FERPA Addendum (Education Customers)
Last updated: June 22, 2026
This FERPA Addendum (the “Addendum”) supplements the agreement between you, an educational institution or agency in the United States (the “Institution,” “you,” or “your”), and Reply Desk, operated by WickScout Finance LLC (“Reply Desk,” “we,” “us,” or “our”), governing your use of the Reply Desk service (the “Service”). It addresses the Family Educational Rights and Privacy Act (“FERPA”), 20 U.S.C. § 1232g, and its implementing regulations at 34 CFR Part 99. This Addendum supplements, and is incorporated into, the Reply Desk Terms of Service and our Data Processing Addendum (the “DPA”). In the event of a conflict regarding student education records, this Addendum controls.
This Addendum does not, by itself, make the Institution or Reply Desk FERPA-compliant. FERPA compliance depends on the Institution designating Reply Desk as a “school official,” maintaining direct control over the relationship, and satisfying its own obligations under FERPA. Reply Desk provides the technical and contractual commitments described here in support of the Institution's compliance program.
1. Applicability
This Addendum applies when an Institution that is subject to FERPA (an “eligible institution” or agency that receives applicable federal funding) uses the Service to receive, store, process, or transmit records that may contain personally identifiable information from students' education records (“Student Data”). For example, this may occur when the Institution operates an IT or campus help desk on Reply Desk and tickets, intake forms, notes, attachments, or notifications contain student information such as names, student identification numbers, contact information, course or enrollment details, or device and account records tied to identifiable students.
This Addendum applies only to the extent the Institution actually places Student Data into the Service. Reply Desk does not direct or require the Institution to submit Student Data, and the Institution remains responsible for deciding what data it routes through the Service.
2. Definitions
- Education Records and Personally Identifiable Information have the meanings given in 34 CFR § 99.3.
- Student Data means personally identifiable information from education records that the Institution submits to or generates within the Service.
- Eligible Student means a student who has reached 18 years of age or attends a postsecondary institution, as defined under FERPA.
- School Official means a party to whom the Institution has outsourced an institutional service or function under 34 CFR § 99.31(a)(1)(i)(B).
2.5 Roles
For purposes of the DPA and applicable data protection law, the Institution is the data controller for Student Data and Reply Desk is a data processor acting only on the Institution's documented instructions. For purposes of FERPA, the Institution is the educational agency or institution that maintains the education records, and Reply Desk acts as a School Official as described in Section 3.
3. Reply Desk as a School Official with a Legitimate Educational Interest
The Institution may, in its discretion, designate Reply Desk as a “school official” with a “legitimate educational interest” in Student Data under FERPA's school official exception, 34 CFR § 99.31(a)(1). To support that designation, Reply Desk acknowledges and agrees that, with respect to Student Data:
- Reply Desk performs an institutional service or function for which the Institution would otherwise use its own employees;
- Reply Desk is under the direct control of the Institution with respect to the use and maintenance of education records, as required by 34 CFR § 99.31(a)(1)(i)(B)(2); and
- Reply Desk is subject to the requirements of 34 CFR § 99.33(a) governing the use and re-disclosure of personally identifiable information from education records, and will use Student Data only for the authorized purposes described in this Addendum.
The Institution is responsible for designating Reply Desk in its annual notification of FERPA rights, for setting its own criteria for what constitutes a legitimate educational interest, and for confirming that providing the Service falls within those criteria.
4. Use Limitation
Reply Desk will access and use Student Data solely to provide, maintain, secure, and support the Service for the Institution, and only on the Institution's documented instructions (which include the Institution's use of the Service's configuration and features). In particular, Reply Desk will not:
- use Student Data to advertise or market to students, parents, or Eligible Students;
- sell, rent, or trade Student Data, or build personal profiles of students except in furtherance of the Institution's authorized use of the Service;
- use Student Data to train generally available machine-learning or artificial-intelligence models for Reply Desk's own purposes; or
- use Student Data for any purpose other than providing the Service to the Institution.
5. No Re-Disclosure
Reply Desk will not disclose Student Data, except as directed or authorized by the Institution, or as required by law. Consistent with 34 CFR § 99.33(a), Reply Desk will not re-disclose Student Data to any third party except:
- on behalf of and at the direction of the Institution;
- to the sub-processors listed in the DPA, who act under written terms that bind them to equivalent confidentiality, use-limitation, and security obligations; or
- as required to comply with a lawful judicial order or legally issued subpoena, in which case, to the extent legally permitted, Reply Desk will provide the Institution with advance notice so the Institution may seek a protective order or otherwise respond.
