InnerJoyEd Privacy Policy
Effective Date: July 31, 2026 | Last Updated: July 31, 2026
1. Introduction
InnerJoyEd ("InnerJoyEd," "we," "us," or "our") provides a preventative mental and behavioral health platform for K-12 students, schools, and districts (the "Service"), accessible at www.innerjoyed.com. This Privacy Policy explains how we collect, use, disclose, and protect information — including personal information, education records, and behavioral/mental health data — from students, parents/guardians, teachers, school staff, and district administrators.
We designed this policy to comply with applicable U.S. federal and state student-privacy and health-privacy laws, U.S. federal cloud-security requirements for government customers, and the data protection laws of the international markets we serve. Because InnerJoyed works primarily through schools and districts (rather than directly marketing to children), our data practices are structured around the "school official" and "school consent" models described below.
This Policy applies to:
- The InnerJoyed web and mobile application(s)
- Any InnerJoyed dashboards used by teachers, counselors, or administrators
- Any APIs, integrations, or data feeds connected to the Service
- www.innerjoyed.com and related subdomains
2. Scope of Compliance
InnerJoyed's privacy and security program is designed with the following frameworks in mind:
| Framework | Jurisdiction | What It Governs |
|---|---|---|
| Student Privacy Pledge | Industry Commitment | Voluntary industry-wide commitments restricting sale, behavioral advertising, and improper use/retention of student data |
| FERPA (Family Educational Rights and Privacy Act) | U.S. Federal | Education records held by schools/districts that use InnerJoyed |
| COPPA (Children's Online Privacy Protection Act) | U.S. Federal | Online collection of personal information from children under 13 |
| PPRA (Protection of Pupil Rights Amendment) | U.S. Federal | Surveys/assessments touching mental health, emotional, or behavioral topics |
| SOPPA (Student Online Personal Protection Act) | Illinois | Student data collected via online platforms used in schools |
| State Student Data Privacy Laws (e.g., NY Ed Law 2-d, California SOPIPA/AB 1584, Colorado Student Data Transparency and Security Act, and similar laws in other states) | Various U.S. states | Restrictions on use/sale of student data, breach notice, data security |
| SOC 2 Type II / ISO 27001 | Industry Security Standards | Independent third-party audit standards for security, availability, and confidentiality controls (InnerJoyed is pursuing certification — see Section 9) |
| FedRAMP (Federal Risk and Authorization Management Program) | U.S. Federal cloud security | Security controls for cloud systems used with federal data/funding |
| NIST 800-53 / NIST 800-171 | U.S. Federal | Underlying security control baseline referenced by FedRAMP |
| HIPAA-aligned safeguards (where applicable) | U.S. Federal | Administrative, physical, and technical safeguards for sensitive health/behavioral data, applied as best practice even where InnerJoyed is not a HIPAA covered entity |
| State mental health confidentiality laws | Various U.S. states | Heightened confidentiality for mental/behavioral health records |
| DPDP Act, 2023 | India | Digital personal data protection |
| LGPD (Lei Geral de Proteção de Dados) | Brazil | General data protection, including children's data |
| Data Protection Act | Belize | Personal data protection |
| PDPL (Federal Decree Law No. 45 of 2021) | United Arab Emirates / Dubai | Personal data protection, including DIFC Data Protection Law where applicable |
Where laws differ, InnerJoyed applies the most protective standard available to the student.
2.1 Student Privacy Pledge
InnerJoyed adheres to the principles of the Student Privacy Pledge, a voluntary industry commitment widely recognized by K-12 procurement officers, districts, and state education agencies. Consistent with the Pledge, InnerJoyed commits to:
- No sale of student information. InnerJoyed will not sell, rent, or trade student personal information.
- No behavioral advertising. InnerJoyed will not use student data to engage in targeted or behavioral advertising, and does not permit advertising trackers within the Service.
- No improper profiling. InnerJoyed will not build a personal profile of a student other than for the supported educational/behavioral health purpose authorized by the school or district.
- Purpose-limited collection, use, and retention. InnerJoyed collects, uses, shares, and retains student data only for the purposes for which the school or district authorized it, and not for any other commercial purpose.
- No unauthorized retention. InnerJoyed will not knowingly retain student data beyond the time period required to support the authorized school purpose, consistent with Section 11 (Data Retention and Deletion).
- Transparency. InnerJoyed clearly discloses the types of student data collected and the purposes for which it is used, as described throughout this Policy.
