Your data, treated with respect.
This statement explains what personal data Class2Class collects, why we collect it, who else processes it on our behalf, how long we keep it, and the rights you have. We publish privacy and accessibility commitments together — both are about respect for the people on the platform.
You control your data
Full GDPR rights — access, rectification, erasure, portability, and more — answered within 30 days. Contact our DPO directly.
No sale, no AI training
We never sell your data. Your work, messages, images, and recordings are never used to train AI models — ours or anyone else's.
EU-first storage
Primary platform data lives in the European Union. US transfers are covered by SCCs, the EU–US Data Privacy Framework where applicable, and Transfer Impact Assessments.
Children first
Teacher gatekeeping, parental consent for under-13s, no one-to-one DMs for minors. Children's data is given dedicated treatment in §7.
Sixteen sections, organised so you can find what you need.
Click any section to jump to it in the document below.
Class2Class Privacy & Accessibility Statement.
Last updated 1 October 2026.
Plain-language summary
This statement explains what personal data Class2Class collects, why we collect it, who else processes it on our behalf, how long we keep it, and the rights you have. It also covers our accessibility commitments — those live in a separate Accessibility Statement that we cross-reference. Where you spot something that's wrong, missing, or unclear, please tell us at dpo@class2class.org and we'll fix it.
This statement applies to teachers, school administrators, principals, coordinators, partners, parents and guardians, students, and anyone using Class2Class.org. Children's privacy is given dedicated treatment in §7. AI-driven features are given dedicated treatment in §6. Cookies are governed by our separate Cookie Policy, cross-referenced in §10.
Who we are
Class2Class ApS ("Class2Class", "we", "our", "us") operates the Class2Class.org platform. We are a Danish company. The data controller for personal data processed on the platform is:
| Controller | Class2Class ApS |
| CVR | 44991071 |
| Registered address | Østerbrogade 148, 1th, 2100 København Ø, Denmark |
| Data Protection Officer | Giancarlo Mena |
| DPO contact | dpo@class2class.org |
| EU representative | Not applicable (controller established in EU) |
| Lead supervisory authority | Datatilsynet (Danish Data Protection Authority) |
For data processed by Class2Class on behalf of a partner school (controller–processor relationship for student data under a signed Data Processing Agreement), the school is the controller and Class2Class is the processor. See §9.
What this statement covers
This statement covers personal data processing for:
- The Class2Class web platform(s) (under the domain
class2class.org) and any associated mobile experience, including subdomain web and mobile platforms. - The Teacher Resources area, including the AI Literacy and Responsible Use guide.
- Customer-support communications via support@class2class.org, dpo@class2class.org, and the in-platform support chatbot.
- AI-assisted features described in §6.
It does not cover personal data processed by your own school's systems or by external sites we link to. Those are governed by their own privacy notices.
What personal data we collect
We aim to collect only what we need to run the platform. The categories below are exhaustive as of this statement date.
3.1 What you provide directly
| Category | Examples | Who provides it | Why |
|---|---|---|---|
| Identity data | Name, email | Teachers, administrators (for themselves); teachers (for students they add) | Account creation, communication |
| Professional data | School name, job position, country | Teachers, administrators | Matching classrooms; verifying educational context |
| Educational context | Grade level, subjects taught, languages spoken, student age group | Teachers | Matching classrooms with compatible curricula and ages |
| Account credentials | Password (hashed) | All users | Account security |
| Project content | Project descriptions, posts, messages, reflections | All users contributing to a project | Educational collaboration |
| Project outputs | Documents, images, recordings created during a project | All users | Educational outputs |
| Parental consent (under-13) | Parent or guardian name; optional parent email | Teachers, on behalf of the parent or guardian, via the consent flow described in §7.4 | Audit trail for parental consent under GDPR Art. 8 and COPPA "school authorisation" |
We do not intentionally collect special categories of personal data (GDPR Art. 9) — health, religion, ethnicity, political opinions, sexual orientation, genetic data, biometric data for unique identification, trade-union membership. Where such information is incidentally shared in a project (for example, a student's reflection that mentions their religion or family background), it is handled with the same protections as other personal data and the teacher may remove it.
Photos and videos shared inside a project are educational content. They are not processed for biometric identification, not analysed by facial-recognition systems, and not used to uniquely identify any person. They are not biometric data within the meaning of GDPR Art. 9.
