Back to Home

RepLogix FERPA & COPPA Compliance Statement

Effective Date: July 6, 2026

This statement outlines how RepLogix addresses compliance with the Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Act (COPPA) when used by schools, districts, and educational organizations. This document is provided to support school district procurement reviews and is intended to be read alongside our Privacy Policy, Information Sharing Policy, Data Retention Policy, and Terms of Service.

1. FERPA — Family Educational Rights and Privacy Act

FERPA (20 U.S.C. § 1232g; 34 CFR Part 99) is a federal law that protects the privacy of student education records. The law applies to all schools that receive funds under an applicable program of the U.S. Department of Education.

1.1 School Official Exception

When a school or district uses RepLogix to manage student-athlete information — including rosters, attendance records, performance metrics, and development notes — RepLogix functions as a "school official" under FERPA's school official exception (34 CFR § 99.31(a)(1)). RepLogix meets the criteria for this exception:

  • Legitimate Educational Interest: RepLogix performs services for the school or district that would otherwise be performed by school employees (tracking athletic attendance and performance)
  • Direct Control: The school or district directly controls the data entered into RepLogix and may access, export, or delete it at any time
  • Use Limitation: RepLogix uses student data only for the purpose of providing and improving the Service for the school — not for any other purpose
  • Re-identification Prohibition: RepLogix does not re-identify or attempt to re-identify de-identified student data

1.2 Types of Student Data That May Be in RepLogix

Depending on how a school or district configures RepLogix, the following types of student information may be entered by authorized coaches or staff:

  • Student-athlete names and jersey numbers
  • Grade level, sport, position, and group/category assignments
  • Attendance and check-in/check-out records
  • Performance metrics (strength, speed, agility, jump data)
  • Development notes and coach-entered observations
  • Event and testing date records

RepLogix does not require Social Security numbers, home addresses, medical records, academic grades, disciplinary records, or immigration status. Schools should not enter such data into RepLogix.

1.3 Parent and Eligible Student Rights

Under FERPA, parents and eligible students have the right to:

  • Inspect and review education records maintained by the school, including records in RepLogix
  • Request that the school amend inaccurate or misleading education records
  • Consent to disclosures of personally identifiable information, except as permitted by FERPA

Because RepLogix operates as a school official on behalf of the school, requests to inspect, amend, or delete student data should be directed to the school or district, which controls the data. RepLogix will assist schools in fulfilling such requests within 30 days of a written request from the school.

1.4 Data Sharing Agreements

RepLogix will sign a Data Processing Agreement (DPA) with schools and districts that require one for FERPA compliance. The DPA will address:

  • The scope and purpose of data processing
  • Security obligations and breach notification timelines
  • Data return and deletion obligations upon contract termination
  • Prohibition on using student data for advertising or commercial purposes
  • Subcontractor disclosure and flow-down obligations

2. COPPA — Children's Online Privacy Protection Act

COPPA (15 U.S.C. §§ 6501–6506; 16 CFR Part 312) is a federal law that imposes requirements on operators of websites or online services directed to children under 13, or operators with actual knowledge that they collect personal information from children under 13.

2.1 RepLogix Is Not Directed to Children Under 13

RepLogix is a professional coaching and athletic management platform intended for use by authorized adult coaches, athletic directors, school staff, and organizational administrators. RepLogix is not directed to children under 13, and children under 13 may not create their own RepLogix accounts.

2.2 School-Provided Accounts and COPPA

When a school or district provides RepLogix accounts to students (if applicable), COPPA provides that operators may collect personal information directly from students with the school's consent, provided the operator follows specific requirements under 16 CFR § 312.5(c):

  • The school provides consent on behalf of the student in its role as the student's agent
  • RepLogix provides the school with the information needed to make an informed consent decision
  • RepLogix does not use student data for behavioral advertising, profiling, or any purpose beyond the educational context
  • RepLogix does not condition a student's participation in an activity on the disclosure of more personal information than is reasonably necessary
  • RepLogix provides parents with the right to review the student's personal information and delete or refuse further collection

2.3 Data Minimization for Students Under 13

If RepLogix is used in a context where students under 13 may be included in rosters or team data, RepLogix applies data minimization principles:

  • Only the minimum information needed for athletic tracking is collected (name, jersey number, sport, attendance, performance data)
  • No Social Security numbers, home addresses, or medical information are collected
  • Student data is not used for targeted advertising or commercial profiling
  • Student data is deleted upon the school's or district's request or upon contract termination

2.4 Direct Contact from Children

If RepLogix becomes aware that it has collected personal information directly from a child under 13 without school or parental consent, RepLogix will take reasonable steps to delete that information and terminate the collection.

3. State Student Data Privacy Laws

Several states have enacted student data privacy laws that may apply when RepLogix is used by schools or districts in those jurisdictions. RepLogix is designed to support compliance with these laws, including but not limited to:

  • SOPIPA (California Student Online Personal Information Protection Act) — prohibits use of student data for targeted advertising or profiling
  • Colorado HB 16-1383 — Student Data Transparency and Security Act
  • New York Education Law § 2-d — Data Privacy and Security
  • Texas HB 3834 / SB 820 — Cybersecurity training and data security requirements for schools

RepLogix will review and sign state-specific addenda or DPAs as required during procurement. Contact us for state-specific compliance documentation.

4. Security and Safeguards

RepLogix protects student and user data through the following safeguards:

  • Encryption in transit: All data is encrypted using TLS/HTTPS
  • Encryption at rest: Data is encrypted at rest by our infrastructure provider (Base44, SOC 2 Type II and ISO 27001 certified)
  • Access controls: Role-based access; only authorized users within an organization can access that organization's data
  • U.S. data residency: All servers are located in the United States
  • PCI DSS payment security: Payments processed by Stripe; RepLogix does not store full credit card numbers

See our Privacy Policy for full security details.

5. Breach Notification

In the event of a data breach involving student personally identifiable information, RepLogix will:

  • Follow documented incident response procedures to contain and investigate the breach
  • Notify the affected school or district without unreasonable delay, and in no case later than 72 hours after confirming the breach
  • Provide details of the breach, the data involved, and the corrective actions taken
  • Cooperate with the school or district in fulfilling any notification obligations to parents or eligible students as required by FERPA or state law

6. Data Return and Deletion

Upon termination of a school or district contract, RepLogix will:

  • Provide the school or district with an export of all student data in a commonly used electronic format (CSV) upon request
  • Delete all student data within 30 days of contract termination, unless a longer retention period is required by the DPA or law
  • Confirm deletion in writing to the school or district
  • Ensure residual data in encrypted backups is overwritten within the backup retention window described in our Data Retention Policy

7. Audits and Certifications

RepLogix's infrastructure provider, Base44, maintains SOC 2 Type II and ISO 27001 certifications. Upon request and subject to confidentiality obligations, RepLogix may provide schools and districts with:

  • SOC 2 Type II report summaries from Base44
  • ISO 27001 certification evidence
  • Summary of security controls and data handling practices

Direct on-site audits are generally not offered, but RepLogix will cooperate with reasonable due diligence requests during procurement.

8. Contact for Compliance Questions

For FERPA, COPPA, or student data privacy questions, or to request a DPA, contact:

9. Changes to This Statement

We may update this FERPA & COPPA Compliance Statement from time to time to reflect changes in law, regulation, or platform practices. Schools and districts under an active DPA will be notified of material changes. Your continued use of RepLogix after the updated statement becomes effective means you accept the updated statement.