How we collect, protect, and share the personal information of our students, families, and staff — and what rights you have.
Summit is an approved private school for students with disabilities and an “educational agency” under New York Education Law § 2-d. We follow the same data privacy and security rules as public school districts, along with FERPA and IDEA. Everything on this page is published under 8 NYCRR Part 121.
New York requires every educational agency to publish this Bill of Rights and attach it to every contract with a company that receives student information. In summary:
Before any company receives student information, it must sign a Data Privacy Agreement that includes our Parents’ Bill of Rights and the protections required by Education Law § 2-d. Every vendor below is bound to these terms:
Open any vendor for the supplemental information the regulation requires: (A) purpose, (B) subcontractors, (C) contract term and data disposition, (D) challenging accuracy, (E) storage location, (F) security and encryption.
Student data is used solely to provide student information system services to Summit: maintaining enrollment records, scheduling, attendance, the PowerTeacher Pro gradebook, report cards, IEP and related document storage, parent/guardian contacts, and state and district reporting for students enrolled at Summit. PowerSchool may use PII only to provide, support, and secure the contracted services. Data is not used for any other purpose, including marketing, advertising, profiling, or product development.
PowerSchool may share data with its cloud hosting and infrastructure subcontractors solely as necessary to deliver the contracted service. Every such subcontractor is contractually bound to the same data protection and confidentiality obligations imposed on PowerSchool under its agreement with Summit, including Education Law § 2-d, Part 121, and FERPA requirements, restrictions on use and disclosure, and required security safeguards. PowerSchool discloses its subprocessors in its Data Privacy Agreement.
The agreement is an annual subscription renewed each school year. Upon expiration or termination, PowerSchool returns Summit’s data in a usable export format on request and securely destroys all student data in its possession, including backups, within the period specified in the Data Privacy Agreement, except where retention is required by law, and provides written confirmation of destruction on request.
A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.
Student data is stored in PowerSchool’s cloud environment on Amazon Web Services data centers located in the United States.
Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Access is restricted to authorized personnel through role-based access controls and multi-factor authentication. PowerSchool maintains a security program aligned with the NIST Cybersecurity Framework, undergoes independent SOC 2 audits, and maintains a documented incident response plan. On Summit’s side, staff access is limited by security group to those with a legitimate educational interest, and multi-factor authentication is enforced for staff logins. PowerSchool must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.
Data is used solely to provide school-managed email, document creation and storage, classroom collaboration, and communication tools for students and staff. Under the Google Workspace for Education Terms of Service and Data Processing Amendment, Google processes Summit customer data only to provide the core services, does not serve advertising in the core services, and does not use core-service data for advertising purposes or to build student profiles.
Google’s agreement requires that any subprocessor engaged to process customer data be bound by written obligations providing at least the same level of data protection. Google publishes its list of Google Workspace subprocessors and provides notice of changes. Summit administrators control which additional Google services are enabled for student accounts and restrict sharing of data outside the Summit domain.
The subscription is ongoing and renews annually; Summit may terminate at any time and may export all customer data at any time. Upon termination, Google deletes customer data from its systems within the period specified in its Data Processing Amendment (generally within 180 days of deletion by the customer or termination), including from backups.
A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.
Data is stored in Google-owned and operated data centers, which are located in the United States and other countries, subject to the protections of the Data Processing Amendment.
Data is encrypted in transit (TLS) between users and Google and between Google data centers, and at rest using AES-256 or stronger. Google Workspace maintains ISO/IEC 27001, 27017, and 27018 certifications and SOC 2/SOC 3 attestations and a security program aligned with the NIST Cybersecurity Framework. Summit enforces 2-step verification for staff, restricts external sharing, limits student accounts to approved services, and manages all accounts through the Admin console. Google must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.
Data is used solely to provide residential student management services to Summit: tracking student attendance, location, and leave; recording pastoral and residential notes; and communicating with parents/guardians and staff about student welfare. Orah may use PII only to provide, support, and secure the contracted service and for no other purpose, including marketing, advertising, or profiling.
Orah shares data with its cloud hosting provider (Amazon Web Services) and other subprocessors solely as necessary to deliver the contracted service. Every such subcontractor is contractually bound to the same data protection and confidentiality obligations imposed on Orah under its agreement with Summit. Orah discloses its subprocessors in its privacy documentation.
The agreement is an annual subscription renewed each school year. Upon expiration or termination, Orah provides an export of Summit’s data on request and securely destroys all student data in its possession, including backups, within the period specified in the Data Privacy Agreement, except where retention is required by law, and confirms destruction in writing on request.
A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.
