How TEAC3H protects training data.
TEAC3H is a professional learning platform for Educational Assistants, supervisors, schools, and districts. These policies describe the practical privacy and security practices that support the public site and LMS.
Information We Handle
The LMS stores information needed to provide training, document participation, and support supervisor feedback. This may include names, email addresses, role and organization assignments, course enrollments, lesson progress, completion status, quiz scores, reflection responses, supervisor notes, certificate records, and approximate active learning time.
The public marketing site may receive inquiry details submitted through the contact form. We use those details to respond to organizations interested in training, service levels, or implementation support.
How We Use Information
We use LMS data to create accounts, assign courses, display progress, support reflection and feedback workflows, generate certificates, provide supervisor and district reporting, and send account or training-related email notifications.
We do not design the LMS as a student record system, payroll system, medical record system, or behavior incident system. Users should avoid entering unnecessary sensitive student, health, or personnel details into reflections, notes, or contact forms.
Access And Roles
Access is based on the user role assigned in the LMS. Educational Assistants see their assigned courses, their own progress, reflections, feedback, and certificates. Supervisors see assigned EAs and can review reflections or add notes. District admins are scoped to organization-level oversight. Admins and super admins manage course content, users, reporting, and support workflows.
Super admin tools are reserved for the smallest practical set of authorized users. Account and role changes are handled through server-side administrative functions rather than direct browser-side profile mutation.
Third-Party Services
TEAC3H uses Netlify for hosting, serverless functions, identity, and managed database services. LMS operational email is sent through Resend. Course media or resources may be embedded from Vimeo, YouTube, Google Drive, or Google Docs when those platforms are used for training materials.
Embedded third-party viewers may process technical information such as browser, device, network, or access information under their own policies. When PDF or resource embeds are used, the LMS provides an open/download path so users can access the source file outside the embedded preview when needed.
Security Practices
The platform uses HTTPS, security headers, role checks, authenticated LMS data functions, constrained data access allowlists, server-side user management, sanitized lesson rendering, email escaping, and protected database connections. Password setup and recovery are handled through Netlify Identity flows.
No system can guarantee absolute security. We review and improve safeguards as the product changes, including tests for data access boundaries, notification authorization, password recovery throttling, and public-page accessibility and security headers.
Retention And Requests
Training records are retained as needed to operate the LMS, support reporting, document completion, and meet organization support needs. Authorized administrators may disable or remove accounts when appropriate, subject to operational, contractual, and institutional requirements.
For questions about privacy, security, account access, or data correction requests, contact the TEAC3H team through the public contact form or through your organization’s designated training administrator.
Policy Review Note
This page describes current product and operational practices. It is not a legal compliance statement, and it should be reviewed by appropriate university, district, or legal stakeholders before being used as a formal contractual privacy notice.
Contact us