Immersive Engineering, Inc.
Privacy Policy
How we collect, use and protect information when you use immerse2learn.com. This applies to students, instructors, administrators and organizations.
We are committed to protecting student privacy in compliance with FERPA, COPPA, GDPR where applicable, CCPA and CPRA, and other laws. We do not sell personal information, use it for targeted advertising, or allow users to post content or communicate electronically within the Service.
Student data we collect, and what we do not
To provide the Service, we collect only the minimum reasonably necessary:
- First and last name, or another unique identifier chosen by the instructor or school
- Email address, used solely for password recovery
- Password
We do not collect or require birth dates, Social Security numbers, school-issued student ID numbers, grades, transcripts, home addresses, phone numbers, financial information, or any other personally identifiable information beyond what is listed above.
The Service contains no features that allow users to post content, upload files, send messages, or engage in any form of electronic communication between users. All interaction is limited to course completion, progress tracking and certification.
Usage data
Usage data is collected automatically when the Service is used. It may include a device’s Internet Protocol address, browser type and version, the pages of the Service visited, the time and date of the visit, unique device identifiers and other diagnostic data.
Content protection
To protect our course content from copying and misuse, the Service may encrypt the content it delivers and add invisible watermarks that identify the organization, or a delivery reference linked to the account, to which the content was delivered. Access to protected content is recorded as part of the usage data above and kept for the same period as other system logs. This information is used only to secure the Service and to investigate misuse of our content. It is not used for advertising or profiling, and no additional student data is collected for it.
Cookies
We use session cookies to keep you signed in and to secure your session. We do not use advertising or cross-site tracking cookies. If your browser refuses cookies, you will not be able to sign in.
Third-party services
We use Akamai Cloud Computing in the United States for hosting, YouTube for embedded instructional video, and Google reCAPTCHA to protect our login and our website forms from automated abuse. Our separate online course store uses Stripe to process payments; Stripe has no access to the learning platform. Video and reCAPTCHA are contacted directly by your browser and receive only standard web request information — IP address, browser type and referring page — and, for reCAPTCHA, interaction signals used to detect automated abuse. They receive no names, email addresses, logins, scores, progress or certificates.
Data location and security
All data is stored in the United States. Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256, including backups). Passwords are stored as salted hashes. Backups are taken daily and kept for 12 days; system logs are kept for 90 days.
Security incidents
If an incident involving student data is confirmed, we notify the affected institution without undue delay and within the period its agreement or applicable law requires.
How we use personal data
To deliver instruction, assessment, progress tracking and certification; to manage accounts and account recovery; and to secure and support the Service, including protecting our content from copying and misuse.
Retention
We retain personal data only as long as necessary for the purposes set out in this policy, and to the extent necessary to comply with legal obligations, resolve disputes and enforce our agreements. Student data is retained only as long as the institution’s agreement requires. On the institution’s written request, or at the end of the agreement, it is deleted within a reasonable time.
FERPA compliance
We protect your information as required by the Family Educational Rights and Privacy Act and applicable state laws, and will only disclose education records or provide access to them in compliance with those laws.
Immersive Engineering acts solely as a service provider and processor of education records. The educational institution remains the data controller and determines how student data is used. We process student data only on the institution’s documented instructions and as required to deliver the Service. Institutions may request data export or portability at any time.
Institutional agreements
Where we have entered into a data privacy, data sharing or student data agreement with a school, district or institution, that agreement governs our handling of that institution’s student data and takes precedence over this policy to the extent the two differ.
Your rights and data ownership
Reports, certificates and progress records belong to your institution. We own platform content, course materials, and aggregated or de-identified system data such as server logs, usage analytics and platform telemetry.
Students should direct requests for access, correction or deletion to their institution; we act on the institution’s instructions within a reasonable time. Other users may contact support@immerse2learn.com.
Changes to this policy
We may update this policy from time to time. We will notify you of any changes by posting the new policy on this page.
Contact us
If you have any questions about this Privacy Policy, or wish to make a request regarding your data:
support@immerse2learn.com
Immersive Engineering, Inc.
+1 248 865 2001
© Immersive Engineering, Inc.