Build the ChangeChild-Friendly Cities & Communities

How can we make our cities and communities better places for children?

Explore. Create. Share it with the world.
Join here
Privacy & Accessibility

Your data, treated with respect.

This statement explains what personal data Class2Class collects, why we collect it, who else processes it on our behalf, how long we keep it, and the rights you have. We publish privacy and accessibility commitments together — both are about respect for the people on the platform.

GDPR COPPA EU AI Act Children's privacy Your rights

You control your data

Full GDPR rights — access, rectification, erasure, portability, and more — answered within 30 days. Contact our DPO directly.

No sale, no AI training

We never sell your data. Your work, messages, images, and recordings are never used to train AI models — ours or anyone else's.

EU-first storage

Primary platform data lives in the European Union. US transfers are covered by SCCs, the EU–US Data Privacy Framework where applicable, and Transfer Impact Assessments.

Children first

Teacher gatekeeping, parental consent for under-13s, no one-to-one DMs for minors. Children's data is given dedicated treatment in §7.

The full Statement

Class2Class Privacy & Accessibility Statement.

Last updated 1 October 2026.

Last updated:1 October 2026
Owner:DPO Giancarlo Mena

Plain-language summary

This statement explains what personal data Class2Class collects, why we collect it, who else processes it on our behalf, how long we keep it, and the rights you have. It also covers our accessibility commitments — those live in a separate Accessibility Statement that we cross-reference. Where you spot something that's wrong, missing, or unclear, please tell us at dpo@class2class.org and we'll fix it.

This statement applies to teachers, school administrators, principals, coordinators, partners, parents and guardians, students, and anyone using Class2Class.org. Children's privacy is given dedicated treatment in §7. AI-driven features are given dedicated treatment in §6. Cookies are governed by our separate Cookie Policy, cross-referenced in §10.

Section 01

Who we are

Class2Class ApS ("Class2Class", "we", "our", "us") operates the Class2Class.org platform. We are a Danish company. The data controller for personal data processed on the platform is:

ControllerClass2Class ApS
CVR44991071
Registered addressØsterbrogade 148, 1th, 2100 København Ø, Denmark
Data Protection OfficerGiancarlo Mena
DPO contactdpo@class2class.org
EU representativeNot applicable (controller established in EU)
Lead supervisory authorityDatatilsynet (Danish Data Protection Authority)

For data processed by Class2Class on behalf of a partner school (controller–processor relationship for student data under a signed Data Processing Agreement), the school is the controller and Class2Class is the processor. See §9.

Section 02

What this statement covers

This statement covers personal data processing for:

  • The Class2Class web platform(s) (under the domain class2class.org) and any associated mobile experience, including subdomain web and mobile platforms.
  • The Teacher Resources area, including the AI Literacy and Responsible Use guide.
  • Customer-support communications via support@class2class.org, dpo@class2class.org, and the in-platform support chatbot.
  • AI-assisted features described in §6.

It does not cover personal data processed by your own school's systems or by external sites we link to. Those are governed by their own privacy notices.

Section 03

What personal data we collect

We aim to collect only what we need to run the platform. The categories below are exhaustive as of this statement date.

3.1 What you provide directly

CategoryExamplesWho provides itWhy
Identity dataName, emailTeachers, administrators (for themselves); teachers (for students they add)Account creation, communication
Professional dataSchool name, job position, countryTeachers, administratorsMatching classrooms; verifying educational context
Educational contextGrade level, subjects taught, languages spoken, student age groupTeachersMatching classrooms with compatible curricula and ages
Account credentialsPassword (hashed)All usersAccount security
Project contentProject descriptions, posts, messages, reflectionsAll users contributing to a projectEducational collaboration
Project outputsDocuments, images, recordings created during a projectAll usersEducational outputs
Parental consent (under-13)Parent or guardian name; optional parent emailTeachers, on behalf of the parent or guardian, via the consent flow described in §7.4Audit trail for parental consent under GDPR Art. 8 and COPPA "school authorisation"

We do not intentionally collect special categories of personal data (GDPR Art. 9) — health, religion, ethnicity, political opinions, sexual orientation, genetic data, biometric data for unique identification, trade-union membership. Where such information is incidentally shared in a project (for example, a student's reflection that mentions their religion or family background), it is handled with the same protections as other personal data and the teacher may remove it.

