logoProduct suite arrow right

US State Privacy Notice

Effective from September 11, 2026
Applies to: residents of United States states with comprehensive consumer privacy laws, in respect of Classe365 and Hiree365 and the classe365.com website.

1. Purpose and scope of this notice

1.1 What this notice does

This notice supplements our Privacy Policy. It sets out the disclosures and rights required by the comprehensive consumer privacy laws of United States states, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”).

Where this notice and the Privacy Policy differ for a resident of a state covered here, this notice governs for that person.

1.2 Which platforms and which entity

This notice covers Classe365, our student information system, learning management system and CRM for education institutions, and Hiree365, our campus recruitment and employability platform. It also covers the classe365.com marketing website.

Customers located in the United States contract with 365 Software, LLC, a Delaware limited liability company, registered office 131 Continental Dr, Suite 305, Newark, DE 19713, New Castle County, United States, registered agent Legalinc Corporate Services Inc. Customers located outside the United States contract with Sprout On Web Pty Ltd, ABN 72 138 602 418, of 22 Palm Street, St Ives, NSW 2075, Australia. Support and engineering services are provided by Classe365 India Pvt Ltd of 37, Venjay Edifice Complex, 3rd Floor, JLB Road, Chamarajapuram, Mysuru – 570 005, India.

If you are a United States resident, 365 Software, LLC is the entity that answers for the personal information described in this notice, working with the entity that holds the relevant contract.

1.3 Which state laws this notice addresses

This notice is written to meet the requirements of the comprehensive privacy laws now in force in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia. As further state laws come into force we will apply them, and we will update this notice.

Some of the rights described below are not available in every state, and some states use different words for the same idea — “consumer” in one law, “resident” in another; “sale” defined broadly in California and narrowly elsewhere. Where a right depends on your state, this notice says so. Where a state gives you a right that this notice does not describe, that right still applies to you, and asking us for it is enough.

1.4 Sector-specific laws still apply

Comprehensive state privacy laws are not the only rules that govern student information. The Family Educational Rights and Privacy Act (FERPA), the Children’s Online Privacy Protection Act (COPPA) and state student-data-protection statutes also apply, and in several cases those laws exempt data from the comprehensive state laws precisely because they already regulate it. Our FERPA position is set out in section 10 and in the Privacy Policy; our COPPA position is set out in the Children’s Privacy Policy.

2. Our two roles: service provider and controller

Everything in this notice depends on which of two roles we are in.

2.1 Service provider and processor to institutions

For personal information held inside the platform — student and learner records, enrolment data, grades, attendance, timetables, fee records, coursework, candidate profiles and placement records — the institution or corporate customer is the business or controller, and we are its service provider or processor.

In that role:

  • We process personal information only to perform the services set out in our written contract with the institution.
  • We do not retain, use or disclose it for any purpose other than performing those services, and we do not use it for a commercial purpose of our own.
  • We do not sell it and we do not share it for cross-context behavioural advertising.
  • We do not combine it with personal information we receive from another source, except as the applicable law permits a service provider to do.
  • Our contract with each institution contains the terms that state law requires of a service provider or processor contract, including the certification that we understand and will comply with those restrictions.
  • Under FERPA, we act as a school official with a legitimate educational interest, under the direct control of the institution.

Consumer rights requests about that information are directed to the institution. Section 8 explains how we route them.

2.2 Business and controller in our own right

We are the business or controller for a narrow category of information that is genuinely ours:

  • account and administrative records for an institution’s contract, including named contacts and billing details;
  • support correspondence sent to us directly;
  • information about visitors to classe365.com and about prospective customers who request a demonstration, download material or start a free trial;
  • security, audit and system logs we generate;
  • our own business marketing and CRM records about professional contacts.

For this information you can come straight to us, and we will handle your request ourselves.

