logoProduct suite arrow right

Children's Privacy Policy

Effective from September 11, 2026
Applies to: children under 13 whose personal information is held in Classe365 by an education institution or corporate training customer, and to the parents and guardians of those children. It also explains our position for Hiree365, which has a minimum age of 16 and no users under 13.

1. About this policy

1.1 Why this policy exists

Classe365 is a student information system, learning management system and CRM used by education institutions. When a school uses Classe365 for pupils in primary or middle years, the platform holds records about children under 13. Those records are protected by the United States Children’s Online Privacy Protection Act (COPPA) and the Children’s Online Privacy Protection Rule made under it, and by children’s privacy provisions in other jurisdictions.

The Federal Trade Commission amended the COPPA Rule in 2025. The Final Amendments were published at 90 FR 16918 on 22 April 2025, took effect on 23 June 2025, and carry a full compliance date of 22 April 2026. The amendments changed the definition of personal information, introduced a requirement for separate consent to third-party disclosure, required operators to publish a retention schedule with deletion timelines, and required a written children’s information security program. This policy is written to meet those amended requirements. It replaces our previous children’s privacy policy in full.

1.2 Which platform this covers

  • Classe365 — covered by this policy in full. Institutions use it for learners of all ages, including children under 13.
  • Hiree365 — our campus recruitment and employability platform. Hiree365 has a minimum age of 16. It is not available to anyone under 16 and it has no users under 13. Section 16 sets out our position. Candidate privacy is described in the Hiree365 Candidate Privacy Notice.

1.3 Which entity contracts

We use a regional contracting model.

  • Customers located in the United States contract with 365 Software, LLC, a Delaware limited liability company, registered office 131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, United States; registered agent Legalinc Corporate Services Inc. Governing law: the State of Delaware. Courts of the State of Delaware.
  • All other customers, including those in the European Union, the United Kingdom, Australia and the rest of the world, contract with Sprout On Web Pty Ltd, ABN 72 138 602 418, registered office 22 Palm Street, St Ives, NSW 2075, Australia; business address 22 Giffnock Avenue, Macquarie Park, NSW 2113, Australia. Governing law: New South Wales, Australia. Courts of New South Wales.
  • Classe365 India Pvt Ltd, 37, Venjay Edifice Complex, 3rd Floor, JLB Road, Chamarajapuram, Mysuru – 570 005, India, is a group affiliate that provides support and engineering services to both contracting entities. Section 12 explains what that means for children’s data, and parents should read it.

In this policy, “Classe365”, “we”, “us” and “our” mean the contracting entity for the child’s institution together with the group affiliate that supports it.

1.4 How this policy fits with our other documents

This policy should be read with our Privacy Policy, which is the master document describing all of our processing, our two roles as processor and controller, our sub-processors, our hosting arrangements and our security controls. Where the Privacy Policy summarises children’s data, this policy governs. Where this policy summarises a topic covered in more detail in the Privacy Policy — for example the full list of sub-processors, or international transfer mechanisms — the Privacy Policy governs.

The Personal Data Processing Agreement governs our processing on behalf of an institution and sets out the transfer mechanisms we rely on. The AI Use Statement describes our AI features. The FERPA Compliance Statement describes our position on education records under United States federal education law.

2. Who this policy applies to

This policy applies to:

  1. Children under 13 whose records are held in Classe365 by an institution — including personal details, enrolment records, attendance, assessment and grading records, learning activity, communications and any additional field the institution has configured.
  2. Parents and guardians of those children, whether or not the institution has issued them a parent portal account.
  3. Institutions — schools, districts, academies and corporate training customers — that decide to place children’s records in the platform and that direct what is collected.

It does not apply to institution staff, to learners aged 13 and over, or to visitors to our marketing website. Those are covered by the Privacy Policy.

We do not offer Classe365 directly to children or to families. A child can only have a Classe365 account because an institution created one. We have no consumer sign-up route for a child, no direct-to-child marketing, and no way for a child to open an account without an institution.

3. Our role, and the institution’s role

3.1 The institution decides; we carry out

Children’s information reaches the platform because an institution decides to put it there. The institution chooses which fields to collect, designs its own admission and enrolment forms, decides which modules and features to switch on, decides which staff can see what, and decides how long to keep a record before deleting it.

