Data Deletion Procedure
Effective date: 06.08.2026 · Version 1.0 · Contact: privacy@canoanumis.org
This page describes exactly what data CANOA Edu holds, when it is deleted automatically, how your district can request deletion at any time, and how deletion is verified. It is written to be attached, as is, to your vendor file.
1. What we hold (and what we don't)
For each LMS deployment (your district's connection to CANOA Edu), we store: anonymous LTI student identifiers (sub), assignment variants, student answers, scores, and teacher assignment templates. We do not hold student names, emails, photos, rosters, or gradebooks — grades are passed to your LMS and live there. Deleting our copy of a submission does not affect grades already in your gradebook.
2. Automatic deletion (no action required)
- Student submissions: deleted automatically at the end of the school year + 90 days (rolling retention window of 455 days, daily purge).
- Teacher assignment templates: retained while the deployment is active, so teachers can reuse them next year; deleted 12 months after last use or upon request.
- Server logs: retained no longer than 30 days; contain no student identifiers beyond standard web-server fields.
3. Deletion on request
Who may request: the district contact named in the NDPA, or your LMS administrator (we verify the requester against the deployment's registered contacts).
Scope options:
- a single student (by opaque LTI identifier — your LMS admin can look it up; we cannot, because we don't know who students are);
- a single course/context;
- the entire deployment (all data for your district).
How: email privacy@canoanumis.org using the template below, or any written form containing the same information.
Timeline: acknowledgment within 2 business days; deletion executed and written confirmation issued within 10 business days.
4. Request template (copy and paste)
To: privacy@canoanumis.org Subject: Data deletion request — [District name] District / school: ______________________________ Requester name and role: ________________________ LMS platform and deployment ID (if known): ______ Scope of deletion: [ ] Entire deployment [ ] Course/context ID: ________________________ [ ] Single student, opaque LTI ID: ____________ Reason (optional): ______________________________ Requested by (signature / email from registered district address serves as signature): _________
Download this template as a text file
5. What deletion means technically
Deletion removes the records from the production database immediately. Backups are rotated by our hosting provider and are restored only for disaster recovery; if a restore ever occurred, deletions would be re-applied before the system returned to service.
6. Contract termination
When a district's agreement ends, deployment data is deleted within 30 days of termination. A certificate of deletion, listing scope and date, is sent to the district contact without being requested.
7. Verification
Your written confirmation includes: date of execution, scope (deployment / context / identifier), record counts deleted, and the name of the operator. Districts may re-verify at any time by requesting a data inventory for their deployment — the honest answer after deletion is "zero records," and we are happy to put that in writing.