Sub-processor List
1. About this list
1.1 What this document is
This is our maintained public list of sub-processors. It names every third party that processes personal information on our behalf in connection with the Classe365 and Hiree365 platforms, what each one does, and where it is located.
It is published, not sent on request, because an institution should be able to see who will touch its students’ data before it starts a procurement process, not after.
1.2 The distinction this list draws
The list is divided into three sections, and the division is the most important thing in this document.
- Section 3 — sub-processors that receive student or candidate data. These are the ones that matter most to a school, a university or a parent. There are five.
- Section 4 — providers that operate on the marketing website only and never receive student or candidate records. Analytics and marketing tools sit here. They run on classe365.com. They are not connected to the platform where student records live.
- Section 5 — optional integrations that the institution enables and contracts for directly. These are not our sub-processors. The institution chooses them and has its own relationship with the provider.
Section 6 covers our group affiliate in India, which is not a third party but does have access to customer data and must therefore be disclosed here.
1.3 Which entity is responsible
Customers located in the United States contract with 365 Software, LLC, a Delaware limited liability company, registered office 131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, United States.
Customers located anywhere else — including the European Union, the United Kingdom, Australia and the rest of the world — contract with Sprout On Web Pty Ltd, ABN 72 138 602 418, registered office 22 Palm Street, St Ives, NSW 2075, Australia.
Support and engineering services are provided by Classe365 India Pvt Ltd, 37, Venjay Edifice Complex, 3rd Floor, JLB Road, Chamarajapuram, Mysuru – 570 005, India.
Together we are “Classe365”, “we”, “us” and “our”.
1.4 Roles
For student, learner and candidate records, the institution is the controller and we are the processor. The parties in section 3 are our sub-processors: they process personal information on our behalf, on our instructions, in order to help us deliver the platform to the institution. The institution’s authorisation of these sub-processors is dealt with in our Personal Data Processing Agreement.
1.5 Related documents
Read this list together with our Privacy Policy, our Children’s Privacy Policy, our Data Retention Schedule, our Security Statement, our AI Use and Transparency Statement and our Cookie Policy. Where personal data is transferred across borders, the transfer mechanisms set out in our Personal Data Processing Agreement and described on our International Data Transfers page govern, and we do not restate their terms here.
2. What we require of every sub-processor
Before a sub-processor is engaged, and for as long as it remains engaged:
- A written contract. Every sub-processor is bound by a written agreement imposing data protection obligations no less protective than those we owe our customers.
- Purpose limitation. It may process personal information only to perform the service we have engaged it for, and only on our instructions. It may not use it for its own purposes.
- No training of shared AI models. No sub-processor is permitted to use customer, student or candidate data to train, fine-tune or improve any general-purpose or shared AI model.
- No sale, no advertising. No sub-processor may sell student, learner or candidate data, use it for advertising, or build advertising profiles from it.
- Security. It must maintain appropriate technical and organisational security measures.
- Confidentiality. Its personnel must be bound by confidentiality obligations.
- Assistance. It must assist us in responding to data subject requests and in meeting our security and breach obligations.
- Deletion. It must delete or return personal information when we instruct it to, and when our engagement ends.
- Due diligence. We assess a sub-processor’s security and privacy posture before engagement and periodically afterwards, and this due diligence forms part of our written children’s information security program. Our Security Statement describes it.
We keep the number of sub-processors small deliberately. Every addition is another organisation with access to education data, and the list below is short because we treat lengthening it as a cost rather than a convenience.
3. Sub-processors that receive student or candidate data
These five sub-processors may process student, learner or candidate personal data in the course of providing their service to us.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting and storage | United States (us-east-1) or requested region |
| Intercom | Customer support messaging | United States |
| Atlassian | Engineering issue tracking and fault diagnosis | United States / Australia |
| Stripe | Payment processing | United States |
| PayPal | Payment processing | United States |
3.1 Amazon Web Services — cloud hosting and storage
AWS provides the infrastructure the platform runs on: compute, storage, databases and backups. All customer data held in the platform, including student, learner and candidate records, resides on AWS infrastructure.
