logo

Privacy Policy

Effective Date: April 19, 2026 Last Updated: July 3, 2026

Edudigital AI, Inc. ("Edudigital," "we," "us," or "our") is a Florida-incorporated educational technology company that provides the Edudigital Campus platform to accredited postsecondary institutions. This Privacy Policy describes how we collect, use, disclose, retain, and protect Personal Data in connection with our platform and services.


Table of Contents

  1. Introduction and Scope

  2. Definitions

  3. Information We Collect

  4. How We Collect Information

  5. Legal Bases and Purposes for Processing

  6. FERPA Compliance

  7. Student Data and Education Records

  8. CCPA/CPRA Rights for California Residents

  9. Children's Privacy (COPPA)

  10. Cookies and Tracking Technologies

  11. Data Sharing and Disclosure

  12. International Data Transfers

  13. Data Retention

  14. Data Security

  15. AI and Automated Processing

  16. Your Rights

  17. Data Protection Contact / How to Exercise Rights

  18. Changes to This Privacy Policy

  19. Contact Information

  20. Governing Law


1. Introduction and Scope

1.1 This Privacy Policy applies to all products and services offered by Edudigital AI, Inc. through the Edudigital Campus platform (available at edudigital.app), including the integrated Student Information System (SIS), Customer/Student Relationship Management (CRM/SRM), Learning Management System (LMS), HUB, and Insights modules.

1.2 This Policy applies to the following categories of individuals:

(a) Institutional Clients — accredited postsecondary career schools and private institutions that contract with Edudigital for use of the Platform;

(b) End Users — administrators, faculty, staff, and other authorized personnel of Institutional Clients who access the Platform;

(c) Students — individuals whose Education Records and Personal Data are processed through the Platform on behalf of Institutional Clients;

(d) Website Visitors — individuals who visit edudigital.app or related marketing sites.

1.3 When Edudigital processes Student Data and Education Records, we do so as a service provider acting on behalf of and under the direction of the Institution. The Institution remains the data controller and is responsible for compliance with applicable privacy and education laws, including the Family Educational Rights and Privacy Act (FERPA). Our obligations with respect to Education Records are governed by our contractual agreements with each Institution.

1.4 This Privacy Policy applies to data processing activities in both the United States and Latin America, including but not limited to operations in Venezuela, Colombia, and El Salvador.


2. Definitions

2.1 "Personal Data" means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identified or identifiable natural person or household.

2.2 "Education Records" has the meaning ascribed to it under FERPA (20 U.S.C. Section 1232g; 34 CFR Part 99), and means records that are directly related to a Student and maintained by an educational agency or institution or by a party acting for the agency or institution.

2.3 "Student Data" means Personal Data and Education Records relating to Students that are processed through the Platform on behalf of an Institution, including but not limited to enrollment records, academic transcripts, attendance data, financial aid information, and related identifiers.

2.4 "Institution" or "Client" means an accredited postsecondary educational institution that has entered into a service agreement with Edudigital for use of the Platform.

2.5 "Platform" means the Edudigital Campus software-as-a-service platform, including all modules (SIS, CRM/SRM, LMS, HUB, Insights), APIs, mobile applications, and related services.

2.6 "End User" means any individual authorized by an Institution to access and use the Platform, including institutional administrators, faculty, admissions personnel, financial aid officers, registrars, and other staff.

2.7 "Directory Information" has the meaning ascribed to it under FERPA and means information contained in an Education Record of a Student that would not generally be considered harmful or an invasion of privacy if disclosed, as designated by the Institution in accordance with 34 CFR Section 99.3.

2.8 "Sub-processor" means a third-party entity engaged by Edudigital to process Personal Data or Student Data on behalf of Edudigital in connection with the provision of the Platform.

2.9 "Title IV Data" means information collected, maintained, or processed in connection with federal student financial aid programs administered under Title IV of the Higher Education Act of 1965, as amended.

2.10 "Digi AI" means the artificial intelligence assistant feature integrated into the Platform.


3. Information We Collect

We collect and process the following categories of information:

3.1 Account and Identity Information

Information necessary to create and maintain End User accounts on the Platform, including: full name, email address, job title, role and permissions, institutional affiliation, login credentials (stored in hashed form), profile photographs (if provided), and multi-factor authentication identifiers.

