Skip to main content

Product Privacy Policy

Version:
1.0.0
Effective date:
July 1, 2026
Last updated:
June 6, 2026

This Product Privacy Policy (this "Policy") explains how Nisana, LLC, a Missouri limited liability company ("Nisana," "we," "us," or "our"), collects, uses, shares, and protects information processed in the Osprey product application (the "Service") — the cloud-hosted, mobile-and-web application used by adult educational and clinical practitioners ("Facilitators") to plan, deliver, monitor, and report on activities and progress for learners ("Learners") under the Facilitator's professional authority.

This Policy is distinct from the Nisana marketing-site Privacy Policy published at nisana.io and osprey.education, which governs only those informational marketing properties. This Policy governs information processed in the Service itself.

Please also read the Osprey Product Terms of Service, which incorporates this Policy by reference and which (together with any applicable Master Agreement, Data Processing Agreement, Business Associate Agreement, and in-product disclosures) constitutes the agreement that governs your use of the Service.

1. Identity and Contact

The data controller / school-official-acting-on-behalf-of-an-Organization for the Service is Nisana, LLC, a limited liability company organized under the laws of the State of Missouri.

You can reach us at:

  • Privacy and data-subject requests: privacy@nisana.io
  • Legal notices, intellectual-property notices (including DMCA), and contractual correspondence: legal@nisana.io
  • Security vulnerability disclosure and security incident reports: security@nisana.io
  • Data protection contact: dpo@nisana.io

2. Scope of This Policy

This Policy applies to information processed in connection with your use of the Service, including:

This Policy does not apply to:

  • Information you provide directly to the Service (during account creation, account maintenance, content authoring, and Learner-records documentation).
  • Information that another Facilitator or your Organization provides to the Service about you, your Learners, or your team.
  • Information that is generated automatically by your use of the Service (authentication events, in-product telemetry, audit log entries, error reports).
  • Inputs and outputs of AI Features that you invoke in the Service.
  • The Nisana marketing properties at nisana.io and osprey.education, which are governed by the separate marketing-site Privacy Policy.
  • Information you provide directly to a third party (for example, an email-service provider, a school information system, or a social-media platform) outside the Service.
  • Third-party websites linked from the Service or content embedded from third-party providers, which are governed by the third party's own privacy disclosures.

3. Roles Under Privacy Law

Privacy obligations differ by Nisana's role in each information flow. We define the role for each material category below:

3.1 Facilitator Account Data. For data about Facilitators themselves (account data, telemetry, AI consent records, audit log entries about Facilitators), Nisana acts as a controller under U.S. comprehensive state privacy laws (e.g., CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA, TIPA, IDPA, DPDPA, NHDPA, NJDPA, MNCDPA, and successor statutes), determining the purposes and means of processing for Facilitator data.

3.2 Learner Records (FERPA Path). For Learner Records that constitute "education records" within the meaning of the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99) ("FERPA"), Nisana acts as an authorized contractor providing services to the Organization (school, district, state education agency, or eligible postsecondary institution) on behalf of the Facilitator who is a school official with legitimate educational interest under 34 CFR § 99.31(a)(1)(i)(B). Nisana is bound by the FERPA "school official" obligations:

The applicable Organization remains the controlling party with respect to Learner Records under FERPA. Nisana surfaces parental, eligible-student, and records-officer requests to the responsible Organization or Facilitator.

3.3 Learner Records (HIPAA Path). Where Learner Records constitute protected health information ("PHI") within the meaning of the Health Insurance Portability and Accountability Act of 1996 (45 CFR Parts 160, 162, and 164) ("HIPAA") — for example, records processed by a clinical practice that is a HIPAA-covered entity operating outside the FERPA "treatment records" carve-out — Nisana acts as a business associate under a written Business Associate Agreement ("BAA") with the covered Organization. Nisana does not act as a business associate in the absence of an executed BAA; Facilitators processing PHI in the Service are responsible for ensuring a BAA is in place.

3.4 IDEA Confidentiality. Where Learner Records contain information about the identification, evaluation, educational placement, or provision of a free appropriate public education to a child with a disability under the Individuals with Disabilities Education Act ("IDEA"; 34 CFR §§ 300.610–300.626), Nisana processes those records consistent with the IDEA confidentiality obligations as flowed down by the responsible Organization.

