Privacy policy
How Classbell handles personal data — what we control ourselves, what we only process on behalf of schools, and what you can do about either.
- Last updated
- 26 July 2026
- Effective from
- 26 July 2026
Draft — not yet reviewed by legal counsel
This document describes how the product actually works, but it has not been reviewed by a qualified lawyer and some company details are still outstanding. It is published for transparency and is not yet a binding legal document. Anything marked ▲ to be supplied is a known gap.
In short
A school that uses Classbell decides what pupil information exists, why it is collected and how long it is kept. We hold that information on the school’s behalf and act on its instructions. We do not own it, we do not sell it, and we do not use it to train models or to advertise.
There is a small amount of data we do decide about ourselves: the account details of the person who signs a school up, our billing records, and visits to this website. This policy covers both, kept clearly apart, because the rights you have and the person you exercise them against are different in each case.
The two roles, and why the distinction matters
Data protection law splits responsibility between a controller, who decides why and how personal data is used, and a processor, who acts on the controller’s documented instructions.
| Data | Controller | Our role |
|---|---|---|
| Pupil, guardian and staff records inside a school’s portal | The school | Processor |
| Account and billing details of the person who signs up | Classbell | Controller |
| Visits to this marketing website | Classbell | Controller |
Part A — Data we control
Visitors to this website
This site is a set of pre-rendered pages. It sets no cookies, runs no analytics or advertising scripts, embeds no third-party trackers, and self-hosts its fonts and video. See the cookie policy for the detail.
Our hosting provider processes standard request data — IP address, user agent, the URL requested, and a timestamp — to serve the page and to protect the service from attack and abuse. Our lawful basis is legitimate interests: we cannot run a website securely without it.
Account holders and billing contacts
When someone registers a school, we collect their name, work email address, the school name, and the billing details needed to take payment. We use this to create and administer the account, to authenticate the person signing in, to take subscription payments, to send service messages such as invitations and password resets, and to meet our own accounting and tax obligations.
Our lawful bases are performance of a contract for providing and billing the service, legal obligation for retaining financial records, and legitimate interests for keeping the service secure and for essential service communications.
We do not send marketing email to school users. Card details are entered directly with our payment provider and never reach our systems.
Part B — Data we process for schools
Everything a school records in its portal, we hold as processor. The school sets the purpose, the lawful basis and the retention period. Our obligations to the school are set out in the data processing agreement, which forms part of the contract.
What categories of data this covers
| People | Data |
|---|---|
| Pupils | Name, date of birth, nationality, identity-document number and expiry, admission number, photograph, contact email, previous school, sibling links, class and enrolment history, attendance records, assessment marks and report cards, fee and payment records, transport, library and boarding records where those modules are enabled Special category: Medical conditions, allergies, medication, dietary requirements and safeguarding notes, where a school chooses to record them |
| Parents and guardians | Name, relationship to pupil, email address, telephone number, postal address, and the payment and correspondence history associated with their account |
| Staff | Name, staff identifier, work email and telephone, employment and contract dates, qualifications and expiry, subject certifications, background-check status, work authorisation, campus scope, timetable and teaching load Special category: Background-check status, where a school chooses to record it |
| All account holders | Login email, hashed password, multi-factor authentication enrolment, session and sign-in records, and an audit trail of the actions taken in the system |
Special category and safeguarding data
Schools can record medical conditions, allergies, medication, dietary requirements and safeguarding notes. This is among the most sensitive data the law recognises, and the product treats it that way:
- It is stored separately from the main pupil record and shown only to roles the school has explicitly permitted.
- It never appears on a published document. Report cards carry no medical and no financial information, and say so on their face.
- Every access to and change of a pupil record is written to an audit log that no user can edit or erase.
Deciding whether to record this data at all, and on what lawful basis, is the school’s decision, not ours.
What we never do with it
- We do not sell it or share it for anyone’s marketing.
- We do not use it to train machine-learning models, our own or anyone else’s.
- We do not use one school’s data to build products for another, aggregated or otherwise.
