Privacy Policy

Privacy Policy

This Privacy Policy ("Policy") explains how Vivacity Tech PBC ("Vivacity Tech," "we," "us," or "our") collects, uses, and protects your personal information when you use the "Dream" web application (the "Service") that utilizes Google APIs. By accessing or using the Service, you consent to the practices described in this Policy.

Information We Collect

We may collect the following types of information:

  • Personal Information: When you use the Service, we may collect information that can be used to identify you, such as your name, email address, and other contact information. This information is collected when you register for an account or interact with the Service. Depending on the data you elect to provide, some student data may be collected.

  • Usage Information: We may collect information about how you use the Service, including your interactions with the Service, the content you view, and the actions you take.

  • Device Information: We may collect information about the device you use to access the Service, including device type, operating system, and unique device identifiers.

  • Location Information: If you grant us permission, we may collect information about your location when you use the Service.

How we collect data:

  • User-provided data when administrators, staff, or students enter or upload information in Dream (e.g., repair notes, contact info).

  • School-provided/imported data from the LEA's systems and Google Workspace for Education via the Admin SDK Directory API (e.g., users, org units, device inventory).

  • Device telemetry imported via the Chrome Management Telemetry API (e.g., battery and OS info).

  • Automatically generated data from use of the Service (e.g., audit logs, timestamps, role permissions). For each category, Dream's data inventory identifies the source and purpose

How We Use Your Information

Where permitted under applicable law, we may use your information for the following purposes:

  • To provide and maintain the Services including but not limited to sending confirmations, invoices, technical notices, product and services information, updates, and security alerts.

  • To administer your account with us.

  • To personalize your experience and provide content and features that are relevant to you.

  • To communicate with you, respond to your inquiries, and send you important updates and information.

  • To improve the Service and develop new features and functionality.

  • To monitor and analyze usage patterns and trends.

  • Link or combine with other information we get from third parties, to help understand your needs, customize our offerings to those needs and provide you with better service.

  • To comply with legal obligations and protect our rights and the rights of others.

The information we collect about you is necessary for the purposes listed in this Policy. If you refuse to provide information to us or if you request that we stop processing information about you, we may not be able to provide the same level of service to you. We may retain your personal data as necessary for the purposes described in this Policy, in accordance with Vivacity Tech's record retention practices. When we no longer need your information we will, unless it is needed to comply with applicable legal requirements, remove/destroy/delete your personal data and/or take steps to anonymize it.

Sharing Your Information

We may share your information in the following circumstances:

  • With third-party service providers and business partners who assist us in providing, maintaining, and improving the Service.

  • With third parties in connection with: (i) the establishment, exercise, or defense of legal claims; (ii) to comply with laws or to respond to lawful requests and legal process; (iii) to protect the rights and property of Vivacity Tech, our agents, customers, and others, including to enforce our agreements, policies, and terms of use; (iv) to detect, suppress, or prevent fraud; (v) to reduce credit risk and collect debts owed to Vivacity Tech; (vi) an emergency to protect the personal safety of Vivacity Tech, its customers, or any person; or (vii) as otherwise permitted by applicable law.

  • In connection with a merger, acquisition, or sale of all or a portion of our assets.

  • With your consent or at your direction.

We may also share aggregated or anonymized information in a form that does not directly identify you.

No Mobile opt-in data will be shared with third parties or affiliates.

Your Choices

You have the following choices regarding your information:

  • You can access and update certain information you have provided by logging into your account settings.

  • You can opt-out of receiving promotional emails by following the instructions in those emails.

  • You can disable location tracking through your device settings.

Security

Vivacity Tech takes reasonable technical, physical, and administrative steps to help protect your personal data in our custody or control from loss, misuse and unauthorized access, disclosure, alteration and destruction. Where you have chosen a password, you are responsible for keeping this password confidential. We ask you not to share a password with anyone or to reuse the same user ID and password on other sites. We take reasonable measures to protect your information, but no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of your data. Except for Vivacity Tech's own online activities on third-party websites and online services where we post our Policy, this Policy does not apply to, and Vivacity Tech is not responsible for, any other data practices of third-party websites and online services or the practices of other third parties. To learn about third-party data practices, please visit their respective privacy policies.

