Legal
Student data addendum
Effective 25 September 2026. Briare Brothers LLC, 30 N Gould St Ste N, Sheridan, WY 82801.
When this applies
This addendum applies whenever you are an educational agency or institution, or a service provider acting for one, and Customer Data includes information about students. It forms part of the terms of service and sits above the data processing addendum: where they conflict about student data, this document wins.
"Student Data" means personally identifiable information about a student, provided to us by you or created by us on your behalf, in any form. It includes photographs of students. It does not include information a student or parent gives directly to a third party unconnected with us, and it does not include data that has been de-identified so that re-identification is not reasonably possible.
No signature is required for this to bind us. If your district requires an executed copy, or its own agreement instead, write to legal@badgewright.com.
FERPA: school official designation
You designate Badgewright as a school official with a legitimate educational interest in Student Data, under 34 CFR 99.31(a)(1)(i)(B). On that basis, and only on that basis, you may disclose education records to us without prior parental consent. We confirm that:
- we perform an institutional service for which you would otherwise use your own employees, namely producing and managing identification cards;
- we are under your direct control with respect to the use and maintenance of education records;
- we use education records only for the purpose for which the disclosure was made;
- we do not redisclose personally identifiable information from education records to anyone, except as you authorise in writing or the law requires;
- we limit access within our organization to those who need it for that purpose.
You remain responsible for the annual FERPA notification to parents and for deciding what is disclosed to us. We will help you answer any question about what we hold.
We understand that a photograph of a student maintained by a school is generally an education record, and we treat every photograph as one.
The school owns the data
All rights in Student Data remain with you, or with the student or parent where the law gives them rights. We acquire no ownership, and no licence beyond what is needed to provide the Service to you.
Student Data is not our asset. It would not transfer as one in an insolvency, a sale or a merger. If the business were ever sold, the buyer would take it subject to this addendum and to your right to have it destroyed, and we would tell you before it happened so you could exercise that right first.
What we may and may not do with it
We use Student Data for one purpose: providing the Service to you, which is holding records, storing photographs, designing cards, printing them, and keeping the history and audit log you asked for. And to answer a support request you make.
We will not, ever:
- use Student Data for targeted advertising, or for any advertising, or disclose it to anyone who would;
- sell, rent, trade or otherwise make Student Data available to a third party for value;
- create a personal profile of a student, other than for the purpose you are using the Service for;
- use Student Data to train, fine-tune or evaluate a machine learning model, or send it to any provider of one;
- use Student Data to develop or improve any product other than the Service we provide to you;
- use Student Data for any commercial purpose of ours;
- disclose Student Data to a law enforcement or immigration authority, other than in response to lawful process served on us, and where that happens we will notify you first unless the law forbids it, so that you can object.
Aggregate, de-identified data may be used to operate and improve the Service only where re-identification is not reasonably possible and the data is never disclosed with a student in it. Given how few records this product holds per school, we do not currently do this at all. Product measurement, described in section 4 of the privacy policy, counts milestones per organization (created, printed a first card, subscribed); it is not derived from Student Data and carries none.
Photographs and biometrics
This is the section most worth reading closely, because "we use face detection" and "we do facial recognition" are entirely different claims and are routinely confused.
When a photograph is taken or uploaded, cropping happens in the browser on the school's own computer, before anything reaches us. If the browser offers face detection, the Service uses it for one purpose: to place the crop rectangle so the face is not off-centre. The detector returns a box with a position and a size; that box is used to compute a rectangle and is then discarded. It never leaves the computer.
What we receive and store is a cropped photograph. We do not:
- extract facial geometry or generate a faceprint, template, embedding or descriptor;
- compare one face with another, match against a gallery, or identify or verify any person;
- store anything derived from a face;
- send photographs to any third party for analysis. No facial recognition service of any kind is used by this product, and none will be added without your written agreement.
Accordingly Badgewright does not collect, capture, store, use, disclose or profit from a biometric identifier or biometric information as the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act or comparable state statutes define them, and holds no biometric record of any student.
The acceptable use policy also forbids you from using the Service, or data taken out of it, to feed a facial recognition system.
Directory information
We do not treat anything as directory information. Whether a student's name or photograph may be disclosed as directory information is your decision under your own FERPA notice, and it changes nothing about how we handle the data: everything is protected as an education record regardless.
The Service is not public-facing. There is no page a student, a parent or a stranger can reach, no public directory, and no shareable link to a record or a photograph.
Children under 13
Badgewright collects nothing from children. Students do not have accounts, do not sign in, and never interact with the Service. Everything about a student is entered by school staff.
Where the Service is used for pupils under 13, you provide consent on behalf of parents, as COPPA permits a school to do for a service used solely for school purposes and for no commercial purpose. We rely on that consent only for those purposes. We will give you, on request, anything you need to describe our practices to a parent, and a parent may, through you, review what is held about their child or have it deleted.
Security
The measures are in Annex B of the data processing addendum, in detail and without aspiration. The ones districts usually ask about first:
- Student Data is stored only in the United States, in one Google Cloud region.
- Two-factor authentication is available to every user on every plan, at no extra cost, and you can require it of everyone. There is no tier where security is an upgrade.
- Each organization's data is isolated by database row-level security, tested by a suite whose only job is to try to cross that boundary.
- Photographs sit in a private bucket with public access prevention enforced. No browser ever reaches the bucket, and no public URL to an image exists.
- Every change, import, export, print and sign-in is in an audit log you can read.
