Prepared Alert, Inc.

Privacy Policy

For Prepared Alert websites, applications, platform services, and related communications

Privacy by design. Security by responsibility. Student data is never an advertising product.

1. Introduction and Scope

Prepared Alert, Inc. (“Prepared Alert,” “we,” “us,” or “our”) provides a hosted, cloud-based all-hazards emergency preparedness, safety operations, facility planning, crisis communication, and incident-response coordination platform designed primarily for K-12 schools and public facilities (collectively, the “Services”). Depending on the applicable Order and Customer configuration, the Services may include emergency and drill initiation; email, push, and SMS notifications; secure two-way chat and image sharing; event updates and follow-up communications; authorized-user check-ins and reported status or location; emergency plans and digital flip books; procedures and response checklists; facility and site information; incident and drill records; reporting; accountability; reunification; Smart Maps; supported Student Information System integrations; authorized responder access; account administration; onboarding; training; and support. Optional modules and integrations are Processed only when purchased or enabled by the Customer.

This Privacy Policy explains how Prepared Alert collects, uses, discloses, retains, and protects Personal Information and other protected information when individuals visit a Prepared Alert website that links to this Policy, use our web or mobile applications, access our hosted platform, receive communications through the Services, communicate with us, or otherwise interact with Prepared Alert.

When a school, district, public agency, municipality, facility, or other organization (“Customer”) provides information to Prepared Alert or directs us to Process information through the Services, that Customer generally controls the information and the purposes for which it is used. Customer agreements, including a Service Agreement, Data Privacy Addendum (“DPA”), state-specific rider, or Order Form, may provide additional or more specific protections. If an executed Customer agreement imposes greater protections for Customer Data, Prepared Alert will follow those applicable contractual requirements.

This Policy applies to Prepared Alert’s U.S. Services. It does not govern independent third-party websites, products, or services that are subject to their own privacy notices.

2. Our Nationwide Privacy Commitments

Prepared Alert recognizes that schools, public agencies, first responders, and other Customers may entrust us with information that is sensitive from a privacy, safety, security, or physical-security perspective. We therefore apply a baseline of protections to protected Customer information, subject to applicable law and contract.

  • We do not sell, rent, trade, or otherwise monetize Student Data.
  • We do not sell confidential Customer Data or Protected Facility Information.
  • We do not use Student Data for targeted or behavioral advertising or unrelated marketing.
  • We do not use Student Data to create commercial advertising profiles of students, parents, guardians, educators, or school personnel.
  • Prepared Alert does not use Student Data, Customer Data, Protected Facility Information, or identifiable Incident and Safety Information to train generalized artificial-intelligence or machine-learning models. Prepared Alert contractually prohibits AI providers processing protected Customer information from using that information to train general-purpose models.
  • We limit collection, use, and disclosure of Student Data and protected Customer information to authorized service, school, safety, emergency, administrative, support, security, legal-compliance, and contractually authorized purposes.
  • We require subprocessors that Process protected information on our behalf to be subject to appropriate contractual privacy, confidentiality, security, use, retention, and deletion restrictions.
  • Customers retain ownership and control of Customer Data they provide to Prepared Alert, subject to applicable law and contract.
  • We support access, correction, export, return, and deletion of Customer Data as required by applicable law and Customer agreements.
  • We do not attempt to re-identify properly Deidentified Student Data.
  • We do not provide law enforcement, first responders, or other governmental entities with standing, unrestricted, or general-purpose access to Student Data, confidential Customer Data, or Protected Facility Information solely because they are governmental or emergency-response organizations.
  • People, not automated systems, remain responsible for consequential emergency, safety, disciplinary, eligibility, legal, and similar decisions.

3. Definitions

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual, or as otherwise defined by applicable law.

“Customer Data” means information submitted to, stored in, transmitted through, or generated through the Services for or on behalf of a Customer, excluding Prepared Alert’s underlying software, technology, documentation, methodologies, configurations, and properly Deidentified Data.

“Student Data” means Customer Data linked or reasonably linkable to a current or former student, including Education Records and information protected under applicable student-privacy laws as student personal information, pupil records, covered information, or children’s personal information.

“Protected Facility Information” means non-public information concerning a Customer’s physical facilities, security systems, emergency procedures, access points, floor plans, evacuation routes, safety resources, hazards, utility infrastructure, emergency-response capabilities, or similar facility-security information.

“Incident and Safety Information” includes alerts, incident reports, messages, event chat, safety check-ins, reported locations, status updates, response actions, task assignments, acknowledgments, attachments, event timelines, and other information generated or used during drills, training, active incidents, or safety operations.