3.5 State Student-Data-Privacy Path. Where state student-data-privacy laws apply (including, without limitation, NY Education Law § 2-d and Part 121, IL SOPPA (105 ILCS 85), CA SOPIPA (Cal. Bus. & Prof. Code §§ 22584–22585) and CA AB 1584 (Cal. Educ. Code § 49073.1), CT 10-234aa et seq., LA Act 837, TN T.C.A. § 49-1-701 et seq., UT 53E-9-301 et seq., VA § 22.1-289.01, WA HB 1495, NV NRS 388.281 et seq., NH RSA 189:65 et seq., AZ HB 2088, and CO HB 16-1423), Nisana operates as a school service provider or operator and is bound by the use, disclosure, security, and de-identification limitations imposed by the applicable statute and by any Master Agreement or Student Data Privacy Agreement ("SDPA") signed with the Organization.

3.6 Demographic and Aggregated Data. Where Nisana processes data that is fully de-identified and aggregated such that no individual Learner or Facilitator can be re-identified, Nisana acts as a controller for the de-identified dataset and uses it solely for the limited purposes described in Section 5 (How We Use Information).

  • Performing a service that the Organization would otherwise use its employees to perform.
  • Operating under the Organization's direct control with respect to use and maintenance of education records.
  • Not redisclosing education records or using them for any purpose other than the purpose for which the Organization disclosed them.

4. Information We Collect

4.1 Facilitator Account Data. When a Facilitator creates or maintains an account, the Service collects:

4.2 Organization, Team, and Roster Data. The Service stores information about the Organizations that use the Service and the team and care-team structures that route Learner Records to authorized Facilitators. This includes Organization names, addresses, billing information (for Paid Tiers), administrator contacts, role assignments, permission overrides under Nisana's role-based access control ("RBAC") framework, and sub-tenant relationships (e.g., independent practices nested under an agency).

4.3 Learner Records. When a Facilitator processes Learner Records in the Service, the Service stores information that may include:

4.4 Usage and Operational Telemetry. The Service collects operational telemetry that supports Service operation, security, and improvement, including:

4.5 Information Received From Sub-processors. The Service receives operational signals from its sub-processors (e.g., deliverability events from email services, request metadata from cloud hosting, completion metadata from AI providers) as needed to operate the Service. The Service does not ingest contact lists from data brokers, purchase enrichment data, or correlate Service users to advertising profiles.

4.6 What We Do Not Collect. The Service is not designed to collect, and Facilitators are instructed not to submit, the following categories at the Facilitator-account or Learner-record layer unless directly necessary to a documented educational or clinical purpose:

  • Legal name, professional email address, password (stored as a salted hash; never in plaintext).
  • Professional role (e.g., BCBA, RBT, SPED Teacher, SLP, OT, PT, General Educator, Para, School Counselor, School Psychologist, Administrator).
  • Organization affiliation (where applicable), including district, school, clinic, agency, or independent-practice information; team and care-team membership.
  • Authentication and session metadata, including device identifier, client platform, IP address at sign-in, multi-factor authentication state, and biometric-unlock enrollment state.
  • Notification and communication preferences.
  • Consent records, including the version and timestamp of accepted Product Terms of Service, accepted Product Privacy Policy, accepted AI processing consent (Facilitator-level), and any opt-in or opt-out preferences for non-mandatory communications.
  • Learner identifiers (legal name, preferred name, date of birth, age, grade, cohort), as supplied by the Facilitator or imported from the Organization's information system. The Service does not require — and Facilitators are encouraged to omit — Social Security numbers, full date-of-birth precision where unnecessary, or government-issued identification numbers.
  • Educational records and goals, including IEP goals (where IDEA applies), individualized program plans, behavior intervention plans, 504 plan accommodations, related-services goals, treatment plans, classroom observation notes, and clinician-authored documentation.
  • Behavioral and clinical data, including discrete-trial training ("DTT") trial-level data, frequency counts, interval recording, ABC (antecedent-behavior-consequence) records, prompt hierarchies, reinforcement records, and articulation/language/AAC data, as applicable to the Facilitator's discipline.
  • Progress monitoring data, including manual progress entries, generated progress aggregates, mastery determinations, and longitudinal progress reports.
  • Session and activity data, including session timestamps, activity invocations, task content, learner responses, and session notes.
  • Media authored or uploaded by Facilitators in connection with Learner Records (images, audio, video, documents). Facilitators are responsible for ensuring uploaded media is appropriate and is processed consistent with Facilitator authorization under FERPA / state law / a BAA.
  • AI Features inputs and outputs that include or refer to a Learner.
  • Audit log entries that record access to and modification of Learner Records.
  • Application-level events (feature invocations, navigation, error reports), correlated to a Facilitator account but not to specific Learner identifiers except where the event itself records a Learner Record action.
  • Authentication events, including sign-in, sign-out, password reset, and multi-factor authentication enrollment events.
  • Audit log entries, including create / read / update / archive / delete operations on Learner Records, RBAC denials, AI consent state changes, legal-document acceptances, and account-deletion events.
  • Device information (operating system, application version, locale, client type) and request metadata (IP address, user agent, request timestamp).
  • Social Security numbers and equivalent national-ID numbers.
  • Payment-card numbers from Facilitators (Paid Tier billing is processed by the Organization, not by individual Facilitators).
  • Precise geolocation derived from a Facilitator's device.
  • Genetic data and biometric identifiers (other than the on-device biometric-unlock template, which never leaves the device).
  • Information about Facilitator union or political affiliation, religious belief, or sexual orientation.
  • Information about minors who are not Learners under a Facilitator's professional authority.

