1. Customer Data ownership
The customer owns and controls its Customer Data. PellLynx.com receives no ownership interest in that data. Use is limited to providing, securing, maintaining, and supporting the service and following authorized customer instructions.
2. Purpose limitation
PellLynx.com does not sell Customer Data, use it for advertising or unrelated profiling, use it to train artificial-intelligence or machine-learning models, or use Student data for direct marketing to Students or families.
3. Tenant separation
PellLynx operates within explicit District or customer context. Server-side authorization validates access to customer-owned records, cross-customer access is prohibited, and administrative workflows involving customer records require authorized context.
4. Role-based access
Institutional roles provide access aligned with assigned responsibilities. Customer administrators manage their authorized users. Platform administration is separately authorized, and access to a District context is limited by the administrative role and operation involved. Access to protected legacy-import information is more narrowly restricted and excludes Platform Support.
5. Encryption
PellLynx uses HTTPS/TLS for connections. Defined sensitive fields are encrypted at rest. Protected Award Notice documents and protected import artifacts, when that separately controlled feature is enabled, use encrypted private storage. These controls do not imply that every database field is individually encrypted.
6. Auditability
PellLynx records meaningful administrative actions and sensitive workflow history. Approved financial decisions and generated Award Notices preserve immutable history, while paid disbursements, refunds, and reversals use append-only ledger behavior. Ordinary audit properties are designed to exclude protected values.
7. Secure operations
Operational safeguards include protected production error handling, controlled deployment, dependency review, forward-safe database practices, queue and scheduler monitoring, protected configuration and secrets, and a rule that real customer data is never used as disposable test data. These practices are reviewed as the service evolves.
8. Backup and recovery
PellLynx.com maintains recovery planning that accounts for coordinated restoration of database records, encrypted private files, and protected encryption-key configuration. Backup protection, integrity verification, retention, and recovery validation must be established and reviewed for the applicable service environment. Where protected backup copies are maintained, they expire according to approved retention schedules. PellLynx.com does not represent that recovery eliminates every risk of data loss or interruption.
9. Confidential administrative access
PellLynx administrative access to Customer Data is limited to authorized personnel with a legitimate operational, security, maintenance, or customer-support need. Administrative access must remain within authorized customer context and is subject to applicable logging and oversight.
10. Service providers
PellLynx.com uses providers only where needed to operate, secure, maintain, and support the service. Providers are subject to appropriate confidentiality and security obligations and may not independently use Customer Data for advertising or sell it.
11. Incident handling
PellLynx.com investigates suspected security incidents, takes reasonable steps to contain and correct confirmed issues, and communicates with affected customers as appropriate under the circumstances and applicable agreements.
12. Data lifecycle
Authorized customers may request an available export. After service termination, they may request deletion of active Customer Data subject to applicable agreements, legal obligations, and approved retention processes. Protected backup copies expire through normal retention schedules, and retained data is not repurposed.
13. Reporting a concern
Report a suspected security or confidentiality concern to support@pelllynx.com. Include enough non-sensitive context for PellLynx.com to identify and investigate the issue; do not send passwords, authentication tokens, or protected Student records by email.
Contact
Questions about this policy may be sent to support@pelllynx.com.