1. Introduction
Cresco is a school management platform provided by Broder ("Broder," "Cresco," "we," "us," or "our"). Cresco helps schools manage academic, administrative, communication, financial, student-support, transportation, and other school-related activities in a unified digital environment.
This Privacy Policy explains how personal information may be collected, processed, stored, accessed, shared, and protected when schools and their users use Cresco.
Cresco is primarily provided to schools under a contractual agreement. Individual users do not independently register for Cresco. Accounts are created or provisioned in connection with a participating school.
For most information relating to students, parents or guardians, teachers, and school staff, the school determines what information is entered into Cresco, who may access it, and how it is used for school purposes. Broder provides and operates Cresco in accordance with its agreement with the school.
Certain arrangements may differ depending on the school's selected deployment, hosting, or service model. Where applicable, the school's agreement with Broder will define additional terms relating to data processing, hosting, retention, backups, and responsibilities.
2. Who Uses Cresco
- Students of any age;
- Parents and legal guardians;
- Teachers;
- School administrators;
- Heads of departments and academic leaders;
- Coordinators;
- Counselors;
- Nurses and medical staff;
- Accountants and financial staff;
- Other school employees, contractors, and authorized personnel;
- School representatives who contact Broder regarding Cresco; and
- Other individuals whose information is legitimately maintained by a school through the platform.
Students may have Cresco accounts regardless of age. Schools are responsible for determining whether student accounts should be created and for obtaining any parental, guardian, or other authorization required for students to use Cresco and for their information to be processed through the platform.
3. Information Processed Through Cresco
3.1 Student Information
- Full name;
- Student identification information;
- Profile photograph;
- Date of birth;
- Gender;
- Contact information;
- Address;
- Academic year, class, section, group, and division;
- Enrollment and re-enrollment history;
- Promotion, failure, graduation, transfer, and withdrawal history;
- Courses and academic programs;
- Grades and assessment results;
- Report cards;
- Assignments and student work;
- Attendance and absence records;
- Conduct and behavioral information;
- Teacher comments and observations;
- Disciplinary information;
- Educational accommodations and special needs;
- Parent and guardian relationships;
- Uploaded documents, photographs, videos, and files;
- Transportation and school bus information;
- Financial information relating to the student's school account; and
- Other information necessary for the school's educational or administrative activities.
Schools may also assign school-defined labels or attributes to students for categorization, organization, filtering, or operational purposes.
3.2 Health, Medical, Counseling, and Other Sensitive Information
- Allergies;
- Medical conditions;
- Medication information;
- Disabilities or special educational needs;
- Emergency medical information;
- Nurse visits and records;
- Counseling information;
- Behavioral or student-support information;
- Educational accommodations; and
- Other health or welfare information entered by authorized school personnel.
Access to such information is subject to Cresco's applicable role-based access controls and the user's relationship to the relevant school or student. Schools are responsible for determining what sensitive information is appropriate to maintain through Cresco and ensuring that they have the appropriate authority to process that information.
3.3 Parent and Guardian Information
- Name;
- Contact information;
- Relationship to students;
- Account information;
- Communications;
- Financial or billing-related information;
- Documents and files; and
- Other information maintained by the school.
Schools are responsible for establishing and maintaining the correct relationships between students and their parents or guardians. This includes managing situations involving custody arrangements, access restrictions, separated or divorced parents, or other circumstances affecting who is authorized to access a student's information. Cresco applies the relationships and access permissions established through the school and does not independently determine an individual's legal entitlement to access a student's records.
3.4 Teacher and School Staff Information
- Name;
- Contact details;
- Profile information;
- Employment or school role;
- Assigned classes, courses, departments, or responsibilities;
- Account information;
- Communications;
- Activity and audit history;
- Uploaded documents and files; and
- Other information required for school operations.
3.5 Financial Information
- Tuition and fee information;
- Invoices;
- Amounts due;
- Payment status and history;
- Discounts;
- Scholarships or financial arrangements;
- Receipts; and
- Related financial records.
