1. Overview/Purpose
DAPORA is a cloud-based software service that helps colleges and universities prepare and manage NCAA and Equity in Athletics Disclosure Act (EADA) athletics-compliance reporting. This notice explains how James Moore & Co., P.L. ("James Moore," "we," "us") handles information in connection with the DAPORA service. The purpose of this notice is to describe what data DAPORA collects and processes, how that data is used, protected, retained, and deleted, and the commitments James Moore makes to its customers with respect to that data.
In plain terms:
- DAPORA processes institutional athletics-reporting data on behalf of the institution. Most of this data is aggregate (for example, scholarship and aid figures are typically provided at the sport and gender level). However, some source files — particularly athletics payroll files — include employee names used to classify salaries (e.g., head coach, assistant coach, support staff), and those names may belong to student employees or graduate assistants.
- Where DAPORA processes student education-record information, James Moore acts as a "school official" with a legitimate educational interest under FERPA (34 CFR 99.31(a)(1)(i)(B)), under the institution's direction and only to provide the contracted service.
- All DAPORA production data is hosted in the United States (primary AWS region us-east-2, with encrypted disaster-recovery backups in a second US region, us-west-2).
- We do not sell Customer Data, use it for advertising, or use it to train artificial-intelligence models.
- Customers control the data they submit and may export or request deletion of their Customer Data, subject to the backup and retention practices described in this notice.
- EADA report outputs are designed to support reporting that institutions publish or submit to regulators; this notice governs the Customer Data processed within DAPORA, not the public report values themselves.
2. Definitions
For purposes of this notice:
"Customer" means the college, university, or other institution that has entered into an agreement with James Moore for the DAPORA service.
"Customer Data" means the institutional athletics-reporting data a Customer submits to the DAPORA service. Customer Data may include limited identifiable student information contained in customer source files (see Section 5), including information that constitutes a student education record under FERPA.
"FERPA" means the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g) and its implementing regulations (34 CFR Part 99).
"School official" describes a contractor to whom an institution has outsourced institutional services or functions under the conditions of 34 CFR 99.31(a)(1)(i)(B).
"Student Data" means any information within Customer Data that identifies an individual student, such as the names of student employees or graduate assistants in athletics payroll source files.
"Subprocessor" means a third-party service provider James Moore uses to process Customer Data to provide the DAPORA service.
3. Scope of This Notice
This notice applies to: institutional customers of DAPORA; authorized customer administrators and users; support contacts; and visitors to the DAPORA service. It does not cover James Moore & Co.'s broader advisory, accounting, or consulting services, employment/applicant data, or client engagement files maintained outside the DAPORA service, which are governed by the firm's separate policies and engagement agreements.
4. Data We Collect and Process
The categories below describe the data collected and processed within DAPORA. "Customer Data" is the institutional reporting data a customer submits to the service, and may include limited identifiable student information (see Section 4).
| Data category | Examples |
| Customer Data (institutional reporting data) | Aggregate athletics aid totals; participation counts by sport/team/gender; expense and revenue totals by sport/team/category; aggregate coach counts and salary data; NCAA/EADA reporting fields |
| Account Data | Name, work email, role, institution, login credentials |
| Usage & Security Data | IP address, login timestamps, browser/device, audit logs |
| Support Data | Support requests and related configuration details |
| Billing & Business-Contact Data | Contact information, contracts, invoices |
5. Limited Student Data DAPORA May Receive
DAPORA is designed around aggregate and team-level athletics-reporting data and applies data minimization. Some source files a customer submits do, however, include limited identifiable student information:
- Employee names — Athletics payroll source files include employee names so that salaries can be classified for reporting (e.g., head coach, assistant coach, support staff). These names may belong to student employees or graduate assistants. Because the name is required to perform the salary classification, DAPORA receives it, stores it in the application database, and uses it in the reporting process. (Student-level data is not written to application or security logs.)
- Scholarship / aid amounts — These are typically provided at the aggregate sport and gender level. Individual student-level scholarship detail is atypical; where a general ledger lacks sufficient detail, an institution may supply a supplemental report or enter a top-side adjustment, which is also generally maintained at the aggregate level.
DAPORA does not request or solicit identifiable student information; however, some source files provided by customers may contain it. Where identifiable student information is present, it constitutes a student education record, and James Moore processes it solely as a school official with a legitimate educational interest under FERPA (34 CFR 99.31(a)(1)(i)(B)), under the institution's direction and only to provide the contracted service.
DAPORA does not knowingly collect, and customers should not submit: Social Security numbers; dates of birth; student health, medical, disability, immigration, disciplinary, or academic-status records; or other sensitive personal information beyond what is necessary for athletics-compliance reporting. Where customer source data includes fields containing sensitive information of this kind (for example, Social Security numbers or dates of birth), DAPORA can be configured to automatically exclude those fields or to mask them so that sensitive values are not stored in readable form.
6. Customer Responsibilities
Customers are responsible for: submitting only data necessary for athletics-compliance reporting; minimizing or de-identifying source data where feasible before upload; ensuring they have authority, as the data controller, to submit the Customer Data (including any FERPA-covered information) to James Moore as a school official; not submitting sensitive data outside the scope described in Section 4; and reviewing exports and reports before submitting them to the NCAA, under EADA, or to any other body. James Moore will handle any FERPA-covered information received under the access, use, and redisclosure limitations of the school-official exception and the applicable customer agreement.
