lOGERD

Legal

Privacy Policy | Terms of Service | Subprocessor & Data Processing | Security Addendum

By Garosoft

It all about Legal…

Privacy Policy

Effective Date: August 31, 2026
Last Updated: August 31, 2026

Garosoft LLC (“Garosoft,” “we,” “us,” or “our”) operates Logerd, including the Logerd website, applications, and related services (collectively, the “Services”).

Logerd provides digital management tools for schools, businesses, and other organizations, including attendance tracking, visitor and contractor management, student check-in and check-out, student transportation and dismissal tracking, parent forms and electronic signatures, employee time tracking, and related operational services.

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our website, use our Services, or otherwise interact with us.

1. Information We Collect

The information we collect depends on how you interact with Logerd and how your organization uses the Services.

Information You Provide

We may collect information you provide directly, including:

  • Name and contact information.
  • Email address and telephone number.
  • Account and login information.
  • Billing and subscription information.
  • Information submitted through contact or demonstration requests.
  • Customer service and support communications.
  • Information submitted through forms and electronic signatures.

Payment card information is processed through Stripe. We do not intend to store complete payment card numbers on our own systems.

Information Collected Through Logerd

Organizations using Logerd may enter or collect information concerning students, parents or guardians, employees, visitors, contractors, drivers, and other individuals.

Depending on how an organization uses the Services, this may include:

  • Names and identification information.
  • Student and employee records.
  • Parent or guardian information.
  • Attendance and tardiness records.
  • Check-in and check-out records.
  • Visitor and contractor records.
  • Student pickup and dismissal information.
  • Transportation and bus boarding information.
  • Employee time and attendance information.
  • Forms and electronic signatures.
  • Telephone numbers used for notifications.
  • Other information an organization chooses to enter into Logerd.

The organization using Logerd generally determines what information is collected and how that information is used.

Automatically Collected Information

We may automatically collect technical and usage information when you access our website or Services, including:

  • IP address.
  • Browser type and version.
  • Device type and operating system.
  • Date and time of access.
  • Pages and features accessed.
  • Referring website.
  • General usage and diagnostic information.

2. How We Use Information

We may use personal information to:

  • Provide and operate the Services.
  • Create and administer accounts.
  • Process payments and subscriptions.
  • Provide customer support.
  • Respond to inquiries.
  • Provide attendance, visitor, transportation, employee, form, and related functionality.
  • Send transactional and service-related communications.
  • Send SMS notifications when authorized.
  • Analyze and improve website and Service performance.
  • Maintain security.
  • Detect fraud, abuse, and unauthorized activity.
  • Comply with legal obligations.
  • Enforce agreements.
  • Protect our rights, customers, users, and the public.

3. Information Processed on Behalf of Organizations

Schools, businesses, and other organizations may use Logerd to collect and manage personal information about individuals.

When we process such information on behalf of an organization, we generally act as a service provider, processor, or other contracted service provider to that organization, as applicable under law.

The organization generally determines:

  • What information is collected.
  • Why the information is collected.
  • How the information is used.
  • How long the information is retained.
  • Which individuals may access the information.

If you have a question concerning information collected by your school, employer, or another organization through Logerd, you should generally contact that organization first.

4. Service Providers

We use third-party providers to operate and support Logerd.

Amazon Web Services

We use Amazon Web Services (“AWS”) for cloud hosting, computing, storage, infrastructure, and related services.

Google Analytics

We use Google Analytics to understand website traffic, usage patterns, and website performance.

Google Analytics may use cookies and similar technologies to collect information about visitors and their interactions with our website.

Stripe

We use Stripe for payment processing and billing-related services.

Payment information may be transmitted directly to Stripe for processing. Stripe’s handling of personal information is subject to its own privacy practices.

Twilio

We use Twilio to provide SMS and other communications functionality.

Depending on how an organization configures Logerd, Twilio may process telephone numbers, message content, delivery information, and related messaging metadata.

5. How We Share Information

We may disclose information:

  • To service providers that help us operate the Services.
  • To organizations using Logerd.
  • To authorized administrators and users of an organization’s Logerd account.
  • When required by law or legal process.
  • To protect the rights, safety, and property of Garosoft, our users, customers, or others.
  • To investigate fraud, abuse, security incidents, or unlawful activity.
  • In connection with a merger, acquisition, financing, sale of assets, reorganization, bankruptcy, or similar transaction.