- Access and correction. InnerJoyed supports the ability of schools, districts, parents, and eligible students to access, correct, and, where appropriate, export or delete student personal information, consistent with Section 15.
- Comprehensive security. InnerJoyed maintains a comprehensive security program designed to protect student data, consistent with Section 9.
- Subprocessor accountability. InnerJoyed requires its subprocessors and service providers with access to student data to adhere to commitments consistent with the Pledge and this Policy.
3. Roles and Relationships: School as Data Controller
For school- and district-deployed use of InnerJoyed:
- The school or district is the data controller (or "educational agency") for student education records and directly provides, or authorizes InnerJoyed to collect, student data solely for the school's educational and preventative behavioral health purposes.
- InnerJoyed acts as a "school official" with a legitimate educational interest under FERPA, and as a "service provider"/"operator" under COPPA, SOPPA, and comparable state laws, operating under a signed Data Processing Agreement ("DPA") or Student Data Privacy Agreement ("DPA"/"SDPC Agreement") with each school or district.
- InnerJoyed does not use student data for any purpose outside the scope authorized by the school/district contract, and does not require parents to directly negotiate terms with InnerJoyed for school-provided access.
4. Information We Collect
4.1 Information Provided by Schools/Districts
- Student roster data (name, grade, gender, school, student ID, class/section)
- Teacher and counselor rosters (name, email address, grade, class room)
4.2 Information Collected Through the Service
- Behavioral and emotional indicators: self-reported mood check-ins, assessment responses, Behavioral Symptom Index (BSI) style indicators (e.g., anxiety, withdrawal, impulsivity, aggression signals), and related wellness survey responses
- Usage and interaction data: content viewed, exercises completed, time on task, engagement patterns
- Teacher/counselor observations entered into the platform
- Device and technical data: IP address, browser type, device identifiers, log data
- Communications sent through in-platform messaging, where offered
4.3 Sensitive Categories
InnerJoyed treats the following as sensitive data requiring heightened protection: mental health and behavioral health indicators, disability-related information, and any data that could reveal a diagnosis, risk level, or need for intervention. This data receives encryption, strict access controls, and minimum-necessary access rules as described in Section 9.
4.4 What We Do Not Do
- We do not collect more information than is reasonably needed to operate the Service ("data minimization").
- We do not use persistent identifiers for behavioral advertising.
- We do not sell, rent, or trade student data, ever.
5. FERPA Compliance
InnerJoyed maintains education records with the same care required of school personnel under FERPA:
- School Official Exception: InnerJoyed acts under the direct control of the school/district regarding the use and maintenance of education records, uses records only for the purposes for which disclosure was made, and does not re-disclose personally identifiable information from education records except as directed by the school or as permitted by FERPA.
- No Unauthorized Redisclosure: InnerJoyed will not disclose personally identifiable information from education records to any third party without school/district authorization, except as required by law.
- Directory Information: InnerJoyed does not treat student data as "directory information" and does not publish or make it publicly available.
- Access and Amendment: Parents/eligible students (students who are 18 or attend a postsecondary institution) may request access to, and correction of, education records through their school/district, which will coordinate with InnerJoyed as needed.
- Recordkeeping of Disclosures: InnerJoyed maintains logs of any disclosures of education records made outside the school official exception, available to the school/district upon request.
- Data Destruction: Upon contract termination or school/district request, InnerJoyed will return or destroy education records in accordance with the DPA and Section 11 below.
6. COPPA Compliance
Because many InnerJoyed users are under 13, we comply with COPPA as follows:
- School Consent Model: For school-deployed use, the school/district may consent on behalf of parents to InnerJoyed's collection of personal information from students under 13, strictly for educational and preventative behavioral health purposes authorized by the school, and only where the school has provided parents notice of its practices (consistent with FTC COPPA guidance for schools).
- No Advertising: InnerJoyed does not use children's information for behavioral advertising, does not build profiles for commercial purposes unrelated to the educational service, and does not enable third-party advertising trackers within the Service.
- Direct-to-Consumer Use: If InnerJoyed offers any direct-to-family or direct-to-consumer product in the future, we will implement verifiable parental consent mechanisms independently, consistent with COPPA, before collecting personal information from a child under 13.
- Parental Rights: Parents may review their child's personal information, request deletion, and refuse further collection by contacting their school/district or InnerJoyed directly at the contact information in Section 18. We will not condition a child's participation in an activity on disclosing more information than is reasonably necessary.