3.2 Student Education Records

Education Records processed on behalf of Institutions, including but not limited to:

(a) Enrollment and Admissions Data — applications, enrollment status, program of study, start and expected graduation dates, enrollment agreements, prior education history, and admission decisions;

(b) Academic Records — grades, transcripts, course registrations, credit hours attempted and earned, GPA, academic standing, satisfactory academic progress (SAP) determinations, attendance records, and certificates or diplomas awarded;

(c) Demographic Information — date of birth, gender, ethnicity, citizenship status, primary language, and contact information (address, phone number, email);

(d) Student Identifiers — student identification numbers, Social Security Numbers (where required for federal reporting), and other institutional identifiers.

3.3 Financial Aid and Title IV Data

Information related to federal and state student financial aid, including: FAFSA data, Expected Family Contribution (EFC) or Student Aid Index (SAI), award letters, loan and grant disbursement records, satisfactory academic progress for financial aid purposes, Return of Title IV (R2T4) calculations, enrollment verification for the National Student Loan Data System (NSLDS), Veteran Affairs education benefit information, and institutional payment plans.

3.4 Usage and Activity Data

Information generated through End User and Student interaction with the Platform, including: login timestamps and session duration, features accessed, pages viewed, actions performed within the Platform, LMS course engagement data (assignment submissions, quiz attempts, forum participation, content access logs), and search queries within the Platform.

3.5 Device and Technical Data

Technical information collected automatically, including: IP addresses, browser type and version, operating system, device type, screen resolution, referring URLs, and unique device identifiers.

3.6 Cookies and Similar Technologies

Information collected through cookies, web beacons, and similar tracking technologies as further described in Section 10 and our Cookie Policy.

3.7 Communication Data

Records of communications between End Users and Edudigital, including: support ticket content, email correspondence, in-platform messaging, and records of telephone or video calls with Edudigital personnel.

3.8 Business Contact Information

For prospective and current Institutional Clients: names, titles, professional email addresses, phone numbers, institutional addresses, and publicly available business information.


4. How We Collect Information

4.1 Information Provided Directly by Institutions

The primary source of Student Data and Education Records is the Institution itself. Institutions provide this data through:

(a) initial data migration during Platform onboarding; (b) ongoing data entry by authorized End Users; (c) bulk data imports via the Platform's import tools; (d) API integrations with the Institution's existing systems.

4.2 Information Collected Automatically

We collect Device and Technical Data, Usage Data, and Cookie data automatically when End Users or Students access the Platform or visit our websites.

4.3 Information from Third-Party Sources

We may receive information from the following third-party sources:

(a) Federal and State Agencies — data received via Institution-authorized integrations with the U.S. Department of Education systems, state regulatory bodies, or accrediting agencies (ACCSC, ACCET, DEAC, ACEN, or others);

(b) Single Sign-On Providers — authentication data when End Users or Students log in via institutional SSO or Google Workspace;

(c) Business Data Providers — professional contact information for business development purposes only (never Student Data);

(d) Communication Platforms — delivery status and engagement data from SMS, WhatsApp, and email communications sent through the Platform.


5.1 Contractual Necessity. We process Personal Data of End Users and Institutional Clients as necessary to perform our contractual obligations under our service agreements, including providing access to the Platform, delivering technical support, and maintaining the services.

5.2 Compliance with Legal Obligations. We process certain data to comply with applicable laws, including FERPA, Title IV regulations, state education licensing requirements, accreditation standards, and tax and financial reporting requirements.

5.3 Legitimate Interests. We process certain data based on our legitimate business interests, including: improving and securing the Platform, detecting and preventing fraud or unauthorized access, conducting analytics to enhance service quality, and communicating with Institutional Clients about service updates. Where we rely on legitimate interests, we balance these interests against the privacy rights of individuals.

5.4 Consent. Where required by applicable law, we obtain consent before processing Personal Data, including for: marketing communications to prospective clients, the use of non-essential cookies, and certain cross-border data transfers.

5.5 Processing on Behalf of Institutions. When processing Student Data and Education Records, Edudigital acts as a service provider under the direction of the Institution. The Institution is responsible for establishing the legal basis for processing under applicable law, including providing required notices to Students and obtaining any necessary consents.


6. FERPA Compliance

This section describes Edudigital's obligations and practices with respect to Education Records protected under the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g; 34 CFR Part 99).

