Legal

FERPA and Student Data Privacy Addendum

Effective Date: October 7, 2026

This FERPA and Student Data Privacy Addendum (“FERPA Addendum”) forms part of the agreement governing the use of Mojo Helpdesk between Metadot Corporation (“Metadot,” “Mojo Helpdesk,” “we,” “us,” or “Provider”) and an educational agency or institution (“Customer”) that is subject to the Family Educational Rights and Privacy Act (“FERPA”), 20 U.S.C. § 1232g and 34 C.F.R. Part 99.

This FERPA Addendum applies when Customer uses Mojo Helpdesk in a manner that involves Provider’s receipt, maintenance, use, or access to personally identifiable information from education records protected by FERPA (“Student Data”).

1. School Official

To the extent Customer relies on FERPA’s school official exception to disclose Student Data to Provider, Provider performs an institutional service or function for which Customer would otherwise use its own employees or other school officials.

Provider will act as a school official with a legitimate educational interest in Student Data solely to the extent necessary to provide, maintain, secure, and support the Services for Customer and as otherwise directed by Customer.

Provider will remain under the direct control of Customer with respect to the use and maintenance of Student Data as required by FERPA.

Customer is responsible for determining that its use of the Services and disclosure of Student Data to Provider complies with FERPA, including determining that Provider satisfies Customer’s criteria for a school official with a legitimate educational interest.

2. Customer Control and Ownership

As between Customer and Provider, Customer retains ownership and control of Student Data.

Customer determines what Student Data is submitted to the Services, which authorized users may access the Services, and how Customer uses the Services.

Provider acquires no ownership interest in Student Data as a result of processing Student Data on Customer’s behalf.

3. Use of Student Data

Provider will use Student Data only for the purposes for which Customer has provided the information and as necessary to provide, maintain, secure, and support the Services for Customer.

Provider will not use Student Data for purposes unrelated to providing the Services to Customer.

Provider will not:

  • sell Student Data;
  • use Student Data for targeted advertising;
  • create commercial profiles of students for purposes unrelated to providing the Services; or
  • use Student Data or other Customer Data to train external artificial intelligence or machine-learning models.

Mojo Helpdesk’s AI functionality operates within the Services. Customer Data processed by AI features remains within the Customer’s helpdesk environment, is not shared across customer instances, and is not used to train external AI models.

4. Disclosure and Redisclosure

Provider will not disclose or redisclose personally identifiable information from education records except:

  • as directed or authorized by Customer;
  • to subprocessors that require access to provide services on Provider’s behalf and that are subject to appropriate confidentiality, privacy, and security obligations;
  • as otherwise permitted under FERPA; or
  • when required by applicable law.

If Provider is legally required to disclose Student Data, Provider will notify Customer before making the disclosure unless applicable law prohibits such notice.

5. Security and Confidentiality

Provider will maintain reasonable administrative, technical, and organizational safeguards designed to protect Student Data against unauthorized access, use, disclosure, alteration, or destruction.

Provider’s security program includes safeguards such as access controls, encryption of Customer Data in transit and, where appropriate, at rest, security monitoring, vulnerability management, and incident-response procedures.

Mojo Helpdesk maintains an independent SOC 2 Type II examination covering the security of the Mojo Helpdesk platform and maintains security controls designed to protect the confidentiality, integrity, and availability of Customer Data.

Personnel authorized to access Customer Data are subject to confidentiality obligations and may access Customer Data only as necessary to perform their responsibilities in connection with providing, supporting, securing, or maintaining the Services.

6. Access to Education Records

Customer is responsible for responding to requests from parents and eligible students to inspect, review, or seek amendment of education records under FERPA.

Upon Customer’s request, Provider will provide reasonable assistance within the functionality of the Services to enable Customer to locate, access, export, correct, or otherwise manage Student Data necessary for Customer to respond to such requests.

Provider will direct requests it receives from parents, students, or eligible students concerning Customer-controlled Student Data to Customer unless otherwise required by applicable law.

7. Subprocessors

Provider may use subprocessors to provide portions of the Services.

Provider will require subprocessors that process Student Data on Provider’s behalf to maintain appropriate confidentiality, privacy, and security protections and to process such data only for purposes necessary to provide their services to Provider.

Provider maintains information regarding its subprocessors as described in its Data Processing Agreement and Security & Compliance documentation.

8. Security Incidents

Provider will maintain incident-response procedures designed to identify, investigate, mitigate, and respond to security incidents involving Customer Data.

If Provider becomes aware of unauthorized access to or disclosure of Student Data that requires notification to Customer under applicable law or the Agreement, Provider will notify Customer without unreasonable delay and provide reasonably available information necessary to assist Customer in evaluating and responding to the incident.

Provider will take reasonable measures to contain and mitigate the effects of a security incident involving Student Data and will reasonably cooperate with Customer in connection with Customer’s response obligations.

9. Retention, Return, and Deletion

Customer may export Customer Data during the subscription term and during any applicable post-termination access period provided by the Services.

Following termination of the Services, Customer Data will remain available for thirty (30) days to allow Customer to export its data. After that period, Provider will securely delete Customer Data in accordance with its data-retention practices unless retention is required by applicable law. Customer may request earlier deletion in writing.

Provider will not retain Student Data longer than necessary to provide the Services or satisfy applicable legal obligations.

10. FERPA Compliance Responsibilities

Provider will process Student Data in accordance with the restrictions applicable to Provider under FERPA when acting as a school official on Customer’s behalf.

Customer remains responsible for its own compliance with FERPA, including:

  • determining whether information submitted to the Services constitutes an education record;
  • determining whether disclosure of Student Data to Provider is permitted under FERPA;
  • establishing the criteria used by Customer to determine who constitutes a school official with a legitimate educational interest;
  • configuring and managing Customer’s authorized users and their access to Student Data; and
  • providing any notices or obtaining any consents required by FERPA.

Nothing in this FERPA Addendum authorizes Provider to determine on Customer’s behalf whether a particular disclosure of an education record is permitted under FERPA.

11. Relationship to Other Agreements

This FERPA Addendum supplements and forms part of the Mojo Helpdesk Terms of Service and, where applicable, the Mojo Helpdesk Data Processing Agreement.

If there is a conflict between this FERPA Addendum and another provision of the Agreement concerning Provider’s processing of Student Data subject to FERPA, this FERPA Addendum will control with respect to that Student Data.

Except as expressly modified by this FERPA Addendum, all other terms of the Agreement remain in effect.

12. Changes to this Addendum

Provider may update this FERPA Addendum to reflect changes in applicable law, the Services, or Provider’s privacy and security practices.

Any material changes will apply prospectively and will not materially reduce the protections applicable to Student Data during Customer’s then-current paid subscription term.

If you have any questions about this FERPA Addendum, please contact us.