“Deidentified Data” means information processed so that it cannot reasonably identify or be linked to an individual, taking into account reasonably available means, and that is maintained subject to controls designed to prevent re-identification.

“Process” or “Processing” means any operation performed on information, including collection, access, storage, organization, use, transmission, disclosure, analysis, return, deletion, or destruction.

4. Information We Collect and Process

Account, Identity, and Contact Information. Name, username, account identifier, organization, role, title, email address, telephone number, authentication information, permissions, site assignments, and similar account information.

Facility and Site Intelligence. Floor plans, site maps, facility layouts and photographs, rooms, hallways, entrances, access points, evacuation routes, emergency exits, safety resources and equipment, hazards, utility shut-offs, emergency plans, procedures, checklists, contacts, and other Customer-selected facility or emergency-response information.

Student and Education Information. Prepared Alert does not collect Student Data directly from students. Only when an educational Customer enables a supported Student Information System (“SIS”) integration for a specific site, Prepared Alert may retrieve limited Student Data reasonably necessary for accountability and emergency-response functionality. This data may include student name or identifier, school or site affiliation, courses or class roster, class schedule, and guardian or emergency-contact information. The standard SIS integration does not collect complete academic records, grades or test scores, disciplinary records, Social Security numbers, financial-account information, special-education records, biometric identifiers, or detailed medical records.

Incident, Safety, Drill, and Event Information. Alerts, event messages, secure chat, images and attachments, acknowledgments, check-ins, reported safety status or location, response actions, task information, timestamps, event timelines, delivery information, after-action information, and other incident, drill, training, or emergency-response records.

Communications Information. SMS, email, push-notification and in-app communication content and metadata, delivery information, acknowledgments, responses, and support communications.

First Responder and Partner Information. Authorized agency user identity, organization, role, permissions, Customer-authorized site connections, and information necessary to provide permissioned access to facility or event information.

Business, Support, and Billing Information. Sales inquiries, demonstration requests, implementation information, training participation, support records, contract and billing contacts, survey responses, event registrations, and other business communications. Payment-card information may be processed directly by an authorized payment processor rather than stored by Prepared Alert.

Device, Log, and Usage Information. IP address, browser or device type, operating system, application version, timestamps, pages or features used, diagnostic and crash information, security logs, device identifiers, app configuration, push-notification tokens, and other technical information reasonably necessary to operate, secure, troubleshoot, and improve the Services.

Information from Integrations and Authorized Sources. Depending on Customer configuration, Prepared Alert may receive information from identity providers, emergency communication systems, Customer systems, public-safety partners, mapping or facility systems, and other Customer-authorized integrations. Student Data is retrieved only from a supported SIS integration that the Customer has enabled for the specific site and is limited to the data described in this Policy.

5. Mobile Applications, Location, and Safety Status

Prepared Alert mobile applications may Process device information and permission-dependent information required for enabled features used by authorized adult users. During an incident, drill, evacuation, training exercise, or other authorized event, those users may provide or update a location, room-level location, safety status, check-in status, availability, or other response information. This information may be visible to authorized Customer personnel and, where configured by the Customer, authorized emergency-response partners. Students do not submit location, safety-status, or check-in information through the standard Services.

Location or safety-status reporting by an authorized adult user does not necessarily mean Prepared Alert continuously tracks the precise geographic location of that user’s device. Prepared Alert does not continuously collect precise device location unless a specific feature requires it, the applicable Customer and user have enabled the feature, device permissions permit it, and the Processing is permitted by applicable law. Prepared Alert does not collect device location from students through the standard Services.

6. How We Use Information

  • Provide, configure, authenticate, operate, maintain, secure, support, troubleshoot, and improve the authorized Services.
  • Maintain facility intelligence, Smart Maps, emergency plans, safety resources, drills, training, preparedness workflows, and Customer documentation.
  • Deliver Customer-authorized emergency and operational communications through app push notifications, SMS, email, and other configured channels.
  • Facilitate incident coordination, event chat, check-ins, accountability, reunification, task management, status reporting, event timelines, reporting, and after-action review.
  • Provide Customer-authorized first responders and response partners with permissioned access to relevant site intelligence and event context.
  • Administer accounts, role-based permissions, site assignments, integrations, and organizational access.
  • Provide implementation, training, documentation, support, diagnostics, and Customer-authorized analytics.
  • Maintain the security, integrity, availability, and proper operation of the Services; prevent misuse, fraud, and unauthorized access.
  • Comply with law, lawful process, Customer contracts, and regulatory obligations; establish or defend legal claims; and enforce agreements.
  • Create aggregated or Deidentified Data for lawful analytics, security, service improvement, and reporting, subject to controls designed to prevent re-identification.