Photos and videos shared inside a project are educational content. They are not processed for biometric identification, not analysed by facial-recognition systems, and not used to uniquely identify any person. They are not biometric data within the meaning of GDPR Art. 9.

3.2 What we collect automatically

CategoryExamplesWhyLegal basis
Device informationBrowser type, IP address, operating systemSecurity, troubleshooting, accessibilityLegitimate interest
Usage dataFeatures accessed, time on page, navigation patternsPlatform improvementLegitimate interest
Cookies and similarSession identifiers, preferencesPlatform functionality (essential); analytics and marketing (with consent)See Cookie Policy
Advertising identifiers (teachers who accept Marketing)Ad click identifier, hashed email, browser details (see below)Ad measurement (see §4)Consent (Art. 6(1)(a))
Analytics identifier (teachers who accept Statistical)Internal account number, never your name or emailUse across devices; ad measurement (see §4)Consent (Art. 6(1)(a))
Time zone & languageDetected from browser settingsLocalisation, schedulingLegitimate interest

Advertising identifiers in full. For Google Ads: the click identifier of the Class2Class ad you clicked (gclid, gbraid or wbraid) and when you clicked it, a one-way hashed (SHA-256) copy of your email address, your browser's user agent, and your IP address if you are outside the EEA, the UK and Switzerland. For Meta: Meta's browser identifier (_fbp) and click identifier (_fbc, which carries the fbclid of the ad you clicked), a hashed copy of your email address, your IP address and your browser's user agent.

Section 04

Why we use personal data, and the legal basis

PurposeLegal basis (GDPR Art. 6)What this looks like
Create and manage your accountContract performance — Art. 6(1)(b)Sign-up, sign-in, profile, password reset
Match classrooms and facilitate projectsContract performance — Art. 6(1)(b)Matching, project setup, in-project communication
Moderate content and enforce the Ethical GuidelinesLegitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c) where applicableReviewing flagged content, applying the Coexistence Policy
Improve the platformLegitimate interest — Art. 6(1)(f)Aggregate analytics, A/B testing of features
Send marketing communicationsConsent — Art. 6(1)(a)Newsletter, programme announcements (with opt-in)
Measure whether our adverts work (teachers only)Consent (Art. 6(1)(a)), given through the Marketing choice in the cookie bannerTelling Google Ads and Meta when a teacher signs up and starts using the platform (explained below the table)
Understand how signed-in teachers use the platformConsent (Art. 6(1)(a)), given through the Statistical choice in the cookie bannerA pseudonymous account number in Google Analytics (explained below the table)
Provide customer support (human + AI)Contract performance — Art. 6(1)(b); legitimate interest — Art. 6(1)(f) for pre-contract inquiriesResponding to questions, AI-assisted triage
Generate completion certificatesContract performance — Art. 6(1)(b)Certificate generation for completed projects
Comply with legal obligationsLegal obligation — Art. 6(1)(c)Tax, accounting, regulatory record-keeping
Protect platform securityLegitimate interest — Art. 6(1)(f)Logging, fraud prevention, abuse detection

How ad measurement works. When a teacher who accepted Marketing signs up, we tell Google Ads and Meta, sending the identifiers listed in §3.2 so that each can match the sign-up to its ad. We also tell Meta, with the same identifiers, when that teacher completes their profile, and Google Ads, with the click identifier only, when they make their first connection with another teacher. Hashing hides the address in transit, but it is not anonymisation: Google and Meta can match it to accounts they already hold. Google and Meta may also use this information to decide which Class2Class ads to show you; for Google, that is because we pass your Marketing choice on as consent to ad personalisation too. We never do this for student accounts.

How the analytics account number works. With Statistical consent, we send Google Analytics a signed-in teacher's internal account number, so that we can see how the platform is used across devices and sessions. We also use it, in our EU data warehouse, to connect an ad click made with Marketing consent to the teacher's account, for the ad measurement above. We stop sending the number as soon as you withdraw consent or sign out. Admin, partner and student accounts are never identified this way.

Where the legal basis is consent, you can withdraw consent at any time. Where the legal basis is legitimate interest, you can object — see §11.

Section 05

Visual retention schedule

We keep personal data only as long as we need it. Below is the consolidated retention schedule, derived from the Records of Processing Activities (ROPA) and the Data Processing Agreement with partner organisations.