6.1 School Official Designation

6.1.1 Edudigital operates as a "school official" with a "legitimate educational interest" as those terms are used in FERPA and its implementing regulations (34 CFR Section 99.31(a)(1)). This designation is established through written agreements with each Institution that specify:

(a) Edudigital performs an institutional service or function for which the Institution would otherwise use its own employees;

(b) Edudigital is under the direct control of the Institution with respect to the use and maintenance of Education Records;

(c) Edudigital is subject to the requirements of 34 CFR Section 99.33(a) governing the use and re-disclosure of personally identifiable information from Education Records;

(d) Edudigital's access to Education Records is limited to that which is necessary to fulfill its contractual obligations to the Institution.

6.2 Education Records Handling

6.2.1 Edudigital will not use or disclose Education Records for any purpose other than those specified in our agreement with the Institution.

6.2.2 Edudigital will not use Education Records for marketing, advertising, or any commercial purpose unrelated to the provision of Platform services to the Institution.

6.2.3 Edudigital will not re-disclose personally identifiable information from Education Records to any third party except as authorized by the Institution or as permitted under FERPA.

6.2.4 Upon request by the Institution, Edudigital will provide access to Education Records to the Student or parent (as applicable) to the extent required by FERPA.

6.3 Directory Information

6.3.1 Edudigital does not independently designate any Student information as Directory Information. The designation of Directory Information, and any decisions regarding its disclosure, remain the sole responsibility of the Institution in accordance with 34 CFR Section 99.37.

6.3.2 Edudigital will process Directory Information in accordance with the Institution's written policies as communicated to Edudigital.

6.4 Parental Rights and Eligible Student Rights

6.4.1 FERPA provides parents of students under 18 enrolled in elementary or secondary programs, and eligible students (those 18 or older, or attending a postsecondary institution), with the right to:

(a) inspect and review the Student's Education Records;

(b) request amendment of Education Records the parent or eligible Student believes are inaccurate, misleading, or in violation of the Student's privacy rights;

(c) consent to the disclosure of personally identifiable information from Education Records, except as otherwise authorized by FERPA.

6.4.2 Because the Platform serves postsecondary institutions, in most cases FERPA rights belong to the eligible Student. The Institution is responsible for managing the exercise of these rights; Edudigital provides technical support to facilitate such requests through the Platform.

6.5 Legitimate Educational Interest

6.5.1 Edudigital's access to Education Records is strictly limited to the legitimate educational interest of providing and maintaining the Platform and related services as contracted by the Institution. This includes:

(a) hosting, storing, and securing Education Records within the Platform;

(b) enabling the Institution's authorized End Users to create, access, modify, and manage Education Records;

(c) generating reports, analytics, and compliance documentation as directed by the Institution;

(d) providing technical support and troubleshooting;

(e) performing data migration, backup, and disaster recovery services.

6.6 Annual Notification

6.6.1 FERPA requires Institutions to provide annual notification to parents or eligible Students of their FERPA rights, including notice that the Institution discloses Education Records to school officials with legitimate educational interests.

6.6.2 Edudigital recommends that Institutions include Edudigital AI, Inc. (or reference to SaaS/technology service providers generally) in their annual FERPA notification. Edudigital can provide template language to Institutions upon request.


7. Student Data and Education Records

7.1 Ownership

7.1.1 Student Data and Education Records are and remain the property of the Institution. Edudigital does not claim ownership of any Student Data or Education Records processed through the Platform.

7.2 Use Restrictions

7.2.1 Edudigital will process Student Data solely for the purpose of providing and improving the Platform services as directed by the Institution, and for no other purpose.

7.2.2 Edudigital will not sell Student Data. Edudigital will not use Student Data for targeted advertising. Edudigital will not create marketing profiles of Students.

7.2.3 Aggregated, de-identified data that cannot reasonably be used to identify any individual Student may be used by Edudigital for product improvement, benchmarking, and research purposes, provided that such de-identification is performed in accordance with applicable law and that re-identification is prohibited.

7.3 Data Return and Deletion

7.3.1 Upon termination or expiration of a service agreement, Edudigital will, at the Institution's election, return all Student Data in a standard, machine-readable format or securely delete it, in accordance with the terms of the service agreement and Section 13 of this Policy.

