Overview

Why Is FERPA Important to Alohi?

The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law that protects education records maintained by educational agencies and institutions receiving funding under applicable U.S. Department of Education programs.

Schools, districts, and universities may use fax and electronic signature services for transcripts, enrollment documents, financial aid records, and other documents containing student information. These workflows require careful control over access, use, and disclosure.

Alohi’s internal FERPA assessment focuses on the safeguards and contractual arrangements needed to support these workflows. Institutions remain responsible for establishing a permitted basis for disclosure and ensuring that their use of a service meets FERPA’s requirements.

This page is provided for general informational purposes and does not constitute legal advice. Institutions should consult their own counsel to confirm FERPA compliance for their specific use case.

Data

How Does Alohi Help Protect Education Records?

Protecting education records requires both security controls and clear rules for handling student information. Our approach addresses the technical safeguards available in Fax.Plus and Sign.Plus and the requirements institutions should resolve before sharing FERPA-covered records.

‍

Institutional Control & Authorized Use

Under FERPA’s school official exception, an outsourced provider must remain under the institution’s direct control regarding the use and maintenance of education records. The institution must also ensure that the provider meets the exception’s other conditions, including its criteria for a school official with a legitimate educational interest.

‍

Student Data Agreements

Alohi offers a FERPA Addendum as the contractual approach for education customers. This agreement should define the covered services, permitted uses, institutional control, and data protection responsibilities. Contact our team to confirm the applicable terms and onboarding requirements before sharing education records.

‍

Data Encryption & Secure Connections

Stored faxed and signed documents are encrypted using AES-256. TLS protects connections between Alohi’s applications or APIs and our servers. Institutions should also review recipient systems, email delivery, and external integrations when assessing the complete path of a student document.

‍

Authentication & Access Management

Account authentication and available administrative controls help institutions manage who can use the service. Enterprise controls for Fax.Plus and Sign.Plus include account access logging and user blocking. Institutions should limit access to authorized staff and promptly update permissions when responsibilities change.

‍

Document Activity & Accountability

Fax.Plus maintains fax transmission records, and Sign.Plus provides document activity records associated with signature workflows. These records can support operational reviews and investigations. Institutions should confirm that the available records, export options, and retention settings meet their specific oversight requirements.

‍

Purpose Limitation & Third Parties

FERPA restricts the use and redisclosure of student information disclosed under the school official exception. Education agreements should address permitted processing and obligations for downstream providers. Alohi’s public Privacy Policy states that customer data is not used to train generalized AI or machine learning models; any additional education-specific restrictions should be addressed in the applicable agreement.

‍

Retention, Return & Deletion

The institution and provider should establish how long education records are retained, how they can be returned, and how deletion requests will be handled. Alohi's FERPA addendum addresses these provisions, including arrangements for the end of the service relationship.

‍

Incident Response & Institutional Cooperation

Alohi’s security practices include monitoring, security assessments, and incident response. Education agreements should define how suspected or confirmed unauthorized access is reported to the institution and how investigations are supported. Applicable notification timelines and cooperation requirements should be confirmed in the agreement and assessed against relevant state laws.

‍

Before using Fax.Plus or Sign.Plus for FERPA-covered records:

‍

  • Confirm the institution’s permitted basis for disclosing student information.
  • Review the applicable education agreement and covered services with our team.
  • Configure access for staff with an authorized educational purpose.
  • Assess connected services and optional features before including them in student-data workflows.
  • Agree on record retention, return, deletion, and incident response responsibilities.