Under data protection law outside the United States, the institution is the controller and we are the processor. Under United States privacy law we are a service provider to the institution. Under the Family Educational Rights and Privacy Act we act as a school official with a legitimate educational interest, under the direct control of the institution.

Under COPPA, the institution operates the online service for its pupils and directs the collection of their information for a school-authorised education purpose. We collect and handle children’s information solely on the institution’s instructions, as the provider that runs the platform for it. We do not decide what is collected about a child, we do not collect anything about a child for our own purposes, and we do not use a child’s information for anything other than providing the service to the institution.

COPPA requires verifiable parental consent before a child’s personal information is collected. In the school setting, the amended Rule recognises that a school may provide that authorisation in place of the parent where the collection is for a school-authorised education purpose and the information is not used for any commercial purpose unrelated to that education purpose.

That is the basis on which children’s information is collected in Classe365:

  • The institution decides that the platform is needed for a school-authorised education purpose — running enrolment, teaching, assessment, attendance, reporting and communication with families.
  • The institution is responsible for giving parents notice of what is collected and how it is used, and for obtaining verifiable parental consent where consent, rather than school authorisation, is required by law or by the institution’s own policy or by the law of its state or country.
  • We support the institution by publishing this policy and the Direct Notice to Parents, which the institution can give to parents before consent is sought, and by recording consent decisions in the platform where the institution uses the consent workflow.
  • We never treat a child’s use of the platform as consent, and we never ask a child to consent on a parent’s behalf.

Some institutions choose to seek verifiable parental consent directly rather than rely on school authorisation, and some are required to. We support either approach. Where an institution asks us for the material it needs to seek consent, we provide the Direct Notice to Parents and the information in this policy free of charge.

3.3 What the institution must do

An institution that places children’s records in Classe365 is responsible for:

  • giving parents direct notice of the collection, use and disclosure of their child’s information before that information is collected;
  • obtaining and recording verifiable parental consent, or providing school authorisation where it is entitled to do so;
  • deciding whether to enable each optional disclosure described in section 8, and recording each parent’s separate consent decision where consent rather than school authorisation is the basis;
  • responding to parents who ask to review, correct or delete a child’s record, and instructing us accordingly;
  • deleting records it no longer needs, which starts our deletion timeline in section 10.

We will not proceed with an optional disclosure for a child where the institution has told us that consent for it has not been given or has been withdrawn.

4. The categories of children’s personal information we hold

The amended COPPA Rule defines personal information broadly. We set out below every category we hold about a child, mapped to that definition. What is actually present for a particular child depends on what the institution has chosen to collect and which modules it uses; nothing in this list is collected by us on our own initiative.

4.1 Identifiers and contact information

  • First and last name.
  • Home or other physical address, including street name and city or town.
  • Email address, where the institution issues or records one.
  • Telephone number, where the institution records one.
  • The institution’s own student or learner reference number.
  • Username and hashed password for the child’s platform account.
  • Screen or user name where it functions as online contact information.

4.2 Persistent identifiers

  • Account identifiers, session identifiers, authentication tokens and single sign-on identifiers.
  • IP address, device and browser information, and cookie or similar identifiers used to keep the child signed in and to keep the account secure.

Persistent identifiers held for a child are used only to support the internal operation of the platform and to keep the account secure. They are never used to build an advertising profile, to serve targeted advertising, or to track a child across other websites or services.

4.3 Photographs, video and audio

  • A photograph of the child, where the institution uploads one to the student record.
  • Files a child uploads as coursework, which may include images or video the child has created.

We do not collect audio recordings of children’s voices. The platform has no voice capture feature for children, and we do not hold voiceprints or voice recordings of children.

4.4 Biometric identifiers

The amended Rule includes biometric identifiers that can be used for automated or semi-automated recognition within the definition of personal information. Our position is stated in full and without qualification beyond the one that follows:

Classe365 and Hiree365 do not themselves collect, store or process biometric identifiers — including fingerprints, handprints, retina or iris patterns, genetic data, voiceprints, gait patterns, facial templates or faceprints — and do not perform facial or voice recognition.

