Processor vs controller boundary
Koydo is a processor under GDPR Article 28 for all learner data processed on behalf of a school or family. Koydo is a controller for: marketing-site analytics on koydo.app, public-facing tutor profiles on /tutors/[slug], and tutor onboarding data.
Article 30 register
Koydo maintains a GDPR Art 30 register of all data processing activities. Available to DPOs on request via trust@koydo.app. Updated within 30 days of any new processing activity.
Sub-processors + SCCs
Koydo's sub-processors are listed at /trust-center/sub-processor-changes. EU-to-US data transfers use the European Commission's Standard Contractual Clauses (2021 module) signed with each sub-processor.
GDPR-K (under-16 protections)
For learners under 16 in the EU (under 13 in some member states with lower age threshold), Koydo applies verifiable parental consent equivalent to COPPA. The same $0.01 credit-card authorization + acknowledgment flow is used.
Data subject rights
Access, rectification, erasure, restriction, portability, objection. All requests routed via privacy@koydo.app or in-app at /parent/data-export. SLA: 30 days to respond, with 60-day extension possible per Art 12.
DPIA support
For high-risk processing (large-scale processing of minor data is one), Koydo provides a DPIA template + reviewed answers for the standard processing activities. The school's DPO completes their own DPIA; Koydo's template answers are pre-filled where they apply uniformly.
EU-EEA representative
Koydo's EU-EEA representative is listed at the bottom of the privacy policy. Direct contact for EU-based DPOs and data subjects who prefer to reach an in-region party.