logoProduct suite arrow right

FERPA Compliance Statement

Effective from September 11, 2026
Applies to: United States educational agencies and institutions subject to the Family Educational Rights and Privacy Act that use Classe365 or Hiree365, and to the parents and eligible students whose education records those institutions hold in our platforms.

1. Purpose of this statement

1.1 What this document does

This statement sets out how Classe365 and Hiree365 handle education records under the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99 (“FERPA”). It explains the capacity in which we act, the limits we accept on our use of education records, how directory information is handled, how parents and eligible students exercise their rights, how long records are kept, and which sub-processors are involved.

It is written for the people who have to answer for FERPA inside an institution — registrars, student records officers, general counsel, district data privacy officers and information security teams — and for parents and eligible students who want to know what a vendor does with a school’s records.

1.2 Which platforms it covers

  • Classe365 — student information system, learning management system and CRM used by K-12 schools and districts, universities and colleges, academies and vocational training providers, and corporates running corporate training.
  • Hiree365 — campus recruitment and employability platform. Where an institution uses Hiree365 as part of its placement programme, the candidate records it holds about its own students are education records of that institution, and this statement applies to them.

1.3 Which entity contracts

United States institutions contract with:

365 Software, LLC A Delaware limited liability company Registered office: 131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, United States Registered agent: Legalinc Corporate Services Inc. Governing law: the State of Delaware, United States. Courts of the State of Delaware.

Institutions outside the United States contract with Sprout On Web Pty Ltd, ABN 72 138 602 418, registered office 22 Palm Street, St Ives, NSW 2075, Australia; business address 22 Giffnock Avenue, Macquarie Park, NSW 2113, Australia. Governing law: New South Wales, Australia. Courts of New South Wales. FERPA does not usually bind those institutions, but the substantive commitments in sections 5, 8 and 9 of this statement apply to every customer regardless of location.

Classe365 India Pvt Ltd, 37, Venjay Edifice Complex, 3rd Floor, JLB Road, Chamarajapuram, Mysuru – 570 005, India, is a group affiliate that provides support and engineering services to both contracting entities. Section 12 explains what that means for education records, and institutions should read it before completing a vendor assessment.

In this statement, “Classe365”, “we”, “us” and “our” mean the contracting entity for the institution together with the group affiliate that supports it. “Institution” means the educational agency or institution that is our customer.

Read this statement with our Privacy Policy, which is the master description of everything we do with personal information; the Personal Data Processing Agreement, which governs our processing on behalf of an institution; the Children’s Privacy Policy, which sets out our COPPA position for children under 13; the US State Privacy Notice; and the AI Use Statement. Where this statement and one of those documents both address a subject, the more specific document governs on that subject.

This statement is not legal advice to an institution about its own FERPA obligations. Those obligations are the institution’s, and an institution should apply its own judgement and take its own advice.

2. What FERPA is, and who it binds

2.1 The statute in short

FERPA is a United States federal law that protects the privacy of student education records. It applies to educational agencies and institutions that receive funds under a programme administered by the United States Department of Education. In practice that means nearly every public school district, public school, and most private and public colleges and universities.

FERPA gives parents rights over their children’s education records. Those rights transfer to the student when the student turns 18 or enrols in an institution of postsecondary education, at which point the student is an “eligible student”. The core rights are:

  1. the right to inspect and review the student’s education records;
  2. the right to request the amendment of records the parent or eligible student believes are inaccurate, misleading, or in violation of the student’s privacy rights, and to a hearing if the institution declines;
  3. the right to consent to disclosure of personally identifiable information from education records, subject to the exceptions FERPA allows; and
  4. the right to file a complaint with the United States Department of Education.

“Education records” means records that are directly related to a student and maintained by the institution or by a party acting for the institution. Records held in Classe365 on an institution’s behalf — enrolment, attendance, grades, transcripts, disciplinary records, coursework, financial records held against a student, and the fields an institution adds itself — are education records of that institution.

2.2 Who FERPA binds

FERPA binds the institution, not the vendor. We are not an educational agency or institution and we do not receive Department of Education funding. FERPA obligations rest with the institution.

That does not put us outside FERPA’s reach. FERPA reaches us through the institution: we may hold education records only on terms that let the institution meet its own obligations, and if we breached those terms the institution’s ability to disclose to us could be affected. We accept the obligations in this statement contractually, and we accept them as a condition of holding education records at all.

