Our Approach to Data Privacy
PAES Productions is committed to protecting student privacy and responsibly handling all data collected within the PAES Scan Scoring System. Student information is minimally collected, securely handled, and entirely controlled by the School or District using the system.
The short version: we do not collect student data. Students do not use the app. The only required field per student is a first name, and we recommend using a PAES Lab alias. Scores are generic numbers. Reports are generated on demand and never saved to our database.
How we keep student data out of the system
Students do not use the app
Most data privacy issues center around a student's use of an application. Students (called Employees in PAES) do not use our App, other than to scan their physical badge to "clock in". The App is for the Teacher's use. Badges consist of a QR code, a first name and a unique avatar for that Employee. The avatar provides visual recognition for each Employee/Student and their Teacher/Supervisor, and the QR code enables direct access to enter that Employee's scores in the App.
Only a first name is required, and an alias is encouraged
We collect very little in the way of personal student data. Most of what we collect are scores (generic numbers 1-4). The only data we require for each Student/Employee is a first name, and for the strictest data privacy standards we suggest the first name be a "PAES Lab" alias to further protect privacy. Anything beyond that is up to the Teacher/School to include or not, since its intended purpose is simply to enhance the usefulness of the Application.
Schools control their own data and permissions
Our legal relationship is with the School/District. The School is responsible for knowing and adhering to their agreements with parents, local privacy laws and policies for student data. By using our Application, Schools agree to our Terms of Use, which prohibit schools from including data they do not have the legal right to include. For instance, a school should only upload student photos to a profile if photo permission forms signed by parents allow it.
Physical materials protect privacy too
The QR codes generated for students (which appear on Work Folders, badges or other forms the Teacher creates) help preserve the student's privacy both inside and outside the electronic environment. QR code labels contain only the student's PAES Employee first name and a unique avatar, so the student's work assignments and scores never include personally identifiable information.
Reporting information is never saved
When a PAES report is generated for a PAES Employee, the PAES Supervisor enters that Employee's real first and last name to generate the report. Neither the report nor the entered name data is saved in our database.
Teacher data is minimal
We limit the capture of teacher personal information to first name, last name, email and phone number, which are typically publicly available anyhow. We do not capture or store SSNs, birthdates, employment IDs, or similar identifiers.
Technical details
- Cloud platform. Our tablet and web-based applications use one common cloud-based database, located on a Microsoft Azure SQL Database within our Microsoft Azure Tenant. Microsoft Azure is a NIST and FedRAMP compliant cloud platform.
- Firewall rules. Our databases, including all raw data, can only be accessed from specifically identified IP addresses belonging to members of our development team (including our CTO), and by services and resources within our Microsoft Azure Tenant, which include our on-tenant web servers and the services that provide data to our applications. No other public IP addresses have access to our databases.
- Authenticated access. End users can access structured and formatted data (not raw data) through our tablet and web-based applications, and only for the school or schools they are authorized to access. Authentication is granted via an HTTPS endpoint; successful users receive a temporal, expiring authentication token used to access data through a secured web API.
- Application-level roles. Data accessed through our applications is controlled through application roles, which restrict what data can be created, viewed, updated and deleted by each user.
- Encryption in transit. Data moving between our web servers and our tablet and web-based applications is encrypted with HTTPS.
- Encryption at rest. Data stored within our Azure SQL Database uses transparent data encryption, which encrypts the database contents, backups and logs.
Rev. 9/19/25. Questions about data privacy? Email support@paesauthor.com.