Loading...
HomeMy WebLinkAboutLexia Learning LLC 2015-16Addendum to Lexia Learning Systems LLC Web-Based Products and Services Terms And Conditions Notwithstanding the standard terms and conditions, Lexia Learning Systems LLC, hereinafter referred to as "Licensor" and Bonneville foint Unified School District 93, hereinafter referred to as "School District" agree to incorporate these additional terms and conditions as required by the Idaho Student Data Accessibility, Transparency, and Accountability Act of 201,4,ldaho Code Title 33, Section 133 (hereafter, the "Act"J, with respect to the sharing of personally identifiable information ["PII"] from Student Data, (as defined below) released to Licensor by School District, for purpose of providing Licensor web-based products and services as purchased by School District. 1. Licensor agrees to comply with all applicable Idaho state and federal laws pertaining to the confidentiality and security of PII, including but not limited to the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. 512329 and its implementing regulations, and the Act. 2. Licensor guarantees to have in place appropriate Administrative Securify, Physical Security, and Logical Security controls and measures designed to protect from a Data Breach or unauthorized data disclosure; 3. Licensor agrees to notiE/ School District as soon as possible and without unreasonable delay after Licensor discovers that a Data Breach has occurred, in accordance with Idaho Code 28-51-105. 4. Licensor will restrict access to PII, as defined below, to the authorized staff (including employees, contractors and agents) of the Licensor who require such access to perform their assigned duties and who are under contractual obligations of confidentiality to Licensor; 5. Licensor is prohibited from any secondary use of personally identifiable information, as defined below, including sales, marketing or advertising; 6, Upon written requestby the School District following the termination of the subscription to the web-based products and services provided by Licensor, all records containing PII provided by the School District will be destroyed or returned to the School District within sixty (60J days from the date of request; otherwise Licensor will destroy such PII records within a commercially reasonable period of time. 7. 8. Licensor agrees to accept the following penalties for non-compliance with these provisions resulting in a Violation under the Act: a. The School District's option and right to immediate termination of web-based products and services. Upon receipt of written notice from School District under this provision, Licensor will refund to the School District all fees paid to Licensor for the affected web-based products and services in the current fiscal year, less the amount pro-rated for months ofuse prior to the breach of terms; b. Licensor will indemnify and hold harmless School District and its employees from any and all third-party claims arising from Licensor,s breach of these terms. Defined Terms Administrative Security consists of policies, procedures, and personnel controls, including security policies, training, and audits, technical training supervision, separation of duties, rotation of duties, recruiting and termination procedures, user access control, background check, performance evaluations, and disaster recovery, contingency, and emergency plans, designed to maintain the security and confidentiality of PII and ensure that authorized users know and understand how to properly use the system in order to maintain security of data. Data Breach is the unauthorized acquisition or disclosure of PII in accordance with Idaho Code 28-51-105. Logical Security consists of software safeguards for an organization's systems, including user identification and password access, authenticating, access rights and authority levels designed to maintain the security and confidentiality of PII and ensure that only authorized users are able to perform actions or access information in a network or a worktation. Personally ldentifiable Information (PII) includes: a student's name; the name of a student's family; the student's address; the students'social security number; a student education unique identification number or biometric record; or other indirect identifiers such as a student's date of birth, place of birth or mother's maiden name; and other information that alone or in combination is linked or linkable to a specific student that would allow a reasonable person in the school community who does not have personal knowledge ofthe relevant circumstances, to identiR/ the student. Physical Security describes security measures designed to deny unauthorized access to facilities or equipment and protect such information against anticipated threats or hazards to the security or integrity ofsuch information. Student Data means data collected at the student level and included in a student's educational records as set forth in the Act. Agreed To: Ltta ″