3. Our status: a school official with a legitimate educational interest

3.1 The school official exception

FERPA permits an institution to disclose personally identifiable information from education records, without prior written consent, to “school officials” whom the institution has determined to have a “legitimate educational interest” in the information (34 C.F.R. § 99.31(a)(1)). The regulations allow an institution to treat a contractor, consultant, volunteer or other outside party as a school official where that party:

  • performs an institutional service or function for which the institution would otherwise use its own employees;
  • is under the direct control of the institution with respect to the use and maintenance of education records;
  • is subject to the requirements of 34 C.F.R. § 99.33(a) governing the redisclosure of personally identifiable information; and
  • uses education records only for the purposes for which the disclosure was made.

3.2 Our position

Classe365 acts as a school official with a legitimate educational interest, under the direct control of the institution, in respect of the education records the institution places in the platform.

We meet each element:

We perform an institutional service or function. Running a student information system, a learning management system and a placement platform is work an institution would otherwise do with its own staff and its own systems. We do it for the institution, under contract.

We are under the direct control of the institution. The institution decides what is collected, from whom, and for what purpose. It configures the forms, fields, workflows, permissions and integrations. It decides who among its own staff sees what. It decides when a record is created, corrected and deleted. We process education records only to provide the service and only on the institution’s documented instructions, as set out in the Personal Data Processing Agreement. We do not change, disclose or delete records inside an institution’s tenant on our own initiative.

We accept the redisclosure limits in § 99.33(a). We do not redisclose personally identifiable information from education records except on the institution’s behalf, at the institution’s direction, and only to the recipients described in section 11 of this statement. Where we do redisclose on the institution’s behalf, it is for the purposes for which the institution disclosed to us, and the recipient is bound by written contract to the same limits. Where the institution is required to record a disclosure, we provide the information it needs to do so.

We use education records only for the purposes for which the disclosure was made — providing, supporting, securing and maintaining the platform for that institution.

3.3 What the institution must do to rely on the exception

Two things are the institution’s to do, and we cannot do them for it:

  1. The institution must specify in its annual FERPA notification the criteria by which it determines who is a school official and what constitutes a legitimate educational interest, in terms broad enough to cover a contracted service provider such as us. Section 9 explains this.
  2. The institution must use reasonable methods to ensure that a school official obtains access only to the education records in which that official has a legitimate educational interest. The platform’s role-based access controls exist precisely so an institution can do that, both for its own staff and for the scope of the tenant it grants us.

We support both. On request we provide the description of our services, our access controls and our sub-processors that an institution needs for its own vendor assessment and notification.

4. Limits on our use of education records

We accept the following limits. They apply to every education record in the platform, for every customer.

  1. Purpose limitation. We use education records only to provide the contracted service to the institution: creating and maintaining student records, admissions, enrolment, timetabling, attendance, assessment, grading, progression, learning delivery, fee and payment records, placement activity in Hiree365, communications, reporting and analytics for that institution’s own cohort, technical support, fault diagnosis, data restoration, audit logging and security.
  2. Instruction limitation. We act only on the institution’s documented instructions, and we tell the institution if we consider an instruction to breach applicable law.
  3. No independent use. We do not use education records for any purpose of our own. We do not analyse them for product research across customers, we do not aggregate them with other customers’ records, and we do not derive any commercial benefit from them beyond the subscription fee the institution pays.
  4. No redisclosure except as permitted. See section 11.
  5. Tenant separation. Each institution’s records are held in a separated tenant. One institution’s records are never visible to another and never combined with another’s.
  6. Minimum access. Access by our personnel is role-based and least-privilege, granted for a defined task, authenticated and logged.
  7. Return and deletion. On the institution’s instruction, and on termination, we return or delete education records as set out in section 8.

5. Advertising, sale, and AI training — explicit commitments

These are the three questions districts ask most often, so we answer them without qualification.

5.1 Education records are not used for advertising

We do not use education records for advertising. We do not serve advertising of any kind inside the authenticated platform. We do not use education records to target, select, deliver or measure advertising. We do not build, buy, enrich or share advertising or marketing profiles from education records. We do not share education records for cross-context behavioural advertising. Students are never added to a marketing list, and marketing and advertising cookies are not served to authenticated student users.

The tools that support our own business marketing — Google Analytics, Semrush, Mailchimp and ActiveCampaign — operate on the classe365.com marketing website only. They never receive student records from the platform. There is no route by which an education record could reach them.

