Data Processing Addendum

Last updated:

This Data Processing Addendum (DPA) under Article 28 GDPR is incorporated into the Terms of Service and governs the processing of personal data by ClassFlow (processor) on behalf of the customer (controller).

1. Roles

The customer acts as controller and ClassFlow as processor for Customer Data. For website/account/billing data, ClassFlow acts as controller (see the Privacy Policy).

2. Subject matter and duration

The subject matter is the provision of the Service. Processing lasts for the term of the agreement plus the 30-day retrieval period, after which data is deleted.

3. Nature and purposes

Processing includes storing, organising, displaying, exporting and deleting data, for the purpose of managing centre operations.

4. Documented instructions

We process Customer Data only on the customer's documented instructions, including with regard to international transfers, unless required by law — in which case we will inform you of that legal requirement before processing, unless the law prohibits it. We will promptly inform you if, in our opinion, an instruction infringes the GDPR or other applicable data-protection law.

5. Confidentiality

Our personnel with access to Customer Data are bound by confidentiality obligations.

6. Security measures

We implement the technical and organisational measures in Annex 2.

7. Assistance to the controller

We assist you, to the extent reasonable, in responding to data-subject requests and in complying with security, breach-notification, data protection impact assessment (DPIA) and supervisory-authority obligations.

8. Breach notification

We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Data.

9. Deletion or return

On termination, and at your choice, we delete or return Customer Data, including deleting existing copies, in line with the retention periods, unless applicable law requires the data to be retained — in which case we protect it and limit processing to what the law requires.

10. Audit and information

We make available the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an independent auditor mandated by you. Audits take place on reasonable prior notice, during normal business hours, no more than once per year (save where required by a supervisory authority or following a personal-data breach), and subject to confidentiality.

11. Subprocessors

You give a general authorisation for us to engage the subprocessors listed in Annex 3 and further subprocessors. By written contract we impose on each subprocessor data-protection obligations that are, in substance, equivalent to those set out in this DPA, and we remain fully liable to you for each subprocessor's performance. We will notify you in advance of any intended addition or replacement of a subprocessor, giving you the opportunity to object on reasonable data-protection grounds; in that case we will seek a reasonable resolution.

12. International transfers

Any transfer of Customer Data outside the EEA is carried out on your documented instructions or as authorised under this DPA, and only where an appropriate transfer mechanism is in place — in particular the EU Standard Contractual Clauses (SCCs), together with any supplementary measures required. Where a subprocessor is located outside the EEA, we ensure an equivalent transfer mechanism applies.

13. Government/disclosure requests

Where legally permitted, we will inform you of binding requests from public authorities relating to Customer Data.

14. Liability and hierarchy

In the event of conflict, this DPA prevails over the Terms with respect to data processing. Liability is governed by the Terms.

15. Governing law

Governing law: Republic of Cyprus.

Annex 1 — Processing details

Categories of data subjects: activity-centre administrators, staff/instructors, students, parents/guardians, emergency contacts, and other customer-provided individuals.

Categories of personal data:

  • Account and contact data.
  • Class and enrolment data, attendance, assessments, notes, certifications, availability and substitutions.
  • Student birth dates and emergency contacts.
  • Special category: allergies and medical conditions.
  • Audit data.

Annex 2 — Security measures

  • Encryption in transit (HTTPS).
  • Provider-managed encryption at rest, where confirmed.
  • Per-organisation tenant separation and authorization controls.
  • Role-based access.
  • Secrets/environment-variable management.
  • Logging and audit capabilities.
  • Backup and recovery arrangements.
  • Vulnerability/dependency management.
  • Incident response and access revocation.

Annex 3 — Subprocessors

Subprocessors
ProviderPurposeData categoriesLocationSafeguard
Vercel Inc.Application hosting, deployment, global CDN and cookieless traffic analytics (Vercel Analytics).All customer data in transit; technical request/usage and aggregate, anonymous traffic metrics.United States and global edge network.Data Processing Agreement with EU Standard Contractual Clauses.
Supabase Inc.Managed PostgreSQL database storing customer-controlled data.All account and customer-controlled data at rest (see Annex 1).European Union (eu-central-1, Frankfurt, Germany).EU hosting (Frankfurt); provider Data Processing Agreement with EU Standard Contractual Clauses.
Clerk Inc.Authentication, session management and user account administration.Administrator/staff identifiers, email addresses, authentication and session data.United States.Data Processing Agreement with EU Standard Contractual Clauses.
Resend (Plush Inc.)Transactional and notification email delivery.Recipient name and email address, and the content of the message sent.United States.Data Processing Agreement with EU Standard Contractual Clauses.
Stripe Payments Europe, Ltd.Subscription management, billing, payment processing and payment fraud prevention.Billing contact details, subscription and payment status, and payment card data processed directly by Stripe.European Union and United States; Stripe also acts as an independent controller for certain payment data.Data Processing Agreement with EU Standard Contractual Clauses.
Usercentrics A/S (Cookiebot)Consent management and maintenance of the consent record.Consent state, a consent identifier, truncated IP address and user-agent.European Union (Denmark/Germany).EU-based processing.
Cloudflare, Inc.Bot and abuse protection (Turnstile) for public forms.IP address, request metadata and challenge tokens used to distinguish humans from automated traffic.Global edge network.Data Processing Agreement with EU Standard Contractual Clauses.
PostHog, Inc.Product analytics, loaded only after statistics consent.Pseudonymous usage events, device/browser information and a pseudonymous identifier.PostHog Cloud, configured to use the EU Cloud endpoint, reached via the ClassFlow reverse proxy.Loaded only after statistics consent; EU Cloud endpoint as configured, with EU Standard Contractual Clauses for any transfer outside the EEA.