Article 28 processor obligations
Per Article 28(3), the processor (Koydo) shall: (a) process personal data only on documented instructions from the controller (the school/customer), (b) ensure persons authorized to process the data are bound by confidentiality, (c) take all measures required pursuant to Article 32 (security), (d) assist the controller with data subject rights requests, (e) assist with data breach notifications under Articles 33-34, (f) delete or return data at contract end, (g) make available all information necessary to demonstrate compliance + allow audits.
Sub-processor authorization
Per Article 28(2) + (4), Koydo lists all sub-processors at /trust-center/sub-processor-changes. Material additions trigger 30-day advance notice to every controller DPO on file. Each sub-processor signs equivalent processor obligations via flow-down. Current sub-processors include Supabase, Stripe, Cloudflare R2, LiveKit, OpenAI, Google Vertex, background-screening provider, Sentry.
Article 32 security measures
Pseudonymization + encryption (AES-256 at rest, TLS 1.3 in transit). Ongoing confidentiality + integrity + availability + resilience. Ability to restore availability after physical or technical incident (backup + DR procedures). Regular testing + evaluation of effectiveness (annual pen-test, quarterly DR drills).
Data subject rights support
Koydo provides controller-facing tools (admin dashboards) for: access requests (export learner data), rectification (update PII), erasure (right to be forgotten — 30-day SLA), restriction (pause processing), portability (machine-readable export), objection (opt out of specific processing). Controllers can handle most data subject requests themselves via the dashboards.
Breach notification flow
Per Article 33, controllers must notify supervisory authorities within 72 hours of becoming aware of a breach. Koydo's commitment: notify controllers within 48 hours of confirmed material breach. Joint timeline: Koydo → 48h notice to controller → controller has 24h to notify supervisor under Article 33.
End-of-contract data handling
Per Article 28(3)(g), at contract termination Koydo deletes or returns all personal data + deletes existing copies (unless EU/Member State law requires retention). Koydo's default: delete (PII purge within 30 days). Return-in-machine-readable-format available on controller request.
EU-to-US transfers + SCCs
When EU personal data is transferred to US-based sub-processors (Supabase us-east-1, OpenAI, etc.), the transfer relies on the European Commission's Standard Contractual Clauses (SCCs, 2021 module 3 — processor-to-sub-processor). Koydo signs SCCs with each US-based sub-processor; controllers receive signed SCC copies on request.