Compliance

Dos Terra Limited Liability Company dba Sibme

Security Statement

Updated on March 4, 2024

Dos Terra Limited Liability Company dba Sibme (“Sibme”) values and prioritizes the safety, privacy and security of the organizations that use its website. For more information about our Privacy Policy, please go to privacy-policy. The security of your personal information is very important to Sibme. We use robust security measures, which encompass both technical and organizational security controls, to prevent data loss, information leaks, or other unauthorized data processing operations. This page outlines the steps we have taken to ensure, to the best of our ability, that our customers’ data is private and secure. For example, Sibme requires that its processors and sub-processors (collectively, “Vendors”) have implemented and maintain a security program in accordance with industry standards.

Amazon AWS Hosting

Sibme website is hosted and customer data resides on Amazon AWS infrastructure, which (i) has highly secure data centers with state-of-the art electronic surveillance and multi-factor access control systems, (ii) is staffed 24×7 by trained security guards, and (iiii) its access is authorized strictly on a least privileged basis. AWS has achieved ISO 27001 certification and has been validated as a Level 1 service provider under the Payment Card Industry (PCI) Data Security Standard (DSS). In addition, AWS undergoes annual SOC 1 audits and have been successfully evaluated at the Moderate level for Federal government systems as well as DIACAP Level 2 for DoD systems. Access to Sibme data portal management with AWS is limited to only a few key employees and is protected by a two-factor authentication mechanism for access, requiring authorized team members to first log in using their email address and password, then enter a six-digit access code that refreshes every 30 seconds from a linked mobile device. All private data exchanged with Sibme is always transmitted over SSL. Here are some useful links relating to their own security and continuity plans:

  • AWS Cloud Security: https://aws.amazon.com/security/

  • AWS Compliance: https://aws.amazon.com/compliance/

Privacy of Videos/Resources Posted to Sibme Website

All videos uploaded to the Sibme website are by default private to the user if uploaded to their Workspace and other selected users if uploaded directly to Huddles. A user decides who else can see those videos and resources. For additional information on our privacy practices, please see our Privacy Policy.

Data Security

Authentication for users happens at app.sibme.com/users/login using email and password authentication, via sign-in via Google, or SSO via an organization’s authentication process (i.e. Microsoft Azure/AD, Canvas, etc.). All requests made through Sibme in a browser are done via TLS/SSL. Sibme keeps a robust set of logs for auditing purposes

Integrations

Sibme is LTI Compliant and we follow the LTI standard when integrating with customer’s LMS’. For more information on LTI Compliance and LTI integrations, please visit the IMS Global Learning Tools Interoperability® page.

SOC and SSAE

Sibme requires its Vendors, such as Amazon AWS to achieve key compliance controls and objectives as well as establish controls to support operations and compliance. More information on AWS System and Organization Controls (SOC) can be found on their site.

PCI Compliance

Sibme maintains Payment Card Industry Data Security Standard (“PCI”) compliance in connection with processing user credit card charges. As required by the PCI compliance standard, Sibme quarterly undergoes extensive third party security and penetration tests to ensure our payment site is secure. Please view our PCI Compliance certificate from SecurityMetrics.

FERPA Compliance

The U.S. Family Educational Rights and Privacy Act (“FERPA”) is designed to protect student identity and academic information from unauthorized disclosure to third parties. Sibme complies with all relevant provisions as follows:

  • User information is private in the system, viewable only by authorized individuals. Such permissions must be explicitly granted within Sibme.
  • When applicable, student grading information is viewable only to authorized instructors, reviewers, IT administrators, and to the individual student themselves.
  • Authorized Sibme staff may access the account information solely for the purpose of providing service and support to the instructor and students. Such access is limited to authorized service and support staff only. Consent for this limited use of their account information is granted by each student user upon signup with required acceptance of the Terms of Service.
  • Sibme does not require any unique identifying information for any student data collected in the platform.

COPPA Compliance

Sibme is compliant with U.S. Children’s Online Privacy Protection Act (“COPPA”) requirements regarding the capture and use of images of children under the age of 13. Key elements include:

  • Videos in the system are private by default, as described above.
  • Users (teachers, administrators, etc.) who post videos that include children under 13, such as classroom observations, are responsible for any parent/guardian permissions.
  • Parents may request removal of any video of their child by directly contacting Sibme.
  • Children under 13 years of age are expressly prohibited by our Terms of Service from creating their own account.

For more information, see the COPPA references in our Terms of Service and Privacy Policy

CCPA Compliance

To the extent applicable, Sibme is compliant with the California Consumer Privacy Act (“CCPA”), including applicable consumer rights in control of their personal data. Please see Sections 3, 10, and 15 in our Privacy Policy

EU Privacy Shield and GDPR Compliance

Sibme complies with the principles of the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework (collectively, the “Data Privacy Framework” or “DPF”) as set forth by the U.S. Department of Commerce. Sibme has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles with regard to the processing of Personal Data received from the European Union in reliance on the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”) and from the United Kingdom(and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Sibme has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework program Principles with regard to the processing of Personal Data received from Switzerland in reliance on the Swiss-U.S. Data Privacy Framework. The DPF includes requirements for security, consent, and user data rights, including the right to deletion. Please refer to the EU/GDPR Section of our Privacy Policy for more details. For EU, UK and Swiss users, you can review your rights and recourse in our Privacy Policy, which outlines our commitment to data privacy and user protection.