5. How We Use Information

We use information processed in the Service only for the following purposes, in alignment with our roles in Section 3:

We do not use Service-collected information for:

  • To provide the Service — to authenticate Facilitators, route Learner Records to authorized Facilitators based on Organization, team, and care-team membership, render the user interface, store Facilitator Content and Learner Records, surface progress, deliver notifications, and process AI Features at Facilitator request.
  • To enforce permission and authorization rules — to evaluate the RBAC framework, gate access to Learner Records, evaluate consent state (Facilitator AI consent and per-Learner AI processing consent), evaluate retention policies, and surface cross-discipline visibility consistent with each Organization's permission posture.
  • To operate AI Features at Facilitator request, subject to the consent gating in Section 7 and the contractual restrictions on our AI sub-processors.
  • To secure the Service — to detect, investigate, and prevent fraud, abuse, security incidents, account takeover, malicious behavior, and service degradation; to perform vulnerability management; to operate rate limits and abuse triage.
  • To meet records-retention and audit obligations — to retain records required by FERPA, IDEA, applicable state student-data-privacy laws, the Organization's records-retention policy, and our own records-retention policy, and to support audits by Organizations, regulators, or third-party assessors.
  • To improve the Service — using de-identified, aggregated, and product-telemetry signals only, in a manner that does not re-identify any Learner or Facilitator. We do not train, fine-tune, or evaluate generative-AI models on Learner Records, Facilitator Content, or any other non-aggregated personal information.
  • To communicate with Facilitators — to send transactional and account communications (security alerts, legal-document re-consent prompts, account-deletion confirmations, notification-preference emails) and, with the Facilitator's opt-in where required by applicable law, occasional product communications. We do not use Service-collected personal information for advertising.
  • To comply with applicable law — to respond to valid legal process (subpoenas, court orders, search warrants, regulator inquiries), to enforce these Terms and the Privacy Policy, to defend Nisana against claims, and to protect the rights, property, or safety of Nisana, Facilitators, Learners, or the public.
  • Targeted advertising or cross-context behavioral advertising.
  • Profiling that produces legal or similarly significant effects on a Learner.
  • Sale of personal information as defined under any applicable U.S. comprehensive privacy law.
  • Training third-party generative-AI models (other than as necessary to produce the immediate AI Features output you requested).

6. How We Share Information

We share personal information only:

We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act, as amended (Cal. Civ. Code § 1798.140), or under any other comparable U.S. state privacy law.

We have not sold or shared (for cross-context behavioral advertising) Service-collected personal information in the preceding twelve months and have no current plans to do so.

  • With sub-processors acting on our behalf, as listed in Section 9 (Sub-processors), under written contracts that limit each sub-processor's use of the information to the purposes Nisana directs. Each sub-processor is bound by data-protection, confidentiality, security, and breach-notification obligations.
  • With your Organization — where Learner Records and team-level records are concerned, with administrators and Facilitators within your Organization who are authorized under the Organization's RBAC posture, team membership, and Master Agreement.
  • To comply with law — when we receive valid legal process (e.g., a subpoena, court order, regulator inquiry, or other lawful request). Where lawful and not prohibited by an investigatory hold, we will give the affected Organization or Facilitator reasonable advance notice and an opportunity to seek a protective order.
  • To protect rights and safety — when we have a good-faith basis to believe disclosure is necessary to protect the rights, property, or safety of Nisana, Facilitators, Learners, the Organization, or the public, including in the context of a security incident.
  • In a corporate transaction — for example, a merger, acquisition, reorganization, financing, or sale of assets. We will provide reasonable advance notice if a transaction would materially change how Service-collected information is handled, and any successor will be bound by privacy obligations no less protective than this Policy.
  • As otherwise authorized in writing by the controlling Organization (for FERPA-path Learner Records) or by the affected Facilitator (for Facilitator-account data).