Institutions may choose to enable SMOWL, a third-party online quiz proctoring service, which they contract with directly. Any biometric processing by SMOWL occurs under SMOWL’s own terms and privacy policy, not ours.

SMOWL is not a sub-processor of ours. It is a service an institution procures for itself and switches on. If your child’s institution has enabled SMOWL for proctored assessments, ask the institution for SMOWL’s privacy notice and for the basis on which it processes your child’s information; we will point you to the right contact at the institution if you ask us.

4.5 Government-issued identifiers

We do not require any government-issued identifier — such as a national identity number, social security number, tax number, passport number or driving licence number — to provide the platform.

Where an institution configures its own admission or enrolment forms to collect one, that identifier is treated as personal information and is held under the retention schedule in section 10. It is subject to the same encryption, access control and audit logging as the rest of the child’s record. The institution decides whether to collect it. We do not ask for it, and we never use it for any purpose of our own.

If your child has been asked for a government-issued identifier on a form inside the platform, that requirement comes from the institution, and questions about why it is being collected should go to the institution.

4.6 Education and pastoral records

  • Programme, course and class enrolment, timetable and attendance.
  • Assessment submissions, grades, transcripts, progression and completion records, certificates and awards.
  • Learning activity: material accessed, submissions, discussion posts, quiz and assignment activity, and engagement data generated by use of the learning management system.
  • Pastoral and administrative records the institution chooses to keep, which may include behaviour and discipline notes, welfare notes, accommodation or accessibility arrangements, and health or dietary information where the institution records it.
  • Communications between the institution, the child and the family through the platform.

4.7 Financial records

  • Fees invoiced and paid, scholarships, concessions and payment plans recorded against the child’s record. The payer is usually a parent or guardian, and payment card and bank details are handled by our payment processors and are not stored by us.

4.8 Information the institution adds

Institutions frequently add fields of their own to admission, enrolment and student forms. Anything an institution adds is covered by this policy, held under the same controls, and deleted on the same schedule.

5. Why children’s information is collected and used

Children’s information is used only to provide the platform to the institution, on the institution’s instructions. Specifically:

  1. Creating and maintaining the child’s student record.
  2. Running admissions, enrolment, timetabling and class allocation.
  3. Recording and reporting attendance.
  4. Delivering learning content and managing coursework, submissions, assessment and grading.
  5. Recording progression, completion, certificates and awards.
  6. Managing fees, invoicing and payment records held against the child.
  7. Enabling communication between the institution, its staff, the child and the family.
  8. Producing reports and analytics for the institution about its own cohort.
  9. Providing AI-assisted features the institution has enabled, within the limits in section 11.
  10. Providing technical support to the institution, diagnosing faults and restoring data.
  11. Keeping audit trails so the institution can see who did what, and keeping the platform secure.

We support the internal operations of the platform — authentication, security, fault diagnosis, backup and restoration — using the minimum information needed for those purposes.

We do not use children’s information for any commercial purpose unrelated to the education purpose for which the institution collected it.

6. Support of internal operations, and what that does not include

COPPA permits an operator to use persistent identifiers for the support of internal operations. We rely on that only for what the term genuinely covers: maintaining or analysing the functioning of the platform, performing network communications, authenticating users, maintaining user-driven preferences, protecting the security and integrity of the service, and complying with law.

It does not, for us, include:

  • contextual or behavioural advertising of any kind;
  • amending a child’s profile for advertising or commercial purposes;
  • audience measurement across other services;
  • profiling a child for any purpose beyond the education purpose the institution has set.

7. Who receives children’s information, and why

We use a small number of sub-processors to run the platform. Each is bound by a written contract, may act only on our instructions, is subject to confidentiality obligations, is assessed before engagement and monitored afterwards, and is included in the due diligence described in section 13.4.

