logoProduct suite arrow right

Privacy Policy

Effective from September 11, 2026
Applies to: Classe365 and Hiree365, our websites, and all customer segments — K-12 schools, universities and colleges, academies and vocational training providers, and corporates using the platform for corporate training.

1. About this policy

1.1 What this policy is

This is the master privacy policy for Classe365 and Hiree365. It explains what personal information we handle, why we handle it, who we share it with, where it goes, how long we keep it, and what rights you have.

Classe365 is a student information system, learning management system and CRM for education institutions. Hiree365 is a campus recruitment and employability platform. Both are operated by the same group. This policy covers both unless a section says otherwise.

We have customers in more than 100 countries. This policy is written to work across those jurisdictions. Where a specific law gives you rights beyond what this policy describes, those rights still apply to you.

1.2 Who this policy is for

This policy applies to:

  • Institution staff — administrators, teachers, lecturers, trainers, placement officers, finance and IT staff who use the platform on behalf of an institution or corporate customer.
  • Students and learners — people enrolled at an institution or enrolled in corporate training, who use the platform or whose records are held in it.
  • Parents and guardians — people with a parent or guardian account, or whose details are recorded as a student’s contact.
  • Candidates — students and graduates using Hiree365 to seek employment.
  • Employers — organisations and their staff who use Hiree365 to run campus recruitment with an institution.
  • Website visitors and prospective customers — people who visit classe365.com, request a demonstration, start a free trial, or contact us.

This policy should be read together with:

  • the Children’s Privacy Policy, which covers children under 13 and our COPPA position;
  • the AI Use Statement, which explains how our AI features work and the limits we place on them;
  • the Cookie Policy, which explains cookies and similar technologies;
  • the Personal Data Processing Agreement (DPA), which governs our processing of customer data as a processor and sets out the transfer mechanisms we rely on;
  • the International Data Transfers page;
  • our Terms of Service.

Where this policy summarises a topic covered in more detail in one of those documents, the more detailed document governs.

2. Who we are and which entity contracts with you

We use a regional contracting model. The entity that contracts with a customer depends on where that customer is located.

2.1 United States customers

Customers located in the United States contract with:

365 Software, LLC A Delaware limited liability company Registered office: 131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, United States Registered agent: Legalinc Corporate Services Inc.

Governing law: the State of Delaware, United States. Courts of the State of Delaware.

2.2 All other customers

Customers located anywhere else — including the European Union, the United Kingdom, Australia and the rest of the world — contract with:

Sprout On Web Pty Ltd ABN 72 138 602 418 Registered office: 22 Palm Street, St Ives, NSW 2075, Australia Business address: 22 Giffnock Avenue, Macquarie Park, NSW 2113, Australia

Governing law: New South Wales, Australia. Courts of New South Wales.

2.3 Group affiliate

Classe365 India Pvt Ltd 37, Venjay Edifice Complex, 3rd Floor, JLB Road, Chamarajapuram, Mysuru – 570 005, India

Classe365 India Pvt Ltd provides support and engineering services to the contracting entities. Section 11 explains what this means for your data, and you should read it.

2.4 How we refer to ourselves

In this policy, “Classe365”, “we”, “us” and “our” mean the contracting entity for your institution together with the group affiliate that supports it. Where a distinction matters — for example, which entity is the controller of your information — this policy says so.

If you are a student, parent, candidate or member of staff and you want to know which entity holds your information, ask your institution, or contact us at clientservice@classe365.com and we will tell you.

3. Our two roles: processor and controller

This is the most important section in this policy, because it determines who decides what happens to your information and who you go to when you want something changed.

3.1 When we act as a processor

For everything inside the platform — student records, enrolment data, grades, attendance, timetables, fee records, learning content, communications between staff and students, candidate profiles and placement records — the institution or corporate customer is the controller and we are the processor. In United States terms, we are a service provider to the institution; under FERPA we act as a school official with a legitimate educational interest, under the direct control of the institution.