California Privacy Rights

If you are a California resident, you may have the right to request information from us about how we may share certain information about you with third parties for their own direct marketing purposes. Please see the "Your Rights and Choices" section below for details on the choices you may have regarding such sharing of your information.

Google Admin SDK Directory API

The "Dream" web application may utilize the Google Admin SDK Directory API ("Directory API") provided by Google. The Directory API allows administrators of enterprise domains to view and manage their organization's users, groups, devices, and related resources.

The Directory API service is hosted at https://developers.google.com/admin-sdk/directory/reference/rest. To interact with this service, we recommend using Google-provided client libraries. If your application needs to use your own libraries to call this service, you can refer to the following information when making API requests:

The following is a list of data that Dream pulls from the GAC:

  • Devices

  • Users

  • Organizational Units

Additionally, Dream can make changes to the GAC devices and users via the aforementioned APIs.

Discovery Document

A Discovery Document is a machine-readable specification for describing and consuming REST APIs. It is used to build client libraries, IDE plugins, and other tools that interact with Google APIs.

The Directory API service provides a Discovery Document at the following URL:

https://admin.googleapis.com/$discovery/rest?version=directory_v1

API Methods

The Directory API provides various methods to interact with resources such as users, groups, and devices. These methods include, but are not limited to, retrieving information, updating properties, and issuing commands for certain devices. Please review the Directory API documentation for detailed information on these methods.

Google Chrome Management Telemetry API

The "Dream" web application may utilize the Chrome Management Telemetry API provided by Google. The Chrome Management Telemetry API enables us to monitor the operation and health of devices running ChromeOS.

Please note that the appropriate reporting policies need to be enabled to ensure that data is reported from the device.

Quick Overview of API Methods

URLs for API methods are relative to https://chromemanagement.googleapis.com/v1/customers/$CUSTOMER :

DescriptionRelative URLHTTP Method
List telemetry information for ChromeOS devices/telemetry/devices/GET
List telemetry information for ChromeOS users/telemetry/users/GET
List telemetry events for the given customer/telemetry/events/GET
Admin Privileges

The Telemetry API respects admin role delegation. Admins must have the permission "Services - Chrome Management - Manage ChromeOS Devices - Manage ChromeOS Devices (read-only)" to use the Telemetry API. To manage admin roles and privileges, visit "Admin Console - Admin Roles." Note that admin roles can be assigned directly to a Service Account.

API Scopes

The Chrome Management Telemetry API requires the following OAuth scope:

https://developers.google.com/chrome/management/guides/telemetry_api

For more information about OAuth scopes and authentication, please refer to the Authentication Overview.

The following is a list of data that Dream pulls from the Telemetry API for devices in an account fleet:

  • Battery Information

  • Operating System Information

Your Rights and Choices

You may ask us not to process your personal data for marketing purposes. In some jurisdictions, you also have the right to opt-out of the disclosure of your personal data to third parties for the third parties' direct marketing purposes.

You can exercise your right to prevent such processing by: (i) following the opt-out instructions in promotional emails; (ii) checking certain boxes on the forms we use to collect personal data; and (iii) for email marketing, by visiting your account settings on our website. You may also make requests about your contact preferences and changes to your information by contacting your account manager.

If you opt-out of promotional emails, we may still send you non-promotional emails, such as emails about your accounts or our ongoing business relations. You may access, correct or delete some personal and account information maintained in your account by logging into your account on our website.

To request access to, or the correction or deletion of any other information about you or content you post on our Sites, or to exercise any right to restrict or object to processing or data portability, please contact your account manager. We reserve the right to decline requests unless required by applicable law. Opt-out/controls: Dream shares student data with subprocessors only as necessary to provide the Service, and does not share student data with third parties for their own purposes. Where optional integrations exist, they are off by default and can be enabled/disabled by the LEA at any time.

Children's Privacy

Dream is not directed at children under the age of 13.

Changes to this Policy

We may update this Privacy Policy from time to time. Any changes will be effective immediately upon posting the updated Policy on the Service. We encourage you to review this Policy periodically.

Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at [email protected].


Did this page help you?