Due to the changing landscape of Data Protection, Privacy and Security, we are updating our Terms of Service, Data Processing Agreement and other associated documents. As of 21st August 2026, the updated Terms will apply to all customers. The prior agreements can be found at Terms of Service – Legacy and Data Processing Agreement – Legacy, and these will still apply to new customers joining us between now and 21st August 2026.
On the above date, Org Admins will be asked to agree to the updated Terms of Service for continued access to the Service, and once authenticated, they will also be asked to agree to the updated Data Processing Agreement.
If you have any queries around this change, please contact the support team who will direct you to the appropriate assistance.
Schedule 1: classroom.cloud Data Processing Agreement
The importance of roles and relationships
If you are a NetSupport customer or subscriber, or just trialling our platform, this agreement applies to you. Schedule 1: classroom.cloud Data Processing Agreement, along with the Terms of Service and the other associated Schedules, forms our contract with you. You should check this agreement to make sure that this is understood to be the instructions that YOU (the Data Controller) give US (the Data Processor), as we are the provider of the classroom.cloud platform. This agreement is based on the UK GDPR, and also covers the principles which apply in other regions. Specific Schedules may also cover information for other regions.
Where we operate as a sub-processor to a Data Processor, the Terms of Service, this Schedule and other Schedules will form the agreement between us and we will act on the instructions from you (as Data Processor) on behalf of your customer (the Data Controller). For the duration of the agreement, we will use the term ‘Data Processor’ to show we are acting under your instructions on behalf of the Data Controller.
1 Definitions and Terms
Definitions and terms within this agreement are as set out below.
1.1. “Personal Data” means any information relating to an identified or identifiable natural person as defined by Data Protection Laws
1.2. “Data Controller” or “Controller” means you, the Customer, as the entity which determines the purpose and means of data processing
1.3. “Data Processor” or “Processor” means the entity processing the Personal Data (us/we) on behalf of the Data Controller, specifically in relation to being the agreed Service Provider.
1.4. “Sub-Processor” means an entity processing the Personal Data under instructions and written agreements of the Data Processor, as agreed and set out by the instructions from the Data Controller
1.5. “Additional Data Processor” means an entity which has a separate relationship as a Data Processor with the Data Controller outside of this agreement with the Service Provider. The Data Controller may provide instructions to transfer data to and from the Additional Data Processor through enabling integrations. Outside of these integrations and instructions, there is no relationship between the Data Processor (Service Provider) and the Additional Data Processor.
1.6. “Third Party” means an entity which is separate to the Data Controller, the Data Processor or any of their respective Sub-Processors. It is an independent Data Controller in their own right and as established within the UK GDPR and EU GDPR.
1.7. “Processing” means any operation performed on Personal Data, such as collection, storage, or deletion.
1.8. “Data Subject” means the individual whose Personal Data is processed.
1.9. “Data Protection Laws” means all applicable laws and regulations relating to data protection and privacy, including but not limited to:
1.9.1. General Data Protection Regulation (EU) 2016/679 (“EU GDPR”)
1.9.2. UK General Data Protection Regulation (“UK GDPR”)
1.9.3. UK Data Protection Act 2018
1.9.4. EU ePrivacy Directive (Directive 2002/58/EC)
1.9.5. Children’s Online Privacy Protection Act (“COPPA”) (15 U.S.C §§ 6501- 6506)
1.9.6. Family Educational Rights And Privacy Act (“FERPA”) (20 U.S.C. Section 1232g)
1.10. “Supervisory Authority” means an independent public authority established by an EU member state or the UK pursuant to EU GDPR or UK GDPR.
1.11. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed, as defined in Article 4(12) of the EU GDPR or UK GDPR
1.12. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries approved by the European Commission pursuant to GDPR Article 46(2)(c), as may be updated from time to time.
1.13. “UK IDTA” means the UK International Data Transfer Agreement issued by the UK Information Commissioner’s Office (ICO) pursuant to Section 119A of the UK Data Protection Act 2018.
1.14. “Restricted Transfer” means a transfer of Personal Data from the European Economic Area (“EEA”) or the United Kingdom (“UK”) to a country that has not been recognized by the European Commission or UK government as providing an adequate level of data protection.
1.15. Capitalised terms not defined in this Data Processing Agreement have the meaning set for within the Terms of Service.
2. Our Responsibilities
2.1. We are registered with the UK Information Commissioner’s Office, or any subsequent replacement authority, under number Z9139408.
