FERPA-ready for schools — with a signed DPA
FERPA does not certify vendors. Schools stay compliant by putting InternPick under a written Student Data Privacy Agreement as a school official. That is the lawful path, and it is built in.
Signed Student Data Privacy Agreement
Your school accepts the Student Data Privacy Agreement at signup. InternPick then acts as a school official for work-based learning — the same model districts use with other instructional vendors.
Your school controls access
You invite staff, students, and hosts. Roles, guardian consent, and retention stay in your Settings. District A cannot see District B.
Hosts only see what students share
Assigned placement hosts see schedule and hours. Resume, phone, and bio stay private until the student opts in. There is no public employer search.
How InternPick and your school work together
InternPick provides and operates the platform. Your school remains the school of record. Students choose what assigned hosts may see beyond schedule and hours.
Your school
- Invite staff, students, and hosts, and assign roles
- Approve placements and remain responsible for supervision
- Keep FERPA notices, consents, and board policy current
- Name InternPick as a school official in your annual FERPA notice where that fits local practice
InternPick
- Provide and operate the InternPick platform, including sign-in
- Enforce the permissions you configure
- Process student data only to run the features you enable
- Never sell student data or use it for advertising
Students
- Choose whether assigned hosts may see resume and contact
- Log hours and complete placements through the school program
- Ask the school first for education-record access or deletion
What you can verify today
- Student Data Privacy Agreement you can accept and shareLive
- Staff, students, and hosts see only what their role allowsLive
- Who-can-see map for directory vs host-visible fieldsLive
- Student opt-in before hosts see resume or phoneLive
- Access and export history in the change logLive
- Authenticator MFA for school adminsLive
- Remove a student’s school records on requestLive
- Student AI resume assist off until the school turns it onLive
- Student information system (SIS) syncComing later
- District single sign-on (SAML / OIDC)Coming later
- SOC 2 Type II reportComing later
Documents for counsel
Full legal text stays on its own URL. Start here, then send the school data agreement if they want the contract.
For counsel & procurement
Data InternPick stores, vendors we use, and answers to common district questions — collapsed so coordinators are not asked to read them first.
What student data InternPick storesOpenClose
Schools decide what to enter. Hosts see only what is needed for assigned placements.
| Category | Examples | Purpose | Access |
|---|---|---|---|
| Institution-managed (Bucket A — FERPA / DPA) | Legal / roster name, School / account email, Grade level, GPA, Date of birth / minor flag, Enrollment / membership status, Guardian email, Emergency contact | School-directed education records under the Student Data Privacy Agreement | Student; school staff with membership. Assigned hosts only see fields the school marks host-visible AND the student has granted host-share consent — never GPA/guardian by default |
| Student-driven (Bucket B — consent) | Student phone, Home address, Professional summary / bio, Work & activity experience, Skills, Resume file / builder content, Portfolio / external links, Career interest areas | Career profile the student authors and may share with assigned placement hosts | Student; school staff. Assigned placement hosts only after explicit student host-share opt-in — no public employer search |
| Operational (placements & supervision) | Placement status & schedule, Hours logs, Program applications, Staff notes, Guardian consent status, In-app messages | Work-based learning operations the school runs in InternPick | Student; school staff; assigned host for their placements/hours/messages as configured — staff notes and applications stay staff-only |
Vendors that help run InternPickOpenClose
Third parties that may process student data to deliver the product. We update this list when vendors change.
| Vendor | Role | Location | Student data |
|---|---|---|---|
| Google Cloud / Firebase | Application hosting, Authentication, Cloud Firestore, Cloud Storage, Cloud Functions | United States (commercial cloud) | Yes — primary datastore and auth for the Service |
| Google AI / Gemini | Optional generative assist (student resume polish/chat when school enables; staff program/copy tools) | United States | Yes when school enables Student AI resume assist or a user submits content to an AI feature — prompts are not used by InternPick to train models; Google’s terms apply to API processing |
| Resend | Transactional email (invites, consent links, notifications, support mail) | United States | Yes — names/emails (and related message content) needed to deliver school-directed messages |
| Google Analytics 4 (optional) | Product analytics for site/app usage | United States | Only when a visitor opts in via Cookie preferences — not used for student advertising |
Common questionsOpenClose
Are you FERPA compliant / FERPA certified?
