Summit School / Summit Children’s Residence Center

Data Privacy & Security

How we collect, protect, and share the personal information of our students, families, and staff — and what rights you have.

Summit is an approved private school for students with disabilities and an “educational agency” under New York Education Law § 2-d. We follow the same data privacy and security rules as public school districts, along with FERPA and IDEA. Everything on this page is published under 8 NYCRR Part 121.

Education Law § 2-d

Parents’ Bill of Rights for Data Privacy and Security

New York requires every educational agency to publish this Bill of Rights and attach it to every contract with a company that receives student information. In summary:

  1. A student’s personally identifiable information (PII) cannot be sold or released for any commercial purpose.
  2. Parents have the right to inspect and review the complete contents of their child’s education record. We respond within 45 days, and before any IEP meeting.
  3. Parents may request correction of records they believe are inaccurate or misleading, with a right to a hearing if we decline.
  4. State and federal laws protect the confidentiality of PII, and safeguards such as encryption, firewalls, and password protection must be in place when data is stored or transferred.
  5. A complete list of student data elements collected by New York State is available at nysed.gov/data-privacy-security/student-data-inventory.
  6. Parents have the right to have complaints about possible breaches of student data addressed — see File a complaint.
  7. Parents have the right to be notified if a breach or unauthorized release of their child’s PII occurs.
  8. Summit staff who handle PII receive annual training on the laws, policies, and safeguards that protect it.
  9. Every contract with a vendor that receives student data requires confidentiality protections consistent with state and federal law.
8 NYCRR § 121.3(c)

Vendors and software that receive student information

Before any company receives student information, it must sign a Data Privacy Agreement that includes our Parents’ Bill of Rights and the protections required by Education Law § 2-d. Every vendor below is bound to these terms:

0student records sold or used for marketing — ever
7 daysmaximum for a vendor to report a breach to Summit
AES-256encryption at rest; TLS in transit
NIST CSFthe security standard every vendor must align to

Open any vendor for the supplemental information the regulation requires: (A) purpose, (B) subcontractors, (C) contract term and data disposition, (D) challenging accuracy, (E) storage location, (F) security and encryption.

PowerSchool SIS student enrollment, scheduling, attendance, gradebook, report cards, IEP document attachments, and district reporting
Contractor
PowerSchool Group LLC, 150 Parkshore Drive, Folsom, CA 95630
Data involved
Student name, local and NYSSIS/district identification numbers, date of birth, gender, address, parent/guardian names and contact information, placing district and program, enrollment dates, class schedules, attendance, grades and assessments, behavior incidents where recorded, IEP documents and classification, and health/emergency information where entered; staff names and school email addresses
Who it covers
All enrolled students; teaching and administrative staff
Agreement
Annual subscription, renewed each school year; Data Privacy Agreement on file

AExclusive purposes for which the data is used

Student data is used solely to provide student information system services to Summit: maintaining enrollment records, scheduling, attendance, the PowerTeacher Pro gradebook, report cards, IEP and related document storage, parent/guardian contacts, and state and district reporting for students enrolled at Summit. PowerSchool may use PII only to provide, support, and secure the contracted services. Data is not used for any other purpose, including marketing, advertising, profiling, or product development.

BSubcontractors and further disclosure

PowerSchool may share data with its cloud hosting and infrastructure subcontractors solely as necessary to deliver the contracted service. Every such subcontractor is contractually bound to the same data protection and confidentiality obligations imposed on PowerSchool under its agreement with Summit, including Education Law § 2-d, Part 121, and FERPA requirements, restrictions on use and disclosure, and required security safeguards. PowerSchool discloses its subprocessors in its Data Privacy Agreement.

CContract term and what happens to data at expiration

The agreement is an annual subscription renewed each school year. Upon expiration or termination, PowerSchool returns Summit’s data in a usable export format on request and securely destroys all student data in its possession, including backups, within the period specified in the Data Privacy Agreement, except where retention is required by law, and provides written confirmation of destruction on request.

DHow to challenge the accuracy of data

A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.

EWhere the data is stored

Student data is stored in PowerSchool’s cloud environment on Amazon Web Services data centers located in the United States.

FSecurity protections, including encryption

Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Access is restricted to authorized personnel through role-based access controls and multi-factor authentication. PowerSchool maintains a security program aligned with the NIST Cybersecurity Framework, undergoes independent SOC 2 audits, and maintains a documented incident response plan. On Summit’s side, staff access is limited by security group to those with a legitimate educational interest, and multi-factor authentication is enforced for staff logins. PowerSchool must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.