That means:

  • The institution decides what personal information is collected, from whom, and for what purpose.
  • The institution configures the forms, fields, workflows and integrations.
  • We process that information only to provide the service and only on the institution’s documented instructions.
  • We do not use it for our own purposes, we do not sell it, we do not use it for advertising, and we do not use it to train shared AI models.
  • Our obligations to the institution are set out in the Personal Data Processing Agreement.

3.2 When we act as a controller

We act as a controller for a narrow set of information that is genuinely our own:

  • account and administrative data for the institution’s contract — the named contacts, billing details, subscription and invoicing records;
  • support correspondence you send us directly;
  • information about visitors to our marketing website, and prospective customers who request a demonstration, download material or start a free trial;
  • security, audit and system logs we generate to keep the service safe and available;
  • our own marketing and CRM records about business contacts at current and prospective customers.

For this information we decide the purposes and means, and we answer directly for it.

3.3 Why the distinction matters to you

If you are a student, a parent, a candidate or a member of teaching staff, almost all of the information about you that sits in the platform is under your institution’s control, not ours. If you want a record corrected, deleted or explained, the institution is the right place to start, and it will usually be faster. We will help the institution do it, and we will never ignore a request that reaches us — see section 15 for how we route requests.

If you are a business contact who has spoken to our sales team, subscribed to our mailing list, or visited our website, we are the controller and you can come straight to us.

4. The personal information we collect

What we hold depends on who you are and how the institution has configured the platform. We do not require any category of information beyond what is needed to run the service; institutions frequently configure additional fields of their own choosing, and those fields are covered by this policy and by the retention schedule in section 13.

4.1 Institution staff and corporate administrators

  • Identity and contact details: name, work email address, telephone number, job title, department, employee or staff reference.
  • Account data: username, hashed password, authentication and single sign-on identifiers, multi-factor authentication settings, role and permission assignments.
  • Usage data: log-in times, IP address, device and browser information, pages and records accessed, actions taken within the platform, audit trail entries.
  • Communications: messages sent through the platform, support tickets, correspondence with our team.
  • Where the staff member is also the billing contact: billing name, address, and payment records (card and bank details are handled by our payment processors, not stored by us).

4.2 Students and learners

  • Identity details: name, date of birth, gender, photograph where the institution uploads one, student or learner reference number.
  • Contact details: address, email address, telephone number, emergency contact details.
  • Enrolment and academic records: programme, course and class enrolment, timetable, attendance, assessment submissions, grades and transcripts, progression and completion records, certificates and awards.
  • Learning activity: material accessed, submissions, discussion posts, quiz and assignment activity, and engagement data generated by use of the learning management system.
  • Pastoral and administrative records the institution chooses to keep, which may include behaviour and discipline notes, welfare notes, accommodation or accessibility arrangements, and health or dietary information where the institution records it.
  • Financial records: fees invoiced and paid, scholarships, concessions and payment plans.
  • Account and usage data: username, hashed password, log-in records, IP address, device and browser information, and platform activity logs.
  • Any additional field the institution adds to its own admission, enrolment or student forms.

Some of these categories — for example health information, or records revealing religious or ethnic background where an institution collects them — are special category data under the UK and EU GDPR and sensitive personal information under several United States state laws. We process them only because the institution has instructed us to hold them as part of the record, and we apply the safeguards in section 14.

4.3 Parents and guardians

  • Name, relationship to the student, address, email address and telephone number.
  • Account credentials and log-in records where the institution issues a parent portal account.
  • Communications with the institution and with us through the platform.
  • Consent records, including consents recorded under the Children’s Privacy Policy.
  • Payment and fee records where the parent or guardian is the payer.

4.4 Candidates (Hiree365)

  • Profile information: name, contact details, institution, programme and graduation year.
  • Curriculum vitae, résumé, cover letters, portfolios and supporting documents.
  • Skills, qualifications, certifications, work experience and preferences.
  • Application history: roles applied for, application status, interview scheduling, offers and outcomes.
  • Assessment and employability activity within the platform.
  • Account and usage data as described above.

