logoProduct suite arrow right

Acceptable Use Policy

Effective from September 11, 2026

1. About this policy

1.1 This Acceptable Use Policy (“Policy”) sets out what may and may not be done on the Classe365 platform (a student information system, learning management system and customer relationship management platform for education institutions) and the Hiree365 platform (a campus recruitment and employability platform). Together these are the“Platforms”.

1.2 This Policy applies to every person who accesses either Platform, including:

  1. the organisation that subscribes (the “Customer” or “Institution”) — a K-12 school, a university or college, an academy or vocational training provider, or a corporate organisation using a Platform for corporate training;

  2. administrators, teaching and academic staff, and professional and support staff;

  3. students, learners and candidates;

  4. parents and guardians with Platform access;

  5. employers and recruiters invited to Hiree365 by an Institution; and

  6. any developer, integrator, contractor or agent acting for a Customer.

Each of these is referred to as a “User”.

1.3 The Customer contracts with one of two entities. Customers established in the United States contract with 365 Software, LLC (a Delaware limited liability company, 131 Continental Dr, Suite 305, Newark, DE 19713, United States). All other Customers, including those in the European Union, the United Kingdom, Australia and the rest of the world, contract with Sprout On Web Pty Ltd (ABN 72 138 602 418, 22 Palm Street, St Ives, NSW 2075, Australia). In this Policy, “Classe365”, “we”, “us” and “our” mean the Customer’s contracting entity.

1.4 This Policy forms part of the Master Terms and Conditions. A breach of this Policy is a breach of those Terms. Where this Policy and the Terms use the same defined term, it has the same meaning.

1.5 The Customer is responsible for the conduct of its Users and must make this Policy known to them. Institutions may impose stricter rules of their own; where they do, Users must comply with both.

1.6 This Policy is not exhaustive. Conduct that is not expressly listed may still breach this Policy if it is unlawful, harmful, or inconsistent with the purpose of the Platforms.

2. General principles

2.1 The Platforms exist to support education, training, student administration, campus placement and employability. Use them for those purposes.

2.2 Users must:

  1. comply with all laws that apply to them, including education, privacy, data protection, employment, anti-discrimination, child protection, consumer, intellectual property and export control laws;

  2. use only the access, records and functionality that their role legitimately requires;

  3. keep credentials confidential and use their own account;

  4. treat student, candidate and staff information as confidential; and

  5. report suspected misuse or a suspected security issue promptly (clause 11).

2.3 Users must not use the Platforms in a way that damages, disables, overburdens or impairs them, or that interferes with any other Customer’s use of them.

3. Prohibited content

3.1 Users must not upload, store, publish, transmit or link to content that:

  1. is unlawful, or that promotes or facilitates unlawful activity;

  2. sexually exploits or abuses a child, sexualises a minor, or constitutes child sexual abuse material. Any such content will be removed immediately, the account will be suspended without notice, and we will report it to the appropriate authorities where required or permitted by law;

  3. is pornographic or sexually explicit;

  4. incites, promotes or glorifies violence, terrorism, or a violent extremist organisation;

  5. incites or promotes hatred, harassment or discrimination against a person or group on the basis of a protected attribute, including race, colour, ethnic or national origin, nationality, religion or belief, sex, gender identity, sexual orientation, marital or family status, pregnancy, age, disability, or any other attribute protected by applicable law;

  6. bullies, harasses, threatens, intimidates, stalks or defames a person, including another student, a staff member, a candidate or an employer contact;

  7. infringes a copyright, trade mark, patent, moral right, database right, trade secret or other intellectual property right;

  8. breaches a person’s privacy, including publishing another person’s personal information without a lawful basis and, where required, their consent;

  9. contains malware, ransomware, spyware, a virus, a worm, a trojan, a logic bomb, or any other harmful, disruptive or destructive code;

  10. is fraudulent, deceptive or misleading, including phishing content and content that impersonates a person, an institution, an employer or Classe365;

  11. promotes self-harm, suicide, disordered eating or the abuse of drugs, alcohol or other substances;

  12. is unsolicited commercial communication (spam), a chain message, a pyramid scheme, or a multi-level marketing solicitation; or

  13. is otherwise inappropriate for an education or training environment in which minors may be present.