Google Workspace for Education Gmail, Drive, Docs/Sheets/Slides, Classroom, Calendar, Meet, and Chat for students and staff
Contractor
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043
Data involved
Student and staff names, school-issued email addresses and usernames, organizational unit and grade grouping, and content users create or store in the services (documents, assignments, messages, files), which may include education records
Who it covers
Students with Summit accounts; all staff
Agreement
Ongoing subscription under the Google Workspace for Education Terms of Service; Data Processing Amendment accepted

AExclusive purposes for which the data is used

Data is used solely to provide school-managed email, document creation and storage, classroom collaboration, and communication tools for students and staff. Under the Google Workspace for Education Terms of Service and Data Processing Amendment, Google processes Summit customer data only to provide the core services, does not serve advertising in the core services, and does not use core-service data for advertising purposes or to build student profiles.

BSubcontractors and further disclosure

Google’s agreement requires that any subprocessor engaged to process customer data be bound by written obligations providing at least the same level of data protection. Google publishes its list of Google Workspace subprocessors and provides notice of changes. Summit administrators control which additional Google services are enabled for student accounts and restrict sharing of data outside the Summit domain.

CContract term and what happens to data at expiration

The subscription is ongoing and renews annually; Summit may terminate at any time and may export all customer data at any time. Upon termination, Google deletes customer data from its systems within the period specified in its Data Processing Amendment (generally within 180 days of deletion by the customer or termination), including from backups.

DHow to challenge the accuracy of data

A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.

EWhere the data is stored

Data is stored in Google-owned and operated data centers, which are located in the United States and other countries, subject to the protections of the Data Processing Amendment.

FSecurity protections, including encryption

Data is encrypted in transit (TLS) between users and Google and between Google data centers, and at rest using AES-256 or stronger. Google Workspace maintains ISO/IEC 27001, 27017, and 27018 certifications and SOC 2/SOC 3 attestations and a security program aligned with the NIST Cybersecurity Framework. Summit enforces 2-step verification for staff, restricts external sharing, limits student accounts to approved services, and manages all accounts through the Admin console. Google must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.

Orah attendance and roll checks, leave and sign-in/out, pastoral notes, and parent/guardian communication
Contractor
Boardingware International Ltd., trading as Orah (Auckland, New Zealand)
Data involved
Student name, photo, date of birth, grade and residence assignment, attendance and location status, leave requests, pastoral and residential notes, medical alerts entered by staff, and parent/guardian names and contact details; staff names and roles
Who it covers
Residential students; residential and supervisory staff; parents/guardians
Agreement
Annual subscription, renewed each school year; Data Privacy Agreement on file

AExclusive purposes for which the data is used

Data is used solely to provide residential student management services to Summit: tracking student attendance, location, and leave; recording pastoral and residential notes; and communicating with parents/guardians and staff about student welfare. Orah may use PII only to provide, support, and secure the contracted service and for no other purpose, including marketing, advertising, or profiling.

BSubcontractors and further disclosure

Orah shares data with its cloud hosting provider (Amazon Web Services) and other subprocessors solely as necessary to deliver the contracted service. Every such subcontractor is contractually bound to the same data protection and confidentiality obligations imposed on Orah under its agreement with Summit. Orah discloses its subprocessors in its privacy documentation.

CContract term and what happens to data at expiration

The agreement is an annual subscription renewed each school year. Upon expiration or termination, Orah provides an export of Summit’s data on request and securely destroys all student data in its possession, including backups, within the period specified in the Data Privacy Agreement, except where retention is required by law, and confirms destruction in writing on request.

DHow to challenge the accuracy of data

A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.

EWhere the data is stored

Student data is stored on Amazon Web Services infrastructure in the United States hosting region selected for Summit’s account.

FSecurity protections, including encryption

Data is encrypted in transit (TLS, with automatic redirection to secure connections) and at rest on Orah’s servers. Orah holds ISO/IEC 27001 and ISO/IEC 27018 certifications, is a Student Privacy Pledge signatory, and maintains 24/7 monitoring, automated daily backups, granular role-based access controls, and an incident response program. Summit limits Orah access to residential and supervisory staff with a legitimate need. Orah must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.

