Privacy & Security
DLG Enterprises, Inc. Privacy & Security Policy
DLG ENTERPRISES, INC. PRIVACY & SECURITY POLICY
Effective Date: 09/17/2026
1. Purpose and Scope
DLG Enterprises, Inc. (“DLG”) provides online software applications, platforms, systems, modules, websites, portals, and related technology and services (“Services”) to Career and Technical Student Organizations (CTSOs) and other authorized Clients. This Privacy & Security Policy explains DLG’s practices regarding personal information and Client Data processed through the Services. Use of the Services is also governed by DLG’s Terms of Use.
DLG recognizes that student information requires particular care. DLG’s privacy and security practices are designed around authorized purposes, appropriate access, security safeguards, and respect for the Client’s ownership and control of its data.
2. Definitions, Data Ownership, and Control
“Client” means the organization or entity that obtains DLG Services and maintains the applicable account or service relationship with DLG. Organizational affiliation or hierarchy alone does not make one Client responsible for another Client’s separately administered DLG account or Client Data.
“Account Owner” means the individual designated by the Client as responsible for the Client’s DLG account and service relationship.
“Authorized User” means an individual authorized by the Client or Account Owner to access or use applicable Services.
“Client Data” means data and content collected, entered, uploaded, imported, configured, transmitted, or otherwise managed by or on behalf of a Client through the Services.
The Client retains ownership and control of Client Data. DLG does not acquire ownership of Client Data by providing the Services. DLG processes Client Data on behalf of the Client only as reasonably necessary to provide, secure, support, maintain, and administer the Services; carry out authorized Client instructions; or comply with applicable legal obligations.
3. Student Information and Education Records
DLG provides technology services that Clients may use to collect, manage, and process student information. DLG is a technology and service provider and does not represent itself as the school official responsible for the underlying education records.
The Client is responsible for establishing the legal authority required to collect, use, and provide student information to DLG, including any authority, notice, consent, permission, agreement, or other requirement applicable under FERPA or other federal or state privacy law.
DLG does not determine the Client’s legal basis for obtaining student information from schools, school districts, states, parents, students, or other sources. DLG processes such information on behalf of the Client for authorized purposes associated with providing the Services and does not independently use the information for unrelated purposes.
4. Core Student-Data Commitments
DLG does not sell student personal information.
DLG does not use student personal information for behavioral or targeted advertising.
DLG does not use student personal information to create commercial profiles of students for purposes unrelated to providing the Services.
DLG does not use student personal information for purposes unrelated to the authorized Services except where permitted or required by applicable law.
DLG discloses or permits access to student personal information only as reasonably necessary to provide, secure, support, or administer the Services; pursuant to authorized Client instructions; through authorized service providers performing services for DLG; or as permitted or required by applicable law.
5. Access and Correction Requests
DLG supports Clients in responding to lawful requests to access or correct personal information maintained through the Services. Because the Client owns and controls Client Data, an individual seeking access to or correction of Client-controlled information should generally direct the request to the applicable Client.
If DLG receives a request directly from a parent, legal guardian, eligible student, or other individual concerning Client-controlled information, DLG may refer the request to the applicable Client so the Client can verify the requester’s identity, authority, relationship to the information, and applicable rights.
DLG will reasonably assist the Client with access, correction, export, or other data actions required by applicable law and supported by the Services within the timeframe required by applicable law.
6. Government and Legal Requests
When a governmental, law-enforcement, or other third party requests Client Data that DLG maintains on behalf of a Client, DLG will generally direct the requesting party to the applicable Client when legally and reasonably appropriate.
If DLG is legally compelled to disclose Client Data, DLG will provide notice to the affected Client when permitted by law and will disclose only the information DLG is legally required to provide.
7. Service Providers and Client-Selected Third Parties
DLG may use selected third-party service providers to support the hosting, operation, security, maintenance, communication, and support of the Services. Where a DLG-selected service provider may access or process Client Data, DLG limits such access to what is reasonably necessary for the provider’s authorized function and seeks to maintain appropriate confidentiality, privacy, and security protections consistent with the provider’s role and applicable law.
DLG does not authorize its service providers to use Client Data for their own unrelated commercial purposes.