2.2. As the service provider of classroom.cloud, we operate as the Data Processor of Personal Data (either directly or as the sub-processor). Conditions for delivery of the service as set out within the Terms of Service, and as set out within any instructions held within Schedule 1 or Schedule 2, or any other reasonable instruction by designated representatives as long as it is in line with the agreed services provided and does not interfere with the provision of the service. As the Data Processor, we will only process Personal Data in accordance with this DPA and Controller’s instructions (unless legally required to do otherwise). Where it is required the Processor will notify the Data Controller before processing any relevant Personal Data, unless specifically prohibited by Law.
2.3. If any processing of Personal Data may infringe applicable Data Protection Legislation, the Data Processor will notify the Data Controller immediately.
2.4. Security Measures
2.4.1. Any NetSupport personnel who have access to Customer Data will be bound by appropriate confidentiality obligations, as stipulated in Schedule 3: Technical and Organisational Measures.
2.4.2. NetSupport will use industry standard technical and organisational security measures to transfer, store and process Customer Data that, at a minimum, will comply with the Security Measures (Technical and Organisational Measures as outline in Schedule 3). The Security Measures are designed to protect the integrity of Customer Data and guard against the unauthorised or unlawful access to, use and processing of Customer NetSupport may update the Security Measures from time to time. NetSupport will provide Customers with at least sixty days (60) days’ prior notice if NetSupport updates the Security Measures in a manner that materially diminishes the administrative, technical or physical security features of the Services taken as a whole. We will provide all applicable information required for the demonstration of compliance with relevant Data Protection Legislation, including but not limited to reasonable assistance with the preparation of any Data Protection Impact Assessment.
2.4.3. We shall review the security of Processing at least once a year by performing checks to ensure that Processing complies with the Terms of Service and all relevant Schedules. The results of these checks will be made available to the Controller.
2.4.4. Data Loss
2.4.4.1. In the event of any Data Loss/Data Breach Event, the Processor shall complete the following, unless required to do otherwise by Law:
2.4.4.1.1 Notify the Data Controller without undue delay
2.4.4.1.2. Provide appropriate updates and information about the investigation of the Data Loss/Data Breach and in a timely manner
2.4.4.1.3. Make reasonable endeavours to contain, control and/or mitigate the effects of the Data loss/Data breach
2.4.4.1.4. Provide any reasonable assistance requested by the controller
2.4.4.1.5. Provide reasonable assistance to any applicable Supervisory Authority in relation to sections 2.4.4.1.1-2.4.4.1.4
2.5. Audits
2.5.1. The Controller or an agent it appoints (who cannot be a competitor of the Processor) is entitled to check that the Processor meets the requirements of this Agreement, Instructions and Data Protection Legislation. During such a check, the Processor shall assist the Controller, or the person carrying out the review on behalf of the Controller, with documentation, access to premises, IT systems and other assets needed to be able to check the compliance of the Controller with this Agreement, Instructions and Data Protection Legislation. The Controller shall ensure that staff who carry out the check are subject to confidentiality or non-disclosure obligations pertaining to law or agreement.
2.5.2. As an alternative to the stipulations of items 2.4.3–2.5.1, the Processor is entitled to offer other means of checking the Processing, such as checks carried out by independent third parties. In such a case, the Controller shall have the right, but not the obligation, to apply such alternative means. In the event of such a check, the Processor shall provide the Controller or third party with the assistance needed for performing the check.
2.6. Other requests for assistance from the Data Controller
Where the Data Processor is required to take action as part of a request, complaint or communication relating to obligations under Data Protection Legislation, the Data Processor will, where permitted by Law:
2.6.1.notify a designated representative of the Data Controller
2.6.2. provide any reasonable assistance requested by the Data Controller to support their compliance with applicable Data Protection Legislation including but not limited to:
2.6.2.1. Subject Access Requests
2.6.2.2. other Subject Requests
2.6.2.3. communications from regulatory authorities
3. Your Responsibilities
Please note that the following statements are to clarify the roles and relationships that affect how a Data Controller ensures their compliance with Data Protection Legislation. If you are reviewing this agreement as a Data Subject, please contact your organisation for more information about how this agreement affects you as an end-user/learner.
3.1. Check any contract or Terms of Service between us or any other document we have asked you to look at, as these may also have specific information that apply to you, including specific details for your region.
