Proposed effective date: Date of publication System owner and administrator: Jessica Bradford Privacy contact: jessicabradford@qcsd.k12.ms.us
About QCCTC Central
QCCTC Central is a personally owned and administered management system made available by Jessica Bradford for authorized work connected with the Quitman County Career & Technical Center. QCCTC Central is not represented as being owned by the Quitman County School District.
Use of school-issued Google accounts, district email addresses, school or program names, or authorized work records for authentication and operation does not transfer ownership or administration of QCCTC Central to the school district and does not represent the system as district-owned.
This policy explains how QCCTC Central accesses, uses, stores, and shares information when authorized staff use the system.
Who may use the system
QCCTC Central is intended for approved staff accounts. It is not intended for student login or general public account creation. Access is limited through Cloudflare Access, Google authentication, and the approved QCCTC Central role roster.
Information collected
QCCTC Central may process the following information:
- Authentication information: the verified Google email address, Google account identifier, hosted-domain and email-verification claims needed to confirm the account, and the matching Cloudflare Access email claim.
- Roster and authorization information: staff name, work email, assigned role, school, program, course, and access scope maintained in the approved application roster.
- Lesson-plan workflow information: Teacher, program/course, reporting week, due date, submission timestamp, Google Form response/event identifier, submission type, evidence or file link supplied through FORM 009, review status, Director feedback, and workflow history.
- Operational work information: assigned owner, task title, status, next action, reported-by/reported-via details, notes, evidence references, entered-by/updated-by identity, timestamps, escalation, closure, and history.
- Technical and security information: session records, authentication state, request time, error and security events, and limited request metadata needed to operate, secure, troubleshoot, and monitor the system.
QCCTC Central does not request a user's Google password or multifactor-authentication code. Those credentials are handled by Google and Cloudflare.
For managed Support Staff work, Assigned To identifies the person responsible for the work. Entered By and Updated By identify the authenticated Director or Front Office user who electronically created or changed the record. A Support Staff owner who has no login is not represented as the person who entered or updated the record.
How information is used
Information is used only to:
- authenticate approved users;
- apply role, school, program, course, and record-level permissions;
- operate lesson-plan submission, review, correction, resubmission, completion, support-work, and oversight functions;
- preserve status, evidence, responsibility, deadline, and audit history;
- investigate failures, prevent unauthorized access, and maintain system reliability;
- meet applicable operational, records, and legal obligations.
QCCTC Central does not sell personal information and does not use Google user data for advertising.
QCCTC Central does not replace an official district system of record where district policy or applicable law requires information to be maintained in another system.
Google user data
QCCTC Central requests the Google OAuth scopes openid, email, and profile. The application uses the verified Google email and account identifier to match a person to the approved QCCTC Central roster. The display name, role, and program scope shown in Central come from the approved roster.
Google user data is not used to build advertising profiles, sold, or shared for unrelated purposes. Access is limited to the minimum identity information needed for authentication and authorization.
Service providers and disclosure
QCCTC Central uses service providers that process information to deliver the system:
- Cloudflare: access control, application hosting, security, logging, and D1 data storage.
- Google: Google sign-in, Google Forms, and files or links supplied through the approved FORM 009 process.
Information may also be disclosed when required by law, to protect the security or integrity of the system, or to authorized organizational personnel who need the information for their assigned responsibilities. Information is not disclosed to unrelated third parties for marketing.
Storage, retention, and deletion
Application records are stored in the production Cloudflare environment. Session identifiers are protected and server-side session tokens are stored as hashes. Workflow history is retained to preserve responsibility, review, correction, completion, and audit evidence.
Information is retained only as long as reasonably necessary for authorized operational, audit, security, records, or legal purposes. A verified user may contact the system administrator to request access, correction, or deletion where deletion is permitted and does not conflict with an applicable record-retention obligation.
Security
QCCTC Central uses Cloudflare Access, Google OAuth, role and program authorization, signed FORM 009 receipts, restricted service credentials, encrypted transport, server-side data validation, and audit history. No system can guarantee absolute security. Suspected unauthorized access should be reported promptly to the privacy contact.
Access may be restricted, suspended, or revoked when a user is no longer authorized, changes roles, violates access requirements, or creates a security risk. Revoking account access does not automatically remove workflow or audit records that must be retained for authorized operational, security, records, or legal purposes.
User responsibilities
Authorized users should enter only information needed for an assigned operational responsibility. Users should avoid placing unnecessary sensitive student, medical, financial, or personal information in free-text notes or evidence fields.
Children and students
QCCTC Central is a staff management system and is not designed for children or students to create accounts. Student-related information, when operationally necessary, should be limited to the minimum information authorized for the staff member's role.
Education records and other protected student information should be handled only as authorized by applicable law and district policy. Users should not enter student information into QCCTC Central merely because a field permits free-text entry.
Changes to this policy
This policy may be updated when system functions, service providers, or data practices change. The public policy will show its effective date. Material changes will be communicated through an appropriate system or staff notice.
Contact
Questions or requests about this policy or QCCTC Central information practices may be sent to:
Jessica Bradford Email: jessicabradford@qcsd.k12.ms.us