7.1 Recipients of children’s personal information

RecipientWhat it isPurpose for which it receives children’s dataLocationConsent status
Amazon Web ServicesCloud hosting and storage providerHosting and storing the platform and its databases, including the child’s record; running daily backupsUnited States (us-east-1) or the requested regionIntegral — required for the service to exist
IntercomCustomer support messaging platformHandling support conversations, where a support conversation includes information about a childUnited StatesOptional — requires separate consent
AtlassianEngineering issue tracking platformRecording and diagnosing faults, where a fault report includes information about a childUnited States / AustraliaOptional — requires separate consent
StripePayment processorProcessing fee payments made against a child’s recordUnited StatesOptional — requires separate consent
PayPalPayment processorProcessing fee payments made against a child’s recordUnited StatesOptional — requires separate consent
Classe365 India Pvt LtdGroup affiliate providing support and engineering servicesProviding support and engineering services, which can require access to records including children’s recordsIndiaNot a disclosure to a third party; see section 12
The child’s institutionThe school, district, academy or training providerEducating and administering the child; the institution controls the recordThe institution’s own locationNot a third-party disclosure; the institution is the customer and controller

7.2 Providers that never receive children’s information

Google Analytics, Semrush, Mailchimp and ActiveCampaign operate on the classe365.com marketing website only. They never receive student or candidate records from the platform, and they never receive information about a child.

We state this plainly because it is one of the questions school administrators and security teams ask us most often. These four tools sit on our public marketing website and support our own business marketing. They have no connection to the authenticated platform, no access to institution tenants, and no route by which a child’s record could reach them.

7.3 Optional services an institution enables and contracts for itself

  • SMOWL — online quiz proctoring. The institution chooses to enable it and contracts with SMOWL directly under SMOWL’s own terms. Any biometric processing occurs under SMOWL’s terms, not ours.
  • Zapier — customer-configured automation. The customer controls what data flows to it and is responsible for that flow.

These are not our sub-processors. When an institution turns one on, the institution takes responsibility for that provider’s handling of the data it receives, and for telling parents about it.

We may disclose information where we are legally required to — for example in response to a valid court order, warrant or regulatory demand. Where we act as processor and the law permits, we will notify the institution before disclosing its data so that it can respond, and we will disclose no more than we are legally obliged to disclose.

8.1 The rule

The 2025 amendments require that a parent be able to consent to the collection and use of a child’s personal information without also being required to consent to its disclosure to third parties, unless that disclosure is integral to the service the child is using. Consent to disclosure must be obtained separately. It cannot be bundled into a single acceptance, and it cannot be a condition of the child using the service where the disclosure is not integral.

We apply that rule as follows.

8.2 The one integral disclosure: Amazon Web Services

Amazon Web Services is the only disclosure that is integral to the platform. Classe365 runs on AWS infrastructure. The child’s record is stored there, served from there and backed up there. There is no version of the service in which the record does not reach AWS, and no configuration in which AWS can be switched off. A parent cannot consent to their child using Classe365 while declining hosting on AWS, because the two cannot be separated.

Standard customers are hosted in the us-east-1 region (Northern Virginia, United States). On request, data can be located in the nearest available AWS region to the customer. Enterprise customers may take an optional private cloud deployment on Amazon Web Services, Microsoft Azure or Google Cloud; where an institution has taken that option, its chosen cloud provider replaces AWS as the integral hosting disclosure for that institution’s tenant, and the institution can tell parents which provider it uses.

The following four disclosures are not integral. Each is presented to the parent as an independent choice, none is pre-ticked, and each can be given or withheld without affecting the other three.

Optional disclosureWhat it is forWhat happens if consent is not given
Intercom — customer support messagingAllows a support conversation about the child to be handled through our support messaging platform, so that a query about the child’s record can be answeredSupport for that child’s record is handled without routing the child’s information through Intercom. Support for the institution continues; the response may take longer where the query cannot be investigated through the normal support channel
Atlassian — engineering issue tracking and fault diagnosisAllows a fault affecting the child’s record to be recorded and diagnosed by our engineers in our issue tracking systemA fault affecting that child’s record is investigated without placing the child’s information into the issue tracker. Diagnosis of a fault specific to that record may take longer
Stripe — payment processingAllows fees relating to the child to be paid online through StripeFees relating to the child are paid by another method the institution offers. The child’s access to the platform is unaffected
PayPal — payment processingAllows fees relating to the child to be paid online through PayPalFees relating to the child are paid by another method the institution offers. The child’s access to the platform is unaffected

8.4 Refusing an optional disclosure does not affect the child’s access

A parent who consents only to the collection and use of their child’s information, together with the integral hosting disclosure to Amazon Web Services, gets the full educational service. The child’s account, lessons, coursework, assessments, attendance, reports and communications all work exactly as they would otherwise. We do not degrade, limit or withdraw a child’s access to the platform because a parent has declined an optional disclosure, and we do not ask an institution to.

