Special education evaluation data, protected by a signed agreement first
EvalCamp is evaluation management for Texas special education teams, from referral to the initial ARD. Your district signs its data privacy agreement with us before any student data is entered. This page covers what we sign, where the data lives, who can see it, and every company that touches it.
Signed DPA before any student data
The TX-NDPA or your district's own agreement, signed as written.
FERPA school-official basis
We perform a service your district would otherwise do itself, under your direction.
Encrypted in transit and at rest, hosted in the US
Every connection uses TLS, and the database is encrypted at rest. Student data is stored and processed in the United States.
Microsoft and Google sign-in
Staff sign in with the district Microsoft or Google account they already use.
Send-only mailbox permission
EvalCamp can send from your email address and can never read your mail.
No selling, no ads, no AI on student data
Student data is used only to run the service for your district.
No student data until the DPA is signed
A signed agreement before any student data. Walkthroughs and setup use a demo district with made-up students. Real student records go in only after your district and EvalCamp have both signed.
Read our Texas DPA (PDF)-
1
The TX-NDPA, signed as written
Most Texas districts use the Texas Student Privacy Alliance's standard agreement. We sign it with the Texas terms and no custom riders. If your district adopts terms through Exhibit E, we work from that.
-
2
Or your district's own DPA
If your district has its own data privacy agreement, send it over and we will work from your paper.
-
3
Or ours, ready to sign
Our Texas DPA covers FERPA, Texas Education Code §32.151, data ownership, retention and destruction, breach notice, and subprocessors. It is public, so your counsel can read it before the first call.
Your district owns the data. We hold it for you
EvalCamp stores what your team needs to run evaluations: student name, ID, date of birth, campus, and grade level, parent or guardian name, email, phone, and preferred language, referral and consent dates, deadlines, eligibility, assignments, and form tracking. For staff, name, work email, and role. No academic records, assessment content, protocols, or IEP documents. It is used for nothing else.
FERPA school official
EvalCamp acts as a school official with a legitimate educational interest under FERPA (34 CFR §99.31(a)(1)(i)). We stay under your district's direct control for how education records are used and kept, and we do not re-disclose them without your written authorization, except as required by law or through the subprocessors listed below.
Encrypted in transit and at rest
Every connection between your staff and EvalCamp, and between EvalCamp and its database, is encrypted with TLS. The database is encrypted at rest. Passwords are stored hashed, and mailbox tokens are encrypted again by the application.
Hosted in the United States
Student data is stored and processed in US data centers, with daily automated database backups. Access to production systems is limited to authorized EvalCamp staff.
Role-based access
Your district decides who sees what. Four roles:
- District admin: every evaluation in the district, plus settings and reporting.
- Campus admin: the evaluations on the campuses they manage.
- Team member: the evaluations they are assigned to and their campuses.
- Contractor: read-only, scoped to their assignments and campuses.
Students and parents never log in.
No file uploads
EvalCamp has no file-upload feature. Protocols, reports, and records stay in your district's systems. When your team links a student's records folder, EvalCamp stores only the link.
An activity log on every evaluation
Each evaluation keeps its own history of what changed and when, so a director can see how a case moved without asking around.
Microsoft or Google sign-in, and mail sent from your own email address
Staff sign in through Microsoft Entra ID or Google Workspace with the district account they already have. IT approves the permissions below with one admin-consent click, and your MFA policy applies because sign-in happens in your own tenant.
When an evaluator connects their Microsoft 365 or Google Workspace mailbox, parent forms and notices go out from their own district email address, so families recognize the sender and replies land in the right inbox.
Google Workspace districts get the equivalent send-only Gmail permission.
EvalCamp can send from your email address and can never read your mail. The connection is optional and made one user at a time.
Used for your district, and nothing else
Each of these is an obligation written into the DPA your district signs.
No selling, no ads, no profiles
We never sell or rent student data, never use it for advertising, and never build commercial profiles of students or mine the data for any purpose your district has not authorized.
No AI on student data today
If we add assistive features later they will be off by default, per-district opt-in, and covered by your DPA.
Returned or deleted when the agreement ends
On termination, or on your written request, we return your district's data and delete it on the timeline in your DPA, then certify the deletion in writing. Under our Texas DPA: data returned within 15 days of the request, deleted from production within 30 days of termination, backups purged within 60 days, and the certificate of destruction within 10 business days after that.
The questions we answer on every approval
Will you sign the TX-NDPA?+
Yes. We sign the Texas Student Privacy Alliance agreement as written, with the Texas terms and no custom riders. If your district adopts terms through Exhibit E, or uses its own DPA instead, we work from that. Either way it is signed before any student data is entered.
What do the Microsoft and Google permissions let EvalCamp do?+
Two things. Microsoft Entra ID or Google Workspace single sign-on lets staff sign in with their district account. The optional mailbox connection requests Microsoft Graph Mail.Send, or the equivalent send-only Gmail permission for Google Workspace districts, plus the standard sign-in scopes (openid, profile, email, offline access), which lets EvalCamp send email from the connected user's address. It cannot read, search, or delete mail, and it cannot see contacts, calendars, or files.
Where is our data hosted?+
In the United States. Student data is stored and processed in US data centers, with daily automated database backups. A few operational services that never receive student data, such as error monitoring and analytics, may process their limited data elsewhere.
Do you use AI on our student data?+
No AI on student data today. If we add assistive features later they will be off by default, per-district opt-in, and covered by your DPA.
Who at EvalCamp can see our data?+
Only authorized EvalCamp staff with production access, and only to run the service or to help your team when you ask for support. Inside the app, your district's roles decide what each of your own users can see.
Do we have to connect EvalCamp to our SIS or IEP system?+
No. EvalCamp runs alongside your IEP system and does not connect to it or to your SIS. There is nothing to install and no data feed to approve. We load your open evaluations from the trackers you use today.
Do you need rostering, a SIS export, or DNS changes?+
No. Staff are invited by email, students are entered when a referral is created, and mail goes out through Microsoft or Google under your existing records.
What happens to our data if we stop using EvalCamp?+
We return it and delete it on the timeline in your DPA, including backups, and certify the deletion in writing. Your IEP system stays your record of compliance throughout, so nothing official lives only in EvalCamp.
Send us your questionnaire. We answer in writing
Vendor security questionnaires, DPA redlines, and IT review calls all go to the same place.
See also our Privacy Policy and Terms of Service.