FERPA Compliance Statement
Precision Start™ by Third Eye Education Analytics LLC
Last Updated: April 28, 2026
This statement summarizes how Precision Start™ complies with the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g; 34 CFR Part 99). It is intended for school general counsel and compliance officers reviewing the platform.
1. School Official Designation
Third Eye Education Analytics LLC (“Provider”) operates as a school official with a legitimate educational interest under FERPA's school official exception (34 CFR 99.31(a)(1)).
Legitimate Educational Interest: Provider's role is limited to delivering diagnostic skill grouping and intervention planning services that the school would otherwise perform internally. Provider analyzes pre-unit assessment data to identify prerequisite skill gaps, groups students by shared instructional need, generates intervention lesson plans, and tracks intervention effectiveness — all functions that directly support the school's educational mission.
Supporting Activities: A Data Processing Agreement (DPA) is executed with each school before any student data enters the system. The DPA codifies:
- The educational purpose of the data processing
- Direct control by the school over its data
- Restrictions on re-disclosure
- Use limitations matching FERPA's school official requirements
2. FERPA Compliance Framework
2.1 Direct Control by the School
The school maintains direct control over Provider's processing of Student Data:
- Schools authorize which staff can access the platform
- Schools determine which students' data is processed
- Schools control demographic data sharing; it is provided only on the school's request
- Cross-school analytics requires the school's opt-in and may be withdrawn at any time
- Schools may request data export, modification, or deletion at any time
- Schools own all Student Data; Provider acquires no ownership rights
2.2 Use Limitation
Student Data is used only for the educational purposes described in the DPA:
- Skill-based tier classification
- Prerequisite skill gap analysis
- Instructional grouping
- Intervention plan generation
- Progress monitoring and RTI documentation
- Within-school analytics for system improvement
- Equity reporting (when the school has requested equity analytics and provided its own demographic data)
Student Data is never used for:
- Advertising or marketing
- Commercial profiling
- Sale or licensing to third parties
- Training of any third-party AI model
- Any purpose unrelated to instructional planning
2.3 No Re-Disclosure
Provider does not re-disclose Student Data to third parties except:
- To subprocessors operating under contractual obligations consistent with FERPA (see Subprocessor List)
- When required by law (e.g., subpoena, court order) — with notification to the school where legally permitted
- With the school's explicit written authorization
2.4 Audit Trail
Every access to Student Data is logged with user identity, action taken, resource accessed, school context, and timestamp. Audit logs are available to schools upon request.
3. Specific FERPA Provisions
3.1 Education Records (34 CFR 99.3)
Provider processes records that meet the FERPA definition of “education records” — records directly related to a student that are maintained by an educational agency or institution. Provider maintains these records on behalf of the school.
3.2 Personally Identifiable Information (34 CFR 99.3)
Provider processes the following categories of PII:
- Student names (provided by teachers)
- Assessment performance data
- Tier classifications
- Group assignments
- Progress monitoring data
Provider does NOT process: Social Security numbers, dates of birth, parent contact information, disciplinary records, health records, or any other category of PII beyond what is necessary for instructional grouping.
3.3 Directory Information (34 CFR 99.37)
Provider does not designate any data as “directory information” or release any data in directory information format.
3.4 Parental Rights (34 CFR 99.10–99.22)
Provider supports schools in fulfilling parental rights under FERPA:
- Right to inspect and review: Schools can export complete student records from the platform for parental review
- Right to request amendment: Schools can modify or correct student records within the platform
- Right to consent to disclosure: Provider does not disclose data without school authorization or, where required, written parental consent secured by the school
- Right to file a complaint: Provider supports schools in responding to complaints; Provider's role is limited to data processing and does not involve direct interaction with parents
3.5 De-Identification (34 CFR 99.31(b))
When Provider uses data for cross-school analytics or system improvement:
- All cross-school analysis uses de-identified data with a minimum group size (n ≥ 5) designed to reduce the risk of re-identification
- Demographic data provided by a school is excluded from cross-school analysis; it is used only within that school's own analytics
- De-identification methods follow the FERPA standard: removal of all PII and consideration of whether remaining information could reasonably be used to identify any individual student
4. Data Subject Categories
| Category | Examples | FERPA Treatment |
|---|---|---|
| Student PII | Names, assessment results, classifications | Education records under FERPA |
| Teacher data | Names, emails, override decisions | Not student records; Provider's contractual data |
| Administrator data | Names, emails, processing actions | Not student records; Provider's contractual data |
| Demographic data (on school request) | IEP/504/EL status, race, ethnicity, gender | Education records under FERPA when linked to identified students |
| Audit log data | User actions and timestamps | Education records when they reference identified students |
5. State Law Compliance
In addition to FERPA, Provider complies with:
- District of Columbia Student Data Protection Act
- Other applicable state student privacy laws as Precision Start™ expands to additional jurisdictions
6. Provider's FERPA Commitments
Third Eye Education Analytics LLC commits to:
- Operating exclusively as a “school official” with “legitimate educational interest” under FERPA
- Using Student Data only for the educational purposes specified in our DPA
- Maintaining direct school control over all Student Data
- Limiting access to Student Data to authorized school personnel and our automated processing systems
- Providing audit logs and data exports upon school request
- Supporting schools in fulfilling parental rights under FERPA
- Restricting re-disclosure of Student Data to authorized subprocessors only
- Notifying schools of any compelled legal disclosure where legally permitted
- Returning or deleting Student Data upon school request or end of service
- Cooperating with U.S. Department of Education investigations involving FERPA
7. Documentation and Verification
Schools may request the following documentation to support FERPA compliance review:
- Data Processing Agreement (DPA)
- Privacy Policy
- Subprocessor List with privacy policy links
- Security Overview
- Breach Notification Plan
- Audit log samples (for the school's own data)
- Vendor security questionnaire responses (HECVAT, SIG, custom)
8. Contact for Compliance Inquiries
Andre Aina, Principal
Third Eye Education Analytics LLC
andre@thirdeyeanalytics.org
For general counsel review of contracts: please reference our DPA
This FERPA Compliance Statement supplements our Data Processing Agreement and Privacy Policy. In the event of conflict, the executed DPA governs the relationship between Provider and School.
© 2026 Third Eye Education Analytics LLC. All rights reserved.