3.2 What we collect automatically
| Category | Examples | Why | Legal basis |
|---|---|---|---|
| Device information | Browser type, IP address, operating system | Security, troubleshooting, accessibility | Legitimate interest |
| Usage data | Features accessed, time on page, navigation patterns | Platform improvement | Legitimate interest |
| Cookies and similar | Session identifiers, preferences | Platform functionality (essential); analytics and marketing (with consent) | See Cookie Policy |
| Advertising identifiers (teachers who accept Marketing) | Ad click identifier, hashed email, browser details (see below) | Ad measurement (see §4) | Consent (Art. 6(1)(a)) |
| Analytics identifier (teachers who accept Statistical) | Internal account number, never your name or email | Use across devices; ad measurement (see §4) | Consent (Art. 6(1)(a)) |
| Time zone & language | Detected from browser settings | Localisation, scheduling | Legitimate interest |
Advertising identifiers in full. For Google Ads: the click identifier of the Class2Class ad you clicked (gclid, gbraid or wbraid) and when you clicked it, a one-way hashed (SHA-256) copy of your email address, your browser's user agent, and your IP address if you are outside the EEA, the UK and Switzerland. For Meta: Meta's browser identifier (_fbp) and click identifier (_fbc, which carries the fbclid of the ad you clicked), a hashed copy of your email address, your IP address and your browser's user agent.
Why we use personal data, and the legal basis
| Purpose | Legal basis (GDPR Art. 6) | What this looks like |
|---|---|---|
| Create and manage your account | Contract performance — Art. 6(1)(b) | Sign-up, sign-in, profile, password reset |
| Match classrooms and facilitate projects | Contract performance — Art. 6(1)(b) | Matching, project setup, in-project communication |
| Moderate content and enforce the Ethical Guidelines | Legitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c) where applicable | Reviewing flagged content, applying the Coexistence Policy |
| Improve the platform | Legitimate interest — Art. 6(1)(f) | Aggregate analytics, A/B testing of features |
| Send marketing communications | Consent — Art. 6(1)(a) | Newsletter, programme announcements (with opt-in) |
| Measure whether our adverts work (teachers only) | Consent (Art. 6(1)(a)), given through the Marketing choice in the cookie banner | Telling Google Ads and Meta when a teacher signs up and starts using the platform (explained below the table) |
| Understand how signed-in teachers use the platform | Consent (Art. 6(1)(a)), given through the Statistical choice in the cookie banner | A pseudonymous account number in Google Analytics (explained below the table) |
| Provide customer support (human + AI) | Contract performance — Art. 6(1)(b); legitimate interest — Art. 6(1)(f) for pre-contract inquiries | Responding to questions, AI-assisted triage |
| Generate completion certificates | Contract performance — Art. 6(1)(b) | Certificate generation for completed projects |
| Comply with legal obligations | Legal obligation — Art. 6(1)(c) | Tax, accounting, regulatory record-keeping |
| Protect platform security | Legitimate interest — Art. 6(1)(f) | Logging, fraud prevention, abuse detection |
How ad measurement works. When a teacher who accepted Marketing signs up, we tell Google Ads and Meta, sending the identifiers listed in §3.2 so that each can match the sign-up to its ad. We also tell Meta, with the same identifiers, when that teacher completes their profile, and Google Ads, with the click identifier only, when they make their first connection with another teacher. Hashing hides the address in transit, but it is not anonymisation: Google and Meta can match it to accounts they already hold. Google and Meta may also use this information to decide which Class2Class ads to show you; for Google, that is because we pass your Marketing choice on as consent to ad personalisation too. We never do this for student accounts.
How the analytics account number works. With Statistical consent, we send Google Analytics a signed-in teacher's internal account number, so that we can see how the platform is used across devices and sessions. We also use it, in our EU data warehouse, to connect an ad click made with Marketing consent to the teacher's account, for the ad measurement above. We stop sending the number as soon as you withdraw consent or sign out. Admin, partner and student accounts are never identified this way.
Where the legal basis is consent, you can withdraw consent at any time. Where the legal basis is legitimate interest, you can object — see §11.