5.2 Education records are not sold

We do not sell education records. There is no circumstance in which student personally identifiable information is sold, licensed, rented, traded or otherwise exchanged for value or other consideration. Our revenue comes from subscription fees paid by institutions, and from nothing else.

5.3 Education records are not used to train shared AI models

We do not use customer, student or candidate data to train, fine-tune or improve any general-purpose or shared AI model.

Where a feature in the platform uses a model that learns from data, that model is trained only on that customer’s own data — it is per-tenant — and is used only for that customer. Data is never pooled across customers, and one institution’s records are never used to improve the service for another institution.

The AI features the platform offers are an AI chat assistant, an agent automation and workflow engine, grading analysis, attendance analysis, attrition tracking, behaviour analytics, a writing assistant, and AI plagiarism checking. An institution chooses which to enable.

All AI outputs are advisory. Decisions about students remain with the institution and its staff. No automated decision produces a legal or similarly significant effect on a student without human review. Where a user interacts with our AI chat assistant, the interface says so.

Institutions with students in the European Union should note that the Annex III high-risk obligations of the EU AI Act for education systems apply from 2 December 2027, following the deferral introduced by the Digital Omnibus; attrition tracking, behaviour analytics and grading analysis fall within that scope. We commit to meeting those obligations by that date. We do not claim high-risk conformity now. The transparency obligations in Article 50 applied from 2 August 2026 and we meet them.

6. Directory information

Districts ask about directory information more often than any other single FERPA topic, and the answer is short.

6.1 What directory information is

FERPA allows an institution to designate certain categories of information from education records as “directory information” — information that would not generally be considered harmful or an invasion of privacy if disclosed. Typical designations include a student’s name, address, telephone listing, email address, photograph, date and place of birth, major field of study, dates of attendance, enrolment status, participation in officially recognised activities and sports, degrees and awards received, and the most recent educational institution attended.

An institution may disclose directory information without consent only if it has given public notice of the categories it has designated and of the parent’s or eligible student’s right to refuse the designation for that student, and has allowed a reasonable period for that refusal.

6.2 Our position, stated plainly

The institution designates what constitutes directory information. The institution controls opt-outs. We do not designate directory information, and we do not disclose directory information on our own initiative.

To be specific:

  1. We do not decide what any institution’s directory information is. There is no default designation in the platform, and we do not supply one.
  2. We do not publish, release, sell or otherwise disclose any student information — designated as directory information or not — to any person or organisation outside the institution’s tenant, other than the sub-processors listed in section 11, which receive information solely to run the platform.
  3. We do not use directory information for our own marketing, for lead generation, or for any purpose of our own.
  4. We do not include student information in directories, listings, alumni products, data-sharing arrangements or partner integrations of our own.

6.3 How the platform supports directory information handling

The institution can record, against each student record, whether a parent or eligible student has opted out of the disclosure of directory information, and can use that flag to control how that student’s information is treated in exports, reports, listings and communications the institution generates. That flag is the institution’s to set and to act on, and the institution’s staff configure how it is applied. We honour the institution’s configuration; we do not override it, and we do not act on the flag independently of the institution.

If a parent or eligible student wants to opt out of directory information disclosure, the request goes to the institution, which is the only party that can act on it. We will pass on any such request that reaches us, and we will help the institution apply it in the platform.

6.4 Hiree365 and directory information

Hiree365 does not change this. In Hiree365, employers receive candidate personal data only via the institution. We do not disclose candidate data directly to employers, and the institution controls what is shared as part of its placement programme. No candidate information is published or shared by us as directory information or on any other basis. Section 10.4 explains this further.

7. Rights of parents and eligible students, and how they are exercised

7.1 The rights

A parent, or a student who has become an eligible student, has the right to:

  1. inspect and review the student’s education records;
  2. request amendment of a record the parent or eligible student believes is inaccurate, misleading or in violation of the student’s privacy rights;
  3. a hearing, if the institution decides not to amend the record as requested, and, if the outcome of the hearing is that the record will not be amended, to place a statement in the record commenting on the contested information and setting out the reason for disagreeing with the institution;
  4. consent to disclosure of personally identifiable information from education records, except where FERPA permits disclosure without consent;
  5. file a complaint with the Student Privacy Policy Office of the United States Department of Education concerning an alleged failure by the institution to comply with FERPA.

7.2 These rights are exercised through the institution

Parents and eligible students exercise inspection, correction and hearing rights through the institution. The institution holds the record, maintains it, and is the party FERPA gives the obligations to. It is also the only party that can convene a hearing, decide whether to amend a record, or accept a statement of disagreement into a record.

