
Data Processing Addendum
Last updated September 13, 2026
This Data Processing Addendum (“DPA”) applies to business customers who use ClassFactor on behalf of an organisation and request a DPA by emailing support@classfactor.com. It sets out how ClassFactor processes personal data on the customer’s behalf and forms part of the customer’s agreement with us. Individuals who use ClassFactor for their own study are covered by our Privacy Policy (/privacy) rather than this DPA.
Parties and application
This DPA is between First Capital Merchant Solutions, Inc., a Florida corporation doing business as ClassFactor, of 10001 NW 50th St, Ste 114, Sunrise, FL 33351-8087, USA (“ClassFactor”, “we”, “us”), and the business customer that has requested and executed this DPA (“Customer”).
This DPA supplements our Terms of Service (/terms) and any other agreement under which Customer uses the ClassFactor services (together, the “Agreement”). It applies only where Customer uses the Services on behalf of an organisation and, in doing so, causes personal data to be processed by ClassFactor on Customer’s behalf.
ClassFactor is available worldwide. This DPA is designed to meet the requirements of the data protection laws that apply to that processing wherever Customer and its users are located.
Definitions
“Data Protection Laws” means all data protection and privacy laws that apply to the processing of Customer Personal Data under the Agreement, including, where applicable, Regulation (EU) 2016/679 (“GDPR”), the GDPR as it forms part of UK law together with the UK Data Protection Act 2018 (“UK GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (“CCPA”), and other US state privacy laws.
“Customer Personal Data” means personal data that ClassFactor processes on behalf of Customer in providing the Services. “Services” means the ClassFactor website, web app, iOS and Android apps and related services. “Sub-processor” means a third party engaged by ClassFactor that processes Customer Personal Data. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
The terms “controller”, “processor”, “data subject”, “personal data” and “processing” have the meanings given in the GDPR, and “business”, “service provider”, “sell” and “share” have the meanings given in the CCPA.
Roles of the parties
For Customer Personal Data, Customer is the controller (or a processor acting on behalf of another controller) and ClassFactor is the processor (or, where Customer is itself a processor, a sub-processor). For the purposes of the CCPA, Customer is the business and ClassFactor is the service provider.
ClassFactor acts as an independent controller for the personal data it needs to run its own business, including account registration and sign-in, billing and payment records, security, fraud and abuse prevention, and compliance with its legal obligations. That processing is described in our Privacy Policy (/privacy) and is not governed by this DPA.
Customer is responsible for having a lawful basis for the processing it instructs, for providing any notices and obtaining any consents required by Data Protection Laws, and for the accuracy and lawfulness of the Customer Personal Data it and its users submit to the Services.
Scope, nature, purpose and duration
Subject matter: provision of the ClassFactor AI study platform to Customer and the users Customer authorises.
Nature of processing: collection, storage, hosting, retrieval, transcription, text recognition, AI generation of study materials (such as flashcards, quizzes, exams, notes and lessons), AI tutor and study coach conversations including optional realtime voice calls, text-to-speech, delivery of notifications and emails, customer support, and deletion.
Purpose: to provide, secure and support the Services in accordance with the Agreement and Customer’s documented instructions.
Duration: for the term of the Agreement and until Customer Personal Data is deleted in accordance with the “Return and deletion” section below.
Categories of data subjects and personal data
Data subjects: Customer’s authorised users (such as employees, contractors and other individuals Customer permits to use the Services on its behalf), and individuals whose personal data appears in material those users upload.
Categories of personal data: names and email addresses; sign-in and session data, including IP address and user agent; uploaded files, links, recordings and the text extracted from them; generated study materials; AI tutor and study coach conversations, study profile information, and voice call audio and transcripts; study activity such as sessions, answers, scores, progress and streaks; support tickets, messages and attachments; notification preferences and device push tokens.
Special categories of personal data: the Services are not designed to process special categories of personal data, and Customer should not instruct ClassFactor to process them unless Customer has a lawful basis to do so and has informed ClassFactor in writing.