Visual retention schedule
We keep personal data only as long as we need it. Below is the consolidated retention schedule, derived from the Records of Processing Activities (ROPA) and the Data Processing Agreement with partner organisations.
| Data category | Retention period | Why | Then |
|---|---|---|---|
| Account data (name, email, role, school) | Duration of active account + 90 days to 2 years after termination | Account recovery, dispute resolution, fraud prevention, legal record-keeping | Securely deleted or anonymised |
| Project content (posts, reflections, images, recordings) | Duration of the account; teacher may request removal at any time | Continuity of the educational record | Securely deleted on account termination or earlier on request |
| Communications (in-platform messages) | Duration of the account + 90 days to 2 years after termination | Continuity, dispute resolution | Securely deleted or anonymised |
| Support tickets | 2 years from ticket closure | Quality assurance, dispute resolution | Securely deleted |
| Security logs (IP, access times, auth events) | 90 days rolling; longer for incidents (typically 2 years from incident) | Security monitoring, incident response | Automatic purge after retention window |
| Error & performance monitoring data (Sentry, EU region — no personal data by default; scrubbed exception reports) | Approximately 30 days (Sentry Developer-plan default) | Diagnose crashes and keep the platform stable | Automatically deleted by Sentry at the end of the retention window |
| Analytics data (PostHog, Google Analytics; Mixpanel historical) | Per sub-processor policy (typically 14–26 months) | Platform improvement; for Google Analytics, also the ad measurement in §4 | Cookie-based and identified analytics require consent; limited cookieless PostHog analytics uses legitimate interests. See the PostHog notice below. |
| Google click identifier kept with a teacher sign-up (Marketing consent) | 100 days from the ad click. The copy in our EU data warehouse is overwritten at its next scheduled update | Reporting a first connection to Google Ads, which accepts clicks up to 90 days old | Cleared automatically |
| Ad-measurement data sent to Google Ads and Meta | Set by Google and Meta under their own terms. We do not keep the hashed copy of your email | Ad measurement (see §4) | Deleted by Google or Meta |
| Marketing consent records | Until you withdraw + suppression list (indefinite) | Honour your unsubscribe; prevent re-contact | Suppression list retained |
| Parental consent records (under-13) | Duration of the student's account + 5 years after closure | GDPR Art. 7(1) burden of proof; COPPA evidence | Securely deleted |
| Anonymous reports + investigation case files | Minimum 5 years from case closure | EU Whistleblower Directive Art. 18; Reports Handling Procedure §10 | Personal data anonymised where the underlying purpose no longer requires it |
| Certificates of completion | Duration of the account + 5 years | Verification of certificate authenticity | Securely deleted |
| Legal & compliance records (tax, accounting) | 5–7 years per Danish law | Legal obligation | Securely deleted at end of retention window |
Where Class2Class is the processor (for partner-school student data under a signed DPA), the retention period in the DPA governs. The retention windows above are the controller-side retention for data Class2Class controls directly.
AI features and how they handle your data
Class2Class operates AI features under the principle "You Decide. AI Helps." — humans remain the decision-makers; AI is assistive only.
6.1 The AI systems we use
| AI feature | What it does | Provider | Risk class |
|---|---|---|---|
| Customer-support chatbot (Chatbase) | Answers questions about Class2Class via a chat interface; routes complex cases to human support | Chatbase, Inc. (US — SCCs + TIA + no-AI-training) | Limited-risk (Art. 50 transparency) |
| Project Creation Assistant — text generation | Suggests project structure, learning objectives, activities, timelines to teachers when they create a new project | Anthropic (US — SCCs + TIA + no-AI-training) as the default model, with Google Gemini and OpenAI (standard API: no-training-by-default; 30-day retention for abuse monitoring) as fallback providers, routed through the Vercel AI Gateway (EU regions for hosting) | Non-high-risk under Art. 6(3)(b) |
| Project Image Generation (Gemini "Nano Banana") | Generates project cover images; teacher chooses whether to use the generated image | Google (US, Gemini 2.5 Flash Image API, DPF-certified + SCCs + no-AI-training) | Non-high-risk under Art. 6(3)(b) |
| Internal Analytics Assistant (Claude) | Class2Class staff use Claude to query our data warehouse for product, marketing, and platform-health analytics. Not user-facing. | Anthropic (US — SCCs + TIA + no-AI-training) | Limited-risk / non-high-risk; staff-only |
We document the basis of these classifications in our standalone Article 6(3) AI Risk Classification Assessment v.1.0, available on request to supervisory authorities and partner schools.
6.2 Our commitments on AI
- No automated decisions about students. We do not use AI to make automated decisions about a student — not about grades, placements, or behaviour. Any decision that materially affects a student is taken by a human.
- No use of your data for AI training. We do not use your work, messages, images, or session recordings to train AI models — neither our own nor any third party's. This is contractually required of every AI sub-processor.