Data categoryRetention periodWhyThen
Account data (name, email, role, school)Duration of active account + 90 days to 2 years after terminationAccount recovery, dispute resolution, fraud prevention, legal record-keepingSecurely deleted or anonymised
Project content (posts, reflections, images, recordings)Duration of the account; teacher may request removal at any timeContinuity of the educational recordSecurely deleted on account termination or earlier on request
Communications (in-platform messages)Duration of the account + 90 days to 2 years after terminationContinuity, dispute resolutionSecurely deleted or anonymised
Support tickets2 years from ticket closureQuality assurance, dispute resolutionSecurely deleted
Security logs (IP, access times, auth events)90 days rolling; longer for incidents (typically 2 years from incident)Security monitoring, incident responseAutomatic purge after retention window
Error & performance monitoring data (Sentry, EU region — no personal data by default; scrubbed exception reports)Approximately 30 days (Sentry Developer-plan default)Diagnose crashes and keep the platform stableAutomatically deleted by Sentry at the end of the retention window
Analytics data (PostHog, Google Analytics; Mixpanel historical)Per sub-processor policy (typically 14–26 months)Platform improvement; for Google Analytics, also the ad measurement in §4Cookie-based and identified analytics require consent; limited cookieless PostHog analytics uses legitimate interests. See the PostHog notice below.
Google click identifier kept with a teacher sign-up (Marketing consent)100 days from the ad click. The copy in our EU data warehouse is overwritten at its next scheduled updateReporting a first connection to Google Ads, which accepts clicks up to 90 days oldCleared automatically
Ad-measurement data sent to Google Ads and MetaSet by Google and Meta under their own terms. We do not keep the hashed copy of your emailAd measurement (see §4)Deleted by Google or Meta
Marketing consent recordsUntil you withdraw + suppression list (indefinite)Honour your unsubscribe; prevent re-contactSuppression list retained
Parental consent records (under-13)Duration of the student's account + 5 years after closureGDPR Art. 7(1) burden of proof; COPPA evidenceSecurely deleted
Anonymous reports + investigation case filesMinimum 5 years from case closureEU Whistleblower Directive Art. 18; Reports Handling Procedure §10Personal data anonymised where the underlying purpose no longer requires it
Certificates of completionDuration of the account + 5 yearsVerification of certificate authenticitySecurely deleted
Legal & compliance records (tax, accounting)5–7 years per Danish lawLegal obligationSecurely deleted at end of retention window

Where Class2Class is the processor (for partner-school student data under a signed DPA), the retention period in the DPA governs. The retention windows above are the controller-side retention for data Class2Class controls directly.

Section 06

AI features and how they handle your data

Class2Class operates AI features under the principle "You Decide. AI Helps." — humans remain the decision-makers; AI is assistive only.

6.1 The AI systems we use

AI featureWhat it doesProviderRisk class
Customer-support chatbot (Chatbase)Answers questions about Class2Class via a chat interface; routes complex cases to human supportChatbase, Inc. (US — SCCs + TIA + no-AI-training)Limited-risk (Art. 50 transparency)
Project Creation Assistant — text generationSuggests project structure, learning objectives, activities, timelines to teachers when they create a new projectAnthropic (US — SCCs + TIA + no-AI-training) as the default model, with Google Gemini and OpenAI (standard API: no-training-by-default; 30-day retention for abuse monitoring) as fallback providers, routed through the Vercel AI Gateway (EU regions for hosting)Non-high-risk under Art. 6(3)(b)
Project Image Generation (Gemini "Nano Banana")Generates project cover images; teacher chooses whether to use the generated imageGoogle (US, Gemini 2.5 Flash Image API, DPF-certified + SCCs + no-AI-training)Non-high-risk under Art. 6(3)(b)
Internal Analytics Assistant (Claude)Class2Class staff use Claude to query our data warehouse for product, marketing, and platform-health analytics. Not user-facing.Anthropic (US — SCCs + TIA + no-AI-training)Limited-risk / non-high-risk; staff-only

We document the basis of these classifications in our standalone Article 6(3) AI Risk Classification Assessment v.1.0, available on request to supervisory authorities and partner schools.

