This page explains how Fullmind handles information it processes as a service provider on behalf of schools, school districts, and other education customers (“Customers”). It does not apply to information collected from visitors to our public website, which is covered by our Website Privacy Policy.
These commitments apply across our platform and every service we deliver. Where Fullmind processes student data for a Customer, our agreement with that Customer governs as well.
Schools and districts provide Fullmind with the information our educators need in order to teach. Depending on the service, that can include:
Student data is used to deliver the services a Customer has contracted for, and for nothing else: live instruction and tutoring, IEP service minutes, credit recovery and attendance programs, customer support, and improving the quality of what we deliver to that Customer. Data that has been stripped of identifying information may be used internally to improve our products.
Fullmind records live sessions to support instruction and quality review. A recording is available to the educator who taught the session, to authorized district staff, and to the student who attended it. Fullmind does not make recordings available to anyone else, except where a legal obligation described in Section 3.6 requires it.
Beyond the Customer's own authorized users and the Fullmind educators assigned to its students, student data reaches only: service providers who help operate our platform and are contractually bound to protect it (Section 8); recipients entitled to it through legal process (Section 3.6); and, in the event of a merger or acquisition, the acquiring organization, which inherits every commitment on this page.
Fullmind provides contracted services to educational agencies and institutions (“EAs”). To deliver those services, an EA gives us access to personally identifiable information (“PII”) from student education records, limited to what our staff and contracted educators need for the work. The Family Educational Rights and Privacy Act (“FERPA”), 20 U.S.C. § 1232g(b)(1)(A), permits these disclosures without separate parental consent.
The mechanism is the school official exception at 34 CFR § 99.31(a)(1)(i)(B). An outside party may be treated the same as a school official employed by the EA when it performs a service the EA would otherwise staff itself, operates under the EA's direct control in how it uses and maintains education records, and accepts the redisclosure limits of 34 CFR § 99.33(a). Fullmind meets all three conditions.
Because we are an outside party rather than an EA employee, § 99.33(a) applies to us directly. We may not redisclose PII from education records except where the EA has authorized it under a FERPA exception and records that subsequent disclosure, or where a parent or eligible student has consented. Under 34 CFR § 99.3, an eligible student is one who has turned 18 or is attending a postsecondary institution. The routine case is a district asking us to help move its records out of our system and into a different platform.
Separately, 34 CFR § 99.31(a)(1)(ii) requires the EA to use reasonable methods to ensure a school official reaches only the records in which it has a legitimate educational interest. We support that obligation with the access controls described in Section 7, and will document them for any Customer that asks.
An EA designates Fullmind as a school official with a legitimate educational interest by specifying the criteria for that designation in its annual FERPA notification to parents, as contemplated by 34 CFR § 99.7(a)(3)(iii) and § 99.31(a)(1)(i)(A). Where an EA has made that designation, Fullmind: (a) performs an institutional service or function the EA would otherwise use its own employees to perform; (b) remains under the EA's direct control in how it uses and maintains education records; and (c) uses those records only for the purpose they were disclosed for, and does not redisclose PII without authorization, consistent with 34 CFR § 99.33(a).
Whether any student data is designated “directory information” under FERPA is the EA's decision alone, governed by its own policy and FERPA obligations. Fullmind never makes that designation and never releases student data on that basis. We act on the EA's instructions and our agreement with it.
Education records are never sold, used, or redisclosed by Fullmind for advertising or marketing. Our products carry no advertising of any kind, so there is no behavioral or targeted advertising. Data inside the platform serves the contracted service and nothing else. Anonymized data that identifies no one may be used internally to make our services better for the EAs we work with.
Student data and district-created data in our products belong to the EA. Fullmind claims no ownership interest in either, at any point, and the EA retains control throughout.
If a third party seeks access to education records we hold, we inform the EA in writing immediately. We do not provide access or otherwise respond unless due process, a court order, or a subpoena lawfully issued by a court with jurisdiction compels us, or the EA instructs us to. Where such an order or subpoena arrives, the EA receives notice and a copy of it before anything is released, unless the law or the order itself forbids telling them.
