Acceptable Use Policy
Effective Date: April 19, 2026 Last Updated: July 3, 2026
1. Introduction and Scope
This Acceptable Use Policy ("AUP" or "Policy") governs the use of the Edudigital Campus platform and all associated services (collectively, the "Platform") provided by Edudigital AI, Inc. ("Edudigital," "we," "us," or "our"), a company incorporated in the State of Florida, United States.
This Policy applies to all individuals and entities that access or use the Platform, including but not limited to: institutional administrators, faculty members, academic advisors, admissions personnel, financial aid officers, registrars, compliance officers, students, and any other authorized users ("Users"). By accessing or using the Platform, you acknowledge that you have read, understood, and agree to comply with this Policy.
This AUP supplements and is incorporated into the Edudigital Terms of Service and any applicable institutional licensing agreement. In the event of a conflict between this AUP and a specific provision in an institutional licensing agreement, the institutional licensing agreement shall prevail to the extent of the conflict.
Edudigital Campus is designed to serve accredited postsecondary career schools in the United States and private educational institutions in Latin America. The Platform processes student education records that may be protected under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. Section 1232g, and other applicable privacy laws. All Users must conduct themselves in a manner consistent with these legal obligations.
2. Definitions
For the purposes of this Policy, the following terms have the meanings set forth below:
Platform -- The Edudigital Campus software-as-a-service application, including its Student Information System (SIS), Customer/Student Relationship Management (CRM/SRM), Learning Management System (LMS), HUB, and Insights modules, together with all associated APIs, integrations, documentation, and support services.
User -- Any individual who is authorized by an Institution to access the Platform, regardless of role or access level. Users include institutional staff, faculty, administrators, and, where applicable, students.
Institution -- An accredited educational institution that has entered into a licensing agreement with Edudigital to use the Platform. The Institution is the data controller for student education records processed through the Platform.
Student Data -- Any information relating to an identified or identifiable student that is processed through the Platform, including but not limited to enrollment information, academic records, attendance records, financial aid data, and demographic information.
Education Records -- As defined under FERPA (34 CFR Section 99.3), records that are directly related to a student and maintained by an educational agency or institution, or by a party acting for the agency or institution. Education Records processed through the Platform are subject to FERPA protections.
Legitimate Educational Interest -- As defined by the Institution in accordance with FERPA, a User has a legitimate educational interest in a student's Education Record when the User needs to review the record in order to fulfill their professional responsibilities for the Institution.
3. Permitted Use
The Platform is provided exclusively for legitimate educational and institutional management purposes. Permitted uses of the Platform include, but are not limited to:
Educational Institution Management -- Using the Platform to manage day-to-day institutional operations, including campus administration, departmental coordination, and institutional communications.
Student Information Management -- Creating, maintaining, and accessing student records in accordance with FERPA requirements and the Institution's policies, including demographic data, contact information, and enrollment status.
Enrollment and Admissions Management -- Managing prospective student inquiries, applications, admissions decisions, and enrollment workflows through the CRM/SRM and SIS modules.
Academic Records Management -- Recording and maintaining grades, transcripts, attendance records, degree progress, course schedules, and other academic data through the SIS module.
Financial Aid Processing -- Managing Title IV federal financial aid data, institutional aid, scholarships, and related financial information in compliance with U.S. Department of Education requirements and applicable regulations.
Learning Management -- Delivering course content, assignments, assessments, and educational materials through the LMS module; facilitating communication between instructors and students.
Institutional Reporting and Analytics -- Generating reports and analyzing data through the Insights module for purposes of institutional effectiveness, accreditation compliance, regulatory reporting, and data-driven decision-making.
Compliance Management -- Using the Platform to support compliance with applicable laws, regulations, and accreditation standards, including FERPA, Title IV, and state-level requirements.
The Platform may only be used for the legitimate educational purposes described above and as otherwise authorized in the Institution's licensing agreement with Edudigital.
4. User Responsibilities
All Users are responsible for the following:
4.1 Account Security
Users must maintain the security of their account credentials at all times. This includes selecting strong, unique passwords; enabling multi-factor authentication (MFA) when available; and never sharing login credentials with any other person. Each User account is personal and non-transferable. Users are responsible for all activity that occurs under their account.
4.2 Accurate Information
Users must ensure that information they enter into the Platform is accurate, complete, and current to the best of their knowledge. This obligation is particularly important for student education records, financial aid data, and compliance-related information, where inaccuracies may have legal or regulatory consequences.
4.3 Compliance with Applicable Laws
Users must comply with all applicable federal, state, and local laws and regulations when using the Platform, including but not limited to FERPA, Title IV of the Higher Education Act, the Gramm-Leach-Bliley Act (where applicable to financial information), state privacy laws, and any applicable laws of the jurisdictions in which the Institution operates.
4.4 FERPA Training
Users who access student education records through the Platform must complete FERPA training as required by their Institution prior to accessing such records. Users must maintain current knowledge of FERPA requirements and participate in refresher training as required by their Institution. Edudigital may, but is not obligated to, provide FERPA training resources; however, the Institution remains responsible for ensuring its Users are adequately trained.
