This page explains the rules for using our website and programs, how we handle personal information, and the additional safeguards we apply when children, students, health information, genetic information, research, or artificial intelligence may be involved.
Effective: July 23, 2026Version: 2026.4-compliance-readyOrganization: Rotger Research Foundation Inc. (“RRF,” “we,” “us,” or “our”)
Website policy only. This page governs RRF’s public website and general online services. A specific research study, diagnostic pilot, school partnership, youth program, scholarship, event, or clinical collaboration may require a separate consent form, participation agreement, release, institutional review, or privacy notice. If a program-specific document conflicts with this page, the program-specific document controls for that program.
RRF is a nonprofit research and education organization. Unless expressly stated in a separate written agreement, RRF does not provide medical care, establish a physician-patient relationship, guarantee clinical outcomes, or operate as a health insurer. Information on this website is educational and informational.
This Privacy Policy is not automatically a HIPAA Notice of Privacy Practices. HIPAA applies only when RRF is acting as a covered entity or business associate under applicable law. When RRF handles protected health information on behalf of a HIPAA-covered organization, the applicable written agreement and HIPAA requirements govern that information.
No sale of personal dataNo targeted advertising to childrenData minimizationParent or guardian controlsProgram-specific consent
A policy is not a compliance certificate. Legal compliance depends on RRF’s actual systems, contracts, notices, consent records, vendor controls, security practices, staff training, registrations, program design, and incident response. This page states RRF’s public standards and identifies legal frameworks that may apply; it does not claim that every law applies to every activity or that publishing this page alone satisfies any law.
RRF will evaluate each website feature, research study, educational program, diagnostic initiative, fundraising campaign, school relationship, healthcare collaboration, and data use before launch. The stricter applicable rule, written agreement, consent form, grant condition, ethics approval, or program notice will control.
Framework
When It May Apply
RRF Standard
COPPA and the COPPA Rule, 16 C.F.R. Part 312
Child-directed online services or actual knowledge of online collection from a child under 13; nonprofit status may affect technical coverage.
RRF adopts COPPA-style protections for child-directed services and will comply fully whenever legally covered.
FERPA, PPRA, IDEA confidentiality, and school privacy requirements
When RRF receives education records, administers protected surveys, supports special-education services, or acts for a school or educational agency.
Use only for authorized educational purposes under written school instructions and required agreements.
HIPAA/HITECH and the FTC Health Breach Notification Rule
HIPAA only when RRF is a covered entity or business associate; the FTC rule may apply to certain non-HIPAA personal health record products or services.
Determine status before collection; execute required agreements; apply health-data breach and security procedures.
Common Rule, 45 C.F.R. Part 46; FDA human-subject rules; NIH policies
Federally supported, FDA-regulated, institutionally committed, or otherwise covered human-subject research.
No enrollment without required IRB or ethics review, informed consent, parental permission, and child assent where appropriate.
Pennsylvania Child Protective Services Law
Employees, contractors, volunteers, and programs involving contact with children in Pennsylvania.
Required clearances, training, mandated reporting, records, supervision, and no delay of an external report for internal review.
State breach, consumer-health, biometric, genetic, and comprehensive privacy laws
Based on the participant’s residence, data category, thresholds, and RRF’s activity.
Provide any required supplemental notice, consent or authorization, processor contract, opt-out, appeal, deletion, and incident notice.
ADA Title III, Section 504, and other civil-rights laws
Public-facing nonprofit services and, for Section 504, programs receiving applicable federal financial assistance.
Equal access, reasonable modifications, effective communication, and a WCAG 2.2 Level AA design target where reasonably achievable.
IRS and state charitable-solicitation requirements
Fundraising, donation receipts, quid pro quo contributions, charitable registration, and public disclosures.
Maintain registrations, truthful solicitations, accurate receipts, donor disclosures, and required nonprofit records.
CAN-SPAM, TCPA, E-SIGN/UETA, and consumer-protection laws
Email, calls, text messages, electronic signatures, recurring donations, and online representations.
Truthful communications, valid consent where required, unsubscribe controls, consent records, and no deceptive design.
International privacy and child-protection laws
When RRF intentionally offers services to or monitors individuals outside the United States.
Conduct jurisdiction-specific review and provide supplemental terms before regulated international processing begins.
Privacy by Design and No Dark Patterns
RRF will seek to use privacy-protective defaults, clear choices, age-appropriate language, minimal collection, purpose limitation, and interfaces that do not manipulate users into providing more data, remaining enrolled, accepting optional tracking, or waiving rights.
By accessing or using this website, related web pages, online forms, educational tools, portals, applications, or digital content operated by RRF (collectively, the “Services”), you agree to these Terms of Use and the policies incorporated into them. If you do not agree, do not use the Services.
2. Eligibility and Authority
You must be legally capable of agreeing to these Terms. A parent or legal guardian must authorize a child’s participation in any feature that requires an account, submission, registration, application, identifiable data, image, voice, precise location, educational record, health information, or genetic information. An adult submitting information for another person represents that the adult has lawful authority and any required consent.
3. Accounts and Credentials
Where accounts are offered, you must provide accurate information, protect your credentials, use reasonable security measures, and promptly notify RRF of suspected unauthorized access. You may not share accounts, impersonate another person, create an account for a child without authority, or attempt to bypass age, consent, safety, or access controls.
4. Permitted Use
RRF grants you a limited, revocable, non-exclusive, non-transferable license to use the Services for lawful personal, educational, charitable, or authorized organizational purposes. No ownership rights are transferred.
5. Prohibited Conduct
You may not:
use the Services unlawfully, fraudulently, deceptively, or in a way that harms RRF, a child, a participant, or another person;
submit another person’s health, genetic, biometric, educational, financial, or identifying information without lawful authority;
post harassment, threats, sexual content, exploitation, grooming behavior, hate content, doxxing, defamation, or material that endangers a child;
use educational or AI tools to cheat, fabricate research, misrepresent qualifications, or make high-stakes medical, legal, financial, or safety decisions without qualified professional review;
copy, sell, reverse engineer, train competing models on, or commercially exploit protected RRF content or software except as permitted by law or written authorization; or
use a child-facing area for advertising, solicitation, recruitment, fundraising directed at children, or direct private contact with a child.