2.3 Why the distinction matters

If you are a student, a parent or a candidate, the great majority of information about you sits in your institution’s tenant under its control. We cannot delete or alter a student’s education record on our own initiative — doing so would override the school and could destroy a record the school is legally required to keep. If you are a business contact, none of that applies and we act on your request directly.

3. Categories of personal information we collect

The table below uses the categories set out in the CCPA at Cal. Civ. Code § 1798.140(v). We collect these categories from the sources described in section 4, for the purposes described in section 5. We have collected each of these categories within the twelve months preceding the date of this notice.

CCPA categoryDo we collect it?Examples
A. IdentifiersYesName, postal address, email address, telephone number, account username, unique student, learner or candidate reference, IP address, device and cookie identifiers
B. Personal information under Cal. Civ. Code § 1798.80(e)YesName, address, telephone number, education records, employment history, financial and fee information
C. Protected classification characteristicsYes, where an institution records themDate of birth and age, gender, disability or accessibility requirements, and where an institution chooses to record them, characteristics such as ethnicity or religion
D. Commercial informationYesSubscription and licence records, invoices, fees charged and paid, payment history, products and services purchased or considered
E. Biometric informationNoSee section 7
F. Internet or other electronic network activity informationYesLog-in records, pages and records accessed, actions taken in the platform, browsing activity on classe365.com, email open and click data for our business marketing
G. Geolocation dataApproximate onlyApproximate location derived from IP address. We do not collect precise geolocation
H. Sensory or surveillance dataNoWe do not collect audio, electronic, visual, thermal or similar information. We do not collect audio recordings of children’s voices
I. Professional or employment-related informationYesJob title, department, employer, work history and preferences in Hiree365, staff role and permissions
J. Non-public education information under FERPAYesEnrolment, timetable, attendance, assessment submissions, grades, transcripts, progression, discipline and pastoral records held on the institution’s instructions
K. Inferences drawn from the aboveLimitedAnalytics generated for an institution about its own cohort, such as attendance patterns or attrition risk, produced by features the institution has enabled. We do not draw inferences to build consumer profiles for our own purposes and we do not create advertising profiles

We do not collect a government-issued identifier in order to provide the platform. Where an institution configures its own admission or enrolment form to collect one, that identifier is treated as personal information and held under the retention schedule in our Privacy Policy.

4. Where we get personal information

  • From you, when you create or use an account, complete a form, contact support, request a demonstration, start a free trial, or subscribe to a mailing list.
  • From your institution or employer, when it uploads or enters records, imports data from another system, or configures the platform.
  • From your device, automatically, through cookies and similar technologies on classe365.com, and through server logs generated by using the platform.
  • From our service providers, such as payment processors confirming a transaction, or support tooling recording a conversation you started.

We do not buy personal information from data brokers and we do not enrich records with information purchased from outside sources.

5. Why we collect it — business and commercial purposes

We use personal information for the following purposes, which correspond to the “business purposes” recognised by state law:

  1. Providing, operating and maintaining Classe365 and Hiree365 for the institution that has engaged us.
  2. Running admissions, enrolment, timetabling, attendance, assessment, grading, progression, fees, learning delivery, campus recruitment and placement.
  3. Providing customer support, diagnosing and fixing faults, and restoring data.
  4. Auditing interactions with the service and maintaining audit trails for institutions.
  5. Detecting and preventing security incidents, fraud and malicious or illegal activity, and protecting the safety of users.
  6. Debugging to identify and repair errors that impair intended functionality.
  7. Short-term, transient use, including for non-personalised presentation of content within the platform.
  8. Internal research for technological development and demonstration, subject to the AI limits in section 11.
  9. Verifying and improving the quality and safety of the service.
  10. Administering and billing the customer relationship, and collecting payment.
  11. Business-to-business marketing to professional contacts at current and prospective customer organisations.
  12. Complying with our legal obligations, and establishing, exercising or defending legal claims.

6. Disclosure of personal information

6.1 We do not sell personal information and we do not share it for cross-context behavioural advertising

We do not sell personal information, and we have not sold personal information in the twelve months preceding the date of this notice.

