Last Updated: July 14, 2026
This Student Data Privacy Addendum (“Addendum”) applies if Customer is a school, school district, college, university, or other educational institution (or an entity acting on behalf of such an institution) and HatchLink will process Student Data on Customer’s behalf through the HatchLink platform (the “Service”). This Addendum is incorporated into and supplements the HatchLink Master Terms (the “Agreement”). Capitalized terms not defined here have the meanings given in the Agreement.
1. Definitions
“Student Data” means personally identifiable information from education records, as defined under FERPA (20 U.S.C. § 1232g and 34 C.F.R. Part 99), that HatchLink receives or generates on behalf of Customer through the Service.
“FERPA” means the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g) and its implementing regulations at 34 C.F.R. Part 99.
“COPPA” means the Children’s Online Privacy Protection Act (15 U.S.C. §§ 6501–6506) and its implementing regulations at 16 C.F.R. Part 312.
2. FERPA — School Official Designation
Customer designates HatchLink as a “school official” with a “legitimate educational interest” in Student Data under 34 C.F.R. § 99.31(a)(1)(i)(B). In this capacity, HatchLink will:
- Perform services that Customer would otherwise use its own employees to perform;
- Remain under Customer’s direct control with respect to the use and maintenance of Student Data;
- Use Student Data only for the purposes for which the disclosure was made; and
- Not redisclose Student Data to third parties except as permitted by FERPA, this Addendum, or as expressly directed by Customer in writing.
3. Ownership and Control of Student Data
As between the parties, Customer (or the parent or eligible student, as applicable) owns and controls all Student Data. HatchLink acquires no ownership, licensing, or commercial rights in Student Data beyond what is strictly necessary to provide the Service in accordance with the Agreement and this Addendum.
4. Permitted Uses
HatchLink will use Student Data only to:
- Provide, maintain, support, secure, and improve the Service for Customer;
- Respond to Customer or authorized user requests;
- Comply with legal obligations; and
- Generate de-identified or aggregated data that cannot reasonably identify any individual student, which may be used to improve the Service, conduct benchmarking, and support product research.
5. Prohibited Uses
HatchLink will not:
- Sell, rent, trade, or otherwise commercialize Student Data;
- Use Student Data for targeted advertising directed to students, parents, or their families;
- Use Student Data to create or contribute to personal profiles of students for any purpose other than supporting authorized educational, health, or school administration purposes as defined by the Agreement;
- Disclose Student Data to third parties except to subprocessors bound by written obligations at least as protective as this Addendum, or as required by law (with notice to Customer where legally permitted); or
- Use Student Data to inform, train, or improve artificial intelligence or machine learning models in a manner that could expose individually identifiable Student Data outside the Service, unless the data has been de-identified in accordance with applicable law.
6. COPPA Compliance
Where the Service is used with students under the age of 13:
- Customer authorizes HatchLink to collect personal information from such students solely for the use and benefit of the educational institution, and not for any other commercial purpose, in reliance on the school authorization mechanism described in the FTC’s COPPA guidance and 16 C.F.R. § 312.5(c)(4).
- Customer represents that it has obtained, or will obtain, any required parental consents before allowing students under 13 to use the Service, or that Customer is relying on the COPPA school consent exception and has a reasonable basis for doing so under its own policies and applicable law.
- HatchLink will, on Customer’s written request, provide a description of the types of personal information collected from students under 13, and an opportunity for Customer (or, through Customer, a parent) to review and request deletion of such information.
- HatchLink will not condition a student’s participation in any activity on the disclosure of more personal information than is reasonably necessary to participate in that activity.
7. Intersection of FERPA, HIPAA, and COPPA
HatchLink’s school health platform may process data elements that are subject to overlapping regulatory frameworks. The following principles govern when Student Data also qualifies as Protected Health Information or is subject to COPPA:
- Student health records maintained by the school. Health records maintained by a school nurse or school health program that are part of the student’s education record are governed by FERPA (not HIPAA) under the FERPA/HIPAA exception at 45 C.F.R. § 160.103. This Addendum applies to such records.
- Health records created by a HIPAA-covered healthcare provider. Where the Service facilitates telehealth or clinical services provided by a HIPAA-covered entity (such as a hospital system or healthcare provider), PHI created or maintained by that provider is governed by the Business Associate Agreement, which controls in the event of conflict with this Addendum with respect to such PHI.