6. User Submissions
You retain ownership of content you lawfully submit. You grant RRF a limited license to host, process, reproduce, and use the submission only as reasonably necessary to provide the requested Service, administer a program, comply with law, protect safety, or fulfill a separate consent or release. RRF may remove content that violates these Terms or creates legal, privacy, security, or safety risk.
7. No Medical, Legal, Financial, or Emergency Service
Website content, AI-generated material, research summaries, simulations, risk indicators, educational exercises, and diagnostic concepts are not a substitute for licensed medical, legal, financial, mental-health, emergency, or other professional services. Do not disregard professional advice based on website content. For an emergency, call 911 or the appropriate local emergency service.
8. Third-Party Services and Links
The Services may link to or integrate with third-party platforms, including donation processors, email providers, analytics providers, cloud hosts, educational tools, laboratories, or research collaborators. Third parties operate under their own terms and privacy practices. RRF is not responsible for a third party’s independent conduct, availability, or content.
9. Disclaimer of Warranties
To the fullest extent permitted by law, the Services are provided “as is” and “as available.” RRF does not guarantee uninterrupted operation, error-free content, scientific certainty, diagnostic accuracy, compatibility, availability, or that every security threat can be prevented. Nothing on the website is a promise of funding, selection, admission, scholarship, research enrollment, medical benefit, or commercial outcome.
10. Limitation of Liability
To the fullest extent permitted by law, RRF and its directors, officers, employees, volunteers, contractors, collaborators, and agents will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages arising from use of the Services. Where liability cannot lawfully be excluded, RRF’s aggregate liability will not exceed the greater of the amount paid directly to RRF for the specific online Service during the twelve months before the claim or one hundred U.S. dollars. These limits do not apply where prohibited by law.
11. Indemnification
To the extent permitted by law, you agree to defend, indemnify, and hold harmless RRF from claims arising from your unlawful use of the Services, violation of these Terms, infringement of another person’s rights, or unauthorized submission of another person’s information. This provision does not require indemnification for RRF’s own conduct where such indemnification is prohibited.
12. Suspension and Termination
RRF may restrict, suspend, or terminate access when reasonably necessary to protect users, children, data, systems, legal rights, or program integrity. Provisions that by their nature should survive termination—including intellectual property, disclaimers, limitations, and dispute provisions—will survive.
13. Governing Law and Venue
These Terms are governed by the laws of the Commonwealth of Pennsylvania, without regard to conflict-of-law rules. Unless applicable law requires otherwise, disputes relating to the public website will be brought in a state or federal court with jurisdiction in or serving Lehigh County, Pennsylvania. Before filing suit, the parties should make a good-faith effort to resolve the dispute through written notice and informal discussion.
14. Changes, Severability, and Entire Agreement
RRF may update these Terms prospectively. Material changes will be identified by a revised effective date and, when appropriate, additional notice. If a provision is unenforceable, it will be limited or removed to the minimum extent necessary, and the remaining provisions remain effective. These Terms and incorporated policies are the complete agreement concerning the general public Services unless a separate written agreement applies.
Messages, support requests, photographs, video, audio, testimonials
User, parent, event, authorized media release
Sensitive information
Health, disability, genetic, biometric, demographic, government identifier, financial, or precise location data
Only when necessary and authorized for a specific program or legal obligation
2. How We Use Information
to operate the website and provide requested programs, educational resources, research administration, communications, and support;
to process donations, issue acknowledgments, maintain nonprofit records, and prevent fraud;
to verify eligibility, parental authority, permissions, consent, and required program documentation;
to protect children, participants, systems, intellectual property, and legal rights;
to improve accessibility, performance, security, and program effectiveness;
to comply with tax, accounting, research, safety, reporting, court, regulatory, and legal obligations; and
for additional purposes disclosed at collection or authorized by valid consent.
3. Data Minimization and Purpose Limitation
RRF seeks to collect only information reasonably necessary for a stated purpose. We do not use health, genetic, child, or student data for unrelated advertising. We do not sell personal information. We do not disclose personal information for cross-context behavioral advertising to children.
4. When Information May Be Shared
RRF may disclose information:
to service providers and contractors that need the information to perform services for RRF and are subject to appropriate confidentiality, security, and use restrictions;
to authorized schools, laboratories, researchers, clinicians, collaborators, funders, or program partners when required for a disclosed program and supported by appropriate consent, agreement, ethics review, or law;
to a parent, legal guardian, authorized representative, or participant as permitted by law;
to protect a child or another person from suspected abuse, neglect, exploitation, self-harm, violence, or serious safety risk;
to comply with valid legal process, regulatory requirements, tax obligations, audits, or lawful government requests; or
in connection with a lawful organizational restructuring, asset transfer, merger, or successor arrangement, subject to applicable restrictions.
5. Retention
RRF retains personal information only as long as reasonably necessary for the disclosed purpose, legal requirements, nonprofit recordkeeping, safety, dispute resolution, research integrity, or contractual obligations. Retention periods vary by category. Child data, health data, genetic data, and unsuccessful applications should be deleted or de-identified when no longer needed unless law, consent, research requirements, or a preservation duty requires longer retention.
6. De-Identification and Aggregation
RRF may create aggregated or de-identified information for research, reporting, quality improvement, fundraising impact reports, or program evaluation. RRF will not attempt to re-identify properly de-identified information except for security testing, validation, legal compliance, or as otherwise permitted by law and appropriate governance. Because genetic and rare-condition information may be inherently identifying, de-identification cannot be promised to eliminate every re-identification risk.
7. International Users
RRF is based in Pennsylvania, United States. Information may be processed in the United States and other locations where authorized service providers operate. Where applicable law requires additional safeguards, legal bases, notices, or transfer mechanisms, RRF will use reasonable measures appropriate to the activity.
8. Legal Bases and Consent
Depending on the activity and jurisdiction, RRF may process information with consent, to provide a requested service, to perform a contract, to comply with law, to protect vital interests and safety, or for a legitimate nonprofit interest that is not overridden by applicable privacy rights. Where consent is the required basis, it may be withdrawn prospectively, subject to lawful retention and completed processing.