7. SOPPA and State Student Data Privacy Laws
In addition to Illinois SOPPA, InnerJoyed designs its practices to meet the common core requirements found across state student-data-privacy statutes (e.g., New York Education Law 2-d, California SOPIPA/AB 1584, Colorado's Student Data Transparency and Security Act, Connecticut Public Act 16-189, and similar laws):
- Prohibited Uses: InnerJoyed will not use student data to engage in targeted advertising, will not sell or rent student data, and will not build a personal profile of a student other than for the authorized educational/behavioral health purpose.
- Purpose Limitation: Student data is used only to further the K-12 purposes for which it was provided (i.e., preventative mental and behavioral health support, progress tracking, and reporting to authorized school personnel).
- Data Security Program: InnerJoyed maintains a written information security program addressing encryption, access controls, incident response, and employee training (see Section 9).
- Breach Notification: InnerJoyed will notify the affected school/district without unreasonable delay following discovery of a security breach involving student data, consistent with statutory timelines (commonly as soon as practicable and no later than the period specified by applicable state law, often within 30 days absent a law enforcement delay request).
- Subcontractor Flow-Down: Any subcontractor or subprocessor with access to student data is bound by confidentiality and security obligations at least as protective as those InnerJoyed owes the school/district.
- Public Disclosure/Transparency: Upon request, InnerJoyed will provide districts with a list of categories of data collected and third parties with whom data may be shared, to support state-required public transparency (e.g., "parent's bill of rights" or data inventory postings some states require districts to publish).
- Data Deletion on Request: InnerJoyed will delete or return student data upon the school/district's request or contract termination, except where retention is required by law.
8. PPRA — Protection of Pupil Rights
Where InnerJoyed surveys or assessments ask students about mental health, emotional, or behavioral topics, InnerJoyed supports school compliance with PPRA by:
- Making survey/assessment instruments available to schools/districts for review before administration
- Enabling schools to provide parents advance notice and an opportunity to opt a student out of non-required surveys concerning protected topics (e.g., mental/psychological problems, sexual behavior, illegal/self-incriminating behavior) as required by law
- Not requiring students to submit to survey items outside the scope authorized by the school
9. Data Security
InnerJoyed maintains administrative, technical, and physical safeguards designed to protect personal information and behavioral/mental health data, including:
- Encryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent)
- Access Controls: Role-based access control (RBAC) so that teachers, counselors, and administrators see only the data necessary for their role; sensitive behavioral indicators are restricted to authorized school personnel (e.g., counselors) as configured by the district
- Authentication: Multi-factor authentication for staff/administrator accounts
- Logging & Monitoring: Continuous monitoring, audit logging, and anomaly detection
- Vendor/Subprocessor Management: Due diligence and contractual security requirements for all subprocessors
- Employee Training: Mandatory privacy and security training for all personnel with data access
- Incident Response Plan: A documented breach/incident response plan with defined notification timelines to schools/districts and, where required, regulators and affected individuals
- Data Minimization & Retention Controls: Automated retention schedules and secure deletion processes (see Section 11)
- Independent Certifications: InnerJoyed is pursuing SOC 2 Type II and ISO 27001 certification to provide independent, third-party validation of its security, availability, and confidentiality controls. Current certification/audit status is available to schools and districts upon request during procurement.
9.1 FedRAMP Alignment
For customers requiring FedRAMP-aligned hosting (e.g., public agencies or districts receiving federal funding, or where required by an RFP):
- InnerJoyed maintains FedRAMP-aligned security controls based upon NIST 800-53, covering control families such as Access Control, Audit and Accountability, Identification and Authentication, Incident Response, and System and Communications Protection.
- Where a specific engagement requires a FedRAMP-authorized cloud service offering, InnerJoyed will host within a FedRAMP-authorized environment (e.g., a FedRAMP Moderate or High baseline cloud provider) and can provide current authorization status, System Security Plan (SSP) summaries, and a FedRAMP Authorization To Operate (ATO) package or sponsorship roadmap upon request during procurement.
- InnerJoyed supports agency and district security reviews, including completion of security questionnaires (e.g., SIG, VPAT, state-specific security exhibits) as part of the RFP and onboarding process.
9.2 Data Residency
U.S. customer data is stored in U.S.-based cloud regions unless otherwise agreed in writing with the school or district. For international customers (e.g., India, Brazil, Belize, and the UAE/Dubai), InnerJoyed will store and process data in-region where required by local law or contractually requested, and will otherwise disclose the location(s) where student data is hosted upon request. Any cross-border transfer of data out of its region of origin is made subject to the safeguards described in Section 13 (International Data Processing).