Clients may elect to configure or connect independent third-party services, including payment-processing services, for use with their DLG account. The Client selects and maintains its relationship with the applicable provider. DLG may facilitate the technical integration but does not control the independent provider’s privacy, security, accessibility, contractual terms, fees, or other practices.
8. Personnel Security, Access, and Training
DLG limits access to Client Data and production systems based on job responsibilities and the level of access reasonably necessary to perform authorized duties.
DLG conducts background checks for new employees in accordance with its hiring and security practices. Employees and contractors with access to confidential information or Client Data are subject to applicable confidentiality obligations.
DLG provides security and privacy training and guidance to applicable employees during onboarding and at least annually thereafter. Training and guidance may address data privacy, confidentiality, account security, phishing and cybersecurity risks, incident reporting, and appropriate handling of Client Data.
9. Infrastructure and Technical Security
DLG maintains administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Client Data against unauthorized access, acquisition, use, alteration, or disclosure.
Security measures include access controls, encryption for data in transit, network and firewall protections, monitoring and logging, backup and recovery procedures, personnel confidentiality requirements, and other safeguards appropriate to DLG’s Services and the information processed.
DLG uses managed data-center infrastructure designed to support physical security, availability, redundancy, backup, recovery, and operational resilience. Current infrastructure-provider controls and certifications may be described in separate DLG security or due-diligence materials and may change as providers, certifications, and technology evolve.
No security program can guarantee that every risk or security incident will be prevented.
10. Payment Card Security
DLG maintains compliance with applicable Payment Card Industry Data Security Standard (PCI DSS) requirements applicable to DLG’s payment-card environment. DLG applications do not store payment-card numbers or payment-card account data.
11. Data Retention, Backups, Logs, and Deletion
When a Client’s DLG service is discontinued, DLG removes the applicable Client site and associated Client Data from active production systems in accordance with its operational procedures.
For active CTSO Clients, DLG retains the current Program Year and the three immediately preceding Program Years of Client Data when operationally necessary to provide the Services, including multi-year participant continuity, historical reporting, program administration, support, and authorized Client access. Historical Client Data maintained for these purposes is separate from DLG's Recovery Backups.
DLG maintains a 30-day rolling retention period for database and virtual-machine Recovery Backups. Recovery Backups are maintained for disaster recovery, restoration, security, and operational resilience and are not DLG's historical archive. A different retention or disposition period will be applied where required by applicable law or an applicable written obligation accepted by DLG.
DLG maintains operational, application, access, and security logs as appropriate for system administration, troubleshooting, security monitoring, auditing, and incident investigation. Security and audit logs are retained for a minimum of 12 months where technically feasible, and operational/application/error logs are retained for a minimum of 90 days where technically feasible. Documented current-system limitations or applicable legal, security, regulatory, or operational requirements may result in different retention periods.
DLG does not currently create and retain separate de-identified Client datasets for independent ongoing use after a Client site is removed.
DLG will provide confirmation of deletion or disposition where required by applicable law or an applicable written obligation accepted by DLG.
12. Security Incident Response
DLG maintains procedures for evaluating and responding to actual or reasonably suspected unauthorized access to, acquisition of, or disclosure of Client Data. DLG will take appropriate steps to investigate, contain, mitigate, and recover from a security incident based on the nature and circumstances of the incident.
When a security incident triggers an applicable legal or written contractual notification obligation accepted by DLG, DLG will notify the affected Client and provide information required by the applicable obligation within the required timeframe.
DLG will coordinate with the affected Client as appropriate regarding investigation, mitigation, recovery, and legally required notifications. The timing, content, recipients, and method of notification may vary based on the facts of the incident, the information involved, applicable law, law-enforcement restrictions, cyber-insurance requirements, and the respective responsibilities of DLG and the Client.
13. Changes to this Policy
DLG may update this Privacy & Security Policy from time to time as laws, technology, Services, security practices, and operational requirements evolve.
DLG will provide notice of material changes to this Policy as required by applicable law. DLG will not materially change its handling of student personal information in a manner inconsistent with its existing commitments without providing any notice, authorization, or consent required by applicable law.
14. Contact
Questions regarding this Privacy & Security Policy or DLG’s privacy and security practices may be directed to:
DLG Enterprises, Inc. Phone: 863-420-9000 Email: dlg.exec@registermychapter.com