Privacy Policy

Last updated:

This Privacy Policy explains how ClassFlow processes personal data in connection with the ClassFlow website and software service. ClassFlow is provided strictly to businesses — activity centres and their authorised adult representatives — and is not offered directly to children.

1. Scope and controller identity

ClassFlow operates the ClassFlow service ("ClassFlow", "we", "us"). This policy covers the processing we carry out as a controller, and explains how our role differs when we act as a processor on behalf of our customers.

Website: https://classflow.cy. For any privacy matter you can contact support@classflow.cy.

2. Our two GDPR roles

ClassFlow has two distinct roles:

  • As controller: for our website, demo enquiries, account administration, billing, support, security, and our business communications.
  • As processor: an activity centre (the customer) is the controller for the student, parent/guardian, instructor, attendance, assessment, health and operational data it enters into the service. We process that data only on the centre's documented instructions, under the Data Processing Addendum.

3. Business-to-business nature of the service

The service is provided to businesses. Accounts are created and used by adult, authorised representatives of the centres. ClassFlow is not intended to be used directly by children.

4. Categories of data subjects

  • Website visitors and prospects who submit a demo request.
  • Account administrators and staff/instructors of the centres.
  • Students and, where entered, parents/guardians and emergency contacts (data controlled by the centre).

5. Categories of personal data we process

As controller (website/account/billing):

  • Account and contact details of administrators/staff (name, email, role, authentication identifiers).
  • Demo request data: name, centre name, activity type, email, phone, student-count range, message, together with attribution details (UTM), referrer and landing page.
  • Billing and subscription details, payment status, and Stripe customer/subscription identifiers.
  • Device, browser, usage, consent, security and diagnostic information, where actually collected.

As processor (data entered by the centre):

  • Students: names, date of birth, experience level and related notes.
  • Parents/guardians and emergency contacts: name, phone, email and relationship.
  • Enrolments, class allocation, attendance, skills, assessments, notes, make-up credits and waiting lists.
  • Instructors: contact details, certifications, availability and substitutions.
  • Audit history recording the actor and the affected record.
  • Medical conditions and allergies — special-category health data (GDPR Article 9).

6. Sources of the data

We receive data directly from you (forms, account creation), from customer centres that enter data, and automatically through use of the service (technical/diagnostic data) and from our providers (for example, payment status from Stripe).

7. Purposes and lawful bases

PurposeLawful basis
Providing and administering the service and accountPerformance of a contract (Art. 6(1)(b))
Responding to demo requests and communicatingPre-contractual steps / legitimate interests (Art. 6(1)(b)/(f))
Billing, invoicing and tax obligationsContract / legal obligation (Art. 6(1)(b)/(c))
Security, abuse prevention and product improvementLegitimate interests (Art. 6(1)(f))
Usage analyticsConsent (Art. 6(1)(a))

For data entered by the centre we act as processor; the lawful basis is determined by the centre as controller.

8. Recipients and service providers

We do not sell personal data. We share data with carefully selected providers acting as processors, only as needed to operate the service (hosting, database, authentication, email, payments, consent management, security, analytics). The full list is in the Data Processing Addendum.

We may also disclose data where required by law or to establish, exercise or defend legal rights.

9. International transfers

The database is hosted in the EU (eu-central-1) and analytics are configured to use an EU endpoint. Some providers (for example, in the United States) may process data outside the EEA; where they do, appropriate safeguards apply, in particular the EU Standard Contractual Clauses (SCCs).

10. Retention periods

DataRetention
Unconverted demo requests12 months
Support correspondence24 months
Customer-controlled dataSubscription duration + 30-day retrieval period
Deleted production dataRemoved within 60 days
BackupsMaximum 90 days
Billing and tax recordsFor the period required by applicable Cyprus law
Consent/security recordsFor the period configured by the provider; rate-limiting data is held only transiently in memory

11. Security

We apply appropriate technical and organisational measures, including encryption in transit (HTTPS), provider-managed encryption at rest, per-organisation data isolation, role-based access control, secrets/environment-variable management, logging and audit history, backups, and vulnerability/dependency management. We do not claim certifications we do not hold.

12. Your rights

You have rights of access, rectification, erasure, restriction, portability and objection. You also have the right to withdraw consent at any time (without affecting the lawfulness of processing before withdrawal) and to object to processing based on legitimate interests.

To exercise your rights, contact support@classflow.cy. Requests concerning student data controlled by a centre should normally be directed to the relevant centre; we will assist the centre as processor.

13. Right to complain

You have the right to lodge a complaint with a supervisory authority. In Cyprus: Office of the Commissioner for Personal Data Protection (Cyprus).

14. Children's data and health data

A centre may enter data about minors, as well as medical conditions and allergies, which constitute special-category health data. Each centre is responsible for identifying its lawful basis and GDPR Article 9 condition, providing appropriate notices, and obtaining parent/guardian consent where legally required.

15. Automated decision-making

We do not make decisions producing legal or similarly significant effects based solely on automated processing.

16. Cookies and analytics

We use cookies and similar technologies. Statistics are loaded only after you consent. See the Cookie & Similar Technologies Policy.

17. Changes to this policy

We may update this policy. We will update the "Last updated" date and, for material changes, provide more prominent notice where appropriate.

18. Contact

For privacy matters: support@classflow.cy. General questions: info@classflow.cy.