Hiree365 has a minimum age of 16. It is not available to anyone under 16, and it has no users under 13.

4.5 Employers (Hiree365)

  • Contact details of the employer’s staff: name, work email address, telephone number, job title.
  • Organisation details: company name, industry, size, locations, recruitment requirements.
  • Account and usage data.
  • Records of vacancies posted, campus drives run, and interactions with institutions.

Employers receive student and candidate personal data only via the institution. We do not disclose candidate data directly to employers on our own initiative. The institution controls what is shared as part of its placement programme.

4.6 Website visitors and prospective customers

  • Information you give us: name, work email address, telephone number, organisation, country, role, and what you tell us about your requirements when you request a demonstration, start a free trial, download material, subscribe to a mailing list or contact us.
  • Information collected automatically on the marketing website: IP address, approximate location derived from it, browser and device type, referring page, pages viewed, time on page, and search terms that brought you to us.
  • Email engagement data for our marketing emails: whether a message was delivered, opened, and which links were followed.
  • Cookies and similar technologies as described in the Cookie Policy.

4.7 Information we do not collect

  • We do not collect audio recordings of children’s voices.
  • We do not require any government-issued identifier to provide the platform. See section 6.
  • We do not collect or process biometric identifiers ourselves. See section 5.

5. Biometric identifiers

Privacy laws in a growing number of jurisdictions treat biometric identifiers as a distinct and specially protected category of personal information. Our position is precise, and we state it in full.

Classe365 and Hiree365 do not themselves collect, store or process biometric identifiers — including fingerprints, handprints, retina or iris patterns, genetic data, voiceprints, gait patterns, facial templates or faceprints — and do not perform facial or voice recognition.

Institutions may choose to enable SMOWL, a third-party online quiz proctoring service, which they contract with directly. Any biometric processing by SMOWL occurs under SMOWL’s own terms and privacy policy, not ours.

If your institution has enabled SMOWL for proctored assessments, ask the institution for SMOWL’s privacy notice, or ask us and we will point you to the institution’s contact for it. SMOWL is not a sub-processor of ours; it is a service the institution procures for itself and switches on.

6. Government-issued identifiers

We do not require any government-issued identifier — such as a national identity number, social security number, tax number, passport number or driving licence number — to provide the platform.

Where an institution configures its own admission or enrolment forms to collect one, that identifier is treated as personal information, is subject to the same access controls and encryption as the rest of the student record, and is held under the retention schedule in section 13. The institution decides whether to collect it; we do not ask for it and we do not use it for any purpose of our own.

If you are asked for a government-issued identifier on a form inside the platform, that requirement comes from your institution. Questions about why it is being collected should go to the institution.

7. How we use personal information

7.1 As processor, on the institution’s instructions

  • Creating and managing student, learner and candidate records.
  • Running admissions, enrolment, timetabling, attendance, assessment, grading and progression.
  • Delivering learning content and managing coursework and submissions.
  • Managing fees, invoicing and payment records.
  • Producing reports and analytics for the institution about its own cohort.
  • Providing AI-assisted features the institution has enabled, within the limits in section 17.
  • Providing technical support, diagnosing faults and restoring data.
  • Keeping audit trails so the institution can see who did what.

7.2 As controller, for our own purposes

  • Establishing, administering and billing the customer relationship, and collecting payment.
  • Providing and improving support, and keeping a record of support correspondence.
  • Keeping the service secure, available and free of abuse: monitoring, logging, fraud and intrusion detection, and incident investigation.
  • Understanding how our marketing website is used, so we can improve it.
  • Sending marketing communications to business contacts about our products, events and content, subject to section 8.5 and to your right to opt out at any time.
  • Meeting our legal, tax, accounting and regulatory obligations, and establishing, exercising or defending legal claims.
  • Producing aggregated statistics that do not identify any individual — for example, total platform usage volumes.

