Help us improve InternPick

We use optional Google Analytics to understand aggregate site usage. Essential sign-in and security storage remains active either way. Learn more

Skip to main content
Back to home

For schools

Compliance

How InternPick handles student data for work-based learning: a Student Data Privacy Agreement, school-controlled access, and hosts who only see what students share. The agreement is the document counsel reviews.

Compliance · Last updated August 13, 2026

FERPA-ready for schools — with a signed DPA

FERPA does not certify vendors. Schools stay compliant by putting InternPick under a written Student Data Privacy Agreement as a school official. That is the lawful path, and it is built in.

Signed Student Data Privacy Agreement

Your school accepts the Student Data Privacy Agreement at signup. InternPick then acts as a school official for work-based learning — the same model districts use with other instructional vendors.

Your school controls access

You invite staff, students, and hosts. Roles, guardian consent, and retention stay in your Settings. District A cannot see District B.

Hosts only see what students share

Assigned placement hosts see schedule and hours. Resume, phone, and bio stay private until the student opts in. There is no public employer search.

How InternPick and your school work together

InternPick provides and operates the platform. Your school remains the school of record. Students choose what assigned hosts may see beyond schedule and hours.

Your school

  • Invite staff, students, and hosts, and assign roles
  • Approve placements and remain responsible for supervision
  • Keep FERPA notices, consents, and board policy current
  • Name InternPick as a school official in your annual FERPA notice where that fits local practice

InternPick

  • Provide and operate the InternPick platform, including sign-in
  • Enforce the permissions you configure
  • Process student data only to run the features you enable
  • Never sell student data or use it for advertising

Students

  • Choose whether assigned hosts may see resume and contact
  • Log hours and complete placements through the school program
  • Ask the school first for education-record access or deletion

What you can verify today

  • Student Data Privacy Agreement you can accept and shareLive
  • Staff, students, and hosts see only what their role allowsLive
  • Who-can-see map for directory vs host-visible fieldsLive
  • Student opt-in before hosts see resume or phoneLive
  • Access and export history in the change logLive
  • Authenticator MFA for school adminsLive
  • Remove a student’s school records on requestLive
  • Student AI resume assist off until the school turns it onLive
  • Student information system (SIS) syncComing later
  • District single sign-on (SAML / OIDC)Coming later
  • SOC 2 Type II reportComing later

Documents for counsel

Full legal text stays on its own URL. Start here, then send the school data agreement if they want the contract.

  • Student Data Privacy AgreementThe contract counsel reviews
  • Platform agreementFacilitator terms for the school account
  • Privacy PolicyHow InternPick handles personal information
  • Terms of UseSite and account terms
  • CookiesOptional analytics — off until chosen

For counsel & procurement

Data InternPick stores, vendors we use, and answers to common district questions — collapsed so coordinators are not asked to read them first.

What student data InternPick storesOpenClose

Schools decide what to enter. Hosts see only what is needed for assigned placements.

CategoryExamplesPurposeAccess
Institution-managed (Bucket A — FERPA / DPA)Legal / roster name, School / account email, Grade level, GPA, Date of birth / minor flag, Enrollment / membership status, Guardian email, Emergency contactSchool-directed education records under the Student Data Privacy AgreementStudent; school staff with membership. Assigned hosts only see fields the school marks host-visible AND the student has granted host-share consent — never GPA/guardian by default
Student-driven (Bucket B — consent)Student phone, Home address, Professional summary / bio, Work & activity experience, Skills, Resume file / builder content, Portfolio / external links, Career interest areasCareer profile the student authors and may share with assigned placement hostsStudent; school staff. Assigned placement hosts only after explicit student host-share opt-in — no public employer search
Operational (placements & supervision)Placement status & schedule, Hours logs, Program applications, Staff notes, Guardian consent status, In-app messagesWork-based learning operations the school runs in InternPickStudent; school staff; assigned host for their placements/hours/messages as configured — staff notes and applications stay staff-only
Vendors that help run InternPickOpenClose

Third parties that may process student data to deliver the product. We update this list when vendors change.