Student data is stored on Amazon Web Services infrastructure in the United States hosting region selected for Summit’s account.
Data is encrypted in transit (TLS, with automatic redirection to secure connections) and at rest on Orah’s servers. Orah holds ISO/IEC 27001 and ISO/IEC 27018 certifications, is a Student Privacy Pledge signatory, and maintains 24/7 monitoring, automated daily backups, granular role-based access controls, and an incident response program. Summit limits Orah access to residential and supervisory staff with a legitimate need. Orah must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.
Data is used solely to support Summit’s internal administrative workflows. Airtable, as the platform provider, processes Summit’s content only to provide, support, and secure the service and for no other purpose, including marketing, advertising, or training of models on Summit content; Summit keeps Airtable’s AI features disabled for bases containing student data.
Airtable engages subprocessors, including its cloud hosting provider (Amazon Web Services), solely as necessary to deliver the service. Airtable’s Data Processing Addendum requires subprocessors to be bound by written obligations at least as protective as Airtable’s own, and Airtable publishes its subprocessor list with notice of changes.
The subscription is annual and renews each school year. Summit may export all bases at any time. Upon termination, Airtable deletes customer content within the period specified in its Data Processing Addendum, including from backups.
A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.
Data is stored in Airtable’s production environment hosted on Amazon Web Services data centers located in the United States.
Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Airtable maintains SOC 2 Type II and ISO/IEC 27001 attestations, role-based permissions, two-factor authentication, and an incident response program. Summit restricts base and workspace sharing to authorized staff and does not use public share links for bases containing PII. Airtable must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.
Data is used solely to provide accounting, invoicing, and payroll services to Summit, including preparing and tracking tuition and service invoices to placing school districts and agencies for each enrolled student. Intuit may use data only to provide, support, and secure the contracted services and as described in its business-customer terms, and not for marketing to students or parents or for building profiles. Summit limits student data in QuickBooks to the minimum needed for billing — no grades, IEP, health, or behavioral information is entered.
Intuit engages subprocessors (hosting, payment processing, payroll tax filing) solely as necessary to deliver the services and requires them to maintain security and confidentiality obligations consistent with Intuit’s own. Intuit describes its service providers in its privacy documentation.
The subscription is ongoing and renews automatically. Summit may export its company file and reports at any time. Upon cancellation, Intuit retains read-only access to data for one year, after which data is deleted in accordance with Intuit’s retention policy, except where retention is required by law (for example, tax and payroll records). Summit retains billing records for the period required by its records retention schedule and audit requirements.
A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.
Data is stored in Intuit-managed data centers and cloud infrastructure located in the United States.
Data is encrypted in transit (TLS) and at rest (AES-256). Intuit maintains SOC 1 and SOC 2 attestations, multi-factor authentication, role-based user permissions, and an incident response program. Summit restricts QuickBooks access to business-office staff, enforces multi-factor authentication, and limits student fields to name, district, program, and service dates. Because staff Social Security and bank account numbers are “private information” under the NY SHIELD Act, Summit treats any breach as reportable under GBL § 899-aa as well as Education Law § 2-d. Intuit must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.
Data is used solely to provision and operate licensed Adobe applications and cloud storage for Summit users. Under the Adobe education terms and Data Processing Agreement, Adobe processes customer content only to provide the services; content-analysis and product-improvement features are disabled for K-12 education accounts, and Adobe does not use K-12 student data for advertising or profiling.
Adobe uses subprocessors, including cloud hosting providers, solely as necessary to deliver the services, and requires them by written agreement to protect personal data consistent with Adobe’s DPA. Adobe publishes its subprocessor list and provides notice of changes.
The license is annual and renews each school year. Summit administrators may remove users and export content at any time. Upon termination, Adobe deletes customer content within the period specified in its Data Processing Agreement, including from backups.
A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.
Data is stored in Adobe cloud infrastructure on data centers located in the United States.
Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Adobe maintains SOC 2 Type II and ISO/IEC 27001 certifications under the Adobe Common Controls Framework and supports single sign-on through Summit’s identity provider. Summit provisions students only with managed education accounts, restricts sharing features, and removes accounts at withdrawal. Adobe must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.
Data is used solely to operate Summit’s staff alert and incident response system: issuing and locating alerts, notifying responders, and maintaining incident records. CENTEGIX may use PII only to provide, support, and secure the service and for no other purpose, including marketing.
CENTEGIX uses cloud hosting (Amazon Web Services) and notification subcontractors solely as necessary to deliver the service and requires them by written agreement to maintain confidentiality and security obligations consistent with its own.
