Data Privacy and Login Access Across Demme Learning Platforms
Logging into an educational platform can feel like unlocking the front door to your home. You want to know who has the key, what’s inside, and how everything is protected. This guide explains how Demme Learning collects, uses, and safeguards your data across all our digital platforms. It also explains how Single Sign-On (SSO) works behind the scenes to simplify your login experience without compromising security.
This article is designed to help homeschool parents, instructors, and school administrators understand our privacy policies and the systems that keep personal data secure and student access seamless.
Scope: This article applies to all platforms using Demme Learning’s central login system, including:
- The Digital Toolbox (legacy and current resources)
- The Early Access platform (new digital course experience)
- The Demme Learning Store site (for purchasing and managing products)
All of these platforms use MiniOrange for Single Sign-On (SSO). While data handling practices are consistent across systems, specific features and types of user interaction may vary slightly by platform. If you use more than one of these platforms, your login and basic account information are shared securely across them to ensure a unified experience.
What data is collected from instructors and students
Think of your account as a digital ID card. To provide a secure and personalized learning experience, we collect only the essential information needed to verify identity, support teaching, and deliver curriculum.
- Student Data: First name, last name, and optionally, school grade level. No email addresses are collected or used for students.
- Instructor and Admin Data: Email addresses and other limited details needed to support instruction and account management.
- Parental Consent (COPPA):
- If a student is under 13, data collection requires parental or administrator consent.
- When homeschool parents or instructors create accounts for students, they provide this consent during setup.
- Under COPPA, parents creating accounts for their own children are permitted to grant this consent directly, in accordance with U.S. law.
- If a student is under 13, data collection requires parental or administrator consent.
How do we use and protect that data
We treat your data like a locked file cabinet, opened only when needed and never shared without cause. Our goal is to support your educational journey without compromising your privacy.
Data is used only for:
- Improving functionality and performance
- Supporting instruction and student learning
- Internal analysis for product improvement
- Compliance with privacy regulations (e.g., GDPR for EU users)
Data is not:
- Sold, rented, or shared with third parties
Visibility Limits:
Instructors and administrators can only access the student data associated with their own groups. There is no visibility across different schools or parent accounts.
Security Measures Include:
- HTTPS encryption for all data in transit
- Access restrictions so only authorized Demme Learning staff can view personal data
- Breach response protocol. In the rare event of a breach, we notify users and regulatory authorities within 72 hours, as required by law
How Single Sign-On (SSO) works and who manages it
Single Sign-On (SSO) simplifies your experience by letting you use one login for multiple platforms. It’s like using one secure keycard to open several locked doors in the same building.
Here’s how it works:
- Powered by MiniOrange, using Xecurify technology
- Applies to: parent, instructor, admin, and store logins (not student accounts)
- Where credentials are stored: in a secure identity provider system managed by the MiniOrange team
- MiniOrange’s role: Acts as a data processor under contract with Demme Learning
What’s important to know:
- Student data is not part of the SSO system
- No personally identifiable student information is shared with MiniOrange
- The SSO system enhances security by reducing password fatigue and centralizing credential management
How long do we retain data, and how can users manage it
We retain data only as long as needed to fulfill educational or legal purposes. After that, your information is deleted using industry-standard encryption and data-wiping methods, similar to shredding a document instead of tossing it in the trash.
You or your legal guardian can:
- Request to view personal data
- Ask for corrections to data
- Request the deletion of your data
To submit a request, email: customerservice@demmelearning.com
Requests are typically handled within 30 calendar days.
What privacy laws do we comply with (COPPA, GDPR)
Demme Learning follows both U.S. and international privacy regulations. Our approach balances transparency, legal responsibility, and ease of use for families and educators.
Laws we follow include:
- COPPA (Children’s Online Privacy Protection Act): Applies to U.S. students under 13 and ensures data is collected only with parental or administrator consent.
- GDPR (General Data Protection Regulation): Applies to users in the European Union. Data processing is based on contractual need, user consent, or legitimate interest.
We also conduct regular audits and updates to keep our practices aligned with evolving security standards and legal requirements.
Cybersecurity Framework Alignment
Demme Learning’s Digital Toolbox follows the principles outlined in the NIST Cybersecurity Framework Version 1.1. Our internal security measures, including encrypted data transmission (HTTPS), strict access controls, breach notification procedures, and data lifecycle protocols, align with the five core functions of the NIST CSF: Identify, Protect, Detect, Respond, and Recover. While we are not formally certified under this framework, our practices adhere to its standards to ensure data protection and compliance.
Cookies and Tracking Technologies
We may use cookies to enhance your experience. Cookies are tiny pieces of data that help us understand how the site is performing.
- Cookies are used only for anonymous performance analytics
- We do not use them to track or collect personally identifiable data
- Learn more in our full Cookie Policy
Terms of Use
For more information about your rights and responsibilities as a user of our platform, please refer to our full Terms of Use.
Frequently Asked Questions (FAQ)
Does Demme Learning collect student email addresses?
No. Students log in with usernames only. Email addresses are not collected or stored for student accounts.
Is my student’s data shared with MiniOrange or other third parties?
No. Student data is excluded from the SSO system and is not accessed by MiniOrange.
Can I delete or update my child’s data?
Yes. Contact us at customerservice@demmelearning.com to submit your request.
Does using SSO affect learning content or student progress?
No. SSO only affects account access. It does not interfere with learning materials, progress tracking, or reporting.
I’m a parent using this from the UK or the EU. How do I request data removal?
Email customerservice@demmelearning.com and mention GDPR. Be sure to include the email address associated with your account.
How often is this policy reviewed?
We review and update policies regularly. You can always view the latest version on our website.Does my school need a signed Data Processing Agreement (DPA)?
Yes, if required. Please contact customerservice@demmelearning.com, and we’ll provide the