Legal & compliance · Updated v3.0 — August 2026

Information Security Policy (Data Security & Privacy Plan)

AskElira’s Data Security and Privacy Plan under 8 NYCRR § 121.6 — the administrative, technical, and physical safeguards behind the DPA and §2-d Addendum.

This PDF is Exhibit A of the NY §2-d Addendum itself — the same pages, sliced out so your IT or data-privacy reviewer can read the §121.6 plan without the whole packet. It is not a standalone document and carries no version of its own: the version above is the Addendum’s. The packet says the Plan “exists once, in full, as Exhibit A” with no separate standalone version, and MSA §14.2 forbids publishing one, so if this page and the executed Addendum ever differ, the Addendum controls and this copy is the error.

What it is

The Data Security and Privacy Plan (8 NYCRR § 121.6) attached to each school’s DPA — mapped to NY Ed Law §2-d, 8 NYCRR Part 121, FERPA, and the NIST Cybersecurity Framework.

Safeguards

Encryption in transit and at rest, envelope-encrypted school credentials, least-privilege access, quiet-hour and consent gates enforced in code, and 24/7 automated security monitoring with a 48-hour school-notification standard.

People controls

Privacy/security training before anyone touches Student Data and annually thereafter, background checks, and a named security lead and data-privacy contact.

Vendors

Every subprocessor with access to Student Data is bound in writing to equivalent encryption, breach-notice, and retention/deletion obligations; schools get 30 days’ notice before changes.

Insurance & risk transfer

Beyond the controls, AskElira carries Cyber Liability insurance (United Specialty Insurance Company, A.M. Best A-rated) with $1M privacy, privacy-regulatory, network-security, and breach-response limits, plus $1M General and $1M Professional (Tech E&O) liability — so a security or privacy incident is backed by real coverage, not just a promise. See the Insurance & Liability Coverage summary.

Honest scope

Controls are sized to a small company and reviewed as school volume grows; open items (e.g. SOC 2 timing) are flagged in the document itself rather than papered over.

Want the full document?
Download the complete PDF, or have our team walk your legal/data-privacy staff through it.
Download full PDFBook a walkthrough