9. Sensitive Data and Secondary Use
RRF will not use sensitive personal information for a materially different purpose without the notice, consent, authorization, ethics review, or other lawful basis required for that new purpose. RRF will not infer sensitive characteristics for advertising or fundraising from browsing behavior.
10. Data Brokers, Sale, Sharing, and Targeted Advertising
RRF does not sell personal information for money and does not sell or share children’s, student, health, genetic, genomic, or biometric information for targeted advertising. If a future activity falls within a state law definition of “sale,” “sharing,” or targeted advertising, RRF will provide the required notice and opt-out before activation.
11. Legal Requests and Transparency
RRF will review subpoenas, warrants, court orders, regulatory demands, and other legal requests for validity and scope; disclose only what is legally required; seek protective measures where appropriate; and provide notice to the affected person when lawful and appropriate. Research information protected by a Certificate of Confidentiality will be handled under that protection.
Children’s Online Privacy Protection Act. RRF recognizes the Children’s Online Privacy Protection Act (“COPPA”) and the FTC’s COPPA Rule, 16 C.F.R. Part 312, as amended. Because many nonprofit activities may be outside the FTC Act’s commercial jurisdiction, COPPA may not technically govern every RRF activity. Nevertheless, RRF voluntarily applies COPPA-style protections to its child-directed online services and will comply with COPPA whenever RRF is a covered operator.
1. Scope and Operator Responsibility
This section applies to online features directed to children under 13 and to general-audience features when RRF has actual knowledge that it is collecting personal information online from a child under 13. RRF remains responsible for collection performed by vendors, plug-ins, analytics tools, embedded media, or other parties acting on its behalf. RRF will not shift the operator’s COPPA obligations to a child, parent, teacher, or school.
2. Information Covered
Children’s personal information may include a child’s name, address, online contact information, telephone number, government identifier, username functioning as contact information, persistent identifier, photograph, video, voice recording, precise geolocation, biometric identifier, or other information about a child or parent combined with an identifier. RRF treats health, disability, education, genetic, genomic, biometric, and family information as heightened-risk child data.
3. Collection Limitation
RRF will not condition a child’s participation on disclosing more information than is reasonably necessary. Child-facing activities should use anonymous or parent-managed access whenever practical and should avoid open-text fields, public profiles, direct messaging, precise location, unnecessary persistent identifiers, and unrestricted uploads.
4. Direct Notice to Parents
Before collection requiring consent, RRF will give the parent or legal guardian a direct, clear notice identifying RRF and relevant operators; the information collected; how it is collected; the purpose; retention period; disclosure practices; parent rights; security practices; and the method of consent. A child-facing privacy notice will not replace the required direct parental notice.
5. Verifiable Parental Consent
RRF will use a method reasonably designed, considering available technology and risk, to verify that consent is provided by the child’s parent or legal guardian. Depending on the activity, methods may include a signed consent form, verified payment-card transaction without an unnecessary charge, knowledge-based verification, government-identifier verification with prompt deletion, video conference, or another legally accepted method. Consent records will be retained only as necessary to document authorization.
6. Separate Consent for Third-Party Disclosure and Advertising
RRF does not use children’s personal information for targeted or behavioral advertising and does not sell children’s personal information. If a future child-directed service proposes a disclosure to a third party that is not integral to the service, RRF will not activate that disclosure without any separate verifiable parental consent required by COPPA. Contextual service operations must remain limited to what is reasonably necessary.
7. Parental Review, Deletion, and Revocation
After verifying identity and authority, RRF will provide parents the legally required ability to review personal information collected from their child, correct inaccuracies, direct deletion, revoke consent, and refuse future collection or use. RRF may terminate a child’s access to a feature that cannot operate without information for which consent has been revoked.
8. Retention and Deletion
Children’s personal information will be retained only as long as reasonably necessary for the specific purpose disclosed and will not be held indefinitely. RRF will securely delete it using measures reasonable for the data and system, subject to lawful safety, litigation-hold, research-integrity, grant, audit, or recordkeeping obligations disclosed in the applicable program documents.
9. Service Providers and Security
Before allowing a service provider or third party to receive children’s personal information, RRF will evaluate its practices, impose written confidentiality, security, purpose, retention, deletion, incident-notification, and subcontractor restrictions, and use reasonable means to confirm compliance. RRF will not knowingly deploy third-party behavioral advertising, cross-site tracking, data-broker, social plug-in, or unmoderated communication technology in a child-directed service.
10. Schools Acting as Parent’s Agent
RRF may rely on school authorization only where legally permitted, solely for the use and benefit of the school and not for an unrelated commercial purpose. RRF will provide the school the required operator notice and mechanisms to review, delete, and stop further collection. School consent does not authorize targeted advertising, sale, unrelated profiling, or use outside the educational purpose. RRF will use a written agreement and will verify that consent comes from an authorized school official.
11. Children Ages 13 Through 17
For minors ages 13 through 17, RRF applies heightened privacy and safety protections and may require parental authorization based on the program, information, school requirements, research rules, health-data laws, media use, or risk. RRF will not knowingly use teen data for targeted advertising, sale, manipulative engagement, or unrelated profiling.
12. Photos, Audio, Video, Location, and Publicity
RRF will obtain an appropriate parent or guardian release before publicly using an identifiable child’s name, image, voice, testimonial, artwork, school affiliation, or other content, unless a clearly applicable legal basis permits the use. Public posts should avoid precise location, schedules, contact details, geotags, medical information, and other facts that create safety risk.
13. Improper Collection
If RRF learns that children’s information was collected without required authorization, RRF will stop the collection, disable unnecessary access, investigate affected vendors, preserve only what is required for safety or law, provide legally required notice, and delete the information as appropriate.
Required before activating child accounts or child data forms: RRF must publish the legal name, physical mailing address, monitored telephone number, monitored privacy email, all relevant operators or an operator contact permitted by the Rule, the exact information collected by each child-directed feature, the consent method, and the parent request procedure. This general page cannot substitute for feature-specific COPPA notice and operational controls.
Child Safeguarding, Online Safety, and Program Conduct#
1. Zero Tolerance
RRF prohibits child abuse, neglect, exploitation, grooming, sexual misconduct, harassment, trafficking, coercion, hazing, bullying, retaliation, corporal punishment, discriminatory abuse, and inappropriate boundary violations in connection with its programs, communications, events, personnel, volunteers, contractors, or online spaces.