7.3 What we never do

  • We do not sell personal information.
  • We do not share personal information for cross-context behavioural advertising.
  • We do not use student, candidate or education records for advertising, and we do not build advertising profiles from them.
  • We do not use customer, student or candidate data to train, fine-tune or improve any general-purpose or shared AI model.
  • We do not serve advertising inside the authenticated platform.

Where the UK GDPR or the EU GDPR applies, we rely on the following legal bases. Remember that for platform data the institution is the controller and chooses the legal basis for its own processing; the bases below are those we rely on for the processing we control, and those that support our processing as processor.

8.1 Performance of a contract (Article 6(1)(b))

We rely on this for administering the customer account, providing the service to the contracting institution, managing log-in and authentication, billing and collecting payment, and providing support to the people named under the contract.

8.2 Legitimate interests (Article 6(1)(f))

We rely on legitimate interests for:

  • keeping the platform and our systems secure, including logging, monitoring and abuse prevention — our interest is protecting the service and the people who use it;
  • diagnosing faults and improving the reliability of the service;
  • administering and developing our business relationship with institutional customers, including business-to-business marketing to professional contacts;
  • understanding how the marketing website performs, where analytics cookies are used with consent;
  • establishing, exercising or defending legal claims.

Where we rely on legitimate interests, we have considered the effect on you, and you may object at any time — see section 15.3.

8.3 Legal obligation (Article 6(1)(c))

We rely on this for retaining financial and tax records, responding to lawful requests from regulators and authorities, and meeting breach-notification and other statutory duties.

8.4 Vital interests (Article 6(1)(d))

In rare cases, information may be processed to protect someone’s life or physical safety — for example, where emergency contact information must be used in an emergency.

8.5 Consent (Article 6(1)(a))

We rely on consent for non-essential cookies and similar technologies on our marketing website, and for marketing emails where consent is required in your jurisdiction. You can withdraw consent at any time, and withdrawal does not affect processing carried out before you withdrew.

8.6 Special category data (Article 9)

Where an institution records health, disability, religious, ethnic or similar special category information, the institution is responsible for identifying its Article 9 condition. We process such data solely on the institution’s instructions and under the DPA. Where we hold special category information about our own staff-facing contacts — for example an accessibility requirement someone tells us about — we rely on explicit consent or, where applicable, the substantial public interest condition.

8.7 Children

Where processing relates to a child, the institution is responsible for obtaining any consent required by law, including parental consent under COPPA and any Article 8 GDPR consent for information society services. Our supporting role is described in the Children’s Privacy Policy.

9. Disclosure of personal information

We disclose personal information only as described below. We do not sell it.

9.1 To the institution

Where we act as processor, the institution has access to the records it controls. Students, parents and candidates should expect their institution to see their platform records.

9.2 To sub-processors

We use a small number of sub-processors to run the service. Sub-processors are bound by written contracts, may act only on our instructions, are subject to confidentiality obligations, and are assessed before engagement and monitored afterwards.

9.2.1 Sub-processors that may receive student or candidate data

Sub-processorPurposeLocation
Amazon Web ServicesCloud hosting and storageUnited States (us-east-1) or requested region
IntercomCustomer support messagingUnited States
AtlassianEngineering issue tracking and fault diagnosisUnited States / Australia
StripePayment processingUnited States
PayPalPayment processingUnited States

Hosting with Amazon Web Services is integral to providing the platform: the service cannot run without it. The others are engaged for support, engineering diagnosis and payment. Where children’s data is involved, the Children’s Privacy Policy explains how separate parental consent applies to the non-integral disclosures.

9.2.2 Providers that never receive student or candidate data

Google Analytics, Semrush, Mailchimp and ActiveCampaign operate on the classe365.com marketing website only. They never receive student or candidate records from the platform.