7.4 Institutional Responsibility

7.4.1 Institutions are responsible for: (a) determining what Student Data is entered into the Platform; (b) ensuring the accuracy and lawfulness of data entered; (c) providing required privacy notices to Students; (d) obtaining any consents required under applicable law; and (e) responding to Student requests regarding their personal data, with Edudigital's technical assistance as needed.


8. CCPA/CPRA Rights for California Residents

This section applies to California residents whose Personal Data is processed by Edudigital in a capacity where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"), applies. Note: Student Data processed on behalf of Institutions pursuant to FERPA may be exempt from certain CCPA requirements under Cal. Civ. Code Section 1798.145(q).

8.1 Categories of Personal Information Collected

In the preceding 12 months, Edudigital has collected the following categories of Personal Information as defined by the CCPA:

  • Identifiers — Examples: name, email, IP address, account identifiers. Collected: Yes.

  • Personal information under Cal. Civ. Code Section 1798.80(e) — Examples: name, address, telephone number, education, employment. Collected: Yes.

  • Protected classification characteristics — Examples: age, gender, ethnicity (as provided by Institutions). Collected: Yes.

  • Internet or other electronic network activity — Examples: browsing history, Platform usage data. Collected: Yes.

  • Geolocation data — Examples: approximate location derived from IP address. Collected: Yes.

  • Professional or employment-related information — Examples: job title, institutional role. Collected: Yes.

  • Non-public education information (per 20 U.S.C. Section 1232g) — Examples: education records. Collected: Yes.

  • Inferences drawn from Personal Information — Examples: user preferences, usage patterns. Collected: Yes.

8.2 No Sale or Sharing of Personal Information

Edudigital does not sell Personal Information as defined by the CCPA. Edudigital does not share Personal Information for cross-context behavioral advertising purposes.

8.3 Rights of California Residents

Subject to applicable exceptions and limitations, California residents have the following rights:

(a) Right to Know — the right to request that we disclose the categories and specific pieces of Personal Information we have collected, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share Personal Information;

(b) Right to Delete — the right to request deletion of Personal Information we have collected, subject to certain exceptions;

(c) Right to Correct — the right to request correction of inaccurate Personal Information;

(d) Right to Opt-Out of Sale or Sharing — although Edudigital does not sell or share Personal Information, California residents may submit an opt-out request, and we will honor it;

(e) Right to Limit Use of Sensitive Personal Information — the right to limit the use and disclosure of sensitive Personal Information to purposes authorized by the CCPA;

(f) Right to Non-Discrimination — Edudigital will not discriminate against any individual for exercising their CCPA rights.

8.4 Submitting Requests

California residents may submit CCPA requests by contacting us at privacy@edudigital.ai. We will verify the requestor's identity before fulfilling any request and will respond within 45 days, or 90 days if an extension is necessary (with notice to the requestor).


9. Children's Privacy (COPPA)

9.1 The Edudigital Campus platform is designed for use by accredited postsecondary educational institutions. The Platform is not directed at children under the age of 13, and Edudigital does not knowingly collect Personal Data directly from children under 13.

9.2 To the extent an Institution provides data relating to individuals under the age of 13 to the Platform, the Institution is solely responsible for ensuring compliance with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. Sections 6501-6506, and for obtaining any required verifiable parental consent prior to the collection or submission of such data.

9.3 If Edudigital becomes aware that it has received Personal Data of a child under 13 without appropriate authorization, we will promptly take steps to delete such data and notify the Institution.


10. Cookies and Tracking Technologies

10.1 The Platform and our websites use cookies and similar tracking technologies to facilitate authentication, maintain session state, analyze usage patterns, and improve the user experience.

10.2 We use the following categories of cookies:

(a) Strictly Necessary Cookies — required for the Platform to function, including authentication, security, and session management cookies;

(b) Functional Cookies — used to remember End User preferences and settings;

(c) Analytics Cookies — used to understand how the Platform and websites are used, including page views, feature engagement, and error tracking;

(d) Marketing Cookies — used on our public-facing websites (not within the Platform when processing Student Data) for marketing attribution and campaign measurement.

10.3 End Users and website visitors can manage their cookie preferences through their browser settings or through the cookie preference tools available on our websites. Disabling certain cookies may affect Platform functionality.

10.4 For detailed information about the specific cookies we use, their purposes, and their retention periods, please refer to our Cookie Policy available at edudigital.app/cookie-policy.


