Data Usage Policy
Dream Data Usage Policy
Last Updated: August 19, 2026
1. Purpose
The Dream Data Usage Policy establishes Vivacity Tech PBC's commitment to responsible data stewardship. It outlines how data—particularly user data—is collected, used, protected, and ultimately disposed of when no longer required. The policy ensures compliance with applicable data privacy and protection laws and provides transparency into the governance of data within the Dream application. All user data collected via the Dream application remains the property of and under the control of the originating organization.
2. Scope
This policy applies to:
- All user data collected via the Dream application
- Data submitted by users or imported from integrated Google services
- All employees, contractors, organization personnel, and external partners who access or process data via Dream
Dream is an application designed for organizations to manage personal devices (e.g., laptops, tablets). It tracks device assignments, repairs, and person–device associations.
3. Data Governance Principles
Dream adheres to the following data governance principles:
- Accountability: Team roles and responsibilities ensure compliance with data standards.
- Transparency: All data practices are clearly documented and accessible.
- Privacy and Security: Data must be handled using industry best practices and legal safeguards.
4. Data Collection and Classification
Based on the aforementioned data input sources, Dream may collect data from these various categories:
- Personal Identifiers: Name, ID, & email
- Device Management Data: Device assignments and repair history
- Communication Data: Phone numbers and email addresses
- Google Account Metadata: Google ID, sign-in information (non-sensitive), and account linkage data
- Organizational Information: Organization, location, and organizational structure
- Thumbnail and Titles: For identifying roles and personalization within the app
Data not collected includes race, ethnicity, health data, attendance records, behavioral information, and standardized assessment results.
5. Data Access and Roles
Access to user data is governed by Role-Based Access Control (RBAC) and granted on a "need-to-know" basis.
Vivacity Tech Roles:
- Software Developers: Improve application features and functionality
- Database Specialists: Organize and manage data systems
- Tech Leads: Oversee data practices and system integrity
- Customer Support: Individuals within Vivacity who assist customers
Dream User Roles:
| Role Name | Role Description |
|---|---|
| Super Admin | For organizations to oversee and manage use of the Dream application to ensure proper use |
| Vivacity Admin | For Vivacity employees (Customer Service, Tech Leads, etc.) to assist organizations in solving issues with the Dream app when they encounter an issue they cannot solve on their own. Also used to demo the application |
| Facilitator | Guide and assist users with their devices, repairs, and Dream |
| Location Admin | To keep track of users, devices, repairs, etc. that happen within a specific location |
| Organization Admin | To keep track of users, devices, repairs, etc. that happen within an organization |
| Repair Tech | To assist in managing repairs of devices and returning devices to users |
| Trained Repair Assistant | For trained individuals to assist in the device repair process for other users |
| Senior Repair Assistant | For trained individuals to assist in the device repair process for other users (similar to Trained Repair Assistant but a different skill level) |
| User | To keep track of their devices and their repairs |
| Loaner Manager | To manage who has access to loaner devices and what type of access they have |
| Custom Roles | Organizations have the ability to create their own custom roles, which may have access to user data depending on the organization's choice and reasoning |
All application access is authenticated and all users have access to multi-factor authentication (MFA).