Where online payments are supported, payment transactions may be processed through authorized third-party payment providers. Cresco does not need to store complete payment card credentials when those credentials are processed directly by an authorized payment provider.
3.6 Communications and Content
- Internal messages;
- School announcements;
- Emails generated or managed through Cresco;
- Push notifications;
- Comments;
- Attachments;
- Uploaded files;
- Student work;
- Photographs;
- Videos; and
- Communication history and related metadata.
Schools and their users are responsible for ensuring that they have appropriate authority to upload, distribute, or otherwise process content through Cresco.
3.7 Technical, Security, and Audit Information
- Login and authentication activity;
- IP addresses;
- Device and browser information;
- Dates and times of access;
- Security events;
- System activity;
- Error and diagnostic information;
- Administrative activity; and
- Audit records.
Cresco may maintain audit trails of actions performed through the platform, including actions affecting student records, grades, user accounts, financial records, permissions, exports, and administrative settings. Audit information may identify the user who performed an action, the action performed, the affected information, and relevant timestamps or contextual information.
4. School Bus and Transportation Information
- Student bus assignments;
- Bus attendance or boarding information;
- Transportation schedules;
- Bus routes;
- Vehicle location information; and
- Information indicating whether a student is recorded as being aboard a particular bus.
Cresco may therefore allow authorized users to infer a student's approximate location while that student is recorded as being aboard a tracked school vehicle. Cresco's transportation functionality is intended to track the school vehicle, not continuously track the location of a student's personal mobile device. Schools determine whether and how transportation tracking features are used and are responsible for providing any notices or obtaining any permissions required for their use.
5. How Information Is Used
- Provide and operate the Cresco platform;
- Manage user accounts and authentication;
- Deliver educational and administrative functionality;
- Maintain student academic records;
- Manage enrollment and school structures;
- Record grades, assessments, attendance, conduct, and comments;
- Generate report cards and other school reports;
- Facilitate communication between authorized users;
- Manage parent and guardian access;
- Support student health, counseling, welfare, and educational needs;
- Manage school transportation;
- Manage tuition, billing, and financial records;
- Generate and manage documents and files;
- Provide authorized integrations;
- Provide technical support;
- Troubleshoot errors and service issues;
- Maintain security and investigate suspected unauthorized activity;
- Maintain audit records;
- Create backups where applicable;
- Improve Cresco's reliability, functionality, and performance;
- Comply with legal or contractual obligations; and
- Otherwise provide services requested by the school.
Broder does not use school-provided personal information for targeted advertising. Broder does not sell school-provided personal information to advertisers or allow advertisers to build advertising profiles from Cresco school data.
6. Artificial Intelligence Features
Cresco may provide artificial intelligence-assisted features. Depending on the functionality available, AI may be used for purposes such as analyzing school or academic data, assisting users in understanding information, building or assisting with examinations and assessments, assisting with reports, rewriting or improving queries or written content, and other productivity or analytical functions requested by authorized users.
Cresco may use third-party AI service providers to perform these functions. Information necessary to fulfill an AI request may therefore be transmitted to an authorized AI service provider.
Broder does not use school or user personal information to train its own artificial intelligence models. Broder's use of third-party AI services is intended to provide requested functionality rather than to create advertising profiles or independently commercialize school data.
Schools and authorized users should use AI functionality appropriately and should avoid submitting information to an AI feature where doing so is unnecessary for the intended task. AI-generated content may require review by an authorized user before it is relied upon for educational, administrative, or other decisions.
7. School and Broder Responsibilities
Cresco operates within a school-managed environment. Depending on the circumstances and applicable agreement, the school generally determines which users receive Cresco accounts, what student and school information is entered into Cresco, which users are assigned to available roles, which students are associated with particular parents or guardians, what information is uploaded, which Cresco features are used, which authorized integrations are enabled, and how school records are used for educational and administrative purposes.
