Privacy Policy - Classigogo B.V.
Version: 3 October 2025
Company: Classigogo B.V. ("Classigogo", "we", "us" or "our")
Contact: info@classigogo.com
Registered address: Saturnusstraat 95, 2516AG, The Hague, Netherlands
KvK number: 94793778
VAT number: NL866894469B01
Jump to a section
1. Key points
- • Only adults (≥16 years) can create an account and make payments.
- • Students use Classigogo without their own account, under the supervision of a Teacher/School.
- • We do not ask for and do not knowingly collect directly identifiable data from children (such as name, email, phone, photo).
- • No sale of personal data; no behavioral advertising; children’s data are not used for marketing.
- • International transfers are covered by appropriate safeguards.
2. Roles and scope
Controller: for teacher/admin accounts, billing, support and our own marketing functions.
Processor: vis-à-vis schools/organizations for data supplied/generated by them relating to students and classroom use; our DPA applies.
3. Categories of data
- Account and contact data (adults): name, school, email, role/function, billing address, payment status, language/country.
- If you choose to use the option to log in or sign up with Google, your email address and profile information (such as your first and last name) will be requested from Google.
- This information is used to create an account and/or to verify that you are the owner of the respective email address.
- The information requested from Google will not be shared with third parties without your consent, just like your other data.
- Transaction and billing data: payment method, invoices, VAT number (if applicable).
- Support/communication data: correspondence, feedback, tickets.
- Technical and usage data: device/browser info, IP (shortened/anonymized where possible), events/logs, session IDs, performance data, timestamps, error codes.
- Student/class data: no direct identifiers; possible data: first names, quiz interaction, session codes, scores, timestamps, aggregated statistics.
- Special categories: we do not ask for these and do not wish to receive them.
4. Purposes and legal basis
- Performance of contract: provision of the service, authentication, management of subscriptions, customer service.
- Legitimate interest: security, fraud prevention, product improvement, internal reporting; proportionality and balancing of interests are safeguarded.
- Legal obligation: fiscal retention duties.
- Consent: where legally required, e.g., non-essential cookies or marketing emails. You can withdraw consent via the settings provided.
5. Children and COPPA (US)
- Accounts are only for ≥16 years.
- Students use the service under the responsibility of School/Teacher; for the US we rely, where permitted, on school consent (solely for educational purposes) under COPPA.
- We do not use children’s data for marketing or advertising profiling; we do not share these with third parties other than necessary service providers.
- Parents/guardians can, via the School or directly by email or post, request access/deletion of directly identifiable child data obtained by mistake; we handle requests without unreasonable delay.
6. Retention periods
- Account/billing data: during the contract + 24 months thereafter (or longer if legally required).
- Log/security data: 12–24 months.
- Support tickets: 24 months.
- Aggregated/anonymous statistics: unlimited (not traceable to a person).
7. Sharing with third parties
- Service providers (sub-processors): including hosting, email, customer support, monitoring, payment processing. We conclude appropriate data processing agreements with them.
- Business transfer: in the event of a merger/acquisition, transfer may occur subject to safeguards and with prior notice where legally required.
- Authorities: only upon a lawful request or to comply with legal obligations.
We do not sell personal data and do not share it for cross-context behavioral advertising.
8. International transfers
Transfers outside the EEA/UK are protected with EU SCCs (2021/914) and/or the UK IDTA/UK Addendum plus supplementary measures where needed.
9. Security
Measures: TLS in transit, encryption at rest where available, least privilege and role-based access, MFA for administrators, logging/monitoring, network segmentation, backups and recovery tests, vulnerability scanning/patching.
We respond to incidents according to an internal response plan; in the event of a data breach with risks we report in accordance with legislation.
10. Your rights (EU/UK)
Right of access, rectification, erasure, restriction, portability, objection and the right to withdraw your consent.
You can easily submit a request to have your data deleted by sending a message to info@classigogo.com.
You can file complaints with the Dutch Data Protection Authority (NL) or your local supervisory authority.
11. Cookies and tracking
Non-essential cookies are only placed after consent.
12. Changes
We may update this policy; we will inform you via email or in-product message.