7. AI Features and AI Data

7.1 What AI Features Do. AI Features in the Service use third-party machine-learning models (including large language models and image-generation models) to generate, suggest, summarize, draft, or transform content on Facilitator request. Examples include drafting session notes, suggesting goal language, summarizing progress data, and generating activity templates.

7.2 Consent Gating. AI Features are gated by two layered consents:

The Facilitator (or, where required, the Organization or parent/guardian/eligible-student under the Facilitator's authority) is responsible for obtaining and recording the appropriate Learner-level consent before enabling AI processing for that Learner. Where consent has not been recorded, the Service does not transmit identifiable Learner data to AI sub-processors.

7.3 Sub-processor Restrictions. Nisana contractually prohibits its AI sub-processors from training, fine-tuning, or evaluating their models on Facilitator Content, Learner Records, or any other non-aggregated personal information processed through the Service, except as strictly necessary to produce the immediate AI Features output the Facilitator requested. The current AI sub-processors and the relevant processing-terms commitments are listed in Section 9 (Sub-processors).

7.4 No Automated Consequential Decisions. AI Features are decision-support tools, not automated decision-makers. The Service does not use AI Features to make consequential decisions about Learner placement, eligibility, identification, discipline, or similar matters without authorized human review. Use of AI Features in a consequential-decision context is constrained by Section 10 of the Product Terms of Service and by applicable AI-governance regimes, including, where applicable, the EU AI Act (Reg. (EU) 2024/1689) and the Colorado AI Act (CO SB 24-205).

7.5 AI Inputs, Outputs, and Audit. AI inputs and outputs are stored in the Service for the limited purposes of (i) returning the immediate output to the requesting Facilitator, (ii) supporting audit trail requirements imposed on Nisana by FERPA, state student-data-privacy law, or any Master Agreement, and (iii) operating safety and abuse controls (e.g., content-policy enforcement on generated outputs). Inputs and outputs that include identifiable Learner data are subject to the same access controls and retention rules as the underlying Learner Records.

  • Per-Facilitator AI consent: Each Facilitator must affirmatively accept the in-product AI consent surface before AI Features that process Facilitator-supplied content are enabled for that Facilitator. Facilitator AI consent is recorded in the Service and may be revoked at any time, in which case AI Features that depend on that consent are disabled until consent is re-granted.
  • Per-Learner AI processing consent: For AI processing that involves an identifiable Learner, the Service additionally requires a per-Learner AI processing consent, recorded on the Learner's record. AI Features that would process a Learner's record without this consent are blocked at the application layer.

8. Cookies and Similar Technologies (In-Product Surface)

The Service uses only strictly-essential browser-side technologies required for the in-product surface to function — for example, transient session storage used to support authentication, RBAC evaluation, AI consent state, and basic CSRF protection. The Service does not use:

Because we do not deploy non-essential cookies in the in-product surface, the Service does not display a cookie consent banner. If we adopt any technology that requires consent under applicable law, we will update this Policy and present the appropriate consent surface before that technology is enabled.

  • Advertising or marketing cookies.
  • Cross-site tracking pixels or beacons.
  • Behavioral-advertising profiling cookies.
  • Device-fingerprinting techniques.
  • Third-party social-network tracking widgets.

9. Sub-processors

Nisana relies on a small number of vetted sub-processors that process information on its behalf under contractual obligations to use the information only for the purposes Nisana directs. The following list is material to the Service's operation as of the Last Updated date above.

We may add, remove, or replace sub-processors as the Service evolves. For sub-processor changes that materially affect the categories of personal information processed, the location of processing, or the rights of Facilitators or Organizations, we will (i) update this Policy with the new sub-processor enumerated, (ii) where required by a Master Agreement or applicable law, provide advance written notice to affected Organizations and an opportunity to object, and (iii) where the change is material under our change-classification policy, treat the corresponding update to this Policy as a material change requiring re-consent under Section 14 (Changes to This Policy).

