Back to Privacy & Compliance
J M McMillan Enterprises, Inc. — Benefit Corporation

Student Data Privacy Addendum & K-12 Security Whitepaper

Viable Arts platform properties — WOODSHED, WOODSHED+, Future Legends, and NACPA institutional programs. Prepared for school district legal counsel, Chief Technology Officers, and procurement review panels.

Draft v1.2 — August 2026
Draft — for counsel review

This addendum is draft boilerplate prepared for review by counsel to J M McMillan Enterprises, Inc. It is not executed and is not a binding legal instrument until signed by both parties. Districts may substitute their own DPA or a state alliance (SDPC / NDPA) agreement.

1. FERPA Compliance — School Official Designation

Under what recognized FERPA exception does the district transfer student PII, and who retains control?

  • 1.1Recognized exception. J M McMillan Enterprises, Inc. and its platform properties (WOODSHED, WOODSHED+, Future Legends, NACPA) operate strictly as a School Official under the FERPA school official exception at 34 CFR § 99.31(a)(1)(i)(B), performing an institutional service or function the district would otherwise perform using its own employees.
  • 1.2Direct control clause. The district retains direct control over the use and maintenance of all education records. Processing occurs only on documented district instruction, and the district may direct the platform to stop, restrict, correct, export, or delete processing at any time.
  • 1.3Non-commercialization clause. Student PII is never mined, sold, licensed, rented, or used for targeted advertising, and is never used to train AI models outside the district's own tenant. No cross-tenant model training, benchmarking, or product development occurs on identifiable student data.
  • 1.4Legitimate educational interest. Access is limited to individuals with a legitimate educational interest as defined in the district's annual FERPA notification — the rostered director, designated district administrators, and the minimum necessary platform operations personnel under written confidentiality obligation.
  • 1.5No redisclosure. Education records are not redisclosed to any third party without prior written district authorization, except where required by law. Subcontracted processors are bound by equivalent FERPA obligations and remain under district-directed control.
  • 1.6Record isolation. Each performer profile, practice session, assessment record, and telemetry record is scoped to its originating institution at the record level and is not readable across institutions.
  • 1.7Inspection and amendment. Parent and eligible-student requests to inspect or amend records are routed through the district as record owner; the platform supplies the export and correction tooling needed to honor those requests inside FERPA's 45-day window.
  • 1.8Directory information. The platform does not independently designate or publish directory information. Any public display of a student name, image, or performance requires district-confirmed consent on file.

2. COPPA Compliance

How are students under the age of 13 protected during account creation and platform use?

  • 2.1Accounts for students under 13 are created only under verified institutional consent obtained by the school or district acting as agent for the parent, or by direct verifiable parental consent.
  • 2.2No student under 13 may self-register. Minor enrollment is initiated by a chartered director or district administrator.
  • 2.3Practice environments are sandboxed. Minors do not have open public messaging, public profile discovery, or unmoderated social posting.
  • 2.4Collection is limited to what is reasonably necessary for the educational activity — performance metrics, practice telemetry, and assessment scores. No behavioral advertising profiles are built.
  • 2.5Parents and guardians may, through the school, review the information collected about their child, request corrections, and request deletion, and may withdraw consent at any time — which terminates further collection for that student.

3. CIPA Alignment

Does platform content and communication remain compatible with the district's CIPA obligations and E-Rate certification?

  • 3.1Content posture. Instructional and practice content is curated for K-12 use. The platform does not surface adult content, gambling, or unfiltered open-web browsing inside student-facing surfaces.
  • 3.2Minor safety. Student-facing surfaces restrict direct messaging with unknown adults, disable public profile discovery for minors, and route social and video posting through moderation before publication.
  • 3.3Filter compatibility. The platform runs over standard HTTPS on published domains and does not require proxy bypass, VPN tunneling, or filter exceptions that would undermine the district's technology protection measure.
  • 3.4Reporting. Directors and district administrators can report and remove content, and platform operations acts on district takedown requests.
  • 3.5Scope note. CIPA filtering certification remains the district's obligation; the platform is designed to operate compatibly with, not in place of, the district's technology protection measure.

4. Data Encryption, Access Control & Architecture

What verifiable cryptographic standards, access controls, and tenant boundaries are in place?

