Data processing addendum
Last updated June 1, 2026
This Data Processing Addendum (“DPA”) applies where ClassFactor processes personal data on behalf of a customer — for example, a school or program — and forms part of our agreement with that customer.
Roles of the parties
For personal data processed on behalf of a customer (such as student data provided by an institution), the customer is the “controller” and ClassFactor is the “processor.”
ClassFactor processes such data only on the customer’s documented instructions and to provide the Services.
Scope of processing
Subject matter: provision of the ClassFactor study platform.
Duration: for the term of the agreement.
Nature and purpose: hosting, generating study content, and enabling learning and analytics.
Categories of data: account identifiers, study content, and usage data of the customer’s authorized users.
Sub-processors
ClassFactor uses vetted sub-processors (such as cloud hosting and payment providers) under contracts imposing data-protection obligations no less protective than this DPA.
We maintain a current list of sub-processors and will notify customers of material changes so they may object.
Security measures
ClassFactor implements appropriate technical and organizational measures — encryption in transit and at rest, access controls, logging, and regular testing — consistent with applicable data-protection requirements.
International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), as required by law.
Personal-data breach notification
ClassFactor will notify the customer without undue delay after becoming aware of a personal-data breach affecting the customer’s data, and will provide the information reasonably needed for the customer to meet its own breach-notification obligations.
We maintain measures to detect, investigate, contain, and remediate security incidents.
Data-subject requests & assistance
ClassFactor will assist the customer, taking into account the nature of processing, in responding to data-subject requests (such as access, correction, deletion, and portability) and in meeting the customer’s obligations regarding security, breach notification, and data-protection impact assessments.
Audits & records
ClassFactor makes available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the customer or an auditor it mandates — on reasonable prior notice, no more than once per year absent a specific concern or legal requirement, and subject to confidentiality.
We may satisfy audit requests by providing current third-party reports or documentation of our security measures where available.
Return & deletion
On termination, ClassFactor will, at the customer’s choice, delete or return personal data processed on the customer’s behalf and delete existing copies, except where retention is required by law.
Precedence & liability
This DPA forms part of, and is subject to, the agreement between ClassFactor and the customer. In the event of a conflict on data-protection matters, this DPA controls over the rest of the agreement.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement.
How to execute this DPA
Institutional customers who require a signed DPA can request one by contacting legal@classfactor.com. We’re glad to work with your data-protection team.