Data Access
Personal Information
| Data | Not Collected | Optional | Currently Used | Source | Purpose | When is Data Deleted |
|---|---|---|---|---|---|---|
| Full Name | X | Dream & Google | Keep track of users and their devices & repairs | 1 year after account closure | ||
| Nickname | X | No current use | 1 year after account closure | |||
| Email Address | X | Dream & Google | To provide a way for Dream users to contact one another | 1 year after account closure | ||
| Phone Number | X | Dream | To provide a way for Dream users to contact one another | 1 year after account closure | ||
| Address | X | |||||
| Thumbnail Photo | X | To help Dream users (staff, other users, repair techs, etc.) personalize and identify people that they work with | 1 year after account closure | |||
| Title | X | Dream & Google | Help understand the person's role | 1 year after account closure | ||
| Personal ID | X | Dream | A unique identifier for a person to avoid confusing their data with another's | 1 year after account closure | ||
| Gender | X | No current use | 1 year after account closure | |||
| Preferred Gender | X | No current use | 1 year after account closure | |||
| Date of Birth | X | |||||
| Place of Birth | X | |||||
| Ethnicity or Race | X | |||||
| Language Information | X | |||||
| Conduct or Behavioral Data | X | |||||
| IP Address/Cookies | X | |||||
| Other Application Metadata | X | |||||
| Metadata on User Interaction With Application | X |
Personal Identifiers
| Data | Not Collected | Optional | Currently Used | Source | Purpose | When is Data Deleted |
|---|---|---|---|---|---|---|
| Local (Organization) ID Number | X | Dream | To identify the location associated with a person's devices & repairs | 1 year after account closure | ||
| Regional ID Number | X | |||||
| Provider/App Assigned Person ID Number | X | Dream | A unique identifier for a person to avoid confusing their data with another's | 1 year after account closure | ||
| App Username | X | Dream | For users to log in | 1 year after account closure | ||
| App Passwords | X | Dream | For users to log in (password is encoded) | 1 year after account closure |
Assessment/Attendance Data
| Data | Not Collected |
|---|---|
| Standardized Assessment Scores | X |
| Observation Data | X |
| Voice Recordings | X |
| Scheduled Activities/Courses | X |
| Staff Names | X |
| Daily Attendance | X |
| Activity/Session Attendance | X |
| Online Communication Captured | X |
| In-App Performance | X |
| User-Generated Content | X |
Transcript
| Data | Not Collected |
|---|---|
| Course/Program Grades | X |
| Course/Program Data | X |
| Course/Program Performance Scores | X |
Transportation
| Data | Not Collected |
|---|---|
| Transportation Assignment | X |
| Pick-Up/Drop-Off Location | X |
| Transportation Card ID Number | X |
Special Indicator
| Data | Not Collected |
|---|---|
| Language Learner Information | X |
| Low-Income Status | X |
| Medical Alerts/Health Data | X |
| Disability Information | X |
| Specialized Support Services | X |
| Living Situations | X |
Enrollment/Membership
| Data | Not Collected | Optional | Currently Used | Source | Purpose | When is Data Deleted |
|---|---|---|---|---|---|---|
| Organization Enrollment/Membership | X | Dream | To identify if the person is still active with the organization | 1 year after account closure | ||
| Level/Tier | X | |||||
| Home Group | X | |||||
| Assigned Coordinator | X | |||||
| Specific Programs | X | |||||
| Year of Completion | X | |||||
| Extracurricular or Related Activities | X | |||||
| Responses to Surveys or Questionnaires | X |
Related Contact Information (e.g., Guardian, Emergency Contact)
| Data | Not Collected |
|---|---|
| Address | X |
| Name | X |
| X | |
| Phone | X |
| Related Contact ID Number | X |
Organization Information
| Data | Not Collected | Optional | Currently Used | Source | Purpose | When is Data Deleted |
|---|---|---|---|---|---|---|
| Organization/Account | X | Dream | Organizational location data to help users with their devices & repairs | 1 year after account closure | ||
| Location/Site | X | Dream | Organizational location data to help with repairs/shipping | 1 year after account closure | ||
| Whitelisted IP Address | X | Dream | No current use | 1 year after account closure | ||
| Organizational Path | X | Dream & Google | Organizational data to help organizations organize users | 1 year after account closure |
Google Account Info
| Data | Not Collected | Optional | Currently Used | Source | Purpose | When is Data Deleted |
|---|---|---|---|---|---|---|
| Google ID | X | Sync Google account to Dream | 1 year after account closure | |||
| 2FA Enrollment | X | No current use | 1 year after account closure | |||
| Google Mailbox Setup | X | No current use | 1 year after account closure | |||
| Included in Global Address List | X | No current use | 1 year after account closure | |||
| Last Google Sign-In | X | No current use | 1 year after account closure | |||
| Google Account Creation Date | X | No current use | 1 year after account closure | |||
| Google Account Last Updated Date | X | No current use | 1 year after account closure | |||
| Google Account Deletion Date | X | No current use | 1 year after account closure |
6. Data Usage
Device Data
Vivacity Tech practices data minimization and uses device data for operational purposes, including:
- Manage assets and repairs
- Allow communication between authorized users and staff
- Improve the Dream application and its services
- Share with approved partners in order to enhance the platform
- Send to other internal Vivacity platforms that adhere to the same data standards, for the purposes of enhancing Dream
Personal Data
Personal data is not shared with third parties except as required to provide services explicitly requested by the organization and under a written agreement with data protection terms aligned to this policy.