FERPA does not issue a vendor certificate. What schools need is a lawful way to share education records with a vendor under their direct control.
InternPick is FERPA-ready: when a school accepts our Student Data Privacy Agreement, we act as a school official with a legitimate educational interest under FERPA’s school official exception (34 CFR § 99.31(a)(1)), processing Student Data only to operate the work-based learning features the school enables.
Your school remains responsible for FERPA notices, consents, and board policy. InternPick provides the contract, product controls, and operational commitments described here and in the DPA.
How does the Student Data Privacy Agreement work?
Schools that create an InternPick account accept the Student Data Privacy Agreement (currently v1.0) during onboarding — after InternPick Terms. The full text is always public at internpick.com/dpa and reviewable anytime under Settings → Legal.
Acceptance is recorded with typed legal name, school admin identity, timestamp, and policy version. Existing schools without a current acceptance see a soft reminder for admins; the workspace is not blocked.
If your district requires its own NDPA or state-specific addendum, counsel can use our public DPA as a starting point and execute a separate instrument that supplements or supersedes it as stated in that agreement.
- Purpose limitation — Student Data used only to provide the Service for authorized educational purposes
- No redisclosure except to subprocessors under contract, users you authorize, or as required by law
- School direct control through roles, Settings, program configuration, and this Agreement
- Retention / deletion on school request or account offboarding as described in-product
- Parent and eligible-student education-record requests routed through the school; InternPick assists as processor
What does the school control vs what InternPick does?
InternPick is a technology facilitator — not your school of record, employer, placement agency, or insurer. You decide what student information is entered and who may see it.
- School: invites staff/students/hosts, assigns roles, configures guardian consent, insurance disclosure, retention, and optional school terms
- School: approves placements, awards credit, and remains responsible for supervision and compliance with board policy
- InternPick: provides and operates the platform, signs users in, enforces the permissions you configure, and processes Student Data under the DPA
- InternPick: does not sell student data or use it for cross-context behavioral advertising
- In-product: Settings → Legal shows live status and links to each control
How do you protect student data technically?
We use commercially reasonable administrative, technical, and organizational measures appropriate for a school work-based learning platform.
- Encryption in transit (TLS) for web and API traffic
- Role-based access: school staff see education records for their school; hosts see assigned placements/hours only (not full student profiles)
- Authentication via Firebase Authentication; data stored in Google Cloud / Firebase services under contractual subprocessors
- Activity / change logging available to schools for operational review (Settings and Reports)
- Optional analytics (e.g. GA4) only after an explicit visitor choice — not used to advertise with student data
- Confirmed Student Data incidents: notify the school without undue delay and, where feasible, within 72 hours of confirmation
Who are your subprocessors?
InternPick engages subprocessors to host and operate the Service. The living list below (and on this page under Subprocessors) is the public inventory schools can share with counsel.
Subprocessors that process Student Data are under contractual confidentiality and data-protection obligations. School admins also see a summary under Settings → Legal.
What student data elements do you collect?
Schools control what is entered. InternPick stores the categories listed in the Data inventory section on this page — identity/contact, academics, guardian contacts, applications/resumes, placements/hours, messages, and consent records — only as needed to run work-based learning features the school enables.
Multi-tenant isolation: Firestore security rules require active school membership (or the student’s own account / assigned host scope) to read Student Data collections. District A staff cannot browse District B rosters. Hosts cannot open full student profiles, resumes, DOB, or guardian data.
What can host employers see?
Hosts are third parties under school direction. InternPick scopes host workspaces to assigned placements only — not Users, Reports, full student education records, or a public employer search.
By default, assigned hosts see minimum-necessary coordination data (placement name, schedule/hours). Resume, bio, phone, and similar student-driven fields require the student’s explicit host-share consent. GPA, guardian contacts, and staff notes stay staff-only.