11. Data Sharing and Disclosure

11.1 General Principles

Edudigital does not sell Personal Data or Student Data. We share data only as described in this section, and only to the extent necessary for the stated purposes.

11.2 Sharing with Institutions

Education Records and Student Data are accessible to authorized End Users of the Institution that provided or generated such data. Institutions control access through role-based permissions configured within the Platform.

11.3 Sub-processors

Edudigital engages the following categories of Sub-processors to provide and support the Platform. Each Sub-processor is bound by contractual obligations to protect Personal Data and is subject to appropriate security and privacy requirements:

  • Frappe Technologies Pvt. Ltd. (Frappe Cloud) — Purpose: Platform hosting, infrastructure, database management. Data processed: all Platform data. Certifications: SOC 2 Type II, ISO 27001.

  • Google LLC — Purpose: Workspace (email, calendar, document collaboration), analytics. Data processed: End User communications, usage analytics. Certifications: SOC 2, ISO 27001, GDPR compliant.

  • Twilio Inc. — Purpose: SMS, WhatsApp, and email communications. Data processed: recipient contact information, message content. Certifications: SOC 2 Type II, ISO 27001.

  • Stripe, Inc. — Purpose: payment processing. Data processed: payment card data, billing information. Certifications: PCI DSS Level 1, SOC 2.

  • Zapier, Inc. — Purpose: workflow automation and integrations. Data processed: varies by Institution-configured workflows. Certifications: SOC 2 Type II.

  • Apollo.io — Purpose: CRM enrichment for business development. Data processed: business contact information only; never Student Data. Certifications: SOC 2 Type II.

11.3.1 The current list of Sub-processors is maintained at edudigital.app/sub-processors. Institutions will be notified of changes to our Sub-processor list at least thirty (30) days prior to engaging a new Sub-processor that processes Student Data.

Edudigital may disclose Personal Data when required by law, regulation, subpoena, court order, or governmental request. Where permitted by law, we will provide the Institution with prior notice of such disclosure. Disclosures of Education Records will be made in compliance with FERPA requirements.

11.5 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of all or a portion of Edudigital's assets, Personal Data may be transferred as part of the transaction. We will notify Institutions of any such transfer and ensure that the receiving entity is bound by obligations consistent with this Privacy Policy. Education Records will continue to be subject to FERPA requirements following any such transfer.

We may disclose Personal Data with the consent of the individual to whom the data pertains, or at the direction of the Institution.


12. International Data Transfers

12.1 Data Processing Locations

The Platform is hosted on Frappe Cloud infrastructure with primary data processing in the United States. Certain data processing activities may occur in other jurisdictions where our Sub-processors maintain facilities.

12.2 US-LATAM Transfers

Edudigital serves Institutional Clients in the United States and Latin America, including Venezuela, Colombia, and El Salvador. Personal Data of Students and End Users at LATAM Institutions may be transferred to and processed in the United States for the purpose of providing Platform services.

12.3 Transfer Safeguards

Where Personal Data is transferred across international borders, Edudigital implements appropriate safeguards, including:

(a) Standard Contractual Clauses (SCCs) — where required by applicable data protection law, Edudigital enters into SCCs approved by the relevant regulatory authority;

(b) Data Processing Agreements — all cross-border data processing is governed by written agreements that include obligations regarding data security, use restrictions, and incident notification;

(c) Data Localization Options — upon request and subject to technical feasibility, Edudigital can offer data residency configurations that restrict the storage of certain data to specific geographic regions.

12.4 LATAM Data Protection Compliance

Edudigital is committed to complying with applicable data protection laws in the jurisdictions where it operates, including but not limited to the Ley Organica de Proteccion de Datos Personales (Venezuela), Ley 1581 de 2012 (Colombia), and applicable data protection frameworks in El Salvador. Institutions operating under specific local data protection requirements should contact us to discuss additional safeguards or data processing addenda.


13. Data Retention

13.1 Retention Periods

Edudigital retains Personal Data for the following periods:

  • Student Education Records — Duration of the service agreement, plus 60 days for data return/deletion, unless the Institution requests extended retention.

  • Financial Aid / Title IV Data — Duration of the service agreement, plus the period required by applicable federal regulations (typically 3 years following the end of the award year).

  • End User Account Data — Duration of the service agreement, plus 30 days.