  • Microsoft Azure (Microsoft Corporation; United States) — cloud hosting (App Service / Front Door), serverless backend (Azure Functions), database (Azure Database for PostgreSQL), object storage (Azure Blob Storage), table storage for transient state (Azure Table Storage), application monitoring (Azure Application Insights), and transactional email delivery (Azure Communication Services Email). All Service workloads are deployed to U.S. Azure regions.
  • Azure OpenAI Service (Microsoft Corporation; United States) — AI Features text generation and (where enabled) image generation. Processed under Microsoft's enterprise data-handling terms, which prohibit Microsoft and OpenAI from using Service-submitted prompts or outputs to train, fine-tune, or evaluate any underlying or successor model.
  • Plausible Analytics (Plausible Insights OÜ; Estonia, EU) — cookieless, aggregate web analytics for the marketing properties only; not enabled in the in-product surface.

10. Data Retention, Deletion, and Account Lifecycle

10.1 Retention Principles. We retain personal information only as long as we need it for the purposes described in this Policy, the Product Terms of Service, any applicable Master Agreement, and applicable records-retention obligations under FERPA, IDEA, applicable state student-data-privacy law, professional licensure requirements, and Nisana's records-retention schedule.

10.3 Self-Service Account Deletion. Facilitators may delete their account at any time using the in-product account-deletion feature accessible from the Profile screen. On self-service account deletion:

A confirmation of account deletion is presented in-product and, where applicable, by email.

10.4 Organization-Initiated Deletion. Where a Master Agreement is in force, the Organization may request deletion or return of Learner Records associated with its tenancy under the procedures specified in that Master Agreement. Nisana will respond within the timelines required by applicable state student-data-privacy law and any contractual SLA, and will document the deletion or return in the audit trail.

10.5 Litigation Holds and Regulator Inquiries. Notwithstanding the retention windows above, Nisana may retain information for the duration of a litigation hold, regulator inquiry, or breach investigation.

  • Facilitator account data is retained for the lifetime of the Facilitator account, plus any post-deletion retention required for audit, dispute resolution, regulatory compliance, security, fraud prevention, or legal-claim defense (typically not to exceed seven (7) years from account deletion, except where a longer retention is required by law or by an Organization's records-retention schedule).
  • Learner Records are retained under the controlling Organization's records-retention schedule (FERPA, IDEA, state student-data-privacy law, professional licensure rules, and any Master Agreement). Where the Organization has not specified a retention window, Nisana applies a default that is consistent with the strictest applicable jurisdictional baseline for educational and clinical records.
  • Audit log entries in ops.audit_log, including legal-document acceptances and account-deletion events, are retained for at least seven (7) years to support FERPA audit obligations, professional licensure board requirements, regulator inquiries, and litigation hold.
  • AI inputs and outputs that reference identifiable Learner data follow the retention rule of the associated Learner Record. AI inputs and outputs that do not reference identifiable Learner data are retained for up to thirty-six (36) months, then pruned, except where retained for security or abuse investigation.
  • Authentication and operational telemetry with personally identifiable elements (e.g., IP address, user agent) is retained in operational logs for up to ninety (90) days, then deleted or aggregated to non-identifying form.
  • Backup copies of the underlying database are retained for the duration of Nisana's standard backup-retention window (typically thirty-five (35) days), then expired by the backup system.
  • The Facilitator's identity is soft-deleted — the identity.users.deleted_at timestamp is set, the account is immediately deactivated, all active sessions are revoked, and authentication is blocked.
  • Operational user records associated with the Facilitator (notification device tokens, RBAC overrides, AI consent state, biometric-unlock enrollment) are anonymized or removed, except where preservation is required by audit or applicable law.
  • Clinical and educational artifacts authored by the Facilitator — including Learner Records, IEP goals, behavior intervention plans, session notes, progress reports, and audit-log references — are preserved under the controlling Organization's authority and the applicable records-retention schedule, with author attribution anonymized to the extent feasible. This preservation is required because the Organization, not the Facilitator, is the controlling party for FERPA-path Learner Records, and unilateral deletion by an individual Facilitator would violate the Organization's records obligations.
  • An audit-log entry is created recording the account-deletion event with the operation ACCOUNT_DELETE.

