Compliance Centre

Questions from schools, DPOs and partners.

Everything an institution asks before working with us, answered in one place: how the platform works, how we protect children, what data we hold, and how we secure it.

Every answer starts with the short version. Where a data protection officer, security reviewer or procurement team needs the mechanics, open More detail underneath it.

Jump to a topic

Eight sections, 85 questions.

Security, privacy and safeguarding are kept separate, because institutional reviewers assess them separately.

1

About Class2Class

8 questions
What is Class2Class?

Class2Class is an online platform where teachers connect their classrooms with classrooms in other countries and run structured collaborative projects together, aligned to the UN Sustainable Development Goals.

More detail

Teachers create or join a project, are matched with a partner classroom abroad, and work through a shared project structure with their students. The platform supplies the matching, the project scaffolding, the collaboration space, and the evidence and certification at the end.

Who is Class2Class designed for?

Primarily teachers in primary and secondary education, and their students. Schools and institutional partners participate around them rather than as the day-to-day users.

Is Class2Class a nonprofit?

No. Class2Class is a for-profit company with a social mission.

The legal entity is Class2Class ApS, a Danish company, CVR 44991071, registered at Østerbrogade 148, 1th, 2100 København Ø, Denmark. Danish and EU law are the primary regime.

How is the platform financially sustainable?

The long-term model is to keep the platform free for teachers and students and to earn revenue from institutions: corporate partnerships, foundation grants, international organisations, premium school services, institutional impact reporting, teacher professional development and school administration tools.

More detail

No school is paying today. Future paid offerings under consideration are verified school networks, teacher professional development, school analytics, institutional impact reports and administrative insights.

Is Class2Class free for teachers and students?

Yes, and the intention is to keep it that way. Teachers and students are not charged and there is no paid tier for them.

What role do institutional and corporate partners play?

Partners fund and sponsor educational initiatives, gain visibility as supporters, and receive evidence of educational impact. They do not get access to classrooms, students or teachers.

More detail

Partner benefits are visibility as a supporter, participation in educational initiatives, evidence of educational impact, and the opportunity to support education in new markets. What a partner can and cannot see is answered in full in section 8.

Can partners advertise or promote products to students?

No. Class2Class is not a marketing channel to children, and partners do not advertise or promote products to students.

More detail

This is a design position, not only a policy one: there is no advertising surface, no partner-facing student data, and no mechanism by which a partner could target or contact a student. Partners support educational initiatives rather than selling products.

Does Class2Class sell advertising?

No. The platform carries no advertising.

2

How Class2Class Works

12 questions
How does a Class2Class project work?

A teacher creates a project or joins an existing one, is matched with a partner classroom in another country, and the two classes work through a shared structure of activities toward a common output. Teachers run the pedagogy; the platform provides the structure, the space and the evidence.

How are classrooms matched?

Teachers find and connect with each other through the platform's Connect area, based on subject, age range, language, SDG interest and availability. Matching is teacher-to-teacher.

What information can teachers see about another classroom?

The teacher's name, their school, their country, and the professional profile they chose to publish (subjects, languages, interests, availability). No pupil-level information about another classroom is exposed.

How do participating classrooms communicate?

Inside the platform, through project chat and teacher-to-teacher messaging. Live classroom meetings happen on external video tools that the teachers choose and schedule.

Are projects synchronous or asynchronous?

Both are supported, and the teachers decide. Most collaboration is asynchronous exchange; live classroom meetings and small-group meetings are optional additions.

Are live video calls required?

No. A project can be completed entirely asynchronously.

Who supervises classroom interactions?

The participating teachers. Class2Class's role is to give them the tools, the rules and the reporting channel; supervision of pupils is the teacher's and the school's responsibility.

More detail

This is reflected in the platform's authorisation model rather than left to policy: group chats can only be created by a teacher or an administrator, and a teacher can only add a student they teach, share a class with, or share a project with. The server enforces this, not the interface.

Can teachers communicate outside Class2Class?

Yes, and many do. Teachers voluntarily exchange contact details with their partner teacher, which is outside the platform and outside our control. Student contact information must never be exchanged.

More detail

The platform stores an optional WhatsApp number for teachers with its own privacy setting and a recorded policy-consent timestamp, so teacher-to-teacher contact by that route is a supported and consented feature rather than a workaround.

Can teachers contact students from another classroom directly?

