Engaging AAC Learning Studio is committed to protecting the privacy and security of personal information of all individuals who participate in our ASHA Continuing Education (CE) programs. This policy outlines how we collect, use, store, protect, and share personal information in compliance with the American Speech-Language-Hearing Association (ASHA) Continuing Education Board (CEB) requirements effective 2025, as well as applicable federal and state privacy laws.
We're a small team doing this work with the resources we have. We haven't gotten everything perfect, and some parts of the site are still catching up to our standards. We're always improving, one step at a time, the same way we ask everyone else to learn.
If something here doesn't work for you, that's important for us to know. It isn't your fault, and it isn't a bother. It helps us do better.
Personal Information:
Any information that can be used to identify an individual, including but not limited to name, ASHA account number, address, email, phone number, date of birth, certification/licensure information, and course participation records.
Sensitive Personal Information:
Information that requires enhanced protection, including financial information, health information, demographic data, and government-issued identification numbers.
Types of Personal Information Collected:
Engaging AAC Learning Studio collects the following types of personal information:
- Full name
- ASHA account number (when applicable)
- Contact information (email, phone, address)
- Professional credentials and licensure information
- Course registration and completion data
- Payment information (when applicable)
- Demographic information (as required by ASHA for reporting purposes)
- Accessibility needs and accommodations requests
- Course evaluation responses
- Learning assessment results
- Professional credentials and licensure information
Methods of Collection:
Personal information is collected through:
- Online registration forms
- Paper registration forms
- Course evaluations
- Learning assessments
- Email communications
- Telephone or Video Call communications
- ASHA CE Registry reporting systems
Consent:
We obtain explicit consent from individuals for the collection, use, and sharing of their personal information. Consent is obtained through:
- Clear privacy notices at the point of collection
- Opt-in mechanisms for data sharing beyond ASHA CE reporting requirements
- Clear explanation of how personal information will be used
- Option to withdraw consent (with understanding that this may impact CE credit reporting)
Engaging AAC Learning Studio uses personal information for the following purposes:
- Processing course registrations and payments
- Reporting course completion to the ASHA CE Registry
- Providing course materials and resources
- Issuing certificates of completion
- Conducting program evaluations
- Communicating about current and future CE opportunities
- Improving our CE programs based on participant feedback
- Meeting legal and regulatory obligations
To protect personal information from unauthorized access, disclosure, alteration, or destruction, Engaging AAC Learning Studio implements the following security measures:
- Processing course registrations and payments
- Reporting course completion to the ASHA CE Registry
- Providing course materials and resources
- Issuing certificates of completion
- Conducting program evaluations
- Communicating about current and future CE opportunities
- Improving our CE programs based on participant feedback
- Meeting legal and regulatory obligations
Technical Safeguards:
- Encryption of personal information during transmission and at rest
- Secure, password-protected database systems
- Multi-factor authentication for staff accessing participant data
- Regular security updates and patch management
- Firewalls and intrusion detection systems
- Regular security assessments and vulnerability testing
- Backup systems and disaster recovery protocols
Administrative Safeguards:
- Staff training on privacy and security procedures
- Background checks for employees with access to personal information
- Written policies and procedures for data handling
- Access controls based on job responsibilities
- Regular privacy and security compliance audits
- Incident response procedures
- Vendor management program for third-party service providers
Physical Safeguards:
- Secure facility with controlled access
- Locked storage for physical documents containing personal information
- Secure disposal of physical and electronic records
To protect personal information from unauthorized access, disclosure, alteration, or destruction, Engaging AAC Learning Studio implements the following security measures:
- Processing course registrations and payments
- Reporting course completion to the ASHA CE Registry
- Providing course materials and resources
- Issuing certificates of completion
- Conducting program evaluations
- Communicating about current and future CE opportunities
- Improving our CE programs based on participant feedback
- Meeting legal and regulatory obligations
Technical Safeguards:
- Encryption of personal information during transmission and at rest
- Secure, password-protected database systems
- Multi-factor authentication for staff accessing participant data
- Regular security updates and patch management
- Firewalls and intrusion detection systems
