Effective Date: August 22, 2026
Last Updated: August 23, 2026
Curriculum Warehouse, operated by NJ Data Diva LLC, is designed with security, Client separation, and responsible data handling as core Platform principles.
This Security & Data Protection Policy describes the administrative and technical practices used to protect information processed through Curriculum Warehouse.
It should be read together with the Curriculum Warehouse Terms of Service, Privacy Policy, Terms of Use, Student Data Scope, Subprocessors, and Service Level Agreement.
No online service can guarantee absolute security. Curriculum Warehouse therefore uses commercially reasonable safeguards designed to reduce risk, protect Client environments, and support timely response when security concerns arise.
The private Curriculum Warehouse application is built and hosted using services provided through Google Cloud Platform and Firebase, including Firebase Hosting and related Google Cloud/Firebase infrastructure.
The private Platform currently uses managed cloud infrastructure for functions that may include:
Client curriculum information and private Platform data are maintained within the Google Cloud/Firebase environment.
The public Curriculum Warehouse marketing and legal Website at curriculumwarehouse.com is hosted and managed through GoDaddy.
The public Website is separate from the private Curriculum Warehouse application.
GoDaddy does not serve as the primary hosting environment for Client curriculum data or the private Curriculum Warehouse Platform.
Primary Curriculum Warehouse Platform data is hosted using United States-based Google Cloud infrastructure.
Applicable Platform services may operate within U.S.-based Google Cloud infrastructure according to Platform configuration and the technical requirements of the applicable Google Cloud/Firebase service.
Curriculum Warehouse does not independently operate physical data centers.
Physical infrastructure protections for the private Platform are provided by the applicable cloud infrastructure provider.
Google Cloud maintains physical and environmental security controls for its data-center infrastructure, including controls relating to:
Curriculum Warehouse uses encrypted HTTPS connections to protect information transmitted between supported user browsers and Platform services.
Transport encryption is provided through industry-standard TLS protocols supported by the applicable hosting infrastructure.
Platform information stored through applicable Google Cloud services is protected using Google Cloud's default encryption-at-rest infrastructure.
Google Cloud encrypts customer content stored at rest within applicable services, including use of AES-256 encryption at the storage layer where supported by the applicable Google Cloud service.
Curriculum Warehouse currently relies upon Google-owned and Google-managed encryption keys associated with Google Cloud's default encryption infrastructure unless otherwise specifically configured.
Curriculum Warehouse does not represent that Clients independently control or possess the underlying cloud-provider encryption keys.
Curriculum Warehouse may support authentication through:
Where a Client uses Google Workspace or Microsoft 365 Single Sign-On (“SSO”), authentication occurs through the applicable identity provider.
Curriculum Warehouse does not receive or store the user's Google Workspace or Microsoft 365 password.
Where Firebase Authentication is used, authentication credentials are managed through the applicable authentication service.
NJ Data Diva LLC personnel do not have access to users' plain-text passwords.
Clients remain responsible for:
Students are not intended to be Authorized Users of the private Curriculum Warehouse Platform.
Additional information regarding unintended student authentication is provided in the Curriculum Warehouse Student Data Scope and Privacy Policy.
Curriculum Warehouse uses role-based access controls designed to limit Authorized Users to information and functions appropriate to their assigned access.
Current Client-level Platform roles include:
An account may also be placed in an Inactive state, which prevents ordinary Platform access.
A separate Corporate Admin role is reserved for authorized NJ Data Diva LLC personnel who require Provider-level access for legitimate Platform administration, configuration, support, security, maintenance, recovery, or related operational purposes.
Platform access controls are designed to be enforced through backend and database security logic rather than relying solely upon what is visible within the user interface.
Curriculum Warehouse uses a multi-Client architecture designed to separate each Client's private Platform environment.
Ordinary Client users are not authorized to access another Client's private curriculum environment.
Access-control rules, Client identifiers, authentication information, and Platform permissions are used to restrict Platform requests to the appropriate Client environment.
Authorized NJ Data Diva LLC personnel with Corporate Admin or other Provider-level administrative access may access Client environments where reasonably necessary to:
Provider-level access is not intended for routine evaluation of Client personnel.
Curriculum Warehouse generates system and audit records associated with certain Platform activity.
Depending upon Platform functionality, these records may include:
Such information may assist with:
Curriculum Warehouse may track the duration of active Platform sessions.
Active session duration may be used for purposes including:
Active session information is intended to describe activity within Curriculum Warehouse.
It is not designed as a payroll, attendance, or employee timekeeping system and should not be relied upon as the sole measure of an individual's:
Depending upon Platform configuration, assigned roles, and permissions, certain audit and activity records may be available to authorized Client administrators.
