Last Updated: December 12, 2025
Quarlo Software LLC ("Quarlo") is committed to protecting student privacy and complying with the Family Educational Rights and Privacy Act (FERPA). We work with higher education institutions to ensure that student data is handled appropriately and in accordance with federal regulations.
This page provides information for institutional partners about our FERPA compliance practices and how to establish a Data Processing Agreement (DPA) with Quarlo.
Under FERPA, Quarlo operates as a "school official" with a "legitimate educational interest" when contracted by an educational institution. This designation allows us to access student education records necessary to provide our services without requiring individual student consent.
Legitimate Educational Interest: Quarlo provides AI-powered interview preparation services that support student career readiness and employment outcomes—a core educational mission of higher education institutions.
Quarlo processes minimal student data necessary to provide our services:
| Data Type | Purpose | Retention |
|---|---|---|
| Institutional Email | Account authentication, institution verification | Until account deletion |
| Resume Content | AI-powered interview prep generation | User-controlled deletion |
| Job/Company Information | Tailored interview preparation | User-controlled deletion |
| Community Contributions | Interview questions and experiences shared voluntarily | Anonymized upon deletion |
Students have full control over their data:
Data Deletion Policy: When a user deletes their account, all interview preps are permanently deleted. Contribution records are scrubbed to minimal data (company name, job title, and interview date only), preserving interview questions for the community research pipeline while removing all personal information. Scrubbed data cannot be traced back to any individual.
Community contributions (interview questions, experiences shared publicly) are anonymous by design and are retained to benefit future students.
Quarlo uses the following sub-processors to deliver our services. All sub-processors are based in the United States and maintain appropriate security measures:
| Category | Purpose | Data Processed |
|---|---|---|
| AI Language Model Provider | AI interview prep generation | Resume text, job descriptions (not stored by provider) |
| Backup AI Provider | Fallback AI processing | Resume text, job descriptions (zero retention) |
| Embedding Service | Text embeddings for search | Content text (converted to vectors) |
| Database Provider | Database and authentication | All user data (encrypted at rest) |
| Hosting Provider | Application hosting | Request logs (anonymized) |
| Company Research Service | Employer intelligence gathering | Company names, job titles |
| Email Delivery Service | Transactional email | Email addresses |
| Error Monitoring Service | Application health | Technical metadata (may include email in error context) |
We will notify institutional partners of any changes to our sub-processor list with at least 30 days notice.
Our Data Processing Agreement, available to partner institutions upon request, includes a complete list of named sub-processors with their legal names, processing roles, and data handling commitments.
Quarlo implements industry-standard security measures to protect student data:
Initial Notification (72 hours): For institutions with a signed Data Processing Agreement, Quarlo will provide an initial breach notification within 72 hours of discovering a Security Breach affecting Student Data, including a preliminary description of the nature of the breach and immediate containment steps taken.
Formal FERPA Notification (45 days): Quarlo will cooperate with the Institution's obligations under FERPA to provide formal institutional notification within 45 days of the breach, supplying all information necessary to fulfill FERPA notification requirements.
Our breach notification will include:
Quarlo will never use student data for:
Educational institutions interested in partnering with Quarlo can request a formal Data Processing Agreement that includes:
Contact us to discuss your institution's requirements
Subject Line: FERPA DPA Request - [Institution Name]