- Students under 13. Where Student Data is subject to both FERPA and COPPA, HatchLink will comply with the more protective requirement. COPPA’s consent and disclosure restrictions apply in addition to FERPA’s protections for such students.
- Conflict resolution. If a specific data element is subject to multiple frameworks, the most restrictive applicable requirement governs HatchLink’s use, disclosure, and protection of that data element. Customer may designate the applicable framework for a data set in the Activation Form or by written notice.
8. Security
HatchLink will maintain administrative, physical, and technical safeguards designed to protect Student Data from unauthorized access, use, disclosure, alteration, or destruction, consistent with the security obligations in the Master Terms and the Security Overview. HatchLink’s safeguards are designed to meet or exceed the requirements of applicable state student data privacy laws.
9. Data Breach Notification
HatchLink will notify Customer in writing of any unauthorized acquisition, access, use, or disclosure of Student Data without unreasonable delay, and in no case later than forty-eight (48) hours after HatchLink’s confirmation of the incident (or such shorter period as required by applicable state law). The notification will include:
- The nature of the incident and the types of Student Data involved;
- The students reasonably believed to be affected;
- A description of HatchLink’s investigation, mitigation, and prevention measures; and
- A designated contact for follow-up communications.
HatchLink will reasonably cooperate with Customer’s investigation and notification obligations under applicable state and federal law.
10. Parental and Eligible Student Rights
HatchLink will support Customer’s obligations under FERPA to provide parents and eligible students with the ability to:
- Inspect and review Student Data maintained in the Service;
- Request correction of inaccurate Student Data; and
- Request deletion of Student Data (where required by applicable law).
HatchLink will provide the requested information or functionality within a reasonable time (and in no event more than thirty (30) days) after Customer’s written request.
11. Return or Destruction
On termination of the Agreement, or earlier on Customer’s written request, HatchLink will:
- Return or make available for export all Student Data in its possession within forty-five (45) days;
- After the export period, securely destroy all Student Data, including copies held by subprocessors, except as required to be retained by law; and
- Certify destruction in writing on Customer’s request.
Backup copies will age out of retention in the ordinary course, during which time they remain protected under this Addendum.
12. Subprocessors
HatchLink may engage subprocessors to assist in providing the Service. A current list is maintained at hatchlinkhealth.com/subprocessors. HatchLink remains responsible for subprocessor compliance with the obligations of this Addendum and binds each subprocessor to written agreements at least as protective as this Addendum with respect to Student Data.
13. State Student Privacy Laws
To the extent applicable, HatchLink will comply with state student data privacy laws in the jurisdictions where Customer operates, including (where relevant):
- Texas Student Privacy Alliance (TxSPA) commitments;
- New York Education Law § 2-d and its implementing regulations;
- California Student Online Personal Information Protection Act (SOPIPA);
- Connecticut Public Act 16-189;
- Colorado Student Data Transparency and Security Act; and
- Similar state statutes as applicable to Customer’s jurisdiction.
If Customer’s state requires execution of a specific data privacy agreement form (e.g., the National Data Privacy Agreement (NDPA) or a state-specific addendum), the parties will execute it as a supplement to this Addendum. In the event of conflict between a state-specific agreement and this Addendum, the more protective provision with respect to Student Data will govern.
14. Transparency
HatchLink will, on reasonable request, provide Customer with:
- A description of the types of Student Data collected and processed through the Service;
- The purposes for which Student Data is used;
- A description of the safeguards in place to protect Student Data; and
- Information about any subprocessors with access to Student Data.
15. Order of Precedence
In the event of a conflict between this Addendum and the Master Terms with respect to the use, disclosure, or protection of Student Data, this Addendum controls. Where Student Data also constitutes Protected Health Information governed by the Business Associate Agreement, the parties will apply the more protective requirement with respect to the overlapping data elements.
16. Governing Law and Dispute Resolution
This Addendum is governed by the laws of the State of Texas, without regard to its conflict-of-laws principles. Any dispute arising out of or relating to this Addendum that is not resolved through good-faith negotiation will be brought exclusively in the state or federal courts located in Travis County, Texas, and each party consents to the personal jurisdiction and venue of such courts.