2. Adult-to-Child Communications
Adults acting for RRF must use authorized, auditable, program-related channels. Secret or disappearing messages, requests to move a conversation to an unapproved platform, romantic or sexual communication, gifts intended to create secrecy or dependency, requests for personal images, and private off-program meetings are prohibited. A parent, guardian, school representative, or second authorized adult should be included where appropriate.
3. Clearances, Screening, and Training
Employees, contractors, volunteers, mentors, instructors, drivers, and others with qualifying contact with children must complete Pennsylvania child-abuse clearances, criminal-history checks, FBI checks where required, mandated-reporter training, role-specific safeguarding training, and renewals required by law and RRF policy before qualifying contact. RRF may apply stricter screening, reference, supervision, and disqualification standards.
4. Mandatory and Permissive Reporting
Suspected child abuse or neglect in Pennsylvania: Call ChildLine at 1-800-932-0313 or use the official Child Welfare Portal when required. Call 911 for immediate danger. A mandated reporter must make the required external report immediately and may not wait for management approval or an internal investigation.
RRF’s internal notice process supplements, and never replaces, legally required reporting to authorities. Good-faith reports are protected from retaliation under RRF policy. RRF may restrict access, preserve records, implement safety plans, contact authorized guardians when appropriate, and cooperate with lawful investigations.
5. In-Person Program Controls
documented sign-in, sign-out, authorized pickup, emergency contact, and missing-child procedures;
two-adult or observable-and-interruptible practices, age-appropriate supervision ratios, and restrictions on isolated one-on-one contact;
transportation authorization, driver qualification, seat-belt and vehicle standards, and prohibition on unauthorized transport;
medication, allergy, injury, emergency, bathroom, changing-area, and overnight-event procedures appropriate to the program;
incident documentation, preservation of relevant evidence, escalation, and parent or guardian communication; and
rules for physical contact, discipline, photography, gifts, social media, off-site contact, and electronic devices.
6. Online Community and Moderation
Child-facing areas will not enable public profiles, direct messaging, location sharing, livestreaming, unrestricted uploads, or public posting unless a written risk assessment supports the feature and RRF has age assurance, parental controls, moderation, reporting, blocking, evidence preservation, privacy-by-default, and rapid escalation procedures. Sexual abuse material or apparent exploitation will be handled under applicable reporting and preservation obligations.
7. Youth Participation and Voice
Children should receive age-appropriate explanations of rules, privacy, photography, reporting channels, and their right to say no to unsafe or uncomfortable conduct. A child’s assent does not replace parental permission or any legally required consent.
Health, Genetic, Genomic, Biometric, Consumer-Health & AI Information#
1. Heightened Sensitivity and Family Impact
Health, genetic, genomic, biometric, family-history, reproductive-health, disability, and inferred health information can reveal sensitive facts about an individual and biological relatives. RRF will apply enhanced necessity review, consent, access controls, logging, vendor restrictions, retention limits, and human oversight appropriate to the program and law.
2. No Sensitive Data Through General Forms
Do not submit specimens, raw genomic files, laboratory results, medical records, diagnoses, medication lists, biometric templates, or another person’s health information through a general contact form or ordinary email. RRF will identify an approved secure method and program-specific notice when such information is necessary.
3. HIPAA and HITECH
HIPAA applies only when RRF is a covered entity or business associate. Before receiving protected health information from a covered entity, RRF will determine its role, execute any required business associate agreement or data-use agreement, restrict use and disclosure, apply the HIPAA Security Rule where applicable, support individual rights as contractually required, and follow applicable breach procedures. This public policy is not a HIPAA Notice of Privacy Practices.
4. Non-HIPAA Consumer Health Data
Non-HIPAA health data may be governed by the FTC Act, the FTC Health Breach Notification Rule, state consumer-health-data laws, genetic-testing laws, biometric laws, contract, research requirements, and state breach-notification statutes. Where applicable, RRF will provide a separate consumer-health privacy notice, obtain consent or signed authorization, honor withdrawal and deletion rights, maintain processor contracts, and obtain any separate authorization required for sale or other regulated disclosure. RRF does not sell health, genetic, genomic, or biometric data.
5. Genetic and Genomic Protections
genetic or genomic data will not be used for employment, insurance, eligibility, fundraising targeting, or unrelated profiling;
RRF will not promise that de-identification eliminates all re-identification or family-identification risk;
return of individual results, carrier status, ancestry, incidental findings, and family findings will occur only under study-specific rules and qualified review;
clinical use will require an appropriately authorized laboratory and any required validation, professional ordering, counseling, or regulatory oversight; and
secondary research, data repositories, model training, commercialization, recontact, and future specimen use require clear study-specific disclosure and authorization where required.
6. Biometric Information
RRF will not collect face geometry, voiceprints, fingerprints, retinal or iris scans, or other biometric identifiers for general website access. A program requiring biometric information must provide a written notice describing the purpose and retention period, obtain any required written release or consent, prohibit sale or profit from biometric data, secure it appropriately, and destroy it according to the applicable retention schedule and law.
7. AI Governance and Human Review
AI outputs may be inaccurate, incomplete, biased, non-generalizable, or outdated and require qualified human review before high-stakes use;
RRF will not make a solely automated final decision concerning medical care, research eligibility, scholarships, education placement, employment, safety, or another significant opportunity when human review is legally required or reasonably necessary;
sensitive, child, student, health, and genomic information will not be used to train a general-purpose or third-party model without a documented lawful basis, contractual controls, and specific notice or consent where required;
RRF will evaluate data provenance, validation, performance limitations, bias, accessibility, cybersecurity, explainability, and monitoring appropriate to the use; and
users will be told when they are interacting with an automated system where disclosure is legally required or material to informed use.
8. FDA, CLIA, and Clinical Status
A research concept, prototype, algorithm, educational demonstration, laboratory workflow, or pilot described by RRF is not necessarily FDA-cleared, approved, authorized, or exempt, and is not necessarily performed in a CLIA-certified laboratory. RRF will not market an investigational or research-only tool for clinical diagnosis or treatment unless the applicable regulatory requirements and professional controls have been satisfied.
