V.E.D.A. is a secure system that school districts use to hold and manage information relating to special education services. The information in it belongs to the district, not to us. We hold and process it on the district's instructions, for that district's own educational purposes, and for nothing else.
1. Our role, and the district's
Under the Family Educational Rights and Privacy Act (FERPA), a district may share education records with a service provider acting as a school official with a legitimate educational interest, provided that provider is under the district's direct control and uses the records only for the purpose it was engaged for. That is the basis on which V.E.D.A. operates.
Practically, this means:
- The district decides what goes into the system and who may use it.
- We do not re-disclose education records to anyone else, except the sub-processors listed in section 8, who are bound to the same limits.
- We do not use student information to build advertising profiles, and we never sell it. There is no advertising anywhere in V.E.D.A.
- If a district ends its use of V.E.D.A., it may take an export of its data and require deletion.
2. What the system holds
About students
- Identifying details drawn from the district's own student information system: name, date of birth, student ID, grade, campus and assigned staff.
- Parent and guardian names and contact details, so the district can reach the family.
- Information district staff record about a student in the course of their special education work, including written observations, assessment results and documents they attach.
- Records of notices given to families and of consent given or declined, including the signature provided, the wording it was given against, and when each step happened.
- Records of meetings held about the student, including who took part and the written record of what was decided.
About district staff
- Name, work email address, job role and campus — taken from the district's own systems or from the Google account used to sign in.
- A record of actions taken in the system, so the district can answer who accessed or changed a record.
- Notification history, and any private notes a staff member writes for their own use.
What we do not collect. V.E.D.A. does not track browsing behavior, does not use advertising or analytics cookies, and sets no third-party trackers. The only cookie it sets is the one that keeps a signed-in staff member signed in.
3. How the information is used
Only to provide the service to the district that entered it: holding the information securely, making it available to the staff who are entitled to see it, producing the documents the district's process requires, and giving the district's own leadership a view of its own operation.
Any aggregate figures shown to district leadership describe that district's own work. We do not combine one district's information with another's for any purpose.
4. Artificial intelligence
The system can produce draft written text to assist a staff member, which that staff member then reviews and edits. The edited text is the record; the draft is only a starting point.
- The student's name is removed before any content is sent for processing, including from free text where someone may have typed it.
- Processing runs inside the district's own Google Cloud environment, so content is not sent to a consumer AI service.
- Student information is not used to train any AI model.
5. Who can see what
Access is limited to the district staff who are involved with a particular student, together with the district leadership responsible for oversight, whose access is read-only. Staff who administer the system's accounts and settings have no access to student records.
Every time a record is read or changed, the system writes an entry recording who did it and when. Those entries deliberately contain no student information themselves.
6. How it is protected
- All traffic is encrypted in transit.
- The most sensitive fields — a student's date of birth and ID number, and guardian contact details — are additionally encrypted in the database using AES-256-GCM, so they are unreadable to anyone reading the raw storage.
- Documents are held in private storage that is not reachable from the public internet.
- Sign-in is restricted to district email addresses, and a session ends automatically after 30 minutes of inactivity.
- The service runs on Google Cloud in the United States, which maintains its own independent security certifications for the underlying infrastructure.
7. How long it is kept
| Record | Kept for |
|---|---|
| The completed record of a student's evaluation | Kept as the district's permanent record |
| Working documents attached along the way | Removed once the record is completed and archived |
| Internal staff notes and messages about a student | Eight months after that student's last record is archived |
| Completed records in day-to-day view | The current school year plus 42 months, after which they are reachable only by a system administrator |
| Records of consent | Retained as the district's legal record |
Nothing is removed while a student still has active work in the system. When records are deleted, the system produces a record of the deletion so the district can show what was removed and when.
8. Who else is involved
We use a small number of providers to run the service. They act on our instructions and may not use the information for their own purposes.
| Provider | What for |
|---|---|
| Google Cloud Platform | Hosting, database, document storage and AI processing, in the United States |
| Google Workspace | Delivering email notices to staff and families |
| Cloudflare | Serving this public website only — it holds no student information |
Your district's student information system is the district's own system, not a sub-processor of ours; V.E.D.A. reads from it with the district's permission.
9. Parents and guardians
Parents have rights under FERPA to inspect and seek correction of their child's education records. Those rights are exercised through the school district, which holds the records — please contact your child's campus or the district's special education office. We will support the district in responding, but we cannot release a child's records directly to a parent, because it is not our decision to make.
When a parent signs or declines something in V.E.D.A., a copy of exactly what they were shown is emailed to them automatically, in the language they read it in, without their having to ask.
10. Children
V.E.D.A. is a tool for school staff. Students do not have accounts and do not sign in. Where a parent is sent a secure link to provide information about their own child, that link gives access to nothing else.
11. Changes to this policy
If we change how the service handles information, we will update this page and change the date at the top. Where a change materially affects a district's data, we will tell the district directly rather than relying on this page alone.
12. Contact
Questions about this policy, or a request from a district about its data:
V.E.D.A. — Validated Entry for Diagnostic Assessment
contact@vedacapture.com
933 Clear View Dr.
Bedford, TX 76021
United States
If you are a parent or guardian with a question about your own child's records, please contact your school district directly — see section 9.