Where SIS-derived Student Data is used to provide, maintain, support, improve, or diagnose the Customer-authorized Services, that use remains within the authorized school-service context and is not used for independent commercialization, targeted advertising, generalized AI model training, or unrelated product development.

7. Student Data, FERPA, and Education Records

Prepared Alert applies heightened protections to Student Data. We do not sell or rent Student Data, use Student Data for targeted or behavioral advertising, create commercial advertising profiles from Student Data, or use Student Data for an independent commercial purpose unrelated to the authorized Services.

When an educational institution discloses Education Records to Prepared Alert under FERPA’s school-official exception, Prepared Alert uses those records only for the purpose for which they were disclosed, remains subject to the institution’s direct control regarding use and maintenance of those records through the applicable agreement, and limits redisclosure as required by FERPA.

Parents and eligible students should generally submit requests to inspect, correct, amend, delete, or otherwise exercise rights regarding Education Records to the applicable school or educational institution. Prepared Alert will reasonably assist the institution as required by applicable law and contract.

8. SIS and Customer-Authorized Integrations

Prepared Alert may support Customer-authorized integrations with SIS, identity, communications, mapping, or other systems. The Customer determines which supported integrations to enable. Student Data is retrieved only through a supported SIS integration that the Customer enables for a specific site; the Customer determines which of the limited SIS data elements described in this Policy Prepared Alert is authorized to receive or Process. Prepared Alert limits integration data to information reasonably necessary for the enabled functionality.

A supported SIS integration does not mean Prepared Alert requires or accesses every category maintained in a Customer’s SIS. Prepared Alert does not use SIS-derived Student Data for advertising, unrelated marketing, commercial profiling, sale or monetization, generalized AI model training, or unrelated product development. Prepared Alert does not use custom integrations or other third-party sources to retrieve additional Student Data unless this Policy and the applicable Customer agreement are first updated as required by law.

9. Children’s Privacy and COPPA

Prepared Alert’s Services are provided to schools, districts, public facilities, and authorized adult personnel. Students cannot create accounts, directly access the standard Services, or submit Personal Information through the standard Services. Prepared Alert’s general public website is not directed to children under 13 and is not intended to solicit Personal Information from them.

Student Information System (SIS) Data

If an educational Customer enables a supported SIS integration for a specific site, Prepared Alert retrieves limited SIS data solely for Customer-authorized accountability and emergency-response purposes:

  • The SIS data may include student name or identifier, school or site affiliation, courses or class roster, class schedule, and guardian or emergency-contact information.
  • Prepared Alert does not retrieve Student Data from an SIS unless the Customer has enabled the integration for the specific site.
  • Outside an active emergency, SIS-derived Student Data is accessible through the Services only to authorized Customer administrator users with appropriate permissions. During an authorized emergency, relevant data may be made available to other Customer-authorized personnel or emergency-response partners as configured or directed by the Customer and permitted by law.
  • Prepared Alert Processes SIS-derived Education Records under the Customer’s direction and a FERPA-permitted basis identified by the Customer, including the school-official arrangement for routine authorized Services and, when its legal requirements are satisfied, the health-or-safety emergency exception.

Prepared Alert does not knowingly collect Personal Information directly from children under 13 through the standard Services. When COPPA applies and a school is legally permitted to consent on behalf of a parent for school-authorized use, Prepared Alert uses the child’s Personal Information only for the use and benefit of the school and the authorized Services, not for an unrelated commercial purpose. Parents and guardians should direct requests to review, correct, or delete Student Data, or to stop further collection, to the applicable school or district. Prepared Alert will assist the school with valid requests and applicable notice, review, deletion, and cessation-of-collection requirements. A school’s authorization does not eliminate Prepared Alert’s independent obligations under applicable law.

10. PPRA and Sensitive Information

Prepared Alert does not administer or independently require students to complete surveys concerning topics protected by the Protection of Pupil Rights Amendment (“PPRA”).

Emergency and safety operations may involve sensitive information concerning authorized adult users or other incident participants, including emergency contacts, voluntarily or organizationally provided health or accessibility information, incident narratives, reported location, threat information, or response actions. Prepared Alert limits use of such information to authorized functionality, safety, support, security, legal compliance, and protection of people or systems. Student Data is limited to the Customer-authorized SIS data described in Sections 4 and 9. Customers should not submit specially regulated data that is unnecessary for the Services.