- AI identifies itself. Where you interact directly with an AI system on Class2Class — at present, the customer-support chatbot — the system identifies itself as AI before the conversation starts, in accordance with EU AI Act Article 50(1). The Project Creation Assistant and the Project Image Generation feature do not "interact directly" within the meaning of Article 50 — they are tools the teacher invokes and reviews; outputs reach the teacher as draft suggestions, not as conversation.
- Human oversight on flags. No content is removed, suspended, or escalated based on an AI flag alone — a human moderator reviews every flag.
- AI literacy for staff and teachers. Our staff complete annual training on AI literacy, the Ethical Guidelines, safeguarding, and reports handling. Teachers using AI features attest, when accepting our Terms & Conditions, that they will read and apply our public AI Literacy and Responsible Use guide before using AI features with students.
You can read the full AI Literacy and Responsible Use guide in our Teacher Resources.
6.3 If you do not want AI to process your data
The customer-support chatbot is one entry point to support — you can email support@class2class.org directly to reach human support without engaging the chatbot. The Project Creation Assistant (text generation and image generation for project covers) is activated only when a teacher chooses to invoke it on a draft project.
Children and minors — what we do differently
Class2Class welcomes students of all ages, including students under 13 with parental consent. Because most of our students are minors, child protection is built into the platform rather than added at the edges.
7.1 Minimum age and verification
The minimum age to use Class2Class is 13. Students under 13 may use the platform only where their teacher has obtained parental or guardian consent and has confirmed that consent in our platform consent flow. Teachers are responsible for verifying that the student is at least 13 (or for obtaining parental consent for students under 13). Adults may not use Class2Class as students.
7.2 Teacher gatekeeping
Students cannot register directly. Every student account is created and managed by a teacher. This gatekeeping model:
- Reduces the risk of a child sharing personal data with us without an adult in the loop
- Ensures every student on the platform is connected to a teacher who is responsible for them
- Allows teachers to delete inappropriate content immediately and to remove students from projects when needed
7.3 Under-13 and under-16 messaging restrictions
| Age band | Restriction |
|---|---|
| Under 13 | One-to-one direct messaging is not available. Communication happens in group spaces or is teacher-mediated. |
| Under 16 | One-to-one direct messaging is not available. Group chats only. |
| 16+ | Standard platform messaging, subject to the Ethical Guidelines |
7.4 Parental consent for students under 13
For students under 13:
- The teacher attests, via the platform consent flow, that the parent or guardian has been informed about Class2Class, has understood what data the student will share and how the student will use the platform, and has agreed.
- This attestation is recorded with the teacher's identity, the student's identity, the version of the attestation text shown, and the timestamp — these records are retained for 5 years after the student's account closes (see §5).
- The recognised legal frameworks are the COPPA "school authorisation" model in the United States and GDPR Article 8 elsewhere (which permits the controller to make reasonable efforts to verify parental authority).
- Teachers must not confirm consent unless parents or guardians have actually been informed and have agreed.
If you are a parent or guardian and want to:
- Withdraw consent: write to dpo@class2class.org. We will block the student's access immediately. The student's project work and learning records are retained while consent is withdrawn (see §7.5). You can also ask your child's teacher to withdraw consent on the platform — they have features to do so.
- Have the student's account fully deleted: write to dpo@class2class.org. This is stronger than consent withdrawal — we will delete the account and the data, with the legally-required retention exceptions (see §5), and confirm in writing what has been deleted.
- Ask what data we hold about your child (access right): write to dpo@class2class.org.
- Correct or update something: write to dpo@class2class.org, or ask the student's teacher to update the record where they hold the relevant information.
We respond to parental data-rights requests within 30 calendar days as required by GDPR Article 12(3).
7.5 Withdrawal of consent and the block screen
When a parent or guardian withdraws consent, the student cannot navigate or use the platform — a block screen prevents access. The account itself is not deleted while the block is in place; the student's project work and learning records are retained, so that consent can be restored without loss of the educational record. The block remains in place until the teacher confirms in the consent flow that consent has been re-obtained.
7.6 Child-friendly summary
A short, plain-language summary of how we handle children's data — written for students aged 13–18 themselves — is published at class2class.org/privacy-for-students. We encourage teachers to introduce it in class.
International transfers — where your data goes
Class2Class is a Danish company. Our primary data storage is in the European Union (Supabase, EU region eu-west-1). Some of our sub-processors are established outside the European Economic Area (EEA), so a portion of your personal data is transferred to the United States or other third countries to deliver specific services (analytics, the customer-support chatbot, the model providers behind our AI features, marketing tools where you have given consent).