10. AI, Behavioral Analytics, and Automated Decision-Making
InnerJoyed uses artificial intelligence and machine learning to support preventative mental and behavioral health insights (for example, behavioral indicators, risk/trend indices, and personalized content recommendations). In connection with this processing:
- No Use to Train Public Foundation Models: Student data is never used to train, fine-tune, or otherwise improve any public or third-party foundation model. Any model training InnerJoyed performs occurs on isolated, purpose-built models used exclusively to operate the Service.
- Per-Tenant Model Isolation: Where technically applicable, AI models and the data used to generate a school or district's behavioral indicators are isolated per tenant (i.e., per school/district), so one institution's student data is not used to generate outputs for another institution.
- Human-in-the-Loop: Automated behavioral indicators and risk scores are provided as decision-support information to trained school personnel (e.g., counselors); InnerJoyed does not make unilateral clinical, disciplinary, or placement decisions about a student. Human review by authorized, trained personnel is required before any intervention, referral, or safety action is taken based on an AI-generated indicator.
- Recommendations Only: All AI-generated behavioral indicators, risk/trend indices, and content recommendations are outputs to inform — not replace — the professional judgment of qualified school staff. InnerJoyed's AI does not diagnose, and its outputs are not a substitute for clinical evaluation.
- Bias Testing: InnerJoyed's models undergo periodic testing for demographic and performance bias (e.g., across race, gender, disability status, and English-learner status, where such attributes are available) as part of its model governance process, with remediation steps taken when material disparities are identified.
- Explainability Documentation: InnerJoyed maintains explainability documentation describing, at a general level, the categories of input data and logic used to generate behavioral indicators and recommendations. This documentation is available to schools/districts upon request to support procurement review, parent inquiries, and regulatory compliance.
- Transparency: Schools/districts may request an explanation of the categories of data and general logic used to generate behavioral indicators or recommendations provided to their staff.
- No Automated Decisions with Legal/Similarly Significant Effects: InnerJoyed does not use automated processing alone to make decisions producing legal effects or similarly significant effects concerning a student (e.g., discipline, special education eligibility) without human review.
- Aggregate/De-identified Analytics: Where InnerJoyed develops population-level behavioral insights or models (e.g., for research or platform improvement), it uses de-identified or aggregated data and does not re-identify individual students from these datasets except as needed to deliver the authorized service back to the originating school.
- Data Sharing Between Institutions: Any cross-institution data sharing (e.g., shared analytics infrastructure) occurs only in de-identified/aggregate form or with an applicable consent/authorization check, and is never used to disclose one school's student-level data to another institution.
11. Data Retention and Deletion
- Student data is retained only as long as necessary to fulfill the purposes described in the applicable school/district agreement, or as required by law.
- Upon contract termination, graduation, withdrawal, or district request, InnerJoyed will delete or return student data within the timeframe specified in the DPA (commonly 30–90 days), except where a copy must be retained to comply with legal obligations, resolve disputes, or enforce agreements.
- Backups containing deleted data are purged on InnerJoyed's standard backup rotation schedule following deletion requests.
- Parents/eligible students may request deletion of specific personal information through their school/district, which InnerJoyed will honor consistent with its role as a service provider, unless retention is legally required.
12. Sharing and Disclosure of Information
InnerJoyed discloses personal information only as follows:
- To the school/district and personnel it authorizes (teachers, counselors, administrators) for educational and behavioral health support purposes
- To subprocessors (e.g., cloud hosting, analytics, customer support tools) bound by written confidentiality and security obligations, acting only on InnerJoyed's instructions
- For legal compliance, such as responding to a valid subpoena, court order, or as required to protect the safety of a student (e.g., imminent risk of harm), consistent with applicable mandatory reporting laws
- In a business transfer (e.g., merger, acquisition), where the receiving party agrees to honor the commitments in this Policy and applicable DPAs
- With parental/eligible student consent, where such consent is obtained directly
InnerJoyed does not sell personal information and does not disclose student data for third-party marketing or advertising purposes.
13. International Data Processing
InnerJoyed is expanding into education markets outside the U.S., including India, Brazil, Belize, and the UAE (Dubai). Depending on where a school/institution and its students are located, InnerJoyed applies the following additional protections:
13.1 India — Digital Personal Data Protection Act, 2023 (DPDPA)
- Processing of children's (under 18) personal data occurs only with verifiable consent of a parent/lawful guardian or through the educational institution acting in that capacity, and InnerJoyed does not undertake tracking, behavioral monitoring for advertising, or targeted advertising directed at children.