3.2 Users must not use the Platforms to store or distribute content that is unrelated to the Customer’s educational, administrative, recruitment or training purposes — for example, using the file storage in a Platform as a general-purpose media library or file-sharing service.

4. Prohibited conduct

4.1 Users must not:

  1. impersonate another person, misrepresent their role, affiliation or identity, or falsify a record;

  2. create an account for a person who has not authorised it, or use another person’s credentials;

  3. access, alter, delete or disclose a record they are not authorised to access, including altering a grade, an attendance record, a disciplinary record, a fee record or an admission decision without authority;

  4. use the Platforms to harass, groom, or make inappropriate contact with a student or a minor;

  5. use the communication, messaging or notification features to send bulk unsolicited messages outside the Customer’s legitimate communications;

  6. resell, sub-licence or provide access to the Platforms to a third party, unless an Order expressly permits it;

  7. use the Platforms to develop, train or benchmark a competing product or service;

  8. remove, obscure or alter any proprietary notice, watermark or audit record;

  9. interfere with, disable or circumvent any logging, monitoring, audit trail or usage measurement function; or

  10. take any action intended to disguise the origin of activity on the Platforms.

4.2 Users must not attempt to do any of the things in clause 4.1, and must not assist or encourage another person to do them.

5. Academic integrity and use of AI features

5.1 The Platforms include AI features: an AI chat assistant, agent automation and a workflow engine, grading analysis, attendance analysis, attrition tracking, behaviour analytics, a writing assistant, and AI plagiarism checking. The AI Use Statement describes them in full.

5.2 Users are told when they are interacting with an AI system. The AI chat assistant identifies itself as an AI system. Users must not configure, relabel or present an AI feature so that a person is led to believe they are dealing with a human being.

5.3 Students and learners must not use the writing assistant or any other AI feature to produce work that is submitted as their own where the Institution’s academic integrity rules do not permit it. The Institution’s academic integrity policy governs what assistance is allowed for a given assessment. Where the Institution’s policy and this Policy differ, the stricter rule applies.

5.4 Staff must not rely on AI output as the sole basis for a decision about a student, learner, candidate or employee. All AI output is advisory. Decisions about students remain with the Institution and its staff, and no automated decision may be allowed to produce a legal or similarly significant effect on a person without meaningful human review.

5.5 Staff must not use grading analysis, attendance analysis, attrition tracking or behaviour analytics to:

  1. apply a sanction, exclusion, withdrawal or academic penalty automatically, without a human reviewing the underlying evidence;

  2. profile students on the basis of a protected attribute, or use those features as a proxy for a protected attribute;

  3. monitor students or staff for a purpose unrelated to education, training or student welfare; or

  4. create a permanent risk label about a student that is not reviewable, correctable or capable of being removed by the Institution.

5.6 AI plagiarism checking produces a probabilistic indication, not proof. An academic integrity finding must not be made on the basis of a plagiarism score alone. A human must review the work and give the student a fair opportunity to respond.

5.7 Users must not submit to an AI feature any data that they are not authorised to process on the Platform, and must not attempt to use an AI feature to extract data belonging to another Customer or to another tenant.

5.8 Users must not attempt to manipulate, jailbreak or prompt-inject an AI feature in order to bypass access controls, safety controls or the restrictions in this Policy, or to cause it to generate content prohibited by clause 3.

5.9 We do not use customer, student or candidate data to train, fine-tune or improve any general-purpose or shared AI model. Where a feature uses a model that learns from data, that model is trained only on that customer’s own data and is used only for that customer. Users must not attempt to defeat that separation.

6. Security restrictions

6.1 No unauthorised security testing. Users must not conduct penetration testing, vulnerability scanning, fuzzing, load testing, red-team exercises, denial-of-service testing or any other security or performance testing against the Platforms without our prior written authorisation. To request authorisation, write to clientservice@classe365.com with the intended scope, the source addresses, the testing window and the contact details of the testers. Testing conducted without written authorisation is a breach of this Policy and may also be a criminal offence.