11. Smart Maps and Protected Facility Information

Prepared Alert treats non-public floor plans, Smart Maps, site photographs, emergency procedures, access points, utility information, security resources, and similar facility intelligence as protected Customer information. Customers control the source materials they provide and are responsible for reviewing and maintaining the accuracy and currency of Customer-provided facility and emergency information.

12. First Responders and Emergency Disclosures

A Customer may authorize police, fire, emergency medical services, emergency-management organizations, or other response partners to receive permissioned access to relevant facility intelligence or incident context. Prepared Alert does not provide such entities with standing, unrestricted, or general-purpose access to Student Data, confidential Customer Data, or Protected Facility Information solely because they are governmental or emergency-response organizations.

Prepared Alert may preserve or disclose information when reasonably necessary and legally permitted to address an imminent health or safety threat, protect users or the public, investigate a safety or security matter, secure the Services, comply with valid legal process, or satisfy another legal obligation. Emergency access does not create unrestricted future access.

13. How We Disclose Information

  • To the Customer and its authorized users in accordance with permissions and Customer configuration.
  • To Customer-authorized first responders, agencies, and response partners for authorized safety or emergency-response purposes.
  • To subprocessors and service providers supporting hosting, infrastructure, communications, integrations, billing, security, support, and other functions, subject to appropriate contractual restrictions.
  • At the Customer’s direction or with appropriate authorization.
  • When reasonably necessary and legally permitted to address an imminent health or safety threat, protect a person or the Services, investigate a security or safety matter, or comply with law or valid legal process.
  • In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to applicable law and contractual restrictions governing protected Customer information.

Prepared Alert does not sell or rent Student Data. We do not use Student Data for targeted advertising, create commercial advertising profiles from Student Data, or disclose Student Data for unrelated commercial purposes.

14. Service Providers and Subprocessors

Prepared Alert uses third-party service providers and subprocessors to support the Services. Prepared Alert currently uses Amazon Web Services (AWS) and Google Cloud for U.S.-based hosting and platform services. Stripe processes payment and billing information and is not intended to receive Student Data as part of standard payment processing. Customer-authorized integration providers may facilitate Customer-directed connections, including supported SIS integrations enabled for a specific site. Google LLC provides Google Analytics 4 for analytics on Prepared Alert's public-facing website and is not intended to receive Student Data or protected Customer information.

A subprocessor that Processes protected Customer information on Prepared Alert’s behalf must be subject to written obligations appropriate to its role concerning confidentiality, security, authorized use, incident response, retention, and deletion. Any integration provider that Processes Student Data on Prepared Alert’s behalf is treated as a subprocessor. Prepared Alert remains responsible for its applicable privacy and contractual obligations when using subprocessors. Prepared Alert may update its service providers as the Services evolve, and current subprocessor information is available upon Customer request where required by law or contract.

15. Artificial Intelligence

Prepared Alert does not currently offer AI-assisted functionality as part of its launch Services. If Prepared Alert introduces an AI-assisted feature in the future, availability will depend on the applicable product configuration and Customer authorization, and the feature will be subject to appropriate privacy, contractual, security, and human-review controls.

Prepared Alert does not use Student Data, Customer Data, Protected Facility Information, or identifiable Incident and Safety Information to train generalized artificial-intelligence or machine-learning models. Prepared Alert contractually prohibits AI providers processing protected Customer information from using that information to train general-purpose models. If an AI-assisted feature is introduced, Prepared Alert will not disclose personally identifiable Student Data to an AI provider except as necessary for a Customer-authorized feature, with appropriate contractual and security protections, and as permitted by law.

AI-generated content, if offered, is assistive and may be incomplete or inaccurate. It should not be the sole basis for consequential emergency, safety, disciplinary, eligibility, legal, or similarly significant decisions.

16. Deidentified and Aggregated Data

Prepared Alert may create and use Deidentified or aggregated information for lawful analytics, security, service improvement, reporting, benchmarking, and research, provided the information is maintained in a form that cannot reasonably identify or be linked to a student, individual, Customer, specific site, or specific incident where such identification is not authorized. Prepared Alert will not attempt to re-identify Deidentified Student Data. Where required, recipients are subject to restrictions against re-identification and unauthorized use.