7. Retention Periods
Vivacity Tech retains data for only as long as necessary:
| Data Category | Retention Period |
|---|---|
| Personal Identifiers | Active period + 1 year following account deactivation or separation from the organization |
| Communication Data | Active period + 1 year following account deactivation or separation from the organization |
| Device Management Records | Device lifecycle + 1 year |
| Google Integration Metadata | 1 year after account closure |
| Log Data and Usage Records | 90 days (unless extended for legal compliance) |
8. Deletion and Anonymization
Procedures
- Notification: Organizations receive a 60-day notice before data deletion
- Secure Deletion: Industry-standard erasure techniques are used
- Backup Deletion: Redundant backups are purged per retention schedules
- Anonymization: Where deletion isn't feasible, data is anonymized to remove personally identifiable information
Verification
All deletion and anonymization actions are logged and independently verified to ensure policy compliance.
9. Data Security
Dream implements strong security protocols, including:
- Encryption: All confidential data is encrypted in transit and at rest
- Network Controls: Firewalls, IDS, and secure gateways
- Vulnerability Testing: Regular security audits and penetration testing
10. Compliance and Monitoring
- Audits: Internal and third-party audits are conducted periodically
- Monitoring: Systems monitor for unauthorized data access or misuse
- Incident Response: A formal Incident Response Plan is in place for any breach
Vivacity Tech complies with all applicable federal, state, and regional privacy laws relevant to the personal data it processes. Vivacity will notify affected organizations of any data breach involving personal information within 72 hours of discovery.
11. Individual Rights
Upon request by the organization, Vivacity will assist in accommodating requests from individuals to access, review, or delete their data in compliance with applicable laws.
12. K–12 Education and Student Data
This section applies only when Dream is used by a K–12 school, school district, or other local educational agency ("LEA"). For K–12 customers, the terms of this section supplement the remainder of this Data Usage Policy. Where this section refers to "student data," it means personal information relating to a student that is provided to, collected by, or processed through Dream on behalf of an LEA.
Ownership and Control of Student Data
Student data collected or processed through Dream remains the property of and under the control of the originating school, district, or LEA. Vivacity Tech processes student data on behalf of the LEA and only for purposes associated with providing and supporting Dream and services requested or authorized by the LEA.
Student Data Collected by Dream
In a K–12 environment, the general data categories described elsewhere in this policy may include student-specific information such as:
- Student name, school or district ID, email address, and Dream-assigned identifiers
- Student account and Google account information described elsewhere in this policy
- School district, school building, organizational path, and enrollment or membership status
- Device assignments, repair history, and other device management information
- Optional information identified elsewhere in this policy, such as phone number, thumbnail photo, and title or role
Dream does not collect educational or sensitive student information such as:
- Standardized test or assessment scores
- Grades, transcripts, course performance, or curriculum data
- Daily or class attendance
- Student-generated educational content
- Student behavioral or conduct information
- Race or ethnicity
- Medical or health information
- Disability or specialized education information
- English language learner information
- Low-income status
- Transportation assignments or pick-up/drop-off information
- Parent or guardian contact information
- Student survey or questionnaire responses
- Academic or extracurricular activity information
Access to Student Data
Access to student data is governed by the Role-Based Access Control and security requirements described elsewhere in this policy and is limited to individuals with an authorized need to access the information.