No. A teacher can only open a one-to-one conversation with a student they teach. Violations of the conduct rules can result in account deletion.

Can students contact each other directly?

Only students aged 16 or over, or younger students whose parental consent has been verified, and only with other students who also pass that same check. Everyone else has no direct student-to-student messaging at all.

More detail

This is the platform's strictest gate and it is worth stating precisely, because it is stronger than what most institutional reviewers expect.

A student reaches the Connect area only if they are at least 16, or their parental consent is recorded as verified. The check is applied on both sides: the list of other students a student can see is filtered by the same rule, so a gated student is neither able to reach others nor visible to them. It is enforced in the data layer rather than in the interface, and it fails closed: if the student's profile cannot be read, access is denied rather than allowed.

Can students take part in project conversations?

Yes, within their own project. Project chat is scoped to the project's participants and a student can only ever see the projects they belong to.

What happens to a student whose parental consent is required but not yet verified?

They cannot use the product. Instead of the dashboard they see a consent-pending screen until the consent is verified.

3

Child Safeguarding

10 questions
What is Class2Class's approach to safeguarding?

Safeguarding is treated as an ongoing operational process rather than a policy document: written policies, teacher-mediated interaction enforced in the platform's authorisation model, content moderation, an in-product reporting channel, an anonymous reporting route, and teacher education.

More detail

The governing documents are the Child Safeguarding Policy, the Code of Conduct, the Ethical Guidelines, and the Safeguarding and Governance Framework, supported by an annual child safety risk assessment and a reports-handling and whistleblower procedure.

Does Class2Class have a Safeguarding Policy?

Yes. It is published at /child-safeguarding/ and available in full to schools and partners on request.

Does Class2Class have a Code of Conduct?

Yes, published at /code-of-conduct/. It applies to everyone who represents Class2Class, including staff, contractors and partners.

Who is responsible for supervising students?

The participating teacher and their school. Class2Class provides the platform, the rules, the moderation tools and the reporting channel; it does not and cannot supervise a classroom.

How are inappropriate interactions prevented?

Structurally, by removing the routes through which they would happen. Teachers cannot message students outside their own teaching relationship, group chats can only be created by teachers, under-16 students without verified parental consent have no direct messaging at all, and every one of those rules is enforced on the server.

More detail

Prevention is layered: the authorisation model removes the opportunity, the Code of Conduct and Safeguarding Policy set the expectation, moderation catches what gets through, and the reporting channel surfaces the rest. Section 2 gives the code-level detail on each gate.

How can safeguarding concerns be reported?

Three routes. Inside the platform, any user can report a message, a post or another user, which opens a case in the moderation queue. By email to the safeguarding and DPO contacts. And through an anonymous web form for anyone who does not want to be identified, including people outside the platform.

More detail

In-product reports are stored as cases with a status, a status timestamp and the moderator who changed it, so handling is auditable rather than ad hoc. Two report types are distinguished: platform issues and behaviour reports, the latter carrying the reported user, post or chat message.

What happens when someone violates safeguarding rules?

The report is triaged under the reports-handling procedure. Outcomes range from a warning to hiding content, blocking the account, or deleting it outright. Direct teacher-to-student contact across classrooms can result in account deletion.

More detail

The platform supports message-level moderation, which hides a message and records who hid it and when, and account-level blocking. Serious cases involving a child are escalated under the Child Safeguarding Policy, which includes referral to the relevant local authority where required.

Are teachers provided with safeguarding guidance?

Yes, through onboarding, the published policies, community reminders, regular teacher meetings and the AI Literacy and Responsible Use guide. Staff complete annual training on AI literacy, the Ethical Guidelines, safeguarding and reports handling.

What happens if a school has stricter safeguarding requirements?

The school's requirements govern. Teachers act within their own school's policy, and where a school needs something specific written down, we will sign it as part of the DPA or an addendum.

Does Class2Class run a child safety risk assessment?

Yes, annually, against a standing template, and it feeds the safeguarding framework rather than sitting on its own.

4

Privacy & Data Protection

15 questions
What personal data does Class2Class collect?

Account and profile data for teachers and students, the content they create in projects, and operational data such as logins and platform usage. The full record of processing is documented in our ROPA.

What data is collected about teachers?

Name, email address, password, school, country, timezone, language, and the professional profile they choose to fill in: role, subjects, interests, SDG focus, availability, biography and profile picture. Optionally a WhatsApp number with its own privacy setting.