We say this explicitly because it is a question we are asked constantly by school administrators and security teams. These four tools sit on the public marketing website and on our own business marketing operations. They are used for website analytics, search performance analysis, and sending email to business contacts. They have no connection to the authenticated platform, no access to institution tenants, and no route by which a student or candidate record could reach them.

9.2.3 Optional services the institution enables and contracts for itself

  • SMOWL — online quiz proctoring. The institution chooses to enable it and contracts with SMOWL directly under SMOWL’s own terms. Any biometric processing occurs under SMOWL’s terms, not ours.
  • Zapier — customer-configured automation. The customer decides what data flows to it and is responsible for that flow.

These are not our sub-processors. When an institution turns them on, the institution takes responsibility for that provider’s handling of the data it receives.

9.3 Within the group

Personnel of Classe365 India Pvt Ltd provide support and engineeringservices and may access customer data. See section 11.

9.4 To employers, in Hiree365

Employers receive student and candidate personal data only via the institution, as part of the institution’s placement programme. We do not disclose candidate data directly to employers on our own initiative.

9.5 To professional advisers and in corporate transactions

We may disclose information to our auditors, insurers, lawyers and other professional advisers where they need it and are bound by confidentiality. If our business or a part of it is sold, merged or reorganised, information may be transferred to the acquiring party, subject to this policy and to the customer’s contract continuing to apply.

9.6 Where the law requires it

We may disclose personal information where we are legally required to — for example in response to a valid court order, warrant or regulatory demand. Where we act as processor and the law permits, we will notify the institution before disclosing its data so that it can respond, and we will disclose no more than we are legally obliged to disclose.

10. Hosting and where your data is stored

  • Standard customers: data is hosted on Amazon Web Services in the us-east-1 region (Northern Virginia, United States) by default.
  • On request: data can be located in the nearest available AWS region to the customer. Ask us before or during onboarding.
  • Enterprise customers: an optional private cloud deployment is available on Amazon Web Services, Microsoft Azure or Google Cloud.

If you are a student, parent or candidate and you want to know where your institution’s data is hosted, ask the institution, or contact us and we will confirm the region for that tenant.

11. International transfers, including access from India

11.1 Access from India — stated plainly

Personnel of Classe365 India Pvt Ltd, located at 37, Venjay Edifice Complex, 3rd Floor, JLB Road, Chamarajapuram, Mysuru – 570 005, India, provide support and engineering services to the group and may access customer data, including student data, for those purposes.

This is a real and ongoing arrangement, not a contingency. Support tickets, fault diagnosis, data restoration requests, configuration assistance and engineering work on the platform may be handled by staff in Mysuru, and doing that work can require access to the records held in a customer’s tenant, including student and candidate records.

That access is subject to:

  • role-based, least-privilege access controls, so an individual can reach only the data needed for the task at hand;
  • authentication controls and audit logging of access;
  • written contractual confidentiality obligations binding on the affiliate and on individual personnel;
  • intra-group data transfer agreements between the contracting entities and Classe365 India Pvt Ltd;
  • the same instruction-bound limits that apply to us as processor — the data is used only to provide support and engineering services, never for any purpose of the affiliate’s own.

We disclose this because institutions need to know it in order to complete their own data protection assessments, and because students and parents are entitled to know who can see their records.

11.2 Other transfers

Because we serve customers in more than 100 countries and host by default in the United States, personal information will in most cases be transferred across borders. Transfers occur:

  • to the United States, where our default hosting region and several sub-processors are located;
  • to Australia, where Sprout On Web Pty Ltd and part of our operations are located;
  • to India, as described above;
  • to any other AWS region a customer has asked us to use.

11.3 Transfer mechanisms

Where personal information is transferred out of the European Economic Area, the United Kingdom or another jurisdiction with transfer restrictions, we rely on the transfer mechanisms set out in our Personal Data Processing Agreement and described on our International Data Transfers page. Those documents set out the mechanisms and safeguards that apply, and they govern; we do not restate their terms here. Institutions that need the executed transfer documentation for their records should request it at clientservice@classe365.com.

