Privacy Policy

Berry Suite is a school management system. Protecting student and family data is not a legal checkbox — it is fundamental to how we operate.

Effective date: June 13, 2026 ·  Applies to: app.berrysuite.xyz

1. Who we are and what Berry Suite does

Berry Suite is a cloud-based school operating system (SIS + LMS + attendance + gradebook + HR + communications + yearbook) sold to K–12 school administrators. Schools pay for and configure the platform; students, parents, and staff are end-users of the school's account.

Berry Suite is not a consumer app. We do not market directly to students or parents. We do not run advertisements. We do not sell data. Our product relationship is with the school, and all student data we hold belongs to the school and the families it serves.

2. Our role under FERPA

The Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g, protects the privacy of student education records. Education records stored in Berry Suite — grades, attendance, enrollment, schedules, and teacher/admin notes — belong to the student and the school, not to Berry Suite.

Berry Suite operates as a "school official" service provider under 34 CFR §99.31(a)(1)(i)(B). This means:

  • We perform institutional functions on behalf of the school (operating the SIS/LMS/gradebook).
  • School staff access student education records only for legitimate educational interests (instruction, administration, school operations).
  • Berry Suite operates under the school's direct control with respect to the use and maintenance of education records.
  • Berry Suite uses student education records only for authorized educational purposes — never for advertising, commercial profiling, or Berry Suite's own business purposes.

⚠️ Pending Counsel Review

The formal FERPA "school official" designation and the four required conditions (34 CFR §99.31(a)(1)(i)(B)(1)–(4)) will be confirmed in a signed Data Processing Agreement (DPA) with each school. The specific contractual language for the DPA is pending outside counsel review. No school pilot should begin without an executed DPA.

3. What data we collect and store

Berry Suite stores data that schools enter into the platform. We do not independently collect data about students beyond what school administrators, teachers, or parents enter.

Student education records

Identity
Full name, email address, assigned grade level, and role (student).
Class enrollment
Which classes a student is enrolled in, including class name and teacher.
Grades and assignments
Points earned, grades, assignment titles, due dates, and submission status. Teachers may add free-text notes to individual grade entries.
Attendance records
Present/absent/late/excused status by date and class. Teachers may add free-text notes to attendance entries.
Admin notes
School administrators may enter free-text notes on student profiles (up to 10,000 characters). These notes are visible only to administrators, not teachers, parents, or students. This field is considered a high-sensitivity education record.
Schedule
Timetable and class schedule slots assigned by the school administration.
Communications
Messages sent through Berry Suite's communications module between school staff and families.
Letters and transcripts
Formal letters and academic transcripts generated by administrators within the platform.
Yearbook content
Photos and content uploaded by school administrators or teachers for the school yearbook module.
Parent-student links
Associations between parent accounts and their children's student records, set up by school administrators or parents.

Staff and HR records

Berry Suite's HR module stores staff employment information entered by school administrators: staff name, email, role, and employment-related records. HR records are employment records, not student education records, and are not subject to FERPA. They are, however, protected as personal data under applicable privacy laws.

Billing records

School billing information (payment method, billing address, invoice history) is stored and processed by Stripe. Berry Suite does not store payment card numbers. Billing records relate to the school's account — they are not student education records.

System-generated data

Berry Suite generates operational records including in-app notifications, audit logs of user actions (e.g., grade entry, attendance marking), and session data for authentication. This data is used to operate the platform and maintain security.

What we do NOT collect

  • We do not collect or store student Social Security numbers.
  • We do not collect health or medical information (see note on therapist role below).
  • We do not track student behavior across third-party websites or services.
  • We do not use cookies or tracking pixels for advertising.
  • We do not build advertising profiles on students or families.

⚠️ Pending Counsel Review

The therapist role in Berry Suite's database schema raises a potential HIPAA question: if licensed therapists enter clinical session notes through Berry Suite, those records may be HIPAA-covered therapy records in addition to (or instead of) FERPA education records. The intended scope of the therapist role and whether a HIPAA Business Associate Agreement (BAA) is required is pending a decision by Berry Suite and review by outside counsel before any therapist-role functionality is activated for school use.

3a. Feature-specific data practices

The following features of Berry Suite process student and family data in ways that parents and schools should understand. All of these features operate only within the school's own data — no data crosses school boundaries.

