Back to Compliance

RepLogix Student Data Privacy Addendum

Effective Date: August 8, 2026

This Student Data Privacy Addendum ("Addendum") supplements the RepLogix Terms of Service and is incorporated by reference into any agreement between RepLogix and a school, district, or educational institution ("School"). It addresses the treatment of student data in compliance with FERPA, COPPA, and applicable state student data privacy laws.

1. Definitions

  • "Student Data" means data provided by or on behalf of the School through the RepLogix Service that is tied to or identifiable to a student, including athlete names, attendance records, performance data, and related information.
  • "School" means the educational institution, district, or organization that uses RepLogix under an active subscription.
  • "Operator" means RepLogix.
  • "Authorized Users" means School personnel authorized to access the Service, including coaches, administrators, and athletic staff.

2. FERPA Compliance

RepLogix acknowledges that Student Data may constitute "education records" under FERPA. RepLogix acts as a "school official" with legitimate educational interests when processing Student Data on behalf of the School. RepLogix:

  • Uses Student Data only for the purpose for which it was provided — to provide and support the Service
  • Does not use Student Data for any commercial purpose, including targeted advertising
  • Does not sell Student Data
  • Protects Student Data using reasonable administrative, technical, and physical safeguards
  • Discloses Student Data to third parties only as permitted by FERPA or as directed by the School

3. COPPA Compliance

RepLogix is not directed to children under 13 and does not knowingly collect personal information directly from children under 13. If the School enters data about students under 13, the School represents that it has obtained any required parental consent. RepLogix:

  • Collects only the minimum data necessary to provide the Service
  • Does not use Student Data for behavioral advertising
  • Provides the School with the ability to review and delete Student Data
  • Maintains the confidentiality and security of Student Data

4. Permitted Uses of Student Data

RepLogix may use Student Data only to:

  • Provide, maintain, and support the Service
  • Generate reports and analytics for the School's use
  • Improve the Service's functionality and performance
  • Comply with legal obligations
  • Protect the security and integrity of the Service

RepLogix does not use Student Data to develop commercial products or services unrelated to the Service provided to the School.

5. Prohibited Uses

RepLogix agrees that it will NOT:

  • Sell, rent, or share Student Data for commercial purposes
  • Use Student Data for targeted advertising
  • Use Student Data to amass a profile about a student for non-educational purposes
  • Disclose Student Data to third parties for their commercial use, except as necessary to provide the Service
  • Use Student Data for any purpose not authorized by the School

6. Data Security

RepLogix implements and maintains reasonable security measures to protect Student Data, including:

  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access controls and least-privilege access
  • Multi-factor authentication for privileged accounts
  • Regular security monitoring and logging
  • Incident response procedures (see Incident Response Plan)

7. Data Deletion and Return

Upon the School's request or termination of the subscription:

  • RepLogix will delete or return all Student Data within 30 days of written request
  • RepLogix will provide written confirmation of deletion
  • Residual data in encrypted backups will be overwritten within the backup retention window
  • RepLogix will not retain Student Data after termination except as required by law

8. Subprocessors

RepLogix uses subprocessors to deliver the Service. A current list of subprocessors is available upon request. RepLogix:

  • Maintains written agreements with subprocessors requiring equivalent data protection
  • Remains liable for subprocessor compliance with this Addendum
  • Notifies the School of any new subprocessor that will have access to Student Data

9. Breach Notification

In the event of a confirmed breach of Student Data:

  • RepLogix will notify the School without unreasonable delay, and in no case later than 72 hours after confirmation
  • Notification will include the nature of the breach, data affected, and remediation steps
  • RepLogix will cooperate with the School's investigation and regulatory notification obligations

10. School Responsibilities

The School acknowledges responsibility for:

  • Obtaining any required parental consent for students under 13
  • Ensuring Authorized Users comply with this Addendum
  • Providing accurate and lawful data to the Service
  • Managing access permissions for its Authorized Users

11. Compliance with State Laws

RepLogix agrees to comply with applicable state student data privacy laws, including but not limited to SOPIPA (California), student data privacy laws in Colorado, New York, and other states where the School operates. Where state law imposes stricter requirements than this Addendum, those requirements apply.

12. Contact

For questions about this Addendum or to request a signed copy, contact: