← Back to home

Privacy policy

How Classbell handles personal data — what we control ourselves, what we only process on behalf of schools, and what you can do about either.

Last updated
26 July 2026
Effective from
26 July 2026

Draft — not yet reviewed by legal counsel

This document describes how the product actually works, but it has not been reviewed by a qualified lawyer and some company details are still outstanding. It is published for transparency and is not yet a binding legal document. Anything marked ▲ to be supplied is a known gap.

In short

A school that uses Classbell decides what pupil information exists, why it is collected and how long it is kept. We hold that information on the school’s behalf and act on its instructions. We do not own it, we do not sell it, and we do not use it to train models or to advertise.

There is a small amount of data we do decide about ourselves: the account details of the person who signs a school up, our billing records, and visits to this website. This policy covers both, kept clearly apart, because the rights you have and the person you exercise them against are different in each case.

The two roles, and why the distinction matters

Data protection law splits responsibility between a controller, who decides why and how personal data is used, and a processor, who acts on the controller’s documented instructions.

DataControllerOur role
Pupil, guardian and staff records inside a school’s portalThe schoolProcessor
Account and billing details of the person who signs upClassbellController
Visits to this marketing websiteClassbellController

Part A — Data we control

Visitors to this website

This site is a set of pre-rendered pages. It sets no cookies, runs no analytics or advertising scripts, embeds no third-party trackers, and self-hosts its fonts and video. See the cookie policy for the detail.

Our hosting provider processes standard request data — IP address, user agent, the URL requested, and a timestamp — to serve the page and to protect the service from attack and abuse. Our lawful basis is legitimate interests: we cannot run a website securely without it.

Account holders and billing contacts

When someone registers a school, we collect their name, work email address, the school name, and the billing details needed to take payment. We use this to create and administer the account, to authenticate the person signing in, to take subscription payments, to send service messages such as invitations and password resets, and to meet our own accounting and tax obligations.

Our lawful bases are performance of a contract for providing and billing the service, legal obligation for retaining financial records, and legitimate interests for keeping the service secure and for essential service communications.

We do not send marketing email to school users. Card details are entered directly with our payment provider and never reach our systems.


Part B — Data we process for schools

Everything a school records in its portal, we hold as processor. The school sets the purpose, the lawful basis and the retention period. Our obligations to the school are set out in the data processing agreement, which forms part of the contract.

What categories of data this covers

PeopleData
PupilsName, date of birth, nationality, identity-document number and expiry, admission number, photograph, contact email, previous school, sibling links, class and enrolment history, attendance records, assessment marks and report cards, fee and payment records, transport, library and boarding records where those modules are enabled
Special category: Medical conditions, allergies, medication, dietary requirements and safeguarding notes, where a school chooses to record them
Parents and guardiansName, relationship to pupil, email address, telephone number, postal address, and the payment and correspondence history associated with their account
StaffName, staff identifier, work email and telephone, employment and contract dates, qualifications and expiry, subject certifications, background-check status, work authorisation, campus scope, timetable and teaching load
Special category: Background-check status, where a school chooses to record it
All account holdersLogin email, hashed password, multi-factor authentication enrolment, session and sign-in records, and an audit trail of the actions taken in the system

Special category and safeguarding data

Schools can record medical conditions, allergies, medication, dietary requirements and safeguarding notes. This is among the most sensitive data the law recognises, and the product treats it that way:

  • It is stored separately from the main pupil record and shown only to roles the school has explicitly permitted.
  • It never appears on a published document. Report cards carry no medical and no financial information, and say so on their face.
  • Every access to and change of a pupil record is written to an audit log that no user can edit or erase.

Deciding whether to record this data at all, and on what lawful basis, is the school’s decision, not ours.

What we never do with it

  • We do not sell it or share it for anyone’s marketing.
  • We do not use it to train machine-learning models, our own or anyone else’s.
  • We do not use one school’s data to build products for another, aggregated or otherwise.
  • We do not access it except where necessary to run or support the service — and support access is recorded in the audit log.

Who else is involved

We use a small number of sub-processors to run the service. Each is bound by a contract that holds it to the same obligations we owe our customers, and the current list is published in full:

ProviderPurposeStatus
Cloudflare, Inc.Application hosting, database, object storage, CDN and DDoS protectionIn use
Postmark (ActiveCampaign, LLC)Transactional email deliveryIn use
Stripe, Inc.Subscription billing and card payment processingPlanned

The full detail — what data reaches each one and where — is on the sub-processors page. We notify customers before adding a new sub-processor, so there is time to object.

We may also disclose data where the law requires it. If we receive a legally binding request for a school’s data, we will tell the school unless we are legally prohibited from doing so.

Where data is held

The primary database is hosted in Western Europe. Static assets are served from the hosting provider’s network location nearest the visitor, and transactional email is delivered through a provider in the United States.

Transfers outside the UK and EEA rely on the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses, together with the technical measures described on the security page. Data is encrypted in transit throughout.

How long data is kept

WhatHow longWhy
Pupil, guardian and staff recordsFor as long as the school's subscription is activeThe school decides its own retention schedule. Classbell retains records until the school deletes them or the account is closed.
Audit log7 yearsFixed by Classbell and not shortenable by a school, because an audit trail that a user can erase is not an audit trail. Records who changed what, when, and in which campus.
Financial records — invoices, payments, receiptsRetained for the life of the account, and never deleted in placePayments are reversed with a compensating entry rather than deleted, and receipt numbering stays gapless. This is an accounting-integrity requirement, not a data-minimisation choice.
Invitation and password-reset links1 hour, single-useExpire automatically. School-owner activation links last 72 hours.
Data after account closure30 days, then deletedA 30-day window to export or reinstate, after which customer data is deleted from live systems. Backups age out on their own cycle.
Suspended or dormant accountsRetained, not deletedSuspension walls access to the portal but retains all data, so a school that resolves a billing issue gets its records back intact.

Your rights

Depending on where you live, you have some or all of the following rights. They are exercised against the controller — which for school records means your school.

RightWhat it means
AccessObtain a copy of the personal data held about you.
RectificationHave inaccurate data corrected and incomplete data completed.
ErasureHave data deleted, where no legal or contractual obligation requires the school to keep it.
RestrictionLimit how data is used while an accuracy or objection dispute is resolved.
PortabilityReceive data in a structured, machine-readable format.
ObjectionObject to processing carried out on the basis of legitimate interests.
Withdraw consentWhere processing relies on consent, withdraw it at any time without affecting prior processing.
ComplainLodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner's Office.

For data we control — your account, billing, or this website — contact Privacy contact address — to be supplied. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

You can also complain to your local supervisory authority. In the UK that is the Information Commissioner’s Office; in the EU it is the authority for the country you live in.

How data is protected

Passwords are hashed, never stored in readable form. Sign-in supports multi-factor authentication. Invitation and password-reset links expire after one hour and work once. Every record is scoped to its school and campus at the data-access layer, so one school cannot reach another’s data. Sessions are bound to a single school. An immutable audit log records who changed what, when, and where.

The security page sets this out in full, including what we have not done — we hold no SOC 2 report and no ISO 27001 certification, and we do not claim otherwise.

Children

The product holds data about children, but children are not our customers and we have no direct relationship with them. A school decides what is recorded about a pupil and is responsible for the notices and consents that apply in its own jurisdiction. Pupil logins are issued by the school, never self-created, and a pupil can see only their own records.

Changes to this policy

We will post any change here and update the date at the top of the page. Where a change materially affects customers we give at least 30 days’ notice before it takes effect.

Contact

Controller: Registered legal name — to be supplied, of Registered address — to be supplied.

Privacy enquiries: Privacy contact address — to be supplied

Data Protection Officer: DPO name — to be supplied DPO email — to be supplied

UK/EU representative: Art. 27 representative — to be supplied

General enquiries: info@axurs.com