FamilyThread

FamilyThread is Berry Suite's secure in-app messaging feature. It allows parents, teachers, and school administrators to communicate in threads that are linked to individual student records. Because these messages are created in connection with a student's enrollment and are maintained by the school, they are treated as education records under FERPA (20 U.S.C. § 1232g). FamilyThread stores the message content, the sender's identity, timestamps, and the student record the thread is associated with. Messages are visible only to the participants in the thread and to school administrators. Berry Suite does not read or analyze the content of FamilyThread messages for any purpose other than displaying them to authorized users and maintaining the platform.

EnrollCast

EnrollCast is a predictive analytics tool available to school administrators. It aggregates data that already exists in Berry Suite — including attendance records, grade averages, billing history (invoice counts, payment timing, outstanding balances), family engagement signals (FamilyThread activity), and sibling/parent link information — to produce a per-student retention probability score and a school-level enrollment and revenue forecast.

EnrollCast does not collect any new data. It derives signals exclusively from education and billing records already held by the school in Berry Suite. The predictive scores and forecasts are visible only to administrators of the school that owns the data. EnrollCast data is never shared with other schools, third parties, or Berry Suite for business purposes. The scoring model is run entirely within Berry Suite's infrastructure — no student data is sent to an external machine-learning service.

FlexTuition

FlexTuition allows parents to request a restructuring of an unpaid tuition invoice — for example, extending a due date, pausing a payment, or splitting an invoice into installments. To evaluate whether a request can be auto-approved or requires admin review, FlexTuition processes the family's billing history within Berry Suite, including the number of prior invoices, payment timeliness, outstanding balances, and the number of prior restructuring requests. This financial data is used only to compute a risk score that determines the review pathway; it is not shared with third parties and is not used for credit reporting or any purpose outside of administering the school's own billing process.

FlexTuition requests, the associated risk scores, and the approval decisions are visible to the school's administrators and to the parent who submitted the request. Berry Suite does not use FlexTuition financial signals for any purpose other than facilitating the school's own tuition management.

Autopilot

Autopilot is a workflow automation feature that allows school administrators to configure rules that fire automatically when specific events occur — for example, when a student's absence count crosses a threshold, when an invoice is paid, or when an enrollment application changes status. When a rule fires, it can take one or more actions, including: sending an email to parents, students, or administrators; sending an in-app notification; appending a note to a student's education record; or changing the status of an enrollment application.

FERPA notice:When an Autopilot rule appends a note to a student's profile or changes an enrollment application status, those changes are modifications to education records within the meaning of FERPA. To maintain the integrity of education records, Berry Suite stores an attribution tag on every automated change — the tag identifies that the change was made by Autopilot, names the rule that triggered it, and records the date. This tag is stored in the record itself, not just displayed in the user interface, so it is part of the permanent education record. Parents who request access to their child's records under FERPA will see these attribution tags.

Autopilot rules are configured entirely by the school's administrators. Berry Suite does not create, modify, or trigger Autopilot rules on its own initiative. All Autopilot actions are logged in Berry Suite's automation run history, which is visible to school administrators.

4. How we use student data

Berry Suite uses student data only for the following purposes:

  • Providing the platform: Operating the SIS, LMS, gradebook, attendance, communications, and other modules as contracted with the school.
  • Technical support: Diagnosing and fixing technical problems reported by the school, with access limited to authorized Berry Suite personnel.
  • Security and fraud prevention: Detecting unauthorized access, abuse, and security threats.
  • Platform improvement: Aggregate, anonymized product analytics (e.g., which features schools use most) that do not identify individual students.

We do not and will not use student data for:

  • Targeted advertising or behavioral advertising of any kind.
  • Selling or renting student PII to any third party.
  • Creating advertising profiles on students.
  • Amassing student profiles for non-educational purposes.
  • Any purpose that is not a school-authorized educational purpose.

These prohibitions apply under FERPA (34 CFR §99.33) and under student data privacy laws in all states where Berry Suite operates (SOPIPA-model legislation).

5. Sub-processors

Berry Suite uses a small number of sub-processors to operate the platform. Student education records are shared with sub-processors only to the extent necessary to provide the contracted service. All sub-processors operate under contractual obligations that prohibit use of student data for their own purposes.

