This Data Processing Agreement (“DPA” forms part of our Terms of Service and applies to schools, districts, and programs that use PandaCheckout (the “Service”) to process student and personal data. It incorporates the student-data privacy commitments required by the Family Educational Rights and Privacy Act (FERPA), the Children’s Online Privacy Protection Act (COPPA), and applicable state student-privacy laws. A signed, school-specific version is available on request.
The school, district, or program (“you” or the “LEA”) is the controller of Customer Data. PandaCheckout (“we” or the “Provider”) acts as a processor. With respect to student education records, we act as a “school official” under FERPA with a legitimate educational interest, under your direct control, performing a service otherwise provided by the LEA.
“Customer Data” means student, parent/guardian, attendance, signature, and operational data the LEA submits through the Service, including education records and personally identifiable information from students. We process Customer Data only on your documented instructions and for the sole purpose of providing the Service.
We will not:
We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption in transit, access controls, role-based permissions, hashed passwords, encrypted integration credentials, audit logging, and tenant isolation. We review these controls regularly and, on request, can describe our security program to support your compliance review.
We use categories of subprocessors to provide the Service (cloud hosting and database infrastructure, cloud object storage for signature images, payment processing, authentication, and analytics on marketing pages). We require each subprocessor to protect Customer Data under a written agreement that meets the standards of this DPA and applicable law. We remain responsible for our subprocessors’ compliance. We do not engage subprocessors to process Customer Data for their own purposes.
On your request, or when your subscription ends, we will delete or return Customer Data within a reasonable period, except where we are legally required to retain it. You may also delete Customer Data directly in the Service at any time.
If we become aware of a confirmed security incident affecting Customer Data, we will investigate and notify you without undue delay, and in any case within the timeframe required by applicable law, so you can meet your own notification obligations.
We will not disclose Customer Data to third parties except as required by law. Where legally permitted, we will notify you of any government request for Customer Data so you can seek appropriate protection, unless we are legally prohibited from doing so.
On reasonable notice, we will provide information reasonably needed to confirm our compliance with this DPA and, where appropriate, make our security documentation available for your review. We will remediate any material gaps we identify.
Where COPPA applies, we act as an operator only with the school’s authorization and within the permitted school-authorization exception. We do not collect personal information directly from children for commercial purposes, and we do not use Student Data for targeted advertising. We retain Student Data only as long as needed to provide the Service or as required by law.
This DPA applies for the duration of your use of the Service and until all Customer Data has been deleted or returned in accordance with Section 6.
For a signed copy of this DPA or questions about student-data privacy, email privacy@pandacheckout.com.