9. Health-Data Incidents
RRF will investigate suspected unauthorized access, acquisition, use, disclosure, or loss and provide notices required by applicable law and contract. Depending on the program, this may include HIPAA/HITECH, the FTC Health Breach Notification Rule, Pennsylvania and other state breach laws, consumer-health statutes, research reporting, grant conditions, and notices to institutional partners.
Human-Subject Research, Biospecimens, and Research Ethics#
Viewing this website, completing a general contact form, or using a public educational tool does not enroll anyone in research. Research participation requires a separate, documented process appropriate to the study.
1. Regulatory and Ethics Review
When applicable, RRF will comply with the Common Rule at 45 C.F.R. Part 46, including additional protections for children under Subpart D, applicable FDA informed-consent and IRB regulations, sponsor requirements, institutional policy, and other governing law. RRF will not describe a project as “IRB approved” unless a valid reviewing body has issued the applicable determination.
2. Consent, Parental Permission, and Child Assent
Study documents will address purpose, procedures, foreseeable risks and benefits, alternatives, confidentiality, compensation, injury information when applicable, contacts, voluntary participation, withdrawal, and legally required elements. Research involving children will include parental permission and age-appropriate assent unless an authorized IRB or law permits a waiver.
3. Biospecimens and Genomic Data
Study-specific documents must explain specimen collection, storage, destruction, future use, secondary research, data sharing, repositories, controlled access, re-identification risk, commercial development, intellectual property, return of results, incidental findings, recontact, and whether participants will share in commercial proceeds.
4. NIH-Funded or NIH-Controlled Data
When applicable, RRF will follow NIH Data Management and Sharing requirements, the NIH Genomic Data Sharing Policy, controlled-access data agreements, security standards, data-use limitations, institutional certifications, incident reporting, and Certificate of Confidentiality restrictions. Protected research information will not be disclosed in legal proceedings except as permitted by governing law and the applicable Certificate.
5. Withdrawal and Continuing Obligations
Withdrawal stops future participation as described in the consent form but may not require removal of information already used in completed analyses, regulatory records, safety reports, backups pending rotation, de-identified datasets, or research records that must be retained. The study-specific form will explain these limits.
6. No Guaranteed Benefit
RRF will not promise direct medical, educational, financial, or other personal benefit from research unless supported and specifically disclosed. Research findings may not be clinically valid or appropriate for individual decision-making.
Student, School, Education, and Protected Survey Data#
1. FERPA Status
RRF is not automatically subject to FERPA merely because it provides educational content. FERPA may govern information when RRF receives education records from a school or educational agency and acts as a school official, contractor, researcher, or other authorized recipient. In that situation, RRF will use the records only for the authorized purpose, remain under the school’s required control, limit redisclosure, and follow the written agreement and 34 C.F.R. Part 99.
2. School Agreements and Data Governance
execute a written agreement describing purpose, data fields, authorized users, security, subprocessors, incident notice, retention, deletion, return, audit, and parent or eligible-student request handling;
collect only information necessary for the educational service and prohibit targeted advertising, sale, unrelated profiling, and unrelated model training;
keep access and disclosure records where required and assist the school with access, correction, complaint, and breach obligations;
return, delete, or de-identify records at the end of the relationship as required; and
direct FERPA rights requests to the school unless the agreement instructs otherwise.
3. PPRA and Sensitive Surveys
When RRF administers a survey, analysis, or evaluation for a school that covers protected topics under the Protection of Pupil Rights Amendment, RRF will follow the school’s instructions concerning notice, inspection, parental consent or opt-out, and use of information for marketing. RRF will not independently use protected survey responses for fundraising, advertising, or profiling.
4. IDEA and Disability Information
Special-education, disability, accommodation, and individualized education information will be treated as confidential and used only for the authorized educational purpose. RRF will support reasonable accommodations and will not use disability data to unlawfully exclude or disadvantage a student.
5. COPPA in Schools
Where a school may consent as a parent’s agent under COPPA, the authorization is limited to the educational context and use for the school’s benefit. RRF remains responsible for its operator obligations and will not rely on school consent for unrelated commercial use, targeted advertising, or disclosure outside the authorized educational purpose.
6. School Security and Filtering Requirements
If a school relationship creates obligations under the Children’s Internet Protection Act, grant terms, state student-privacy law, district cybersecurity rules, or acceptable-use policies, the written agreement and technical deployment will address those requirements before student data is processed.
Email, Text Messaging, Calls, Electronic Signatures, and Marketing#
1. Email
Commercial or promotional email will use accurate sender and routing information, non-deceptive subject lines, required identification and postal information, and a functioning unsubscribe method. RRF will honor legally valid opt-out requests within the required period. Transactional, safety, program-administration, and legally required messages may continue when permitted.
2. Text Messages and Calls
RRF will obtain and document consent required by the Telephone Consumer Protection Act and related rules before sending regulated automated marketing texts or calls. Consent to receive marketing is not a condition of a donation or program service unless lawfully and clearly disclosed. Message frequency, carrier charges, STOP instructions, and HELP information will be disclosed where appropriate. RRF will not send marketing texts directly to a child.
3. Newsletters and Fundraising
Newsletter, advocacy, event, and fundraising lists will be maintained with source and consent records appropriate to the communication. Purchased, scraped, or unlawfully obtained contact lists are prohibited. Sensitive program, child, health, education, and research information will not be used to target fundraising unless specifically authorized and lawful.
4. Electronic Records and Signatures
Electronic signatures and records may be used when legally permitted. RRF may require identity verification, an audit trail, a copy capable of retention, and a separate paper or wet-signature process for documents requiring stronger formality. Consent to electronic records may be withdrawn prospectively where required.
Applicants, Employees, Contractors, and Volunteers#
Information submitted for employment, contracting, board service, internships, mentoring, or volunteering may include identity, contact, qualifications, references, availability, accommodations, background-check information, clearances, and legally permitted demographic data.
RRF will use workforce information for recruitment, screening, safeguarding, onboarding, administration, security, legal compliance, and recordkeeping.