We do not share personal information for cross-context behavioural advertising, as that term is defined in the CCPA, and we have not done so in the twelve months preceding the date of this notice.

We do not sell or share the personal information of any consumer we know to be under 16 years of age. Because we do not sell or share personal information at all, we do not offer a “Do Not Sell or Share My Personal Information” mechanism — there is nothing for it to switch off. We do not engage in targeted advertising to students, and we do not profile individuals in furtherance of decisions that produce legal or similarly significant effects, other than as described in section 11.

6.2 Who we disclose personal information to, for a business purpose

We disclose personal information to the following categories of recipient, for the business purposes set out in section 5.

Service providers and processors that may receive student or candidate data:

RecipientPurposeLocation
Amazon Web ServicesCloud hosting and storageUnited States (us-east-1) or a requested region
IntercomCustomer support messagingUnited States
AtlassianEngineering issue tracking and fault diagnosisUnited States / Australia
StripePayment processingUnited States
PayPalPayment processingUnited States

Each of these is engaged under a written contract that limits it to processing on our instructions, prohibits retention, use or disclosure for its own purposes, and imposes confidentiality obligations.

Providers that never receive student or candidate data:

Google Analytics, Semrush, Mailchimp and ActiveCampaign operate on the classe365.com marketing website only. They never receive student or candidate records from the platform. They are used for website analytics, search performance analysis, and email to business contacts. They have no access to the authenticated platform or to any institution’s tenant.

Optional services an institution enables and contracts for itself:

  • SMOWL — online quiz proctoring, contracted by the institution directly under SMOWL’s own terms.
  • Zapier — customer-configured automation, where the customer decides what data flows to it.

These are not our service providers. When an institution turns one on, that institution takes responsibility for the provider’s handling of the data it receives.

Group affiliate: Classe365 India Pvt Ltd, for support and engineering services. Its personnel in Mysuru, India may access customer data, including student data, for those purposes, under role-based least-privilege access controls, audit logging, written confidentiality obligations and intra-group data transfer agreements. We state this plainly because institutions need it for their own assessments.

Other recipients: the institution that controls the record; professional advisers under confidentiality; a party acquiring our business or part of it, subject to this notice continuing to apply; and government or regulatory bodies where we are legally required to disclose. Where we act as service provider and the law permits, we notify the institution before disclosing its data.

6.3 Categories disclosed

In the twelve months preceding the date of this notice, we disclosed for a business purpose the categories of personal information marked “Yes” in the table at section 3 — that is, categories A, B, C, D, F, G, I, J and the limited inferences in K — to the categories of recipient listed in section 6.2. We disclosed no personal information for monetary or other valuable consideration.

7. Sensitive personal information

Several state laws define a category of sensitive personal information or sensitive data, which typically includes government-issued identifiers, precise geolocation, account log-in credentials, racial or ethnic origin, religious belief, health information, sexual orientation, citizenship or immigration status, genetic and biometric data, and the personal data of a known child.

Our position:

  • We do not collect or process biometric identifiers. Classe365 and Hiree365 do not themselves collect, store or process biometric identifiers — including fingerprints, handprints, retina or iris patterns, genetic data, voiceprints, gait patterns, facial templates or faceprints — and do not perform facial or voice recognition. Institutions may choose to enable SMOWL, a third-party proctoring service, which they contract with directly; any biometric processing by SMOWL occurs under SMOWL’s own terms and privacy policy, not ours.
  • We do not collect precise geolocation.
  • We do not require a government-issued identifier to provide the platform. Where an institution configures its own form to collect one, we hold it as personal information under our published retention schedule.
  • We hold account credentials in the form of a username and a hashed password, because authentication requires it.
  • We hold health, disability, accessibility and similar information only where an institution records it in a student or learner record, and only on the institution’s instructions.
  • We hold personal data of known children where an institution enrols them. This is governed by the Children’s Privacy Policy.