  • 4.1In transit. All client and server traffic is carried over HTTPS with TLS 1.3 preferred and TLS 1.2 as the negotiated floor. SSL and TLS 1.0/1.1 are disabled, HTTP is redirected to HTTPS, and forward-secret cipher suites (ECDHE key exchange with AES-GCM) are used.
  • 4.2At rest. All databases, file and audio storage, and backups are encrypted at rest using AES-256. Keys are held in the hosting provider's managed key service, are never stored in application code or source control, and are rotated on the provider's standard schedule.
  • 4.3Access control. Access is governed by Role-Based Access Control (RBAC) on a least-privilege basis, enforced at the record level. Instructor, director, and administrator accounts support multi-factor authentication, and MFA can be required district-wide as a condition of the institutional license.
  • 4.4Tenant isolation. Records are partitioned by institution so that Ensemble A cannot read Ensemble B's rosters, acoustic recordings, practice telemetry, or assessment profiles. Cross-tenant read paths are not exposed by the application or its APIs.
  • 4.5Credential handling. Passwords are stored only as salted one-way hashes; no plaintext credentials are retained. API keys and service secrets live in a managed secret store, are injected at runtime, and are never exposed to browser clients.
  • 4.6Hosting and residency. Student data is hosted in United States–based, access-controlled cloud infrastructure with managed encrypted backups and provider-level physical security controls.
  • 4.7Telemetry scope. Analytics layers (internally referenced as Sub-Legion nodes) operate on aggregated and de-identified performance signals. They do not export identifiable student records and do not transmit student PII to external analytics vendors.
  • 4.8Logging. Administrative and privileged actions are logged with actor, action, and timestamp, and log extracts are available to the district for audit review.
  • 4.9Payments. Payment transactions are processed by PCI-DSS compliant third-party processors. Full payment card numbers are never transmitted to or stored on platform systems.
  • 4.10Vulnerability and incident response. Platform and dependency patches are applied on an ongoing basis. Suspected incidents affecting student data are investigated on discovery, contained, and reported to affected districts under applicable state and federal breach-notification requirements, including the detail the district needs for its own notification duties.

5. Data Retention & Deletion SLA

What is the contractual offboarding timeline, and how is permanent deletion evidenced?

  • 5.1Offboarding SLA. All student performance data, uploaded audio and voice recordings, assessment scores, and identifiable telemetry are permanently purged from production systems within 30 days of written district request or contract expiration, and from encrypted backup media within 60 days — after which the records are cryptographically unrecoverable.
  • 5.2Retention period. Records are otherwise retained only for the duration of the active institutional license or charter term, plus a reconciliation window not to exceed 90 days for billing, grant reporting, and dispute resolution.
  • 5.3Contract conclusion. On termination, non-renewal, or expiration, the district elects either export-then-delete (a machine-readable export followed by purge) or immediate purge. Absent district instruction, records are purged at the end of the reconciliation window.
  • 5.4Individual requests. When a student withdraws, transfers, or graduates — or when parental consent is withdrawn — the district may request individual-record deletion on the same 30/60-day SLA without terminating the institutional license.
  • 5.5Scope of deletion. Purge covers the student profile, practice sessions, uploaded audio and media, voice and acoustic profiles, assessment scores, and identifiable telemetry. Deletion is permanent and irreversible once the backup cycle expires.
  • 5.6De-identified data. Only aggregated, de-identified data that cannot reasonably be re-associated with an individual student may be retained for research and program evaluation, consistent with the district agreement.
  • 5.7Audit evidence. Requests, exports, completion timestamps, and written certificates of deletion are recorded and furnished to the district for its own audit and records-retention file.
  • 5.8State records law. Deletion schedules are adjusted on district instruction where state public-records or records-retention law requires a different disposition.

6. Independent Validation & Attestations

What independent, third-party validation supports these claims rather than vendor self-assertion?

  • 6.1Current posture. The statements on this page are presently vendor-asserted. J M McMillan Enterprises, Inc. does not represent that it holds a completed SOC 2 Type II attestation at this time, and does not ask districts to treat self-assertion as independent validation.
  • 6.2HECVAT. A completed HECVAT (Lite or Full) questionnaire is furnished to any district, university, or consortium on request as part of vendor risk review.
  • 6.3SOC 2 roadmap. A SOC 2 Type II readiness path is planned as institutional deployment scales; districts may request the current roadmap, scope, and target window in writing.
  • 6.4Penetration testing. A third-party penetration test summary letter is provided under NDA on request, along with the remediation status of any material findings.
  • 6.5Data Privacy Agreement. The platform will execute the district's own DPA, a state alliance DPA (including SDPC / NDPA-format agreements), or the addendum published on this site, whichever the district's counsel prefers.
  • 6.6Subprocessors. A current list of subprocessors touching student data, and their function, is furnished on request and updated on material change.

7. Federal Grant Alignment

Does the platform support federally funded arts and workforce program requirements?

  • 7.1Program reporting is structured to support arts-education and workforce-development grant narratives, including participation counts, longitudinal growth measures, and outcome reporting.
  • 7.2Assessment and progression records are exportable so districts can substantiate grant-funded program outcomes.
  • 7.3Data handling is designed to remain compatible with district obligations under federal privacy law while participating in federally funded programming.

Execution & District Contact

Districts requesting execution of this addendum, a completed HECVAT, a penetration test summary under NDA, a current subprocessor list, or a certificate of deletion may contact the office below.

J M McMillan Enterprises, Inc.
viablearts@viableartsllc.com
757-969-9554
Authorized District Representative
Date
J M McMillan Enterprises, Inc.
Date