Standard customers are hosted in us-east-1 (Northern Virginia, United States). On request, data can be located in the nearest available AWS region to the customer. Enterprise customers may opt for a private cloud deployment on AWS, Microsoft Azure or Google Cloud; where an enterprise customer chooses Azure or Google Cloud for such a deployment, that provider hosts that customer’s deployment in place of AWS under the arrangements agreed with that customer.
AWS is infrastructure, not an application that reads records. It stores and serves data at our direction and does not access the content of customer data for its own purposes.
Under the amended COPPA Rule, hosting is an integral disclosure. The platform cannot be delivered without infrastructure to run on. AWS is therefore the only disclosure of children’s personal information that is integral to the service, and it is not one a parent can decline while still receiving the service.
3.2 Intercom — customer support messaging
Intercom powers the in-platform and email support messaging through which users reach our support team. Personal information reaches Intercom in two ways: the identity and contact details of the person raising the request, and whatever that person includes in the message.
A support message about a student — a query about an enrolment record, a screenshot of a fault on a student’s page — necessarily contains student information. That is why Intercom appears in this section rather than in section 4.
We ask institutions not to include student personal information in support messages where an account reference or a record identifier will do. Support correspondence is retained for 24 months from resolution under our Data Retention Schedule, which is longer than a deleted student record is retained, so keeping student detail out of tickets is genuinely worthwhile.
Under the amended COPPA Rule, this is an optional disclosure requiring separate consent. A parent may consent to collection and use of their child’s information without consenting to disclosure to Intercom.
3.3 Atlassian — engineering issue tracking and fault diagnosis
Atlassian’s tools are where our engineering team records and tracks faults. When a defect affects specific records — a calculation producing the wrong result on a particular student’s grades, an import that has misplaced a cohort — diagnosing it can require the affected data to be referenced in the issue.
We restrict what is included to what is needed to reproduce and fix the fault, and issues are accessible only to the engineering personnel who need them.
Under the amended COPPA Rule, this is an optional disclosure requiring separate consent. A parent may consent to collection and use without consenting to disclosure to Atlassian.
3.4 Stripe — payment processing
Stripe processes payments. This covers subscription payments from institutions, and — where an institution uses the platform to collect fees — payments made by or on behalf of students and families.
Where a fee payment relates to a student, the payment record identifies who the payment is for, which is why Stripe appears in this section. We do not store full payment card numbers. Card data is handled by the payment processor under its own security controls and its obligations as a payment provider.
Under the amended COPPA Rule, this is an optional disclosure requiring separate consent. A parent may consent to collection and use without consenting to disclosure to Stripe.
3.5 PayPal — payment processing
PayPal processes payments on the same basis as Stripe, for institutions and payers who use it. The same position applies: fee payments can identify the student the payment relates to, we do not store full payment card numbers, and card data is handled by the payment processor under its own controls.
Under the amended COPPA Rule, this is an optional disclosure requiring separate consent. A parent may consent to collection and use without consenting to disclosure to PayPal.
3.6 Summary of the COPPA position
| Sub-processor | COPPA classification |
|---|---|
| Amazon Web Services | Integral to the service — hosting |
| Intercom | Optional — separate consent required |
| Atlassian | Optional — separate consent required |
| Stripe | Optional — separate consent required |
| PayPal | Optional — separate consent required |
Under the FTC’s COPPA Final Amendments (90 FR 16918, published 22 April 2025, effective 23 June 2025, compliance date 22 April 2026), parents may consent to the collection and use of a child’s personal information without consenting to third-party disclosure, except where the disclosure is integral to the service. Our Children’s Privacy Policy explains how separate consent is obtained and withdrawn.
4. Providers that operate on the marketing website only
The following providers never receive student or candidate records. They operate on the classe365.com marketing website only.
| Provider | Purpose | Receives student or candidate data? |
|---|---|---|
| Google Analytics | Website analytics for the marketing website | No |
| Semrush | Search and marketing performance analysis for the marketing website | No |
| Mailchimp | Business-to-business marketing email | No |
| ActiveCampaign | Business-to-business marketing email and CRM | No |
4.1 Why this distinction matters
This is a genuine architectural separation, not a labelling exercise, and it is one of the strongest things we can tell a reviewer.