- Data principals (or their guardians) may exercise rights of access, correction, and erasure by contacting their institution or InnerJoyed directly.
13.2 Brazil — Lei Geral de Proteção de Dados (LGPD)
- Processing of children's and adolescents' data relies on consent given by at least one parent/legal guardian, or the legal basis applicable to the educational institution, and is limited to the child's best interests.
- Data subjects (titulares) may request confirmation of processing, access, correction, anonymization, or deletion of unnecessary/excessive data through their institution or InnerJoyed's designated contact.
13.3 Belize — Data Protection Act
- Personal data of students is collected and processed based on the lawful basis provided by the educational institution's engagement of InnerJoyed, with data minimization and security principles applied consistent with this Policy.
13.4 United Arab Emirates / Dubai — Federal Decree-Law No. 45 of 2021 (PDPL) and applicable free-zone regimes (e.g., DIFC Data Protection Law)
- Where InnerJoyed serves institutions in the UAE or within a free zone such as DIFC, InnerJoyed applies the relevant free-zone or federal data protection regime's requirements for consent, cross-border transfer safeguards, and data subject rights.
- Cross-border transfers of personal data out of the UAE (e.g., to U.S.-based infrastructure) are made subject to appropriate safeguards such as standard contractual clauses, adequacy determinations, or explicit consent, as required by applicable law.
13.5 Cross-Border Transfers Generally
Where InnerJoyed transfers personal data across borders (e.g., from an international school to U.S.-hosted infrastructure, or vice versa), it uses appropriate transfer mechanisms (such as standard contractual clauses or equivalent safeguards) required by the exporting jurisdiction.
14. Mental and Behavioral Health Data — Heightened Confidentiality
Recognizing the sensitivity of mental and behavioral health information, InnerJoyed applies additional safeguards beyond baseline education-record protections:
- Access to individual student behavioral/mental health indicators is limited to school personnel specifically authorized by the district (e.g., school counselors, social workers, or designated administrators) rather than all staff.
- InnerJoyed does not disclose individual student behavioral/mental health data to parents, other students, or other school staff except as directed by the school/district in accordance with applicable law and district policy (which may include mandatory reporting obligations for imminent safety concerns).
- Where required by state law, InnerJoyed supports schools in honoring any heightened confidentiality requirements applicable to counseling or therapy-adjacent records, and will not treat such data as ordinary "directory information" or general education records for sharing purposes.
- Crisis/Safety Protocol: If the platform identifies indicators suggesting a student may be at risk of harm to self or others, InnerJoyed's protocol is to alert designated, authorized school personnel promptly so that trained staff can follow the school's existing crisis-response and mandatory-reporting procedures. InnerJoyed does not independently contact parents, law enforcement, or emergency services except where legally required or explicitly authorized by the school/district agreement.
15. Parent, Guardian, and Eligible Student Rights
Depending on applicable law, parents, guardians, and eligible students (18+) may have the right to:
- Review the personal information/education records InnerJoyed holds about the student
- Request correction of inaccurate information
- Request deletion of the student's personal information (subject to legal retention requirements)
- Opt out of non-required data collection (e.g., optional surveys) where permitted
- Receive notice of the categories of data collected and third parties with whom it may be shared
- Lodge a complaint with the school/district, InnerJoyed, or, where applicable, a data protection authority
Because InnerJoyed typically operates through schools/districts, these requests are generally coordinated through the student's school. Parents/guardians may also contact InnerJoyed directly using the information in Section 18, and we will coordinate with the applicable school/district to respond.
16. Cookies Policy
This Section applies to cookies and similar tracking technologies used on www.innerjoyed.com and within the Service. InnerJoyed uses a minimal, purpose-limited approach to cookies, consistent with the "no behavioral advertising" commitments in Section 2.1 (Student Privacy Pledge).
16.1 Essential Cookies
Strictly necessary for the website and Service to function, including authentication/session management, security (e.g., CSRF protection), load balancing, and remembering basic user preferences (e.g., language). Essential cookies cannot be disabled through cookie preference tools because the site/Service will not work properly without them; they do not require consent under most cookie laws.
16.2 Analytics Cookies
Used to understand aggregate website and Service usage (e.g., pages visited, time on page, general navigation patterns) so InnerJoyed can improve site performance and content. Analytics cookies do not create advertising profiles and, on student-facing areas of the Service, are limited to what is necessary to operate and improve the Service on behalf of the school/district. Where required by law, analytics cookies are only set after consent is obtained (see Section 16.4).
