QCCTC Central

Privacy Policy

Proposed effective date: Date of publication System owner and administrator: Jessica Bradford Privacy contact: jessicabradford@qcsd.k12.ms.us

About QCCTC Central

QCCTC Central is a personally owned and administered management system made available by Jessica Bradford for authorized work connected with the Quitman County Career & Technical Center. QCCTC Central is not represented as being owned by the Quitman County School District.

Use of school-issued Google accounts, district email addresses, school or program names, or authorized work records for authentication and operation does not transfer ownership or administration of QCCTC Central to the school district and does not represent the system as district-owned.

This policy explains how QCCTC Central accesses, uses, stores, and shares information when authorized staff use the system.

Who may use the system

QCCTC Central is intended for approved staff accounts. It is not intended for student login or general public account creation. Access is limited through Cloudflare Access, Google authentication, and the approved QCCTC Central role roster.

Information collected

QCCTC Central may process the following information:

QCCTC Central does not request a user's Google password or multifactor-authentication code. Those credentials are handled by Google and Cloudflare.

For managed Support Staff work, Assigned To identifies the person responsible for the work. Entered By and Updated By identify the authenticated Director or Front Office user who electronically created or changed the record. A Support Staff owner who has no login is not represented as the person who entered or updated the record.

How information is used

Information is used only to:

QCCTC Central does not sell personal information and does not use Google user data for advertising.

QCCTC Central does not replace an official district system of record where district policy or applicable law requires information to be maintained in another system.

Google user data

QCCTC Central requests the Google OAuth scopes openid, email, and profile. The application uses the verified Google email and account identifier to match a person to the approved QCCTC Central roster. The display name, role, and program scope shown in Central come from the approved roster.

Google user data is not used to build advertising profiles, sold, or shared for unrelated purposes. Access is limited to the minimum identity information needed for authentication and authorization.

Service providers and disclosure

QCCTC Central uses service providers that process information to deliver the system:

Information may also be disclosed when required by law, to protect the security or integrity of the system, or to authorized organizational personnel who need the information for their assigned responsibilities. Information is not disclosed to unrelated third parties for marketing.

Storage, retention, and deletion

Application records are stored in the production Cloudflare environment. Session identifiers are protected and server-side session tokens are stored as hashes. Workflow history is retained to preserve responsibility, review, correction, completion, and audit evidence.

Information is retained only as long as reasonably necessary for authorized operational, audit, security, records, or legal purposes. A verified user may contact the system administrator to request access, correction, or deletion where deletion is permitted and does not conflict with an applicable record-retention obligation.

Security

QCCTC Central uses Cloudflare Access, Google OAuth, role and program authorization, signed FORM 009 receipts, restricted service credentials, encrypted transport, server-side data validation, and audit history. No system can guarantee absolute security. Suspected unauthorized access should be reported promptly to the privacy contact.

Access may be restricted, suspended, or revoked when a user is no longer authorized, changes roles, violates access requirements, or creates a security risk. Revoking account access does not automatically remove workflow or audit records that must be retained for authorized operational, security, records, or legal purposes.

User responsibilities

Authorized users should enter only information needed for an assigned operational responsibility. Users should avoid placing unnecessary sensitive student, medical, financial, or personal information in free-text notes or evidence fields.

Children and students

QCCTC Central is a staff management system and is not designed for children or students to create accounts. Student-related information, when operationally necessary, should be limited to the minimum information authorized for the staff member's role.

Education records and other protected student information should be handled only as authorized by applicable law and district policy. Users should not enter student information into QCCTC Central merely because a field permits free-text entry.

Changes to this policy

This policy may be updated when system functions, service providers, or data practices change. The public policy will show its effective date. Material changes will be communicated through an appropriate system or staff notice.

Contact

Questions or requests about this policy or QCCTC Central information practices may be sent to:

Jessica Bradford Email: jessicabradford@qcsd.k12.ms.us