Supabase (PostgreSQL + Storage)
Primary database and file storage for all Berry Suite data, including all student education records. Supabase provides AES-256 encryption at rest and TLS 1.2+ in transit. Hosted on AWS infrastructure. Data residency: United States.
Stripe
Payment processing for school billing. Stripe receives school billing information only — Stripe does not receive student education records. Stripe is PCI DSS Level 1 certified.
Resend (email delivery)
Transactional email delivery (e.g., enrollment invitations, password resets). Berry Suite limits the student PII in email bodies to what is strictly necessary for the email's purpose. A FERPA-compliant Data Processing Agreement with Resend governs use of any student PII transmitted via email.
Vercel
Application hosting and edge infrastructure. Vercel serves the Berry Suite web application. Vercel does not have access to the Berry Suite database; it processes only the web requests needed to serve the application.

⚠️ Pending Counsel Review

The formal sub-processor list and DPA provisions governing each sub-processor's handling of student PII (including FERPA-required contractual language and state-specific addenda for CA AB 1584 and NY Education Law §2-d) are pending outside counsel review and will be incorporated into the school services agreement template before any school pilot launch.

6. Parent and student rights

Under FERPA, parents of students under 18 (and students 18 or older) have the right to:

  • Inspect and review their child's education records. Berry Suite gives parents access to grades, attendance, and schedules through the parent portal. For records not accessible in the portal, contact the school directly.
  • Request amendment of records they believe are inaccurate or misleading. Requests to amend records should be made to the school. Berry Suite will implement any amendments directed by the school.
  • Request deletion of their child's data. Deletion requests should be made to the school. Berry Suite will delete education records upon receiving a confirmed deletion request from the school.
  • Know about disclosures of their child's education records. Berry Suite does not disclose student education records to third parties other than the sub-processors listed in Section 5.

How to exercise rights: For access, amendment, or deletion requests, contact your school's administrator first — the school controls its Berry Suite account and the education records within it. If you have questions Berry Suite can answer directly, email privacy@berrysuite.xyz.

⚠️ Pending Counsel Review

The formal FERPA rights notice and the specific procedures for parents to exercise FERPA rights (including the amendment dispute procedure under 34 CFR §99.21 and the right to file a complaint with the U.S. Department of Education) are pending outside counsel review and will appear in the school services agreement. The school is the primary FERPA rights administrator; Berry Suite's obligations are secondary and contractual.

7. Data security

Berry Suite uses the following security measures to protect student education records:

  • Encryption in transit: All data transmitted between Berry Suite and users is encrypted using TLS 1.2 or higher.
  • Encryption at rest: Student data stored in Supabase is encrypted at rest using AES-256 (Supabase's default encryption, backed by AWS infrastructure).
  • Row-Level Security (RLS): Berry Suite's database enforces row-level access controls so that each user can only access records their role is authorized to see. Students cannot access other students' records; teachers can only access classes they are assigned to; admin notes are restricted to administrators only.
  • Authentication: All users authenticate via Supabase Auth with email and password. Session tokens are stored as HttpOnly cookies and are not accessible to client-side JavaScript.
  • Access controls: Berry Suite staff access to production data is restricted to authorized personnel for support and maintenance purposes only. Access is logged.

⚠️ Pending Counsel Review

A formal written information security program (WISP) — required under NY Education Law §2-d, CA Civil Code §1798.81.5, and the COPPA Rule — is in preparation. The WISP will specify technical, administrative, and physical safeguards, the personnel responsible for the security program, and the annual review cadence. This document is pending completion and outside counsel review before Berry Suite's first school deployment.

8. Data retention and deletion

Berry Suite retains student education records for as long as the school's active subscription continues. When a school terminates its subscription:

  • The school may request a data export of its education records in CSV format at any time before termination.
  • Berry Suite will delete or anonymize the school's student education records following termination.

⚠️ Pending Counsel Review

The specific retention period after subscription termination (e.g., 30-day grace period for data export, then deletion), the deletion verification procedure, and any exceptions for data Berry Suite is required to retain under law (e.g., backup retention, legal holds) are pending outside counsel review. These terms will be specified in the school services agreement and DPA. Applicable state law minimums: CA Ed. Code §49073.1 (destruction of records); NY Education Law §2-d (contract must specify retention); IL SOPPA §15(b)(5) (destruction upon termination or completion of contract).

