This Privacy Policy explains how Hylen Technologies ("we", "us") collects, uses, shares, and protects personal information in connection with Hylen Education. It applies to our marketing website (hylen.education) and to the custom software we build for schools, colleges, universities and other educational institutions (each an "Institution"), together with any Hosted Services we provide for it. Because the Delivered Software belongs to the Institution and is used to run its own community, this policy distinguishes between data we handle on our own behalf and Customer Data we process on behalf of an Institution. Capitalised terms not defined here have the meaning given in our Terms of Service.
1. Who we are
Hylen Education is operated by Hylen Technologies, a company registered in the State of Wyoming, United States, with a registered office at 30 N Gould St, Ste R, Sheridan, WY 82801, USA. Hylen Education is part of the Hylen family (hylen.tech).
For any privacy question, or to exercise a privacy right, contact us at [email protected].
2. Our two roles: processor and controller
The Institution decides what information to collect about its students, families, and staff, and why. In data-protection terms the Institution is always the "controller" of Customer Data. Whether we are a "processor" depends on where the Delivered Software runs.
- Hosted by Hylen. Where we host and operate the Delivered Software for the Institution (Hosted Services), we are the Institution’s processor for Customer Data. We handle it only to provide the Hosted Services, on the Institution’s documented instructions and under our agreement with it.
- Self-hosted by the Institution. Where the Institution runs the Delivered Software on its own servers, the Customer Data stays on infrastructure the Institution controls. We process Customer Data only if and when the Institution gives us access, for example to provide support, and then only on its instructions and for that purpose.
Under US student-privacy law we act as a "school official" performing a service the Institution would otherwise perform itself.
For our website visitors and prospective Institutions, we act as the controller of the limited information described below. This policy covers both situations and notes which applies.
3. Information we collect
Customer Data the Institution puts into its Delivered Software
- Student records — names, dates of birth, guardians, attendance, grades, and any notes an Institution chooses to store.
- Family and guardian contact details.
- Staff and HR records the Institution manages.
- Financial records — fees, invoices, and payroll the Institution runs through its software.
- Operational data — timetables, transport, boarding, store and inventory records.
Information we collect about website visitors
- Contact-form submissions — your name, email, Institution, institution type, hosting preference, and message.
- Basic technical data — IP address, browser type, and pages viewed, used for security and to understand interest. When you first open the site without a language in the address, your IP address is also matched against a country database on our own server, only to choose which language to show you; the result is not stored, and a language you choose yourself always takes precedence.
- Cookies and similar technologies — see our Cookie Policy.
IP geolocation by DB-IP.
Information from running a project with us
- Account holder name and email.
- Institution name and domain.
- Billing and project details.
- Support correspondence with us.
4. How and why we use information
For Customer Data we process on an Institution's behalf, we use it only to provide, secure, and support the Hosted Services or the support we have been asked for, as the Institution instructs, and as set out in our agreement with it.
For data we control (website, prospect, and project and billing data), we rely on the following lawful bases under the GDPR, where applicable, and equivalent principles elsewhere:
- Contract.
- to scope, quote, build and run your project.
- Legitimate interests.
- to secure our systems, prevent abuse, and respond to Institutions that contacted us — balanced against your rights.
- Consent.
- for non-essential cookies and any marketing email, which you can withdraw at any time.
- Legal obligation.
- to meet tax, accounting, and other legal duties.
We do not sell personal information, and we do not use children’s data for advertising.
5. Children’s data (COPPA & FERPA)
The software we build is used by Institutions to educate and support children, so children’s personal information is often processed. We treat it with particular care.
COPPA (United States)
Where the US Children’s Online Privacy Protection Act applies, we collect and process information about children under 13 only on behalf of, and under the authorisation of, the Institution. Institutions provide and manage consent for this processing in their role acting for parents, consistent with the COPPA school-consent framework. We use children’s information only to provide the Hosted Services or support to the Institution — never for our own commercial purposes or advertising.
FERPA (United States)
For Institutions subject to the Family Educational Rights and Privacy Act, Hylen Technologies acts as a "school official" with a "legitimate educational interest" in the education records it processes, under the Institution’s direct control. We use education records only to provide the contracted services and do not re-disclose them except as the Institution directs or the law permits.
Institutions outside the US
We apply the same principle everywhere: we process children’s data strictly on the Institution’s documented instructions and under the GDPR-grade safeguards described in this policy.
7. International data transfers
We are a United States company incorporated in Wyoming, serving Institutions worldwide. Depending on your Institution’s location, personal information may be processed in the United States or in other countries where we or our sub-processors operate.
Where we transfer personal data out of the UK/EEA or other regions with transfer restrictions, we put appropriate safeguards in place — such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) — and take additional measures so your information keeps an equivalent level of protection. Contact [email protected] for details.
8. Data retention
For Customer Data we process on an Institution’s behalf, we keep it while we host it for the Institution, then return and delete it as described in our agreement (typically within a defined window after the Hosted Services end). Where the Institution self-hosts, we do not retain Customer Data beyond any access it grants us for support. For data we control, we keep it only as long as needed for the purpose it was collected, or as the law requires, then delete or anonymise it.
9. How we protect your data
Security is built into what we deliver and host. Key measures for Hosted Services include:
- Isolation — each Institution’s records are kept separate from every other Institution’s, so one Institution’s data cannot appear on another’s screens.
- Encryption — data is encrypted in transit and at rest.
- Access controls — staff access is least-privilege and logged.
- Testing — isolation and security are tested regularly.
No system is perfectly secure, but we work hard to protect your information and will notify the Institution without undue delay if a breach affects Customer Data we host, as required by law and our agreement.
10. Your rights and choices
Depending on where you live, you may have rights over your personal information — including to access, correct, delete, restrict, or object to processing, to port your data, and to withdraw consent. Under the GDPR these are the data-subject rights; several US states provide similar rights.
If your data is held by an Institution, contact the Institution first — as controller it manages these requests, and we assist it. For data we control, contact [email protected] and we will respond within the timeframes the law requires. You also have the right to complain to your local data-protection authority.
11. Exporting and taking your data with you
The Institution can export all of its data at any time, and receives a full export when our agreement ends. We will help it migrate to another system if it ever decides to leave — that is part of our agreement, not an add-on. The Institution’s data is its own, and it also owns the Delivered Software, so it can keep running it without us.
12. Changes to this policy
We may update this policy as our services evolve or the law changes. We will post the new version here with a revised "last updated" date and, for material changes, give Institutions reasonable notice.
13. How to contact us
Questions, requests, or concerns: email [email protected], or write to Hylen Technologies, 30 N Gould St, Ste R, Sheridan, WY 82801, USA.