More detail

Teachers may also sign in with Google, in which case the provider identity is stored. A newsletter opt-in is recorded separately from account creation.

Do students create accounts?

Yes. A student registers their own account, but only with a teacher's referral code, so a student cannot join independently of a participating classroom.

Does Class2Class collect student email addresses?

Yes. An email address is required to create and verify a student account and to recover access.

Does Class2Class collect student contact information beyond email?

No. No postal address, no phone number and no WhatsApp number for students. The WhatsApp field exists on teacher accounts only.

Why does Class2Class collect date of birth?

To determine the student's age, because the age decides whether parental consent is required and whether the student may use direct messaging at all. It is a data-protection control, not a profile field.

More detail

Registration only accepts a date of birth that produces an age between 6 and 25. The age then drives two separate gates: the parental-consent requirement, which uses the consent age of the student's own country, and access to student-to-student messaging, which requires 16 or verified consent.

How does Class2Class handle parental consent?

Where the student is below their country's digital age of consent, the account is flagged as requiring verified parental consent and the student cannot use the platform until it is recorded. Verification is performed by the teacher or the student's tutor.

More detail

The consent age is resolved per country rather than using a single global figure, because GDPR Article 8 lets member states set their own between 13 and 16. The platform carries the per-country table: 16 in Germany, the Netherlands, Ireland, Poland, Romania, Slovakia, Hungary, Luxembourg, Croatia and Liechtenstein; 15 in France, Czechia, Greece and Slovenia; 14 in Austria, Bulgaria, Cyprus, Italy, Lithuania, Spain and Australia; and a universal floor of 13 where a country has no statute, which matches COPPA.

The student record stores whether consent is required, whether it is verified, the verification type, the verification timestamp and a revocation timestamp.

What is the legal basis for processing personal data?

Set out per processing activity in the Privacy Policy and the ROPA. In the standard school deployment the school is the controller for pupil data and Class2Class is the processor, under the DPA.

Can users request deletion of their data?

Yes. A teacher or student can delete their own account from Settings, and the request is honoured immediately rather than queued.

More detail

Deletion anonymises rather than destroys the record, which is the normal posture for a collaborative platform and worth stating plainly to a DPO. On deletion: the email address is removed, the name becomes "Deleted user", the username and profile picture are cleared, the account is marked deleted and blocked, and the authentication record is hard-deleted from Supabase Auth so sign-in is impossible. Notifications sent to or from the user are hard-deleted and chat memberships are deactivated. Project content the user contributed remains, no longer attributable to an identified person.

Can schools request deletion of their data?

Yes, through the DPO. As controller, a school can request deletion or return of pupil data, and the DPA sets out what happens at the end of the engagement.

Does Class2Class sell personal data?

No. User data is never sold.

Does Class2Class share personal data with partners?

No. Partners receive aggregated, anonymised information only. See section 8.

Is user data used to train AI models?

No. Contractual no-training commitments are in place with the AI providers. See section 7.

Has Class2Class carried out a Data Protection Impact Assessment?

Yes. A DPIA is maintained, alongside a GDPR Article 9 and Article 5(1)(f) compliance declaration.

Who can schools contact about privacy questions?

The Data Protection Officer, at dpo@class2class.org. Teachers can also raise country-specific questions directly with the team or at the global teacher meetups.

5

Security

11 questions
How does Class2Class protect user data?

Through a documented set of security invariants that every change is reviewed against, rather than a list of features. The core ones are: all protected data reaches the browser through a same-origin server layer, every protected operation fails closed unless the caller's identity, tenant, ownership and role are all established, and the database enforces the same tenant rules independently through row-level security.

More detail

The platform's security properties are written down as explicit invariants in our engineering repository, and they are the standard that code reviewers and automated security tooling assess every change against. The ones an institutional reviewer usually cares about:

  • Sessions live in secure, HTTP-only cookies. Authentication material is never in browser storage, query parameters or application headers.
  • Every cookie-authenticated mutation passes a central CSRF control.
  • Possession of an identifier never grants access on its own. Caller, tenant, ownership and role are each established or the operation is refused.
  • Components never touch the database directly. Server data access goes through a repository layer and caller-scoped transactions.
  • The runtime database login is a role that cannot bypass row-level security and cannot log in directly, and it cannot fall back to owner-level access.
  • Row-level security, grants, views, functions, triggers and realtime policies all enforce the same tenant and ownership rules, and tables exposed to browser roles fail closed.
  • Storage paths enforce bucket, prefix, owner, tenant, content-type, size and lifecycle rules, and signed URLs do not disclose unrelated or expired content.
How are passwords stored?

