Skip to content

Security & Compliance

Privacy & Data Protection

We collect as little as the work requires, protect what we hold, and keep customer data under customer control. Education technology contexts receive additional care because student information is involved.

Practices

How information is protected

Privacy Principles

Personal information is collected for a stated purpose, used only for that purpose, and protected commensurate with its sensitivity.

  • Purpose limitation
  • Transparency about what is collected
  • Proportionate protection by sensitivity
  • Accountability for downstream use

Data Minimization

Systems are designed to collect the least information necessary. Fields that are not required are not requested.

  • Least-data collection by design
  • No unnecessary sensitive fields
  • Aggregation preferred over identification
  • Public forms explicitly warn against sensitive submissions

Retention

Information is retained only as long as needed for the stated purpose or as required by contract or law, then disposed of securely.

  • Defined retention periods
  • Secure disposal and media sanitization
  • Backup retention aligned to policy
  • Contractual retention honored

Encryption

Personal information is encrypted in transit and at rest, with access limited to those who need it for delivery.

  • TLS in transit
  • Encryption at rest
  • Role-restricted access
  • Access logging for sensitive records

Customer Ownership

Customer and agency data belongs to the customer. It is not sold, and it is not used for unrelated purposes.

  • Customer retains ownership of their data
  • No sale of customer or agency data
  • No unrelated secondary use
  • Return or deletion at end of engagement

Access Requests

Requests to access personal information are handled through the secure contact workflow with identity verification appropriate to the request.

  • Requests received through the contact workflow
  • Identity verification before disclosure
  • Defined acknowledgement timeline
  • Contractual and legal obligations respected

Deletion Requests

Deletion requests are honored where no overriding contractual, legal, or records-retention obligation applies.

  • Deletion honored where permitted
  • Explanation provided where retention is required
  • Propagation to backups on the retention cycle
  • Confirmation on completion

Related

Website privacy notice

This page describes program practices. The notice covering information submitted through this website is published separately.

Read the Privacy Policy for details on website data collection, use, and retention.

IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.

Requesting security documentation?

Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.