How we collect, protect, and share the personal information of our students, families, and staff — and what rights you have.
The Summit School is an approved private school for students with disabilities and an “educational agency” under New York Education Law § 2-d. We follow the same data privacy and security rules as public school districts, along with FERPA and IDEA. Everything on this page is published under 8 NYCRR Part 121.
New York requires every educational agency to publish this Bill of Rights and attach it to every contract with a company that receives student information. In summary:
Before any company receives student information, it must sign a Data Privacy Agreement that includes our Parents’ Bill of Rights and the protections required by Education Law § 2-d. Every vendor below is bound to these terms:
Open any vendor for the supplemental information the regulation requires: (A) purpose, (B) subcontractors, (C) contract term and data disposition, (D) challenging accuracy, (E) storage location, (F) security and encryption.
Data is used solely to provide school-managed email, document creation and storage, classroom collaboration, and communication tools for students and staff. Under the Google Workspace for Education Terms of Service and Data Processing Amendment, Google processes Summit customer data only to provide the core services, does not serve advertising in the core services, and does not use core-service data for advertising purposes or to build student profiles.
Google’s agreement requires that any subprocessor engaged to process customer data be bound by written obligations providing at least the same level of data protection. Google publishes its list of Google Workspace subprocessors and provides notice of changes. Summit administrators control which additional Google services are enabled for student accounts and restrict sharing of data outside the Summit domain.
The subscription is ongoing and renews annually; Summit may terminate at any time and may export all customer data at any time. Upon termination, Google deletes customer data from its systems within the period specified in its Data Processing Amendment (generally within 180 days of deletion by the customer or termination), including from backups.
A parent, student, or eligible student who believes data is inaccurate may request a correction from Summit’s Data Protection Officer at privacy@summitqueens.com. Requests are reviewed under Summit’s record-amendment procedures (FERPA, 34 CFR §§ 99.20–99.22) and Education Law § 2-d. Summit makes the correction or directs the vendor to; parents never need to contact the vendor.
Data is stored in Google-owned and operated data centers, which are located in the United States and other countries, subject to the protections of the Data Processing Amendment.
Data is encrypted in transit (TLS) between users and Google and between Google data centers, and at rest using AES-256 or stronger. Google Workspace maintains ISO/IEC 27001, 27017, and 27018 certifications and SOC 2/SOC 3 attestations and a security program aligned with the NIST Cybersecurity Framework. Summit enforces 2-step verification for staff, restricts external sharing, limits student accounts to approved services, and manages all accounts through the Admin console. Google must notify Summit of any breach or unauthorized release of personally identifiable information in the most expedient way possible and without unreasonable delay, and in no case later than seven (7) calendar days after discovery, as required by 8 NYCRR § 121.10.
The Family Educational Rights and Privacy Act gives parents and eligible students (18 or older) the right to inspect and review education records, to request amendment of records that are inaccurate or misleading, to consent to most disclosures of personally identifiable information, and to file a complaint with the U.S. Department of Education. IDEA adds protections specific to students with disabilities, including the right to a list of the types and locations of records we keep.
We send our FERPA annual notice to families each September and post it here.
Summit students are placed by their home school district’s Committee on Special Education. Summit keeps records for the services provided here; the placing district keeps the CSE and IEP record. You can exercise your FERPA rights with either of us, and we coordinate on requests.
Parents, eligible students, staff, and others may file a complaint about a possible breach or unauthorized release of personal information, or about how Summit or one of its vendors is handling it.
What happens after you file
You may also file directly with the New York State Education Department: online form, privacy@nysed.gov, or Chief Privacy Officer, NYSED, 89 Washington Avenue, Albany, NY 12234.
If student or staff personal information is accessed or released without authorization, Summit notifies affected parents, eligible students, and staff in the most expedient way possible and without unreasonable delay — and never later than 60 calendar days after discovery. Notices are in plain language and explain what happened, what information was involved, what we have done, and whom to contact.
All staff who handle personal information complete data privacy and security training on hire and every year after, and sign our Technology Acceptable Use Policy. The policy requires that student information be entered only into approved, contracted systems — never personal email, personal cloud storage, or unapproved apps — and that it be sent to districts and families only through encrypted channels.
Students and families sign the Student Acceptable Use Policy, which covers safe and respectful use of Summit devices and accounts, both in school and in the residence.
AI tools (chatbots, writing assistants, transcription, and AI features built into other software) are treated exactly like any other vendor under Education Law § 2-d: if a tool would receive student information, it needs a signed Data Privacy Agreement first. Our rules:
Enter student, family, or staff personal information into a free, trial, or personal AI account. Use AI tools that train on Summit data. Record or transcribe IEP meetings or clinical sessions with AI. Let AI decide anything about a student’s placement, services, or discipline.
Only AI tools approved by the Data Protection Officer and covered by a signed Data Privacy Agreement may be used with personal information. Even then, staff remove names and identifiers whenever the task does not require them, and IEPs, evaluations, and health or behavioral records are not processed by AI without written approval. Staff remain responsible for anything produced with AI help.
Approved AI tools for use with student information: none at this time. When Summit signs a Data Privacy Agreement with an AI vendor, that vendor will be added to the list above with its full supplemental information, and this section will be updated.
Students may use AI tools only when a teacher directs it, with tools Summit has approved, and must not present AI-generated work as their own. Students never enter their own or other students’ personal information into AI tools.
No. Student information is never sold or used for marketing, and every vendor is contractually prohibited from doing so.
Yes. Contact the Data Protection Officer or the main office to arrange to inspect your child’s records. We respond within 45 days, usually much sooner, and always before an IEP meeting.
Ask the Data Protection Officer in writing to correct it. If we do not agree, you have the right to a hearing under FERPA. If the record lives in a vendor system, we make the correction there — you never need to contact the vendor.
Students use Google Workspace for Education (school email, Classroom, Drive). See the vendor list above. Each vendor that receives student information has a published supplement explaining what data it holds, where it is stored, and how it is protected.
We notify you directly, in plain language, within the timelines in the “If a breach happens” section.
Either. Summit holds the records for services provided here; your district holds the CSE and IEP record. We coordinate with the district on any request.
Not today. No AI tool is currently approved for use with student information. If that changes, the vendor will be listed on this page with a signed Data Privacy Agreement, and staff will still remove names and identifiers wherever a task does not require them. See “How Summit uses — and limits — AI tools” above.
Related: NYSED Data Privacy & Security · FERPA (U.S. Dept. of Education) · New York Education Law § 2-d and 8 NYCRR Part 121 · NY SHIELD Act (staff data)
Page last reviewed September 2026. Policy adopted September 2026. Questions: Data Protection Officer, privacy@summitqueens.com.