Accessibility

Sibme is designed to comply with applicable software accessibility requirements of Section 508 of the U.S. Rehabilitation Act. The system is designed to work with native accessibility tools within Windows and Mac operating systems as well as the enhanced functions included in modern web browsers. For details related to our Section 508 compliance, please see our Voluntary Product Assessment Template (VPAT). Sibme is also designed to comply with the Web Content Accessibility Guidelines (WCAG) version 2.1, levels A and AA. For more about WCAG 2.1 compliance, see Web Content Accessibility Guidelines (WCAG) Overview.

If you have additional questions regarding Sibme’s security or privacy, please contact us at Sibme Support at any time.

Data Breach Notification Compliance

Sibme has a Data Breach Notification Policy, which describes a process to quick and efficient recovery from security incidents, respond in a systematic manner to incidents and carry out the steps necessary to handle an incident, and minimize disruption to critical computing services or loss or theft of sensitive or mission critical information. Sibme will determine whether the compromised system is a low risk or a high risk data and whether the system affected is considered a high critically system. “High Critically System” is when it meets either of the following criteria: (i) stores, transmits, or provides access to High Risk Data (as defined below) or (2) loss of access could have a significant impact on Sibme as a whole and the overall institution risk from downtime is high. “High Risk Data” is defined when either of the following conditions apply: (A) the data is governed by laws or regulations that requires Sibme to report to the government and/or provide notice to individuals if the data is breached, or (B) the unauthorized use, access, or alteration of the data could have a significant adverse impact on Sibme or an individual community member. For example, social security numbers and national identification numbers, driver’s license numbers, passport and visa numbers, operating system passwords, application passwords, and API keys, central authentication credentials, financial information, health information, special categories of data under GDPR.

Sibme will risk classify the data by taking into account the (i) inherent attributes of the data; (ii) source of the data; (iii) regulation or policy governing the data; and (iv) relationship of the data to previously disclosed data. The classification of specific data is subject to change as the attributes of that data change (e.g. its elements, content, uses, importance, method of transmission, or regulatory context).

List of Sub-Processors

Sibme uses the 3rd party entities below (each, a “sub-processor”) to process personal data on behalf of Sibme customers and in accordance with contract terms between Sibme and the sub-processor to uphold Sibme’s commitments.

Further information relating to sub-processor security measures can be found via the external links below. For each sub-processor below, processing of personal data will be for the duration of use of the applicable service(s) by the customer, and for the retention periods as set out in the customer’s agreement with Sibme and any product documentation.

Sub-Processor Nature and Purpose of Processing Categories of Personal Data Location of Processing Security and Supplemental Measures
Amazon Web Services, Inc. Hosting and Cloud Infrastructure Personal data contained in User Account information and Artifacts created by customer and stored in Sibme. United States AWS Compliance Programs
AWS Sub-Processors
MongoDB, Inc. Managed Database Services Personal data contained in User Account information and Artifacts created by customer and stored in Sibme. United States MongoDB Atlas Trust Center
MongoDB Sub-Processors
OpenAI, L.L.C. Generative AI Services Provider for Intelligence Product Features Artifacts created by customer and stored in Sibme. United States OpenAI Security & Trust
OpenAI Sub-Processors List
FileStack Cloud-Based File Handling Service Artifacts uploaded by customer and stored in Sibme. United States FileStack Privacy
FileStack Sub-Processors
Cloudflare, Ltd. Content Delivery Network Provider Personal data contained in User Account information and Artifacts created by customer and stored in Sibme. United States Cloudflare Certifications and Compliance Resources
Cloudflare Sub-Processors
ChurnZero Customer Success Management Personal data contained in User Account information. United States ChurnZero Privacy Policy
OneSignal Push Notification Services Personal data contained in User Account information. United States OneSignal Security & Privacy
OneSignal Sub-Processors
HubSpot, Inc Marketing and Sales Operations Personal data contained in User Account information. United States HubSpot Data Privacy
HubSpot Sub-Processors
edTPA Educational Teacher Performance Assessment User Account information and Artifacts created by customer and stored in Sibme. United States edTPA Privacy Policy
Intercom, Inc Customer Service and Technical Support Personal data contained in User Account information. United States Intercom Terms and Policies
Intercom Sub-Processors
Stripe, Inc. Billing Personal data contained in User Account information. United States Stripe Privacy Center
Stripe Sub-Processors
Braintree Payments Billing Personal data contained in User Account information. United States Braintree Privacy Policy
Braintree Customer Data Protection
Zoom Video Communications Inc. Video Conferencing, Web Meetings Personal data contained in User Account information. United States Zoom Privacy Policy
Zoom Sub-Processors
Agora Solutions Interactive Live Streaming Personal data contained in customer created live stream. United States Agora Compliance & Privacy
Agora Security
SendGrid Email Delivery Services Personal data contained in product notice communications. United States Sendgrid Security
Sendgrid Sub-Processors
OpenGraph Technologies Web Scraping Personal data contained in customer created Artifacts. United States OpenGraph Technologies Privacy
Google Inc. Calendar Events OAuth 2.0 Personal data contained in User Account information. United States Google Privacy Policy
Google Sub-Processors
Microsoft Corporation Calendar Events OAuth 2.0 Personal data contained in User Account information. United States Microsoft Cloud Data Integrity
Microsoft Service Trust Portal
Thinkific Learning Center Personal data contained in User Account information. United States Thinkific Privacy Policy
Thinkific Sub-Processors

Use the form below to sign up form below to be notified when we add new Sibme sub-processors.