Math Facts Pro Data Security and Privacy Plan
1. Introduction
This Data Security and Privacy Plan outlines how Math Facts Pro safeguards student data and ensures compliance with relevant privacy regulations as we provide targeted math fact fluency practice. We are committed to maintaining a secure and confidential environment for all users, especially students
2. Applicable laws and regulations
- The Family Educational Rights and Privacy Act (FERPA)
- The Children’s Online Privacy Protection Act (COPPA)
- The Protection of Pupil Rights Act (PPRA)
Relevant state student privacy laws (e.g., California’s SOPIPA and AB-1584)
3. Data collection, use, and disclosure
Data Minimization: Math Facts Pro collects and stores only the PII (Personally Identifiable Information) necessary for the functionality of our program, user security, and for teacher monitoring. All identifiable data is used solely for educational purposes. We do NOT handle or store any financial information (credit card processing is handled externally by PayPal), addresses, phone numbers, school/government issued student identification numbers, or other Sensitive PII.
- For teachers (or schools), we store
- Username
- Password
- Email address
- Report name, correspondence name
- Time zone.
- For students we store
- First and last name
- Password
- Grade
- Class
- Teacher/school username.
- For teachers (or schools), we store
Data Ownership: Account owners (Educational institutions, teachers, or parents) retain ownership of all student data shared with Math Facts Pro and associated with the respective accounts. Account owners can modify and delete student data at any time via their dashboard. If parents who are not the account owners want to change or delete student information, they need to contact the teacher or school (the account owner).
Prohibited Uses: Math Facts Pro will not use or disclose student/teacher/parent personally identifiable information (PII) for purposes other than the specified educational services. We will not monetize or sell student data to third parties or allow targeted advertising. In fact, we do not allow advertising of any kind. We will not share any personally identifiable data for commercial purposes.
4. Data security practices
- Encryption: Student data is protected through encryption both at rest and in transit, utilizing industry accepted standard encryption methods.
- Access Controls: Access to student data is strictly limited to authorized personnel with clearly defined user roles and permissions.
- Security Audits: Math Facts Pro conducts regular security audits to identify and address potential weaknesses in our systems.
- Framework: Math Facts Pro utilizes the NIST Cyber Security Framework. Continuous Monitoring: Monitoring systems track user activity and system performance so that we can detect and respond to potential security incidents.
Employee Training: Employees train on and adhere to data security and privacy industry best practices.
5. Incident response and recovery
Incident Response Plan: Math Facts Pro has an Incident Response Plan that outlines procedures for addressing security incidents, including data breaches.
Notification: In the event of a security incident or data breach, account holders, including educational institutions, will be notified within 72 hours.
Recovery: A disaster recovery plan is in place to minimize data loss and ensure service continuity in the event of an unforeseen incident. We will not disclose your email address or any other personally-identifiable information to anyone except employees and trusted third parties with whom we contract to assist us in the operation of MathFactsPro.com.
6. Data retention and destruction
Retention Policy: Student data is retained only as long as necessary for the purpose for which it was collected, as agreed upon with the educational institution. It will be deleted within 6 months after the contract expires, and it will be removed from backups within 10 days of deletion.
Deletion: Educational institutions have the right to request the deletion of student data at the conclusion of the contract term or when it is no longer needed.
Secure Destruction: When Math Facts Pro servers are replaced, AWS will securely destroy all data storage media per AWS policy. When your students log-in under your account, we collect performance data in order to best help them with becoming fluent in their basic math facts. We also use this data to improve the effectiveness and efficiency of Math Facts Pro. Additionally, we sometimes use this data in an anonymous and/or aggregate form for marketing purposes.
7. Vendor accountability
Data Processing Agreements (DPAs): Math Facts Pro enters into Data Processing Agreements (DPAs) or similar contracts with educational institutions outlining data privacy and security obligations.
Subcontractor Management: Math Facts Pro ensures that any subcontractors or third parties with access to student data adhere to the same stringent privacy and security standards outlined in this plan.
List of subcontractors: CrewRed OÜ in Estonia
If there are any questions regarding this privacy policy you may contact us via our contact page.
Please also see our Terms of Service.
Last modified: September 1, 2025