For each US-based sub-processor we rely on the European Commission's Standard Contractual Clauses (SCCs) supplemented by a Transfer Impact Assessment (TIA) that we maintain internally per the Schrems II judgment and EDPB Recommendations 01/2020. The TIA is reviewed annually and on every change to a sub-processor's data location or contractual terms.
Where a sub-processor is certified under the EU–U.S. Data Privacy Framework (DPF) — for example, Google LLC, which covers Google Analytics, Google Ads, Google Tag Manager, Google Cloud / BigQuery, and Google's Gemini API — we additionally rely on the European Commission's Adequacy Decision (EU) 2023/1795 of 10 July 2023 as a primary transfer basis. SCCs are retained as a fallback mechanism; the TIA is still maintained.
The current sub-processors and their transfer mechanisms are listed in our public Sub-processor List. Highlights:
- Mixpanel (US — SCCs + TIA; being retired, superseded by PostHog — historical data only)
- CookieYes (India — SCCs + TIA; consent management platform)
- Google Analytics (US — Google LLC DPF-certified + SCCs as fallback + TIA + IP anonymisation)
- Google Ads (US: Google LLC DPF-certified + SCCs as fallback + TIA; ad measurement for teachers who accept Marketing, never students)
- Meta (US — SCCs + TIA, marketing only with consent)
- Chatbase (US — SCCs + TIA + contractual no-AI-training-on-user-data commitment)
- OpenAI (US — SCCs + TIA; standard API with no-training-by-default and 30-day retention for abuse monitoring; powers the Project Creation Assistant text generation, teacher-only)
- Google (Gemini API) (US — Google LLC DPF-certified + SCCs as fallback + TIA + contractual no-AI-training-on-user-data commitment; powers Project Image Generation, teacher-only)
- Anthropic (Claude AI) (US — SCCs + TIA + contractual no-AI-training-on-user-data commitment; default model for Project Creation Assistant text generation, teacher-only, and staff-only internal analytics over the BigQuery data warehouse)
EU-based sub-processors (no transfer outside EEA): Supabase (EU region eu-west-1 — platform database, authentication, file storage and realtime), Xano (EU residency, legacy authentication paths only), Brevo, Vercel (EU regions, platform hosting and the AI Gateway), PostHog (EU Cloud, Frankfurt — product-usage analytics; cookies and identification consent-gated; limited cookieless analytics based on legitimate interests; teacher heatmaps with Statistical consent; student heatmaps and session replay off), Stape (Estonia — first-party server-side tagging proxy), Sentry (EU region, Frankfurt — error & performance monitoring; no personal data sent by default and remaining event data scrubbed; retention ≈ 30 days), Google Cloud — BigQuery (EU regions for the centralised data warehouse), Airbyte (EU deployment for the ETL pipelines that load BigQuery).
Sub-processors
We engage sub-processors to deliver parts of the platform — for example, the database, the email service, the customer-support chatbot. Every sub-processor:
- Has been reviewed before engagement and at least annually thereafter
- Is listed publicly at class2class.org/data-processing-agreement
We notify partners and schools at least 30 calendar days in advance of any addition, replacement, or material change to the sub-processor list, via the contact on file under their signed DPA. Partners and schools may object on reasonable data-protection grounds within 15 calendar days. Individual users (teachers, parents) who want to be notified of material changes can write to dpo@class2class.org.
Google processes the data behind enhanced conversions, Google Analytics and Google Tag Manager on our behalf, under the Google Ads Data Processing Terms. When we report a sign-up or a first connection to Google Ads with the ad's click identifier alone, Google uses that identifier as an independent controller, under its own privacy policy.
We do not sell your personal data to anyone. Sub-processors are bound to use Class2Class data only to deliver the service for which they are engaged.
Cookies
Cookies and similar technologies are governed by our separate Cookie Policy. The Cookie Policy describes the four categories of cookies we use (Necessary, Functional, Statistical, Marketing), the cookies in each category, our consent banner, and how to change your preferences at any time.
We do not use cookie walls. You can use the essential platform features without consenting to non-essential cookies.
