Built to meet school requirements
Compliance isn't a checkbox for us. It's the baseline expectation when you're handling data from real students in real schools.
Children's Online Privacy Protection Act
Elysian currently serves students aged 13 and above, which means COPPA's strictest requirements around under-13 data collection don't apply to our core product. For any edge cases, we obtain appropriate consent and strictly limit data collection.
Family Educational Rights and Privacy Act
Schools retain ownership of their student data. Elysian acts as a service provider under the school's authority — not an independent data controller. We do not access, use, or share student education records outside of providing the service.
General Data Protection Regulation
For schools and students in the European Economic Area, we support GDPR requirements including data subject rights, lawful basis for processing, and transparent data practices.
Where we operate
We adapt to local requirements in every jurisdiction we serve.
United States
In addition to FERPA and COPPA, we comply with state-specific requirements including CCPA (California) and other state educational privacy laws.
Asia-Pacific
We comply with data protection laws in Singapore (PDPA), Australia (Privacy Act), and other Asia-Pacific jurisdictions where we operate.
We provide a full DPA
Every institutional client receives a Data Processing Agreement that covers:
Need compliance documentation?
We can provide DPAs, security questionnaires, and compliance documentation for your procurement process.