Broder provides the technology and related services necessary to operate Cresco according to the applicable agreement. Where Broder processes school data on behalf of a school, Broder uses that data to provide, maintain, support, secure, and improve the contracted service and for other purposes described in this Privacy Policy or the applicable school agreement.
8. Role-Based Access
Cresco uses role-based access controls to limit access to information. Access may depend on the user's predefined role, the school to which the user belongs, the user's relationship to a student, the classes, courses, departments, or responsibilities assigned to the user, and the type of information being accessed.
Different roles may therefore have access to different information. Schools are responsible for assigning users to the appropriate available roles. Cresco's role and permission structure may evolve as the platform develops.
9. Access by Broder Personnel
Authorized Broder personnel may access school information when reasonably necessary to provide customer support, troubleshoot technical problems, investigate errors, maintain Cresco, perform migrations or contracted technical services, investigate security incidents, restore or manage data where applicable, or fulfill other support or operational obligations to the school.
Such access is intended for legitimate support, security, maintenance, and operational purposes and is limited to authorized personnel. Broder personnel are not authorized to browse school information for unrelated purposes.
10. Hosting, Deployment, and Data Location
Cresco may be deployed using different technical models depending on the agreement with a school. These may include infrastructure managed by Broder, dedicated cloud environments, cloud infrastructure owned or controlled by the school, infrastructure managed by Broder on behalf of the school, on-premises deployments, local backup arrangements, or other agreed deployment configurations.
As a result, the location and party responsible for hosting, infrastructure management, backups, and related operations may differ between schools. Personal information may be stored or processed in Lebanon or in other countries depending on the deployment model, cloud infrastructure, backup arrangements, technical service providers, AI service providers, payment providers, authorized integrations, and other infrastructure required to provide Cresco.
Where specific hosting, residency, backup, or infrastructure requirements apply, they may be addressed in the agreement between Broder and the school.
11. Service Providers and Subprocessors
Broder may use authorized third-party providers to help operate and provide Cresco. These providers may perform services including cloud hosting, database services, data storage, backups, email delivery, push notifications, artificial intelligence services, payment processing, security services, error monitoring, technical infrastructure, analytics, and other services necessary to operate Cresco.
These providers may process information as necessary to perform services for Broder or the relevant school. Broder may change service providers as Cresco's infrastructure and services evolve.
12. School-Authorized Third-Party Integrations
Cresco may integrate with third-party services at the request or authorization of a school. These may include identity providers, educational platforms, accounting systems, payment services, communication services, productivity tools, or other systems.
When a school enables an integration, Cresco may exchange information with that service as necessary to provide the integration. The third party's own privacy practices may apply to information processed independently by that third party. Schools are responsible for determining whether a third-party integration is appropriate for their use and for maintaining any necessary agreements or permissions relating to that service.
14. Public Website and Demo Requests
Cresco includes publicly accessible pages through which school representatives and other visitors may learn about the service or contact Broder. Visitors may submit information through contact, demo request, or similar forms.
This information may include name, email address, phone number, school or organization, professional role, information included in a message, and other information voluntarily submitted.
Broder may use this information to respond to the inquiry, arrange demonstrations, communicate about Cresco, evaluate potential business relationships, and maintain appropriate business records. This information is collected directly by Broder rather than on behalf of an existing Cresco school customer.
15. Service Communications
Cresco may send communications necessary to operate the service, including account-related communications, password reset messages, authentication or security alerts, school announcements, grade or report notifications, reminders, push notifications, administrative notifications, and other communications initiated by or relating to the user's school.
Broder does not use school-provided student, parent, teacher, or staff contact information for unrelated direct marketing.
16. Children's Privacy
Cresco is designed for use by schools and knowingly processes information relating to children and students of different ages. Students do not independently sign up for Cresco. Student accounts are created in connection with a participating school.
