Effective date: June 1, 2026
This page is the short canonical reference for Talk and Comment's breach-notification procedure and data-retention posture. Districts and educational agencies that need the full security program should also review the Data Security and Privacy Plan.
1. Scope
This procedure applies to security incidents, breaches, or unauthorized releases that may involve personal information, student personally identifiable information (student PII), teacher/principal APPR data, recordings, transcripts, account data, operational logs, or other data processed by Talk and Comment.
For school or district deployments, a signed DPA, NDPA, or other written agreement may add district-specific requirements. Where an agreement requires stricter handling, Talk and Comment follows the stricter applicable requirement.
2. Breach Notification Procedure
When Talk and Comment identifies a potential breach or unauthorized release, the designated incident commander coordinates the response with privacy, security, operations, and legal/contract stakeholders as needed:
- Contain the incident to stop further exposure. This may include revoking credentials, disabling integrations, isolating affected systems, or pausing affected workflows.
- Assess the type of data involved, affected users or educational agencies, date of discovery, likely incident window, and whether the incident is ongoing.
- Notify affected educational agencies no later than 72 hours after discovery when student PII or teacher/principal APPR data may have been breached or released without authorization, consistent with the NDPA commitment referenced in the Data Security and Privacy Plan.
- Remediate the root cause and confirm that the exposure is closed.
- Document the timeline, scope, response actions, notification record, follow-up tasks, and any changes made to prevent recurrence.
Notifications are sent by email to the educational agency's designated privacy, security, or contract contact, with phone follow-up when appropriate. Notifications include the information known at the time, including:
- A description of the incident.
- The date of discovery and, where known, the incident date range.
- The categories of data involved.
- The estimated number of affected records, users, or educational agencies.
- Containment and remediation actions taken.
- The Talk and Comment contact for follow-up questions.
- Whether supplemental updates are expected as the investigation continues.
If Talk and Comment receives a relevant security notice from a sub-processor, that notice is evaluated under the same procedure. If the sub-processor incident may affect student PII or other covered data, Talk and Comment coordinates notice to affected educational agencies under the same 72-hour commitment.
3. Data Retention Statement
Talk and Comment retains personal information and student data only for as long as needed to provide the Service, support active school or district agreements, comply with legal obligations, resolve disputes, maintain security and auditability, and enforce agreements.
The operational retention posture is:
- Recordings and playback metadata: retained while needed to provide playback, sharing, account/library access, and support, unless deleted by the user, educational agency, or an authorized retention request.
- Transcripts and summaries: retained only when the relevant feature is enabled and while needed to provide the requested transcript, summary, account, library, support, or agreement workflow.
- Account and billing records: retained while the account, subscription, legal, tax, dispute, or security need remains active.
- Application logs that may contain personal information: rotated and purged on the operational schedule described in the Data Security and Privacy Plan, currently 90 days for logs containing PII.
- Database backups: retained and rotated by the managed database provider. After deletion from the primary database, covered data ages out of backups within the provider's backup-retention window, currently described as typically 7 days in the Data Security and Privacy Plan.
Users may delete recordings where the Service provides deletion controls and may request account deletion by contacting [email protected]. Educational agencies may request return, deletion, or certification under the applicable DPA, NDPA, or written agreement.
4. School Contract Termination and Destruction
When a school or educational agency contract expires or terminates, Talk and Comment follows the data transition and destruction process in the Data Security and Privacy Plan:
- Make covered student PII and education records available for export within 30 days of a written request from the educational agency.
- Give the educational agency a reasonable retrieval period before destruction begins.
- Destroy covered student PII and education records after the transition period using the deletion methods described for each storage location.
- Provide a written certification of destruction upon request, generally within 60 days of the destruction request to allow for backup rotation.
5. Questions and Requests
Questions, privacy requests, educational agency requests, and suspected incidents should be sent to [email protected].
For education privacy requests, include "Education Privacy" in the subject line. For suspected incidents, include "Security Incident" in the subject line and provide enough context for prompt routing.