What this DPA covers
GDPR Article 28 obligations (Koydo as processor, you as controller). FERPA-aligned 'school official' designation when contracted with a US school. COPPA verifiable parental consent flow documentation. DSGVO + KJSG baseline for German schools. Standard contractual clauses (SCCs) for any US-to-EU data transfer.
What's in scope
All learner data processed by Koydo on your behalf: roster, lesson recordings (when enabled), homework submissions, gradebook entries, attendance, parent-tutor messages, engagement events. Aggregate de-identified metrics also covered.
What's out of scope
Tutor personal data (tutors are independent contractors, not your employees). Marketing analytics on koydo.app (your students never see marketing pages signed in). Public-facing tutor profiles on /tutors/[slug] (tutor-controlled).
Sub-processors
Koydo's sub-processor list is published at /trust-center/sub-processor-changes and updated within 30 days of any addition. Material additions trigger an email to your data protection officer at minimum 30 days before deployment.
Breach notification
Koydo notifies you within 48 hours of confirmed material breach, with the full timeline + scope + remediation status. Status updates every 24 hours until resolved. Post-mortem within 5 business days.
Retention
Per Koydo's retention policy at /trust-center/retention-policy. Lesson recordings 90 days; gradebook + attendance full school year + 90; aggregate de-identified 7 years; PII purged on contract termination + 30 days.
How to execute
Email trust@koydo.app with your organization name and signing party. We countersign within one business day and return the executed copy. Most procurement reviewers complete review inside one week.