Skip to main content

Privacy Policy

Last updated: 2026-10-01

Text messages: No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the categories of sharing in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Details are in section 5A.

1. Who we are

Omni Forge District Enterprise Platform (DEP) (the “Product”) is a district enterprise platform operated by Your Resource Consultants Inc. (“we”, “us”) for K-12 school districts in the United States. School districts using the Product are referred to in this policy as “Districts.” This policy describes how the Product processes information and how Districts, parents, and eligible students may exercise their rights with respect to that information.

2. Roles under FERPA, COPPA, and state law

Districts are the FERPA-covered education-records holders for student records entered into the Product. The Product acts as the District's “school official” under 34 C.F.R. § 99.31(a)(1)(i)(B), processing education records solely on the District's instructions and only to provide the Product's functions. We do not use student records for advertising, do not sell student records, and do not build profiles of students for any purpose unrelated to school services authorized by the District.

For students under 13, the Product is operated under the District's authority to consent on parents' behalf to the collection of personal information from students for the use and benefit of the school, as permitted by FTC COPPA FAQ §M and analogous state laws (e.g., NJ Student Privacy Act).

3. What the Product collects

Categories of personal information the Product processes on behalf of Districts:

4. Where the data lives and how it's isolated

The Product stores all District data in a single relational database in the United States, partitioned by an explicit districtId column on every row. Application middleware enforces tenant isolation: every database query is scoped to the calling user's District. No District's data is queryable from another District's session. Backups are encrypted and stored in the same United States region.

5. Subprocessors

We use the following subprocessors to deliver the Product. Each is bound by a data-processing agreement and is restricted to the purposes shown:

We do not transfer student personal information outside the United States.

5A. Text messages (SMS)

OmniForge SIS text messages are sent by Your Resource Consultants Inc., 20 S Charles St, Ste 403, Baltimore, MD 21201. Parents and guardians receive texts only after turning on SMS in their notification settings; texts cover attendance, announcements, health and other updates they choose, and emergency alerts may be sent to the number on file. Reply STOP to any message to opt out or HELP for help. See our SMS Terms.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the categories of sharing in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

6. How long we keep data

Active student records are retained while the student is enrolled with a District using the Product, plus the retention period the District specifies in its records-retention schedule (typically 5 years post-graduation for academic records, longer for transcripts; District policy controls). Audit logs are retained for 7 years per FERPA-aligned best practice. Backups are retained for 7 days locally and indefinitely in the encrypted backup bucket per District configuration.

On District termination, the District may export data via the Product's export tools and request deletion of the District's tenant. We delete production data within 30 days of confirmed District export and retain only backup copies as required by contract; backup copies are deleted on the standard backup-rotation schedule (no longer than 30 days after deletion).

7. Parent and eligible-student rights

Under FERPA, NJ Student Privacy Act, and equivalent laws:

Direct all access, correction, and deletion requests to the District's records office. We will support the District in honoring such requests within the timelines required by applicable law.

8. Security

We use industry-standard administrative, technical, and physical safeguards: TLS 1.2+ in transit, encryption at rest, Argon2id password hashing, multi-factor authentication for staff accounts, least-privilege role-based access control, per-tenant data isolation, audit logging on every state change, and regular security reviews of new code. Despite these measures, no system is perfectly secure; we will notify Districts of any security incident affecting their data without unreasonable delay and in any case within the timelines required by applicable law.

9. Cookies and tracking

The Product uses one essential session cookie (HttpOnly, Secure, SameSite=Lax) to keep authenticated users signed in. We do not use third-party advertising or analytics trackers in the authenticated application. Public marketing pages may use limited first-party analytics; these do not track student users.

10. Changes to this policy

We will post material changes here with a new “Last updated” date and, for Districts, provide direct notice through their administrator account.

11. Contact

Privacy questions about a specific student record should be directed to the student's District. Vendor-level privacy questions about the Product itself may be sent to privacy@omniforge.click.

OmniForge SIS is operated by Your Resource Consultants Inc., 20 S Charles St, Ste 403, Baltimore, MD 21201. References to specific statutes and rights are for orientation; the binding text of those laws controls.