What SOPIPA prohibits
Online services covered by SOPIPA cannot: (1) use covered information to engage in targeted advertising to students, (2) sell covered information, (3) disclose covered information except in narrow circumstances (e.g., legal compliance, ensuring continued service, deidentified research). Koydo's terms comply with all three prohibitions absolutely.
Covered information scope
Per SOPIPA's definition: information that is descriptive of a student or otherwise identifies a student. Includes: name, address, phone, email, social security number, photo, biometric data, geolocation, online identifiers, parents' information, education records, food purchase history, performance evaluations, special needs information, juvenile records.
What Koydo doesn't do
We don't sell student data. We don't run targeted advertising to students (we don't run advertising at all). We don't disclose to third parties for advertising purposes. We don't allow third-party analytics (Google Analytics, etc.) on signed-in K-12 student surfaces. We honor SOPIPA in practice, not just in writing.
Data security under SOPIPA §22584(d)
SOPIPA requires reasonable security procedures. Koydo's security baseline (encryption at rest + transit, MFA, row-level access-control policies, audit logging, annual pen-test) exceeds reasonable; matches the higher standards in NY §2-d + EU GDPR.
Deletion under SOPIPA §22584(d)(2)
Per SOPIPA, covered information must be deleted on request from the school. Koydo's standard process: school requests deletion → PII purge initiated within 7 days → completes within 30 days → confirmation sent to school.
How CA schools engage
CA K-12 school contracts use the standard CA School Boards Association DPA template + Koydo's SOPIPA addendum. Many CA districts use the California Student Privacy Alliance (CSPA) standard contract, which Koydo also signs. Review cycle typically 3-6 weeks at district level.