6.2 No circumventing access controls. Users must not:

  1. attempt to gain unauthorised access to any part of the Platforms, to any account, or to any system, server, network or database used to operate them;

  2. bypass, disable or interfere with authentication, authorisation, session management, rate limiting, tenant isolation or any other security or access control mechanism;

  3. attempt to access data belonging to another Customer, another tenant or another user;

  4. escalate privileges, or use an administrative function they have not been granted;

  5. probe, scan or test the vulnerability of the Platforms or their infrastructure; or

  6. reverse engineer, decompile or disassemble any part of the Platforms, except to the extent this restriction cannot lawfully be excluded.

6.3 No scraping. Users must not use a robot, spider, crawler, scraper, headless browser, automated script or any other automated means to extract, copy, index or harvest data from the Platforms, except through our documented application programming interfaces and in accordance with clause 8. This restriction applies in particular to student records, candidate profiles, employer contact details, staff directories and any listing or directory feature.

6.4 Users must not introduce malicious code, and must not use the Platforms to launch or relay an attack on any other system.

6.5 Users must not use the Platforms to mine cryptocurrency, to run distributed computation unrelated to the Customer’s use of the Platform, or to operate a proxy, VPN or anonymisation service.

6.6 Users must promptly report any vulnerability or security weakness they become aware of to clientservice@classe365.com, and must not disclose it publicly, exploit it, or use it to access data, beyond the minimum necessary to demonstrate that it exists.

6.7 Users must not disclose to a third party any non-public information about our security architecture, controls or vulnerabilities.

7. Student and candidate data

7.1 Student and candidate records held on the Platforms are confidential. Users may access and use them only for the legitimate educational, administrative, welfare, placement or training purpose for which their role requires access.

7.2 Users must not:

  1. access a student or candidate record out of curiosity, or for a personal, social, commercial or political reason;

  2. look up a family member, friend, neighbour, colleague, public figure or any other person where the User’s role does not require it;

  3. disclose a student or candidate record to a person who is not authorised to receive it, including to another student, another parent, a journalist, or an organisation outside the Institution;

  4. export, download, print, photograph, screenshot or copy student or candidate data other than as required for their role, and where they do, they must handle and dispose of the copy securely;

  5. transfer student or candidate data to a personal device, personal email account, personal cloud storage account, or any unapproved third-party service;

  6. use student or candidate data for marketing, advertising, list-building, fundraising or commercial solicitation, other than communications the Institution itself is entitled to send;

  7. sell, licence, trade or otherwise disclose student or candidate data for money or other valuable consideration;

  8. use student or candidate data to build an advertising or behavioural profile, or to target advertising at a student, a candidate or a parent;

  9. publish student or candidate data, including on social media, or use it in a publicly accessible presentation, report or research output without the Institution’s authorisation and any consent required by law; or

  10. use student or candidate data to train an AI model outside the Platform.

7.3 Users must apply particular care to records about children. Children under 13 who access Classe365 are covered by the Children’s Privacy Policy and the Direct Notice to Parents. Hiree365 has a minimum age of 16 and must not be made available to anyone under 16.

7.4 Institutions must configure roles and permissions so that Users can see only the records their role requires, must review those permissions periodically, and must deactivate accounts promptly when a person leaves or changes role.

7.5 Institutions must not upload data categories they have no lawful basis to hold, and must not use the Platforms to hold records that their own retention policy or applicable law requires them to have destroyed.

7.6 Where an Institution enables an optional third-party integration — including SMOWL proctoring or Zapier automation — the Institution contracts with that provider directly and is responsible for the data it sends there. Users must not configure an integration that sends student or candidate data to a destination the Institution has not approved.

8. Rate limits and API fair use

8.1 Access to our application programming interfaces is provided for the Customer’s own integrations and must be used in accordance with our documentation.