17. Information Security

Prepared Alert maintains reasonable administrative, technical, and organizational safeguards designed to protect information appropriate to its nature and sensitivity. Production Customer Data is stored in the United States and encrypted at rest and in transit. Prepared Alert uses role-based access controls and limits personnel and contractor access to individuals who need access to provide, secure, maintain, or support the Services and who are subject to appropriate confidentiality obligations. Additional safeguards may include authentication, logging and monitoring, vulnerability and patch management, secure development practices, backup and recovery, incident response, vendor risk management, and secure disposal.

Prepared Alert does not represent that it holds a particular security certification, audit report, penetration-testing cadence, or security control unless separately documented in current written security materials or an executed agreement. No method of electronic transmission or storage can be guaranteed to be completely secure.

Customers and authorized users are responsible for protecting credentials, devices, administrative access, authorized-user lists, and configurations within their control and for promptly notifying Prepared Alert of suspected unauthorized access.

18. Security Incidents

If Prepared Alert discovers a Security Incident affecting protected Customer information, Prepared Alert will investigate and take reasonable steps to contain, mitigate, and remediate the incident and will provide notice to the affected Customer without unreasonable delay and within any shorter period required by applicable law or an executed Customer agreement. Initial notices may be supplemented as additional material information becomes available.

Unsuccessful login attempts, scans, blocked attacks, pings, ordinary service outages, or other events that do not compromise protected information are not treated as Security Incidents solely because they occurred.

19. Data Retention, Export, and Deletion

Prepared Alert retains information for the period reasonably necessary to provide the Services, satisfy Customer instructions and contractual requirements, protect the Services, maintain legitimate business records, and comply with applicable legal obligations. Customer-specific retention, export, and deletion requirements may be stated in the applicable Service Agreement, DPA, Order Form, or state rider.

Following termination, Customers may have an opportunity to export Customer Data through available functionality or a support process before required deletion. Protected information remaining temporarily in backups remains protected and is deleted or overwritten through the applicable backup cycle, subject to legal holds, litigation-preservation requirements, regulatory obligations, and other legally required retention.

Prepared Alert does not retain Student Data indefinitely merely because it could potentially be useful for a future incident, investigation, analytics project, or product-development activity.

20. Cookies, Analytics, and Website Technologies

Prepared Alert may use cookies, local storage, session technologies, logs, and similar technologies reasonably necessary for website and application functionality, authentication, security, preferences, diagnostics, analytics, and service improvement. Student Data is not used for cross-context behavioral advertising.

Where applicable law requires consent or provides an opt-out right for a particular non-essential website technology, Prepared Alert will provide appropriate notice or controls. Browser or device settings may also allow users to manage certain technologies.

Google Analytics

Prepared Alert uses Google Analytics 4 on its public website to understand traffic and improve content. It may collect cookie, website usage, device, approximate location, and online identifier data, but Prepared Alert does not send Student Data or authenticated Service data to Google Analytics or use it for advertising or remarketing; see How Google uses information from sites that use its services and Google Privacy Policy.

21. Marketing Communications

Prepared Alert may use adult business-contact information to communicate with prospects, Customers, and partners about demonstrations, product information, events, implementation, support, and related Prepared Alert services. Recipients may opt out of non-transactional marketing communications through an available unsubscribe mechanism or by contacting Prepared Alert. Student Data is never used for marketing.

SMS Privacy and Event Notifications

Prepared Alert sends SMS messages only when a Customer-authorized drill or incident starts, changes status, or ends, and only to users who have affirmatively opted in and are configured to receive SMS notifications for that event type. Prepared Alert does not send marketing or promotional text messages.

Prepared Alert uses mobile numbers and related delivery, consent, response, and opt-out records only to deliver and support these event notifications, secure the Services, and comply with law. Prepared Alert does not sell, rent, or share mobile numbers, SMS opt-in information, or consent records with third parties or affiliates for their own marketing or promotional purposes. Communications providers receive only the information necessary to deliver and support messages. Recipients may reply STOP to opt out or HELP for assistance. Message frequency depends on drills and incidents, and message and data rates may apply.

22. Privacy Rights and Requests

Account and Associated Data Deletion

To request deletion of your Prepared Alert account and associated personal information, email privacy@preparedalert.com and identify the email address associated with your account and your organization. You do not need to access or reinstall the app to submit a request. We may verify your identity and coordinate with your organization for Customer-controlled records. Within sixty (60) days of receiving your request, we will delete your account and delete or de-identify associated personal information in production systems, subject to applicable legal retention requirements and other lawful exceptions. Any retained information remains protected. Residual copies of information deleted from production systems may remain in protected backups for up to thirty (30) additional days before deletion or overwriting, for a total of up to ninety (90) days after receipt of your request, subject to applicable legal retention requirements. Shorter periods required by applicable law or Customer agreements will apply.