Processing on documented instructions
ClassFactor processes Customer Personal Data only on Customer’s documented instructions, which are the Agreement, this DPA and Customer’s use and configuration of the Services, unless processing is required by applicable law. In that case ClassFactor will inform Customer of the legal requirement before processing, unless the law prohibits it.
ClassFactor will tell Customer promptly if, in its opinion, an instruction infringes Data Protection Laws.
ClassFactor does not use Customer Personal Data to train its own AI models. The AI providers listed on our Subprocessors page (/subprocessors) process it under their commercial API terms, under which they do not use content submitted through the API to train their models and may retain it for a limited period, typically up to 30 days, for abuse and misuse monitoring.
CCPA service provider terms
Where the CCPA applies, ClassFactor will not sell or share Customer Personal Data; will not retain, use or disclose it for any purpose other than the business purposes of providing the Services under the Agreement, or outside the direct business relationship between ClassFactor and Customer, except as the CCPA permits; and will not combine it with personal information ClassFactor receives from or on behalf of another person or collects from its own interactions with consumers, except as the CCPA permits.
ClassFactor will comply with the obligations that apply to it as a service provider under the CCPA, provide the same level of privacy protection the CCPA requires of businesses, and notify Customer if it determines it can no longer meet those obligations. Customer may take reasonable and appropriate steps to ensure ClassFactor uses Customer Personal Data consistently with Customer’s CCPA obligations and to stop and remediate any unauthorised use.
ClassFactor certifies that it understands and will comply with the restrictions in this section.
Confidentiality
ClassFactor limits access to Customer Personal Data to personnel who need it to provide, secure or support the Services, and ensures that those personnel are bound by appropriate obligations of confidentiality.
Sub-processors
Customer gives ClassFactor general authorisation to engage Sub-processors. The current list, with each Sub-processor’s purpose, the data it processes and its location, is published at /subprocessors.
ClassFactor imposes data protection obligations on each Sub-processor by written contract that are no less protective in substance than those in this DPA, and remains responsible to Customer for each Sub-processor’s performance of those obligations.
ClassFactor will give at least 30 days’ notice before a new Sub-processor begins processing Customer Personal Data, by updating the Subprocessors page and emailing each customer that has signed this DPA at the notice email address it provided. Customer may object to a new Sub-processor on reasonable data protection grounds by emailing support@classfactor.com within that notice period. The parties will discuss the objection in good faith; if they cannot resolve it, Customer may stop using the affected part of the Services or terminate the Agreement.
Security measures
ClassFactor maintains the following technical and organisational measures: encryption of data in transit using TLS; encryption of data at rest by its hosting providers; hashed passwords; private file storage that is reachable only through short-lived signed links; access controls, including role-based administrative access with audit logging; rate limiting and bot protection; verification of app store purchases and signature checks on payment webhooks; and error reporting configured to remove one-time tokens.
No method of transmission or storage is completely secure, and ClassFactor cannot guarantee absolute security. ClassFactor may update these measures over time, provided that the updates do not materially reduce the overall protection of Customer Personal Data.
International transfers
ClassFactor and its Sub-processors process Customer Personal Data in the United States. Customer authorises these transfers, subject to this section.
To the extent Customer Personal Data subject to the GDPR is transferred to a country that has not received an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference: Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is a processor. Customer is the data exporter and ClassFactor is the data importer. Clause 7 (docking clause) applies; under Clause 9, Option 2 (general written authorisation) applies with the notice period set out in the “Sub-processors” section; the optional wording in Clause 11 does not apply; under Clause 17, the clauses are governed by the law of the EU Member State in which Customer is established; and under Clause 18, disputes are resolved by the courts of that Member State. Annex I is completed by the “Parties and application”, “Scope, nature, purpose and duration” and “Categories of data subjects and personal data” sections, Annex II by the “Security measures” section, and Annex III by the list at /subprocessors.
