New York Student Privacy (Education Law §2-d)
Last Updated: August 16, 2026
This page explains how DAILE Learning Inc. handles student, teacher, and principal data under New York Education Law §2-d and Part 121 of the Commissioner’s Regulations. It is for parents, eligible students, and New York schools.
This page is informational. It is not the district’s Parents’ Bill of Rights, and it is not a Data Privacy Agreement (DPA). Each New York educational agency that shares personally identifiable information (PII) with DAILE must have a written contract or DPA that includes the Parents’ Bill of Rights and the supplemental information required by law. That contract controls if it conflicts with this page.
Related pages: Privacy Policy · COPPA
1. Who This Applies To
Education Law §2-d protects PII from student records, and certain teacher or principal evaluation data, held by New York educational agencies (school districts, BOCES, and covered schools).
When a New York school uses DAILE, DAILE is a third-party contractor: we receive student data (and, if applicable, teacher data) to provide the contracted educational service.
FERPA still applies. Parents inspect and correct education records through the school, not by treating DAILE as the records custodian.
2. Parents’ Bill of Rights Themes
New York requires each educational agency to publish a Parents’ Bill of Rights. In plain language, those rights include:
- A student’s PII cannot be sold or released for commercial purposes
- Parents may inspect and review their child’s education records (through the school, generally within 45 days)
- PII must be protected with safeguards such as encryption, access controls, and passwords
- Parents may complain about a possible breach or unauthorized disclosure
- The State publishes a list of data elements it collects; ask the school or NYSED how to obtain it
DAILE’s role is to help the school honor those rights for data that lives in our product.
3. What DAILE Collects
We collect the minimum needed to roster students and deliver lessons:
Student data
- Email address (sign-in username)
- Name, when provided
- Grade level (K–5)
- Optional school student ID
- Class membership
- Lesson activity (progress, answers, scores, time spent)
Teacher and school admin data
- Name and school email
- Classes they teach or administer
- Assignment and progress summaries for their students
We do not collect Social Security numbers, biometric identifiers, or student payment cards.
4. Exclusive Purposes
We use this data only to:
- Provide K–5 lessons the school has licensed
- Let authorized teachers and admins roster classes and view educational progress
- Operate, secure, and improve the educational service
We do not sell student or teacher PII. We do not use it for marketing, targeted advertising, or commercial profiling.
5. Where Data Is Stored and How It Is Protected
Student and teacher data are stored in a cloud database and application host in the United States (currently Supabase for accounts and records, and Vercel for the website). We do not publish exact facility addresses in order to protect the security of that infrastructure.
Safeguards include:
- Encryption in transit (TLS) and at rest for database storage
- Invite-only student accounts (no public student sign-up)
- Role-based access in the product (student, teacher, school admin)
- Hashed passwords and hashed, expiring invite PINs
- Separate development and production databases so demo accounts are not mixed with school data
6. Subcontractors
Limited service providers help us run the platform (hosting, database, transactional email, and school billing). They may access PII only as needed to provide that service. The same confidentiality rules apply to them.
School billing (Stripe) uses organization and adult contact information, not student lesson records.
If a school later connects Clever or ClassLink for rostering, that partner is a subcontractor for rostering only and must be named in the district’s DPA.
7. Accuracy and Parent Requests
Parents, eligible students, teachers, and principals challenge the accuracy of education records with the school. The school may ask DAILE to correct or delete data in our systems.
You may also email info@dailelearning.com with the subject line Data Privacy Request. We will work with the educational agency. We do not respond independently to parent record requests in a way that would bypass the school’s FERPA process.
8. Retention, Return, and Deletion
We keep PII only while the school’s contract is in effect, or as required by law. When the agreement expires or the school directs us to, we will return data in a reasonable format and/or delete it. Upon a school’s deletion request or contract end, we delete student data within 60 days and confirm in writing.
Exact return and destruction terms are set in the district DPA.
9. Breaches
If we discover a breach or unauthorized release of PII, we will notify the educational agency in the most expedient way possible and within seven calendar days, as Education Law §2-d requires of third-party contractors. The school then notifies parents and NYSED on the timelines that apply to educational agencies.
10. Complaints
Start with the school’s Data Protection Officer. You may also contact:
DAILE Learning Inc.
Email: info@dailelearning.com
Subject line: Education Law 2-d Complaint
New York State Education Department Privacy Office: nysed.gov/data-privacy-security
11. The District Contract Controls
New York schools should execute a §2-d–compliant DPA (NYSED publishes a model) before sharing student PII with DAILE. Click-wrap website terms do not replace that contract. This page is meant to help parents and schools understand our practices in one place.