- Determining whether a student should have a Cresco account;
- Having appropriate authority to provide student information to Cresco;
- Providing required notices to parents or guardians;
- Obtaining parental, guardian, student, or other consent or authorization where required; and
- Managing access to student information.
Broder relies on the school's authority to provide and process student information through Cresco in connection with the services requested by the school. Parents or guardians who have questions about information held about their child should generally contact the child's school.
17. Photos, Videos, Student Work, and Uploaded Content
Schools and authorized users may upload photographs, videos, student work, documents, attachments, and other materials to Cresco. The school and its users are responsible for ensuring that they have the appropriate authority, permissions, or consents to upload, store, publish, or share such content through Cresco.
18. Data Exports and Portability
Authorized users may export or download information from Cresco during normal use, including student lists, grades, attendance, report cards, financial records, documents, and other permitted data. Export capabilities are subject to the user's applicable access rights.
When a school's relationship with Cresco ends, the school will be given an appropriate means to obtain its data, subject to the applicable agreement and deployment model. The format, timing, deletion process, and responsibilities following termination may depend on the school's deployment and contractual arrangements.
19. Data Retention
Cresco does not apply one universal retention period to all school data. Retention may depend on the nature of the information, purpose for which it is held, school agreement, deployment model, school instructions, legal or regulatory requirements, security needs, and backup arrangements.
After termination, Broder may retain limited business, contractual, accounting, support, security, audit, or compliance records where reasonably necessary or legally required. School operational data will be handled according to the applicable deployment model and agreement.
20. Individual Privacy Requests
Requests by students, parents or guardians, teachers, or staff to access, correct, delete, restrict, or obtain copies of school-managed personal information should generally be directed to the relevant school. The school is responsible for determining how the request should be handled.
Broder may assist the school in responding to such requests where reasonably necessary and technically possible. Broder will not ordinarily independently delete or alter school records solely on the basis of a direct request from an individual where the school controls the relevant record.
21. Aggregated and De-Identified Information
Broder may create and use aggregated or de-identified information for product improvement, analytics, research, benchmarking, service performance, planning, and similar purposes, provided that the information cannot reasonably be used to identify an individual or a specific school.
22. Security
Broder uses reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information and the applicable deployment model. These safeguards may include access controls, authentication, role-based permissions, logging, backups, monitoring, and other measures appropriate to the environment.
No particular security technology, certification, encryption method, backup frequency, or technical standard is guaranteed by this Privacy Policy. Specific security requirements may be addressed in the applicable school agreement.
Cresco may restrict or suspend access to an account where reasonably necessary to protect users, school data, the platform, or other systems, including where unauthorized access or account compromise is suspected or where requested by the relevant school.
23. Security Incidents and Data Breaches
If Broder becomes aware of a confirmed personal data breach affecting school data for which Broder is responsible, Broder will notify the affected school without undue delay, provide reasonably available information about the incident and affected data, and cooperate with the school in connection with any notifications or actions the school is required to undertake.
24. International Processing
Because Cresco may use different hosting arrangements, service providers, integrations, AI services, payment providers, and backup systems, personal information may be processed in countries other than the country in which the school or user is located. The applicable school agreement may contain additional requirements concerning hosting or data location.
25. No Sale of Personal Information or Targeted Advertising
Broder does not sell school-provided personal information. Cresco does not use school-provided student, parent, teacher, or staff information for targeted advertising, and Broder does not provide such information to advertisers for the purpose of building advertising profiles.
26. Changes to This Privacy Policy
Broder may update this Privacy Policy as Cresco evolves, its data practices change, legal requirements develop, or new functionality is introduced. The current version will display an effective date or last-updated date. Where changes are material, Broder may provide reasonable notice through Cresco, by email, through the relevant school, or by another appropriate method.
27. Contact Us
Questions about school-managed personal information should generally be directed to the relevant school.
For questions about this Privacy Policy or Broder's privacy practices, contact:
Broder / Cresco
Email: [Privacy Contact Email]
Address: [Business Address, when available]
— End of Privacy Policy —