We do not sell personal information for monetary consideration.

6. Cookies and Analytics

We may use cookies, pixels, local storage, and similar technologies to:

  • Maintain sessions.
  • Keep users signed in.
  • Remember preferences.
  • Provide security features.
  • Analyze website traffic.
  • Improve website and Service performance.

We use Google Analytics for website analytics.

You may control cookies through your browser settings. Disabling cookies may affect certain functionality.

7. SMS and Text Messaging

Logerd may facilitate SMS communications through Twilio.

Messages may include:

  • Attendance notifications.
  • Student pickup or dismissal notifications.
  • Transportation notifications.
  • Account notifications.
  • Operational alerts.
  • Other messages configured by the organization.

The organization using Logerd is responsible for determining who receives messages and obtaining any consent required by applicable law.

Recipients may opt out of SMS messages by replying STOP or another supported opt-out keyword. Recipients may request assistance by replying HELP where supported.

After an opt-out, additional messages should not be sent unless the recipient subsequently provides valid consent to receive them again.

Message and data rates may apply.

8. Children’s and Student Information

Logerd is designed to support schools and may process information concerning students, including children.

We do not use student information for targeted advertising.

When we process student information on behalf of a school or other organization, the organization generally determines the purposes for which the information is collected and used and is responsible for providing applicable notices and obtaining required permissions or consents.

Garosoft does not knowingly require children to provide personal information directly to us for purposes unrelated to providing the Services.

Parents and guardians with questions about student information processed through Logerd should contact the applicable school or organization.

9. Security

We maintain reasonable administrative, technical, and organizational safeguards designed to protect personal information.

These safeguards may include access controls, authentication, encryption, monitoring, backups, and other security measures appropriate to the nature of the information and Services.

No electronic system or internet transmission can be guaranteed to be completely secure.

10. Data Retention

We retain personal information for as long as reasonably necessary to provide the Services, fulfill contractual obligations, comply with legal requirements, resolve disputes, enforce agreements, and protect our legitimate business interests.

For information processed on behalf of an organization, retention may be determined by the organization’s instructions and our contractual arrangements.

11. Privacy Rights

Depending on applicable law, you may have rights to:

  • Request access to personal information.
  • Request correction of inaccurate information.
  • Request deletion of personal information.
  • Request information about how personal information is collected and used.
  • Object to or restrict certain processing.
  • Request portability of certain information.
  • Withdraw consent where processing is based on consent.

Where information is processed on behalf of an organization, the organization may be responsible for responding to your request.

12. California Residents

California residents may have additional rights under applicable California privacy laws.

These rights may include rights to access, correct, delete, and obtain information concerning the collection and disclosure of personal information.

Garosoft does not sell personal information for monetary consideration.

Where Garosoft processes information solely on behalf of a customer organization, that organization may be responsible for responding to certain requests.

13. International Users

Garosoft is based in the United States.

Information may be transferred to and processed in the United States and other jurisdictions where Garosoft or its service providers operate.

Where required by applicable law, we will use appropriate safeguards for international transfers.

14. Third-Party Services

Our website and Services may contain links to third-party websites or services.

We are not responsible for the privacy or security practices of third-party services.

15. Changes

We may update this Privacy Policy periodically.

We will update the “Last Updated” date when changes are made. Where required by law, we will provide additional notice of material changes.

16. Contact

Garosoft LLC
Logerd
Atlanta, Georgia, USA

Email: info@logerd.com
Phone: +1 (844) 410-9697

Logerd Terms of Service

Effective Date: August 31, 2026
Last Updated: August 31, 2026

These Terms of Service (“Terms”) govern access to and use of Logerd and related services provided by Garosoft LLC (“Garosoft,” “we,” “us,” or “our”).

By accessing or using Logerd, you agree to these Terms. If you are using Logerd on behalf of an organization, you represent that you have authority to bind that organization to these Terms.

1. The Services

Logerd provides software and related services that may include:

  • Attendance management.
  • Visitor and contractor management.
  • Student check-in and check-out.
  • Student transportation and bus tracking.
  • Student dismissal and pickup management.
  • Parent forms and electronic signatures.
  • Employee time tracking.
  • Notifications and communications.
  • Other features made available by Garosoft.