If Reply Desk receives a request from a parent, Eligible Student, or other third party for access to or disclosure of Student Data, Reply Desk will not respond directly (except to confirm the request should be directed to the Institution) and will refer the requester to the Institution.
6. Directory Information
The Institution is solely responsible for determining what, if any, Student Data constitutes “directory information” under 34 CFR § 99.3, and for honoring any opt-outs from directory-information disclosures. Reply Desk does not designate directory information and will not treat any Student Data as directory information for purposes of disclosure absent the Institution's instruction.
7. Notifications Sent on the Institution's Behalf
Where the Institution configures the Service to send SMS or email notifications (for example, ticket status updates, appointment reminders, or technician arrival messages), those messages are sent on the Institution's behalf and may contain Student Data. The Institution is responsible for ensuring it has any required consent for those communications, including under the Telephone Consumer Protection Act (TCPA) and CAN-SPAM, and for ensuring such notifications are consistent with FERPA and the Institution's own policies. Reply Desk transmits these notifications using the sub-processors identified in the DPA.
8. Data Security
Reply Desk will protect Student Data using the technical and organizational security measures described in the DPA, which are incorporated into this Addendum by reference. These measures include encryption in transit and at rest, access controls and authentication, tenant isolation, logging, and personnel confidentiality obligations. Reply Desk will notify the Institution without undue delay after becoming aware of any unauthorized access to or disclosure of Student Data (a “security incident”) in accordance with the breach-notification provisions of the DPA, so the Institution can meet its own notification obligations.
9. Sub-Processors
Reply Desk uses the sub-processors listed in the DPA to provide the Service, including hosting and database (Railway), authentication (Clerk), payments (Stripe), SMS (Twilio), a transactional email provider, and calendar synchronization (Google or Microsoft, when connected by the Institution). Each sub-processor that may handle Student Data is bound by written terms imposing data-protection obligations no less protective than those in this Addendum and the DPA, and is restricted to using Student Data only to provide its service to Reply Desk. Reply Desk remains responsible to the Institution for the performance of its sub-processors with respect to Student Data.
10. Payments
Where the Institution enables optional invoicing and payments, payments are processed by Stripe through Stripe Connect, and the Institution (or its connected account holder) is the merchant of record. Reply Desk is not a party to the payment transaction and is not a money transmitter, and does not store full payment-card numbers. Cardholder and payment data handled by Stripe is governed by Stripe's Connected Account Agreement. The Institution should not place Student Data into payment fields beyond what is necessary to process a transaction.
11. Rights of Parents and Eligible Students
The Institution, not Reply Desk, is responsible for responding to requests by parents and Eligible Students to inspect, review, amend, or control the disclosure of education records, and for any related complaints. The Service provides the Institution with tools to access, export, correct, and delete Student Data so the Institution can fulfill those obligations. Reply Desk will, on reasonable request and at the Institution's direction, provide reasonable assistance to help the Institution respond to such requests.
12. Return and Deletion of Student Data
Upon termination or expiration of the Institution's subscription, or upon the Institution's earlier written request, Reply Desk will, at the Institution's election, return or delete Student Data in accordance with the data return and deletion provisions of the DPA, except where retention is required by law. During the subscription term, the Institution may export and delete Student Data using the Service's features. Backups containing Student Data are deleted on Reply Desk's ordinary backup-rotation schedule described in the DPA.
13. Relationship to Other Agreements
This Addendum supplements and is incorporated into the DPA and the Reply Desk Terms of Service. Except as expressly modified here, those agreements remain in full force and effect. This Addendum does not expand the scope of the Service or create any obligation for Reply Desk to receive Student Data the Institution does not choose to submit.
14. Governing Law
This Addendum is governed by the laws of the Commonwealth of Pennsylvania, USA, without regard to its conflict-of-laws rules, except to the extent FERPA and other applicable federal law govern.
15. Contact
Questions about this Addendum or about how Reply Desk handles Student Data may be directed to WickScout Finance LLC, Philadelphia, Pennsylvania, USA, at wickscoutio@gmail.com.