retention defaults are designed to be compatible with the Local Government Records Act and the State Records Retention Schedule. The Texas Public Information Act, Tex. Gov't Code Chapter 552, may apply to records held by public Institutions; nothing in QuantegyAI's processing waives or modifies the Institution's responsibilities under that Act.
7. Open items for institutional counsel
Counsel reviewing this memorandum on behalf of the Institution should confirm:
- That the School Official designation is acceptable to the Institution under its annual FERPA notice and that the Institution's notice will be updated to identify QuantegyAI as a vendor with a legitimate educational interest.
- Whether the Institution's record-retention schedule requires harder destruction than the soft-delete default; if so, the data-processing addendum will be amended to that effect.
- Whether the Institution requires a subprocessor pre-approval right (in lieu of the default thirty-day prior-notice mechanism).
- Whether on-site audit rights are required, in lieu of the default written-cooperation mechanism.
- The categories and format of internal student identifiers (if any) that the Institution intends to pass through cohort rosters.
8. Contact
Institutional counsel may direct questions about this memorandum to support@quantegyai.com, or by mail to QuantegyAI, 118 Harvest Loop, Harker Heights, TX 76548.