Compliance
Privacy and compliance.
Scanmarker takes student and user privacy seriously. This page summarizes our compliance posture across major education and privacy regulations. For the full Privacy Policy, see our Privacy Policy.
Last updated: May 2026
FERPA
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records. When Scanmarker products or services are deployed by a school or district, Scanmarker acts as a school official under FERPA — we may access student data only to fulfill the contracted educational purpose and are prohibited from using it for advertising or sharing it with third parties without consent.
- —Student scan data is not used to train machine learning models.
- —Schools retain control over student data and can request deletion at any time.
- —Data is never sold to third parties.
COPPA
The Children's Online Privacy Protection Act (COPPA) restricts the collection of personal information from children under 13 without verifiable parental consent.
- —Scanmarker does not knowingly collect personal data directly from children under 13 via our consumer-facing website.
- —When Scanmarker is deployed in K-8 schools, the school acts as the operator under COPPA's school authority exception, and Scanmarker processes student data only as directed by the school.
- —Schools may execute a Data Processing Agreement (DPA) to formalize these responsibilities — see below.
GDPR
The General Data Protection Regulation (GDPR) applies to users in the European Economic Area and the United Kingdom. Scanmarker complies with GDPR as a data processor when handling personal data on behalf of our educational customers.
- —Data subjects have the right to access, correct, and delete their data upon request.
- —Data transfers outside the EEA use Standard Contractual Clauses (SCCs) approved by the European Commission.
- —Scanmarker maintains a record of processing activities as required by GDPR Article 30.
Data retention
Scanmarker retains user account data and scan history for as long as your account is active. Upon account deletion:
- —Personal profile data is deleted within 30 days.
- —Scan content and history is deleted within 60 days.
- —Aggregated, anonymized usage data (no personal identifiers) may be retained for product improvement purposes.
- —Transaction records are retained for 7 years for legal and tax purposes.
Request a Data Processing Agreement
Schools and districts deploying Scanmarker in a student-facing capacity can request a signed Data Processing Agreement (DPA). The DPA formalizes our roles as controller and processor, specifies the categories of data processed, and documents our security and deletion obligations.
To request a DPA, email privacy@scanmarker.com with your district name and state. We will send a pre-signed DPA template within 3 business days. If your district uses a standard DPA template, we will review it and respond within 5 business days.