Legal

Privacy Policy

Effective July 27, 2026 · Last reviewed July 27, 2026

The Career Readiness Report ("the Service") is operated by Champlin Enterprises, LLC ("we", "us"). This policy explains what we collect, why, and what we will never do with it. It is written to be read, not to be survived.

The short version: we hold student education records on behalf of your institution, we act only on your instructions, we do not sell data, we do not use it for advertising, and we do not use it to train third-party AI models.

Who controls the data

For student records, your institution is the data controller and we are the processor. We hold and process education records solely to provide the Service to you, under your direction. We do not decide what is collected, who is enrolled, or how results are used. You do.

That distinction matters legally and practically. It means you retain the relationship with your students, you retain the obligations that come with it, and you can direct us to export or delete at any time.

FERPA

We handle personally identifiable information from education records as defined by the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99).

We operate as a school official with a legitimate educational interest under 34 CFR § 99.31(a)(1)(i)(B). Accepting that designation carries obligations, and we accept them expressly:

  • We use education records only to perform the service you engaged us for.
  • We are under your direct control with respect to the use and maintenance of those

records.

  • We do not redisclose personally identifiable information to any third party except

as you direct in writing, or where required by law (and then we will tell you first unless legally barred from doing so).

  • We do not use education records for our own purposes, including marketing, product

development on identifiable data, or any form of profiling.

You remain responsible for determining that our designation as a school official is consistent with your institution's annual FERPA notification.

What we collect

From your institution: the student records you import or your students enter. Typically name, institutional email, student identifier, program or major, class standing, cohort and term, plus any custom fields you choose to define. You decide which fields exist; we recommend collecting the minimum that answers your question.

From students: their assessment responses, the experiences they record, and optionally demographic fields where your institution enables them.

From raters: the name, employer, job title and relationship of the supervisor, employer, mentor or faculty member a student invites, plus their ratings and comments. Raters do not create accounts and we collect nothing about them beyond what they enter.

Automatically: standard server logs (IP address, user agent, timestamp, requested path) retained for a short period for security and abuse prevention, and minimal first-party analytics. We do not use third-party advertising or cross-site tracking technologies, and we do not deploy cookies for advertising purposes.

What we do not do

These are commitments, not aspirations.

  • We do not sell personal information. We have never done so and the Service has no

business model that would require it.

  • We do not share personal information for cross-context behavioral advertising.
  • We do not use student data to train third-party AI models. Where AI is used to

generate a student's development narrative, the request is transmitted to our model provider under an agreement that prohibits training on the content, and it is not retained by them for that purpose.

  • We do not permit advertising anywhere in the student experience.
  • **We do not create profiles about students for any purpose outside your institution's

use of the Service.**

Benchmarking and aggregate data

We compute national and peer benchmarks from anonymized, aggregated data. Before any figure is published:

  • Direct and indirect identifiers are removed.
  • A minimum group-size threshold is applied, so no statistic is derived from a group

small enough to identify an individual or a small cohort.

  • No institution is identified by name in any cross-institutional comparison without

its written agreement.

If your institution prefers not to contribute to aggregate benchmarks at all, you can opt out in your settings, and opting out does not restrict any other feature.

AI-generated content

The Service can generate a written development narrative for a student from their competency results. When it does:

  • The request contains the student's competency scores and limited context such as

major and institution name. It is transmitted to our model provider over an encrypted connection.

  • Our agreement with that provider prohibits using the content to train their models.
  • The output is clearly labeled as AI-generated within the Service.
  • A student or an administrator can request regeneration, and an administrator can

disable the feature for the institution entirely.

International students and GDPR

Where you enroll students in the European Economic Area, the United Kingdom or Switzerland, we act as a processor and you as controller. We will:

  • Process personal data only on your documented instructions.
  • Ensure personnel with access are bound by confidentiality.
  • Apply the security measures described on our security page.
  • Assist you, taking account of the nature of processing, with data subject requests

and with your obligations under Articles 32 to 36.

  • Notify you without undue delay on becoming aware of a personal data breach.
  • Delete or return personal data at the end of the engagement, at your choice.
  • Make available the information reasonably necessary to demonstrate compliance.

We will enter into a Data Processing Agreement incorporating the European Commission's Standard Contractual Clauses on request. Contact us and we will send it.

State privacy law

Under the California Consumer Privacy Act as amended by the CPRA, and under comparable laws in other states, we act as a service provider (California) or processor (most other states). We are contractually prohibited from retaining, using or disclosing personal information for any purpose other than performing the Service.

Where a state law grants rights of access, correction, deletion or portability, those requests should be directed to your institution as the controlling party. We will support your institution in responding.

Note that FERPA-governed education records are excluded from the scope of several state privacy statutes; where the laws overlap, we apply whichever standard is more protective.

Retention and deletion

You control retention. By default we retain records for as long as your institution has an active account, plus a short grace period so an accidental deletion can be reversed.

You may at any time:

  • Export all of your data in open formats.
  • Delete an individual student's records.
  • Delete your institution's account and all associated records.

On account deletion we remove personal data from live systems promptly and from encrypted backups within the normal backup rotation. Anonymized aggregate statistics that can no longer be linked to any individual may be retained.

Students may ask their institution to correct or delete their records. Because the institution is the controller, we act on those requests through the institution.

Security

Encryption in transit and at rest, strict tenant isolation, role-based access, append-only audit logging, and least-privilege access for our own staff. The detail, including our sub-processors, is on the security page.

Children

The Service is designed for post-secondary students and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If your institution enrolls dual-enrollment or early-college students who are under 18, tell us, and note that additional obligations may apply under state law and your own policies.

Changes to this policy

If we make a material change we will notify institutional administrators by email before it takes effect, and post the new effective date here. We will not make a retroactive change that reduces the protections applying to data already collected.

Contact

Privacy questions, data protection agreements, and data subject requests: [email protected]

Champlin Enterprises, LLC, Illinois, United States