The subscription is annual and renews each school year. Upon termination, CENTEGIX deletes customer data within the period specified in the Data Privacy Agreement, except where retention is required by law, and confirms destruction on request.
A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitnyack.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.
Data is stored in CENTEGIX’s cloud environment hosted on Amazon Web Services data centers located in the United States.
Data is encrypted in transit (TLS) and at rest (AES-256). Access is restricted through role-based administrator permissions and multi-factor authentication. CENTEGIX maintains SOC 2 Type II attestation and an incident response program. Summit instructs staff to record student names in incident records only when necessary. CENTEGIX must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.
The Family Educational Rights and Privacy Act gives parents and eligible students (18 or older) the right to inspect and review education records, to request amendment of records that are inaccurate or misleading, to consent to most disclosures of personally identifiable information, and to file a complaint with the U.S. Department of Education. IDEA adds protections specific to students with disabilities, including the right to a list of the types and locations of records we keep.
We send our FERPA annual notice to families each September and post it here.
Summit students are placed by their home school district’s Committee on Special Education. Summit keeps records for the services provided here; the placing district keeps the CSE and IEP record. You can exercise your FERPA rights with either of us, and we coordinate on requests.
Parents, eligible students, staff, and others may file a complaint about a possible breach or unauthorized release of personal information, or about how Summit or one of its vendors is handling it.
What happens after you file
You may also file directly with the New York State Education Department: online form, privacy@nysed.gov, or Chief Privacy Officer, NYSED, 89 Washington Avenue, Albany, NY 12234.
If student or staff personal information is accessed or released without authorization, Summit notifies affected parents, eligible students, and staff in the most expedient way possible and without unreasonable delay — and never later than 60 calendar days after discovery. Notices are in plain language and explain what happened, what information was involved, what we have done, and whom to contact.
All staff who handle personal information complete data privacy and security training on hire and every year after, and sign our Technology Acceptable Use Policy. The policy requires that student information be entered only into approved, contracted systems — never personal email, personal cloud storage, or unapproved apps — and that it be sent to districts and families only through encrypted channels.
Students and families sign the Student Acceptable Use Policy, which covers safe and respectful use of Summit devices and accounts, both in school and in the residence.
AI tools (chatbots, writing assistants, transcription, and AI features built into other software) are treated exactly like any other vendor under Education Law § 2-d: if a tool would receive student information, it needs a signed Data Privacy Agreement first. Our rules:
Enter student, family, or staff personal information into a free, trial, or personal AI account. Use AI tools that train on Summit data. Record or transcribe IEP meetings or clinical sessions with AI. Let AI decide anything about a student’s placement, services, or discipline.
Only AI tools approved by the Data Protection Officer and covered by a signed Data Privacy Agreement may be used with personal information. Even then, staff remove names and identifiers whenever the task does not require them, and IEPs, evaluations, and health or behavioral records are not processed by AI without written approval. Staff remain responsible for anything produced with AI help.
Approved AI tools for use with student information: none at this time. When Summit signs a Data Privacy Agreement with an AI vendor, that vendor will be added to the list above with its full supplemental information, and this section will be updated.
Students may use AI tools only when a teacher directs it, with tools Summit has approved, and must not present AI-generated work as their own. Students never enter their own or other students’ personal information into AI tools.
No. Student information is never sold or used for marketing, and every vendor is contractually prohibited from doing so.
Yes. Contact the Data Protection Officer or the main office to arrange to inspect your child’s records. We respond within 45 days, usually much sooner, and always before an IEP meeting.
Ask the Data Protection Officer in writing to correct it. If we do not agree, you have the right to a hearing under FERPA. If the record lives in a vendor system, we make the correction there — you never need to contact the vendor.
Students use Google Workspace for Education (school email, Classroom, Drive), PowerSchool, Orah in the residence, and Adobe Creative Cloud in creative programs. See the vendor list above. Each vendor that receives student information has a published supplement explaining what data it holds, where it is stored, and how it is protected.
We notify you directly, in plain language, within the timelines in the “If a breach happens” section.
Either. Summit holds the records for services provided here; your district holds the CSE and IEP record. We coordinate with the district on any request.
Not today. No AI tool is currently approved for use with student information. If that changes, the vendor will be listed on this page with a signed Data Privacy Agreement, and staff will still remove names and identifiers wherever a task does not require them. See “How Summit uses — and limits — AI tools” above.
Related: NYSED Data Privacy & Security · FERPA (U.S. Dept. of Education) · New York Education Law § 2-d and 8 NYCRR Part 121 · NY SHIELD Act (staff data)
Page last reviewed September 2026. Policy adopted September 2026. Questions: Data Protection Officer, privacy@summitnyack.com.