6.2 Our commitments on AI

  • No automated decisions about students. We do not use AI to make automated decisions about a student — not about grades, placements, or behaviour. Any decision that materially affects a student is taken by a human.
  • No use of your data for AI training. We do not use your work, messages, images, or session recordings to train AI models — neither our own nor any third party's. This is contractually required of every AI sub-processor.
  • AI identifies itself. Where you interact directly with an AI system on Class2Class — at present, the customer-support chatbot — the system identifies itself as AI before the conversation starts, in accordance with EU AI Act Article 50(1). The Project Creation Assistant and the Project Image Generation feature do not "interact directly" within the meaning of Article 50 — they are tools the teacher invokes and reviews; outputs reach the teacher as draft suggestions, not as conversation.
  • Human oversight on flags. No content is removed, suspended, or escalated based on an AI flag alone — a human moderator reviews every flag.
  • AI literacy for staff and teachers. Our staff complete annual training on AI literacy, the Ethical Guidelines, safeguarding, and reports handling. Teachers using AI features attest, when accepting our Terms & Conditions, that they will read and apply our public AI Literacy and Responsible Use guide before using AI features with students.

You can read the full AI Literacy and Responsible Use guide in our Teacher Resources.

6.3 If you do not want AI to process your data

The customer-support chatbot is one entry point to support — you can email support@class2class.org directly to reach human support without engaging the chatbot. The Project Creation Assistant (text generation and image generation for project covers) is activated only when a teacher chooses to invoke it on a draft project.

Section 07

Children and minors — what we do differently

Class2Class welcomes students of all ages, including students under 13 with parental consent. Because most of our students are minors, child protection is built into the platform rather than added at the edges.

7.1 Minimum age and verification

The minimum age to use Class2Class is 13. Students under 13 may use the platform only where their teacher has obtained parental or guardian consent and has confirmed that consent in our platform consent flow. Teachers are responsible for verifying that the student is at least 13 (or for obtaining parental consent for students under 13). Adults may not use Class2Class as students.

7.2 Teacher gatekeeping

Students cannot register directly. Every student account is created and managed by a teacher. This gatekeeping model:

  • Reduces the risk of a child sharing personal data with us without an adult in the loop
  • Ensures every student on the platform is connected to a teacher who is responsible for them
  • Allows teachers to delete inappropriate content immediately and to remove students from projects when needed

7.3 Under-13 and under-16 messaging restrictions

Age bandRestriction
Under 13One-to-one direct messaging is not available. Communication happens in group spaces or is teacher-mediated.
Under 16One-to-one direct messaging is not available. Group chats only.
16+Standard platform messaging, subject to the Ethical Guidelines

7.4 Parental consent for students under 13

For students under 13:

  • The teacher attests, via the platform consent flow, that the parent or guardian has been informed about Class2Class, has understood what data the student will share and how the student will use the platform, and has agreed.
  • This attestation is recorded with the teacher's identity, the student's identity, the version of the attestation text shown, and the timestamp — these records are retained for 5 years after the student's account closes (see §5).
  • The recognised legal frameworks are the COPPA "school authorisation" model in the United States and GDPR Article 8 elsewhere (which permits the controller to make reasonable efforts to verify parental authority).
  • Teachers must not confirm consent unless parents or guardians have actually been informed and have agreed.

If you are a parent or guardian and want to:

  • Withdraw consent: write to dpo@class2class.org. We will block the student's access immediately. The student's project work and learning records are retained while consent is withdrawn (see §7.5). You can also ask your child's teacher to withdraw consent on the platform — they have features to do so.
  • Have the student's account fully deleted: write to dpo@class2class.org. This is stronger than consent withdrawal — we will delete the account and the data, with the legally-required retention exceptions (see §5), and confirm in writing what has been deleted.
  • Ask what data we hold about your child (access right): write to dpo@class2class.org.
  • Correct or update something: write to dpo@class2class.org, or ask the student's teacher to update the record where they hold the relevant information.

We respond to parental data-rights requests within 30 calendar days as required by GDPR Article 12(3).

7.5 Withdrawal of consent and the block screen

When a parent or guardian withdraws consent, the student cannot navigate or use the platform — a block screen prevents access. The account itself is not deleted while the block is in place; the student's project work and learning records are retained, so that consent can be restored without loss of the educational record. The block remains in place until the teacher confirms in the consent flow that consent has been re-obtained.

7.6 Child-friendly summary

A short, plain-language summary of how we handle children's data — written for students aged 13–18 themselves — is published at class2class.org/privacy-for-students. We encourage teachers to introduce it in class.

Section 08

International transfers — where your data goes

Class2Class is a Danish company. Our primary data storage is in the European Union (Supabase, EU region eu-west-1). Some of our sub-processors are established outside the European Economic Area (EEA), so a portion of your personal data is transferred to the United States or other third countries to deliver specific services (analytics, the customer-support chatbot, the model providers behind our AI features, marketing tools where you have given consent).