We cannot and do not:

  • grant a parent or eligible student direct access to an institution’s tenant on our own initiative;
  • amend or delete a record in an institution’s tenant on our own initiative;
  • decide whether a record is inaccurate or misleading;
  • conduct a hearing or decide its outcome.

Attempting any of those would mean overriding the institution and altering an education record without the school’s knowledge, which is precisely what the “direct control” element of the school official exception forbids.

7.3 What we do when a request reaches us

Requests do sometimes come to us first. When one does:

  1. We acknowledge the request and identify the institution concerned.
  2. We forward the request to that institution without undue delay, because the institution holds the obligation and the decision is legally its to make.
  3. We tell the person who made the request that we have done so, and who to expect a response from.
  4. We give the institution whatever technical assistance it needs to respond — see section 10.
  5. We do not disclose, amend or delete records inside an institution’s tenant on our own initiative, and we do not act against the institution’s instruction.

7.4 Timeframes

FERPA requires an institution to comply with a request to inspect and review education records within a reasonable period, and in any case not more than 45 days after the request is received. That obligation is the institution’s. Our commitment is that we will pass a request to the institution without undue delay, and that we will provide the institution with the exports, searches and technical assistance it needs within a timeframe that lets it meet the 45-day period comfortably. Where an institution tells us a request is urgent, we prioritise it.

8. Retention and deletion of education records

8.1 The institution decides retention

The institution decides how long it needs each education record and when to delete it. Many institutions are subject to state records-retention schedules that require them to keep certain records for years; those schedules are the institution’s to apply, and we do not delete records on our own timetable. Our retention periods below describe what happens after the institution deletes a record, or after the subscription ends.

8.2 Published retention schedule

Data categoryRetention
Student or candidate record after the institution deletes it7 days, then permanent deletion
All customer data after subscription termination30 days, then permanent deletion
Support correspondence24 months from resolution
Server and security logs30 days
Marketing and CRM contact data36 months from last engagement
BackupsEach daily backup retained 7 days

Marketing and CRM contact data is never student data. It consists of business contact records for staff at current and prospective customer organisations.

8.3 The 7-day backup window

We take daily backups. Each daily backup is retained for 7 days on a rolling basis, giving the institution a seven-day restore window: it may request restoration from any of the preceding 7 days. Backups are maintained for the life of an active subscription.

Because of that rolling window, an education record deleted by an institution persists in backups for no more than 7 days, after which the last backup containing it has expired and the record is permanently gone. During that period the record is not present in the live platform, is not accessible to users, and is not used for any purpose; it exists only so that the institution can recover from an error.

8.4 On termination

On termination of a subscription, all customer data, including education records, and all backups containing that data, are deleted within 30 days. Before deletion, and on request during the notice period, we provide the institution with an export of its data so that it can meet its own records-retention obligations. An institution should take that export before termination takes effect.

8.5 Longer retention where the law requires it

We retain financial and tax records for the period required by applicable tax and company law, which may exceed the periods above. Where we are subject to a legal hold, we retain the affected records until the hold is lifted and no longer. Neither exception is used to retain education records for a purpose of our own.

9. The institution’s annual notification

FERPA requires an institution to notify parents and eligible students annually of their rights under FERPA. That notification is the institution’s responsibility, not ours. We do not issue it and we cannot issue it on an institution’s behalf.

The annual notification must inform parents and eligible students of:

  • the right to inspect and review education records and the procedure for doing so;
  • the right to request amendment and the procedure for doing so;
  • the right to consent to disclosures, and the exceptions permitting disclosure without consent — including the school official exception;
  • where the institution relies on the school official exception, the criteria by which it determines who is a school official and what constitutes a legitimate educational interest;
  • the right to file a complaint with the United States Department of Education, and that office’s name and address.

If an institution wants to designate directory information, that public notice — of the categories designated and of the right to refuse designation — is also the institution’s to give.

What we provide. On request, and at no charge, we give an institution the material it needs to describe our role accurately in its notification: a description of the services we provide, confirmation of our status as a school official under the institution’s direct control, the list of sub-processors in section 11, our security controls, our retention schedule, and this statement. Institutions are free to reproduce or cite this statement in their own notices and vendor registers.

10. How we support the institution in responding to requests

Our support is part of the service, not a chargeable extra.