  • Usage and Activity Logs — 24 months from collection, unless required for security investigations.

  • Support and Communication Records — 36 months from resolution.

  • Website Analytics Data — 26 months from collection.

  • Business Contact Data (prospective clients) — Until opt-out or 36 months from last interaction, whichever is sooner.

  • Backup copies — 90 days following deletion from production systems.

13.2 Post-Termination

Upon termination or expiration of a service agreement, Edudigital will:

(a) provide the Institution with an opportunity to export all of its data in a standard, machine-readable format within sixty (60) days;

(b) upon the Institution's written confirmation or upon expiration of the export period, securely delete all Student Data and Education Records from production systems within thirty (30) days;

(c) delete backup copies containing the Institution's data within ninety (90) days of production deletion.

Notwithstanding the foregoing, Edudigital may retain data as required by applicable law, regulation, legal proceeding, or governmental investigation.


14. Data Security

14.1 Encryption

(a) Data at Rest — all data stored within the Platform is encrypted using AES-256 encryption or equivalent;

(b) Data in Transit — all data transmitted between End Users and the Platform, and between Platform components, is encrypted using TLS 1.2 or higher.

14.2 Access Controls

(a) Edudigital enforces role-based access controls for all internal personnel, limiting access to Personal Data to those employees and contractors who require access to perform their job functions;

(b) The Platform provides Institutions with granular role-based access controls to manage End User permissions;

(c) Multi-factor authentication is supported and recommended for all End User accounts;

(d) All access to production systems is logged and auditable.

14.3 Infrastructure Security

The Platform is hosted on Frappe Cloud, which maintains SOC 2 Type II and ISO 27001 certifications. Security measures include:

(a) network segmentation and firewalls;

(b) intrusion detection and prevention systems;

(c) regular vulnerability assessments and penetration testing;

(d) automated patching and update management;

(e) geographic redundancy and disaster recovery capabilities.

14.4 Organizational Measures

(a) All Edudigital personnel with access to Personal Data are subject to confidentiality obligations;

(b) Edudigital conducts regular security awareness training for all personnel;

(c) Background checks are conducted for personnel with access to Student Data and Education Records, to the extent permitted by applicable law.

14.5 Incident Response

14.5.1 Edudigital maintains a documented security incident response plan. In the event of a security incident involving unauthorized access to, or unauthorized disclosure of, Student Data or Education Records:

(a) Edudigital will notify the affected Institution without unreasonable delay, and in no event later than seventy-two (72) hours after becoming aware of the incident;

(b) Edudigital will provide the Institution with sufficient information to enable the Institution to fulfill its own notification obligations under FERPA, state breach notification laws, and other applicable regulations;

(c) Edudigital will cooperate with the Institution in investigating and remediating the incident;

(d) Edudigital will document the incident and provide a post-incident report to the Institution.


15. AI and Automated Processing

15.1 Digi AI Assistant

15.1.1 The Edudigital Campus platform includes Digi AI, an artificial intelligence assistant designed to support End Users with tasks such as data analysis, report generation, compliance checking, communication drafting, and workflow recommendations.

15.1.2 Digi AI processes data within the Platform to generate responses and recommendations. This may include processing Student Data and Education Records to the extent necessary to respond to authorized End User queries and instructions.

15.2 Data Used for AI Features

15.2.1 Digi AI operates within the boundaries of the Institution's own data. It does not access data belonging to other Institutions.

15.2.2 Edudigital does not use Student Data or Education Records to train general-purpose AI models. AI processing is performed solely to provide real-time responses and functionality within the Platform on behalf of the Institution.

15.2.3 Aggregated, de-identified usage patterns may be used to improve AI feature performance, provided that such data cannot reasonably be used to identify any individual Student.

15.3.1 Digi AI does not make automated decisions that produce legal effects or similarly significant effects on Students without meaningful human review. All consequential decisions — including but not limited to admissions decisions, financial aid determinations, academic standing assessments, and disciplinary actions — require review and approval by authorized institutional personnel.

15.3.2 AI-generated recommendations, predictions, or scores are presented to End Users as decision-support tools and are not binding.

15.4 Opt-Out

15.4.1 Institutions may disable Digi AI features for their Platform instance by contacting Edudigital. Individual AI feature toggles are available within the Platform's administrative settings.

