Data Security and Privacy Plan

Nov 2024

The Client: School Districts In the State of New York

The Service Provider: Konstella Inc. (Konstella)

I. Objective and Scope

In providing Software as a Service, Konstella acknowledges that we have a serious obligation to protect the confidentiality of student, parent, staff, and community data in our custody. This Data Security and Privacy Plan (DSPP) outlines the administrative, technical, and physical safeguards used to protect the data we receive from the Client. Personally identifiable information (PII) of students, parents, and staff members is protected under FERPA, PPRA, COPPA, and other federal, state, and local regulations, including NY State Education Law section 2-d. Konstella's Privacy Policy strictly prohibits the sale of sensitive student, staff, and community data under any circumstances or the unauthorized sharing of that data with other parties. Data collected is only used for the approved purposes specified in agreements between Konstella and the Client.

II. Data Security and Privacy Obligations & Policies

1. Allowed and Prohibited Access/Use/Disclosure

Student and staff data provided to Konstella by the District is only to be used by Konstella. Within Konstella, data is only to be shared with employees who have a legitimate need to access it in connection with the agreed-upon services. All employees, whether or not they have access, receive annual security and privacy awareness training. The training will be provided in document/video format followed by questions after every section. Employees' progress will be tracked online by the completeness of every section. In order to provide the agreed-upon services, Konstella must initially receive data from the District's Student Information System (SIS), and also pass some data back. Data Integration standards and processes are in place to ensure that data is transferred securely between the two systems.

2. State/Local Data Privacy Regulations

In accordance with NY State Education Law section 2-d, each district must publish a Parents' Bill of Rights (PBOR), which outlines the District's specific student data privacy responsibilities and expectations. Konstella is also in compliance with federal law requirements, including FERPA and COPPA. Konstella strictly prohibits the sale of sensitive student, staff, and community data under any circumstances or the unauthorized sharing of that data with other parties. Data collected is only used for the approved purposes specified in agreements between Konstella and the Client. Specific requirements include FERPA training for Konstella employees, adequate data protection measures, data breach notification procedures, etc. Other state and federal regulations outline similar requirements. Konstella stays continuously updated on evolving privacy regulations and will work with your district to ensure that you are in compliance.

3. Restrictions on Use and Release of Student Information

Student and staff data, provided to Konstella by the Client is only to be used for the purposes defined in the agreement with the Client. In accordance with applicable data privacy laws and Konstella's privacy policy, Konstella will not sell a student's personally identifiable information or release it for any commercial purposes. Within Konstella, access to student and staff data is only granted to individuals who need such access to perform their job functions in connection with the specific services outlined in the service agreement. Konstella employees are prohibited from accessing this data for any other purpose and are made aware of this restriction through policy and training. Additionally, Konstella implements specific operational policies to enhance data security, including a "Clean Desk Policy." Staff are required to clear all work documents from their desks and lock their screens when away from their desks or computers. Furthermore, we provide detailed guidance to employees on best practices for data protection, including secure handling of sensitive information, ensuring that they understand their responsibilities even in areas not directly controlled by the employer. These measures, along with ongoing training, foster a culture of accountability and vigilance regarding data security.

4. Subcontractors Accessing Student Information

In order to provide the agreed-upon services, it may be necessary to share student or staff information with subcontractors. Konstella maintains written agreements with subcontractors and ensures they abide by the data protection and security requirements specified in the Non-disclosure Agreement with the DOE.

III. Protection of Personally Identifiable Student Information

1. Policies and Procedure

Konstella maintains a full set of security policies covering the 3 major areas of security - confidentiality, integrity, and availability. Specific topics include information sensitivity/classification, privacy obligations, system configuration standards, data retention, encryption, access control, software development guidelines, security monitoring and testing, awareness and training, incident response and business continuity. Policies are distributed to new employees as part of onboarding, reviewed throughout the year as part of ongoing risk assessment and updated according to business/technology changes when appropriate.

2. Infrastructure

Data protection starts with a secure infrastructure. Konstella servers and storage space are hosted on Amazon Web Services. We have an agreement with AWS that contains data privacy and security requirements at least as stringent as those required of Konstella by the DOE in this agreement.