VendorRoleLocationStudent data
Google Cloud / FirebaseApplication hosting, Authentication, Cloud Firestore, Cloud Storage, Cloud FunctionsUnited States (commercial cloud)Yes — primary datastore and auth for the Service
Google AI / GeminiOptional generative assist (student resume polish/chat when school enables; staff program/copy tools)United StatesYes when school enables Student AI resume assist or a user submits content to an AI feature — prompts are not used by InternPick to train models; Google’s terms apply to API processing
ResendTransactional email (invites, consent links, notifications, support mail)United StatesYes — names/emails (and related message content) needed to deliver school-directed messages
Google Analytics 4 (optional)Product analytics for site/app usageUnited StatesOnly when a visitor opts in via Cookie preferences — not used for student advertising
Common questionsOpenClose

Are you FERPA compliant / FERPA certified?

FERPA does not issue a vendor certificate. What schools need is a lawful way to share education records with a vendor under their direct control.

InternPick is FERPA-ready: when a school accepts our Student Data Privacy Agreement, we act as a school official with a legitimate educational interest under FERPA’s school official exception (34 CFR § 99.31(a)(1)), processing Student Data only to operate the work-based learning features the school enables.

Your school remains responsible for FERPA notices, consents, and board policy. InternPick provides the contract, product controls, and operational commitments described here and in the DPA.

How does the Student Data Privacy Agreement work?

Schools that create an InternPick account accept the Student Data Privacy Agreement (currently v1.0) during onboarding — after InternPick Terms. The full text is always public at internpick.com/dpa and reviewable anytime under Settings → Legal.

Acceptance is recorded with typed legal name, school admin identity, timestamp, and policy version. Existing schools without a current acceptance see a soft reminder for admins; the workspace is not blocked.

If your district requires its own NDPA or state-specific addendum, counsel can use our public DPA as a starting point and execute a separate instrument that supplements or supersedes it as stated in that agreement.

  • Purpose limitation — Student Data used only to provide the Service for authorized educational purposes
  • No redisclosure except to subprocessors under contract, users you authorize, or as required by law
  • School direct control through roles, Settings, program configuration, and this Agreement
  • Retention / deletion on school request or account offboarding as described in-product
  • Parent and eligible-student education-record requests routed through the school; InternPick assists as processor

What does the school control vs what InternPick does?

InternPick is a technology facilitator — not your school of record, employer, placement agency, or insurer. You decide what student information is entered and who may see it.

  • School: invites staff/students/hosts, assigns roles, configures guardian consent, insurance disclosure, retention, and optional school terms
  • School: approves placements, awards credit, and remains responsible for supervision and compliance with board policy
  • InternPick: provides and operates the platform, signs users in, enforces the permissions you configure, and processes Student Data under the DPA
  • InternPick: does not sell student data or use it for cross-context behavioral advertising
  • In-product: Settings → Legal shows live status and links to each control

How do you protect student data technically?

We use commercially reasonable administrative, technical, and organizational measures appropriate for a school work-based learning platform.

  • Encryption in transit (TLS) for web and API traffic
  • Role-based access: school staff see education records for their school; hosts see assigned placements/hours only (not full student profiles)
  • Authentication via Firebase Authentication; data stored in Google Cloud / Firebase services under contractual subprocessors
  • Activity / change logging available to schools for operational review (Settings and Reports)
  • Optional analytics (e.g. GA4) only after an explicit visitor choice — not used to advertise with student data
  • Confirmed Student Data incidents: notify the school without undue delay and, where feasible, within 72 hours of confirmation

Who are your subprocessors?

InternPick engages subprocessors to host and operate the Service. The living list below (and on this page under Subprocessors) is the public inventory schools can share with counsel.

Subprocessors that process Student Data are under contractual confidentiality and data-protection obligations. School admins also see a summary under Settings → Legal.

What student data elements do you collect?

Schools control what is entered. InternPick stores the categories listed in the Data inventory section on this page — identity/contact, academics, guardian contacts, applications/resumes, placements/hours, messages, and consent records — only as needed to run work-based learning features the school enables.

Multi-tenant isolation: Firestore security rules require active school membership (or the student’s own account / assigned host scope) to read Student Data collections. District A staff cannot browse District B rosters. Hosts cannot open full student profiles, resumes, DOB, or guardian data.

What can host employers see?

Hosts are third parties under school direction. InternPick scopes host workspaces to assigned placements only — not Users, Reports, full student education records, or a public employer search.

By default, assigned hosts see minimum-necessary coordination data (placement name, schedule/hours). Resume, bio, phone, and similar student-driven fields require the student’s explicit host-share consent. GPA, guardian contacts, and staff notes stay staff-only.

See Compliance for how InternPick and your school split the work, and Settings → Legal → Who can see student data for field-level controls.

Do you use AI on student data?

