Privacy Statement
1. Who we are and what this covers
pantherSIS is a Student Information System provided by OASIS Technologies (“OASIS,” “we,” “us,” or “our”) to schools, colleges and universities (“Institutions”). This Privacy Statement explains how we collect, use, share and protect personal information through the pantherSIS application, its AI assistant, its public forms and portals, and this website (together, the “Service”).
We do not sell personal information, and we do not use student or Institution data for advertising.
2. Our role for schools
Most personal information in pantherSIS, such as student, applicant, employee, alumni and donor records, is entered or controlled by an Institution. For that information the Institution decides what is collected and why, and OASIS processes it on the Institution’s behalf and under its instructions (a “service provider” or “processor”).
For Institutions subject to the Family Educational Rights and Privacy Act (FERPA), we act as a “school official” with a legitimate educational interest. We use education records only to provide the Service to that Institution and do not re-disclose them except as the Institution authorizes or the law requires.
If you are a student, applicant, employee or other member of an Institution’s community, please contact that Institution first about your records. It controls them, and we will help it respond to your request.
3. Information we collect
Information Institutions and their users provide
- Identity and contact details: names, ID numbers, addresses, email addresses, phone numbers, dates of birth and photographs.
- Education records: applications, enrollment, courses, grades, transcripts, attendance, program and degree progress, and learning-management activity.
- Financial information: student account balances, invoices, payments, and financial aid and eligibility information. Card and bank details entered for payments are handled by the Institution’s payment processor; pantherSIS does not store full card numbers.
- Employment information: for Institution staff, HR, payroll-related and personnel records the Institution chooses to keep in the Service.
- Content: documents, uploaded files, messages, letters, form responses and notes.
Information collected automatically
- Account and usage data: sign-in times, pages and features used, and actions taken, kept in audit logs so Institutions can see who did what.
- Device and log data: IP address, browser type and version, and error logs, used for security and troubleshooting.
Information from website visitors and prospects
- If you request a demo, join the beta, or chat with the pantherSIS agent on this website, we collect what you choose to give us, such as your name, institution, email address, phone number and your messages.
Information from integrations
- When an Institution connects services such as a learning management system, payment processor or reporting clearinghouse, we receive the data those services send so the integration can work.
4. How we use information
- to provide, operate, maintain and support the Service for the Institution;
- to authenticate users, including sending one-time verification codes by email or text message;
- to send the notifications, letters and messages an Institution or user asks the Service to send;
- to secure the Service, prevent fraud and abuse, and investigate incidents;
- to troubleshoot, fix errors and improve the reliability and performance of the Service;
- to respond to requests from website visitors and prospective customers; and
- to comply with law and enforce our Terms of Service.
We do not use Institution data for targeted advertising, do not build marketing profiles of students, and do not use it for any purpose unrelated to providing the Service.
5. AI features and your data
- Permission-bound. The AI assistant can reach only the records and actions the signed-in user is already allowed to access, limited to the module that user is currently working in.
- You confirm actions. The assistant proposes changes and acts only after the user confirms.
- No training on your data. We do not use Institution data or student records to train AI models. The model providers we use process requests under commercial terms that do not permit them to train on that data.
- Minimum necessary. Only the information needed to answer a given request is sent to the model provider, and requests are logged so Institutions can review assistant activity.
8. Security
We use administrative, technical and physical safeguards appropriate to the sensitivity of education and financial records, including encryption in transit, role-based permissions, verification codes for sensitive actions, audit logging, and restricted access to production systems. No system is perfectly secure. If we learn of a security incident affecting an Institution’s data, we will notify that Institution without undue delay so it can meet its own notification obligations.
9. Retention
We keep Institution data for as long as the Institution’s subscription is active, or as it directs. Many records, such as transcripts and financial aid files, have retention periods set by law or by the Institution. After a subscription ends, the Institution may request an export, and we then delete or de-identify the data within a reasonable period, subject to backup cycles and legal obligations. Information from website visitors is kept only as long as needed to respond and to maintain our business records.
10. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete or obtain a copy of your personal information, or to object to or restrict certain processing. Under FERPA, eligible students have the right to inspect and request amendment of their education records through their Institution.
- Students, staff and other Institution users: send requests to your Institution. We will support it in responding.
- Website visitors and prospects: contact us directly using the details below, and we will respond within the time the law requires.
We will not discriminate against you for exercising your privacy rights.
11. Children
The Service is provided to educational Institutions and is not directed at children under 13. Where an Institution serves students under 13, that Institution is responsible for providing any notice and obtaining any consent that laws such as the Children’s Online Privacy Protection Act require, and we process that information only on the Institution’s behalf.
12. International users
The Service is operated from, and data is stored in, the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.
13. Changes to this Statement
We may update this Privacy Statement from time to time. The “Last updated” date at the top shows when it last changed. For material changes we will give Institutions reasonable advance notice through the Service or by email.
14. Contact us
Questions or requests about this Privacy Statement can be sent to:
OASIS Technologies · pantherSIS
Email: lucian@iplexone.com
Web: panthersis.com