16.3 No Advertising Cookies
InnerJoyed does not use advertising, retargeting, or behavioral-tracking cookies anywhere on www.innerjoyed.com or within the Service, and does not permit third-party ad networks to place cookies on our site. This applies to all visitors, including students, parents, educators, and general website visitors.
16.4 Cookie Preferences
Website visitors can manage non-essential cookie preferences (e.g., analytics) through the cookie preference banner/tool presented on first visit, or at any time via the "Cookie Preferences" link in the website footer. Preferences can be updated or withdrawn at any time. Where required by applicable law (e.g., EU/UK-style cookie consent regimes encountered in certain international markets), InnerJoyed will obtain opt-in consent before setting non-essential cookies.
17. Website Visitor Privacy (Non-Student Visitors)
Sections 3–15 of this Policy describe how InnerJoyed handles student data collected through the Service on behalf of schools and districts. This Section separately addresses personal information InnerJoyed collects from general visitors to www.innerjoyed.com who are not students using the Service — for example, prospective district customers, parents researching the platform, job applicants, and other members of the public.
17.1 Newsletter Sign-Ups
If you subscribe to InnerJoyed's newsletter, we collect your name and email address to send updates about the platform, company news, and relevant education/behavioral-health content. You may unsubscribe at any time using the link in any email or by contacting privacy@innerjoyed.com.
17.2 Contact Forms and Inquiries
Information submitted through "Contact Us," demo request, or RFP-inquiry forms (e.g., name, email, phone, organization, and message content) is used to respond to your inquiry, evaluate procurement opportunities, and, where relevant, follow up about the Service. We do not sell this information.
17.3 Recruiting and Careers
If you apply for a position with InnerJoyed through our website or a linked careers platform, we (and any third-party applicant-tracking system we use) collect the information you submit (e.g., resume/CV, contact details, work history) to evaluate your candidacy, consistent with applicable employment and data protection law. This data is retained consistent with our recruiting records retention practices and is not used for any purpose other than hiring.
17.4 Marketing Pages
General marketing pages on www.innerjoyed.com (e.g., product overviews, case studies, blog content) may use analytics cookies as described in Section 16.2 to understand engagement, but do not use advertising/retargeting cookies or sell visitor data, consistent with Section 16.3.
17.5 CRM and Sales/Marketing Systems
Contact and inquiry information described in Sections 17.1–17.2 may be stored in InnerJoyed's customer relationship management (CRM) system to manage communications with prospective and current district customers. Access to CRM data is limited to authorized sales, marketing, and customer success personnel, and this data is protected using the security safeguards described in Section 9. CRM data about prospective customers/website visitors is not the same as, and is never combined with, individual student data collected through the Service.
17.6 Your Choices
General website visitors may opt out of marketing communications at any time (see Section 17.1), manage cookie preferences (Section 16.4), and contact privacy@innerjoyed.com to ask what information InnerJoyed holds about them as a website visitor or to request its deletion, subject to legitimate business or legal retention needs (e.g., completing an active recruiting process).
18. Contact Us
For privacy questions, data subject requests, or to report a security concern:
InnerJoyed Privacy Office
Email: info@innerjoyed.com
Website: www.innerjoyed.com
Mailing Address: 11168 N Lake Shore Dr, Mequon, WI, 53092
For security incidents, please also contact: info@innerjoyed.com
Schools and districts with questions about their Data Processing Agreement should contact their InnerJoyed account representative.
19. Changes to This Policy
InnerJoyed may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the markets we serve. We will post the updated Policy on this page with a revised "Last Updated" date, and where changes are material, we will provide additional notice to schools/districts (e.g., via email) consistent with our contractual obligations.
20. Definitions
- "Education Record": Records directly related to a student and maintained by an educational agency/institution or a party acting for it (per FERPA, 20 U.S.C. § 1232g).
- "Personal Information": Information that identifies, relates to, or could reasonably be linked with a particular student or household.
- "Student Data": Any data collected by InnerJoyed through the Service that is linked to an identifiable K-12 student, including behavioral/mental health indicators, assessment responses, and usage data.
- "Operator" / "Service Provider": InnerJoyed, acting on behalf of the school/district under the terms of a Data Processing Agreement.
- "De-identified Data": Data that has had personal identifiers removed such that it cannot reasonably be used to identify an individual student.
