🤝 Vendor Data Privacy and Security Policy

Better Choices Education LLC

www.BetterChoicesEducation.com

1. Purpose

This policy defines the requirements and responsibilities for all vendors, subcontractors, and third-party service providers (“Vendors”) who may process or access data on behalf of Better Choices Education LLC (“Company”). It ensures compliance with Connecticut General Statutes §§ 10-234aa to 10-234dd, FERPA, and applicable federal privacy standards.

2. Scope

This policy applies to all third-party entities engaged by the Company for:

3. Vendor Requirements

All Vendors must:

4. Data Security Obligations

Vendors must demonstrate the following security controls:

5. Subprocessors

Vendors must:

6. Data Breach Notification

Vendors must immediately notify the Company of any suspected or confirmed security incident involving Company-managed data. The Vendor shall cooperate fully with the Company’s incident response and reporting process.

7. Right to Audit

The Company reserves the right to:

8. Contract Termination and Data Disposition

Upon termination of the contract or project:

9. Policy Review

This policy will be reviewed annually or upon changes in legal or contractual requirements. Vendors will be notified of material updates.

10. Contact