Confidentiality Policy
Scope of Confidentiality
This policy applies to all employees, contractors, and third-party vendors involved in the handling of student information. It encompasses the following:
-
Student Records: Includes academic records, progress reports, assessments, and attendance logs.
-
Personal Data: Covers names, addresses, contact information, health details, and any other identifying information.
​
Data Management Practices
​
1. Access Control:
-
Access to student records and personal data is limited to authorized personnel only.
-
Permissions are granted based on the employee’s role and responsibilities.
​
2. Data Storage:
-
All electronic records are stored in secure, password-protected systems.
-
Physical records, if any, are kept in locked cabinets accessible only to authorized personnel.
​
3. Data Transmission:
-
Email communications containing sensitive information are encrypted.
-
Sharing of data via physical or digital means is subject to approval and tracking.
​
4. Retention and Disposal:
-
Records are retained only for the duration required by law or operational needs.
-
Data is securely deleted or shredded once retention requirements are fulfilled.
​
Employee Responsibilities
All employees are required to:
-
Maintain confidentiality and avoid unauthorized sharing of student information.
-
Report any suspected breaches of data security to the Learning Manager or designated data officer.
-
Complete regular training on data privacy and security best practices.
​
Breach Management
In the event of a data breach, Mystis Education Program (Owned and Operated by Schachere Industries LLC) will:
-
Notify affected individuals promptly, outlining the nature and scope of the breach.
-
Conduct a thorough investigation to identify the cause and prevent future occurrences.
-
Comply with all reporting requirements under applicable privacy laws.
Parent and Student Rights
Parents and students have the right to:
-
Access their records and request corrections if needed.
-
Understand how their data is being used and stored.
-
Withdraw consent for data sharing, except where required by law.