Legal · Privacy
Privacy Policy and Data Processing Notification
1. Preliminary Declarations & Scope
This document governs the collection, processing, and retention of personal data within the SGA Sync multi-tenant application. It is designed for university Student Government Associations (SGAs), collegiate legislative assemblies, and student executive councils. By accessing the platform, users acknowledge the processing of their data in accordance with this policy.
We prioritize Institutional Stability; therefore, we expressly declare that SGA Sync does not sell, rent, monetize, or trade personal data or student records to any third party or data broker. No third-party advertising or cross-site tracking pixels are deployed within the platform.
2. Notice at Collection and Categories of Personal Data
To maintain Accountable Action, we collect and process specific categories of data exclusively to facilitate institutional governance and secure system operations.
| Category of Data | Specific Data Points | Purpose of Processing |
|---|---|---|
| Account & Profile | Full name, institutional (.edu) email address, profile photo/avatar URL, optional phone number, biographical statement. | Account authentication, identity verification, role-based access control (RBAC), and legislative roster management. |
| Institutional & Role Data | University/college affiliation, official title, committee assignments, voting eligibility, term dates. | Determining voting rights, meeting quorums, committee authority, and document access permissions. |
| Governance Records | Recorded roll call attendance, legislative votes, parliamentary motions, bill sponsorship, speaking times, submitted minutes. | Official institutional governance record-keeping. Maintaining democratic transparency and legislative archives. |
| User-Authored Content | Uploaded context resources, legislative drafts, resolution texts, meeting agendas, committee notes, internal announcements. | Enabling legislative drafting, collaboration, and archival storage for student government operations. |
| AI Deliberation Queries | User questions submitted to "Sync AI", meeting transcripts for auto-summaries, document text sent for analysis. | Providing parliamentary guidance, legislative summaries, and agenda preparation via server-side AI processing. |
| Technical & Audit Logs | IP address, browser user-agent, timestamps of system actions, modification history of bills/users/settings. | Security auditing, fraud prevention, tracking unauthorized privilege modifications, and ensuring vote integrity. |
3. Authorized Sub-Processors
To execute our services, SGA Sync utilizes authorized third-party data processors. We bind all sub-processors to strict confidentiality and security obligations.
| Sub-Processor | Entity Location | Role & Purpose | Data Shared | Contractual Safeguards |
|---|---|---|---|---|
| Google Cloud / Firebase | United States | Primary database (Firestore), User Authentication (Firebase Auth), secure file storage. | User profiles, hashed passwords, institutional emails, database documents, governance records. | Subject to Google Cloud Data Processing Addendum (DPA) incorporating standard legal protections. |
| Google Gemini API | United States | AI inference engine powering "Sync AI" and parliamentary query processing. | User queries, governing documents your SGA has uploaded, legislative excerpts and meeting records, sent via server-side API proxy. | Data is transmitted securely via a server-side proxy and used only to generate responses. Governing documents may be held in Google's temporary file storage for up to 48 hours, then deleted automatically. Never used to train public foundational AI models. |
| Vercel Inc. | United States | Frontend hosting, edge routing, CDN, and serverless compute (/api/*). | IP addresses, HTTP request headers, serverless execution logs, transit data. | Subject to a standard GDPR-compliant Data Processing Addendum (DPA) incorporating European Standard Contractual Clauses (SCCs). Processes data solely to deliver service. |
| Resend, Inc. | United States | Delivery of member invitation emails. | The invited member's email address, the inviting administrator's email address, the campus name, and a single-use sign-in link. | Data is shared solely to deliver invitation emails. |
| Google Fonts | United States | Web typography (Fraunces font). | Client IP address upon initial asset fetch. | IP addresses are processed strictly on a transactional basis to retrieve font assets. |
4. Educational Compliance & FERPA
SGA Sync does not request, require, or store the categories of education records that FERPA treats as most sensitive, including:
- Academic records: grades, transcripts, class schedules, and test scores.
- Disciplinary records: behavioral reports and disciplinary actions.
- Financial information: tuition payments, financial aid, and scholarships.
- Health and medical records: records maintained by a school nurse or health clinic.
- Special education files: Individualized Education Programs (IEPs).
- Personal identifiers: Social Security numbers, student ID numbers, and birth dates.
User profiles are limited to directory-style information, such as full name, institutional email address, class year, major, profile photo, and an optional phone number visible only to administrators. Because users can upload documents and enter free text, we ask that the records listed above never be entered into the Platform, and our Terms of Use prohibit submitting protected student records to Sync AI.
5. California Privacy Rights (CCPA / CPRA / CalOPPA)
SGA Sync issues this affirmative declaration for residents of California: We do not sell or share your personal information for cross-context behavioral advertising. You possess the right to:
- Request access to the specific pieces of personal information we have collected.
- Request the correction of inaccurate data.
- Request the deletion of your personal data, subject to mandatory institutional retention requirements.
Requests may be submitted to privacy@sgasync.com.
6. European Economic Area (GDPR / UK GDPR)
For users located in the European Economic Area or the United Kingdom, we process personal data under the following lawful bases:
- Performance of a Contract: Essential for serving the student government platform.
- Legitimate Interests: Required for institutional governance, security auditing, and system integrity.
- Consent: Utilized for optional profile fields.
Data subjects maintain the right to access, rectify, request data portability, and request erasure ("Right to be Forgotten"). Erasure requests will be fulfilled unless the data must be retained to comply with a legal obligation or official public institutional retention rules.
7. Artificial Intelligence & Data Transmission
The application utilizes an artificial intelligence feature ("Sync AI") to support parliamentary procedure. When utilizing this feature, queries, document text, and meeting transcripts are transmitted securely via a server-side API proxy to the Google Gemini API. This data is used only to generate responses. Governing documents may be held in Google's temporary file storage for up to 48 hours so they do not have to be re-sent with every question, after which Google deletes them automatically. No personal data is utilized to train public foundational AI models. Google may retain this data for a limited period solely to detect abuse and meet legal obligations; it is not used to improve Google's products.
8. Technical Safeguards, Retention, and COPPA
- Cookies and Tracking: We utilize strictly necessary local storage and session cookies exclusively for session authentication, active tenant identification, and user interface preferences. We deploy zero cross-site tracking cookies.
- Analytics: We use privacy-friendly, cookieless analytics (Vercel Analytics) to monitor website performance, aggregate visitor counts, and page load speeds without storing cookies or tracking individual personal identities.
- Data Retention: Data is retained only for the duration necessary to fulfill the operational requirements of the institutional tenant, or as mandated by statutory public records archiving obligations.
- Children's Privacy (COPPA): SGA Sync is explicitly designed for college and university students (typically ages 17 and older). The platform is not directed to children. We do not knowingly collect personal information from individuals under the age of 13.
9. Amendments and Accountable Action
We reserve the right to amend this policy to reflect changes in legal, regulatory, or operational requirements. Material changes will be communicated via institutional administrative channels or through platform notifications. Continued use of SGA Sync following modifications constitutes binding acceptance of the updated terms.