Features may change, be modified, or be discontinued from time to time.

2. Accounts

Certain features require an account.

You agree to provide accurate information and to maintain the security of your login credentials.

You are responsible for activity occurring through your account and must promptly notify Garosoft of suspected unauthorized access.

Organizations are responsible for managing their authorized users and access permissions.

3. Customer Data

Organizations may submit information to Logerd, including information concerning students, employees, parents, visitors, contractors, and other individuals (“Customer Data”).

The organization retains responsibility for Customer Data and determines the purposes for which Customer Data is collected and used.

Garosoft may process Customer Data solely as necessary to provide, maintain, secure, and improve the Services and as otherwise permitted by the applicable agreement or Data Processing Addendum.

4. Privacy and Data Processing

Our Privacy Policy describes our general privacy practices.

Where an organization uses Logerd to process personal information on its behalf, the parties may enter into a Data Processing Addendum (“DPA”).

If there is a conflict between these Terms and an applicable DPA concerning the processing of Customer Data, the DPA controls to the extent of that conflict.

5. Customer Responsibilities

Customers are responsible for:

  • Using the Services in compliance with applicable law.
  • Providing required notices to individuals.
  • Obtaining required consents.
  • Maintaining appropriate user permissions.
  • Ensuring that submitted information is accurate and lawful.
  • Responding to individuals’ privacy requests where required.
  • Maintaining the confidentiality of account credentials.
  • Using SMS functionality in compliance with applicable messaging laws and regulations.

Customers must not use Logerd to transmit unlawful, fraudulent, abusive, or harmful content.

6. SMS Messaging

Customers using Logerd’s SMS functionality are responsible for obtaining any consent required before sending messages.

Customers must not send unsolicited or unlawful messages.

Customers must honor recipient opt-out requests.

Where applicable, recipients may reply STOP to unsubscribe and HELP for assistance. Twilio’s messaging infrastructure supports standard opt-out handling, including STOP, and requires appropriate consent practices. 

7. Fees and Payment

Paid Services are subject to the pricing and payment terms presented to the customer.

Payments may be processed through Stripe.

Unless otherwise stated:

  • Fees are due according to the applicable subscription or order.
  • Customers are responsible for applicable taxes.
  • Subscription fees are generally non-refundable except where required by law or expressly agreed otherwise.
  • Garosoft may suspend Services for materially overdue amounts after providing reasonable notice.

8. Intellectual Property

Garosoft and its licensors retain all rights in:

  • The Logerd software.
  • The Logerd website.
  • The Logerd trademarks and branding.
  • Documentation.
  • Software code.
  • Designs.
  • Interfaces.
  • Other intellectual property comprising the Services.

Except as expressly permitted by these Terms, customers receive a limited, non-exclusive, non-transferable right to use the Services during the applicable subscription period.

Customers retain ownership of their Customer Data.

9. Restrictions

You may not:

  • Reverse engineer or attempt to derive source code from the Services.
  • Circumvent security controls.
  • Access accounts without authorization.
  • Resell or sublicense the Services unless expressly authorized.
  • Interfere with the operation of the Services.
  • Introduce malicious code.
  • Use the Services to violate applicable law.
  • Use the Services to transmit spam or unlawful communications.
  • Attempt to gain unauthorized access to another customer’s data.

10. Availability

We strive to provide reliable Services but do not guarantee uninterrupted availability.

The Services may occasionally be unavailable because of:

  • Maintenance.
  • Updates.
  • Security incidents.
  • Third-party infrastructure failures.
  • Internet or telecommunications failures.
  • Events outside our reasonable control.

11. Third-Party Services

Logerd relies on third-party services, which may include AWS, Google Analytics, Stripe, and Twilio.

Third-party services may have their own terms and privacy policies.

Garosoft is not responsible for failures or actions of third-party services outside our reasonable control.

12. Suspension and Termination

We may suspend or terminate access if:

  • A customer materially breaches these Terms.
  • A customer fails to pay applicable fees.
  • Use of the Services creates a security or legal risk.
  • The Services are being used unlawfully.
  • Suspension is reasonably necessary to protect users or the Services.

Customers may terminate their subscription according to their applicable agreement.

