EFL App

EFL App Privacy Policy

Effective Date: July 31, 2026
Applies to: eflapp.com and the Essential for Living (EFL) App

Data Makes the Difference, LLC ("DMTD", "we", "us"), 17 Greystone Drive, Mountain Top, Pennsylvania 18707, USA, operates the EFL App. This policy explains what information we collect, how we use it, who we share it with, how long we keep it, and how to exercise your rights.

The EFL App is a professional tool licensed to schools, districts, clinics and agencies (each, an "Organization"). It is not a consumer product and is not directed to the general public.

Two kinds of people, two different roles

Account holders are the practitioners, educators and administrators who log in. We act as the controller of their account information.

Learners are the individuals being assessed and taught. Learners do not have accounts and cannot log in. Learner information is entered by the Organization's staff. The Organization owns and controls that information; we process it only on the Organization's instructions, as its service provider. Where the Organization is a school or district, we act as a "school official" with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)(i)(B)), and where applicable under state student-privacy laws such as the Illinois Student Online Personal Protection Act (SOPPA) and the Illinois School Student Records Act (ISSRA).

If you are a parent or guardian and want to see, correct or delete a learner's information, please contact the school, district or agency that entered it. We will refer such requests to them and support them in responding.

What we collect

Account holder information

Learner information

Entered by the Organization's staff:

Where an Organization enables an authorized partner integration, the partner system may additionally send us a learner's e-mail address, mailing address and photograph. This happens only if the Organization turns that integration on.

We do not collect learner ethnicity or race, place of birth, school enrolment or grade level, attendance, transcripts, transportation details, parent/guardian contact details, or any content created by the learner. Learners have no username or password with us.

Technical information

How we use information

We do not sell personal information. We do not use learner information for advertising, and we do not allow behavioural or targeted advertising in the EFL App. We do not use learner information to build any profile except the assessment and teaching record the Organization is creating for that learner.

Artificial intelligence features

The EFL App includes optional AI-assisted drafting: parent-facing progress summaries and practitioner session notes. These features are off by default, are rate-limited, and every output is reviewed and editable by the Organization's staff before it is used. AI output is a drafting aid and does not replace professional clinical judgement.

Cookies

We use a single essential session cookie to keep you signed in. If you block it you will not be able to log in. We do not use advertising cookies and we do not permit third-party behavioural tracking in the app.

Instructional help videos are embedded from Vimeo. When you play one, Vimeo may set its own cookies under its privacy policy. These videos are informational only and play no part in assessment.

Who we share information with

We share information only with service providers who help us run the EFL App. Each is bound by contract to protect it, to use it solely to provide services to us, and to meet standards no less protective than those we owe our customers. Our current providers are:

An up-to-date list is available on request from privacy@datamtd.com, and is provided automatically to customers whose agreements require it. We will give notice before adding a provider that would have access to learner information.

We may also disclose information where required by law. If law enforcement or another government body asks us for learner information, we will notify the Organization before disclosure unless we are legally prohibited from doing so, and we will direct the requester to the Organization wherever possible.

Where information is stored, and how it is protected

All learner information is stored in the United States on Amazon Web Services, encrypted in transit and at rest. Access is limited to the small number of personnel who need it, each under a confidentiality obligation.

DMTD maintains ISO/IEC 27001:2022 certification, a SOC 2 attestation, and a HIPAA and HITRUST-aligned control programme with continuous monitoring. Our current attestations are published at https://trust.datamtd.com.

If there is a data breach

If learner or other regulated information is subject to unauthorised access, disclosure or acquisition, we will notify the affected Organization within 72 hours of confirming the incident, unless notice within that period would obstruct a law-enforcement investigation, in which case we will notify as soon as we are permitted. Our notice will include what we know about the nature of the incident, the categories of information involved, when it occurred, the individuals affected if known, and a contact for follow-up questions. We maintain a written incident response plan and will provide a summary to customers on request.

Where we act as a service provider to a school or district, the Organization is responsible for notifying affected individuals, and we will support it in doing so.

How long we keep information

We keep learner information for as long as the Organization's licence is active and it instructs us to retain it. On the Organization's written request we will return or delete learner information, and we will confirm in writing once we have done so. Information deleted by a customer is removed from active systems within 30 days and purged from backups on our standard backup cycle. We review retained learner information at least annually and tell the Organization about anything that no longer needs to be kept. Account and billing records are retained as long as needed for legal, tax and accounting purposes.

Your rights

Account holders can view and update their own details by signing in, or by contacting us. You may ask us to provide a copy of your information, correct it, or delete it, and you may opt out of marketing e-mail at any time using the unsubscribe link or by writing to us. We will not treat you differently for exercising these rights.

For learner information, please direct requests to the Organization that entered it. If a factual inaccuracy is reported to us by the Organization, we will correct it within 90 days and confirm the correction in writing. Where our cooperation is needed for a parent to inspect or copy learner information, we will respond to the Organization within 5 business days.

Children's privacy

The EFL App is used with learners who are often children, including children under 13. Learners never interact with the app directly and never create accounts. Information about them is entered by the Organization's authorised staff, and under the Children's Online Privacy Protection Act (COPPA) that Organization provides the necessary consent on behalf of parents for the limited educational purpose of delivering our services. We do not market to children, and we do not use learner information for any purpose other than providing the EFL App to the Organization.

Changes to this policy

We may update this policy from time to time. We will revise the Effective Date above and, where the change is material and affects learner information, we will notify affected Organizations directly.

Contact us

Data Makes the Difference, LLC
17 Greystone Drive, Mountain Top, PA 18707, USA
Privacy: privacy@datamtd.com
Telephone: +1 (570) 550-4013

HIPAA policies and compliance questions: Steve Maher, steve@datamtd.com