The public marketing site and the authenticated platform are different environments. Analytics and marketing technologies run on the marketing site — the pages where someone reads about our products, requests a demonstration or starts a free trial. They do not run inside the authenticated platform, where student, learner and candidate records live. There is no path by which a student record reaches an analytics or marketing provider, because the tools are not present in the environment the records are in.
The practical consequence: a student logging in to check their timetable is not being measured by an analytics provider, is not being added to a marketing audience, and is not being profiled for advertising. A candidate in Hiree365 is not being tracked by a marketing tool. Nothing in this section touches a child’s record.
4.2 What these providers do see
They see activity on the public marketing website and interactions with our business-to-business marketing: which marketing pages are visited, how visitors arrive, and whether a business contact opened one of our marketing emails. The people concerned are staff at institutions and organisations who have engaged with us commercially. That data is held under the marketing and CRM category of our Data Retention Schedule — 36 months from last engagement.
4.3 Cookies and consent
Our Cookie Policy explains what each of these providers sets on your device, which category it falls into, and how consent is obtained in jurisdictions that require it. It also confirms that marketing and advertising technologies do not operate inside the authenticated platform.
5. Optional integrations enabled by the institution
The following are not our sub-processors. They are optional integrations that an institution chooses to enable and contracts for directly.
| Provider | Purpose | Contracting party | Our role |
|---|---|---|---|
| SMOWL | Online quiz proctoring | The institution contracts directly with SMOWL | We provide the integration point; SMOWL’s processing is under SMOWL’s own terms |
| Zapier | Customer-configured automation | The institution contracts directly with Zapier | The customer controls what data flows to it |
5.1 SMOWL — online quiz proctoring
SMOWL performs proctoring under its own terms. An institution that wants online proctoring chooses to enable SMOWL and contracts with SMOWL directly, under SMOWL’s own terms and privacy policy. SMOWL is not engaged by us and does not process data on our instructions.
This matters for biometrics, so we state our position exactly:
Classe365 and Hiree365 do not themselves collect, store or process biometric identifiers — including fingerprints, handprints, retina or iris patterns, genetic data, voiceprints, gait patterns, facial templates or faceprints — and do not perform facial or voice recognition.
Institutions may choose to enable SMOWL, a third-party proctoring service, which they contract with directly. Any biometric processing by SMOWL occurs under SMOWL’s own terms and privacy policy, not ours.
An institution enabling SMOWL should review SMOWL’s terms and privacy policy, satisfy itself about what SMOWL processes, and meet its own notice and consent obligations to the students concerned. Those obligations sit with the institution, because it is the institution that has chosen the service and entered into the contract.
5.2 Zapier — customer-configured automation
Zapier lets a customer connect the platform to other systems it uses and move data between them automatically. The customer controls what data flows to it. The customer builds the automation, chooses which fields it carries, and decides which destination systems receive them.
Because the customer configures the flow, the customer is responsible for what leaves the platform through it, for its contract with Zapier, and for the onward destinations it has connected. Institutions should treat a Zapier automation carrying student data as a disclosure of student data and govern it accordingly. Where children’s data is involved, an institution should consider whether such a flow is consistent with the consents it holds.
5.3 Institution-built integrations generally
The same principle applies to any integration a customer builds itself — through our APIs or otherwise. Where a customer directs data out of the platform to a system of its own choosing, the customer is responsible for that destination. It is not a sub-processor of ours and does not appear on this list, because we did not engage it and do not control it.
6. Group affiliate with access to customer data
Classe365 India Pvt Ltd 37, Venjay Edifice Complex, 3rd Floor, JLB Road, Chamarajapuram, Mysuru – 570 005, India Services: support and engineering
Personnel of Classe365 India Pvt Ltd provide support and engineering services and may access customer data, including student data, for those purposes.
