Skip to content

Legal

Data processing addendum

Last updated 9 October 2026

This addendum forms part of the terms of service and applies whenever we process personal data on your behalf. It exists because when a learning center uses Classivo, we end up holding data about that center's students, parents and staff — including data about children — and both sides should be clear about the terms on which we do that.

1. Roles

You are the controller. You decide what data to collect from families, why, and how long to keep it. We are the processor: we handle that data only to provide the service, and only on your documented instructions. Your use of the service, together with these documents, is those instructions.

We are a controller only for our own account and billing records, which the privacy notice covers.

2. Scope of processing

Subject matterProviding the Classivo service and any agreed service work.
DurationFor as long as your account is open, plus the deletion window in section 7.
Nature and purposeStoring, organizing, transmitting, encrypting and deleting data so your center can run enrollment, attendance, scheduling and parent communication.
Types of dataNames, email addresses, phone numbers, grade or level, form responses you define, signatures, staff clock-in and clock-out records, and message send history.
Categories of personStudents (including children), their parents and guardians, and your staff.

3. Our obligations

  • Process personal data only on your instructions, unless the law requires otherwise — in which case we will tell you first unless we are legally prevented from doing so.
  • Keep it confidential, and make sure anyone with access is under a duty of confidence.
  • Apply the security measures in section 4, and not weaken them during the term.
  • Help you respond to requests from parents, students or staff exercising their rights.
  • Help you with data protection impact assessments and with regulators, so far as is reasonable given the information we hold.
  • Tell you without undue delay, and in any case within 72 hours of becoming aware, if personal data is breached.

4. Security measures

These are what the software does today, not aspirations:

  • Encryption at rest. Personal details are encrypted in the database, not merely protected by a login.
  • Encryption in transit. All traffic is over HTTPS.
  • Tenant isolation. Each customer's data is separated from every other customer's, and that separation is enforced server-side on every request rather than by hiding things in the interface.
  • Access auditing. Every time a staff member reveals a parent's personal details, it is recorded with who, what and when. This is on for every customer.
  • Authentication controls. Sign-in attempts are logged and rate-limited; sessions use hardened cookies.
  • Role separation. Staff accounts are scoped to their home center; admin rights are granted deliberately.
  • Spam and abuse controls on public forms, so that a form link cannot be used to flood your inbox.

Backups and testing — what we commit to

The list above is what the software does today. These two are commitments about how we run it, kept separate so the distinction is not blurred:

  • Backups. Encrypted daily backups of the database, retained for 35 days, stored separately from the live server. Restore of a single customer's data is available on request rather than only a whole-server restore.
  • Security testing. We have not yet commissioned an independent penetration test. We will not claim one we have not had. When we do, we will say so here and share a summary with customers who ask.

5. Sub-processors

You agree we may use the following, and we will keep this list current:

  • Our hosting provider, on servers in the United States — infrastructure. We will name the current provider on request.
  • Namecheap — DNS, and forwarding for mail to our published addresses. It carries no student, parent or staff data.
  • Paddle.com — payment processing, as merchant of record. Paddle handles billing data only; it is not given access to your students', parents' or staff data.
  • Our own transactional mail is sent through our hosting provider's mail service. We use no third-party marketing email platform.

Your own email provider is not our sub-processor. Mail to parents is sent through your account, under your agreement with that provider.

We will give you 30 days' notice before adding one, and you may object on reasonable data-protection grounds. If we cannot resolve the objection you may cancel the affected add-on and receive a refund for the unused period.

6. International transfers

Personal data is stored on servers in the United States, and our sub-processors are located in the United States and the European Economic Area.

Where you or your data subjects are in the EU or the UK, this is a restricted transfer. We make it under the European Commission's standard contractual clauses (module three, processor to sub-processor, where applicable) together with the UK International Data Transfer Addendum, which are incorporated into this addendum by reference and take effect between us when you accept it. We have carried out a transfer risk assessment and will share it with you on request. If a mechanism we rely on is invalidated, we will move to a valid alternative or give you the option to terminate the affected add-on with a refund for the unused period.

7. Return and deletion

You can export your data at any time while your account is open. After you close it you have 30 days to export, after which we delete your personal data from live systems within 30 days and from backups within 35 days.

Independently of termination, we hold personal data on our servers for a maximum of 4 years. Audit and security logs reach that ceiling because a center may need to investigate a historic access; most other categories are deleted well before it. You may instruct us to delete sooner at any time, and that instruction overrides the ceiling. Billing and tax records are the one exception — they are held by Paddle as merchant of record for as long as tax law requires, which may be longer.

8. Audit

We will make available the information reasonably needed to show we are meeting this addendum, and will answer security questionnaires within a reasonable time. We do not offer on-site audits: we are a small team and an on-site audit right we could not service well would be worth less to you than the alternative. Instead you get our security documentation, a completed security questionnaire, our transfer risk assessment, and a written answer to specific questions, at no cost, once per year and after any breach affecting you. If your own regulator requires more than that, tell us and we will agree something workable rather than hide behind this clause.

9. Children's data

Much of what this service holds concerns children. We treat all personal data in the product as sensitive regardless of category, we do not use it for any purpose beyond providing the service, and we never use it for advertising or model training. Which regime binds you depends on what your center is. FERPA binds schools receiving federal funding, so a private tutoring business is usually outside it — but a center working under contract to a school district can be pulled inside it by that contract. COPPA obligations for collection from children under 13 sit with you as the operator of that collection; we act only on your instructions. Several US states impose additional student-data rules.

We will sign a district-specific or state-specific student data agreement where you need one, and we will not treat that as a reason to move you to a more expensive plan. If you are subject to a regime that requires more of us than this addendum gives, raise it before you subscribe.

10. Order of precedence

If this addendum conflicts with the terms of service on the handling of personal data, this addendum wins.