3.2. Read this Data Processing Agreement, including section 4: Sub-Processors and other relationships.
3.3. Read all other relevant Schedules and documentation, including Schedule 3: Technical and Organisational Measures
3.4. You will ensure that you have a legal basis for the Processing of any Personal Data at all times, and that this will enable the Data Processor to Process Personal Data upon your behalf.
3.5. By submitting the information to us, you confirm that you have the right to authorise us to process it on your behalf in accordance with the Terms of Service, and associated schedules, including Schedule 1: Data Processing Agreement. Where you have provided us with personal information as part of our service, or where your end-users (staff and children) have provided us with personal data, it will only be used for the reasons it was provided to us.
3.6. Complete any applicable risk assessments, including reviewing the most appropriate use of cloud in your school and considered its impact on privacy.
3.7. You will provide your Data Subjects with sufficient information about the nature and purposes of processing.
3.8. Review sufficient documentation and guidance for the design, deployment, implementation and maintenance of the Service for the duration of the subscription.
4. Sub-Processors and other relationships.
4.1. The Data Controller agrees to the Data Processor using the following Sub-Processors for the processing of Personal Data, including but not limited to the storage and hosting of Personal Data, and as set out within this agreement.
4.2. You agree that the Terms of Service, this agreement and other applicable Schedules provide the required information on the use of Sub-Processors.
4.3. All Sub-Processors shall be covered by written agreements between the Sub-Processor and the Data Processor and, where required by legislation, be governed by the same data protection obligations set out within this Schedule, the Terms of Service and any other applicable Schedules.
4.4. The Processor will give notification to the Controller of any replacements or additions to the list of Sub-Processors. Notification will be up to 30 calendar days to allow for any reasonable objection to such an appointment where it applies to processing of Personal Data on behalf of the Controller. Where like-for-like replacements are made to prevent the sudden degradation of the service or specific functionality, and due to circumstances outside the control of the Processor or the Controller, reasonable notifications will be made.
4.5. Where the appointment of additional Sub-Processors is related to new features or additional functionality, these features will not be available by default and where the Controller enables the functionality/features then it is on the understanding that they are accepting the addition of any new or replacement Sub-Processors.
4.6. If the Controller objects to the appointment of a new Sub-Processor under clause 4.4, both the Controller and Processor shall approach the concerns in good faith, with the aim of achieving resolution prior to any enactment of termination of the Terms of Service.
4.7. List of Sub-Processors
| Company/organisation | Address and contact details | Location of Personal Data (address, country) | Types of Personal Data Processed by the Sub-Processor | Purpose of processing by the Sub-Processor | Processing time | Additional information about the Sub-Processor’s Processing of Personal Data |
| Infrastructure | ||||||
| Microsoft Corporation (Microsoft Azure) | Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA. Contact: https://azure.microsoft.com/support | UK, US, DE (location dependent on location of customer) | User ID, device and session data, technical logs | Cloud hosting, storage and operation of the classroom.cloud service | Limited to the duration of the Agreement and agreed retention | Microsoft Data Protection Addendum and security documentation: https://www.microsoft.com/trust-center |
| ServiceCloud (from Salesforce) | EMEA Regional Headquarters SFDC Ireland Ltd. | Ireland | Contact details Technical details | To provide support and training.
| Limited to the duration of the Agreement and agreed retention | Salesforce/Legal For Salesforce Customers | Legal Salesforce/Compliance |
| Communications | ||||||
| Twilio SendGrid | Twilio Inc., 101 Spear Street, San Francisco, CA 94105, USA. Contact: [email protected] | USA / EU | System-related contact details and service messages | Delivery of system and service-related communications | Limited to the duration of the Agreement and agreed retention | https://www.twilio.com/legal/privacy (SCCs and IDTA in place, where applicable) |
| Tawk.to | Tawk.to Inc., 187 East Warm Springs Rd, SB298, Las Vegas, NV 89119, USA. Contact: [email protected] | EU / USA | Support-related identifiers and technical information | Customer support and service communication | Limited to the duration of the Agreement and agreed retention | https://www.tawk.to/privacy-policy (SCCs and IDTA in place, where applicable) |
| Support | ||||||
| Image Analyzer | Towngate House, 2-8 Parkstone Road, Poole, Dorset, BH15 2PW | UK | Images and videos from user activities | To reduce or remove false positive identifications on image/video analysis | Limited to the duration of the Agreement and agreed retention | Image Analyzer Privacy Policy |
| South West Grid for Learning | Belvedere House, Woodwater Park, Pynes Hill, Exeter, Devon, UK EX2 5WS | UK | Safeguarding data and activities | To provide support for Assisted Monitoring tools | Limited to the duration of the Agreement and agreed retention | SWGfL Privacy Policy | SWGfL |
| Analytics | ||||||
| N/A – no sub-processor used for analytics | N/A | N/A | N/A | N/A | N/A | N/A |
5. Data Transfers to Third Countries (outside of EEA and/or UK)
5.1. Where Personal Data is transferred to a third country, i.e. outside of the UK and/or EEA, the Processor complies with the European Data Protection Board (EDPB) and ICO recommendations for transferring data outside of the EU and/or the UK. All data transfers are conducted in accordance with the UK GDPR and EU GDPR Articles 44-50. Where data is transferred, mechanisms for transfer are recorded within Schedule 1: Data Processing Agreement.