11. Security

We implement reasonable administrative, technical, and physical safeguards designed to protect the personal information we collect, including:

No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur. If we determine that personal information has been subject to unauthorized acquisition or use, we will notify affected individuals, the controlling Organization, and, where required, regulators without unreasonable delay and consistent with applicable state and federal breach-notification law (including, without limitation, RSMo § 407.1500 and equivalent state regimes).

To report a vulnerability or a suspected security incident affecting the Service, contact security@nisana.io.

  • Encryption of data in transit using TLS for all client traffic to the Service.
  • Encryption of data at rest using the underlying Azure platform's default encryption.
  • Access limited to authorized Nisana personnel on a need-to-know basis, enforced through RBAC, multi-factor authentication, and audit logging.
  • A comprehensive permission framework that gates access to Learner Records by Facilitator role, team membership, care-team scope, and per-learner consent state.
  • Honeypot rejection, IP-based rate limiting, and abuse-detection controls.
  • Secret rotation procedures for service credentials, including AI sub-processor credentials.
  • Incident response procedures aligned to industry-standard frameworks (e.g., NIST SP 800-61) and to applicable breach-notification obligations.

12. Your Rights and Choices

12.1 Rights Available to Facilitators. Subject to verification of your identity and to limited statutory exceptions, you may request that Nisana:

12.2 Rights Concerning Learner Records. Rights requests concerning Learner Records under FERPA, IDEA, or applicable state student-data-privacy laws are administered by the controlling Organization, not by Nisana directly. If a parent, guardian, eligible student, or records officer submits a Learner-record rights request to Nisana, we will route the request to the responsible Organization or Facilitator and will cooperate with the Organization's response, subject to applicable law.

12.3 California-Specific Disclosures. In addition to the rights above, California residents have the rights under the California Consumer Privacy Act, as amended (CCPA/CPRA), to know the categories of personal information we have collected, the categories of sources from which it was collected, the business or commercial purposes for which it was collected, and the categories of third parties to whom we have disclosed it. Those categories are enumerated in Section 4, Section 5, Section 6, and Section 9 and are incorporated into this Section by reference.

You have the right to designate an authorized agent to submit a request on your behalf. We may require the agent to provide written proof of authorization and may require you to verify your identity directly with us before we honor an agent-submitted request.

We will not discriminate against you for exercising any privacy right.

12.4 Appeals. If we decline a privacy request, you may appeal that decision by emailing privacy@nisana.io with the subject line "Privacy Request Appeal." We will respond to appeals within sixty (60) days of receipt and, where state law permits, will provide information about further recourse (for example, the Attorney General of your state).

12.5 Global Privacy Control. Where applicable to Facilitator-account data, we honor the Global Privacy Control (GPC) browser signal as a valid opt-out preference.

12.6 How to Submit a Request. To exercise any of the rights described above, email us at privacy@nisana.io with the subject line "Privacy Request" and describe what you are asking us to do. We will acknowledge your request within ten (10) business days and respond substantively within forty-five (45) days of receipt. We may extend the response window by up to an additional forty-five (45) days where reasonably necessary, in which case we will tell you the reason and the expected response date before the original window closes.

  • Confirm and access what personal information we hold about you as a Facilitator.
  • Correct Facilitator-account information about you that is inaccurate.
  • Delete Facilitator-account information about you (subject to the account-deletion behavior in Section 10.3 and to retention obligations under FERPA, IDEA, applicable state law, and any Master Agreement).
  • Provide a portable copy of the Facilitator-account information you have provided to us, in a structured, commonly used format.
  • Opt out of any future processing of your Facilitator-account data for cross-context behavioral advertising or for profiling that produces legal or similarly significant effects on you. (We do not currently engage in either activity, but the opt-out remains available as a forward-looking commitment.)
  • Limit the use of sensitive personal information as defined under applicable law.
  • Withdraw your AI processing consent at the Facilitator level, using the in-product AI consent surface.

13. Children's Privacy

The Service is intended for adult professional Facilitators. Children do not create accounts and do not interact directly with the Service.

Where Learner Records concern children under thirteen (13), the processing operates under one of the following grounds, depending on the controlling regime:

Nisana does not knowingly collect personal information directly from children at the Facilitator account layer. If you believe a child has inadvertently submitted personal information through the Service, contact privacy@nisana.io and we will investigate and take appropriate action.