7. How We Use Data
We use the data described above to: provide the DAPORA service; generate reports and calculations; create and administer user accounts; secure and monitor the service; provide customer support; troubleshoot and maintain reliability; meet legal and contractual obligations; and maintain audit logs. We use Usage & Security Data and aggregated, de-identified operational data to maintain and improve service reliability and security.
8. How We Do Not Use Data
- We do not sell Customer Data.
- We do not use Customer Data for advertising, behavioral targeting, or marketing profiles.
- We do not use Customer Data to train artificial-intelligence models.
- We do not use Customer Data for benchmarking or analytics unrelated to the service without the customer's written permission.
- We do not disclose Customer Data except as described in this notice or the applicable customer agreement.
9. Sharing and Subprocessors
We share data only as needed to operate DAPORA: with our cloud-hosting and infrastructure provider; with security/monitoring and support providers; with users the customer designates; with professional advisers; as required by law or valid legal process; and in connection with a corporate transaction, subject to this notice. We do not otherwise disclose Customer Data. Current subprocessors:
| Subprocessor | Function |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure |
| [Support / ticketing provider — CONFIRM] | Customer support |
| [Logging / monitoring provider — CONFIRM, if any beyond AWS-native] | Security and reliability monitoring |
10. Data Location
DAPORA production Customer Data is hosted and stored in United States AWS regions. The primary production environment is hosted in AWS us-east-2, and encrypted disaster-recovery database backups are copied to AWS us-west-2. Customer Data may be transferred or copied between AWS availability zones and servers within these US regions for redundancy and backup purposes. DAPORA may use AWS global or edge services to route, secure, and deliver the service; those services may process network, security, or routing metadata as part of service delivery, but DAPORA stores production Customer Data in the U.S. AWS regions described above.
Administrative access. Access to Customer Data and uploaded source files is restricted to authorized James Moore personnel with a legitimate business need, using role-based, least-privilege access controls and strong authentication, and is recorded in audit logs. Production access is limited; routine internal access is generally read-limited, and elevated access required for support, security, or troubleshooting is approved through an internal support/change process, limited to the purpose and duration of the task where practicable, and logged for auditability.
11. Security
DAPORA uses a defense-in-depth security model, including: encryption in transit (TLS 1.2+) and at rest (AWS KMS); role-based, least-privilege access controls; multi-tenant isolation with database row-level security and per-tenant storage; audit logging; automated backups; vulnerability management and security scanning in the development pipeline; incident-response procedures; and subprocessor review. No method of transmission or storage is completely secure, and we do not guarantee absolute security.
12 Retention and Deletion
| Data type | Retention |
|---|---|
| Customer Data | Retained for the subscription term; on termination, exported and/or deleted per the customer agreement. |
| Backups | Daily production database backups and DR copies retained for 35 days; weekly production backups and DR copies retained for up to 90 days. Backups are stored in US AWS regions (primary us-east-2; DR copies in us-west-2). |
| Security logs | Security, audit, and production service logs retained for at least 365 days, unless a longer period is required by law, contract, litigation hold, or a security investigation. Logs are access-controlled and protected against unauthorized access or alteration. |
| Support tickets | Retained for support history unless deletion is requested. |
| Billing records | Retained as required for accounting and legal purposes. |
Deletion scope. Upon verified customer request or contract termination, Customer Data is deleted or rendered inaccessible from active production systems within 90 days after the applicable export window closes, after delivery of a requested export, or after verification of the deletion request, as applicable, unless retention is required by law, contract, billing obligations, security investigation, dispute, or other legitimate legal or business requirement. Customer Data contained in encrypted backups and snapshots is removed on the applicable backup-expiration cycle rather than by immediate targeted deletion, because targeted deletion from historical backups and snapshots may compromise backup integrity and recoverability; backup data remains encrypted and access-controlled until expiration. Under the current production backup schedule, daily production database backups and their disaster-recovery copies are retained for 35 days, and weekly production backups and their disaster-recovery copies are retained for up to 90 days.
13. Termination of Services
Upon expiration or termination of a Customer's subscription, the export, deletion, and handling of Customer Data are governed by the applicable customer/license agreement. In general, the Customer may export its Customer Data during any export window provided in the agreement; Customer Data is then deleted or rendered inaccessible from active production systems, and removed from encrypted backups on the backup-expiration cycle, in each case within the timeframes and subject to the legal-retention exceptions described in Section 12.
14. Handling of Student Education-Record Data
Because some source data may include limited student education-record information (see Section 4), James Moore handles it as follows: it is processed only as a school official under FERPA, at the institution's direction and only to provide the contracted service; it is protected by the security controls in Section 10 (encryption, role-based least-privilege access, multi-tenant isolation, audit logging); it is not redisclosed except as permitted by the customer agreement and FERPA; and it is retained and deleted per Section 11 and the customer agreement. James Moore applies data minimization to limit identifiable student information to what is necessary. If a customer submits sensitive data outside the scope of Section 4, we may notify the customer, restrict access, or delete the data, and may ask the customer to resubmit it within scope. The institution retains ownership and control of its education records and other Customer Data at all times. Upon request, James Moore will provide the institution with a copy of its Customer Data in a commonly used format through a secure transfer process.
15. Customer and User Rights
Institutional customers may access, export, correct, or delete their Customer Data through the service or by request. Individual users may update their account information. Because the institution controls its Customer Data, requests from individuals about that data may be routed to the institution. We respond in accordance with the customer agreement and applicable law.
16. Changes to This Notice and Contact
We will update this notice when our practices change and will provide notice of material changes. Questions or requests: digitalsupport@jmco.com (Attn: DAPORA / Daniel Shorstein, President, James Moore Digital).