10.1 Inspection and review

We provide export and reporting tools that let an institution produce a complete copy of a student’s record, and where a request is unusual or spans several modules, our support team will help the institution assemble it. Where an institution asks, we produce the export for it.

10.2 Amendment

Institution staff can correct records directly in the platform. Where a correction is complex — a bulk correction, a correction to historical data, or one that touches records the institution’s own interface does not expose — our support and engineering teams make the change on the institution’s written instruction, and record what was changed.

10.3 Deletion

Institution staff can delete records directly. Where a deletion is bulk or complex, we carry it out on the institution’s written instruction. Deletion starts the retention timetable in section 8.

10.4 Disclosure records and audit trails

The platform keeps audit trails of access and changes within a tenant, which an institution can use to see who did what. Where an institution needs information about disclosures made through the platform in order to maintain the record of disclosures FERPA requires it to keep, we provide what we have.

10.5 Hearings

We do not conduct or participate in hearings. Where an institution needs the underlying record, its history, or evidence of what was in the system at a point in time in order to conduct a hearing, we provide it on request.

10.6 Subpoenas, court orders and law enforcement requests

If we receive a subpoena, court order or law enforcement demand for education records held in an institution’s tenant, we will, unless legally prohibited, notify the institution before responding so that it can seek to quash the order, notify the parent or eligible student as FERPA requires, or otherwise respond. We disclose no more than we are legally obliged to disclose. We do not volunteer education records to law enforcement.

10.7 Breach and unauthorised disclosure

If we become aware of a breach affecting customer data, including education records, we notify the affected institution within 24 hours of becoming aware, with the information available at that point, and follow up as the investigation develops. The institution decides whether and how to notify parents, eligible students and authorities, and we support it with the information and technical assistance it needs.

11. Sub-processors and redisclosure

11.1 Sub-processors that may receive student data

We use a small number of sub-processors to run the platform. Each is bound by a written contract, may act only on our instructions, is subject to confidentiality obligations, is assessed before engagement, and is monitored afterwards. Each is subject to the redisclosure limits in 34 C.F.R. § 99.33(a) as passed down through our contracts, and each uses education records only for the purpose for which we disclosed them.

Sub-processorPurposeLocation
Amazon Web ServicesCloud hosting and storageUnited States (us-east-1) or requested region
IntercomCustomer support messagingUnited States
AtlassianEngineering issue tracking and fault diagnosisUnited States / Australia
StripePayment processingUnited States
PayPalPayment processingUnited States

Hosting with Amazon Web Services is integral to providing the platform; the service cannot run without it. The others are engaged for support, engineering diagnosis and payment.

Where the records concerned are those of a child under 13, additional parental consent requirements apply to the four non-integral disclosures under the amended COPPA Rule. The Children’s Privacy Policy sets out how separate parental consent operates and how an institution records each parent’s choices.

11.2 Providers that never receive student data

Google Analytics, Semrush, Mailchimp and ActiveCampaign operate on the classe365.com marketing website only. They never receive student or candidate records from the platform. They have no connection to the authenticated platform, no access to institution tenants, and no route by which an education record could reach them.

11.3 Services the institution enables and contracts for itself

  • SMOWL — online quiz proctoring. The institution chooses to enable it and contracts with SMOWL directly under SMOWL’s own terms. Any biometric processing occurs under SMOWL’s terms, not ours. SMOWL is not our sub-processor. Where an institution enables it, the institution is responsible for the FERPA analysis of that disclosure, including whether SMOWL is a school official under the institution’s own criteria.
  • Zapier — customer-configured automation. The customer controls what data flows to it and is responsible for that flow, including its FERPA analysis.

11.4 Biometric identifiers

Classe365 and Hiree365 do not themselves collect, store or process biometric identifiers — including fingerprints, handprints, retina or iris patterns, genetic data, voiceprints, gait patterns, facial templates or faceprints — and do not perform facial or voice recognition. Institutions may choose to enable SMOWL, a third-party proctoring service, which they contract with directly; any biometric processing by SMOWL occurs under SMOWL’s own terms and privacy policy, not ours.

11.5 Government-issued identifiers

We do not require any government-issued identifier to provide the platform. Where an institution configures its own admission or enrolment forms to collect one — a social security number, for example — that identifier forms part of the education record, is subject to the same access controls and encryption as the rest of the record, and is held under the retention schedule in section 8. Institutions should note that a social security number is not permissible directory information.