8.5 How the choices are presented

Where an institution uses the platform’s consent workflow, the four optional disclosures are presented as four separate, individually selectable items, each with its own explanation, none selected in advance. The required item — collection and use for the educational service, including hosting with Amazon Web Services — is presented separately and identified as required. The Direct Notice to Parents is the notice a parent reads before making those choices.

Where an institution collects consent by its own means, it is responsible for presenting the same four choices separately and for telling us the outcome, and we honour what it records.

Consent decisions recorded through the platform are stored against the child’s record, with the date and the identity of the parent or guardian who made them, so that the institution can demonstrate what was consented to and when. Those records are part of the child’s record and are deleted with it.

A parent may withdraw consent to any of the four optional disclosures at any time, without giving a reason, and without affecting the other three or the child’s access to the platform.

A withdrawal can be given to the institution, which will record it in the platform, or sent to us at clientservice@classe365.com, in which case we will acknowledge it, identify the institution concerned and pass it on without undue delay. We will act on a withdrawal recorded in the platform whether the institution recorded it or we did.

  1. We stop the disclosure. From the point the withdrawal is recorded, no further information about that child is sent to the provider concerned.
  2. We ask the provider to delete the information about that child that it already holds, and we confirm to the institution when that is done.
  3. Where the provider is Intercom or Atlassian, any existing support conversation or engineering ticket containing that child’s information is closed and the child’s information is removed from it.
  4. Where the provider is Stripe or PayPal, no further payment relating to that child is processed through that provider. Records of payments already made are retained where we or the institution are required by tax, accounting or financial law to keep them, and for no longer than that requirement demands.
  5. The withdrawal is recorded against the child’s record with the date it took effect.

Withdrawal does not undo processing that was lawfully carried out before the withdrawal took effect.

9.3 Refusing further collection altogether

A parent may refuse to permit any further collection or use of their child’s personal information. Because the institution controls the record, that decision has consequences for the child’s enrolment that only the institution can explain — a child’s record is how a school runs the child’s education. A parent who wants to refuse further collection should raise it with the institution, which will tell us. Where such a request reaches us first, we acknowledge it, identify the institution, pass it on without undue delay, and tell the parent who to expect a response from. Where the institution instructs us to stop further collection for a child, we do so, and we delete the child’s information on the institution’s instruction under section 10.

10. How long children’s information is kept, and when it is deleted

10.1 Published retention schedule

The amended Rule requires operators to publish a retention schedule with deletion timelines rather than describe retention in general terms. This is ours, and it is the same schedule we publish for all customer data.

Data categoryRetention
Student or candidate record after the institution deletes it7 days, then permanent deletion
All customer data after subscription termination30 days, then permanent deletion
Support correspondence24 months from resolution
Server and security logs30 days
Marketing and CRM contact data36 months from last engagement
BackupsEach daily backup retained 7 days

Marketing and CRM contact data is never data about a child. We hold no marketing records about children, and children are never added to any marketing list.

10.2 We keep a child’s information only as long as it is needed

A child’s record is held for as long as the institution needs it for the education purpose it was collected for, and no longer. The institution decides when that purpose has ended and deletes the record. We do not retain a child’s information indefinitely, and we do not retain it for any purpose of our own once the institution has deleted it.

10.3 The 7-day backup consequence, stated plainly

We take daily backups. Each daily backup is retained for 7 days on a rolling basis, which gives an institution a seven-day restore window: it may request restoration from any of the preceding 7 days. Backups are maintained for the life of an active subscription.