4.5 Data Minimization
Users must follow the minimum necessary principle when accessing student data. Users should access only the student records and data elements necessary to fulfill their specific professional responsibilities and should not browse, search for, or access records for which they do not have a legitimate educational interest.
5. Prohibited Conduct
The following activities are strictly prohibited when using the Platform. This list is not exhaustive, and Edudigital reserves the right to determine, in its reasonable judgment, whether any conduct violates this Policy.
5.1 General Prohibitions
Users shall not:
Attempt to gain unauthorized access to any portion of the Platform, other Users' accounts, or any systems or networks connected to the Platform.
Reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code of the Platform, except to the extent expressly permitted by the open-source components of the Frappe framework and applicable law.
Circumvent, disable, or otherwise interfere with security features of the Platform, including authentication mechanisms, access controls, encryption, or audit logging.
Introduce viruses, malware, ransomware, trojans, worms, or any other malicious or destructive code or content into the Platform.
Interfere with or disrupt the integrity, performance, or availability of the Platform or the data contained therein.
Use the Platform in any manner that could damage, disable, overburden, or impair any Edudigital server or network.
Impersonate another User, Institution, or any other person or entity, or falsely represent your affiliation with any person or entity.
5.2 Data Handling Prohibitions
Users shall not:
Access, view, or retrieve student education records without a legitimate educational interest as defined by the User's Institution and FERPA.
Share, disclose, or transmit FERPA-protected student data to any individual or entity not authorized to receive such data under FERPA, the Institution's policies, or applicable law.
Use student data for marketing, advertising, profiling, or any commercial purpose unrelated to the educational services provided by the Institution.
Fail to follow the minimum necessary principle when accessing or disclosing student data. Users must limit their access to the specific records and data elements needed to perform their assigned duties.
Download, export, copy, or store student data outside the Platform except as expressly authorized by the Institution and consistent with applicable data protection requirements.
Share login credentials or provide another person with access to student data through the User's account.
Create unauthorized copies or extracts of student data, including screenshots, exports, or printouts, except as necessary for authorized educational or administrative purposes and in compliance with the Institution's policies.
Modify, falsify, or delete student records except as authorized in the performance of legitimate job duties and in accordance with applicable record retention requirements.
5.3 Content Prohibitions
Users shall not use the Platform to create, store, transmit, or display:
Content that is illegal under federal, state, or local law.
Content that is discriminatory, harassing, threatening, abusive, defamatory, or obscene.
Content that violates the intellectual property rights of any third party, including copyrighted material used without authorization.
Unsolicited bulk messages, spam, or other forms of unauthorized mass communications.
Content that violates the Institution's own policies, codes of conduct, or ethical standards.
5.4 System Prohibitions
Users shall not:
Place excessive or unreasonable load on Platform infrastructure, including through automated scripts, bots, scraping tools, or other programmatic means, except as authorized through Edudigital's published APIs and applicable rate limits.
Access or interact with the Platform through automated means without prior written authorization from Edudigital, unless using Edudigital's documented and supported API endpoints.
Modify, alter, or tamper with Platform code, configurations, or infrastructure, except for customizations expressly permitted within the Frappe framework's open-source components and documented by Edudigital.
Use the Platform, its data, or any information derived from the Platform to develop, market, or operate a product or service that competes with Edudigital or the Edudigital Campus platform.
Sublicense, resell, lease, or otherwise provide access to the Platform to any third party without Edudigital's prior written consent.
6. FERPA-Specific Requirements
The Platform processes student education records subject to FERPA. All Users who access Education Records through the Platform must adhere to the following requirements:
Complete FERPA Training. Users must complete FERPA training provided or designated by their Institution before being granted access to student education records. Users must participate in periodic refresher training as required by their Institution.
Legitimate Educational Interest. Users may access student education records only when they have a legitimate educational interest as defined by the Institution's annual FERPA notification and institutional policies. Casual browsing or curiosity-driven access to student records is prohibited.
Institutional FERPA Policies. Users must familiarize themselves with and follow their Institution's FERPA policies, including policies regarding directory information, parental access rights, student consent requirements, and permissible disclosures.
Breach Reporting. Users must immediately report any suspected or actual unauthorized access to, disclosure of, or loss of student education records to their Institution's designated FERPA compliance officer and to Edudigital at security@edudigital.ai. Timely reporting is essential to limit the impact of a breach and to fulfill regulatory notification obligations.
No Unauthorized Disclosure. Users must not share student data with individuals or organizations not authorized to receive it, including but not limited to other students, unauthorized staff members, third-party vendors, or personal contacts. Disclosures to third parties must comply with FERPA's requirements for prior written consent or applicable exceptions.
Re-disclosure Prohibition. When Users receive student data from the Platform for authorized purposes, they must not re-disclose that data to additional parties unless such re-disclosure is independently authorized under FERPA.
Record Retention. Users must comply with their Institution's record retention and destruction policies. Student data that is no longer needed for its authorized purpose should not be retained in personal files, local storage, or email.
7. Security Requirements
All Users must adhere to the following security requirements to protect the Platform, student data, and institutional information:
7.1 Authentication and Passwords
Use strong passwords that meet or exceed the Platform's minimum password requirements (minimum 10 characters, including uppercase letters, lowercase letters, numbers, and special characters).