Your rights
Under the GDPR, you have the following rights in respect of your personal data. We honour all of them, with the limited exceptions described in the GDPR itself (for example, where a deletion request would conflict with our legal obligations).
| Right | What it means | How to use it |
|---|---|---|
| Access (Art. 15) | Receive a copy of the personal data we hold about you | Use Settings → Download your data, or write to dpo@class2class.org |
| Rectification (Art. 16) | Correct inaccurate or out-of-date data | Use the in-platform profile screens, or write to dpo@class2class.org |
| Erasure (Art. 17) | Request deletion of your data, subject to legal retention | Write to dpo@class2class.org |
| Restriction (Art. 18) | Limit how we process your data while a question or dispute is resolved | Write to dpo@class2class.org |
| Portability (Art. 20) | Receive the data you provided, together with your platform activity, in a structured, machine-readable file (JSON; CSV on request) | Use Settings → Download your data, or write to dpo@class2class.org |
| Object (Art. 21) | Object to processing based on legitimate interest, on grounds relating to your particular situation | Write to dpo@class2class.org |
| Withdraw consent (Art. 7(3)) | Withdraw consent for processing based on consent (e.g. marketing, non-essential cookies) — does not affect processing already lawfully done | Use the in-platform settings, the unsubscribe link in marketing emails, or write to dpo@class2class.org |
| No solely automated decisions (Art. 22) | Class2Class does not make solely automated decisions about you that produce legal or similarly significant effects | Documented in §6.2 |
| Lodge a complaint | Complain to a data protection authority | Datatilsynet — dt@datatilsynet.dk; or your own national supervisory authority |
We respond to data-rights requests within 30 calendar days of receipt (GDPR Art. 12(3)). Where a request is unusually complex, we may extend by up to 60 additional days, with written notice to you and the reason for the extension. There is no fee for these requests, except where the request is manifestly unfounded or excessive.
If your request relates to a child's data, see §7.4.
A portability export contains the data you provided to us (such as your profile, projects, posts, reflections, messages, and certificates) together with the activity you generated on the platform. It is assembled from our operational database and delivered as a JSON file (CSV on request). It does not include data we derive internally — for example aggregated analytics — or data about other users, both of which fall outside the scope of Article 20.
Security
We implement appropriate technical and organisational measures to protect your personal data, in line with GDPR Article 32. Highlights:
- Encryption in transit — TLS 1.2+ across all connections to the platform.
- Encryption at rest — provided by Supabase in the EU storage layer.
- Password storage — passwords are stored using bcrypt, the modern adaptive hashing algorithm recommended by OWASP and NIST SP 800-63B. Hashing is performed by Supabase Auth in the EU. Imported accounts that have not signed in since the migration are still verified against the legacy Xano store until that path retires.
- Role-based access control — Class2Class staff access to personal data is restricted by role and logged.
- Multi-factor authentication — required for administrative access to platform infrastructure.
- Sub-processor due diligence — every sub-processor has been reviewed and has a signed DPA.
- Regular security audits — annual security reviews, supplemented by ad-hoc reviews on incident or material change.
- Security frameworks — our controls are mapped and continuously monitored against ISO 27001 and SOC 2. The ISO 27001 certification audit and the SOC 2 attestation are in progress, so we do not yet hold either report. Current control status is published on our Trust Centre.
- Incident response — a documented Data Breach Response Procedure covers detection, classification, regulatory notification within 72 hours under GDPR Art. 33, and notification to affected individuals under Art. 34 where required.
We have completed a Data Protection Impact Assessment (DPIA) for the platform that identifies and mitigates 10 core risks, with overall residual risk assessed as Low to Moderate (acceptable). The DPIA is reviewed annually.
Changes to this statement
We may update this statement to reflect changes in our services, applicable law, or our compliance commitments.
| Change type | What we do |
|---|---|
| Material change (e.g. new processing purpose, new sub-processor category, change in retention) | Notify users at least 14 calendar days in advance via the email on the account or via a platform announcement; partner schools are notified per the signed DPA |
| Minor change (e.g. typographical correction, clarification, update to a sub-processor URL) | Apply directly; the version number and "Last updated" date at the top always reflect the current state |
Continued use of the platform after the notice period constitutes acceptance of the revised statement. If you do not agree, you can close your account during the notice period — see Terms & Conditions §9.5.
Accessibility
Our standalone Accessibility Statement describes our commitment to WCAG 2.1 Level AA and the European Accessibility Act.
If a feature of this Privacy & Accessibility statement (or any other document we publish) is not accessible to you in its current form, write to support@class2class.org (subject "Accessibility") and we will provide it in an alternative format.