Parents, legal guardians, and eligible students exercise FERPA rights through their school or district, using the procedures that EA has established. Those procedures generally include the right to inspect and review a student's education records, and the right to request an amendment to a record the parent or eligible student believes is inaccurate, misleading, or in violation of the student's privacy rights.
To request an amendment, write to an EA official, identify the specific part of the record at issue, and explain what is wrong with it. An EA that declines will say so and will explain the right to a hearing on the request.
Where an EA needs records that sit in our systems in order to answer such a request, Fullmind will retrieve them at the EA's direction and expense.
If you have a question about information Fullmind processes for a school or district, please contact that school or district directly.
Fullmind supports special education service delivery and IEP fulfillment, so Customers often ask how HIPAA applies. In nearly every case, the governing law is FERPA, not HIPAA.
Records an EA discloses to Fullmind, and that we maintain to serve that EA, are education records under FERPA. HIPAA's definition of “protected health information” carves education records out explicitly — see paragraph (2)(i) of the definition at 45 CFR § 160.103, which excludes “education records covered by the Family Educational Rights and Privacy Act.” The reason is that FERPA already protects them. The U.S. Department of Education and the U.S. Department of Health and Human Services explain the boundary between the two statutes in their Joint Guidance on the Application of FERPA and HIPAA to Student Health Records (updated December 2019).
Where a Customer is not subject to FERPA, and the health information it shares with Fullmind therefore does constitute protected health information, Fullmind operates as a HIPAA-compliant Business Associate. In those engagements Fullmind and the Customer execute a Business Associate Agreement (“BAA”), and from that point HIPAA, the regulations implementing it, and the BAA itself set our obligations for that information.
Whichever framework applies, student health information — IEP records, evaluations, related service documentation — is protected by the safeguards described in Section 7, and the personnel who handle it are trained on the requirements of both laws.
Fullmind's services are built to meet the Children's Online Privacy Protection Act. For students under 13, Fullmind relies on the school or district to provide consent on a parent's behalf, an approach FTC guidance permits where the information is collected solely for the use and benefit of the school and for no other commercial purpose. That condition describes exactly how we operate.
A majority of states now regulate student data beyond what FERPA requires, tightening what may be gathered, how it may be used or shared, whether it may be sold, and how long it may be kept — and adding their own requirements for security, breach notification, and transparency. Fullmind complies with those obligations wherever they apply to us. Where a state conditions lawful processing on a specific contract term, data protection addendum, or written assurance, we work with the Customer in good faith to execute that documentation.
Requests from individuals under the California Consumer Privacy Act or comparable state laws should be directed to the school or district that controls the record. Where Fullmind holds personal information in its own right, write to us using the contact details in Section 12 and we will respond within the period the statute allows.
Security is a core component of our technology and a cornerstone of our company culture. The technical and organizational measures we run are scaled to how sensitive student data is, and include:
Fullmind engages third-party service providers to help deliver its platform and services, and some of them process student data or other personally identifiable information on our behalf. We hold every subprocessor to protections at least as strong as our own, and we remain responsible to the Customer for a subprocessor's handling of student data to the same extent as if Fullmind had processed it directly.
A current list of Fullmind's subprocessors is available to Customers and prospective Customers on request using the contact details in Section 12.
When Fullmind identifies a security incident affecting student PII, containment begins immediately. Within 72 hours of confirming the incident we notify the affected EA's superintendent, or whoever holds the equivalent chief executive role, with the facts as we know them at that point. Fullmind and the EA then determine a response together, including any notification of affected individuals required by law.
How long Fullmind keeps student data, and the manner of its destruction, is set by whichever of these governs: the Customer agreement, a Data Processing Agreement, a Business Associate Agreement, or applicable law. Disposal is carried out so the contents stay confidential from start to finish, and a Customer may request written certification that destruction has occurred.
Fullmind may update this page from time to time to reflect evolving state and federal law. We will not revise this page in a way that weakens the protections described here for an existing EA without that EA's written consent.
For questions about this page or Fullmind's student data practices:
Email: security@fullmindlearning.com
Mail: iTutor.com, Inc. d/b/a Fullmind, PO Box 25436, New York, NY 10087-5436
For questions about student records maintained by a specific school or district, please contact that educational agency directly.