13. Customer Data After Termination

Following termination, Customer Data will be handled according to the applicable agreement and DPA.

Subject to applicable legal requirements, Garosoft may delete Customer Data after a reasonable period following termination.

Garosoft may retain information where required by law or reasonably necessary for legal, security, accounting, or legitimate business purposes.

14. Disclaimers

To the maximum extent permitted by law, the Services are provided on an “as is” and “as available” basis.

Garosoft disclaims warranties not expressly stated in these Terms, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement, to the extent permitted by law.

Garosoft does not guarantee that the Services will meet every customer’s requirements or operate without interruption or error.

15. Limitation of Liability

To the maximum extent permitted by law, Garosoft will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or loss of profits, revenue, data, goodwill, or business opportunities arising from use of the Services.

To the maximum extent permitted by law, Garosoft’s aggregate liability arising out of or relating to the Services will not exceed the fees paid by the customer to Garosoft for the Services during the twelve months preceding the event giving rise to the claim.

Nothing in these Terms limits liability that cannot legally be limited.

16. Indemnification

To the extent permitted by law, customers agree to defend, indemnify, and hold harmless Garosoft and its officers, employees, agents, and affiliates from claims arising from:

  • The customer’s unlawful use of the Services.
  • Customer Data supplied by the customer.
  • The customer’s violation of these Terms.
  • The customer’s violation of applicable law.
  • The customer’s violation of another person’s rights.

17. Changes to the Services or Terms

We may modify the Services or these Terms from time to time.

We will update the “Last Updated” date when material changes are made.

Where required, we will provide notice of material changes.

18. Governing Law

These Terms are governed by the laws of the State of Georgia, without regard to conflict-of-law principles, except where applicable law requires otherwise.

Any dispute will be resolved in the courts located in Georgia unless the parties agree otherwise or applicable law requires another forum.

19. General

If any provision of these Terms is determined to be unenforceable, the remaining provisions will remain effective.

Failure to enforce a provision does not constitute a waiver.

These Terms, together with applicable order forms, agreements, the Privacy Policy, and any applicable DPA, constitute the agreement governing use of the Services.

20. Contact

Garosoft LLC
Logerd
Atlanta, Georgia, USA

Email: info@logerd.com
Phone: +1 (844) 410-9697

Logerd Subprocessor & Data-Processing Schedule

Garosoft LLC / Logerd
Effective Date: August 31, 2026
Last Updated: August 31, 2026

This Subprocessor & Data-Processing Schedule (“Schedule”) supplements the Logerd Data Processing Addendum (“DPA”).

1. Purpose

Garosoft LLC (“Garosoft”) uses certain third-party service providers to operate, maintain, secure, and support Logerd.

These providers may process Customer Data, including Personal Data, only as necessary to provide the services for which they are engaged.

Garosoft remains responsible for its obligations under the DPA with respect to Customer Data processed by its authorized subprocessors, subject to the terms of the applicable agreements.

2. Current Subprocessors

SubprocessorServicePotential Data ProcessedPrimary Function
Amazon Web Services, Inc. (“AWS”)Cloud infrastructureCustomer Data, account information, technical informationHosting, storage, computing, databases, backups, infrastructure
Google LLC / Google AnalyticsAnalyticsWebsite usage, device/browser information, IP-related and analytics informationWebsite analytics and performance measurement
Stripe, Inc.Payment processingCustomer contact, billing and payment informationPayment processing, subscriptions, billing
Twilio Inc.CommunicationsTelephone numbers, message content, delivery information, messaging metadataSMS/text messaging and communications

The actual information processed by each subprocessor depends on the Logerd features used by Customer.

3. AWS

Garosoft uses AWS infrastructure to host and operate portions of Logerd.

AWS may process Customer Data in accordance with its applicable agreements and data-processing terms.

AWS provides compliance and security capabilities that customers may use to support applicable compliance requirements, but Garosoft remains responsible for configuring and using AWS appropriately. AWS itself states that its customers remain responsible for applicable compliance obligations. 

Garosoft will configure AWS services using security measures appropriate to the nature of the Services and the information processed.

4. Google Analytics

Google Analytics is used for website analytics and performance measurement.

Google Analytics should be configured so that Customer Data and student information are not intentionally transmitted to Google Analytics.

