SDPC National Data Privacy Agreement
ThinkKits LLC supports the principles of the Student Data Privacy Consortium (SDPC) National Data Privacy Agreement v2.1. ThinkKits does not collect, store, or process student personally identifiable information (PII) and is not subject to FERPA. Our platform processes only publicly available federal education data and serves adult education professionals, administrators, and vendors.
What is the SDPC National DPA?
The Student Data Privacy Consortium (SDPC) National Data Privacy Agreement is a standardized data privacy agreement developed in collaboration with education stakeholders, legal experts, and privacy advocates. It establishes comprehensive protections for student data used by education technology vendors.
Our Commitment
Although ThinkKits does not handle student PII, we commit to:
- Processing only publicly available, aggregate school-level data
- Never collecting, storing, or processing student personally identifiable information
- Not selling or disclosing any user data
- Providing transparent data practices and collection notices
- Maintaining robust security controls for all platform data
- Deleting user account data upon request or account closure
- Operating in alignment with FERPA, COPPA, and applicable state privacy law principles
Key Protections
Data Security
No Data Mining
No Sale of Data
Data Deletion
No Student PII
Adult Users Only
Data Collection Transparency
ThinkKits maintains complete transparency about what data we collect, how we use it, and how long we retain it. ThinkKits does not collect, store, or process student personally identifiable information (PII).
| Data Category | Collection Method | Purpose | Retention Period | Status |
|---|---|---|---|---|
| Public School Data | NCES CCD, CRDC, USAC E-Rate | Education intelligence and analysis | Updated annually with federal releases | Public Data |
| User Account Data | Clerk auth (signup) | User identification and access control | Active account + 30 days after closure | Compliant |
| Usage Analytics | Platform Interaction Logs | Service improvement and support | 2 years (anonymized after 90 days) | Compliant |
| Technical Data | Automatic System Collection | Security and system operation | 90 days | Exceeds |
For detailed information about our data collection practices, see our Data Collection Transparency Report.
Student Privacy Rights
FERPA
ThinkKits does not collect, store, or process student personally identifiable information (PII) and is not subject to FERPA. We:
- Use only publicly available, aggregate school-level data from federal sources (NCES CCD, CRDC, USAC E-Rate)
- Do not access, collect, or store student-level personally identifiable information
- Do not receive education records from schools or districts
- Maintain comprehensive audit trails of all data access
COPPA Compliance
ThinkKits does not collect, use, or disclose personal information from children under 13. Our platform processes only publicly available school-level aggregate data from NCES and does not interact with students or collect student-level data. The platform is designed exclusively for adult education professionals, administrators, and vendors.
State Privacy Laws
ThinkKits complies with state student privacy laws including:
- California Student Online Personal Information Protection Act (SOPIPA)
- New York Education Law 2-d
- Illinois Student Online Personal Protection Act (SOPPA)
- Other applicable state student privacy regulations
Data Processing Principles
Purpose Limitation
Platform data is processed only for providing the ThinkKits service. We do not use any data for:
- Commercial advertising or marketing to students or parents
- Creating behavioral profiles for non-educational purposes
- Selling or disclosing information to data brokers
- Any purpose not directly related to the educational services provided
Data Minimization
We collect only the minimum amount of data necessary to provide our services. Our data collection is:
- Limited to specific educational purposes
- Proportionate to the services provided
- Regularly reviewed to ensure continued necessity
- Subject to ongoing minimization efforts
Transparency and Control
ThinkKits provides clear information about our data practices and enables appropriate controls:
- Transparent privacy notices and data collection disclosures
- Clear information about data use and retention periods
- Mechanisms for data access, correction, and deletion requests
- Regular privacy impact assessments and policy updates
Security Measures
ThinkKits implements comprehensive security measures to protect all platform data:
Encryption
Access Control
Monitoring
Incident Response
Compliance Monitoring
ThinkKits maintains ongoing alignment with SDPC National DPA principles through:
- Regular Audits: Quarterly internal privacy and security audits
- Staff Training: Mandatory privacy training for all employees
- Policy Updates: Regular review and updates of privacy policies and procedures
- Third-Party Assessments: Independent security and privacy assessments
- Transparency: Public documentation of data practices and compliance posture
Questions About Data Privacy?
Our privacy team is available to answer questions about our data protection practices and SDPC alignment.
Contact Privacy Team View Transparency ReportSDPC National DPA Version: v2.1 | Last Updated: February 2026 | Next Review: August 25, 2026 | Questions about this compliance statement?