6. Personal Data collection, processing and retention
6.1. As part of the initial setup, subsequent configuration and deployment, and ongoing operation of the service, the Processor will collect and process Personal Data. This may be provided by the Controller, provided by the Data Subjects or collected automatically by the service. This includes, and is not limited to, the following:
6.1.1. Creation of staff accounts and roles
6.1.2. Creation of device and end-user groups
6.1.3. Monitoring and logging of devices and end-user activities during defined lessons
6.1.4. Monitoring, logging and/or review of devices and end-user activities for safeguarding and/or where the end-user reports a concern
6.1.5. Notification and/or email alerts about activities
6.1.6. Personal Data provided by or to Additional Data Processors, including relating to 6.1.1-6.1.5
6.2. Data Retention
6.2.1. At the end of the subscription or evaluation of the service, data will be retained for a 30 day period. At the end of the 30 day period, if the subscription has not been renewed or evaluation extended, then all data relating to the account will be deleted.
6.2.2. If the account is terminated by NetSupport Ltd, as set out within the Terms of Service, then all data may be removed immediately.
6.2.3. Historical safeguarding data and audit log data will be retained for a rolling 13-month period. Data older than 13 months will be purged from the system. If you require us to store data older than the 13 month period, then this may be enabled at additional cost.
6.2.4. Historical activity monitor data will be retained and made available for a rolling 90 day period. If you require us to store historical data for longer than the 90 day rolling period, then this may be enabled at additional cost.
6.2.5. Where required due to regulated authorities, additional data retention periods may be put in place when legally required to do so. The Processor will notify the Controller, unless there is a specific legal requirement not to do so.
6.2.6. At all times, the Controller will have access to export Personal Data from within the Service and no additional actions are required from the Processor to return data at the end of the agree retention periods.
6.3. What types of data we collect
6.3.1. Contact details
Staff:
Required
– Name
– email address
– role in the organisation;
Optional
– Photograph
– groups such as class/year/department
– contact numbers
– organisation details.
Learners:
Optional
– Name
– role in the organisation
– groups such as class/year/subjects/interests
– organisation details.
6.3.2. Technical data that identifies Data Subjects
Required
– IP address
– login information
– browser type
– time zone setting
– browser plug-in types
– geolocation information about where you might be
– the device you are using
– operating system and version
– applications installed and used
– websites accessed.
6.3.3. Data on how you use classroom.cloud during lessons
Dependent on subscription
– Images of the end-user desktop whilst they are working
– responses to surveys provided by the teacher/instructor
– requests for help/chats between learner and teacher/instructor
– rewards points
– applications used
– websites accessed
6.3.4. Data on how classroom.cloud is accessed or changes made
– Information on access to the teacher/admin portal
– changes to groups/devices/users
– an audit trail for any configuration changes and who made them
6.3.5. Data on how end-users/learners use the computer or device, for monitoring and safeguarding purposes
Dependent on subscription
– Images or video of the desktop whilst you are working
– matched phrases or keywords
– matched images or videos
– requests for help/chats between learner and teacher/instructor
– rewards points
– applications used and websites accessed
– anonymised details of false positives
6.3.6. Sensitive data?
We consider Sensitive Data to be Special Category Personal Data, as set out within UK GDPR, or Personal Data which may need to be treated with particular care, e.g. funding and scholarships (Pupil Premium/Free School Meals, etc), or family circumstances (in care, adoption, split parenting, etc).
