Privacy Policy
Effective date: July 1, 2026
EvalCamp is a product of NetDev Studio, LLC ("EvalCamp," "we," "us," or "our"), located in Austin, Texas. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with the EvalCamp special-education evaluation workflow platform and our website (collectively, the "Service").
1. Scope and our two roles
EvalCamp is a business-to-business tool sold to K–12 school districts and similar educational agencies ("Districts"). Students and parents do not create EvalCamp accounts. Because of this, we handle information in two distinct roles, and different rules apply to each:
| Role | What it covers | Who controls it |
|---|---|---|
| A. Service Provider / "School Official" | Student and school data a District puts into (or has us collect through) the Service to manage special-education evaluations ("Service Data") | The District is the controlling party. We process Service Data only under the District's direction and our Data Privacy Agreement (the "DPA"). |
| B. Controller | Account information about District staff who use EvalCamp, plus website visitors, prospects, and demo requesters ("Account & Website Data") | EvalCamp controls this data, and this Policy governs it directly. |
For Service Data (Role A), this Policy is informational. The District's own privacy notices, its agreement with EvalCamp, and the Family Educational Rights and Privacy Act ("FERPA") govern how that data is handled, and individuals exercise their rights through their District (see Section 11).
2. Information we collect
2.1 Service Data (collected on behalf of Districts)
When a District uses EvalCamp to coordinate special-education evaluations, the Service stores the following categories of information. Districts and their authorized staff enter this data; EvalCamp does not obtain it from students or parents directly.
| Category | Data elements | Purpose |
|---|---|---|
| Student identification | First name, last name, District-assigned student ID | Associate evaluations with the correct student |
| Student enrollment | Grade level, campus assignment, date of birth | Organize and schedule evaluations; verify identity and timelines |
| Special-education evaluation data | Disability categories, eligibility determinations, referral source, referral concerns, consent dates, evaluation and eligibility due dates, completion dates, evaluation status and phase, cancellation reasons, and evaluation notes | Track the evaluation lifecycle and compliance deadlines |
| Parent/guardian contact | Name, email address, phone number, preferred language | Distribute and follow up on evaluation-related forms |
| Staff/teacher contact | Name, email address, phone number, campus | Assign and distribute evaluation-related forms |
| Form distribution | Form title and type, recipient name and email, message subject and body, external form URL, send count, send and completion timestamps | Send, track, and record evaluation forms (e.g., consent, developmental history, rating scales) |
| Links to external records | District-supplied URLs to a student's records folder | Let staff reach records stored in the District's own systems |
EvalCamp does not intentionally collect, and asks Districts not to enter, the following: Social Security numbers, financial account numbers, biometric data, or document attachments. The Service has no file-upload feature. When a District links to an external system, EvalCamp stores only the link, not the contents behind it.
2.2 Account & User Data (District staff)
For each District staff member who uses EvalCamp, we collect: first and last name, work email address, phone number (optional), job title, role and permission level, District and campus affiliation, a securely hashed password, and account-status information (invited, active, or deactivated).
2.3 Website, prospect, and demo data
If you request a demo, sign up for a conference sandbox, or otherwise contact us, we collect the information you provide — typically your full name, work email address, and District or organization name — along with the source of the request.
2.4 Information collected automatically
When authorized users access the Service, we and our infrastructure providers automatically log technical data, including: IP address, sign-in and sign-out timestamps, sign-in counts, browser and device information, pages and actions taken within the app, and audit records of security-relevant events (such as team-membership changes). We use session and authentication cookies to keep users signed in (see Section 9).
3. How we use information
We use information to:
- Provide, operate, secure, and maintain the Service for Districts;
- Authenticate users and manage access, roles, and permissions;
- Send transactional and evaluation-related email (such as form distribution, notifications, and password resets);
- Track evaluation timelines and surface compliance deadlines;
- Maintain audit logs and investigate security or misuse;
- Provide customer support and respond to requests;
- Monitor performance, diagnose errors, and improve reliability;
- Communicate with prospects and administer demos and sandboxes; and
- Comply with law and enforce our agreements.
We never use Service Data for advertising, sell or rent it, build commercial profiles of students, or mine it for non-educational commercial purposes. See Section 5.
4. How we share information
We do not sell personal information. We share information only as follows.
4.1 Subprocessors
We use vetted third-party providers to run the Service. Each is contractually bound to data-protection obligations no less protective than our commitments to Districts.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Hetzner | Application and database hosting | All Service Data (encrypted in transit and at rest) |
| DigitalOcean | Encrypted database backup storage | All Service Data (encrypted) |
| Resend | Transactional and form-distribution email | Recipient names, email addresses, message content |
| AppSignal | Error reporting and performance monitoring | Application error logs and performance metrics (no student data) |
| PostHog | Website and product analytics | Usage events and page interactions (no student data) |
| Gleap | Customer support | Support messages, screenshots, and metadata (may reference Service Data) |
4.2 With the District
Service Data is accessible to the District's own authorized users according to the roles and permissions the District configures.
4.3 Legal and safety
We may disclose information if required by law, subpoena, or valid legal process, or to protect the rights, safety, or property of EvalCamp, our users, or the public — and, for Service Data, only as permitted by our agreement with the District and FERPA.