Airtable internal administrative tracking for admissions, enrollment, and program records
Contractor
Airtable, Inc., 799 Market Street, San Francisco, CA 94103
Data involved
Student name, identification number, grade, placing district, program, key dates, parent/guardian contact information, and administrative notes, limited to the fields needed for each tracking base
Who it covers
Students in the tracking bases; staff users
Agreement
Annual subscription, renewed each school year; Airtable Data Processing Addendum accepted

AExclusive purposes for which the data is used

Data is used solely to support Summit’s internal administrative workflows. Airtable, as the platform provider, processes Summit’s content only to provide, support, and secure the service and for no other purpose, including marketing, advertising, or training of models on Summit content; Summit keeps Airtable’s AI features disabled for bases containing student data.

BSubcontractors and further disclosure

Airtable engages subprocessors, including its cloud hosting provider (Amazon Web Services), solely as necessary to deliver the service. Airtable’s Data Processing Addendum requires subprocessors to be bound by written obligations at least as protective as Airtable’s own, and Airtable publishes its subprocessor list with notice of changes.

CContract term and what happens to data at expiration

The subscription is annual and renews each school year. Summit may export all bases at any time. Upon termination, Airtable deletes customer content within the period specified in its Data Processing Addendum, including from backups.

DHow to challenge the accuracy of data

A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.

EWhere the data is stored

Data is stored in Airtable’s production environment hosted on Amazon Web Services data centers located in the United States.

FSecurity protections, including encryption

Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Airtable maintains SOC 2 Type II and ISO/IEC 27001 attestations, role-based permissions, two-factor authentication, and an incident response program. Summit restricts base and workspace sharing to authorized staff and does not use public share links for bases containing PII. Airtable must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.

Intuit QuickBooks Online accounting, tuition and service billing to placing districts and agencies, accounts payable, and payroll
Contractor
Intuit Inc., 2700 Coast Avenue, Mountain View, CA 94043
Data involved
Student data limited to what is needed to invoice districts for tuition and services: student name, placing school district or agency, program or placement type, dates of service, and billed amounts. Staff and vendor data: employee names, addresses, Social Security numbers, bank account details, and compensation for payroll.
Who it covers
All enrolled students (billing records only); employees; vendors; placing districts
Agreement
Ongoing subscription; Intuit business-customer terms and Data Processing Agreement accepted

AExclusive purposes for which the data is used

Data is used solely to provide accounting, invoicing, and payroll services to Summit, including preparing and tracking tuition and service invoices to placing school districts and agencies for each enrolled student. Intuit may use data only to provide, support, and secure the contracted services and as described in its business-customer terms, and not for marketing to students or parents or for building profiles. Summit limits student data in QuickBooks to the minimum needed for billing — no grades, IEP, health, or behavioral information is entered.

BSubcontractors and further disclosure

Intuit engages subprocessors (hosting, payment processing, payroll tax filing) solely as necessary to deliver the services and requires them to maintain security and confidentiality obligations consistent with Intuit’s own. Intuit describes its service providers in its privacy documentation.

CContract term and what happens to data at expiration

The subscription is ongoing and renews automatically. Summit may export its company file and reports at any time. Upon cancellation, Intuit retains read-only access to data for one year, after which data is deleted in accordance with Intuit’s retention policy, except where retention is required by law (for example, tax and payroll records). Summit retains billing records for the period required by its records retention schedule and audit requirements.

DHow to challenge the accuracy of data

A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.

EWhere the data is stored

Data is stored in Intuit-managed data centers and cloud infrastructure located in the United States.

FSecurity protections, including encryption

Data is encrypted in transit (TLS) and at rest (AES-256). Intuit maintains SOC 1 and SOC 2 attestations, multi-factor authentication, role-based user permissions, and an incident response program. Summit restricts QuickBooks access to business-office staff, enforces multi-factor authentication, and limits student fields to name, district, program, and service dates. Because staff Social Security and bank account numbers are “private information” under the NY SHIELD Act, Summit treats any breach as reportable under GBL § 899-aa as well as Education Law § 2-d. Intuit must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.

