How BoodleBox handles student data (FERPA overview)

Goal

Understand how BoodleBox protects student data and how it complies with FERPA.

Official statement on BoodleBox's status as a school official under FERPA

BoodleBox qualifies as a "school official" under the Family Educational Rights and Privacy Act (FERPA) when properly designated by educational institutions through appropriate contractual agreements. As a technology service provider to educational institutions, we maintain strict compliance with FERPA regulations governing the privacy and security of student education records.

Our Qualification as a School Official

BoodleBox meets the requirements for designation as a school official with legitimate educational interests through:

  1. Contractual Designation: Our service agreements with educational institutions explicitly establish BoodleBox as a school official with legitimate educational interests in accessing specific student data necessary to perform contracted services.
  2. Direct Institutional Control: We only access student records that are explicitly shared with us by authorized institutional users, maintaining the educational institution's direct control over all student data.
  3. Limited Data Access: Our access to student information is strictly limited to data necessary to fulfill specific educational functions as defined in our service agreements.
  4. Educational Purpose: BoodleBox provides services that serve legitimate educational functions, including collaborative learning environments, AI-assisted educational tools, and knowledge management capabilities that enhance educational outcomes.

Our FERPA Compliance Commitments

As a school official under FERPA, BoodleBox commits to:

  1. Use Limitation: We use student data solely for the purposes specified in our agreements with educational institutions and not for any commercial purpose outside these agreements.
  2. Redisclosure Prevention: We do not disclose student information to third parties except as permitted by FERPA and authorized by our agreements with educational institutions.
  3. Data Security: We implement comprehensive technical, administrative, and physical safeguards to protect the security, confidentiality, and integrity of student records.
  4. Data Retention: We maintain clear data retention policies that limit the storage of student information to periods necessary to fulfill our contractual obligations.
  5. Compliance Documentation: We maintain records of our FERPA compliance measures and make these available to educational institutions as needed.

Implementation Requirements

For educational institutions to properly designate BoodleBox as a school official:

  1. The institution must enter into our standard service agreement which includes FERPA compliance provisions.
  2. The institution should document BoodleBox's designation as a school official in its FERPA policies.
  3. The institution maintains responsibility for determining what student data is appropriate to share with BoodleBox based on legitimate educational needs.

BoodleBox is committed to maintaining the trust of educational institutions and protecting the privacy of student data in full compliance with FERPA and other applicable privacy regulations.

How your data is protected

  • Prompts are anonymized before they reach any AI model.
  • Files are encrypted at rest and in transit, and are only used when explicitly attached.
  • AI providers are contractually prohibited from training on BoodleBox data.
  • Data minimization — only what's necessary is stored.
  • US-based data centers, with multi-tenant logical isolation per customer.
  • Prompts sent to AI providers are not retained by them beyond 30 days (see Understanding data retention policies).

Certifications

BoodleBox maintains FERPA, SOC 2 Type II, HIPAA, GDPR, HECVAT 4.0, VPAT (WCAG), and TX-RAMP. Reports and attestations are available through the Trust Center: https://trust.boodlebox.ai/ (most are self-serve; some are available on request).

Questions or documentation requests?

For compliance documentation, start at the Trust Center: https://trust.boodlebox.ai/. For anything your legal or security team needs that isn't there, email compliance@boodle.ai. General questions: success@boodle.ai.

Contact us

Didn’t find what you need?

Send us a note and the team will get back to you — typical response within 8 business hours.

PNG, JPG, GIF, WEBP or PDF. Up to 310 MB each.