StepUp
Legal

Privacy Policy

Last updated 1 January 2026. This is a template policy provided for evaluation and must be reviewed by your board's legal counsel before deployment.

1. Who we are

StepUp provides career-pathway assessment and guidance analytics software to secondary schools, school boards and districts. When a school licenses StepUp, the school (or its board) is the data controller and StepUp acts as a data processor / service provider on the school's documented instructions.

2. Information we collect

Account information (name, school email, role); school and board affiliation; academic records supplied by the school (courses, grades, GPA); assessment responses and scores (Holland RIASEC and related inventories); career pathway selections and milestone progress; counselor notes and intervention records; and technical logs required to operate and secure the service.

3. How we use information

To generate career recommendations and roadmaps, to surface risk indicators to authorised guidance staff, to provide aggregate reporting to school and board administrators, and to maintain the security, integrity and availability of the platform. We do not sell personal information, and we do not use student data for advertising or profiling outside the educational purpose.

4. Legal bases and jurisdictions

Depending on where the school operates, processing is grounded in the school's public-interest / educational mandate, contractual necessity, or consent obtained by the school. StepUp is designed to support obligations under PIPEDA and provincial acts such as FIPPA/MFIPPA in Canada, FERPA in the United States, and the GDPR in the EEA/UK.

5. Data residency and retention

Data is stored in managed cloud infrastructure with encryption in transit and at rest. Retention follows the licensing school's records schedule; by default, student records are retained for the duration of enrolment plus the period the board requires, then deleted or irreversibly anonymised. Schools may request export or deletion at any time.

6. Access controls

Access is enforced at the database level with row-level security. Students can only read and write their own records. Counselors can only read records for students at the school they have been verified against — counselor access is granted through an administrator-provisioned invitation, never self-declared. All privileged actions are written to an immutable audit log.

7. Sub-processors

We use a small number of infrastructure sub-processors for hosting, database, authentication and email delivery. A current list is provided to licensed schools on request and updated before any material change.

8. Your rights

Students, parents/guardians and staff may request access to, correction of, or deletion of personal information. Requests should be directed to the school's privacy officer, who will coordinate with StepUp. Where StepUp is the controller (for example, for direct staff accounts), requests can be sent to us directly.

9. Children and minors

StepUp is used by students aged 13 and above under a school's authority. We do not knowingly collect information from students outside a licensed school relationship, and we rely on the school to obtain any parental notice or consent its jurisdiction requires.

10. Changes and contact

We will notify licensed schools in advance of material changes to this policy. Questions can be sent through our contact page.

Questions about this policy? Contact us.