Garosoft will not intentionally configure Google Analytics to send student education records, student names, student identification numbers, parent records, attendance records, transportation records, or other Customer Data into analytics properties.

If analytics functionality is deployed inside authenticated portions of Logerd, Garosoft will review the configuration to ensure that Personal Data is not unnecessarily transmitted to Google Analytics.

5. Stripe

Stripe is used for payment processing and billing.

Payment card information may be transmitted directly to Stripe.

Garosoft does not intentionally store complete payment card numbers or card security codes in Logerd databases.

Billing information processed through Stripe may include:

  • Customer name.
  • Business or organization name.
  • Billing address.
  • Email address.
  • Telephone number.
  • Subscription information.
  • Transaction information.

Stripe processes payment information according to its applicable terms and privacy practices.

6. Twilio

Twilio is used to provide SMS and related communication services.

Depending on Customer’s use of Logerd, Twilio may process:

  • Telephone numbers.
  • Message content.
  • Sender information.
  • Recipient information.
  • Message timestamps.
  • Delivery status.
  • Messaging metadata.

Customer is responsible for determining whether it has the necessary authorization and consent to send messages to recipients.

Customer must comply with applicable laws and regulations governing SMS and automated communications.

7. Student Data and Subprocessors

Garosoft will not intentionally disclose Student Data to a subprocessor for advertising or unrelated commercial purposes.

Where a subprocessor is necessary to provide the Services, Garosoft will limit the subprocessor’s access to information reasonably necessary for the applicable service.

School customers should understand that third-party infrastructure providers may process technical information and Customer Data as necessary to provide the infrastructure or functionality selected by the school.

8. Changes to Subprocessors

Garosoft may add, remove, or replace subprocessors when reasonably necessary to provide or improve the Services.

Where required by applicable law or contractual agreement, Garosoft will provide notice of material subprocessor changes.

Customer may raise a reasonable objection to a new subprocessor where required by applicable law or the DPA.

If the parties cannot reasonably resolve a material objection, the parties will work in good faith to identify an alternative solution.

9. Subprocessor Agreements

Garosoft will require subprocessors that process Personal Data on Garosoft’s behalf to maintain contractual obligations appropriate to the nature of the processing.

Those obligations will address, as applicable:

  • Confidentiality.
  • Security.
  • Appropriate use restrictions.
  • Data protection.
  • Assistance with applicable privacy obligations.
  • Deletion or return of information where appropriate.

10. Data Locations

The geographic location of processing may depend on the service, AWS Region, configuration, and subprocessors used.

Garosoft will not represent that all Customer Data is stored exclusively in the United States unless the applicable Logerd infrastructure and configuration actually provide that restriction.

Where Customer requires a specific geographic storage location, the parties may address the requirement in a separate written agreement if technically supported.

11. International Transfers

Where Customer Data is transferred internationally and applicable law requires a transfer mechanism or safeguard, Garosoft will implement an appropriate lawful mechanism.

For AWS processing, AWS maintains a global Data Processing Addendum and provides contractual mechanisms intended to support applicable data-protection requirements. 

12. Customer Review

Customers may request current information regarding Garosoft’s subprocessors.

Garosoft may provide additional information concerning subprocessors where reasonably necessary for Customer’s privacy or security assessment, subject to confidentiality and security restrictions.

13. Effective Date

This Schedule is effective as of the date stated above and may be updated periodically.

The current version should be made available to customers through the Logerd website or another reasonable customer-accessible location.

Logerd Security Addendum

Garosoft LLC / Logerd
Effective Date: August 31, 2026
Last Updated: August 31, 2026

This Security Addendum (“Security Addendum”) describes the administrative, technical, and organizational safeguards Garosoft LLC (“Garosoft”) maintains in connection with the Logerd Services.

This document describes Garosoft’s intended security practices and does not constitute a guarantee that a particular security control will prevent every security incident.

1. Security Program

Garosoft maintains a security program designed to protect the confidentiality, integrity, and availability of information processed through Logerd.

The security program is designed to account for:

  • The nature and sensitivity of information processed.
  • The purposes for which information is processed.
  • The risks associated with unauthorized access or disclosure.
  • The size and complexity of the Services.
  • Applicable legal and contractual requirements.