Because of that rolling window, a child’s record deleted by an institution persists in backups for no more than 7 days. After 7 days the last backup containing it has itself expired and the record is gone. That is why the retention line for a deleted student record reads “7 days, then permanent deletion” — the 7 days is the backup tail, not a period during which we continue to use the record. Once a record is deleted from the live platform it is no longer accessible in the platform, is not used for any purpose, and is not restored except on the institution’s own request within that window.

10.4 On termination

When an institution’s subscription ends, all of its customer data, including children’s records, and all backups containing that data, are deleted within 30 days.

10.5 Longer retention where the law requires it

We keep financial and tax records for the period required by applicable tax and company law, which may be longer than the periods above. Where we are subject to a legal hold, we retain the affected records until the hold is lifted, and no longer. Neither exception is used to retain a child’s education record for a purpose of our own.

11. What we never do with children’s information

These are commitments, not aspirations.

  1. We do not sell children’s personal information. There is no circumstance in which a child’s record is sold, licensed, rented or exchanged for value.
  2. We do not serve targeted advertising to children. No advertising of any kind is served inside the authenticated platform.
  3. We do not build advertising profiles. We do not create, buy, enrich or share a profile of a child for advertising or commercial purposes, and we do not share children’s information for cross-context behavioural advertising.
  4. We do not use children’s data to train, fine-tune or improve any general-purpose or shared AI model. Where an AI feature uses a model that learns from data, that model is trained only on that customer’s own data — it is per-tenant — and is used only for that customer. Data is never pooled across customers, and one customer’s data is never used to improve the service for another.
  5. We do not use children’s information for our own marketing. We send no marketing to children and no marketing to parents about our products.
  6. We do not condition a child’s participation on disclosing more information than is reasonably necessary for the child to take part in the activity concerned.
  7. We do not collect audio recordings of children’s voices.
  8. We do not perform facial or voice recognition, subject to the SMOWL qualification in section 4.4.

11.1 AI features and children

Institutions choose which AI features to enable. Where one is enabled and operates on a child’s record — for example grading analysis, attendance analysis, attrition tracking or behaviour analytics — all outputs are advisory. Decisions about a child remain with the institution and its staff. No automated decision produces a legal or similarly significant effect on a child without human review.

Where a user interacts with our AI chat assistant, we say in the interface that they are interacting with an AI system, reflecting the transparency obligations in Article 50 of the EU AI Act, which applied from 2 August 2026.

The Annex III high-risk obligations of the EU AI Act for education systems apply from 2 December 2027, following the deferral introduced by the Digital Omnibus. Attrition tracking, behaviour analytics and grading analysis fall within that scope. We commit to meeting those obligations by that date. We do not claim high-risk conformity now.

12. Access from India

Personnel of Classe365 India Pvt Ltd, located at 37, Venjay Edifice Complex, 3rd Floor, JLB Road, Chamarajapuram, Mysuru – 570 005, India, provide support and engineering services to the group and may access customer data, including children’s records, for those purposes.

This is a real and ongoing arrangement, not a contingency. Support tickets, fault diagnosis, data restoration requests, configuration assistance and engineering work on the platform may be handled by staff in Mysuru, and doing that work can require access to the records held in an institution’s tenant, including the records of children.

That access is subject to:

  • role-based, least-privilege access controls, so an individual can reach only the data needed for the task at hand;
  • authentication controls and audit logging of access;
  • written contractual confidentiality obligations binding on the affiliate and on individual personnel;
  • intra-group data transfer agreements between the contracting entities and Classe365 India Pvt Ltd;
  • the same instruction-bound limits that apply to us as processor — the data is used only to provide support and engineering services, never for any purpose of the affiliate’s own.

Classe365 India Pvt Ltd is a group affiliate acting for the contracting entity, not an independent third-party recipient, and access by its personnel is part of providing the core service. We disclose it because institutions need to know it to complete their own assessments, and because parents are entitled to know who can see their child’s record.

13. Our written children’s information security program

We maintain a written children’s information security program, established, implemented and maintained to protect the confidentiality, security and integrity of children’s personal information. It is documented, it is reviewed, and its elements are set out below.

13.1 Designated coordinator

A named individual is designated as the coordinator of the children’s information security program. The coordinator is responsible for the programme’s implementation and maintenance, for the annual risk assessment, for sub-processor due diligence in relation to children’s data, for the annual testing and review, and for reporting the results of that review to management. The coordinator is the internal point of escalation for any incident involving children’s information.