Individual student deletion: If a school requests deletion of an individual student's records (e.g., upon a parent's request to the school), Berry Suite will delete or anonymize those records upon receiving confirmed written direction from the school within a commercially reasonable timeframe.

9. COPPA — children under 13

The Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, applies to operators that collect personal information from children under 13.

Berry Suite does not have a consumer signup flow. Students are enrolled into Berry Suite by school administrators — children do not self-register. When a school enrolls students under 13, Berry Suite relies on the school-authorization exception under 16 CFR §312.5(b)(1): schools may authorize collection of student PII on behalf of parents for school-use purposes, provided the data is used only for educational purposes and not for commercial use.

  • Berry Suite does not use student data for any purpose other than operating the school's account (see Section 4).
  • Berry Suite does not disclose student data to third parties outside the sub-processors listed in Section 5.
  • Parents may request access to, correction of, or deletion of their child's data through the school (see Section 6).

⚠️ Pending Counsel Review

Whether Berry Suite's enrollment flow qualifies for the COPPA school-authorization exception as currently implemented — and whether Berry Suite meets the definition of an "operator" for COPPA purposes given its school-directed model — requires outside counsel confirmation. Specifically, the 2025 COPPA Rule amendments and the exact scope of 16 CFR §312.5(b)(1) in the context of a SaaS school platform are pending legal analysis. The school services agreement template must expressly invoke the school-authorization exception and require the school to provide parental notice. This language is pending counsel review.

10. State student data privacy laws

In addition to FERPA and COPPA, Berry Suite is designed to comply with state student data privacy laws. The following core prohibitions apply regardless of the school's state:

  • We do not use student data for targeted advertising (SOPIPA, 20+ states).
  • We do not sell student data (SOPIPA, 20+ states).
  • We do not amass student profiles for non-educational purposes (SOPIPA).
  • We do not disclose student data for non-educational purposes (SOPIPA).

⚠️ Pending Counsel Review

State-specific addenda are required for schools in California (CA Ed. Code §22584 SOPIPA + AB 1584), New York (Education Law §2-d + 8 NYCRR Part 121), Illinois (IL SOPPA, 105 ILCS 85/), and Texas (TX SB 11). These addenda — specifying encryption standards, breach notification timing, annual training requirements, and designated privacy contact requirements — are pending outside counsel drafting and will be incorporated into the school services agreement before Berry Suite serves schools in those states.

11. Breach notification

If Berry Suite becomes aware of a security breach that compromises student education records, we will notify the affected school(s) as quickly as reasonably practicable to allow the school to fulfill its own breach notification obligations to families.

Berry Suite maintains an internal incident response procedure for identifying, containing, and investigating suspected breaches. Upon confirmation of a breach involving education records, Berry Suite will provide schools with:

  • A description of the categories and approximate number of records affected.
  • The date of the breach and date of discovery.
  • A description of steps Berry Suite has taken to address the breach.
  • Contact information for follow-up questions.

⚠️ Pending Counsel Review

Contractual breach notification timing — which varies by state (NY 8 NYCRR §121.10: 60 days to affected individuals; NYC DoE contracts: 7 days; CA Ed. Code §49073.6: 72 hours to school) — will be specified in each school's DPA. The governing-law clause and specific notice delivery method (e.g., email to school's designated privacy contact) are pending outside counsel review for inclusion in the school services agreement template.

12. Changes to this policy

Berry Suite may update this privacy policy as the product evolves, as laws change, or as our sub-processor list changes. When we make material changes, we will:

  • Update the effective date at the top of this page.
  • Notify school administrators via in-app notification and email at least 30 days before material changes take effect.
  • Maintain the previous version of this policy available upon request.

Continued use of Berry Suite after the effective date of an updated policy constitutes acceptance of the updated terms, to the extent permitted by law and the school's DPA.

13. Contact us

For privacy questions, data access requests, or to obtain a copy of Berry Suite's Data Processing Agreement template:

Berry Suite Privacy

Email: privacy@berrysuite.xyz

We will respond to privacy-related inquiries within 10 business days.

© 2026 Berry Suite. All rights reserved.

Sign in · Privacy Policy