Research privacy / MVP notice
Operations belong in the study. Families do not.
Activion is designed for organization-level discovery. This notice explains the practical data boundaries in the assessment portal.
01What we collect
Organization name, program types, broad enrollment and location ranges, current systems, role, and answers about business workflows. A respondent may optionally provide an email address for a private resume link or follow-up. When email delivery is requested, the recipient address and message are processed by Activion’s configured transactional email provider.
02What we do not want
Student or parent names, birth dates, contact details, payment information, attendance records, health information, or other family-level data. Free-text fields repeat this boundary and basic server-side checks reject common contact or card-like patterns.
03How responses are used
To produce the respondent’s private operations report and to study workflow friction, workarounds, system gaps, and automation opportunities. Organization-level responses stay linked to the organization so Activion can provide an individual studio view; they are not described as anonymous.
04How access is protected
Optional contact fields are encrypted. Private assessment and report links use high-entropy bearer tokens whose raw values are not stored in the database. Research administration requires a separate signed session, and public pages do not expose respondent contact details.
05Retention and control
Incomplete assessment access expires after the configured research window, set to 90 days for the MVP. Completed report links expire after 180 days. Optional contact fields are scheduled for purging after 365 days, and expired incomplete records are removed by the retention task. Completed organization-level responses and organization names currently remain part of the research record unless the organization requests withdrawal or deletion; the MVP does not yet apply a fixed deletion period to those records.