We use sensitive personal information only to perform the services, to secure accounts, and for the other purposes state law permits without an obligation to offer a limitation right. We do not use or disclose sensitive personal information to infer characteristics about anyone. Because our use is confined to those permitted purposes, the CCPA right to limit the use of sensitive personal information does not arise; if you nonetheless ask us to limit such use, we will treat it as a request under section 8 and respond.

8. Your rights and how to exercise them

8.1 The rights

Depending on your state of residence, you have some or all of the following rights.

  1. Right to know. To know the categories of personal information we have collected about you, the categories of source, the business or commercial purpose for collecting it, the categories of third party to whom it is disclosed, and the specific pieces of personal information we hold.
  2. Right to access and to obtain a copy. To receive a copy of the personal information you provided to us, in a portable and, where technically feasible, readily usable format that allows you to transmit it to another entity without hindrance.
  3. Right to delete. To request deletion of personal information we hold about you, subject to the exceptions in section 8.6.
  4. Right to correct. To request correction of inaccurate personal information, taking into account the nature of the information and the purpose of processing it.
  5. Right to opt out of sale, sharing for targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not sell personal information and we do not share it for cross-context behavioural or targeted advertising, so there is nothing to opt out of. Where a state gives an opt-out from profiling of that kind, our position is set out in section 11: AI outputs are advisory and decisions about students remain with the institution and its staff.
  6. Right to limit the use of sensitive personal information, where a state provides it. See section 7.
  7. Right against discrimination. We will not deny you goods or services, charge you a different price, provide a different level or quality of service, or retaliate in any way because you exercised a privacy right.
  8. Right to appeal, where the applicable state law provides one. See section 8.7.
  9. Right to opt out of automated decision-making, where the applicable state law provides one and the decision produces a legal or similarly significant effect. No such decision is made without human review.

We honour universal opt-out mechanisms, including Global Privacy Control, where a state law requires us to and where a browser sends the signal to classe365.com. Because we neither sell nor share personal information, the practical effect on our side is limited, but we do not disregard the signal.

8.2 How to make a request

If the information is held in the platform by your institution, contact the institution — its registrar, administrator, student services team or privacy contact. It controls the record and can act on it directly. This is almost always faster.

If you deal with us directly — as a business contact, a website visitor, a prospective customer, or someone who has written to our support team — email clientservice@classe365.com. Put “US privacy request” in the subject line and tell us:

  • your full name and the email address you use with us;
  • which right you are exercising;
  • your state of residence;
  • if the request concerns an institution, which one, and in what capacity you are connected to it.

You may also write to us by post at 365 Software, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Requests by post take longer only because the post does; we treat the request as received when it reaches us.

There is no charge for making a request. We may charge a reasonable fee, or decline, where a request is manifestly unfounded, excessive or repetitive, and we will tell you why.

8.3 How we verify a request

We must be reasonably certain that you are who you say you are before we act, particularly on a request to delete, correct or receive specific pieces of personal information. We verify by matching information you give us against information already in our records.

  • For a request to know categories, we generally ask you to confirm two pieces of information we already hold.
  • For a request for specific pieces of personal information, deletion or correction, we apply a higher standard and generally ask you to confirm three, and to confirm the request from the email address associated with the account.
  • For a correction request, we may ask for documentation supporting the correct value, and we will consider the total of the information we hold in deciding whether the existing record is inaccurate.

We do not require a government-issued identity document, and we do not create a record of one. We only use information supplied for verification to verify the request, and we delete it as soon as the request is closed. If we cannot verify you to the standard the law requires, we will tell you, explain why, and treat a request to know as a request for categories only where that is permitted.

8.4 Authorised agents

You may use an authorised agent to make a request on your behalf.