13.2 Annual risk assessment

At least once a year, we carry out and document a risk assessment covering internal and external risks to the confidentiality, security and integrity of children’s personal information. The assessment considers:

  • employee training and management, including who has access to children’s records and why;
  • the design and operation of the platform, including information processing, storage, transmission, retention and disposal;
  • the ability to prevent, detect and respond to attacks, intrusions and other systems failures;
  • the risks introduced by each sub-processor that receives children’s data.

Each identified risk is assigned an owner and a remediation plan, and the plans are tracked to completion.

13.3 Safeguards

We design, implement and maintain safeguards to control the risks identified in the assessment. The technical and organisational controls in place across the platform are:

  • hosting on Amazon Web Services infrastructure;
  • encryption of data in transit using TLS;
  • encryption of data at rest;
  • network segregation between environments and between tenants;
  • least-privilege access control, with access granted by role and reviewed;
  • an OWASP-aligned secure development lifecycle;
  • daily backups, retained for 7 days on a rolling basis;
  • DDoS protection;
  • continuous monitoring of systems and security events;
  • audit logging of access to records.

13.4 Sub-processor due diligence

Before we engage a service provider or sub-processor that will receive children’s personal information, we take reasonable steps to satisfy ourselves that it is capable of maintaining the confidentiality, security and integrity of that information, and we obtain written assurances that it will do so. We do this for each of Amazon Web Services, Intercom, Atlassian, Stripe and PayPal, and for Classe365 India Pvt Ltd as an intra-group provider.

Each provider is bound by a written contract that requires it to act only on our instructions, imposes confidentiality obligations, and requires security measures appropriate to the information it handles. We reassess each provider that receives children’s data at least annually as part of the review in section 13.6, and we monitor them in between.

13.5 Testing and monitoring

We test and monitor the effectiveness of the safeguards at least annually. Testing covers the operation of access controls, encryption, logging and monitoring, the backup and restoration process, and our incident response process. Findings are recorded, assigned an owner and remediated.

13.6 Annual evaluation and review

At least once a year, and whenever there is a material change to our business practices, our systems, our sub-processors or the risks we face, the coordinator evaluates and adjusts the programme in light of the results of the testing and monitoring, the risk assessment, and any incident. The review and its outcome are documented.

13.7 Certifications — stated accurately

A SOC 2 Type II audit is in progress and is expected to complete in December 2026. We do not hold a SOC 2 report today and do not claim one. We do not hold ISO 27001 certification and do not claim one. We will update this section when the position changes.

13.8 Breach notification

If we become aware of a personal data breach affecting customer data, including children’s records, we will notify the affected institution within 24 hours of becoming aware of it, with the information we have at that point, and will follow up as the investigation develops. Where we act as processor, the institution as controller decides whether and how to notify regulators, parents and individuals, and we support it in doing so with the information and technical assistance it needs.

14. Parental rights

A parent or guardian of a child under 13 has the right to:

  1. Review the personal information we hold about their child, and be told what categories are held, how they are used and who receives them.
  2. Refuse to permit further collection or use of their child’s personal information.
  3. Direct the deletion of their child’s personal information.
  4. Consent to collection and use without consenting to third-party disclosure, as set out in section 8, and to withdraw any optional consent at any time, as set out in section 9.
  5. Not be required to disclose more information than is reasonably necessary for the child to take part in an activity.

Parents in the European Union, the United Kingdom, Australia and other jurisdictions have further rights under their own law, including rights of access, correction, erasure, restriction, portability and objection. Those rights are described in the Privacy Policy and we honour them.

14.1 How to exercise these rights

Start with the institution. The institution controls the child’s record. It can act immediately, it holds the context, and it is the fastest route. Contact the school office, the registrar, student services, or the institution’s data protection contact.

If you cannot reach the institution, or you want to raise something with us directly, email clientservice@classe365.com. Tell us the child’s name, the institution, your relationship to the child, and what you want. We will help.