Contact
| If you want to | Use this contact |
|---|---|
| Exercise a data right (access, rectification, erasure, restriction, portability, object, withdraw consent) | dpo@class2class.org |
| Ask a privacy question | dpo@class2class.org |
| Raise a safeguarding concern about a minor | anton@class2class.org (Anton Skriver, Safeguarding contact) or support@class2class.org |
| Raise an ethical concern (general) | support@class2class.org |
| Raise an ethical concern that involves a Class2Class team member | jorgen@class2class.org (Jørgen Balle Olesen, CEO) |
| Raise an ethical concern that involves the CEO | class2class.org@gmail.com (Independent Reviewer) |
| Raise an anonymous concern | Anonymous Reports Form |
| Lodge a complaint with a supervisory authority | Datatilsynet — dt@datatilsynet.dk, or your own national authority |
The full reporting framework is described in the Ethical Guidelines §10 and in the Reports Handling and Whistleblower Procedure.
Related documents
- Terms & Conditions v.2.0
- Cookie Policy
- Sub-processor List
- Accessibility Statement
- Ethical Guidelines
- Code of Conduct
- Child-friendly Privacy Summary
- AI Literacy and Responsible Use guide
If any of these documents conflicts with this statement on a matter of substance, we apply the most protective interpretation for the data subject and resolve the conflict at the next document review. Tell us at dpo@class2class.org and we will fix it.
The questions we get most often.
Do you sell my data?
No. We do not sell your personal data to anyone — never have, never will. Sub-processors are bound to use Class2Class data only to deliver the service for which they are engaged. See §9 for the full statement.
Do you train AI models on my work?
No. We do not use your work, messages, images, or session recordings to train AI models — neither our own nor any third party's. This is contractually required of every AI sub-processor we use (Chatbase, OpenAI, Google Gemini, Anthropic). See §6.2 for the detail.
Where is my data stored?
Most platform data lives in the European Union — our platform database, authentication and file storage on Supabase in an EU region, our remaining Xano legacy authentication store with EU residency, our data warehouse on Google Cloud BigQuery in EU regions, and the platform itself hosted on Vercel in EU regions.
Some sub-processors are based in the US (Mixpanel, and the AI model providers behind the Project Creation Assistant — Anthropic as the default model, with OpenAI and Google Gemini as fallbacks and Gemini for project cover images). Those transfers are covered by Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, and a Transfer Impact Assessment we maintain internally. Section 8 has the full picture; Section 9 lists every sub-processor.
How do I exercise my GDPR rights?
Write to our Data Protection Officer at dpo@class2class.org. We respond within 30 calendar days, in line with GDPR Article 12(3). For unusually complex requests we may extend by up to 60 days with written notice.
Section 11 has the full table of rights with links. There is no fee.
My child is on Class2Class — what are my rights as a parent?
You can withdraw consent at any time (we'll block the student's access immediately while keeping their work intact in case consent is restored). You can request full account deletion, ask what data we hold, request corrections, and lodge a complaint with a supervisory authority.
Write to dpo@class2class.org for any of the above. For safeguarding concerns about your child's experience, write to Anton Skriver at anton@class2class.org. Section 7 has the dedicated treatment of children's privacy.
How are passwords stored?
Passwords are stored using bcrypt, the modern adaptive hashing algorithm recommended by OWASP and NIST SP 800-63B. Hashing is performed by Supabase Auth in the EU. We never store passwords in plain text. See §12 for the full security posture.
How will I know if you change this Policy?
For material changes — new processing purpose, new sub-processor category, change in retention — we notify users at least 14 calendar days in advance via email and a platform announcement, and partner schools per the signed DPA. The "Last updated" date at the top of the statement always reflects the current version. See §13.
My school is using Class2Class — is the platform GDPR-compliant for partner schools?
Yes. Where Class2Class processes student data on behalf of a school, the school is the controller and Class2Class is the processor under a signed Data Processing Agreement. The DPA covers Article 28(3) requirements end-to-end, including a sub-processor list, transfer mechanisms, breach notification SLAs, and AI-specific TOMs.
If you are a school administrator considering Class2Class, write to dpo@class2class.org for the current DPA template.
Have a privacy concern? Tell us.
Reports made in good faith are taken seriously, kept confidential, and protected from any form of retaliation. You can also lodge a complaint directly with Datatilsynet (the Danish Data Protection Authority) or your own national supervisory authority.