- We do not access it except where necessary to run or support the service — and support access is recorded in the audit log.
Who else is involved
We use a small number of sub-processors to run the service. Each is bound by a contract that holds it to the same obligations we owe our customers, and the current list is published in full:
| Provider | Purpose | Status |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database, object storage, CDN and DDoS protection | In use |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery | In use |
| Stripe, Inc. | Subscription billing and card payment processing | Planned |
The full detail — what data reaches each one and where — is on the sub-processors page. We notify customers before adding a new sub-processor, so there is time to object.
We may also disclose data where the law requires it. If we receive a legally binding request for a school’s data, we will tell the school unless we are legally prohibited from doing so.
Where data is held
The primary database is hosted in Western Europe. Static assets are served from the hosting provider’s network location nearest the visitor, and transactional email is delivered through a provider in the United States.
Transfers outside the UK and EEA rely on the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses, together with the technical measures described on the security page. Data is encrypted in transit throughout.
How long data is kept
| What | How long | Why |
|---|---|---|
| Pupil, guardian and staff records | For as long as the school's subscription is active | The school decides its own retention schedule. Classbell retains records until the school deletes them or the account is closed. |
| Audit log | 7 years | Fixed by Classbell and not shortenable by a school, because an audit trail that a user can erase is not an audit trail. Records who changed what, when, and in which campus. |
| Financial records — invoices, payments, receipts | Retained for the life of the account, and never deleted in place | Payments are reversed with a compensating entry rather than deleted, and receipt numbering stays gapless. This is an accounting-integrity requirement, not a data-minimisation choice. |
| Invitation and password-reset links | 1 hour, single-use | Expire automatically. School-owner activation links last 72 hours. |
| Data after account closure | 30 days, then deleted | A 30-day window to export or reinstate, after which customer data is deleted from live systems. Backups age out on their own cycle. |
| Suspended or dormant accounts | Retained, not deleted | Suspension walls access to the portal but retains all data, so a school that resolves a billing issue gets its records back intact. |
Your rights
Depending on where you live, you have some or all of the following rights. They are exercised against the controller — which for school records means your school.
| Right | What it means |
|---|---|
| Access | Obtain a copy of the personal data held about you. |
| Rectification | Have inaccurate data corrected and incomplete data completed. |
| Erasure | Have data deleted, where no legal or contractual obligation requires the school to keep it. |
| Restriction | Limit how data is used while an accuracy or objection dispute is resolved. |
| Portability | Receive data in a structured, machine-readable format. |
| Objection | Object to processing carried out on the basis of legitimate interests. |
| Withdraw consent | Where processing relies on consent, withdraw it at any time without affecting prior processing. |
| Complain | Lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner's Office. |
For data we control — your account, billing, or this website — contact Privacy contact address — to be supplied. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
You can also complain to your local supervisory authority. In the UK that is the Information Commissioner’s Office; in the EU it is the authority for the country you live in.
How data is protected
Passwords are hashed, never stored in readable form. Sign-in supports multi-factor authentication. Invitation and password-reset links expire after one hour and work once. Every record is scoped to its school and campus at the data-access layer, so one school cannot reach another’s data. Sessions are bound to a single school. An immutable audit log records who changed what, when, and where.
The security page sets this out in full, including what we have not done — we hold no SOC 2 report and no ISO 27001 certification, and we do not claim otherwise.
Children
The product holds data about children, but children are not our customers and we have no direct relationship with them. A school decides what is recorded about a pupil and is responsible for the notices and consents that apply in its own jurisdiction. Pupil logins are issued by the school, never self-created, and a pupil can see only their own records.
Changes to this policy
We will post any change here and update the date at the top of the page. Where a change materially affects customers we give at least 30 days’ notice before it takes effect.
Contact
Controller: Registered legal name — to be supplied, of Registered address — to be supplied.
Privacy enquiries: Privacy contact address — to be supplied
Data Protection Officer: DPO name — to be supplied — DPO email — to be supplied
UK/EU representative: Art. 27 representative — to be supplied
General enquiries: info@axurs.com