For each US-based sub-processor we rely on the European Commission's Standard Contractual Clauses (SCCs) supplemented by a Transfer Impact Assessment (TIA) that we maintain internally per the Schrems II judgment and EDPB Recommendations 01/2020. The TIA is reviewed annually and on every change to a sub-processor's data location or contractual terms.

Where a sub-processor is certified under the EU–U.S. Data Privacy Framework (DPF) — for example, Google LLC, which covers Google Analytics, Google Ads, Google Tag Manager, Google Cloud / BigQuery, and Google's Gemini API — we additionally rely on the European Commission's Adequacy Decision (EU) 2023/1795 of 10 July 2023 as a primary transfer basis. SCCs are retained as a fallback mechanism; the TIA is still maintained.

The current sub-processors and their transfer mechanisms are listed in our public Sub-processor List. Highlights:

  • Mixpanel (US — SCCs + TIA; being retired, superseded by PostHog — historical data only)
  • CookieYes (India — SCCs + TIA; consent management platform)
  • Google Analytics (US — Google LLC DPF-certified + SCCs as fallback + TIA + IP anonymisation)
  • Google Ads (US: Google LLC DPF-certified + SCCs as fallback + TIA; ad measurement for teachers who accept Marketing, never students)
  • Meta (US — SCCs + TIA, marketing only with consent)
  • Chatbase (US — SCCs + TIA + contractual no-AI-training-on-user-data commitment)
  • OpenAI (US — SCCs + TIA; standard API with no-training-by-default and 30-day retention for abuse monitoring; powers the Project Creation Assistant text generation, teacher-only)
  • Google (Gemini API) (US — Google LLC DPF-certified + SCCs as fallback + TIA + contractual no-AI-training-on-user-data commitment; powers Project Image Generation, teacher-only)
  • Anthropic (Claude AI) (US — SCCs + TIA + contractual no-AI-training-on-user-data commitment; default model for Project Creation Assistant text generation, teacher-only, and staff-only internal analytics over the BigQuery data warehouse)

EU-based sub-processors (no transfer outside EEA): Supabase (EU region eu-west-1 — platform database, authentication, file storage and realtime), Xano (EU residency, legacy authentication paths only), Brevo, Vercel (EU regions, platform hosting and the AI Gateway), PostHog (EU Cloud, Frankfurt — product-usage analytics; cookies and identification consent-gated; limited cookieless analytics based on legitimate interests; teacher heatmaps with Statistical consent; student heatmaps and session replay off), Stape (Estonia — first-party server-side tagging proxy), Sentry (EU region, Frankfurt — error & performance monitoring; no personal data sent by default and remaining event data scrubbed; retention ≈ 30 days), Google Cloud — BigQuery (EU regions for the centralised data warehouse), Airbyte (EU deployment for the ETL pipelines that load BigQuery).

Section 09

Sub-processors

We engage sub-processors to deliver parts of the platform — for example, the database, the email service, the customer-support chatbot. Every sub-processor:

We notify partners and schools at least 30 calendar days in advance of any addition, replacement, or material change to the sub-processor list, via the contact on file under their signed DPA. Partners and schools may object on reasonable data-protection grounds within 15 calendar days. Individual users (teachers, parents) who want to be notified of material changes can write to dpo@class2class.org.

Google processes the data behind enhanced conversions, Google Analytics and Google Tag Manager on our behalf, under the Google Ads Data Processing Terms. When we report a sign-up or a first connection to Google Ads with the ad's click identifier alone, Google uses that identifier as an independent controller, under its own privacy policy.

We do not sell your personal data to anyone. Sub-processors are bound to use Class2Class data only to deliver the service for which they are engaged.

Section 10

Cookies

Cookies and similar technologies are governed by our separate Cookie Policy. The Cookie Policy describes the four categories of cookies we use (Necessary, Functional, Statistical, Marketing), the cookies in each category, our consent banner, and how to change your preferences at any time.

We do not use cookie walls. You can use the essential platform features without consenting to non-essential cookies.

Section 11

Your rights

Under the GDPR, you have the following rights in respect of your personal data. We honour all of them, with the limited exceptions described in the GDPR itself (for example, where a deletion request would conflict with our legal obligations).

