← Back to Platform

SDPC National DPA Compliance

ThinkKits is committed to data privacy and aligns with the SDPC National Data Privacy Agreement v2.1 principles. ThinkKits does not collect, store, or process student PII.

SDPC National DPA v2.1 Compliant

SDPC National Data Privacy Agreement

ThinkKits LLC supports the principles of the Student Data Privacy Consortium (SDPC) National Data Privacy Agreement v2.1. ThinkKits does not collect, store, or process student personally identifiable information (PII) and is not subject to FERPA. Our platform processes only publicly available federal education data and serves adult education professionals, administrators, and vendors.

What is the SDPC National DPA?

The Student Data Privacy Consortium (SDPC) National Data Privacy Agreement is a standardized data privacy agreement developed in collaboration with education stakeholders, legal experts, and privacy advocates. It establishes comprehensive protections for student data used by education technology vendors.

Our Commitment

Although ThinkKits does not handle student PII, we commit to:

Key Protections

Data Security

Enterprise-grade security measures including encryption, access controls, regular security audits, and incident response procedures to protect all platform data.

No Data Mining

We do not use platform data for advertising, marketing, or creating profiles for non-educational purposes. User data is used solely for providing the service.

No Sale of Data

ThinkKits never sells user data or account information to third parties. All data remains confidential and protected.

Data Deletion

User account data is deleted upon request or within 30 days of account closure.

No Student PII

ThinkKits does not collect, store, or process student personally identifiable information (PII) and is not subject to FERPA. We process only publicly available federal education data.

Adult Users Only

The platform is designed exclusively for adult education professionals, administrators, and vendors. We do not collect personal information from children under 13.

Data Collection Transparency

ThinkKits maintains complete transparency about what data we collect, how we use it, and how long we retain it. ThinkKits does not collect, store, or process student personally identifiable information (PII).

Data Category Collection Method Purpose Retention Period Status
Public School Data NCES CCD, CRDC, USAC E-Rate Education intelligence and analysis Updated annually with federal releases Public Data
User Account Data Clerk auth (signup) User identification and access control Active account + 30 days after closure Compliant
Usage Analytics Platform Interaction Logs Service improvement and support 2 years (anonymized after 90 days) Compliant
Technical Data Automatic System Collection Security and system operation 90 days Exceeds

For detailed information about our data collection practices, see our Data Collection Transparency Report.

Student Privacy Rights

FERPA

ThinkKits does not collect, store, or process student personally identifiable information (PII) and is not subject to FERPA. We:

COPPA Compliance

ThinkKits does not collect, use, or disclose personal information from children under 13. Our platform processes only publicly available school-level aggregate data from NCES and does not interact with students or collect student-level data. The platform is designed exclusively for adult education professionals, administrators, and vendors.

State Privacy Laws

ThinkKits complies with state student privacy laws including:

Data Processing Principles

Purpose Limitation

Platform data is processed only for providing the ThinkKits service. We do not use any data for:

Data Minimization

We collect only the minimum amount of data necessary to provide our services. Our data collection is:

Transparency and Control

ThinkKits provides clear information about our data practices and enables appropriate controls:

Security Measures

ThinkKits implements comprehensive security measures to protect all platform data:

Encryption

Data encrypted in transit (TLS 1.3) and at rest (AES-256) with secure key management and rotation procedures.

Access Control

Role-based access controls with multi-factor authentication and principle of least privilege access to platform data.

Monitoring

Continuous security monitoring, intrusion detection, and comprehensive audit logging of all data access activities.

Incident Response

Documented incident response procedures with immediate notification protocols for any potential data breaches.

Compliance Monitoring

ThinkKits maintains ongoing alignment with SDPC National DPA principles through:

Questions About Data Privacy?

Our privacy team is available to answer questions about our data protection practices and SDPC alignment.

Contact Privacy Team View Transparency Report

SDPC National DPA Version: v2.1 | Last Updated: February 2026 | Next Review: August 25, 2026 | Questions about this compliance statement?

Was this article helpful?

← Back to Help Center