Where RRF obtains a consumer report or investigative consumer report, it will provide notices, obtain authorization, and follow pre-adverse and adverse-action procedures required by the Fair Credit Reporting Act and applicable state law.
Child-abuse clearances and criminal-history information will be accessed only by authorized personnel, stored with heightened controls, and retained according to law and policy.
RRF will not use genetic information for employment decisions and will limit medical and disability information to lawful purposes with appropriate confidentiality.
Automated screening tools will be reviewed for job relevance, accessibility, bias, notice, and legally required human review or accommodation.
RRF may use essential cookies or local storage for security, accessibility, navigation, form operation, and remembering privacy preferences. Optional analytics will load only after consent where required and should not be enabled in child-directed areas unless specifically assessed and lawful.
Essential technologies: needed for requested functions, security, fraud prevention, and privacy preferences.
Analytics technologies: used to measure page performance and improve services; configured to minimize data where reasonably possible.
Advertising technologies: RRF does not use child data for targeted advertising. Any future advertising or social-media tracking must be separately assessed and disclosed before activation.
You may use the cookie control displayed on this page or browser settings to limit non-essential technologies. Blocking certain technologies may affect functionality.
Information Security, Vendor Governance, and Incident Response#
RRF uses a risk-based security program appropriate to its size, resources, activities, and data. Controls may be aligned to recognized frameworks such as the NIST Cybersecurity Framework, but RRF does not claim certification unless independently obtained and expressly stated.
1. Administrative Safeguards
data inventory, classification, owners, risk assessments, policies, training, confidentiality agreements, and sanctions;
role-based and least-privilege access, joiner-mover-leaver controls, periodic access review, and segregation of duties;
documented retention schedules, legal holds, secure disposal, backup governance, and incident-response exercises; and
enhanced procedures for children’s, education, health, genetic, biometric, financial, donor, and research information.
2. Technical and Physical Safeguards
multi-factor authentication where appropriate, encryption in transit and at rest where supported, secure configuration, patching, endpoint protection, logging, monitoring, and vulnerability management;
secure software development, code and dependency review, secrets management, backups, recovery testing, and restricted production access;
physical access controls and secure handling of paper records, devices, specimens, and removable media; and
separation or coding of direct identifiers from research data when feasible.
3. Vendors and Subprocessors
Before a vendor receives sensitive information, RRF will conduct due diligence proportionate to risk and use written terms addressing permitted use, confidentiality, security, incident notice, deletion or return, audit or assurance, subprocessors, location, legal requests, and assistance with individual rights. HIPAA business associate agreements, FERPA terms, COPPA duties, consumer-health processor agreements, or research data-use agreements will be used when applicable.
4. Incident Response and Notification
RRF will identify, contain, investigate, document, remediate, and learn from suspected incidents. RRF will assess whether notice is required under Pennsylvania’s Breach of Personal Information Notification Act, other state breach laws, COPPA, HIPAA/HITECH, the FTC Health Breach Notification Rule, consumer-health statutes, biometric laws, contracts, grant conditions, research oversight, or school agreements. Notices will be made to affected individuals, regulators, partners, law enforcement, media, or consumer reporting agencies when required.
No website, transmission, database, or security control is guaranteed to be completely secure. Users should not send sensitive information through unapproved channels and should report suspected unauthorized access promptly.
Depending on the applicable law and RRF’s role, a person may have rights to know or access information, obtain a copy, correct inaccuracies, delete information, restrict or object to processing, withdraw consent, opt out of sale, sharing, targeted advertising, profiling, or certain health-data uses, obtain portability, request a list of certain third parties, or appeal a denied request.
RRF will verify identity and, for an authorized agent or parent, authority appropriate to the sensitivity of the request.
RRF will respond within the legally required period and may extend where permitted with notice.
RRF will not unlawfully discriminate or retaliate for a valid request.
Exceptions may apply for child safety, legal obligations, fraud prevention, security, research integrity, tax and nonprofit records, free expression, litigation holds, and the rights of others.
Where legally required, RRF will recognize browser-based opt-out preference signals such as Global Privacy Control for covered sale, sharing, or targeted-advertising activity.
A parent seeking child information should use the COPPA process described above. FERPA requests should generally be directed to the school. Research-participant requests are also governed by the study consent and research record obligations.
Operational requirement: Before publication, RRF must designate and actively monitor a privacy email, child-safety reporting address, mailing address, and telephone number; adopt identity-verification and appeal procedures; and assign responsible personnel. A general contact form alone may not satisfy program-specific notice requirements.
Donations, Charitable Solicitation, Receipts, and Fundraising#
RRF will maintain charitable-solicitation registrations or documented exemptions in Pennsylvania and other jurisdictions where registration is required before solicitation.
Solicitations will accurately describe RRF, the campaign, material restrictions, the role of any professional fundraiser, and how funds are expected to be used. RRF will not use deceptive urgency, fabricated matching gifts, misleading impact claims, or hidden recurring charges.
Donations are generally final and non-refundable, except where required by law, a duplicate or processing error occurred, fraud is confirmed, or RRF approves a correction.
Unless RRF expressly accepts a written restriction, a donation may be used for RRF’s charitable purposes in the discretion of its governing body. If a restricted purpose becomes impossible, impracticable, unlawful, or inconsistent with charitable obligations, RRF will handle the funds according to applicable law and donor documentation.
RRF will provide acknowledgments needed for contributions of $250 or more and written quid pro quo disclosures for payments exceeding $75 when goods or services are provided, as required by federal tax law. Tax deductibility depends on law and the donor’s circumstances.
Recurring donations will disclose amount, frequency, cancellation method, and material terms before authorization. Cancellation will not affect completed transactions unless required by law.
Payment-card information is generally processed by a third-party provider. RRF will not represent itself as PCI-certified unless that status has been independently established and maintained.
Donor recognition will follow the donor’s choice and applicable confidentiality obligations. RRF will not publicly identify an anonymous donor without authorization or legal requirement.
Intellectual Property, Copyright, DMCA, and Attribution#
Unless otherwise identified, the website’s text, design, branding, logos, graphics, code, videos, educational materials, databases, and original content are owned by or licensed to RRF and protected by applicable law. Personal, noncommercial viewing is permitted. Reproduction, modification, publication, redistribution, model training, commercial use, or removal of attribution requires written permission unless a legal exception applies.
