Legal

Privacy Policy

Last updated: June 24, 2026

The most important things to know up front:

  • Korus stores data in U.S.-based cloud infrastructure. AI and ML processing is performed by providers operating under U.S.-only data residency commitments.
  • Student identity data is stored under strict access controls and separated from response data in normal operations.
  • All access to the Korus platform requires SAML 2.0 SSO authentication. There is no anonymous or unauthenticated access.
  • Korus is FERPA-compliant. A Data Processing Agreement (DPA) and Business Associate Agreement (BAA) are available for institutional customers.
  • Korus does not sell customer data to any third party.

1. Scope of this policy

This Privacy Policy describes how Korus Education, Inc. ("Korus," "we," "us") collects, uses, discloses, and protects information in connection with the Korus platform, our marketing website at heykorus.com, and related services (collectively, the "Services").

Korus is a business-to-business service. Our direct customer is the educational institution ("Institution") that licenses the platform. When Korus processes student, faculty, or staff data through the platform, we do so as a service provider to the Institution and under the terms of our Data Processing Agreement (DPA) with that Institution. The Institution remains the controller of that data.

2. Information we collect

a. Information provided by Institutions

Institutions provide roster, course, and identity information through their Student Information System (SIS), Learning Management System (LMS), Identity Provider (IdP), or other supported integrations. This typically includes name, institutional email, role, course enrollment, and identifiers required to route surveys correctly.

b. Information provided by end users

When students, faculty, or staff use the platform, we receive the content of their survey responses, ratings, and any free-text input they choose to submit, along with timestamps and the survey context (course, instructor, term).

c. Authentication and access information

We receive authentication metadata from the Institution's Identity Provider through SAML 2.0 SSO, including user identifier and session attributes required to grant access.

d. Technical and usage information

We log technical information needed to operate and secure the platform: IP address, browser and device type, pages accessed, actions taken in the application, and error and performance data.

e. Information from our marketing website

On heykorus.com, we collect information you voluntarily provide through forms (for example, demo requests, pilot applications, and newsletter sign-ups), as well as standard analytics and cookie information. See Cookies and analytics below.

3. How we use information

We use information to:

  • Deliver, operate, secure, and improve the Services for the Institution.
  • Authenticate users and enforce access controls.
  • Generate the analyses, summaries, reports, and signals that are the purpose of the platform (Korus Survey, Reports, Discover, and Sense).
  • Diagnose problems, prevent abuse, monitor system health, and respond to support requests.
  • Comply with legal obligations and enforce our agreements.
  • Communicate with Institution administrators about service updates, security notifications, and account matters.

We do not use student or institutional response data to train foundation models and we do not allow our AI/ML providers to do so. Customer data is processed for the customer's benefit only.

4. How we share information

We share information only in the following limited circumstances:

  • With the Institution. Authorized administrators and other roles at the Institution can access data as configured by the Institution.
  • With subprocessors. We use a small number of vetted subprocessors — primarily U.S.-based cloud infrastructure and AI/ML providers — bound by contractual obligations consistent with this policy and the applicable DPA. A current list of subprocessors is available on request.
  • For legal reasons. We may disclose information if required by law, subpoena, court order, or other valid legal process, or to protect the rights, property, or safety of Korus, our customers, or the public. Where lawful, we notify the affected Institution before disclosing.
  • In connection with a business transaction. If Korus is involved in a merger, acquisition, financing, or sale of assets, customer data may transfer subject to the confidentiality and use restrictions in this policy and the applicable DPA.

Korus does not sell personal information. Korus does not share personal information for cross-context behavioral advertising.

5. Data retention

Korus retains customer data for the duration of the Institution's subscription and according to the retention terms in the applicable agreement. On termination, customer data is deleted or returned in accordance with the DPA, typically within 30 days of the end of the contract or a documented deletion request, subject to any legal hold requirements.

Logs and operational data are retained for the period required to operate and secure the Services and to satisfy audit and compliance requirements.

6. Security

Korus uses administrative, technical, and physical safeguards designed to protect customer data, including encryption in transit and at rest, SAML 2.0 SSO-only access, role-based access controls, audit logging, and ongoing monitoring. For details, see our Trust & Security page.

No system is perfectly secure. If we become aware of a security incident affecting customer data, we will notify the affected Institution in accordance with the applicable DPA and applicable law.

7. Your choices and rights

Because Korus processes student, faculty, and staff data on behalf of the Institution, requests to access, correct, delete, or restrict the use of that data should generally be directed to the Institution, which is the data controller. Korus will support the Institution in responding to verifiable requests as required by FERPA, GLBA, GDPR (where applicable), the CCPA/CPRA, and other applicable privacy laws.

For information you provide directly to Korus through our marketing website (for example, an email address used to subscribe to updates), you may unsubscribe at any time using the link in our emails or by contacting us at team@heykorus.com.

8. Children's privacy

Korus is designed for use by adult learners and staff at higher-education institutions. The platform is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact team@heykorus.com and we will take appropriate steps.

9. Cookies and analytics

The Korus platform uses cookies and similar technologies that are necessary to authenticate users, maintain sessions, and operate the Services securely.

Our marketing website at heykorus.com uses a limited set of analytics and product-analytics tools (such as PostHog) to understand how visitors find and use the site, in order to improve it. These tools may set cookies or use similar identifiers. You can control cookies through your browser settings; disabling cookies may affect site functionality.

10. International users

Korus is operated from the United States, and our infrastructure and processing are located in the United States. If you access the Services from outside the United States, you do so voluntarily and understand that your information will be transferred to and processed in the United States.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date below and, where appropriate, notify Institution administrators through the platform or by email.

12. Contact us

For privacy questions, to request our DPA or BAA, or to exercise any rights described above, contact:

Korus Education, Inc.
Email: team@heykorus.com

For the full DPA, BAA, subprocessor list, or any other documentation, contact team@heykorus.com. See also our Trust & Security and FERPA pages.

Questions about how Korus handles data?