We state this plainly, in this document and in our Privacy Policy, Security Statement, Data Retention Schedule and AI Use and Transparency Statement, because institutions and parents are entitled to know who can see student records. It is not buried, and it is not softened.
That access is subject to:
- access controls — least-privilege access, granted for the purpose and no wider;
- contractual confidentiality obligations binding on the entity and its personnel; and
- intra-group data transfer agreements governing the transfer of personal data within the group.
Classe365 India Pvt Ltd is part of the same group as the contracting entities. It is not a third party engaged at arm’s length, which is why it appears in its own section rather than in section 3. Where a transfer of personal data to India requires a transfer mechanism, the mechanisms set out in our Personal Data Processing Agreement and described on our International Data Transfers page govern.
7. How we notify you of changes to this list
7.1 Notice before a change takes effect
Before we add a new sub-processor that will receive student or candidate data, or replace an existing one, we will give at least 30 days’ notice before the change takes effect. Notice is given by:
- updating this list on classe365.com, with the new “Last updated” and “Effective” dates; and
- emailing institutional account contacts.
Institutions should make sure the contact we hold for them is a monitored address, and can ask us at clientservice@classe365.com to add or change the address that receives these notices.
7.2 Changes that do not require notice
A change of name, a corrected description, or a clarified location entry for a provider already on the list is a correction, not a new sub-processor, and takes effect when published. Removing a sub-processor takes effect when published — fewer parties with access is not a change anyone needs 30 days to prepare for.
7.3 Emergency changes
Very occasionally we may need to engage a sub-processor at short notice — to maintain security, to keep the service running, or to replace a provider that has failed. Where that happens, we will engage it under the requirements in section 2, update this list, and notify institutional account contacts as soon as we reasonably can, explaining what happened and why the ordinary notice period could not be met.
8. How to object to a change
8.1 Your right to object
An institution may object to the addition or replacement of a sub-processor on reasonable grounds relating to data protection.
8.2 How to object
Write to clientservice@classe365.com within the 30-day notice period, identify the sub-processor concerned, and explain the grounds for the objection. An objection from an institution’s authorised contact is enough — there is no form to complete.
8.3 What we do with an objection
We will work with the institution in good faith to address the concern. That may mean explaining the safeguards in place, providing further detail about the sub-processor’s role and security, agreeing a configuration in which the institution’s data is not processed by that sub-processor where that is technically possible, or proposing an alternative approach.
Where we cannot resolve the objection and the change would have a material adverse effect on the institution’s ability to meet its own data protection obligations, the institution may terminate the affected subscription in accordance with its agreement with us. We would rather lose a renewal than tell an institution it has no choice.
8.4 Objections about a sub-processor already on the list
The same address works for a concern about a sub-processor already engaged. Tell us the concern and we will answer it. We will provide the detail an institution reasonably needs to assess a sub-processor, subject to the confidentiality obligations we owe that provider.
8.5 Parents and students
If you are a parent, a student or a candidate, and you have a concern about who processes your or your child’s information, raise it with your institution, which controls the records and holds the relationship with you. You are also welcome to write to us at clientservice@classe365.com, and we will help the institution answer.
9. Changes to this document
We review this list at least annually, and whenever a sub-processor is added, removed or changed. Additions and replacements follow the notice process in section 7.
Each version carries a “Last updated” date and an “Effective” date at the top. The current version is dated 15 September 2026 and takes effect on 15 October 2026.
10. Contact us
Questions about this list, or to object to a change: clientservice@classe365.com Support: clientservice@classe365.com Accessibility line: +61 2 9472 5000
By post — United States customers: 365 Software, LLC 131 Continental Dr, Suite 305 Newark, DE 19713 United States
By post — all other customers: Sprout On Web Pty Ltd 22 Palm Street St Ives, NSW 2075 Australia
If you are completing a vendor assessment and need more detail about any party named here, write to us. We would rather answer the question than have it answered by assumption.
Classe365 and Hiree365 are operated by 365 Software, LLC (United States customers) and Sprout On Web Pty Ltd (all other customers), with support and engineering services provided by Classe365 India Pvt Ltd.