We know that you will be using classroom.cloud in lessons and other general activities as part of life in your organisation. When your learners are using their devices during lessons, talk with others via their devices and share how they are feeling or their particular experiences, then you may be sharing sensitive information. You may also include learners in particular groups based on ‘sensitive data’ (like racial or ethnic origin, political opinions, religious/philosophical beliefs, genetic data, biometric data, health data, or data about their sexual life). Additionally, where safeguarding triggers are raised, this may also contain sensitive data based on what was being viewed/used at that time. Where you share sensitive information or we process it on your behalf, then it will be allowed based on how you, as an organisation, have agreed to it. We will process this information on the understanding that you have a Lawful Basis for processing it.
6.3.7. Enhancements, bugs and improvements
To ensure classroom.cloud remains fit for purpose, we will take specifically provided information to deal with any issues raised by the Data Controller. This may be used to identify bugs or support the development of additional functionality. Where instructed, we will anonymise any personal data to ensure any improvements or new features are not based specifically on customer data, only customer requirements.
7. Partners/Additional Data Processors
7.1. As part of the Service, integrations with Additional Data Processors may be enabled by the Data Controller, and as defined in section 1.5.
7.2. Any integration with an Additional Data Processor is reliant of the designated and authorised representative of the Data Controller granting the appropriate permissions to enable the transfer of Personal Data to and/or from the Service to that Additional Data Processor within that Additional Data Processor’s systems or environment.
7.3. During initial setup and configuration, NetSupport will provide the technical request for these permissions to be set, but it is the responsibility to ensure that these are appropriate and limited to that required to enable the integration(s) to take place.
7.4. It is the responsibility of the Data Controller to ensure that access to subsequent Personal Data within the Service is granted based on available roles within classroom.cloud and/or within the systems of the Additional Data Processor.
7.5. Disabling of any integration with Additional Data Processors can be completed through the Service configuration or by disabling access through the Additional Data Processor. Any issues or faults generated by solely disabling with the Additional Data Controller will be dealt with by NetSupport on a reasonable grounds basis.
7.6. The list of present integrations and partners is as follows:
| Integrations (optional) | |||
| Service provider | Data collected or processed | Purpose | Place of processing |
| Microsoft SDS/M365 |
| To enable access to the platform and access to relevant class groups. To provide monitoring of key aspects of M365. | Regionally specific |
| Google Classroom |
| To enable access to the platform and access to relevant class groups. | Regionally specific |
| ClassLink |
| To enable access to the platform and access to relevant class groups. | Regionally specific |
| Clever (US hosted customers only) |
| To enable access to the platform and access to relevant class groups | US |
| MyConcern |
| To provide information on possible safeguarding issues | UK |
| CPOMS |
| To provide information on possible safeguarding issues | UK |
8. The use of Cookies
8.1. To enable the provision of parts of the Service, we use cookies. Unless you adjust your browser settings to refuse them, we (and our sub-processors) will issue cookies when you interact with cloud. These may be session cookies, meaning they delete themselves when you leave classroom.cloudor ‘persistent’ cookies which do not delete themselves and help us to recognise you when you return so we can provide you with requested Service.
8.2. Where cookies are blocked, through activating a setting within browsers, the use of plug-ins or the prevention of connection to the Service or API distributing the Cookie, this is considered to refusing the Cookie. All provided Cookies are considered to be essential, and if you disable, reject or block these cookies certain parts of the Service will not function fully. In some cases, the platform may not be available at all. Please note that where sub-processors use Cookies it is also to enable the Service to work correctly.
8.3. Cookies from Additional Data Processors. Where Additional Data Processors set cookies, this is deemed to be a separate arrangement directly between you and the Additional Data Processor. Where these Cookies are disabled, rejected or blocked, NetSupport may not be able to complete any integration with the Additional Data Processor, as this would be outside of our control.
8.4. The cookies used for the Service are as follows:
| Service provider | Key cookies | Purpose |
| NetSupport | ARRAffinity | Identity and authentication |
| ARRAffinitySameSite | Identity and authentication | |
| .AspNetCore.Antiforgery.w5W7x28NAIs | Identity and authentication | |
| idsrv | Identity and authentication | |
| Tawk | __tawkuuid | Support |
| ss | Support | |
| tawkUUID | Support | |
| TawkConnectionTime | Support |
Publication date: 2026-07-21
Version: 2
What’s new
Terms of Service, Data Processing Agreement and additional schedules restructured to improve meeting requirements for customers under UK, EU and US legislations, or to meet additional certification/standards requirements