Legal
Privacy Policy
Effective date: September 19, 2026
1. Who We Are
InFocus Pathways (“InFocus,” “we,” “us,” or “our”) operates the InFocus Career Assessment Platform, a web application that helps nonprofit workforce and reentry organizations, K–12 schools, and districts administer career interest, work values, and aptitude assessments and deliver results to participants, students, and the case managers and counselors who support them. Our registered address is available upon request. You can reach us at [email protected].
2. Scope and Applicability
This Privacy Policy applies to all information collected through the InFocus platform, including our website at infocuspathways.com and all associated web application routes. It applies to Program Administrators (School Administrators), Case Managers (Counselors), Evaluators, and Participants (Students) who access the platform under an organization, school, or district subscription. In this policy, “organization” means any nonprofit, school, or district that subscribes to InFocus, and “participant” means any individual whose assessment data is entered or collected on the platform, including students.
InFocus processes participant data solely on behalf of, and under the direction of, the organization with which we have a signed Data Processing Agreement (DPA). The organization is responsible for determining who is enrolled and for having the authority to provide participant information to us. For school and district customers, student data is also governed by the Family Educational Rights and Privacy Act (FERPA) and, where applicable, the Children’s Online Privacy Protection Act (COPPA); see Sections 6 and 7. FERPA and COPPA do not apply to nonprofit deployments serving adults, but the same technical and contractual protections described in this policy apply to every customer.
3. Information We Collect
3.1 Organization and Administrator Information
When an organization creates an account, we collect: organization or school name, district name (for school customers), billing contact name and email address, and billing information processed through Stripe. Stripe is PCI-DSS compliant and no payment card data is stored on InFocus servers.
3.2 User Account Information
For all account holders (Program Admins, Case Managers, Evaluators), we collect: full name, work email address, hashed password, role designation, and multi-factor authentication (MFA) configuration data. Passwords are hashed using bcrypt (cost factor 12) and are never stored in plaintext.
3.3 Participant Data
Participant data is entered by authorized organization personnel and includes: participant name, grade level or program cohort, date of birth (used for age verification, including COPPA compliance for school customers), and assessment responses and scores. Participant data is scoped to the organization that created the record and is never shared across organizations or used for any advertising purpose. Organizations should enter only the information needed to administer assessments and deliver results.
3.4 Assessment Data
We collect responses to the Career Interest Battery (48 items), the Work Values Survey, and manually-entered scores for the InFocus Aptitudes battery. All scoring is performed server-side. No assessment logic executes in the user’s browser.
3.5 Automatically Collected Data
We collect server-side logs including IP addresses, timestamps, and actions taken — stored in an append-only audit log for FERPA compliance and security purposes. We do not use third-party analytics services, advertising pixels, or behavioral tracking technologies on any page of the platform.
4. How We Use Information
We use collected information to:
- Operate and deliver the InFocus platform under the organization’s subscription
- Generate career assessment results, Sweet Spot profiles, and PDF reports
- Authenticate users and enforce role-based access controls
- Maintain security audit logs required by FERPA and our SOC2 commitments
- Send transactional emails (password resets, MFA codes, report delivery) via Resend
- Process subscription billing via Stripe
- Respond to support requests and legal inquiries
Participant and student data is never used for advertising, behavioral targeting, data mining for commercial purposes, or sold to any third party.
5. Data Sharing and Subprocessors
We share data only with the following subprocessors, all of which have signed Data Processing Agreements and are listed in the organization DPA:
| Vendor | Purpose | Touches Participant Data |
|---|---|---|
| Supabase | Database, file storage | Yes |
| Railway | Application hosting | Yes (in transit only) |
| Cloudflare | TLS termination, DNS, DDoS protection, CDN | Yes (in transit only) |
| Resend | Transactional email | Report delivery only |
| Stripe | Subscription billing | No |
| Railway Redis | Rate limiting | No |
No new subprocessor that touches participant personally identifiable information (PII) may be added without updating the DPA and notifying existing organizations in advance.
6. FERPA (School and District Customers)
For school and district customers, InFocus operates as a “school official” under FERPA, meaning we access student education records only to the extent necessary to perform services on behalf of the school. Schools retain ownership and control of all student records. We do not disclose student records to third parties without explicit written consent from the school, except as required by law.
Nonprofit organizations retain the same ownership and control of their participant records, and we apply the same disclosure restrictions: we do not disclose participant records to third parties without the written consent of the organization, except as required by law.
7. COPPA and Minors
InFocus does not permit direct participant account creation. All participant records are created and managed by authorized organization personnel. Organizations attest in the DPA that they have the authority to consent on behalf of parents under COPPA for any participant under 13. Our nonprofit programs are intended for adult participants; an organization that enrolls minors must comply with applicable parental-consent requirements. Participant-facing pages do not contain advertising, behavioral tracking, or third-party analytics.
8. Data Retention
Participant and student records are retained for a minimum of 7 years from the date of last activity, consistent with FERPA records guidance. Organizations may request a shorter retention period, but may not extend the default. Audit logs are append-only and retained for a minimum of 7 years. No hard deletes are performed on participant, student, or user records — deletion requests are fulfilled through a soft-delete process with a full audit trail.
9. Security
InFocus implements the following security controls:
- MFA required for all Program Admin (School Admin) and Case Manager (Counselor) accounts
- Passwords hashed with bcrypt (cost factor 12)
- Account lockout after 5 consecutive failed login attempts
- 90-day password expiry for administrator and case manager/counselor roles
- Append-only audit log with 28+ tracked action types
- HTTPS enforced; HSTS header with one-year max-age
- Content Security Policy (CSP) and X-Frame-Options headers on all responses
- Signed URLs for all file access (15-minute expiry); no public storage buckets
- Row-level security on the database; no cross-organization data access
10. Data Rights
Organizations may, at any time, request a full JSON export of all participant and student data associated with their account or submit a data deletion request through the platform’s Data Rights panel. Deletion requests are logged, reviewed, and fulfilled within 30 days. Individual participant records may also be deleted upon written request from the organization. Individual participants who wish to access, correct, or delete their data should contact the organization that enrolled them; we will assist that organization in responding.
11. Cookies
InFocus uses session cookies strictly for authentication. No advertising cookies, behavioral tracking cookies, or third-party analytics cookies are set. Marketing pages (this page included) do not set any cookies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify organizations via email at least 30 days before the changes take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
13. Contact
Questions about this Privacy Policy or our data practices should be directed to: [email protected].