Passwords are hashed with bcrypt by Supabase Auth in the EU. They are never stored in plain text.

More detail

Accounts imported from the legacy system that have not signed in since the migration are still verified against the legacy authentication store until they convert, at which point they move to Supabase Auth.

How is access to production systems controlled?

Production database access runs through a restricted application role that cannot bypass row-level security. Administrative credentials, service-role keys and provider tokens are server-only and least-privileged, and cannot be reached from an ordinary user session.

How are employee permissions managed?

Least privilege, with administrative capability separated from ordinary accounts. An ordinary session cannot reach administrative behaviour by altering claims, identifiers, headers or route parameters.

How are security incidents detected and handled?

Under a written data breach response procedure, with error and exception monitoring in production feeding detection.

Does Class2Class have an incident response process?

Yes, including notification obligations. Breach notification timelines are contractual commitments in the DPA rather than best-efforts.

Does Class2Class perform vulnerability assessments?

Yes. A structured application security assessment programme ran in August 2026 across three rounds, and automated controls run on every change: secret scanning, static security analysis and dependency vulnerability monitoring, with a scheduled maintenance sweep.

More detail

The programme was deliberately designed so that the person who writes a fix is not the person who declares it fixed. Each round used two independent lanes, a static analysis lane and a gray-box review lane, sealed before comparison. Round 2 re-tested round 1's remediation treating every fix as unproven; round 3 verified closure blind to the remediator's claims.

Three verification standards were applied: a control counted as working only when the unauthorised case was refused and the legitimate case was proven still to succeed; where a regression test was offered as evidence, the control was deleted from the product code and the suite re-run to prove the test actually held it; and remediation that could affect legitimate users was measured against production data before being applied.

Severity was scored with CVSS v3.1. Across the whole programme severities ranged from Low to High and no finding reached the Critical band. Severity fell markedly between rounds, and no finding in the final round reached High. All findings have been remediated and no known finding of any severity remains open. Every remediation is held in place by a regression test that was itself mutation-checked. A small number of items were accepted rather than changed, each with recorded reasoning, a stated impact boundary and a condition that would reopen it.

How are third-party vendors assessed?

Every sub-processor is recorded with its role, location, transfer mechanism and DPA, and is covered in Appendix C of our DPA. The list is reconciled against what the platform actually runs, most recently on 27 August 2026.

Is Class2Class ISO 27001 certified?

No, not yet. Our controls are mapped and continuously monitored against ISO 27001, and the certification audit is in progress. We do not claim the certificate until we hold it.

Is Class2Class SOC 2 compliant?

No, not yet. The SOC 2 attestation is in progress on the same basis.

What security documentation can Class2Class provide to a school or partner?

The assessment summary, the DPA with Appendix C, the sub-processor list, the ROPA, the DPIA, the breach response procedure and the security review policy. We will also complete a school's own security questionnaire.

6

Compliance

10 questions
Which privacy and security frameworks does Class2Class follow?

GDPR as the governing law, with controls mapped against ISO 27001 and SOC 2. Child protection follows COPPA-equivalent thresholds where they are stricter, and accessibility follows WCAG 2.1 Level AA. AI features are built against the EU AI Act.

Is Class2Class pursuing ISO/IEC 27001?

Yes. Controls are mapped and continuously monitored, and the certification audit is in progress.

Is Class2Class pursuing SOC 2?

Yes, in progress.

How does Class2Class handle country-specific regulatory requirements?

Where a country sets a stricter threshold than the GDPR baseline, we apply the stricter one. The clearest example is the digital age of consent, which the platform resolves per country rather than using a single global figure.

More detail

See section 4 for the per-country consent table. Teachers with country-specific questions can reach the DPO directly or raise them at the global teacher meetups.

Does Class2Class have a Data Protection Officer?

Yes, reachable at dpo@class2class.org.

How does Class2Class approach children's privacy?

By treating age as an access control rather than a profile attribute. A student's age determines whether parental consent is required, using their own country's threshold, and whether they may use direct messaging at all. Both gates are enforced in the data layer and fail closed.