  • FERPA school official path — The Organization has designated the Facilitator (and, by extension, Nisana as the contractor providing the Service) as a school official with legitimate educational interest under 34 CFR § 99.31(a)(1)(i)(B), with no commercial use and no redisclosure outside the educational context.
  • COPPA school-as-agent path — Where COPPA applies (15 U.S.C. §§ 6501–6506; 16 CFR Part 312, including the FTC's 2025/2026 amendments), the Organization acts as the parent's agent for purposes of consent to the limited educational processing performed by Nisana on the Organization's behalf, consistent with FTC guidance on the school-as-agent doctrine.
  • HIPAA path under BAA — Where the Learner Record is PHI processed by a HIPAA-covered Organization under a written BAA with Nisana, the HIPAA Privacy Rule governs.

14. Changes to This Policy

We may update this Policy from time to time. When we do, we will increment the version label, update the "Effective Date" and "Last Updated" dates at the top of this document, and publish the new version through the in-app legal-document registry.

For each new version, we will determine whether the change is material under our published change-classification policy. Material changes — including, without limitation, changes to the categories of personal information collected, the purposes for which it is used, the sub-processors with which it is shared, or the rights extended to Facilitators or Organizations — will require Facilitator re-consent through the in-product re-consent gate before continued use of the Service.

For non-material changes (formatting, typo corrections, clarifications that do not alter rights or obligations), we may publish the updated version without requiring re-consent.

Prior versions of this Policy are preserved in the identity.legal_document_versions registry table and in the public version history of the Nisana source repository (docs/legal/product-privacy-policy.md in the postrema/ALC repository).

15. International Use

The Service and its sub-processors are oriented toward use in the United States and are hosted in U.S. Azure regions. We do not currently market the Service to, or actively solicit personal data from, individuals in the European Union, the United Kingdom, the European Economic Area, the Russian Federation, the People's Republic of China, or any other jurisdiction whose laws would require localized processing, specific cross-border transfer mechanisms, or appointment of a local representative. If you are located in such a jurisdiction and choose to use the Service through your Organization's Master Agreement, please be aware that the protections of your local law may not apply except as provided in that Master Agreement.

16. Accessibility

We are committed to maintaining the Service in accordance with Web Content Accessibility Guidelines (WCAG) 2.1 Level AA as a design and engineering standard. We continue to test and improve the Service against this standard. If you encounter an accessibility barrier in the Service, please contact legal@nisana.io with a description of the barrier (page or screen, what you were trying to do, the assistive technology you were using, and what happened) and we will work in good faith to address it.

This commitment does not constitute a representation, warranty, or guarantee that the Service is free of every accessibility issue at every moment. We aspire to substantial conformance with WCAG 2.1 AA and will continue to invest in that conformance.

17. FERPA Audit Posture (For Organizations and Reviewers)

This Section is included for the benefit of Organizations, district records officers, state student-data-privacy reviewers, and the Student Data Privacy Consortium / NDPA review process. Nisana's posture as the contractor providing the Service to a school official with legitimate educational interest is summarized in Section 3.2 and is operationally reflected in the following controls:

  • Direct control by the Organization. The Organization controls the use and maintenance of education records processed in the Service through Master Agreements, Student Data Privacy Agreements, the Organization-level RBAC posture, and Organization-administered team and care-team membership.
  • No redisclosure. Nisana does not redisclose education records outside the Organization except as authorized in writing by the Organization, as required by valid legal process, or as expressly provided in this Policy (Section 6).
  • No secondary use. Nisana does not use education records for purposes other than providing the Service to the Organization, except for security, fraud prevention, audit, and compliance.
  • Audit logging. Operations on Learner Records are recorded in ops.audit_log with operation, resource type, actor, and timestamp, and are retained per Section 10.2.
  • De-identification standard. Where Nisana derives de-identified aggregate data from Service operations, it does so consistent with the FERPA de-identification standard at 34 CFR § 99.31(b)(1) and applicable state-law definitions of de-identification.
  • Records destruction. On termination of an Organization's Master Agreement, Nisana returns or destroys education records as specified in that Master Agreement.

18. Contact Us

You can reach us at the following role-based addresses:

For general (non-legal, non-privacy, non-security) inquiries about the Service, you may contact hello@osprey.education.

  • Privacy and data-subject requests: privacy@nisana.io
  • Legal notices and contractual correspondence: legal@nisana.io
  • Security vulnerability disclosure and security incident reports: security@nisana.io
  • Data protection contact: dpo@nisana.io