To the extent Customer Personal Data subject to the UK GDPR is transferred outside the United Kingdom, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner is incorporated by reference, completed with the information in this DPA, and either party may end it as permitted by its Section 19.
Where a Sub-processor is certified under the EU-U.S. Data Privacy Framework and its UK Extension, ClassFactor may also rely on that certification for onward transfers to that Sub-processor.
Personal Data Breach notification
ClassFactor will notify Customer without undue delay, and in any event no later than 72 hours, after confirming a Personal Data Breach affecting Customer Personal Data.
The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, its likely consequences, and the measures taken or proposed to address it. Where not all of this information is available at once, ClassFactor will provide it in phases as it becomes available.
ClassFactor will take reasonable steps to contain, investigate and remediate the breach. Notifying Customer of a Personal Data Breach is not an acknowledgement of fault or liability.
Data subject requests and assistance
The Services include tools that let users export their data (Settings → Account → Your data) and delete their accounts. Taking into account the nature of the processing, ClassFactor will provide reasonable assistance to help Customer respond to requests from data subjects to exercise their rights under Data Protection Laws.
If ClassFactor receives a request directly from a data subject that relates to Customer Personal Data, it will promptly tell Customer and will not respond to the request itself other than to direct the data subject to Customer, unless required by law.
ClassFactor will provide reasonable assistance, taking into account the nature of the processing and the information available to it, with Customer’s data protection impact assessments and any related prior consultations with supervisory authorities.
Audits and information
ClassFactor will make available the information reasonably necessary to demonstrate its compliance with this DPA. ClassFactor will first meet audit requests by providing documentation of its security measures and written answers to reasonable security and privacy questionnaires, no more than once in any twelve-month period unless a Personal Data Breach has occurred or a supervisory authority requires otherwise.
If Data Protection Laws or a supervisory authority require an on-site audit or inspection that the documentation cannot satisfy, ClassFactor will allow one, conducted by Customer or an independent auditor bound by confidentiality, on reasonable advance written notice, during normal business hours, with a scope agreed in advance and in a way that does not disrupt the Services or compromise the confidentiality of other customers’ data. Customer bears the cost of any such audit.
Return and deletion
During the term of the Agreement, Customer and its users can export their data with the export tools in the Services.
When the Agreement ends, or earlier on Customer’s written request, ClassFactor will delete Customer Personal Data within 30 days, unless applicable law requires it to be retained. Deleted data may remain in encrypted database backups for up to 30 days before those backups are overwritten. Billing and AI usage records are retained in de-identified form for as long as the law requires, generally up to seven years, for tax, accounting and fraud-prevention purposes.
On request, ClassFactor will confirm the deletion to Customer in writing.
Liability
Each party’s liability arising out of or in connection with this DPA, including the Standard Contractual Clauses, is subject to the limitations and exclusions of liability in the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits either party’s liability to data subjects where Data Protection Laws or the Standard Contractual Clauses do not permit it.
Precedence and term
If there is a conflict, the following order of precedence applies: first, the Standard Contractual Clauses and the UK Addendum, where they apply; second, this DPA; and third, the rest of the Agreement.
This DPA takes effect when ClassFactor countersigns it and remains in effect for as long as ClassFactor processes Customer Personal Data.
Governing law
Except where the Standard Contractual Clauses, the UK Addendum or Data Protection Laws require otherwise, this DPA is governed by the same law, and disputes under it are resolved in the same way, as set out in the Terms of Service.
How to execute this DPA
To request a countersigned copy of this DPA, email support@classfactor.com from the email address on the account your organisation uses. Please include your organisation’s legal name and address, the name and title of the person signing, and the email address where you would like to receive notices about new Sub-processors. We will send a countersigned copy for your records.
Notices to ClassFactor under this DPA may be sent to support@classfactor.com or by post to First Capital Merchant Solutions, Inc. d/b/a ClassFactor, 10001 NW 50th St, Ste 114, Sunrise, FL 33351-8087, USA.