See Compliance for how InternPick and your school split the work, and Settings → Legal → Who can see student data for field-level controls.
Do you use AI on student data?
Optional Google Gemini assist can help students polish resume content or chat-tailor a resume preview when the school turns on Student AI resume assist (Settings → Profile → Advanced features). The toggle defaults off.
When enabled and a student runs an AI action, InternPick sends the fields needed for that request through our authenticated API to Google’s Generative Language API. InternPick does not use Student Data to train its own models. Staff-facing AI (program copy, branding) uses program/school content, not student roster exports.
Schools that do not want Student Data in AI prompts should leave Student AI resume assist off.
How does school offboarding / deletion work?
School account owners (or a sole admin) can delete the school workspace under Settings → Profile or Workspaces. Deletion runs a server-side cascade: school profile and settings, memberships/invites, school-owned programs and linked placements/applications/hours/messages/files, and school Storage prefixes.
Student and staff InternPick logins are retained; school roster links for that workspace are cleared. Business-owned programs shared into the school are unshared, not deleted from the business.
Export datasets from Reports → Data before delete if you need a local copy. For written purge confirmation after deletion: privacy@internpick.com.
What is your incident response process?
When we confirm a security incident involving unauthorized access to, disclosure of, or loss of Student Data for a school, we notify that school without undue delay and, where feasible, within 72 hours of confirmation (see the Student Data Privacy Agreement).
- Detect & contain — isolate affected systems and preserve forensic evidence
- Assess — determine whether Student Data was involved and which school(s)
- Notify — privacy@internpick.com / hello@internpick.com coordinate school notice with known facts, likely impact, and mitigation steps
- Remediate & follow up — close the vulnerability, rotate credentials as needed, and provide a written summary the school can use for its own notices
- Schools remain responsible for parent/eligible-student and regulator notices under FERPA and local policy
How do parents or students request access or deletion?
FERPA access and amendment requests for education records go to the school. InternPick is not the school of record and does not replace your FERPA program.
We reasonably cooperate with the school for data held in the Service. Questions about InternPick’s processing practices: privacy@internpick.com.
What about state student-privacy laws (SOPIPA, SOPPA, NY Ed Law 2-d, etc.)?
Our DPA and product posture are designed to support common U.S. K–12 vendor expectations: purpose limitation, no student-data advertising, school control, breach notice, and deletion on exit.
State laws vary. Districts in stricter states may still require their own DPA exhibits or NDPA. We will work with counsel on those addenda; the public DPA is the baseline engagement document for InternPick.
Are you FISMA or FIPPA compliant?
FISMA applies to U.S. federal information systems. Typical K–12 districts do not require FISMA authorization for a commercial WBL tool. Selling to federal agencies usually involves FedRAMP / NIST control evidence — a security authorization program, not a school click-accept. We do not claim FISMA or FedRAMP authorization today.
FIPPA / MFIPPA are Canadian public-sector privacy laws. InternPick’s current market focus is the United States. Canadian school boards would need a Canada-specific contract package (and often data-residency discussion) before go-live — not covered by the U.S. FERPA DPA alone.
Do you have SOC 2?
SOC 2 Type II is a common third-party security attestation districts request for larger procurements. It is on our roadmap for expanding district sales; it is not a substitute for the FERPA school-official DPA.
Until then, schools can review this page, the DPA, Privacy Policy, and subprocessors, and complete your security questionnaire with our team.
What documents should we send to counsel?
Share this Compliance page plus the linked agreements:
- Student Data Privacy Agreement — /dpa
- Platform Facilitator Agreement — /platform-agreement
- Privacy Policy — /privacy
- Terms of Use — /terms
- Cookie Policy — /cookies
- In-app: Settings → Legal after the school account exists
Contact
Privacy and Student Data questions: privacy@internpick.com.
General support and counsel introductions: hello@internpick.com.
Share this page and the Student Data Privacy Agreement with district counsel if they want the contract. Coordinators can use InternPick as FERPA-ready without a separate vendor certificate.