12. How we keep information secure

12.1 Controls in place

  • Hosting on Amazon Web Services infrastructure.
  • Encryption of data in transit using TLS.
  • Encryption of data at rest.
  • Network segregation between environments and tenants.
  • Least-privilege access control, with access granted by role and reviewed.
  • An OWASP-aligned secure development lifecycle.
  • Daily backups.
  • DDoS protection.
  • Continuous monitoring of systems and security events.
  • A written children’s information security program, with a designated coordinator, annual risk assessment, documented safeguards, sub-processor due diligence, and annual testing and review.

12.2 Certifications — stated accurately

A SOC 2 Type II audit is in progress and is expected to complete in December 2026. We do not hold a SOC 2 report today and do not claim one.

We do not hold ISO 27001 certification and do not claim one.

We will update this section when the position changes.

12.3 Breach notification

If we become aware of a personal data breach affecting customer data, we will notify the affected customer within 24 hours of becoming aware of it, with the information we have at that point, and will follow up as the investigation develops. Where we act as processor, the institution as controller decides whether and how to notify regulators and individuals, and we support it in doing so.

12.4 What we ask of you

No system is immune from risk. Please protect your account: use a strong and unique password, enable multi-factor authentication where your institution offers it, do not share credentials, and tell your institution or clientservice@classe365.com immediately if you think an account has been compromised.

13. How long we keep information

We publish our retention periods rather than describing them in general terms.

Data categoryRetention
Student or candidate record after the institution deletes it7 days, then permanent deletion
All customer data after subscription termination30 days, then permanent deletion
Support correspondence24 months from resolution
Server and security logs30 days
Marketing and CRM contact data36 months from last engagement
BackupsEach daily backup retained 7 days

13.1 Backups and what the 7-day window means

We take daily backups. Each daily backup is retained for 7 days on a rolling basis, which gives customers a seven-day restore window: a customer may request restoration from any of the preceding 7 days. Backups are maintained for the life of an active subscription.

Because of that rolling window, a record deleted by an institution persists in backups for no more than 7 days, after which the last backup containing it has itself expired and the record is gone. This is why the retention line for a deleted student or candidate record is 7 days and then permanent deletion.

On termination of a subscription, backups are deleted together with all other customer data within 30 days.

13.2 Longer retention where the law requires it

We keep financial and tax records for the period required by the applicable tax and company law, which may be longer than the periods above. Where we are subject to a legal hold, we retain the affected records until the hold is lifted, and no longer.

14. Sensitive information

Where an institution records health information, disability or accessibility requirements, dietary requirements, welfare notes, or information that reveals racial or ethnic origin, religious belief or similar characteristics, that information is:

  • held only because the institution has chosen to record it;
  • restricted to the institution’s own tenant and to staff the institution has authorised;
  • subject to the same encryption, access control and audit logging as the rest of the record;
  • never used for advertising, never used to train shared AI models, and never disclosed except as set out in section 9;
  • deleted on the same schedule as the rest of the record.

We do not infer sensitive characteristics about anyone, and we do not enrich records with information from outside sources.

15. Your rights

15.1 Rights under the GDPR

If the UK GDPR or EU GDPR applies to you, you have the right to:

  1. Be informed — to know what is done with your personal information, which is what this policy is for.
  2. Access — to obtain confirmation of whether your personal information is processed and to receive a copy of it.
  3. Rectification — to have inaccurate information corrected and incomplete information completed.
  4. Erasure — to have your personal information deleted where one of the grounds in Article 17 applies.
  5. Restriction — to have processing restricted while an issue is resolved.
  6. Data portability — to receive information you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  7. Object — to object to processing based on legitimate interests, and to object to direct marketing at any time and without qualification.
  8. Withdraw consent — where processing is based on consent, at any time.
  9. Not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. As set out in section 17, our AI features are advisory and decisions about students remain with the institution and its staff.
  10. Complain to a supervisory authority — see section 20.