2. Access Controls

Garosoft uses reasonable access controls designed to limit access to Customer Data to authorized individuals.

Access controls may include:

  • Unique user accounts.
  • Authentication requirements.
  • Role-based access.
  • Least-privilege principles.
  • Administrative access restrictions.
  • Access reviews.
  • Removal of access when no longer required.

Customer administrators are responsible for assigning appropriate permissions to their users.

3. Customer Account Security

Customers are responsible for:

  • Protecting usernames and passwords.
  • Maintaining appropriate user permissions.
  • Removing former employees and users.
  • Protecting authentication credentials.
  • Reporting suspected unauthorized access.

Garosoft may provide administrative controls to assist customers in managing access.

4. Encryption

Garosoft uses encryption and secure communication mechanisms appropriate to the Services.

Information transmitted between users and Logerd should be protected using industry-standard encrypted transport protocols.

Where supported by the underlying infrastructure, stored information may also be encrypted at rest.

Specific encryption technologies and configurations may change as the Services evolve.

5. Infrastructure Security

Logerd uses Amazon Web Services infrastructure for portions of its hosting and technology environment.

Garosoft relies on AWS security capabilities and configures applicable services according to its security requirements.

AWS provides a range of compliance and security programs, including resources relevant to FERPA and other regulatory frameworks. AWS also makes clear that customers remain responsible for their own compliance and configuration decisions. Amazon Web Services, Inc.

6. Application Security

Garosoft uses reasonable measures designed to protect the Logerd application against unauthorized access and common application security threats.

These measures may include:

  • Authentication controls.
  • Authorization controls.
  • Input validation.
  • Secure coding practices.
  • Dependency updates.
  • Vulnerability remediation.
  • Logging.
  • Monitoring.
  • Security testing appropriate to the Services.

7. Production Access

Access to production systems is restricted to personnel who require such access to perform their responsibilities.

Where administrative access is required, Garosoft will use reasonable safeguards appropriate to the sensitivity of the environment.

Production access should be reviewed periodically and removed when no longer necessary.

8. Employee and Contractor Confidentiality

Personnel who may access Customer Data are subject to confidentiality obligations.

Access to Customer Data is limited based on job responsibilities and operational requirements.

9. Security Monitoring

Garosoft uses reasonable monitoring and logging practices designed to identify:

  • Unauthorized access.
  • Suspicious activity.
  • System failures.
  • Security events.
  • Operational issues.

Logs may be retained for a reasonable period for security, troubleshooting, compliance, and operational purposes.

10. Backups

Garosoft maintains backups appropriate to the Services and operational requirements.

Backups are intended to support recovery from:

  • Hardware failures.
  • Software failures.
  • Accidental deletion.
  • Certain security incidents.
  • Other operational disruptions.

Backup retention may differ from production-data retention.

Customer Data contained in backups will be subject to applicable security protections and will be deleted according to the applicable backup lifecycle.

11. Security Incident Response

Garosoft maintains procedures designed to identify, investigate, contain, and remediate security incidents.

When Garosoft determines that a security incident has resulted in unauthorized access to or disclosure of Customer Data and notification is required by applicable law or contract, Garosoft will notify the affected Customer without unreasonable delay.

Where reasonably available, Garosoft’s notification may include:

  • A description of the incident.
  • The approximate date or period of the incident.
  • Categories of information affected.
  • Remediation measures taken.
  • Steps being taken to prevent recurrence.

Garosoft may provide supplemental information as it becomes reasonably available.

12. Customer Cooperation

Customers agree to reasonably cooperate with Garosoft during security incidents.

Customers should promptly notify Garosoft of suspected:

  • Account compromise.
  • Unauthorized access.
  • Lost credentials.
  • Security vulnerabilities.
  • Improper disclosure of Customer Data.

13. Data Minimization

Garosoft is committed to limiting the collection and processing of information to information reasonably necessary to provide the Services.

Customers are responsible for determining what information they enter into Logerd.

Customers should not enter information into Logerd that is not necessary for their use of the applicable functionality.

14. Student Data

Garosoft will not intentionally use Student Data for:

  • Targeted advertising.
  • Behavioral advertising.
  • Selling personal information.
  • Building commercial advertising profiles.
  • Unrelated commercial purposes.