K–12 customers may assign Dream roles to school or district personnel, students, repair personnel, or other authorized users. Schools and districts may also create custom roles. Because custom roles may provide access to student information, the LEA is responsible for determining which individuals receive those roles and the permissions associated with them.
Vivacity Tech personnel may access student data only as necessary to operate, maintain, secure, troubleshoot, support, or improve Dream, consistent with this policy and applicable agreements.
Use and Disclosure of Student Data
Vivacity Tech uses student data only for authorized purposes related to providing Dream and services requested by the LEA.
Student data is not shared with third parties except as required to provide services explicitly requested or authorized by the LEA and under written agreements containing data protection requirements consistent with this policy.
Subprocessors that process student data are subject to the requirements described in the Data Subprocessors section of this policy.
Student Data Retention and Deletion
For K–12 accounts, student personal identifiers and communication data are retained during the student's active period and for up to one academic year following graduation or other separation from the LEA, unless a different retention period is required by law or an applicable agreement.
Google integration metadata associated with a student is retained for up to one year following student graduation or separation.
Device management records, logs, backups, and other information remain subject to the retention and deletion requirements described elsewhere in this policy.
LEAs receive a 60-day notice before scheduled data deletion as described in the Deletion and Anonymization section of this policy.
Student and Parent/Guardian Rights
The LEA maintains control over student data provided to Dream. Upon request by the LEA, Vivacity Tech will assist the LEA in accommodating applicable student or parent/guardian requests to access, review, correct, or delete student data in accordance with applicable law and the LEA's instructions.
Parents, guardians, and students seeking to exercise rights concerning student data should ordinarily direct those requests to the applicable school, district, or LEA.
K–12 Privacy Compliance
When Dream is used in a K–12 educational environment, Vivacity Tech complies with applicable federal and state student privacy requirements, including the Family Educational Rights and Privacy Act ("FERPA"), the Children's Online Privacy Protection Act ("COPPA"), where applicable, and applicable state-specific student and education privacy laws.
Vivacity Tech will maintain student data in accordance with applicable contractual and legal requirements and will not use student data for unauthorized purposes.
In the event of a data breach involving student personal information, Vivacity Tech will notify the affected LEA within 72 hours of discovery, consistent with the notification commitment described elsewhere in this policy.
13. Data Subprocessors
Vivacity Tech may engage third-party service providers ("subprocessors") to support the operation, maintenance, and improvement of the Dream application. These subprocessors may have access to personal data only to the extent required to perform services on behalf of Vivacity and under strict contractual obligations.
All subprocessors are contractually bound to:
- Use data solely for the purpose of delivering services to Vivacity Tech;
- Maintain data security and confidentiality consistent with this policy and all applicable laws;
- Refrain from further disclosure or use of data for any non-authorized purpose.
Current Subprocessors:
- Google Cloud Platform (GCP): Provides infrastructure hosting and storage for the Dream application.
- Google Analytics: Used to collect anonymized usage metrics to improve the performance and usability of the Dream platform. No personally identifiable information is collected or processed through this service.
An up-to-date list of subprocessors is maintained and available upon request.
14. Training and Awareness
All employees receive mandatory data governance training upon onboarding and annually thereafter. Employees with elevated data access receive specialized training.
15. Amendments
This policy may be revised as needed to reflect:
- Legal or regulatory changes
- Advances in technology
- Operational modifications
Amendments will be communicated via the Dream platform and/or email to authorized users.
16. Non-Compliance
Violations of this policy may result in disciplinary action up to termination of employment or contracts. External partners may face agreement termination.
17. Contact Information
For questions or concerns about this policy, please contact:
Vivacity Tech Sales Team at [email protected]
Updated 2 days ago