  • The agent must provide written permission signed by you, or proof of a valid power of attorney.
  • We may contact you directly to confirm that you gave permission, and we may ask you to verify your own identity with us.
  • Where the agent is a business, it must be registered with the California Secretary of State if California law requires it to be.
  • A parent or legal guardian may make a request on behalf of a minor child, and we may require proof of the relationship. Where the child’s record is held by an institution, we will route the request as described in section 8.5.

We will not act on an agent request that lacks these elements, and we will tell the agent what is missing rather than simply refusing.

8.5 How requests are routed when we act as service provider

If you send us a request about information held inside an institution’s tenant:

  1. We acknowledge your request and identify the institution concerned.
  2. We forward the request to that institution without undue delay, because state law makes the institution — as the business or controller — responsible for deciding it.
  3. We tell you that we have forwarded it and who will respond.
  4. We do not delete, correct or disclose records inside an institution’s tenant on our own initiative. Doing so would override the institution and could alter or destroy an education record it is required to maintain.
  5. We provide the institution with the technical assistance it needs to respond — exports, searches, corrections, deletions and confirmations — as part of the service.

Where we are the business or controller, we handle the request ourselves and none of the above applies.

8.6 When we may decline

We may decline a request, in whole or in part, where the law permits — for example where:

  • we cannot verify your identity to the required standard;
  • the information is subject to an exemption, including personal information regulated by FERPA, COPPA, the Gramm-Leach-Bliley Act or HIPAA, or information about you in your capacity as an employee or job applicant of a business, to the extent a state law exempts it;
  • retention is required to comply with a legal obligation, including tax and accounting record-keeping;
  • the information is needed to complete a transaction, provide a service you requested, detect security incidents, protect against fraud or illegal activity, or exercise or defend legal claims;
  • deletion would require us to override an institution’s instruction as controller of an education record.

Where we decline, we will tell you which exception we are relying on, and we will still comply with the rest of the request.

8.7 Appeals

Where the applicable state law provides an appeal right — which most state comprehensive privacy laws other than California and Utah do — you may appeal a refusal by replying to our response, or by emailing clientservice@classe365.com with “Privacy appeal” in the subject line, within a reasonable period after our decision. Tell us what you disagree with.

An appeal is reviewed by someone who was not responsible for the original decision. We will respond in writing within 60 days of receiving the appeal, explaining the outcome and our reasons. If we deny the appeal, we will give you a method of contacting your state Attorney General to submit a complaint, and for California residents the contact details of the California Privacy Protection Agency.

9. Response timeframes

StepTimeframe
Acknowledging a requestWithin 10 business days
Substantive response to a request we controlWithin 45 days of receiving a verifiable request
Extension where reasonably necessaryA further 45 days, with notice to you within the first 45 days explaining why
Response to an appealWithin 60 days of receiving the appeal
Forwarding a request to an institution where we act as service providerWithout undue delay, and in any event promptly on identifying the institution
Acting on an opt-out signal, where applicableWithin 15 business days

Requests to know cover the twelve-month period preceding the request unless the applicable state law requires or permits a longer period, in which case we apply the longer period.

10. Student data, FERPA and advertising

Student information deserves its own statement, because it is the reason most of our customers read this notice.

  1. We act as a school official with a legitimate educational interest under the FERPA school official exception, under the direct control of the institution.
  2. We use education records only to provide the service, on the institution’s instructions.
  3. We do not use education records for advertising, and we do not sell them. There is no advertising inside the authenticated platform.
  4. We do not use education records to train shared AI models. See section 11.
  5. We do not build advertising or marketing profiles from student data, and we do not use it to construct audiences or lookalike segments.
  6. Directory information is designated by the institution, which also controls opt-outs through the platform. We do not designate directory information and we do not disclose it on our own initiative.
  7. Parents and eligible students exercise inspection, correction and hearing rights through the institution, and we support the institution in fulfilling them.
  8. Children under 13 are covered by our Children’s Privacy Policy, which sets out our position under the FTC’s COPPA Final Amendments (90 FR 16918, published 22 April 2025, effective 23 June 2025, compliance date 22 April 2026), including separate consent for non-integral disclosures, our published retention schedule and our written children’s information security program. We do not sell children’s data, do not serve targeted advertising to children, and do not build advertising profiles.
  9. We do not collect audio recordings of children’s voices.
  10. Hiree365 has a minimum age of 16 and is not available to anyone under 16.