The Client is responsible for its use of such information in accordance with applicable law, Board policy, employment agreements, collective bargaining obligations, and internal procedures.
Authorized NJ Data Diva LLC personnel may access audit, session, and security information only where reasonably necessary to:
Curriculum Warehouse does not monitor a user's browsing, communications, device activity, or online activity outside of the Curriculum Warehouse Platform.
Detailed information regarding Platform activity, active session duration, audit records, and their use is provided in the Curriculum Warehouse Privacy Policy.
Curriculum Warehouse uses backup and recovery processes designed to help protect Client curriculum information against accidental deletion, corruption, Platform failure, or other data-loss events.
Backup architecture may include provider-managed cloud backup capabilities and Curriculum Warehouse-controlled backup or recovery processes.
Where technically feasible and appropriate to the circumstances, Curriculum Warehouse may use available backups or recovery mechanisms to restore information following:
Depending upon the nature of the event, recovery may require Provider or developer-level administrative support.
The Platform's Client-separated architecture is designed to support recovery operations that may, where technically feasible, target a particular Client, course, curriculum area, or other limited dataset without intentionally altering unrelated Client data.
Backup and recovery systems reduce the risk of data loss but cannot guarantee that every item of information can be recovered under every circumstance.
Unless expressly stated in a Client-specific agreement, Curriculum Warehouse does not guarantee a specific:
Clients should maintain copies of information they independently require for archival, records-management, or legal-retention purposes.
Curriculum Warehouse incorporates security considerations into Platform development and maintenance.
Security-related development practices may include:
NJ Data Diva LLC may implement security updates, configuration changes, infrastructure improvements, dependency updates, or other technical changes when reasonably necessary to protect the Platform or Clients.
Emergency security changes may be implemented without advance notice when delay could materially increase security or operational risk.
Curriculum Warehouse may conduct internal reviews or use technical tools and qualified external resources to evaluate Platform security.
Unless expressly stated otherwise, Curriculum Warehouse does not represent that NJ Data Diva LLC or Curriculum Warehouse itself currently holds an independent SOC 2 or ISO certification.
Curriculum Warehouse benefits from security and compliance controls maintained by its cloud infrastructure providers.
Google Cloud maintains independent certifications, attestations, and audit programs applicable to portions of its infrastructure and services, including programs such as:
These certifications and attestations apply to Google Cloud and the Google services within their respective audit scopes.
They should not be interpreted as independent certification of NJ Data Diva LLC or Curriculum Warehouse itself.
Additional information regarding Google Cloud security and compliance is available through Google's published security and compliance resources.
If NJ Data Diva LLC discovers or confirms unauthorized access to Client data, Curriculum Warehouse will notify the affected Client without unreasonable delay and in accordance with applicable law.
Where applicable law requires notification immediately following discovery or establishes another notification deadline, that requirement will control. Nothing in this Policy is intended to extend a shorter notification period required by applicable law.
Initial notice may be based on the information reasonably available to Curriculum Warehouse at the time of notification. Additional information may be provided as the investigation develops.
Curriculum Warehouse will make commercially reasonable efforts to:
Curriculum Warehouse will make commercially reasonable efforts to:
Clients should promptly notify Curriculum Warehouse if they become aware of:
NJ Data Diva LLC may temporarily restrict an affected account, user, Client environment, or portion of the Platform when reasonably necessary to prevent:
Where reasonably feasible, restrictions will be limited to the scope and duration reasonably necessary to address the identified risk.
Security is a shared responsibility.
Curriculum Warehouse is responsible for commercially reasonable safeguards within the Platform and Provider-controlled systems.
Clients and Authorized Users remain responsible for the security of systems and configurations outside Curriculum Warehouse's control, including:
Clients may contact NJ Data Diva LLC with reasonable security questions or requests for additional technical information.
Where appropriate, Curriculum Warehouse may provide additional security documentation to authorized Client representatives.
Sensitive information regarding:
will not be publicly disclosed.
Third-party providers may support the operation of Curriculum Warehouse or related business services.
The current Curriculum Warehouse Subprocessors page identifies relevant providers and distinguishes between:
NJ Data Diva LLC may update this Security & Data Protection Policy as Platform architecture, infrastructure, security practices, technology, service providers, or applicable requirements evolve.
Updates will be published within the Curriculum Warehouse Terms & Policies center with a revised “Last Updated” date.
Material changes will not intentionally reduce the overall security protections of the Platform during an active Client term without a legitimate technical, legal, operational, or security reason.
Security questions or suspected security concerns may be directed to:
NJ Data Diva LLC
Curriculum Warehouse
Email: jackie@curriculumwarehouse.com
Website: curriculumwarehouse.com
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.