RightWhat it meansHow to use it
Access (Art. 15)Receive a copy of the personal data we hold about youUse Settings → Download your data, or write to dpo@class2class.org
Rectification (Art. 16)Correct inaccurate or out-of-date dataUse the in-platform profile screens, or write to dpo@class2class.org
Erasure (Art. 17)Request deletion of your data, subject to legal retentionWrite to dpo@class2class.org
Restriction (Art. 18)Limit how we process your data while a question or dispute is resolvedWrite to dpo@class2class.org
Portability (Art. 20)Receive the data you provided, together with your platform activity, in a structured, machine-readable file (JSON; CSV on request)Use Settings → Download your data, or write to dpo@class2class.org
Object (Art. 21)Object to processing based on legitimate interest, on grounds relating to your particular situationWrite to dpo@class2class.org
Withdraw consent (Art. 7(3))Withdraw consent for processing based on consent (e.g. marketing, non-essential cookies) — does not affect processing already lawfully doneUse the in-platform settings, the unsubscribe link in marketing emails, or write to dpo@class2class.org
No solely automated decisions (Art. 22)Class2Class does not make solely automated decisions about you that produce legal or similarly significant effectsDocumented in §6.2
Lodge a complaintComplain to a data protection authorityDatatilsynet — dt@datatilsynet.dk; or your own national supervisory authority

We respond to data-rights requests within 30 calendar days of receipt (GDPR Art. 12(3)). Where a request is unusually complex, we may extend by up to 60 additional days, with written notice to you and the reason for the extension. There is no fee for these requests, except where the request is manifestly unfounded or excessive.

If your request relates to a child's data, see §7.4.

A portability export contains the data you provided to us (such as your profile, projects, posts, reflections, messages, and certificates) together with the activity you generated on the platform. It is assembled from our operational database and delivered as a JSON file (CSV on request). It does not include data we derive internally — for example aggregated analytics — or data about other users, both of which fall outside the scope of Article 20.

Section 12

Security

We implement appropriate technical and organisational measures to protect your personal data, in line with GDPR Article 32. Highlights:

  • Encryption in transit — TLS 1.2+ across all connections to the platform.
  • Encryption at rest — provided by Supabase in the EU storage layer.
  • Password storage — passwords are stored using bcrypt, the modern adaptive hashing algorithm recommended by OWASP and NIST SP 800-63B. Hashing is performed by Supabase Auth in the EU. Imported accounts that have not signed in since the migration are still verified against the legacy Xano store until that path retires.
  • Role-based access control — Class2Class staff access to personal data is restricted by role and logged.
  • Multi-factor authentication — required for administrative access to platform infrastructure.
  • Sub-processor due diligence — every sub-processor has been reviewed and has a signed DPA.
  • Regular security audits — annual security reviews, supplemented by ad-hoc reviews on incident or material change.
  • Security frameworks — our controls are mapped and continuously monitored against ISO 27001 and SOC 2. The ISO 27001 certification audit and the SOC 2 attestation are in progress, so we do not yet hold either report. Current control status is published on our Trust Centre.
  • Incident response — a documented Data Breach Response Procedure covers detection, classification, regulatory notification within 72 hours under GDPR Art. 33, and notification to affected individuals under Art. 34 where required.

We have completed a Data Protection Impact Assessment (DPIA) for the platform that identifies and mitigates 10 core risks, with overall residual risk assessed as Low to Moderate (acceptable). The DPIA is reviewed annually.

Section 13

Changes to this statement

We may update this statement to reflect changes in our services, applicable law, or our compliance commitments.

Change typeWhat we do
Material change (e.g. new processing purpose, new sub-processor category, change in retention)Notify users at least 14 calendar days in advance via the email on the account or via a platform announcement; partner schools are notified per the signed DPA
Minor change (e.g. typographical correction, clarification, update to a sub-processor URL)Apply directly; the version number and "Last updated" date at the top always reflect the current state

Continued use of the platform after the notice period constitutes acceptance of the revised statement. If you do not agree, you can close your account during the notice period — see Terms & Conditions §9.5.

Section 14

Accessibility

Our standalone Accessibility Statement describes our commitment to WCAG 2.1 Level AA and the European Accessibility Act.

If a feature of this Privacy & Accessibility statement (or any other document we publish) is not accessible to you in its current form, write to support@class2class.org (subject "Accessibility") and we will provide it in an alternative format.