- Regular security assessments and vulnerability testing
- Backup systems and disaster recovery protocols
Administrative Safeguards:
- Staff training on privacy and security procedures
- Background checks for employees with access to personal information
- Written policies and procedures for data handling
- Access controls based on job responsibilities
- Regular privacy and security compliance audits
- Incident response procedures
- Vendor management program for third-party service providers
Physical Safeguards:
- Secure facility with controlled access
- Locked storage for physical documents containing personal information
- Secure disposal of physical and electronic records
ASHA CE Registry
- Course completion information is reported to the ASHA CE Registry for participants who provide their ASHA account number
- Information shared includes: participant name, ASHA account number, course information, completion date, and number of CEUs earned
- Backup systems and disaster recovery protocols
Third-Party Service Providers
We may share personal information with third-party service providers who help us deliver CE programs, including:
- Learning management system providers
- Payment processors
- Email communication platforms
- Survey and evaluation tools
All third-party service providers are contractually required to:
- Use personal information only for the purpose of providing the contracted service
- Implement appropriate security measures
- Comply with applicable privacy laws and regulations
- Not share or sell personal information to other parties
Legal Requirements:
- We may disclose personal information when required by law, regulation, or legal process
- We will notify individuals of such disclosures unless prohibited by law
Participants in our CE programs have the following rights regarding their personal information:
Right to Access:
- Encryption of personal information during transmission and at rest
- Secure, password-protected database systems
- Multi-factor authentication for staff accessing participant data
- Regular security updates and patch management
- Firewalls and intrusion detection systems
- Regular security assessments and vulnerability testing
- Backup systems and disaster recovery protocols
Right to Correction:
- Staff training on privacy and security procedures
- Background checks for employees with access to personal information
- Written policies and procedures for data handling
- Access controls based on job responsibilities
- Regular privacy and security compliance audits
- Incident response procedures
- Vendor management program for third-party service providers
Right to Deletion:
- Secure facility with controlled access
- Locked storage for physical documents containing personal information
- Secure disposal of physical and electronic records
Right to Opt Out:
Individuals may opt out of:
- Marketing communications
- Sharing of information beyond what is required for ASHA CE reporting
- Certain types of data processing
Process for Exercising Rights:
To exercise any of these rights, individuals should contact our Privacy Officer at:
- Email: privacy@engagingaac.com
- Phone: 1+ 215-360-3088
- Mail: 96 Stardust Drive Holland PA 18966
In the event of a data breach involving personal information, Engaging AAC Learning Studio will notify affected individuals within [X - follow ASHA guidelines] days of discovery.
We will notify the ASHA CEB of the breach as required.
Notification will include:
- Description of the breach
- Types of information involved
- Steps we are taking to investigate and mitigate harm
- Measures individuals can take to protect themselves
- Contact information for questions
Special Considerations for Virtual Learning Environments:
For online and virtual CE programs:
- We implement additional security measures for virtual learning platforms.
- Access to online courses is protected by unique login credentials.
- Participant interactions and communications within virtual platforms are subject to this privacy policy.
- We do not record participants without explicit consent.
- If sessions are recorded, participants are notified in advance and given options to:
- Turn off their camera
- Use a virtual background
- Change their display name
- Participate via chat only
If personal information is transferred outside the United States:
- We ensure appropriate safeguards are in place to protect the information
- We comply with applicable international data protection laws
- We inform individuals if their data will be transferred internationally
Our CE programs are designed for adult professionals. We do not knowingly collect personal information from individuals under the age of 18.
This privacy and security policy will be reviewed annually and updated as needed to reflect:
- Changes in ASHA CEB requirements
- Changes in applicable laws and regulations
- Changes in our CE program operations
- Technological developments
When this policy is updated:
- The revised policy will be posted on our website with an updated effective date
- Current CE program participants will be notified of material changes
- A copy of the updated policy will be available upon request
For questions or concerns about this privacy and security policy, please contact:
Engaging AAC Learning Studio ASHA CE Administrator/Privacy Officer:
- Lauren Enders Gonzales, M.A., CCC-SLP
- lauren@engagingaac.com
- Phone: 215-262-8280
- Address: 96 Stardust Drive Holland PA, 18966 (USA)