15.2 Rights under other laws

Residents of California and other United States states with comprehensive privacy laws should read our US State Privacy Notice, which sets out those rights and how to use them. Australian customers and individuals have rights of access and correction under the Australian Privacy Principles. Other jurisdictions give comparable rights, and we honour them.

15.3 How to make a request

  • If your information is held in the platform by an institution — the fastest route is your institution. It controls the record and can usually act immediately. Contact its administrator, registrar, student services or data protection contact.
  • If you deal with us directly — as a business contact, a website visitor, a prospective customer or a support correspondent — email clientservice@classe365.com with what you want and enough detail for us to find your information.

We do not charge for responding to a request. We may charge a reasonable fee, or decline, if a request is manifestly unfounded or excessive, and we will explain why if that happens.

15.4 How we verify a request

We will ask you to confirm information we already hold so that we can be satisfied you are who you say you are. We match what you tell us against our records. We will not ask for a government-issued identity document unless there is no other way to verify a high-risk request, and we will not create a new record of one. If we cannot verify you to a reasonable degree of certainty, we will tell you and explain what would allow us to proceed.

15.5 How requests are routed when we act as processor

This is the part that most often causes confusion, so we set it out step by step.

  1. If you send us a request about information held in an institution’s tenant, we will acknowledge it and identify the institution concerned.
  2. We will forward the request to that institution without undue delay, because the institution is the controller and the decision is legally its to make.
  3. We will tell you that we have done so, and who to expect a response from.
  4. We will not disclose, correct or delete records inside an institution’s tenant on our own initiative, and we will not act against the institution’s instruction. Doing so would mean overriding the controller and, in schools, potentially altering an education record without the school’s knowledge.
  5. We will give the institution the technical help it needs to fulfil the request — exports, searches, corrections, deletions and confirmations — and we do so as part of the service, not as an extra.

Where we are the controller, none of this applies: we deal with your request ourselves.

15.6 Response times

We respond to requests we control within one month of receiving a verifiable request. Where a request is complex or where we have received several from you, we may extend by up to a further two months and will tell you within the first month, with the reason. For requests we forward to an institution, the institution’s own timeframe applies, and we will have passed the request on promptly.

Under FERPA, parents and eligible students exercise inspection, correction and hearing rights through the institution. The institution designates what constitutes directory information and controls opt-outs through the platform; we do not designate or disclose directory information on our own initiative.

16. Children’s data

Children’s privacy is dealt with in a separate document, the Children’s Privacy Policy, which should be read alongside this one. It covers:

  • how the amended COPPA Rule applies to us and to institutions, including the compliance date of 22 April 2026;
  • school-based consent and the circumstances in which an institution may provide consent on a parent’s behalf;
  • separate consent — the fact that a parent may consent to collection and use without consenting to disclosure to third parties, except where the disclosure is integral to the service;
  • which disclosures are integral (hosting with Amazon Web Services) and which require separate consent (Intercom for support, Atlassian for engineering, and Stripe and PayPal for payments);
  • our published retention schedule and deletion timelines;
  • our written children’s information security program;
  • the commitment that we do not sell children’s data, do not serve targeted advertising to children, and do not build advertising profiles.

We do not collect audio recordings of children’s voices. Hiree365 has a minimum age of 16 and no users under 13.

If you are a parent or guardian with a question about a child’s information, contact the child’s institution first, or email clientservice@classe365.com and we will help you reach the right place.

17. AI features

Our AI features are described in full in the AI Use Statement. The essentials are these.

17.1 Our data commitment

We do not use customer, student or candidate data to train, fine-tune or improve any general-purpose or shared AI model.

Where a feature uses a model that learns from data, that model is trained only on that customer’s own data — it is per-tenant — and is used only for that customer. Data is never pooled across customers, and one customer’s data is never used to improve the service for another.