12. Hosting, and access from India

12.1 Hosting

  • Standard customers: data is hosted on Amazon Web Services in the us-east-1 region (Northern Virginia, United States) by default.
  • On request: data can be located in the nearest available AWS region to the customer.
  • Enterprise customers: an optional private cloud deployment is available on Amazon Web Services, Microsoft Azure or Google Cloud.

12.2 Access from India — disclosed in full

Personnel of Classe365 India Pvt Ltd, located at 37, Venjay Edifice Complex, 3rd Floor, JLB Road, Chamarajapuram, Mysuru – 570 005, India, provide support and engineering services to the group and may access customer data, including student data and education records, for those purposes.

This is a real and ongoing arrangement, not a contingency. Support tickets, fault diagnosis, data restoration requests, configuration assistance and engineering work on the platform may be handled by staff in Mysuru, and doing that work can require access to the records held in an institution’s tenant.

That access is subject to:

  • role-based, least-privilege access controls, so an individual can reach only the data needed for the task at hand;
  • authentication controls and audit logging of access;
  • written contractual confidentiality obligations binding on the affiliate and on individual personnel;
  • intra-group data transfer agreements between the contracting entities and Classe365 India Pvt Ltd;
  • the same instruction-bound limits that apply to us as school official — education records are used only to provide support and engineering services, never for any purpose of the affiliate’s own.

Classe365 India Pvt Ltd personnel act for the contracting entity and are covered by the same school official commitments in this statement. FERPA does not prohibit a school official from being located outside the United States, but institutions are entitled to know where their records can be seen from, and many need it for their own vendor assessments and board reporting. We state it plainly for that reason.

13. Security

13.1 Controls in place

  • Hosting on Amazon Web Services infrastructure.
  • Encryption of data in transit using TLS.
  • Encryption of data at rest.
  • Network segregation between environments and between tenants.
  • Least-privilege access control, granted by role and reviewed.
  • An OWASP-aligned secure development lifecycle.
  • Daily backups, retained 7 days on a rolling basis.
  • DDoS protection.
  • Continuous monitoring of systems and security events.
  • Audit logging of access to records.
  • A written children’s information security program, with a designated coordinator, annual risk assessment, documented safeguards, sub-processor due diligence, and annual testing and review.

13.2 Certifications — stated accurately

A SOC 2 Type II audit is in progress and is expected to complete in December 2026. We do not hold a SOC 2 report today and do not claim one. We do not hold ISO 27001 certification and do not claim one. We will update this section when the position changes. We would rather an institution’s assessment record what we actually have than what we would like to have.

13.3 Breach notification

If we become aware of a personal data breach affecting customer data, we notify the affected institution within 24 hours of becoming aware of it. See section 10.7.

14. Complaints

An institution or an individual who believes we have not met the commitments in this statement should tell us at clientservice@classe365.com, setting out what happened and what they would like us to do. We investigate and respond.

A parent or eligible student who believes an institution has failed to comply with FERPA may file acomplaint with:

Student Privacy Policy Office United States Department of Education 400 Maryland Avenue, SW Washington, DC 20202-8520

A complaint about the handling of an education record by an institution is normally a matter for the institution and that office, because FERPA obligations rest with the institution.

15. Changes to this statement

We review this statement at least annually and whenever a change affects it. Where a change materially affects how we handle education records, we give at least 30 days’ notice before it takes effect, by email to institutional account contacts and by a notice on our website and in the platform, so that institutions can update their own notifications and vendor registers. Minor corrections take effect when published.

Every version carries a “Last updated” date and an “Effective” date at the top. The current version is dated 15 September 2026 and takes effect on 15 October 2026.

16. Contact

FERPA, privacy and vendor assessment enquiries: clientservice@classe365.com Support: clientservice@classe365.com Accessibility line: +61 2 9472 5000

Legal notices — United States customers: 365 Software, LLC 131 Continental Dr, Suite 305 Newark, DE 19713 United States

Legal notices — all other customers: Sprout On Web Pty Ltd 22 Palm Street St Ives, NSW 2075 Australia

Institutions completing a vendor privacy assessment, a district data-sharing agreement, or a student data privacy addendum should write to clientservice@classe365.com. We will provide the documentation we hold, and we will tell you plainly where we do not hold something rather than leave a gap for you to discover later.

Classe365 and Hiree365 are operated by 365 Software, LLC (United States customers) and Sprout On Web Pty Ltd (all other customers), with support and engineering services provided by Classe365 India Pvt Ltd.