Depending on applicable law, an individual’s jurisdiction, statutory thresholds, and available exemptions, individuals may have rights to access or know Personal Information, correct inaccuracies, delete information, obtain a portable copy, limit certain uses, opt out of certain processing, or appeal certain privacy-request decisions.

For Student Data, Education Records, and other Customer-controlled information, individuals should generally contact the applicable school, district, agency, employer, or other Customer first. Prepared Alert will reasonably assist the Customer with valid requests as required by law and contract.

For Personal Information that Prepared Alert controls directly, requests may be submitted to privacy@preparedalert.com. Prepared Alert may request information reasonably necessary to verify identity, authority, residency, and the relationship to the requested information. Prepared Alert may deny, limit, or retain information where permitted or required by law.

23. State-Specific Student and Privacy Protections

Prepared Alert serves Customers across the United States and applies mandatory federal and state student privacy and general privacy requirements applicable to its role and Services. Requirements vary by jurisdiction, and Prepared Alert may use state specific or Customer specific supplements where legally or contractually required.

Applicable state privacy supplements are provided through Customer agreements or upon request at privacy@preparedalert.com. When public state supplements are posted, they will be linked from the online version of this Policy. If an applicable supplement or executed Customer agreement provides greater privacy protections, the more protective applicable terms control.

Prepared Alert reviews legal demands for Customer Data and seeks to disclose only information it reasonably believes is required or legally permitted. Where legally permitted and appropriate, Prepared Alert will seek to notify the relevant Customer before disclosure.

Public-sector Customers may be subject to public-records or freedom-of-information laws. The Customer is generally responsible for determining whether a Customer record is subject to disclosure. Prepared Alert will reasonably assist with requests relating to Customer Data in its possession when required by law or contract. Nothing in this Policy requires Prepared Alert to waive protections applicable to its own trade secrets, proprietary technology, confidential security information, or other information exempt from disclosure.

25. Business Transfers and Successors

If Prepared Alert is involved in a merger, acquisition, financing, bankruptcy, reorganization, sale of substantially all assets, or other business transfer, information may be reviewed or transferred as part of that transaction subject to applicable law, contractual restrictions, and appropriate confidentiality protections. A successor receiving protected Customer information remains subject to applicable legal and contractual restrictions for so long as it retains or Processes that information.

26. No Emergency-Service or Safety Guarantee

Prepared Alert provides technology that supports preparedness, communication, situational awareness, information sharing, and incident coordination. The Services do not replace 911 or other emergency services, and Prepared Alert does not provide emergency dispatch, law enforcement, firefighting, emergency medical services, or other first-responder services.

No technology can prevent every emergency, ensure that a communication will always be delivered or received, guarantee a particular response time or outcome, or ensure that Customer-provided information is complete or accurate. Customers remain responsible for emergency decisions, procedures, legal obligations, personnel actions, and appropriate use of emergency services.

The Services may interoperate with third-party products, integrations, communications networks, app stores, websites, or services. A Customer’s or user’s use of an independent third-party service may be governed by that third party’s own terms and privacy notice. Prepared Alert is not responsible for the independent privacy practices of third parties that are not acting as Prepared Alert subprocessors.

28. Changes to This Privacy Policy

Prepared Alert may update this Privacy Policy to reflect changes in the Services, practices, technology, legal requirements, or business operations. We will post the updated version with a revised “Last Updated” date.

Where applicable student-privacy law or an executed Customer agreement requires additional notice, consent, or authorization for a material change affecting the collection, use, or disclosure of Student Data or other protected Customer information, Prepared Alert will follow those requirements before applying a materially inconsistent practice to previously collected protected information.

29. Contact Us

Questions or requests concerning this Privacy Policy or Prepared Alert’s privacy practices may be directed to:

Prepared Alert, Inc.
Privacy: privacy@preparedalert.com
Security: security@preparedalert.com
Support: support@preparedalert.com
Legal / Contracts: legal@preparedalert.com
Website: preparedalert.com

For K-12 Customers, this public Privacy Policy should be read together with the applicable Prepared Alert Service Agreement and Data Privacy Addendum. Those contractual documents may provide more detailed requirements concerning Student Data, FERPA, COPPA, subprocessors, security incidents, retention, deletion, SIS integrations, state-specific obligations, and Customer-specific requirements.