For districts
District documents
A complete seven-document procurement packet for technology directors, special education directors, and procurement reviewers. Download them individually below, or take the whole packet as a single ZIP.
Complete 7-document procurement packet
Downloads
Policy and specification PDFs
The same content lives on the web at /product-overview, /privacy, /security, and /district-addendum, so reviewers can read before downloading.
Download complete packet (.ZIP)
All four policy PDFs, both completed assessments (readable PDF plus the official spreadsheet), and the cover letter in one file, ready to attach to a vendor review.
ZIP • 7 documents • 1.5 MB • v1.3
Product overview and functional specification
Scope by MTSS tier, roles and permissions, technical specifications, Chromebook and Windows support, use cases, and accessibility commitments.
Download PDFPDF • 6 pages • 371 KB • v1.3Privacy policy
FERPA school official status, what the application collects, why we use it, sub-processors, retention periods, student and parent rights, and contact information.
Download PDFPDF • 5 pages • 621 KB • v1.3Data security and incident response policy
Encryption, access control, identity configurations, shared hosting responsibility, backups, monitoring, incident response timelines, breach notification, and current attestations.
Download PDFPDF • 6 pages • 727 KB • v1.4District addendum and schedule of data
Line-item schedule of data, excluded data categories, optional facial lookup data, named hosting providers and regions, deployment scope, breach cooperation, and state privacy addenda.
Download PDFPDF • 8 pages • 858 KB • v1.4CAIQ v4.1 self-assessment (completed)
The Cloud Security Alliance Consensus Assessments Initiative Questionnaire, completed for this service: 283 answers covering audit, application security, continuity, encryption, identity, logging, incident response, supply chain, and vulnerability management.
Download PDFPDF • 31 pages • 64 KB • v1.1Download spreadsheet (.xlsx)Spreadsheet • official form • 148 KB • v1.1HECVAT 4.1.6 self-assessment (completed)
The EDUCAUSE Higher Education Community Vendor Assessment Toolkit, completed for this service: hosting, datacenter, authentication, accessibility, privacy, and AI sections, with non-applicable sections noted.
Download PDFPDF • 28 pages • 63 KB • v1.1Download spreadsheet (.xlsx)Spreadsheet • official form • 635 KB • v1.1Cover letter for your procurement packet
We also have a short cover letter that answers the common district questions in one place: what the product is, who stores the data and how FERPA applies, what security controls and breach protocols are in place, exactly who hosts the data and where, and where to find the schedule of data.
Download cover letter PDFPDF • 2 pages • 50 KB • v1.3
About the completed assessments
The CAIQ v4.1 and HECVAT 4.1.6 above are completed self-assessments, answered from the same controls documented in the policies in this packet. Each is provided as a readable PDF and as the official spreadsheet form. Answers reflect the service as documented today; where a control is operated by infrastructure providers, the answer says so. Questions about any answer: help@breatheasy.net.
NDPA
NDPA exhibit crosswalk
This table maps common data privacy agreement exhibit items to the corresponding section in the privacy policy and the data security policy. Every section name links straight to that heading on the live page.
The line-item Schedule of Data, excluded data categories, named hosting providers and regions, deployment scope, and state-specific addenda are contained in the district addendum. We serve districts nationwide: Nevada terms under NRS 388.267 through 388.296 ship by default, and the standard NDPA state-specific terms for California (CSDA), Texas (TX-NDPA), Illinois (SOPPA), and New York (Education Law 2-d) are available on request. The signed NDPA exhibit itself is available for district counsel from help@breatheasy.net.
Document versions current as of September 18, 2026. PDFs and the ZIP packet are regenerated whenever these pages change, so the live pages at /product-overview, /privacy, /security, and /district-addendum always reflect the most recent text.