Overview
Peekapak is built with student data privacy as a core priority. This article answers common questions about the compliance standards and data protection practices Peekapak follows, including COPPA, FERPA, GDPR, ISO 27001, and state-specific Data Privacy Agreements (DPAs).
Is Peekapak COPPA and FERPA compliant?
Yes. Peekapak is compliant with both COPPA (Children's Online Privacy Protection Act) and FERPA (Family Educational Rights and Privacy Act), which govern the collection and handling of student data in the U.S.
Is Peekapak GDPR compliant?
Yes. Peekapak complies with the General Data Protection Regulation (GDPR), and this compliance is independently monitored by Drata, which helps proactively track vulnerabilities and streamline ongoing compliance.
Is Peekapak compliant with any other data security standards?
Yes. Peekapak is also compliant with ISO 27001, an internationally recognized standard for information security management. Peekapak's practices around data security, availability, and confidentiality are additionally monitored by Drata.
What student data does Peekapak collect?
Peekapak limits data collection to only what's essential for delivering its educational services. The identity data collected includes:
Student's name
Student's email
Student's password
Student ID number
Student's parent's name
Student's parent's email
How does Peekapak process student data?
Data is processed lawfully, fairly, and transparently, with a clear purpose defined before collection. Processing is based on consent, contractual necessity, or legitimate educational interest. Where possible, Peekapak de-identifies data — removing direct identifiers such as unique ID numbers or codes — before using, archiving, or sharing it.
Does Peekapak follow data minimization practices?
Yes. Peekapak only collects and stores essential information, and retains student data only as long as necessary to fulfill its educational purpose. After that, data is securely deleted.
Does Peekapak sell or share student data with third parties?
No. Peekapak does not sell or share student data with third parties for commercial purposes. Where third-party service providers are used, strict contractual agreements are in place to ensure those providers also meet GDPR requirements.
What security measures does Peekapak use to protect student data?
Peekapak maintains the following safeguards:
Encryption of data in transit and at rest
Secure, role-based access controls
Regular security audits and vulnerability assessments
Ongoing compliance with industry best practices for data protection
What happens if there's a data breach?
Peekapak maintains a structured incident response plan for data breaches. Affected individuals and relevant authorities are notified in accordance with GDPR requirements.
Does Peekapak have Data Privacy Agreements (DPAs) with U.S. states?
Yes. Peekapak has signed DPAs with multiple U.S. states, including:
California — in alignment with the California Student Data Privacy Agreement (CSDPA)
Utah — compliant with the Utah Student Data Protection Act (SDPA)
Oregon — following the Oregon Student Information Protection Act (OSIPA)
These agreements cover data ownership, encryption, access controls, and third-party limitations.
How do I get a copy of my state's DPA?
Contact Peekapak and the team will provide documentation and walk you through the compliance approach for your state.
Who do I contact with privacy or data protection questions?
For inquiries about data protection and privacy, please contact the Peekapak team.