Optional Google Gemini assist can help students polish resume content or chat-tailor a resume preview when the school turns on Student AI resume assist (Settings → Profile → Advanced features). The toggle defaults off.

When enabled and a student runs an AI action, InternPick sends the fields needed for that request through our authenticated API to Google’s Generative Language API. InternPick does not use Student Data to train its own models. Staff-facing AI (program copy, branding) uses program/school content, not student roster exports.

Schools that do not want Student Data in AI prompts should leave Student AI resume assist off.

How does school offboarding / deletion work?

School account owners (or a sole admin) can delete the school workspace under Settings → Profile or Workspaces. Deletion runs a server-side cascade: school profile and settings, memberships/invites, school-owned programs and linked placements/applications/hours/messages/files, and school Storage prefixes.

Student and staff InternPick logins are retained; school roster links for that workspace are cleared. Business-owned programs shared into the school are unshared, not deleted from the business.

Export datasets from Reports → Data before delete if you need a local copy. For written purge confirmation after deletion: privacy@internpick.com.

What is your incident response process?

When we confirm a security incident involving unauthorized access to, disclosure of, or loss of Student Data for a school, we notify that school without undue delay and, where feasible, within 72 hours of confirmation (see the Student Data Privacy Agreement).

  • Detect & contain — isolate affected systems and preserve forensic evidence
  • Assess — determine whether Student Data was involved and which school(s)
  • Notify — privacy@internpick.com / hello@internpick.com coordinate school notice with known facts, likely impact, and mitigation steps
  • Remediate & follow up — close the vulnerability, rotate credentials as needed, and provide a written summary the school can use for its own notices
  • Schools remain responsible for parent/eligible-student and regulator notices under FERPA and local policy

How do parents or students request access or deletion?

FERPA access and amendment requests for education records go to the school. InternPick is not the school of record and does not replace your FERPA program.

We reasonably cooperate with the school for data held in the Service. Questions about InternPick’s processing practices: privacy@internpick.com.

What about state student-privacy laws (SOPIPA, SOPPA, NY Ed Law 2-d, etc.)?

Our DPA and product posture are designed to support common U.S. K–12 vendor expectations: purpose limitation, no student-data advertising, school control, breach notice, and deletion on exit.

State laws vary. Districts in stricter states may still require their own DPA exhibits or NDPA. We will work with counsel on those addenda; the public DPA is the baseline engagement document for InternPick.

Are you FISMA or FIPPA compliant?

FISMA applies to U.S. federal information systems. Typical K–12 districts do not require FISMA authorization for a commercial WBL tool. Selling to federal agencies usually involves FedRAMP / NIST control evidence — a security authorization program, not a school click-accept. We do not claim FISMA or FedRAMP authorization today.

FIPPA / MFIPPA are Canadian public-sector privacy laws. InternPick’s current market focus is the United States. Canadian school boards would need a Canada-specific contract package (and often data-residency discussion) before go-live — not covered by the U.S. FERPA DPA alone.

Do you have SOC 2?

SOC 2 Type II is a common third-party security attestation districts request for larger procurements. It is on our roadmap for expanding district sales; it is not a substitute for the FERPA school-official DPA.

Until then, schools can review this page, the DPA, Privacy Policy, and subprocessors, and complete your security questionnaire with our team.

What documents should we send to counsel?

Share this Compliance page plus the linked agreements:

  • Student Data Privacy Agreement — /dpa
  • Platform Facilitator Agreement — /platform-agreement
  • Privacy Policy — /privacy
  • Terms of Use — /terms
  • Cookie Policy — /cookies
  • In-app: Settings → Legal after the school account exists

Contact

Privacy and Student Data questions: privacy@internpick.com.

General support and counsel introductions: hello@internpick.com.

Share this page and the Student Data Privacy Agreement with district counsel if they want the contract. Coordinators can use InternPick as FERPA-ready without a separate vendor certificate.

InternPick.com

InternPick helps schools run internship and work-based learning programs — publish opportunities, review applications, place students with local hosts, and track hours in one platform.

Optional guardian consentSearchable activity records

Request platform access

Share your organization details and email — we will follow up to start onboarding.

Explore
  • Explore
  • For Educators
  • For Business
  • For Students
Get started
  • Sign in
  • Request access
  • Accept invite
Legal & help
  • Compliance
  • Terms
  • Privacy

© 2026 InternPick. All rights reserved. Connecting classrooms to careers. Sponsoring schools handle background check compliance.

Made withfor educational innovation.