classroom.cloud Privacy Centre
Frequently Asked Questions on Privacy and Data Protection
1. Introduction
NetSupport have provided a range of documents and agreements for customers to review and agree with so that we can provide you with the classroom.cloud service. These agreements are, where possible, written with a Plain English approach but we are aware that some terms and sections may not be as easy to work through as we all might like.
As a result, we have taken previous information and looked how we can make sure that we give our customers sufficient support when they are talking to their data subjects/users. Some of this is also required under legislation such as COPPA in the US, but generally we see it as good practice and links in with our support for a Privacy First approach from customers.
2. What Are All The Various Documents And Agreements?
As the provider of classroom.cloud, we try to make sure that it is clear that we do so based on your needs and requirements. Often, we will refer to these as instructions. This simply means that we will only do what you tell use and won’t do things unless you allow us. Ye, that could mean that not all the functionality works as a result, and we might even say that we can no longer provide you with the service, but that is your choice as the customer.
All of this is governed by a few core documents.
2.1. Terms Of Service
The Terms of Service is our basic contract with you. You might get a quote from us, put in a purchase order, we send out an invoice and so on, but the core document is our Terms of Service. This tells you how the contract will run, what reasons we might stop it and sets out that you are buying a service from us. When the designated member of staff at your organisation (or your representative) logs in and sets up classroom.cloud, you must agree to these terms of service. If we must make a change to our terms we will let you know in the same way, so that we get a chance to show you agree once more.
2.2. Schedule 1: Data Processing Agreement
Schedule 1: Data Processing Agreement lets you know the definitions we use when talking about Person Data, such as the Data Controller (i.e. the customer/organization such as your school) and the Data Processor (i.e. NetSupport). The core details of the purposes and categories of data are included and broken down to make it clear about how it links to the different functions and the different data subjects it affects. We talk about how long we keep it for the data for and so on. This allows customers to complete their checks that we will only do what only do what they say, only keep it for how long it is really needed and not share it with anyone not involved in providing the service. It is really about being transparent and below we will provide more details about this.
2.3. Schedule 2: Data Processing Addendum For COPPA, FERPA And Other Regional Legislation
Because there are some very specific requirements covered by US Laws, Schedule 2: Data Processing Addendum for COPPA, FERPA and Other Regional Legislation allows us to set out how we cover them. When combined with the other documents, it gives an overall picture of how we comply with these laws. All our documents within our agreement with you have been externally verified and certified by iKeepafe.org, and is listed on their database of certified products – classroom.cloud – iKeepSafe
2.4. Schedule 3: Technical And Organisational Measures
We make every effort to be transparent about measures we take to keep all information confidential, safe and secure; to only use companies in our supply chain for development or as sub-processors to the service if we have completed detailed checks and, where needed, have the correct agreements and contracts in place with them. There is a lot of specific information that may need to be reviewed to allow customers to complete these checks on us, and so Schedule 3: Technical And Organisational Measures is aimed at covering that, being clear about any certification and independent, external checks we undergo, and any other information we think may be relevant to you and all our other customers.
Some areas we do not cover in as much detail as this is a public document, and we have both security and commercially sensitive information we don’t openly share, but we are always more than happy to discuss these areas with our customers and their authorised representatives.
2.5. Other Information
We know what this can still be a bit difficult to review and so provide these FAQs and the additional Privacy Notice aimed purely at parents and children. This covers all of our customers, but makes specific COPPA-related references.
We also provide a range of administrative, security and technical guides within the My Support area which customers can register and have access to.
In line with supporting schools with a privacy-first approach to using personal data, providing additional protections for staff and learners/end-users, we also provide guidance on Privacy by Design and by Default.
And finally, we regularly produce articles, case studies, webinars and videos on how classroom.cloud can be used for the most benefit for the delivery of education and learning.
3. School Privacy Notice (COPPA)
For some schools, noticeably those within the United States of America and where COPPA is applicable, there is a requirement to provide more direct notices on how personal data is being processed. Whilst it is the customer’s responsibility to make sure that there is sufficient communication with children and their families, we want to do everything we can to help. Working with iKeepSafe.org to assess and verify classroom.cloud, our terms and documentation, and we are now listed in their database of certified products – classroom.cloud – iKeepSafe
We have created a Privacy Notice aimed at children and their families which would meet the requirements set out for COPPA. This can be adapted for other regions by schools and we ask that if you do make any changes to it, please be clear that it is based on the one linked above but that you have adapted it.
4. Privacy by Design and by Default
Across the globe there is an increasing awareness about how technology and its use can be harmful to children, especially when insufficient planning happens or there is a lack of awareness of the possible impact. Technology is often looked at as the way to solve a problem, a silver bullet as the saying goes.
However, almost all countries state that we must take more care of the personal data of children, and the approach you may hear mentioned is to have a Privacy-first approach. You may hear it within the terms Data Protection by Design and by Default, or Security by Design and by Default within some laws or statutory guidance. This reinforces the very simple questions, “Do we really need to do this?” and “is there a less intrusive way?”
To help with this, we have provided a guide in what you can do within classroom.cloud to take a privacy first approach and allows you to work through the scenarios where some may feel you are intrusive but allows you to show how you worked out the best way of doing things. This is, of course, heavily tied in the completing a Data Protection Impact Assessment, the essential risk assessment all organisations should do when adopting different tools or procedures.
5. Support and User Guides
Although this is not always applicable for technology, we should not forget that range of additional guides and articles which are available via the My Support pages. These provide a range of guidance to not only help with your initial deployment but provide you with knowledge for technical and operational changes you may want to do within classroom.cloud.
If you have not already registered with My Support, it would be extremely beneficial to do so at your earliest convenience.
Publication date: 2023-07-10
Version: 1