Version 2026-07-31
Privacy Policy
Who controls your information
Your school district or educational agency is the data controller. SolutionWhere operates this service on their behalf as a service provider, and processes personal information only on their documented instructions. If you want your records corrected or removed, your district decides — ask them first, and they can instruct us.
What we collect
- Identity and contact details: your name, work email address, district, building, and position.
- Professional learning records: the sessions you register for, your attendance, the credit you earn, and evaluations you submit.
- Payment records: the amount, date, card brand, and last four digits. We never receive or store full card numbers or security codes — those go directly from your browser to our payment processor.
- Technical records: sign-in times and the audit trail described below.
How we use it
To register you for training, record the credit you earn, produce transcripts and certificates, take payment where a session has a fee, and report participation to your district and, where required, to the state. We do not sell personal information, and we do not use it to train machine-learning models.
Student records and FERPA
This service holds records about educators, not students. Where a district’s use touches records covered by FERPA, SolutionWhere acts as a school official with a legitimate educational interest under the district’s direct control, uses the information only for the purpose it was disclosed, and does not re-disclose it without the district’s authorization.
The audit trail
We record every creation, change, deletion, sign-in, and export, together with who performed it and when. This exists to protect you: it is how your district can answer the question of who altered a record. The log cannot be edited or deleted from within the application by anyone, including administrators, and entries are kept for seven years by default.
How it is protected
All traffic is encrypted in transit with TLS, and data is encrypted at rest. Access is controlled by role and enforced in the database itself rather than only in the interface. We sign you in through your organization’s Google account, so we never hold a password of yours at all — multi-factor authentication is whatever your organization requires. Backups are encrypted and taken daily.
How long we keep it
Your district sets its own retention period. Transcript records are usually kept longer than operational records, because educators rely on them for licence renewal, sometimes many years after the fact. A district may instruct us to export or permanently delete its data at any time, and permanent deletion is exactly that — it cannot be undone.
Your choices
You can view and correct your own profile and training history at any time from My Training. Transactional email about sessions you registered for cannot be turned off, because it carries information you need — dates, room changes, cancellations. Optional announcements can be, using the unsubscribe link in every such message.
Contact
Questions about this policy: privacy@solutionwhere.com. Questions about your own records: your district’s professional learning office, who can act on them directly.
This text describes what the software does today and has not yet been reviewed by counsel. It should be before a district signs anything that references it.