15.5 Transparency

15.5.1 When Digi AI generates content or recommendations, the output is clearly identified as AI-generated within the Platform interface.


16. Your Rights

16.1 Rights for Students (via Institutions)

Because Edudigital processes Student Data as a service provider on behalf of Institutions, Students should direct requests regarding their Education Records and Personal Data to their Institution. Edudigital will cooperate with Institutions in fulfilling such requests. Students generally have the right to:

(a) access and inspect their Education Records (under FERPA);

(b) request amendment of inaccurate Education Records (under FERPA);

(c) consent to or restrict disclosures of Education Records (under FERPA, subject to exceptions);

(d) file a complaint with the U.S. Department of Education (FERPA);

(e) exercise rights under applicable state laws, including CCPA rights as described in Section 8.

16.2 Rights for End Users

End Users may exercise the following rights by contacting Edudigital at privacy@edudigital.ai:

(a) access the Personal Data we process about them;

(b) request correction of inaccurate Personal Data;

(c) request deletion of Personal Data, subject to our data retention obligations;

(d) object to or restrict certain processing of their Personal Data;

(e) request data portability where technically feasible;

(f) withdraw consent where processing is based on consent.

16.3 Rights for LATAM Data Subjects

Individuals whose data is processed in connection with LATAM operations may have additional rights under local data protection laws, including the rights of access, rectification, cancellation, opposition, and where applicable, the right to revoke consent. Requests may be submitted to privacy@edudigital.ai.

16.4 Verification

Edudigital will verify the identity of any individual submitting a rights request before fulfilling the request. For requests related to Student Data, Edudigital will coordinate verification with the applicable Institution.


17. Data Protection Contact / How to Exercise Rights

17.1 Edudigital has designated a Data Protection Contact to oversee compliance with this Privacy Policy and applicable data protection laws. All privacy-related inquiries, data subject requests, and complaints should be directed to:

Data Protection Contact Edudigital AI, Inc. Email: privacy@edudigital.ai

17.2 We will acknowledge receipt of all requests within five (5) business days and will provide a substantive response within the timeframes required by applicable law (typically 30 to 45 days, depending on jurisdiction and the nature of the request).

17.3 Institutions with questions about the processing of Student Data should contact their designated Edudigital account representative or email privacy@edudigital.ai.


18. Changes to This Privacy Policy

18.1 Edudigital reserves the right to modify this Privacy Policy at any time. We will notify Institutional Clients of material changes by:

(a) posting the updated Privacy Policy on edudigital.app with a revised "Last Updated" date;

(b) sending written notice to the primary contact on file for each Institutional Client at least thirty (30) days before the changes take effect;

(c) for changes that affect the handling of Student Data or Education Records, providing Institutions with a summary of the changes and a reasonable opportunity to object or terminate their service agreement.

18.2 Continued use of the Platform after the effective date of a revised Privacy Policy constitutes acceptance of the revised terms.

18.3 Prior versions of this Privacy Policy will be archived and made available upon request.


19. Contact Information

For questions, concerns, or requests related to this Privacy Policy:

Edudigital AI, Inc. Website: edudigital.app Privacy Inquiries: privacy@edudigital.ai

For FERPA complaints, Students and parents may also contact:

Family Policy Compliance Office U.S. Department of Education 400 Maryland Avenue, SW Washington, D.C. 20202-8520 Website: studentprivacy.ed.gov


20. Governing Law

20.1 This Privacy Policy, and any disputes arising from or related to it, shall be governed by and construed in accordance with the laws of the State of Florida, United States of America, without regard to its conflict of law provisions.

20.2 For Institutional Clients located outside the United States, the governing law and dispute resolution provisions set forth in the applicable service agreement shall control to the extent they conflict with this section.

20.3 Nothing in this Privacy Policy limits any rights that may be available under mandatory applicable data protection laws, including FERPA, the CCPA, and applicable LATAM data protection legislation.


Edudigital AI, Inc. recommends that all Institutional Clients review this Policy with their own legal advisors.

Edudigital AI, Inc. is a BBB Accredited Business and a member of the Florida Association of Postsecondary Schools and Colleges (FAPSC). Edudigital is a Google Partner.


Copyright 2026 Edudigital AI, Inc. All rights reserved.

Campus Operations, Unified

Get practical insights on compliance, enrollment, and student success for career-focused institutions.