Legal
Privacy notice
Last updated 5 October 2026
This notice explains what Classivo does with personal data. It covers two quite different things, and it is worth being clear about which is which:
- This website, where we decide what is collected — so we are the controller.
- The product, where a learning center puts its students' and parents' data into our software. There, the center decides what is collected and why. They are the controller and we are their processor, acting on their instructions.
Who we are
Classivo is operated by Classivo. For anything in this notice, including a request about your own data, write to privacy@classivo.co. General enquiries go through the contact form and security reports to security@classivo.co. We will give you a postal address on request.
We are not required to appoint a Data Protection Officer, and we have not appointed one. Data protection questions go to the address above and are answered by us directly rather than by a department. If we begin selling into the EU or UK at a scale that requires a representative there, we will appoint one and name them on this page.
This website
What we collect
What you type into the contact form: your name, your email address, optionally your center's name, which add-ons you ticked, and your message. We also record the IP address the message came from and your browser's user-agent string, to limit abuse of the form.
If you create a Classivo account: your email address, your name if you sign in with Google, when you last signed in, and which edition of our terms you agreed to and when. We do not receive a password, because there is none, and we receive nothing else from your Google account.
Cookies and analytics
Browsing this website sets no cookies and runs no analytics. Signing in does set a few, all strictly to make sign-in work: one that keeps you signed in (for up to 30 days), one that protects the sign-in and sign-out forms, a short-lived one that protects the Google sign-in while you are at Google, and a two-hour one that remembers which plan you picked until you have signed in. There is no tag manager, no advertising pixel, no session tracking, and no third-party web fonts. The only third-party resources that can load are the Cloudflare Turnstile anti-spam widget on the contact page, which is currently switched off and therefore does not load at all, and Paddle's checkout on the payment page.
Why we are allowed to use it
We use what you send to answer you, and to keep a record of the conversation. Our lawful basis is our legitimate interest in responding to an enquiry about our own product, and in protecting the form from abuse. We do not add you to a marketing list because you sent an enquiry; if we ever want to send you something that is not a reply, we will ask first and you can decline without it affecting your enquiry.
For an account, we use your email address to sign you in and to run the account, because that is what you asked us to do. We also email you about Classivo itself — product news, new features and offers — because you agreed to that when you created the account (section 15 of the terms). Every one of those emails has an unsubscribe link, and using it stops them without affecting your account. Sign-in links, receipts and security or service notices are not marketing and keep coming while you have an account.
How long we keep it
Enquiries are kept for up to 4 years and then deleted. Rate-limiting records, which contain a hashed IP address only, are discarded after an hour. You can ask us to delete an enquiry sooner and we will.
The product
Our role
When a learning center uses Classivo, the data about their students, parents and staff belongs to that center. They decide what to collect and how long to keep it. We only process it to provide the service, and we do not use it to train anything, sell anything, or market to the families in it. The detail of that arrangement is in our data processing addendum.
What the software holds
- Student and parent names, email addresses and grade or level
- Whatever a center's own enrollment, policy or agreement forms ask for
- Staff names, email addresses, and their clock-in and clock-out records
- Calendar events and message send history
Some of this concerns children. We treat all of it as sensitive regardless of what any particular law requires.
Which student-privacy rules apply depends on the center, not on us. A private tutoring business is generally not a school and generally not subject to FERPA, which binds schools receiving federal funding; a center contracted by a school district may be, through that contract. Where a center collects data from children under 13 online, COPPA obligations sit with the center as the operator of that collection, and several US states impose further student-data rules. We support the center in meeting whichever apply: we do not use children's data for advertising, profiling, or model training, we do not disclose it to anyone outside the sub-processors listed below, and we will sign a district or state-specific data agreement where a center needs one. If your center is subject to a regime that needs something more from us, tell us before you sign up rather than after.
How it is protected
- Personal details are encrypted at rest, not merely stored behind a login.
- Every time a staff member reveals a parent's details, that is recorded — who, what and when. Centers can see their own log, and that is included for every customer rather than sold as an upgrade.
- Sign-in attempts are logged and rate-limited.
- Each customer's data is isolated from every other customer's.
Email to parents
Mail from the product goes out through the center's own email account, not through a shared sending service of ours. Practically, that means the content of those messages passes through the center's own provider — usually Google — under the center's own agreement with them, rather than through us.
Who else sees data
We keep this list short on purpose, and we will keep it current:
- Our hosting provider, on servers in the United States — infrastructure. We will name the current provider on request.
- Namecheap — DNS for the domain, and the forwarding service that delivers mail sent to our published addresses.
- Paddle.com — payment processing. Paddle is the merchant of record for every order, so your billing details go to Paddle rather than to us: we never see or store a full card number. Paddle is a controller in its own right for that data, under its own privacy notice.
- Our own mail to you — sign-in links, receipts, reminders, system notices and our occasional product emails — is sent from our hosting provider's mail service. We do not use a third-party marketing email platform.
- Google, but only under the customer's own account, for mail the customer sends.
We do not sell personal data, and we do not share it for advertising. If we are ever required to hand something over by law, we will tell the affected customer unless we are legally prevented from doing so.
Where data is stored
Product data is stored on servers in the United States. If you are in the EU or the UK, that is a transfer outside your region: we make it under the UK and EU standard contractual clauses, which are included in our data processing addendum and which you enter into with us when you accept it. We can tell you which safeguards apply to a specific data flow if you need that for your own records.
How long we keep it
We keep personal data on our own servers for a maximum of 4 years. That is a ceiling, not a target — most categories are deleted sooner:
| Website enquiries | Up to 4 years from the message. |
|---|---|
| Product data belonging to a center | For as long as the account is open. After it closes, 30 days to export, then deleted from live systems within 30 days and from backups within 35 days. |
| Access and reveal audit logs | Up to 4 years, so a center can still investigate a historic access. |
| Sign-in and security logs | Up to 4 years. |
| Billing and tax records | Retained as long as tax law requires, which may exceed 4 years. Held by Paddle as merchant of record. |
| Rate-limiting records | One hour. Hashed IP only. |
A center can ask us to delete its data earlier than any of this, and we will act on that request — the periods above are the longest we hold something, not a commitment to keep it from you.
Your rights
Depending on where you live you may have the right to see a copy of your data, correct it, delete it, restrict how it is used, object to that use, or receive it in a portable form. Send us a message through the contact form and we will respond within 30 days. That is the GDPR deadline and we apply it to everyone who asks, wherever they live, rather than sorting requests by jurisdiction. If a request is complex enough to need longer, we will tell you inside those 30 days.
If your child attends a center that uses Classivo and you want to see or delete their records, please contact the center directly. They control that data; we will help them act on your request, but we cannot act on it without them.
Breach notification
If personal data is exposed, we will notify affected customers without undue delay and in any case within 72 hours of becoming aware of it, with what we know, what we are doing, and what they need to do.
Changes
If we change this notice materially we will say so on this page and tell existing customers by email before it takes effect.