PII data is stored on encrypted disks provided by Amazon Web Services. As Konstella servers and databases are hosted on AWS, Konstella does not have physical access to the data centers and does not have control over who can physically access the data centers. However, the Konstella servers are virtually segmented in their own network. Firewall rules are defined to explicitly allow specific types of traffic based on business needs and deny the rest by default. Intrusion detection and load balancing functions are integrated into the firewall. Data in transit on our network is protected by TLS protocol.

3. Data Access

Konstella employees work remotely. Security for remote employees is ensured in the following ways.

Secure Workspace: SSH & SFTP access is only permitted by certain IP addresses. These IP addresses must only be accessible by Konstella employees with the need to upload/download the data. Rules are reviewed regularly by Konstella's technical team to ensure that only the necessary traffic is being allowed. In addition, access to AWS data centers can only be done from devices owned by Konstella. All Konstella devices constantly run malware detection software (Sophos currently) with automatic updates turned on.

Secure Data Transmission: Data transferred between users' devices and the Konstella server is always encrypted, and typically transmitted in secure industry standard protocols such as SSL or TLS.

Data Access Control: Data access control is governed by the principle of least privilege. Specific users are granted the minimum access needed to perform their job functions. In general, most Konstella internal staff members do not have direct access to education records, with the following exceptions:

Training: Periodic training is given to employees to recognize phishing attempts, suspicious links, or attachments, and report suspicious emails.

IV. Breach Notification Requirements

Konstella continuously monitors its systems for unauthorized activities that may result in the exposure of sensitive data. The purpose of the log monitoring process is to document unusual occurrences in order to spot potential system security and operational problems, including both internal and external threats. Logs are aggregated using a logging mechanism that allows for some automation of the review process. Manual reviews are performed every week. Some critical issues are picked up by alerts on a real-time basis while some issues are flagged for manual review.

Should Konstella become aware of any unauthorized release of student, parent, or staff PII data, in violation of applicable privacy laws, the parents' bill of rights, and/or binding contractual obligations relating to data privacy and security, we will notify the Organization's designated privacy official in the most expedient way possible and without unreasonable delay.

The CTO of Konstella is responsible for the overall information security incident response. Konstella has a small team and does not have a data breach committee. However, it does not mean we do not take data security seriously. When an issue arises, every individual is involved in the process of the investigation and remediation of the issue. The specific process goes as follows.

If there is a valid reason to suspect a breach (i.e., clients report fraudulent activity on their accounts, or we see signs that someone has gained unauthorized remote or physical access to the data center), Konstella will do the following.

  1. Konstella's engineering team will check for common indicators of compromise to determine whether or not a breach has actually occurred. Common indicators of compromise include but are not limited to network traffic anomalies, unusual sign-in attempts, queries to invalid URLs, etc.
  2. Konstella's engineering team will notify CTO and application owners of findings.
  3. CTO will assess the situation and ask the teams and the application owners to conduct additional research as necessary to determine the extent of impact.
  4. CTO will notify CEO who will notify the Client about the incident, our findings, actions taken, and improvement plans if any. The CEO will notify the Client within 24 hours of discovery of a security incident.
  5. The engineering team and the application owners will address the issue and secure the system as necessary.
  6. CTO will review all the findings and the fixes and document them.
  7. CTO will lead the team to continue monitoring the traffic and the log files to make sure the same attack is stopped.
  8. CTO will lead the team to improve the existing safeguards and policies as needed.

If it is determined that a breach has occurred, system(s) or system component(s) may need to be taken offline until they can be locked down with additional security measures (change passwords and certificates, update firewall settings, etc.) An official statement will be issued to the Client, summarizing the findings and providing an estimated time frame for service restoration.

V. Data Retention and Disposal

Student and staff data will only be stored as long as the Client legitimately needs it.

Konstella's data architecture makes it straightforward to remove an individual's data. Upon request of a user, the data along with any backups will be permanently deleted on Konstella servers.

Unless otherwise agreed upon by the parties in writing, Konstella will remove the data from Konstella servers after the effective date of termination or cancellation, following Konstella's standard procedures.