Adobe Creative Cloud creative and document tools for students and staff, managed through the Adobe Admin Console
Contractor
Adobe Inc., 345 Park Avenue, San Jose, CA 95110
Data involved
Student and staff names, school email addresses, and content created or stored in Adobe cloud services (documents, images, projects). Student accounts are provisioned by Summit as managed education accounts, not personal Adobe IDs.
Who it covers
Students in creative arts and technology programs; staff
Agreement
Annual education license, renewed each school year; Adobe Data Processing Agreement accepted

AExclusive purposes for which the data is used

Data is used solely to provision and operate licensed Adobe applications and cloud storage for Summit users. Under the Adobe education terms and Data Processing Agreement, Adobe processes customer content only to provide the services; content-analysis and product-improvement features are disabled for K-12 education accounts, and Adobe does not use K-12 student data for advertising or profiling.

BSubcontractors and further disclosure

Adobe uses subprocessors, including cloud hosting providers, solely as necessary to deliver the services, and requires them by written agreement to protect personal data consistent with Adobe’s DPA. Adobe publishes its subprocessor list and provides notice of changes.

CContract term and what happens to data at expiration

The license is annual and renews each school year. Summit administrators may remove users and export content at any time. Upon termination, Adobe deletes customer content within the period specified in its Data Processing Agreement, including from backups.

DHow to challenge the accuracy of data

A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.

EWhere the data is stored

Data is stored in Adobe cloud infrastructure on data centers located in the United States.

FSecurity protections, including encryption

Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Adobe maintains SOC 2 Type II and ISO/IEC 27001 certifications under the Adobe Common Controls Framework and supports single sign-on through Summit’s identity provider. Summit provisions students only with managed education accounts, restricts sharing features, and removes accounts at withdrawal. Adobe must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.

CENTEGIX CrisisAlert wearable staff alert badges, incident alerting, and campus safety platform
Contractor
CENTEGIX, LLC, Atlanta, Georgia
Data involved
Staff names, roles, badge assignments, and location during alerts; incident records, which may reference a student’s name when an alert concerns a specific student
Who it covers
Staff; students only as referenced in incident records
Agreement
Annual subscription, renewed each school year; Data Privacy Agreement on file

AExclusive purposes for which the data is used

Data is used solely to operate Summit’s staff alert and incident response system: issuing and locating alerts, notifying responders, and maintaining incident records. CENTEGIX may use PII only to provide, support, and secure the service and for no other purpose, including marketing.

BSubcontractors and further disclosure

CENTEGIX uses cloud hosting (Amazon Web Services) and notification subcontractors solely as necessary to deliver the service and requires them by written agreement to maintain confidentiality and security obligations consistent with its own.

CContract term and what happens to data at expiration

The subscription is annual and renews each school year. Upon termination, CENTEGIX deletes customer data within the period specified in the Data Privacy Agreement, except where retention is required by law, and confirms destruction on request.

DHow to challenge the accuracy of data

A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.

EWhere the data is stored

Data is stored in CENTEGIX’s cloud environment hosted on Amazon Web Services data centers located in the United States.

FSecurity protections, including encryption

Data is encrypted in transit (TLS) and at rest (AES-256). Access is restricted through role-based administrator permissions and multi-factor authentication. CENTEGIX maintains SOC 2 Type II attestation and an incident response program. Summit instructs staff to record student names in incident records only when necessary. CENTEGIX must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.

Staff-only systems. Microsoft 365 (staff email, files, and identity), Brivo (door access), Singlewire InformaCast (emergency notification), and monday.com (IT and facilities requests) are used by staff and do not hold student records. Students do not have accounts in these systems. Their supplemental information sheets are kept on file and are available from the Data Protection Officer on request.
Federal law

Your rights under FERPA and IDEA

The Family Educational Rights and Privacy Act gives parents and eligible students (18 or older) the right to inspect and review education records, to request amendment of records that are inaccurate or misleading, to consent to most disclosures of personally identifiable information, and to file a complaint with the U.S. Department of Education. IDEA adds protections specific to students with disabilities, including the right to a list of the types and locations of records we keep.

We send our FERPA annual notice to families each September and post it here.

Two schools, two sets of records.

Summit students are placed by their home school district’s Committee on Special Education. Summit keeps records for the services provided here; the placing district keeps the CSE and IEP record. You can exercise your FERPA rights with either of us, and we coordinate on requests.

8 NYCRR § 121.4

Report a concern or file a complaint

Parents, eligible students, staff, and others may file a complaint about a possible breach or unauthorized release of personal information, or about how Summit or one of its vendors is handling it.

