FERPA Statement
Last updated: 2026-04-28
Summary
NILifi is operated by MW Creative LLC. When NILifi is delivered through an educational institution — a school, district, college, or athletic department — student activity records held by NILifi may be considered “education records” under the Family Educational Rights and Privacy Act of 1974 (FERPA), 20 U.S.C. § 1232g.
This statement explains how we operate to align with FERPA and the obligations we accept toward institutions and students.
School official designation
For institution-licensed deployments, NILifi operates as a school official with a legitimate educational interest under 34 C.F.R. § 99.31(a)(1)(i)(B). Specifically:
- The institution outsources a function it would otherwise perform — financial-literacy education for student athletes.
- NILifi is under the direct control of the institution with respect to use and maintenance of education records.
- NILifi is subject to the requirements of 34 C.F.R. § 99.33(a) governing the use and redisclosure of personally identifiable information from education records.
What we collect, on the institution’s behalf
For institution-licensed accounts, NILifi may hold:
- Student directory-style data — name, email, school, sport, position, graduation year.
- Course activity records — lessons completed, quiz responses and scores, time spent, certificate issuance.
- Audit logs — actions taken in the application (sign-in, lesson completion, content publish events), IP address, user-agent.
We do not collect Social Security numbers, payment information, biometric data, or substance-use / health information from students.
What we will not do
- We do not sell, rent, or share student data with third parties for any purpose other than delivering the service.
- We do not use student data for advertising or to train third-party AI / large language models.
- We do not redisclose education records except as authorized by FERPA, the institution, or the eligible student / parent.
- We do not retain student data past the institution’s retention requirements without written direction.
Subprocessors
NILifi uses a small set of subprocessors (e.g., cloud hosting, email delivery) to operate the platform. Each is bound by a Data Processing Agreement and a defined scope of access. The complete list and locations are published at /legal/subprocessors. We notify institutions of changes per our agreement.
Parent and student rights
Eligible students (18+ or in postsecondary enrollment) and parents of students under 18 may exercise the rights afforded by FERPA, including:
- Inspect and review education records held by NILifi via the in-app data export endpoint, or by request through the institution.
- Seek amendment of records the student or parent believes to be inaccurate, misleading, or in violation of privacy rights.
- Consent, where required, to disclosures of personally identifiable information from education records.
- File a complaint with the U.S. Department of Education concerning alleged failures to comply with FERPA.
Requests are routed through the institution that licensed NILifi for its students, except where the institution has designated NILifi to receive requests directly.
Data deletion and retention
- We delete student data within 30 days of a written request from the student, parent, or institution, subject to legal-hold exceptions.
- Audit-log records are retained as required by SOC 2 and institution policy. We can document the retention window during contracting.
- Backup retention follows our backup rotation schedule, after which deletion is final. We do not restore deleted data from backup absent legal compulsion.
- On termination of an institution’s license, we return or destroy education records per the institution’s direction within 90 days.
Security
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based access scoped to institutions; staff access logged.
- Append-only audit log for every meaningful action.
- SOC 2 Trust Services Criteria controls implemented; Type II report targeted by end of 2026. Plan available under NDA.
- Incident response and breach notification per the Data Processing Agreement, including timelines that meet FERPA expectations.
Institutional addenda
NILifi accepts standard institutional FERPA addenda and student data privacy agreements (including the SDPC NDPA). Send your template alongside the contracting paperwork and we’ll work through redlines with our counsel.
Contact
FERPA-specific questions or notices: privacy@mw-creative.com. General institutional questions can also reach us through our Privacy Policy contact.