Do not reuse passwords across multiple services or platforms.
Enable multi-factor authentication (MFA) when available. Institutions may require MFA for all Users accessing student education records.
Change passwords immediately if there is any indication that your credentials may have been compromised.
7.2 Security Incident Reporting
Report any suspected security incident, unauthorized access, data breach, or suspicious activity to your Institution's IT security team and to Edudigital at security@edudigital.ai without delay.
Preserve any evidence related to a suspected incident and do not attempt to investigate or remediate on your own.
Cooperate fully with any investigation conducted by the Institution or Edudigital.
7.3 Physical Security
Follow clean desk and clean screen practices when working with student data. Lock your screen when stepping away from your workstation, and do not leave student records displayed on unattended screens.
Do not access the Platform from public or shared computers unless required by your Institution and only with appropriate security precautions (e.g., using private/incognito browsing, logging out fully when done).
Secure physical devices (laptops, tablets, phones) that are used to access the Platform with device-level passwords, encryption, and remote-wipe capabilities where available.
7.4 Network Security
Exercise caution when accessing the Platform over public or unsecured Wi-Fi networks. Use a VPN or other encrypted connection when possible.
Do not access the Platform through proxy services or anonymization tools that may compromise the integrity of audit logging.
8. Monitoring and Enforcement
Edudigital maintains audit logs of Platform activity, including user logins, data access, modifications to student records, data exports, and administrative actions. These logs are retained in accordance with Edudigital's data retention policies and may be made available to Institutions for compliance, auditing, and investigation purposes.
Edudigital reserves the right to monitor Platform usage to ensure compliance with this Policy, applicable laws, and the terms of institutional licensing agreements. Monitoring activities may include, but are not limited to:
Reviewing audit logs for unusual or unauthorized access patterns.
Tracking data export and download activity.
Identifying attempts to circumvent security controls.
Analyzing system performance to detect abuse or excessive load.
Institutions may also conduct their own monitoring and auditing of their Users' activity on the Platform, in accordance with the Institution's internal policies and applicable law.
9. Violations and Consequences
Violations of this Policy may result in one or more of the following actions, depending on the nature and severity of the violation, at Edudigital's sole discretion:
Written Warning. A formal written notice identifying the violation and requiring corrective action. Warnings are documented and retained.
Temporary Suspension. Temporary suspension of the User's access to the Platform, pending investigation or remediation of the violation.
Permanent Termination. Permanent termination of the User's access to the Platform, with notification to the User's Institution.
Institutional Notification. Notification to the User's Institution, including its designated FERPA compliance officer, IT security team, and/or institutional leadership, as appropriate. Edudigital may share relevant audit logs and investigation findings with the Institution.
Legal Action. Edudigital reserves the right to pursue legal remedies, including injunctive relief and damages, for violations that cause harm to Edudigital, its clients, or the individuals whose data is processed through the Platform.
Regulatory Reporting. In cases involving suspected violations of FERPA, Title IV requirements, or other applicable laws, Edudigital may report the violation to the relevant regulatory authority, including the U.S. Department of Education's Student Privacy Policy Office or the Federal Student Aid office.
Edudigital will cooperate with Institutions in investigating and addressing violations of this Policy. The Institution retains primary responsibility for managing its employees and Users and for determining appropriate disciplinary action under its own policies and applicable employment law.
10. Reporting Violations
If you become aware of any violation of this Policy, or if you suspect that a violation may have occurred, you are required to report it promptly. Reports may be made through the following channels:
Email: security@edudigital.ai
Institutional Channels: Contact your Institution's designated IT security, privacy, or compliance officer.
When reporting a violation, please include as much detail as possible, including:
A description of the suspected violation.
The approximate date and time of the suspected violation.
The identity of the individuals involved, if known.
Any evidence or documentation that supports the report.
Edudigital prohibits retaliation against any User who reports a suspected violation in good faith. Reports will be investigated promptly and confidentially to the extent permitted by law.
11. Updates
Edudigital may update this Policy from time to time to reflect changes in legal requirements, industry best practices, or our Services. When we make material changes, we will update the "Last Updated" date at the top of this Policy and provide notice to Institutions through the Platform or by other appropriate means. Continued use of the Platform after the effective date of any updated Policy constitutes acceptance of the revised terms.
We encourage all Users to review this Policy periodically to stay informed about their obligations when using the Platform.
12. Contact Information
If you have questions about this Acceptable Use Policy, please contact us:
Edudigital AI, Inc. Email: privacy@edudigital.ai Security Reports: security@edudigital.ai Website: https://edudigital.app
For FERPA-related inquiries, you may also contact your Institution's designated FERPA compliance officer. For complaints regarding the handling of student education records, you may contact:
U.S. Department of Education Student Privacy Policy Office 400 Maryland Avenue, SW Washington, DC 20202-8520 Website: https://studentprivacy.ed.gov
This Acceptable Use Policy applies to the Edudigital Campus platform operated by Edudigital AI, Inc., a company incorporated in the State of Florida, United States.