4.4 Business transfers
If EvalCamp is involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction, subject to the confidentiality and student-privacy commitments in this Policy and applicable law.
5. Student privacy commitments
Because EvalCamp processes student education records, we make the following binding commitments for all Service Data:
- FERPA "school official." EvalCamp acts as a "school official" with a "legitimate educational interest" under FERPA (34 CFR §99.31(a)(1)(i)), performing a service the District would otherwise perform itself. We remain under the District's direct control as to the use and maintenance of education records.
- Use limitation. We use Service Data solely to provide the Service, and only for purposes the District authorizes.
- No re-disclosure. We do not re-disclose personally identifiable information from education records to any third party without the District's prior written authorization, except as required by law or through the subprocessors listed above.
- No advertising, no sale, no profiling. We do not use Service Data for targeted advertising, do not sell or rent it, and do not build commercial profiles of students.
- District ownership. The District retains sole ownership of Service Data; EvalCamp holds it only as a custodian and processor.
5.1 COPPA
EvalCamp is used exclusively by District staff. Students do not log in to or interact with the Service, and the Service has no student-facing interface. We do not knowingly collect personal information directly from children. Where a District uses EvalCamp with data about children under 13, the District (school) provides any consent required under the Children's Online Privacy Protection Act ("COPPA") on behalf of parents, consistent with FERPA and COPPA's school-authorization framework.
5.2 Texas and other state student-data-privacy laws
We comply with applicable state student-data-privacy laws, including:
- Texas Education Code §32.151 et seq. (Texas Student Privacy Act) and Texas HB 2087 — including prohibitions on using student data for targeted advertising, marketing based on academic performance, selling student data, or building commercial profiles;
- Texas Government Code Chapter 560, as applicable.
Districts may require EvalCamp to execute their preferred data-privacy agreement, including SDPC / Texas Student Privacy Alliance (TX-NDPA) standard agreements. As EvalCamp expands to additional states, we will comply with those states' student-data-privacy laws and update this Policy accordingly.
6. Data retention and deletion
- Service Data is retained for the term of the District's agreement and for no more than thirty (30) days after its termination.
- On termination or written request, we export Service Data to the District in a standard, machine-readable format (CSV) within fifteen (15) days, permanently delete it (including backups) within thirty (30) days, and provide written certification of destruction.
- Encrypted database backups are retained on a rolling 60-day cycle and then overwritten.
- Account & Website Data is retained for as long as needed to operate the account or pursue the relationship, and thereafter as required for legal, audit, or security purposes.
We retain no Service Data after the destruction period except as required by law.
7. Data security
We maintain administrative, technical, and physical safeguards including: encryption in transit (TLS/HTTPS); encryption of stored data at rest; secure authentication with hashed passwords; role-based access control configured by the District; restricted production access limited to authorized personnel; automated encrypted backups; and audit logging. We review our security practices periodically. No system is perfectly secure, but we work to protect information using industry-standard measures.
7.1 Breach notification
If we discover a breach of Service Data, we notify the affected District in writing within seventy-two (72) hours of discovery, cooperate in investigation and remediation, and comply with applicable breach-notification obligations under FERPA and Texas law. Notifications to individuals, where required, are coordinated with and generally made by the District.
8. Where your data is processed
EvalCamp stores and processes all student and school data (Service Data) in the United States. We do not offer the Service outside the United States. Certain service providers that handle only operational data — such as error logs and product-analytics events that do not contain student information — may process that limited data outside the United States.
9. Cookies and similar technologies
The EvalCamp application uses strictly necessary session and authentication cookies (including an optional "remember me" cookie) to keep users signed in and secure.
Our website and application use PostHog analytics technologies to understand how visitors and users interact with EvalCamp (for example, page views and feature usage) so we can improve the product. These do not process student data. We do not use advertising cookies or third-party tracking for behavioral advertising.
10. State consumer privacy rights (Account & Website Data)
For Account & Website Data (not student education records, which are governed by FERPA and your District), Texas residents may have rights under the Texas Data Privacy and Security Act (TDPSA) to access, correct, delete, or obtain a portable copy of their personal information, and to opt out of the "sale" of personal data or its use for "targeted advertising." We do not sell personal information or use it for targeted advertising. To exercise these rights, contact us using Section 13; we will verify and respond as required by law. Student education records are exempt from the TDPSA and are handled under FERPA through your District.
11. Your rights and choices
- Parents and students. Rights concerning a student's education records — including access, review, and correction — are exercised through the student's District, which controls that data. Please direct such requests to your District. EvalCamp will support the District in responding.
- District staff. You may update your profile information within the app or by contacting your District administrator. Deactivation and role changes are managed by your District.
- Prospects and website visitors. You may unsubscribe from marketing email using the link in any message, or contact us to access or delete your prospect data.
12. Changes to this Policy
We may update this Policy from time to time. We will revise the "Effective date" above and, for material changes affecting Service Data, notify Districts as required by our agreements.
13. Contact us
NetDev Studio, LLC (EvalCamp)
Austin, Texas
Email: [email protected]
Districts with data-privacy questions should also refer to their executed Data Privacy Agreement with EvalCamp.