- Staff access is limited to running the service, and any administrative action that could affect your data is delayed, emailed to every owner of your organization in advance, and cancellable by you.
If something goes wrong
We will notify you of a breach of Student Data without unreasonable delay and in any event within 72 hours of discovering it, by email to your organization's owners and to any security contact you have given us.
We will tell you what happened, when, what data and roughly how many students were involved, what we have done, and what you should consider doing. We will:
- co-operate fully with your own investigation and preserve evidence;
- help you meet your notification obligations to parents, to your state education department and to any other authority, and bear the reasonable cost of notification where the breach was our fault;
- not notify parents directly unless you ask us to or the law requires it, because that conversation is yours to have;
- not name you publicly without your consent unless the law requires it.
Our liability for a breach of this addendum is not capped by section 16 of the terms of service. We think a cap on that particular failure would be indefensible to offer a school.
Subcontractors
Every subcontractor that touches Student Data is listed at badgewright.com/legal/subprocessors, is bound in writing to obligations no weaker than these, and is our responsibility to you as though its acts were ours.
We give at least 30 days' notice before adding one and you may object; if we cannot resolve the objection you may terminate and be refunded for what you have not used.
Today one subcontractor stores Student Data, and that is Google Cloud. Neither our payment processor nor our email provider receives any. Our analytics provider measures the public website only and receives nothing whatever from the application.
Parent and student requests
Requests to inspect, correct or delete a student's information go to the school, which is the right place: you hold the relationship, you can verify the requester, and the Service lets you search, correct, export and delete any record yourself without involving us.
If a parent or student contacts us directly, we will not answer substantively. We will tell them to contact you, and tell you they got in touch, promptly. If you need help answering, we will help at no charge, and within 5 business days.
Return and destruction
You may export at any time, on any plan, at no cost: any dataset as a CSV file from within the Service, and a complete export, photographs and card designs included, produced on request to support@badgewright.com.
On termination, we destroy Student Data within 30 days, or sooner on your written request, or later if you tell us in writing that you want longer. This overrides the 90-day window in the general terms: a school should not have to ask for the shorter one.
Destruction means what section 11 of the data processing addendum describes: a complete export offered first, on request, then a scheduled deletion with every owner notified and able to cancel, then a real delete of every record, dataset, template, print job, audit entry and user, and of every photograph in object storage.
Backups are the part most agreements leave vague, so plainly: deleted data remains within our backup window for up to seven days after erasure, because a backup cannot have one school surgically removed from it without corrupting it. Live data is erased within the stated period, backups roll off within seven days after that, and if a backup is ever restored the erasure is re-applied to the restored copy before it serves traffic.
We will give you written certification of destruction on request, naming what was destroyed and when.
Parents bill of rights
New York Education Law 2-d requires a school's contracts to carry a parents bill of rights. It is good practice everywhere, so it is here for every district, not only New York ones.
- Student Data will not be sold or released for any commercial or marketing purpose. It will not be sold at all.
- Parents have the right to inspect and review the complete contents of their child's education record, by asking the school.
- Student Data is protected by safeguards including encryption in transit and at rest, access controls with two-factor authentication, database-enforced isolation between schools, and an audit log. The full list is in Annex B.
- A complete list of every third party with access is published at badgewright.com/legal/subprocessors and kept current.
- Parents may complain about a possible breach of student data to their school district, or to the New York State Education Department's Chief Privacy Officer, or to their own state's education department or attorney general.
- Student Data will be stored in the United States and will be destroyed when it is no longer needed for the purpose it was collected for, and in any event within 30 days of the end of the school's contract.
- Any subcontractor is bound by these same obligations in writing.
- Addressing the exclusive purposes: Student Data is used solely to produce and manage identification cards for the school, and for no other purpose.
- Parents may challenge the accuracy of Student Data through the school, and the school can correct it immediately in the Service without involving us.
Term, changes and survival
This addendum lasts as long as we hold Student Data, which may be after your subscription ends and until destruction is complete.
We may update it to reflect a change in law or in what we do, on at least 30 days' notice to your organization's owners, and never in a way that reduces protection for students. If a change is unacceptable you may terminate and have the unused part of your fees refunded.
Sections 3, 4, 5, 12 and this one survive termination, along with anything else that by its nature should.
What this document does not do
Said here rather than left for your procurement office to discover.
- It is not your state's rider. New York's Education Law 2-d and Illinois's SOPPA, among others, require signed instruments with state-specific content that a published page cannot be. Send us yours, or the Student Data Privacy Consortium's National Data Privacy Agreement with your state's exhibit, and we will sign it. We would rather sign your paper than argue for ours.
- We hold no SOC 2 report and no ISO 27001 certificate. If one is a hard requirement, tell us early so neither of us wastes a procurement cycle. We will complete your security questionnaire in full and answer every question honestly, including the ones where the answer is no.
- We are not a HIPAA business associate and will not sign a business associate agreement. Health information does not belong in a badge database, and the acceptable use policy forbids putting it in one.
- This is not an access control or attendance system and should not be described as one in your procurement documents. It prints cards. What a reader at a door does with the number on the card is your access system's business, not ours.
Questions, redlines, or your own agreement to sign: legal@badgewright.com. Briare Brothers LLC, 30 N Gould St Ste N, Sheridan, WY 82801.
Questions about this document: legal@badgewright.com. Questions about your own data: privacy@badgewright.com. To report a security problem: security@badgewright.com.