Section 15

Contact

If you want toUse this contact
Exercise a data right (access, rectification, erasure, restriction, portability, object, withdraw consent)dpo@class2class.org
Ask a privacy questiondpo@class2class.org
Raise a safeguarding concern about a minoranton@class2class.org (Anton Skriver, Safeguarding contact) or support@class2class.org
Raise an ethical concern (general)support@class2class.org
Raise an ethical concern that involves a Class2Class team memberjorgen@class2class.org (Jørgen Balle Olesen, CEO)
Raise an ethical concern that involves the CEOclass2class.org@gmail.com (Independent Reviewer)
Raise an anonymous concernAnonymous Reports Form
Lodge a complaint with a supervisory authorityDatatilsynet — dt@datatilsynet.dk, or your own national authority

The full reporting framework is described in the Ethical Guidelines §10 and in the Reports Handling and Whistleblower Procedure.

Common questions

The questions we get most often.

Do you sell my data?

No. We do not sell your personal data to anyone — never have, never will. Sub-processors are bound to use Class2Class data only to deliver the service for which they are engaged. See §9 for the full statement.

Do you train AI models on my work?

No. We do not use your work, messages, images, or session recordings to train AI models — neither our own nor any third party's. This is contractually required of every AI sub-processor we use (Chatbase, OpenAI, Google Gemini, Anthropic). See §6.2 for the detail.

Where is my data stored?

Most platform data lives in the European Union — our platform database, authentication and file storage on Supabase in an EU region, our remaining Xano legacy authentication store with EU residency, our data warehouse on Google Cloud BigQuery in EU regions, and the platform itself hosted on Vercel in EU regions.

Some sub-processors are based in the US (Mixpanel, and the AI model providers behind the Project Creation Assistant — Anthropic as the default model, with OpenAI and Google Gemini as fallbacks and Gemini for project cover images). Those transfers are covered by Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, and a Transfer Impact Assessment we maintain internally. Section 8 has the full picture; Section 9 lists every sub-processor.

How do I exercise my GDPR rights?

Write to our Data Protection Officer at dpo@class2class.org. We respond within 30 calendar days, in line with GDPR Article 12(3). For unusually complex requests we may extend by up to 60 days with written notice.

Section 11 has the full table of rights with links. There is no fee.

My child is on Class2Class — what are my rights as a parent?

You can withdraw consent at any time (we'll block the student's access immediately while keeping their work intact in case consent is restored). You can request full account deletion, ask what data we hold, request corrections, and lodge a complaint with a supervisory authority.

Write to dpo@class2class.org for any of the above. For safeguarding concerns about your child's experience, write to Anton Skriver at anton@class2class.org. Section 7 has the dedicated treatment of children's privacy.

How are passwords stored?

Passwords are stored using bcrypt, the modern adaptive hashing algorithm recommended by OWASP and NIST SP 800-63B. Hashing is performed by Supabase Auth in the EU. We never store passwords in plain text. See §12 for the full security posture.

How will I know if you change this Policy?

For material changes — new processing purpose, new sub-processor category, change in retention — we notify users at least 14 calendar days in advance via email and a platform announcement, and partner schools per the signed DPA. The "Last updated" date at the top of the statement always reflects the current version. See §13.

My school is using Class2Class — is the platform GDPR-compliant for partner schools?

Yes. Where Class2Class processes student data on behalf of a school, the school is the controller and Class2Class is the processor under a signed Data Processing Agreement. The DPA covers Article 28(3) requirements end-to-end, including a sub-processor list, transfer mechanisms, breach notification SLAs, and AI-specific TOMs.

If you are a school administrator considering Class2Class, write to dpo@class2class.org for the current DPA template.

Have a privacy concern? Tell us.

Reports made in good faith are taken seriously, kept confidential, and protected from any form of retaliation. You can also lodge a complaint directly with Datatilsynet (the Danish Data Protection Authority) or your own national supervisory authority.

Privacy & reporting channels
  • Data rights & privacyGiancarlo Mena (DPO) — dpo@class2class.org
  • Safeguarding (about a minor)Anton Skriver — anton@class2class.org
  • General concernsupport@class2class.org
  • Concern about the CEOIndependent Reviewer — class2class.org@gmail.com
  • Supervisory authorityDatatilsynet — dt@datatilsynet.dk

OpenAI Ads measurement

Class2Class uses the OpenAI Ads Conversions API to measure the successful creation of a new free teacher account. This advertising use is separate from OpenAI model services used to help teachers prepare projects. We do not send public project page views, project-button clicks, email verification, profile completion or project participation to OpenAI Ads.