8.2 Users must not:

  1. exceed a published or communicated rate limit, or make requests at a volume or frequency that degrades the Platforms for other customers;

  2. circumvent a rate limit by rotating credentials, API keys, IP addresses or accounts;

  3. share, publish or embed an API key or credential in client-side code, a public repository or a distributed application;

  4. poll an endpoint more frequently than the documentation permits, where a webhook or event subscription is available for the same purpose;

  5. use the API to perform a bulk extraction of an entire dataset on a recurring basis where an export function is provided for that purpose; or

  6. run automated load or stress testing against the API, which is security testing under clause 6.1 and requires written authorisation.

8.3 Fair use means the volume of use reasonably expected of an organisation of the Customer’s size using the Platforms for their intended purpose. Where use materially exceeds that, we may contact the Customer to discuss it, apply a technical rate limit, or require a plan appropriate to the volume.

8.4 We may impose, publish and vary rate limits, storage limits, message-sending limits and file size limits to protect the stability, security and performance of the Platforms. We will give reasonable notice of a change that materially affects an existing integration, except where an immediate change is necessary to protect the service.

8.5 Storage included in a plan is for Customer Data used in connection with the Platforms. Sustained storage use materially beyond the plan allowance may be subject to additional charges or a plan change, on notice.

9. Hiree365 — additional restrictions

9.1 This clause applies to all Users of Hiree365, and in particular to employers and recruiters invited by an Institution.

9.2 Employers receive student personal data only via the Institution. We do not disclose candidate data directly to employers. The Institution controls what is shared as part of its placement programme. Employers must not attempt to obtain candidate data by any other route.

9.3 No discriminatory job postings. A job posting, role description, screening question, filter, shortlisting criterion or communication published or used through Hiree365 must not:

  1. state or imply a preference, limitation, requirement or exclusion based on race, colour, ethnic or national origin, nationality, religion or belief, sex, gender identity, sexual orientation, marital or family status, pregnancy or parental status, age, disability, medical condition, caste, political opinion, trade union membership, or any other attribute protected by applicable law, except where a genuine occupational requirement or a lawful positive-action measure applies and the employer can demonstrate it;

  2. use a filter, keyword, screening criterion or automated ranking that has the purpose or effect of excluding candidates on the basis of such an attribute;

  3. require a candidate to disclose a protected attribute, a health condition, a disability, a pregnancy, or a criminal record, except where the disclosure is lawfully required for that role and is requested at a lawful stage of the process; or

  4. refuse a reasonable adjustment requested by a candidate with a disability in connection with an application or interview.

9.4 No misuse of candidate data by employers. An employer must not:

  1. use candidate data for any purpose other than assessing that candidate for the role or programme for which the data was provided;

  2. retain candidate data longer than is necessary for that purpose and for any period required by law;

  3. transfer, sell, licence, share or otherwise disclose candidate data to another organisation, including a parent, subsidiary, affiliate, staffing agency, background-check provider or data broker, unless the Institution has authorised it and the candidate has been informed;

  4. add a candidate to a marketing list, newsletter, mailing list or talent-pool database used for unrelated purposes, without the candidate’s consent;

  5. contact a candidate for a purpose unrelated to the placement programme, or continue to contact a candidate who has asked them to stop;

  6. use candidate data to build a profile for advertising, credit assessment, insurance assessment, or any purpose unconnected with recruitment;

  7. scrape, bulk-export, index or replicate candidate profiles into the employer’s own systems beyond the records genuinely under consideration; or

  8. publish a candidate’s information, or use it in marketing or promotional material.

9.5 Employers must not post a role that does not exist, a role for which they are not recruiting, an unpaid role misrepresented as paid, a role that requires the candidate to pay a fee to apply or to be placed, or an opportunity that is in substance a sales, investment, franchise or multi-level marketing solicitation.

9.6 Employers must not use Hiree365 to solicit candidates for work that is unlawful, unsafe, or in breach of minimum employment standards in the place where the work is performed.

9.7 Institutions running a placement programme must obtain any consent required from a candidate before sharing that candidate’s information with an employer, must tell candidates what will be shared and with whom, and must honour a candidate’s withdrawal from the programme.