User submissions must be original or properly licensed. A user may not upload confidential research, student work, photographs, music, video, or other material without authority and required permissions.
Copyright Complaints
A notice should identify the protected work; identify and locate the challenged material; provide contact information; state a good-faith belief that the use is unauthorized; state under penalty of perjury that the notice is accurate and the sender is authorized; and include a physical or electronic signature. RRF may remove or restrict material while reviewing a complaint and may consider a valid counter-notice.
DMCA safe-harbor condition: RRF should not claim the Digital Millennium Copyright Act service-provider safe harbor unless it has registered a designated agent with the U.S. Copyright Office, publishes the agent’s current contact information, adopts a repeat-infringer policy, and satisfies the other applicable requirements.
Accessibility, Reasonable Accommodation, and Nondiscrimination#
RRF seeks to provide people with disabilities equal access to public-facing programs, services, communications, facilities, and digital content. Depending on the activity, the Americans with Disabilities Act, Section 504 of the Rehabilitation Act, grant conditions, education laws, and state law may apply.
RRF targets WCAG 2.2 Level AA as a technical design and remediation benchmark where reasonably achievable; this target does not replace the specific legal analysis applicable to a program.
RRF will provide reasonable modifications, auxiliary aids, effective communication, accessible forms and documents, captions or transcripts where appropriate, and alternate formats unless doing so would create an undue burden or fundamentally alter the service under applicable law.
Third-party platforms will be evaluated for accessibility before use where reasonably practicable, and accessible alternatives will be provided when required.
Accommodation requests will be handled promptly, interactively, confidentially, and without retaliation.
RRF does not unlawfully discriminate in programs, employment, or services on a protected basis. Lawful, mission-related eligibility requirements may be used when clearly disclosed and applied consistently.
Contact, COPPA Operator Notice, Privacy Requests, and Policy Administration#
General and Privacy Requests
Use the RRF contact form and include “Privacy Request,” “COPPA Parent Request,” “Accessibility Request,” or the applicable subject in the first line.
Child Safety Concerns
Use the contact form and include “Child Safety Concern.” For suspected abuse or neglect in Pennsylvania, call ChildLine at 1-800-932-0313. Call 911 for immediate danger.
Child Privacy and Safety Readiness Review
Before any child-facing feature is made available to the public or used with identifiable information from children or students, RRF will complete an appropriate privacy, security, safeguarding, and legal readiness review. This review may apply to child or student accounts, registrations, applications, surveys, assessments, direct messaging, photographs, videos, voice recordings, location information, device identifiers, cookies, analytics, educational records, health or genetic information, research participation, artificial-intelligence tools, uploads, payment or donation functions involving minors, and third-party integrations that may collect or process information about a child.
RRF will evaluate each program based on its specific purpose, audience, technology, partners, funding requirements, geographic reach, and data practices. Approval to launch will be based on documented safeguards, tested controls, appropriate consent procedures, trained personnel, reviewed vendors, and confirmation that the program is prepared to operate consistently with the commitments described on this page.
Mandatory Operational Readiness Requirements
Program and legal-scope review. Prepare a written applicability assessment for COPPA, state child-privacy laws, FERPA and school contracts, PPRA, IDEA confidentiality, HIPAA and HITECH, the FTC Health Breach Notification Rule, human-subject research requirements, Pennsylvania child-protection law, accessibility duties, biometric and genetic-information laws, breach-notification laws, charitable-solicitation requirements, and any grant, institutional, contractual, or international obligations that may apply.
Data inventory and flow mapping. Document every category of information collected, inferred, generated, uploaded, received from schools or partners, shared with vendors, used by artificial intelligence, stored in backups, or deleted. Identify the source, purpose, legal authority or consent, users, recipients, storage location, retention period, and deletion method.
Child-directed and age-screening assessment. Determine whether each feature is directed to children, likely to attract children, or creates actual knowledge that a user is under 13. Use a neutral and tested age-screening method where appropriate, prohibit circumvention, and do not encourage children to misstate their age.
Direct notice and verifiable parental consent. Create program-specific parental notices and a documented verifiable parental-consent process before collecting personal information online from a child when required. Maintain proof of notice, consent, verification method, scope, date, changes, withdrawal, and deletion. Obtain separate consent where required for disclosures, public posting, advertising, profiling, biometric information, precise geolocation, or other materially different uses.
Parent and guardian rights workflow. Provide authenticated procedures for parents or guardians to review information collected from their child, correct it, revoke consent, refuse further collection or use, obtain required disclosures, and request deletion. Establish identity-verification standards, response deadlines, escalation procedures, and a request log.
Data minimization and retention. Collect only information reasonably necessary for the disclosed activity. Adopt a written retention schedule for each data category, prohibit indefinite retention, delete information when no longer reasonably necessary, address backups and derived data, and document deletion or approved de-identification.
Vendor and operator governance. Complete documented privacy, security, safeguarding, accessibility, and legal reviews before engaging any hosting provider, analytics service, learning platform, payment processor, communications tool, cloud provider, artificial-intelligence provider, laboratory, researcher, school vendor, or other operator. Execute appropriate data-processing, confidentiality, security, school-data, research, and business-associate agreements. Contracts should prohibit undisclosed secondary use, sale, targeted advertising, unauthorized profiling, re-identification, and model training with protected data unless specifically approved and lawfully authorized.
Security baseline. Implement role-based access, least privilege, multifactor authentication, secure credential management, encryption in transit and at rest where appropriate, system and access logging, monitoring, patch and vulnerability management, secure backups, recovery testing, device security, secure development and change control, vendor access controls, and prompt removal of access when personnel or relationships change.
Incident response and notification. Maintain a written incident-response and breach-notification plan with defined decision-makers, evidence preservation, containment, vendor notification duties, legal assessment, insurer notification, communication templates, regulator and affected-person notification procedures, and post-incident corrective action. Conduct and document tabletop exercises.
Child safeguarding. Adopt a board-approved child-safeguarding policy covering required Pennsylvania clearances, mandated-reporter training and immediate reporting, professional boundaries, adult-to-child communications, two-adult or observable-and-interruptible practices where appropriate, transportation, pickup and release, restroom and changing-area procedures, photography and media consent, prohibited conduct, allegations against personnel, anti-retaliation, emergency response, and preservation of records.
