Last updated: July 23, 2026
Celerity is built for education data workflows. The controls described here support a customer's privacy program; they are not a blanket legal certification. Applicability depends on the deployment, data, institution policies, and executed agreements.
A district may designate a service provider as a school official only when its facts, policies, and agreement satisfy FERPA. The customer and Celerity document the authorized purpose, access, retention, and deletion terms during onboarding.
The pilot is intended for institution-managed use, not direct consumer enrollment by children. The institution determines whether COPPA applies and documents the appropriate consent and data-minimization requirements before student data is introduced.
State obligations vary and are evaluated with the customer before a deployment processes student data. Celerity does not publish a blanket state-law certification.
| State | Law | Status |
|---|---|---|
| Texas | HB 2087 (Student Data Privacy) | Customer review required |
| California | SOPIPA (Student Online Personal Information Protection Act) | Customer review required |
| New York | Education Law 2-d | Customer review required |
| Colorado | Student Data Transparency and Security Act | Customer review required |
| Illinois | SOPPA (Student Online Personal Protection Act) | Customer review required |
| Connecticut | PA 16-189 (Student Data Privacy) | Customer review required |
Additional states will be added as Celerity enters new markets. Contact us if your state has specific requirements.
Customer-specific data processing terms are reviewed privately during onboarding. Celerity does not publish DPA terms or imply that one agreement resolves every institution's requirements.
Student data flows through the Celerity platform as follows:
District SIS / Data Source
|
v
Keycloak (Authentication)
OIDC / SAML 2.0 — identity verified
|
v
PostgREST API (Authorization)
JWT validated — tenant scope enforced
|
v
Tenant Schema (Isolation)
Schema-per-tenant + row-level security
|
v
Amazon RDS (Storage)
AES-256 at rest — TLS 1.2+ in transit
US-only data residencyEach tenant's data is isolated at the database schema level. Cross-tenant access is architecturally prevented by row-level security policies enforced at every query.
| Classification | Examples | Handling |
|---|---|---|
| Education Records (FERPA) | Grades, enrollment, assessments, IEP data | Encrypted, tenant-isolated, access logged, no commercial use |
| Personally Identifiable Information | Student names, IDs, dates of birth, contact info | Encrypted, access restricted to authorized roles, never in logs |
| Directory Information | School name, grade level, enrollment status | Treated as PII unless district designates otherwise |
Celerity will never:
Under FERPA, parents and eligible students have the right to inspect and review education records. Celerity supports this process:
The following compliance documents are available. Per-customer agreements (DPA, MSA) are provided during onboarding and are accessible through the customer portal.
| Document | Access |
|---|---|
| Privacy Policy | Public |
| Security Practices | Public |
| Acceptable Use Policy | Public |
| Responsible Disclosure Policy | Public |
| Data Processing Agreement (DPA) | Customer portal |
| Pilot Platform Agreement | Customer portal (Pilot phase) |
| Production Enablement Agreement (MSA) | Customer portal (Production phase) |
| Service Level Agreement (SLA) | Customer portal |
Compliance inquiries: privacy@celerityedu.com
Security inquiries: security@celerityedu.com