Student Data will be processed to provide the Services and as otherwise permitted by the Customer agreement, DPA, or applicable law.

This approach is consistent with FTC guidance that school-authorized educational technology providers should limit children’s information to the educational purpose for which the school requested the service. FFederal Trade Commission+1

15. Data Retention

Garosoft will maintain Customer Data only for as long as reasonably necessary to provide the Services and satisfy applicable contractual, legal, security, and operational requirements.

For children’s information subject to COPPA, Garosoft will not intentionally retain information indefinitely and will maintain retention and deletion practices appropriate to the purposes for which information was collected. The FTC’s updated COPPA framework specifically emphasizes purpose-based retention and deletion. FFederal Trade Commission+1

16. Vulnerability Management

Garosoft will use reasonable procedures to identify and address vulnerabilities affecting the Services.

Critical vulnerabilities that present a material risk may be prioritized for expedited remediation.

The timing of remediation may depend on:

  • Severity.
  • Exploitability.
  • Exposure.
  • Availability of a fix.
  • Operational impact.
  • Other mitigating controls.

17. Security Assessments

Garosoft may periodically evaluate the security of the Services through internal reviews, vulnerability assessments, penetration testing, third-party assessments, or other reasonable methods appropriate to the size and nature of the Services.

Garosoft may provide customers with appropriate security documentation upon reasonable request, subject to confidentiality and security restrictions.

18. Physical Security

Because Logerd uses cloud infrastructure, physical security of certain systems is provided through cloud infrastructure providers such as AWS.

Garosoft will use reputable infrastructure providers with security controls appropriate to the Services.

19. Business Continuity

Garosoft maintains reasonable measures designed to support continued operation and recovery of the Services following significant operational disruptions.

Business continuity measures may include:

  • Backups.
  • System redundancy.
  • Monitoring.
  • Incident response procedures.
  • Disaster recovery procedures.
  • Cloud infrastructure recovery capabilities.

20. Third-Party Services

Garosoft uses third-party providers including AWS, Google Analytics, Stripe, and Twilio.

These providers may maintain their own security programs and contractual obligations.

Garosoft will select and manage service providers in a manner reasonably designed to protect Customer Data.

21. FERPA and School Customers

Where Customer is subject to FERPA and Garosoft processes education records on Customer’s behalf, Garosoft will process such records in accordance with the applicable DPA and Customer’s documented instructions.

FERPA’s school-official framework requires, among other things, that the outside party perform an institutional service or function, remain under the school’s direct control concerning the use and maintenance of education records, and comply with applicable use and redisclosure restrictions. SStudent Privacy+1

Nothing in this Security Addendum makes Garosoft independently responsible for determining whether Customer’s use of Logerd satisfies FERPA or other education-law requirements.

22. COPPA

Where COPPA applies, Garosoft will support Customer’s use of the Services in a manner designed to limit children’s information to the purposes for which the Services are provided.

Customer remains responsible for determining whether it must provide notices, obtain consent, or take other actions under COPPA.

The FTC recognizes that schools may, in certain educational contexts, authorize an operator’s collection of children’s information on the school’s behalf, but the school-authorized use must remain within the educational context and not be used for unrelated commercial purposes. FFederal Trade Commission

23. CCPA and Other State Privacy Laws

Where applicable state privacy laws require contractual restrictions between a business and service provider, processor, or contractor, the DPA is intended to establish those restrictions.

Garosoft will not intentionally:

  • Sell Customer Data.
  • Share Customer Data for cross-context behavioral advertising.
  • Retain, use, or disclose Customer Data for purposes unrelated to the agreed Services, except as permitted by applicable law.
  • Combine Customer Data with information obtained from another customer except as permitted by applicable law and the applicable agreement.

The parties intend the DPA to provide the contractual restrictions necessary for applicable service-provider or processor relationships.

24. Changes to Security Practices

Garosoft may modify its security practices as technology, threats, infrastructure, and applicable standards evolve.

Garosoft will not intentionally materially reduce the overall security protections applicable to Customer Data without reasonable consideration of the potential impact on Customers.

25. Security Contact

Security and privacy inquiries may be directed to:

Garosoft LLC
Logerd
Atlanta, Georgia, USA

Email: info@logerd.com
Phone: +1 (844) 410-9697