This measurement requires your explicit Marketing consent in CookieYes (the advertisement category). Statistical consent alone is insufficient. Global Privacy Control (GPC) and Do Not Track (DNT) override consent. Student sessions, student-directed pages, public project pages, login pages, returning sign-ins and unsuccessful registrations are excluded from advertising measurement.

The server event registration_completed contains a random event identifier, registration time, a website source indicator, a fixed registration-page address without query parameters or fragments, and the customer_action event category. Where available with advertising consent, it also includes the original OpenAI ad-click reference (oppref). Free registrations have no monetary value or currency attached.

We do not include a user object, contact details or their hashes, account identifiers, your IP address or your browser user-agent in these events. Every event carries opt_out: true as our default setting. This is not a user-made opt-out choice, does not replace consent and does not make OpenAI our processor for advertising.

After advertising consent, the first-party cookie c2c_openai_oppref can hold the ad-click reference, a random flow reference and its expiry time. It is restricted to the host that sets it and the /api/auth path. Its absolute lifetime is 20 minutes and ordinary navigation does not extend it. The integration does not install an OpenAI browser pixel or SDK.

While your choice is pending, no ad-click cookie is stored. The reference may remain in the current landing-page address so that accepting advertising on that page allows capture. Leaving the page, refusing or withdrawing consent, or GPC/DNT discards it. Later consent does not recover a discarded reference or measure earlier registrations. The cookie is also cleared after signup or sign-in. You can change your choice in the CookieYes preference centre.

A separate first-party session cookie, c2c_openai_ads_denied, stores only the value 1 to tell the server that advertising consent is refused or withdrawn, or that GPC or DNT applies. It contains no identifier and may be set without advertising consent to respect that choice. It is limited to the setting host and / path. It is cleared after an explicit advertising grant without a conflicting privacy signal. It never grants consent or restores an ad-click reference.

OpenAI Ireland Limited receives EEA and Swiss events as an independent controller under the Conversion Terms and Ad Tools Data Processing Addendum. We make no transfer outside the EEA for that processing; OpenAI is responsible for its onward transfers. UK events are received by OpenAI OpCo, LLC under the UK Standard Contractual Clauses (Module 1) incorporated in the addendum. OpenAI may use events for its own purposes under its terms, including measuring, optimising and delivering ads and developing and improving its products and services. This is separate from the no-training commitment of our AI-feature sub-processors. OpenAI Ads is a recipient, not an AI sub-processor. OpenAI retains events under its own terms; our servers log transport outcomes for troubleshooting.

PostHog product analytics and heatmaps

We use PostHog EU Cloud for product-usage and performance analytics on the platform and public website. With Statistical consent, it may use first-party cookies and browser storage; platform account identification is limited to consented sessions. Without that consent, limited cookieless analytics help us improve the service under our legitimate interests. We assess necessity, proportionality and your rights separately from consent for storage or access to your device. You may object by contacting dpo@class2class.org.

In cookieless mode we do not assign a persistent browser identifier or create an account-linked person profile. PostHog processes the IP address and browser user-agent to calculate a server-side hash with a daily rotating salt. This is limited measurement, not advertising, and does not support tracking the same visitor across days or devices. Statistical cookies remain subject to consent. Browser privacy signals are respected.

Platform heatmaps capture interaction coordinates for signed-in teachers with Statistical consent. Student, signed-out and unresolved sessions are excluded from heatmaps. Text and element attributes are masked. Project Viewed and Join Project Clicked are product events with the project id, sent only to PostHog for signed-in teachers with Statistical consent; these events are not sent to advertising platforms.

Session recordings and replay remain switched off. Before any recording pilot, we will complete DPIA screening, publish the approved configuration and updated notices, and give users 14 days and partner schools 30 days notice. The proposed pilot covers consented signed-in teachers only, with fully masked text, inputs and images, excluded sensitive content, no network or console capture, restricted product-team access and 30-day retention. No recording is enabled by this notice.

Have a question we didn't answer?

We update this statement when our services change, when applicable law changes, or when our compliance commitments tighten. Suggestions for improvement are welcome — write to our DPO at dpo@class2class.org.

Email the DPO
Class2Class ApS · CVR 44991071 · Østerbrogade 148, 1th, 2100 København Ø, Denmark
Privacy & Accessibility Statement · Last updated 1 October 2026