- Data rights & privacyGiancarlo Mena (DPO) — dpo@class2class.org
- Safeguarding (about a minor)Anton Skriver — anton@class2class.org
- General concernsupport@class2class.org
- Concern about the CEOIndependent Reviewer — class2class.org@gmail.com
- Supervisory authorityDatatilsynet — dt@datatilsynet.dk
OpenAI Ads measurement
Class2Class uses the OpenAI Ads Conversions API to measure the successful creation of a new free teacher account. This advertising use is separate from OpenAI model services used to help teachers prepare projects. We do not send public project page views, project-button clicks, email verification, profile completion or project participation to OpenAI Ads.
This measurement requires your explicit Marketing consent in CookieYes (the advertisement category). Statistical consent alone is insufficient. Global Privacy Control (GPC) and Do Not Track (DNT) override consent. Student sessions, student-directed pages, public project pages, login pages, returning sign-ins and unsuccessful registrations are excluded from advertising measurement.
The server event registration_completed contains a random event identifier, registration time, a website source indicator, a fixed registration-page address without query parameters or fragments, and the customer_action event category. Where available with advertising consent, it also includes the original OpenAI ad-click reference (oppref). Free registrations have no monetary value or currency attached.
We do not include a user object, contact details or their hashes, account identifiers, your IP address or your browser user-agent in these events. Every event carries opt_out: true as our default setting. This is not a user-made opt-out choice, does not replace consent and does not make OpenAI our processor for advertising.
After advertising consent, the first-party cookie c2c_openai_oppref can hold the ad-click reference, a random flow reference and its expiry time. It is restricted to the host that sets it and the /api/auth path. Its absolute lifetime is 20 minutes and ordinary navigation does not extend it. The integration does not install an OpenAI browser pixel or SDK.
While your choice is pending, no ad-click cookie is stored. The reference may remain in the current landing-page address so that accepting advertising on that page allows capture. Leaving the page, refusing or withdrawing consent, or GPC/DNT discards it. Later consent does not recover a discarded reference or measure earlier registrations. The cookie is also cleared after signup or sign-in. You can change your choice in the CookieYes preference centre.
A separate first-party session cookie, c2c_openai_ads_denied, stores only the value 1 to tell the server that advertising consent is refused or withdrawn, or that GPC or DNT applies. It contains no identifier and may be set without advertising consent to respect that choice. It is limited to the setting host and / path. It is cleared after an explicit advertising grant without a conflicting privacy signal. It never grants consent or restores an ad-click reference.
OpenAI Ireland Limited receives EEA and Swiss events as an independent controller under the Conversion Terms and Ad Tools Data Processing Addendum. We make no transfer outside the EEA for that processing; OpenAI is responsible for its onward transfers. UK events are received by OpenAI OpCo, LLC under the UK Standard Contractual Clauses (Module 1) incorporated in the addendum. OpenAI may use events for its own purposes under its terms, including measuring, optimising and delivering ads and developing and improving its products and services. This is separate from the no-training commitment of our AI-feature sub-processors. OpenAI Ads is a recipient, not an AI sub-processor. OpenAI retains events under its own terms; our servers log transport outcomes for troubleshooting.
PostHog product analytics and heatmaps
We use PostHog EU Cloud for product-usage and performance analytics on the platform and public website. With Statistical consent, it may use first-party cookies and browser storage; platform account identification is limited to consented sessions. Without that consent, limited cookieless analytics help us improve the service under our legitimate interests. We assess necessity, proportionality and your rights separately from consent for storage or access to your device. You may object by contacting dpo@class2class.org.
In cookieless mode we do not assign a persistent browser identifier or create an account-linked person profile. PostHog processes the IP address and browser user-agent to calculate a server-side hash with a daily rotating salt. This is limited measurement, not advertising, and does not support tracking the same visitor across days or devices. Statistical cookies remain subject to consent. Browser privacy signals are respected.
Platform heatmaps capture interaction coordinates for signed-in teachers with Statistical consent. Student, signed-out and unresolved sessions are excluded from heatmaps. Text and element attributes are masked. Project Viewed and Join Project Clicked are product events with the project id, sent only to PostHog for signed-in teachers with Statistical consent; these events are not sent to advertising platforms.
Session recordings and replay remain switched off. Before any recording pilot, we will complete DPIA screening, publish the approved configuration and updated notices, and give users 14 days and partner schools 30 days notice. The proposed pilot covers consented signed-in teachers only, with fully masked text, inputs and images, excluded sensitive content, no network or console capture, restricted product-team access and 30-day retention. No recording is enabled by this notice.
Have a question we didn't answer?
We update this statement when our services change, when applicable law changes, or when our compliance commitments tighten. Suggestions for improvement are welcome — write to our DPO at dpo@class2class.org.
Email the DPO