Personnel screening and training. Confirm and document all legally required Pennsylvania Child Abuse History, Pennsylvania State Police, FBI, and other applicable screenings before covered personnel or volunteers have contact with children. Track renewal dates. Require role-based onboarding and recurring training in privacy, COPPA, cybersecurity, accessibility, safeguarding, mandated reporting, research ethics, and incident escalation.
School and student-data controls. Before receiving education records or operating for a school, execute a written agreement defining the educational purpose, school control, permitted users and uses, redisclosure restrictions, security, parental rights, retention, deletion or return, incident notice, subcontractors, and termination. Do not rely on school authorization for activities outside the educational context or for RRF's independent commercial, fundraising, advertising, profiling, or research purposes.
Research involving children. Do not begin human-subject research involving children without a documented determination of whether Institutional Review Board review is required and, when applicable, approval by a properly constituted IRB. Use protocol-specific parental permission, child assent appropriate to age and maturity, recruitment materials, risk disclosures, privacy protections, adverse-event procedures, withdrawal processes, data and specimen plans, and re-consent procedures when a participant reaches the age of legal consent.
Health, genetic, genomic, biometric, and specimen governance. Determine RRF's role under applicable health-privacy laws before collection or exchange. Use specific and understandable authorization or consent; define testing limitations, return-of-results rules, incidental findings, clinical-confirmation requirements, familial implications, storage, secondary research, data sharing, specimen retention and destruction, law-enforcement requests, and withdrawal limitations. Execute business-associate agreements when RRF is acting as a HIPAA business associate.
Artificial intelligence and automated systems. Inventory every AI system and model, its provider, inputs, outputs, training-data practices, retention, human access, accuracy limitations, bias risks, and security controls. Prohibit the use of protected child, student, health, biometric, genetic, or research data for vendor model training unless expressly approved and lawfully authorized. Require meaningful human review for consequential decisions and provide a process to question or correct material outputs.
Communications, community features, and media. Disable unmoderated child-to-adult or child-to-child messaging, public profiles, public location disclosure, open comments, livestreaming, and uncontrolled uploads unless a documented safety and moderation design has been approved. Establish reporting, blocking, moderation, evidence-preservation, escalation, and emergency-response procedures. Obtain appropriate releases before publishing a child's name, image, voice, work, testimonial, or identifying information.
Accessibility and inclusive design. Test child and parent notices, consent tools, forms, learning content, authentication, request mechanisms, and emergency information for keyboard access, screen-reader compatibility, captions, readable language, color contrast, zoom, mobile use, and alternative formats. Document remediation and a method for requesting accommodations.
Insurance and contractual risk allocation. Review whether RRF maintains appropriate general liability, directors and officers, cyber/privacy, professional or errors-and-omissions, abuse and molestation, volunteer, event, and research-related coverage. Confirm that contracts contain appropriate confidentiality, indemnification, insurance, audit, breach, deletion, subcontractor, and termination provisions.
Records and audit readiness. Maintain a controlled compliance repository containing policies, data maps, risk assessments, notices, consent and assent records, contracts, vendor reviews, security tests, training records, clearances, incident records, privacy requests, deletion records, accessibility testing, research approvals, board actions, complaints, and corrective-action documentation.
Testing before launch. Test every form, consent flow, age screen, account, email, text message, upload, permission setting, parental dashboard, deletion process, vendor transfer, cookie or analytics tool, security control, accessibility feature, and emergency escalation using synthetic or authorized test data—not real child information.
Formal Authorization Required Before Activation
No covered feature may be activated until RRF records a written launch approval identifying the specific feature, approved data uses, vendors, retention periods, notices, consent mechanism, security review, safeguarding review, accessibility review, remaining risks, conditions of approval, and responsible owner. Approval should include the following roles, as applicable:
RRF executive or authorized program leader;
Privacy and COPPA responsible person;
Child safeguarding lead;
Information-security or qualified technical reviewer;
Program, education, healthcare, laboratory, or research lead;
Institutional Review Board or other ethics reviewer when required;
Qualified Pennsylvania counsel and any additional counsel needed for other jurisdictions; and
Board or designated board committee when the feature presents material child-safety, research, health, biometric, genetic, artificial-intelligence, financial, reputational, or regulatory risk.
Required Internal Policies and Records
RRF should adopt and maintain written procedures that correspond to the public statements on this page, including data inventories and maps; records of processing; risk and privacy-impact assessments; retention and secure-deletion schedules; COPPA direct-notice templates; verifiable parental-consent records; parent-request procedures; school and student-data agreements; research protocols, consent and assent templates; health, genetic, genomic, biometric, and specimen governance; artificial-intelligence governance; vendor due diligence and contract standards; incident-response and breach-notification plans; privacy-request and complaint logs; accessibility testing; personnel clearances; safeguarding and mandated-reporter training; records-management controls; insurance reviews; and board-level reporting and oversight.
Professional Review and Continuing Oversight
Qualified Pennsylvania counsel and appropriate privacy, child-safety, research, cybersecurity, education, healthcare, laboratory, accessibility, insurance, tax, charitable-solicitation, and nonprofit professionals should review each applicable program before launch. Specialized counsel should be consulted before offering services or collecting information from residents of additional states or countries.
This page and the supporting operational program should be reviewed at least annually, after a security or safeguarding incident, and before any material change involving data practices, child-facing features, eligibility, research, artificial intelligence, health or genetic activities, vendors, funding conditions, school relationships, jurisdictions, or legal obligations. Material changes should be documented, risk-assessed, approved, reflected in updated notices and consent where required, and communicated before the changed practice begins.
Important: This policy reflects RRF’s commitment to responsible privacy, security, safeguarding, and research practices. RRF will support these commitments through appropriate technology, trained personnel, carefully managed vendor relationships, documented consent procedures, effective security controls, strong child-protection measures, sound research governance, and timely, respectful responses to individuals and families.
RRF uses essential browser storage for security and preferences. Optional analytics should load only after permission where required. A recognized privacy preference signal will be honored for covered activities.