11. Artificial intelligence and profiling

We do not use customer, student or candidate data to train, fine-tune or improve any general-purpose or shared AI model. Where a feature uses a model that learns from data, that model is trained only on that customer’s own data — it is per-tenant — and is used only for that customer. Data is never pooled across customers and is never used to improve the service for other customers.

The platform’s AI features are an AI chat assistant, an agent automation and workflow engine, grading analysis, attendance analysis, attrition tracking, behaviour analytics, a writing assistant and AI plagiarism checking. Institutions choose which to enable. Where you interact with the AI chat assistant, the interface tells you that you are interacting with an AI system.

All AI outputs are advisory. Decisions about students remain with the institution and its staff. No automated decision produces a legal or similarly significant effect without human review. Where a state law gives a right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects, we will honour it and will route it to the institution where the institution controls the feature.

Full detail is in the AI Use Statement.

12. Retention

We publish our retention periods rather than describing them in general terms.

Data categoryRetention
Student or candidate record after the institution deletes it7 days, then permanent deletion
All customer data after subscription termination30 days, then permanent deletion
Support correspondence24 months from resolution
Server and security logs30 days
Marketing and CRM contact data36 months from last engagement
BackupsEach daily backup retained 7 days

We take daily backups and retain each daily backup for 7 days on a rolling basis, which gives a seven-day restore window. Because of that window, a deleted record persists in backups for no more than 7 days. On termination, backups are deleted with all other customer data within 30 days. We retain financial and tax records for the period required by law, which may be longer, and we retain records subject to a legal hold until the hold is lifted.

13. Security

Personal information is protected by encryption in transit using TLS, encryption at rest, network segregation, least-privilege access control, an OWASP-aligned secure development lifecycle, daily backups, DDoS protection and continuous monitoring, on Amazon Web Services infrastructure. We maintain a written children’s information security program with a designated coordinator, an annual risk assessment, documented safeguards, sub-processor due diligence, and annual testing and review.

A SOC 2 Type II audit is in progress and is expected to complete in December 2026; we do not hold a report today and do not claim one. We do not hold ISO 27001 certification and do not claim one.

If we become aware of a breach affecting customer data, we notify the affected customer within 24 hours of becoming aware of it.

14. Notice at collection

For California residents, this notice serves as our notice at collection. At or before the point of collection, we collect the categories of personal information listed in section 3, for the purposes listed in section 5, and retain them for the periods listed in section 12. We do not sell personal information and we do not share it for cross-context behavioural advertising. A link to this notice appears on classe365.com and within the platform.

15. Changes to this notice

We review this notice at least annually and update it when the law or our practices change. Where a change materially affects how we handle personal information, we will give at least 30 days’ notice before it takes effect, by email to institutional account contacts and by a notice on our website and in the platform. Minor corrections take effect when published. Each version carries a “Last updated” date and an “Effective” date at the top. The current version is dated 15 September 2026 and takes effect on 15 October 2026.

16. Contact us

Privacy requests and enquiries: clientservice@classe365.com Support: clientservice@classe365.com Accessibility line: +61 2 9472 5000

By post — United States: 365 Software, LLC 131 Continental Dr, Suite 305 Newark, DE 19713 United States

By post — all other locations: Sprout On Web Pty Ltd 22 Palm Street St Ives, NSW 2075 Australia

If you are not satisfied with how we have handled your request, you may complain to your state Attorney General. California residents may also complain to the California Privacy Protection Agency.

Classe365 and Hiree365 are operated by 365 Software, LLC (United States customers) and Sprout On Web Pty Ltd (all other customers), with support and engineering services provided by Classe365 India Pvt Ltd.