What happens after you file

  1. We acknowledge your complaint promptly and open an investigation led by the Data Protection Officer.
  2. We take immediate steps to protect any affected information.
  3. We send you written findings within 60 calendar days. If we need more time, we tell you why and when to expect our response.
  4. If a breach is confirmed, we notify affected families and, where applicable, the placing school district.

File a complaint by email

You may also file directly with the New York State Education Department: online form, privacy@nysed.gov, or Chief Privacy Officer, NYSED, 89 Washington Avenue, Albany, NY 12234.

8 NYCRR § 121.10

If a breach happens

If student or staff personal information is accessed or released without authorization, Summit notifies affected parents, eligible students, and staff in the most expedient way possible and without unreasonable delay — and never later than 60 calendar days after discovery. Notices are in plain language and explain what happened, what information was involved, what we have done, and whom to contact.

7days for a vendor to notify Summit
10days for Summit to notify the NYSED Chief Privacy Officer
60days maximum to notify affected families and staff
Plain languagewhat happened, what was involved, what we did, whom to call
Training, acceptable use, and artificial intelligence

What we require of our staff and students

All staff who handle personal information complete data privacy and security training on hire and every year after, and sign our Technology Acceptable Use Policy. The policy requires that student information be entered only into approved, contracted systems — never personal email, personal cloud storage, or unapproved apps — and that it be sent to districts and families only through encrypted channels.

Students and families sign the Student Acceptable Use Policy, which covers safe and respectful use of Summit devices and accounts, both in school and in the residence.

Artificial intelligence

How Summit uses — and limits — AI tools

AI tools (chatbots, writing assistants, transcription, and AI features built into other software) are treated exactly like any other vendor under Education Law § 2-d: if a tool would receive student information, it needs a signed Data Privacy Agreement first. Our rules:

What we never do

Enter student, family, or staff personal information into a free, trial, or personal AI account. Use AI tools that train on Summit data. Record or transcribe IEP meetings or clinical sessions with AI. Let AI decide anything about a student’s placement, services, or discipline.

What we require

Only AI tools approved by the Data Protection Officer and covered by a signed Data Privacy Agreement may be used with personal information. Even then, staff remove names and identifiers whenever the task does not require them, and IEPs, evaluations, and health or behavioral records are not processed by AI without written approval. Staff remain responsible for anything produced with AI help.

Approved AI tools for use with student information: none at this time. When Summit signs a Data Privacy Agreement with an AI vendor, that vendor will be added to the list above with its full supplemental information, and this section will be updated.

Students may use AI tools only when a teacher directs it, with tools Summit has approved, and must not present AI-generated work as their own. Students never enter their own or other students’ personal information into AI tools.

Frequently asked questions

Does Summit sell student information?

No. Student information is never sold or used for marketing, and every vendor is contractually prohibited from doing so.

Can I see what information Summit keeps about my child?

Yes. Contact the Data Protection Officer or the main office to arrange to inspect your child’s records. We respond within 45 days, usually much sooner, and always before an IEP meeting.

What if I think something in my child’s record is wrong?

Ask the Data Protection Officer in writing to correct it. If we do not agree, you have the right to a hearing under FERPA. If the record lives in a vendor system, we make the correction there — you never need to contact the vendor.

Which apps and websites does my child use?

Students use Google Workspace for Education (school email, Classroom, Drive), PowerSchool, Orah in the residence, and Adobe Creative Cloud in creative programs. See the vendor list above. Each vendor that receives student information has a published supplement explaining what data it holds, where it is stored, and how it is protected.

How will I know if there is a data breach?

We notify you directly, in plain language, within the timelines in the “If a breach happens” section.

Who do I contact — Summit or my school district?

Either. Summit holds the records for services provided here; your district holds the CSE and IEP record. We coordinate with the district on any request.

Does Summit use AI tools with student information?

Not today. No AI tool is currently approved for use with student information. If that changes, the vendor will be listed on this page with a signed Data Privacy Agreement, and staff will still remove names and identifiers wherever a task does not require them. See “How Summit uses — and limits — AI tools” above.

All documents

Related: NYSED Data Privacy & Security · FERPA (U.S. Dept. of Education) · New York Education Law § 2-d and 8 NYCRR Part 121 · NY SHIELD Act (staff data)

Page last reviewed September 2026. Policy adopted September 2026. Questions: Data Protection Officer, privacy@summitnyack.com.