17.2 Features

The platform offers an AI chat assistant, an agent automation and workflow engine, grading analysis, attendance analysis, attrition tracking, behaviour analytics, a writing assistant, and AI plagiarism checking. Institutions choose which of these to enable.

17.3 Transparency

Where you interact with our AI chat assistant, you are interacting with an AI system and we tell you so in the interface. This reflects the transparency obligations in Article 50 of the EU AI Act, which applied from 2 August 2026.

17.4 High-risk obligations

The Annex III high-risk obligations of the EU AI Act for education and for employment and recruitment systems apply from 2 December 2027, following the deferral introduced by the Digital Omnibus. Attrition tracking, behaviour analytics, grading analysis and the Hiree365 candidate processes fall within that scope. We commit to meeting those obligations by that date. We do not claim high-risk conformity now.

17.5 Human oversight

All AI outputs are advisory. Decisions about students remain with the institution and its staff. No automated decision produces a legal or similarly significant effect without human review.

18. Cookies and similar technologies

Our use of cookies, pixels, local storage and similar technologies is described in the Cookie Policy. In summary: analytics and marketing cookies operate on the classe365.com marketing website, where they are set with consent where consent is required; the authenticated platform uses only the cookies and persistent identifiers needed to run it; and marketing and advertising cookies are not served to authenticated student users.

19. Marketing communications

We send marketing communications to business contacts at current and prospective customer organisations — for example, product news, event invitations and educational content. We do not send marketing to students, candidates or parents, and we do not use platform data to build marketing lists.

Every marketing email has an unsubscribe link, and it works. You can also email clientservice@classe365.com and ask to be removed. We retain marketing and CRM contact data for 36 months from last engagement, after which it is deleted.

Operational messages about your account, your subscription, security, or a change to these terms are not marketing, and you cannot unsubscribe from them while you hold an account.

20. Complaints

If you are unhappy with how we have handled your personal information, tell us first at clientservice@classe365.com. Set out what happened and what you would like us to do. We will investigate and respond.

If you are not satisfied with our response, you may complain to a regulator:

  • In the European Union, to the supervisory authority in the Member State where you live, work or where the issue arose.
  • In the United Kingdom, to the Information Commissioner’s Office.
  • In Australia, to the Office of the Australian Information Commissioner.
  • In the United States, to your state Attorney General, and in California to the California Privacy Protection Agency.
  • Elsewhere, to your national or state data protection authority.

If your complaint concerns information an institution controls, the institution is usually the correct respondent, and a regulator will normally deal with the controller.

21. Changes to this policy

We review this policy at least annually and whenever we make a change that affects it.

Where a change materially affects how we handle personal information, we will give at least 30 days’ notice before it takes effect, by email to institutional account contacts and by a notice on our website and in the platform. Minor corrections — a broken link, a clarified sentence, an updated address — take effect when published.

Every version carries a “Last updated” date and an “Effective” date at the top. The current version is dated 15 September 2026 and takes effect on 15 October 2026. Continuing to use the platform after a change takes effect means the updated policy applies to you; if you do not accept it, you or your institution may cancel in accordance with the Terms of Service.

22. How to contact us

General and privacy enquiries: clientservice@classe365.com Support: clientservice@classe365.com Accessibility line: +61 2 9472 5000

Legal notices — United States customers: 365 Software, LLC 131 Continental Dr, Suite 305 Newark, DE 19713 United States

Legal notices — all other customers: Sprout On Web Pty Ltd 22 Palm Street St Ives, NSW 2075 Australia

If you write to us about a privacy matter, say which institution you are connected with and in what capacity — staff member, student, parent, candidate or employer. It lets us route your request correctly the first time.

Classe365 and Hiree365 are operated by 365 Software, LLC (United States customers) and Sprout On Web Pty Ltd (all other customers), with support and engineering services provided by Classe365 India Pvt Ltd.