Skip to content

Data Deletion Procedure

Effective date: 06.08.2026 · Version 1.0 · Contact: privacy@canoanumis.org

This page describes exactly what data CANOA Edu holds, when it is deleted automatically, how your district can request deletion at any time, and how deletion is verified. It is written to be attached, as is, to your vendor file.

1. What we hold (and what we don't)

For each LMS deployment (your district's connection to CANOA Edu), we store: anonymous LTI student identifiers (sub), assignment variants, student answers, scores, and teacher assignment templates. We do not hold student names, emails, photos, rosters, or gradebooks — grades are passed to your LMS and live there. Deleting our copy of a submission does not affect grades already in your gradebook.

2. Automatic deletion (no action required)

3. Deletion on request

Who may request: the district contact named in the NDPA, or your LMS administrator (we verify the requester against the deployment's registered contacts).

Scope options:

How: email privacy@canoanumis.org using the template below, or any written form containing the same information.

Timeline: acknowledgment within 2 business days; deletion executed and written confirmation issued within 10 business days.

4. Request template (copy and paste)

To: privacy@canoanumis.org
Subject: Data deletion request — [District name]

District / school: ______________________________
Requester name and role: ________________________
LMS platform and deployment ID (if known): ______
Scope of deletion:
  [ ] Entire deployment
  [ ] Course/context ID: ________________________
  [ ] Single student, opaque LTI ID: ____________
Reason (optional): ______________________________
Requested by (signature / email from registered
district address serves as signature): _________

Download this template as a text file

5. What deletion means technically

Deletion removes the records from the production database immediately. Backups are rotated by our hosting provider and are restored only for disaster recovery; if a restore ever occurred, deletions would be re-applied before the system returned to service.

6. Contract termination

When a district's agreement ends, deployment data is deleted within 30 days of termination. A certificate of deletion, listing scope and date, is sent to the district contact without being requested.

7. Verification

Your written confirmation includes: date of execution, scope (deployment / context / identifier), record counts deleted, and the name of the operator. Districts may re-verify at any time by requesting a data inventory for their deployment — the honest answer after deletion is "zero records," and we are happy to put that in writing.