More detail

Section 4 gives the mechanics and section 2 gives the messaging restrictions. The supporting documents are the Child Safeguarding Policy, the child-friendly privacy summary written for students aged 13 to 18, and the parental DSAR process.

How does Class2Class assess new compliance requirements?

Through the safeguarding and governance framework, with an annual child safety risk assessment, an annual transparency report, and an external review scope for independent assessment.

Can Class2Class complete a school's security or privacy questionnaire?

Yes. Send it to the DPO. This Q&A is the source we answer from, so responses stay consistent between schools.

Does Class2Class have an anti-corruption policy?

Yes, with zero tolerance for corruption in any form, published at /anti-corruption/.

What responsibilities remain with the participating school?

Four, and they are worth stating explicitly because institutional reviewers look for them: deciding to participate and which classes take part; obtaining whatever local parental permissions the school's own policy requires, including for images of pupils; supervising pupils during classroom activity and live meetings; and applying the school's own safeguarding and acceptable-use policies to teacher and pupil conduct on the platform.

7

Artificial Intelligence

12 questions
Does Class2Class use AI?

Yes, in the Project Creation Assistant, which helps teachers plan projects, and in a support chatbot available from the help menu. Both are assistive; neither makes decisions about students.

Where is AI used within the platform?

In teacher-facing project authoring: suggesting project titles and descriptions, generating activities and learning outcomes, suggesting SDGs, skills and child rights connections, classifying learning outcomes, and generating project cover images. Plus the support chatbot.

Is teacher data used to train AI models?

No. Contractual no-training commitments are in place with the model providers.

Is Class2Class user data used to train external AI models?

No. This is a contractual commitment with each provider, not a setting we rely on.

Which AI models does Class2Class use?

Claude Haiku from Anthropic as the default model for text features, with Google Gemini and OpenAI as fallbacks, all routed through the Vercel AI Gateway. Project cover images are generated with Google Gemini Flash Image.

More detail

The gateway fails over between providers automatically on provider outage or rate limiting, which is why three providers appear in the sub-processor list for one feature. Fallback providers process the same teacher-authored project context as the default.

Can AI make decisions about students?

No. No AI feature assesses, scores, ranks, profiles or makes any determination about a student. The AI helps a teacher plan a project.

Can AI publish educational content automatically?

No. Every AI output is a suggestion that the teacher must review and accept. Nothing an AI produces reaches students without a teacher's action.

Does a teacher review AI-generated content?

Always. The teacher reviews, edits, approves and retains final educational authority over everything.

How does Class2Class maintain human oversight?

The teacher is the only route by which AI output reaches a classroom, and that is enforced by the authorisation model rather than by convention. Staff also complete annual AI literacy and ethical conduct training, and there is a written AI incident reporting procedure.

How does Class2Class protect teacher autonomy and creativity?

By designing the AI to assist planning rather than to author lessons. The teacher's pedagogical choices, framing and adaptation to their own class are the point of the tool, not something it replaces.

How does Class2Class classify its AI systems under the EU AI Act?

Through a documented Article 6(3) risk classification assessment covering each AI system in the inventory.

Is AI use disclosed to teachers and students?

Yes. AI features are labelled in the product, the AI Literacy and Responsible Use guide is published for teachers, and teachers attest when accepting the Terms that they will read and apply it before using AI features with students.

8

Data Sharing & Partner Reporting

7 questions
Can partners see individual students?

No. Never, in any form.

Can partners identify participating classrooms?

No. Reporting is aggregated so that individual classrooms are not identifiable.

What information is included in impact reports?

Participation figures, teacher reflections in aggregate, learning outcomes, project outcomes and classroom evidence in summary form, organised by country and SDG.

Can partners contact participating students?

No. There is no mechanism for it, and it is prohibited.

Can partners contact participating teachers?

Not through the platform. Any contact happens through Class2Class, and only where the teacher has agreed.

Can partners use Class2Class data for marketing?

Partners may say they support Class2Class and may use the aggregated impact figures we provide. They receive no personal data, so there is nothing personal for them to market with, and they may not market to students.

Who can see a teacher's own classroom report?

The teacher. A teacher can download the impact report for their own project and cannot see another teacher's.

More detail

The report is assembled from live data on each request and nothing is stored, and the route is rate limited. Access is scoped to the caller.

Not answered here?

Send us your own security or privacy questionnaire and we will complete it. For anything about personal data, write to our Data Protection Officer.

Email the DPO Back to Compliance Centre