9.8 Candidates must provide accurate information. Fabricating qualifications, results, employment history or references in a Hiree365 profile is a breach of this Policy and may also be a breach of the Institution’s rules.

10. Consequences of breach

10.1 If we reasonably believe that this Policy has been breached, we may take one or more of the following steps, proportionate to the breach:

  1. contact the Customer and ask for the issue to be remedied;

  2. require the Customer to remove or disable specific content;

  3. remove or disable specific content ourselves, where it is unlawful, harmful, or presents a risk to a person or to the Platforms;

  4. apply a technical restriction, such as a rate limit;

  5. suspend an individual User’s access;

  6. suspend the Customer’s account or specific functionality, in whole or in part;

  7. terminate the subscription for material breach in accordance with the Master Terms and Conditions;

  8. report the matter to a law enforcement agency, a regulator, or a child protection authority where required or permitted by law; and

  9. preserve evidence, including logs and content, where necessary for an investigation or a legal obligation.

10.2 Except where immediate action is necessary to protect the safety of a person, the security of the Platforms, or our compliance with the law, we will notify the Customer and give a reasonable opportunity to remedy the breach before suspending access. Where we must act immediately, we will notify the Customer as soon as practicable afterwards and explain what is required to restore access.

10.3 We will limit any suspension to the accounts, content or functionality affected wherever it is practicable to do so, rather than suspending an entire Institution.

10.4 Content involving child sexual abuse material, a credible threat to life or safety, or an active attack on the Platforms will be acted on immediately and without prior notice.

10.5 Suspension does not relieve the Customer of its obligation to pay fees for the subscription term, unless the suspension was our fault.

10.6 A Customer may ask us to review a suspension decision by writing to clientservice@classe365.com. We will review the decision and respond in writing.

10.7 We do not routinely monitor the content of Customer Data. We act on reports, on automated security signals, and where we are required to act by law. Nothing in this Policy obliges us to monitor, screen or moderate Customer Data, and no failure to detect a breach waives our rights.

11. Reporting a violation

11.1 To report a breach of this Policy, misuse of the Platforms, a security vulnerability, unlawful content, or conduct that puts a student or candidate at risk, write to clientservice@classe365.com.

11.2 Please include, as far as you are able:

  1. your name, role and organisation, and how to contact you;

  2. the Platform concerned (Classe365 or Hiree365) and the account, institution or user involved;

  3. what happened, and when;

  4. the location of the content or activity, such as a screen, module, record identifier or link; and

  5. any evidence you can safely provide, such as a screenshot or an email header.

11.3 Do not include a copy of a student’s or candidate’s personal information in a report unless it is necessary to identify the issue. If it is necessary, say so in the report so that we can handle it appropriately.

11.4 We will acknowledge a report and investigate it. We will keep the reporter’s identity confidential to the extent we are able, unless disclosure is required by law or is necessary to protect a person from harm.

11.5 A vulnerability reported in good faith under clause 6.6, without exploitation and without accessing data beyond the minimum needed to demonstrate the issue, will not be treated by us as a breach of this Policy.

11.6 If a report concerns an immediate risk to the safety of a child or any other person, contact your local emergency services and your Institution’s safeguarding lead first, and then notify us.

11.7 Users may also raise a concern through their Institution. Institutions remain responsible for their own safeguarding, complaints and disciplinary processes.

12. Changes to this Policy

12.1 We may amend this Policy. We will give at least 30 days’ prior notice of any material change, by email to the account’s nominated contact and by publishing the updated Policy on our website with a “Last updated” and “Effective” date. Changes required by law, and changes that are purely administrative, may take effect on a shorter notice period.

12.2 Continued use of a Platform after the effective date of a change constitutes acceptance of the amended Policy.

13. Contact

Reports, questions and authorisation requests under this Policy:
clientservice@classe365.com

365 Software, LLC — 131 Continental Dr, Suite 305, Newark, DE 19713, United States
Sprout On Web Pty Ltd — ABN 72 138 602 418, 22 Palm Street, St Ives, NSW 2075, Australia