14.2 How requests are routed when we act as processor

Because the institution controls the record, a request that reaches us is handled like this:

  1. We acknowledge the request and identify the institution concerned.
  2. We forward the request to that institution without undue delay, because the institution is the controller and the decision is legally its to make.
  3. We tell you that we have done so, and who to expect a response from.
  4. We do not disclose, correct or delete records inside an institution’s tenant on our own initiative, and we do not act against the institution’s instruction. Doing so would mean overriding the controller and altering a child’s education record without the school’s knowledge.
  5. We give the institution whatever technical help it needs to fulfil the request — exports, searches, corrections, deletions and confirmations — as part of the service and at no extra charge.

There is one exception. Where a parent withdraws consent to one of the four optional disclosures in section 8, we act on that withdrawal as soon as it is recorded, and we tell the institution. A parent should never have to wait on an administrative process to stop an optional disclosure.

14.3 Verification

Before we act on a request about a child, we need to be satisfied that the person making it is the child’s parent or guardian. Where the institution handles the request, the institution verifies the relationship from its own records, which is usually the most reliable method available. Where we handle a request directly, we confirm details against the record held in the institution’s tenant and, where necessary, ask the institution to confirm the relationship. We will not ask you for a government-issued identity document unless there is no other way to verify a high-risk request, and we will not create a new record of one.

14.4 Response times

We respond to requests we control within one month of receiving a verifiable request. Where a request is complex, or where we have received several from you, we may extend by up to a further two months and will tell you within the first month, with the reason. For requests we forward to an institution, the institution’s own timeframe applies, and we will have passed the request on promptly.

14.5 No charge

We do not charge a parent for reviewing, correcting or deleting a child’s information, or for withdrawing a consent.

15. FERPA and other education law

Where an institution in the United States is subject to the Family Educational Rights and Privacy Act, a child’s records in the platform are education records and we act as a school official with a legitimate educational interest, under the direct control of the institution. Parents exercise inspection, correction and hearing rights through the institution. The institution designates what constitutes directory information and controls opt-outs through the platform; we do not designate or disclose directory information on our own initiative. Our full position is in the FERPA Compliance Statement.

Where an institution is subject to a state student privacy law, or to a children’s or education privacy law outside the United States, our commitments in sections 11, 13 and 14 apply regardless, and we support the institution in meeting its own obligations.

16. Hiree365 and children

Hiree365 has a minimum age of 16. It is not available to anyone under 16, and it has no users under 13. It is a campus recruitment and employability platform used by students seeking employment, by institutions running campus placement programmes, and by employers seeking candidates.

Because Hiree365 has no users under 13, COPPA’s parental consent requirements do not arise for it. If we became aware that a person under 16 had obtained a Hiree365 account, we would tell the institution and the account would be removed. Candidate privacy on Hiree365 is described in the Hiree365 Candidate Privacy Notice.

17. Changes to this policy

We review this policy at least annually and whenever we make a change that affects it.

Where a change materially affects how we handle children’s personal information, we will give at least 30 days’ notice before it takes effect, by email to institutional account contacts and by a notice on our website and in the platform, so that institutions can inform parents. Where a change would materially expand what is collected about a child, how it is used, or who receives it, the institution is responsible for obtaining fresh consent before the change applies to that child, and we support it in doing so. Minor corrections — a broken link, a clarified sentence, an updated address — take effect when published.

Every version carries a “Last updated” date and an “Effective” date at the top. The current version is dated 15 September 2026 and takes effect on 15 October 2026.

18. How to contact us

Privacy and children’s privacy enquiries: clientservice@classe365.com Support: clientservice@classe365.com Accessibility line: +61 2 9472 5000

Legal notices — United States customers: 365 Software, LLC 131 Continental Dr, Suite 305 Newark, DE 19713 United States

Legal notices — all other customers: Sprout On Web Pty Ltd 22 Palm Street St Ives, NSW 2075 Australia

If you write to us about a child, please tell us the child’s name, the institution the child attends, and your relationship to the child. It lets us route your request correctly the first time.

Classe365 and Hiree365 are operated by 365 Software, LLC (United States customers) and Sprout On Web Pty Ltd (all other customers), with support and engineering services provided by Classe365 India Pvt Ltd.