Dataprivacy policy.
Where institutional data lives, what the product holds, and every outbound request it makes, named so your IT team can review or block any of them.
Where institutional data lives
In the institution’s own database, on infrastructure the institution owns and controls. Kenii software reads and writes that database in place. It does not transmit catalog, program, course, policy or directory records to Kenii.
What the product holds
- Academic content: courses, credentials, programs, policies, campuses, terms, catalog years, academic calendars, handbook content.
- Staff directory entries the institution publishes: name, title, department, work email, work phone.
- Board records: meetings, agendas, trustee listings.
The product does not store student records. It holds no grades, transcripts, financial aid data or student identifiers, so it is not a repository of education records under FERPA. An institution deploying Kenii should still confirm that against its own FERPA analysis.
What leaves the institution’s server
The product makes outbound requests to the services below. Each is named so an institution can review or block it.
| Destination | Purpose | What is sent |
|---|---|---|
| kenii.app | License verification and update checks | Site URL and license key |
| api.bls.gov, www.bls.gov | Wage and employment statistics | Occupation codes only |
| www.careeronestop.org | Career and wage data | Occupation codes only |
| services.onetcenter.org | Occupation detail | Occupation codes only |
| projectionscentral.org | State employment projections | Occupation and state codes |
| fonts.googleapis.com | Web fonts, when brand fonts are enabled | The visitor’s request reaches Google, including IP address |
| graph.microsoft.com, login.microsoftonline.com | Optional staff directory sync | Directory attributes from the institution’s own tenant |
| player.vimeo.com, www.youtube-nocookie.com | Embedded video, when the institution embeds one | The visitor’s request reaches the video host |
No institutional or personal record is included in the statistical data requests. Occupation codes are public identifiers.
The two worth attention
Google Fonts means a site visitor’s IP address reaches Google. An institution with a European audience, or a policy against third-party font hosting, should disable brand fonts and self-host.
Microsoft Graph directory sync is optional, is configured by the institution against its own tenant, and moves staff attributes from the institution’s directory into the institution’s own site.
Vendor-side services
Kenii operates a licensing service, an update service, and optional hosted evaluation sandboxes used before a sale. The licensing and update services hold a site URL, a license key and entitlement state. Evaluation sandboxes hold sample or publicly available catalog content and are removed when the evaluation ends.
Retention and deletion
Institutional data is retained by the institution, deleted by the institution, and is not Kenii’s to retain. Kenii holds no copy to return or destroy at contract end. Licensing records are kept while an agreement is active and for the period required to administer renewals and billing.
Access by Kenii personnel
Kenii personnel access an institution’s site only with credentials the institution issues, scoped to that site, for implementation, support or a fault the institution has reported. Credentials are revoked when the work ends.
Kenii does not use institutional data for product development, analytics, marketing or model training.
Selling data
Kenii does not sell institutional or personal data, and does not share it with advertisers or data brokers.
See where your datawould actually live.
Request a demo and your IT team can inspect the database and the outbound calls themselves, on a site carrying your own logo.