Privacy Policy

Applicable framework: Law No. 29733 — Personal Data Protection Law (Peru) and its Regulation (D.S. 003-2013-JUS).

Version 2.0 · effective from 2026-06-23

Clase Privada ("we") operates the Campus education platform and its mobile app (the "Service"). This policy describes how personal data is processed within the Service in accordance with Law No. 29733.

1. Data Bank Owner and Processor

Law No. 29733 distinguishes two roles. Campus assigns them as follows:

Data bank owner: the school. Each educational institution is the owner of its community's data bank (students, parents, teachers, staff). It decides the purpose and content of processing and is responsible toward its data subjects.

Data processor: Clase Privada / Campus. Clase Privada processes data on behalf of and under the instructions of the school, solely to provide the Service. We do not use the data for our own purposes. The relationship is formalized in a Data Processing Agreement (DPA). Status as of today: no DPA is in force with any school yet; the model agreement is drafted and pending legal review. In the meantime, the processor obligations that agreement sets out —those in this policy and in the Terms— bind us all the same.

2. Data we process

2.1 Provided by the school

2.2 Collected automatically

2.3 Sensitive data (special categories, art. 2.5)

On behalf of the school, the Service processes sensitive data within the meaning of art. 2.5 of Law No. 29733. The categories present in the platform are expressly declared here:

Legal basis. For sensitive data, Law No. 29733 requires the express, written consent of the data subject (art. 13.5). For underage students it is given by the parent or legal guardian and collected by the school, as owner of the data bank. Two categories also rest on their own basis: school violence (SíseVe) cases are processed to comply with the school's legal duty to record and report incidents to MINEDU, and credentials, tokens and session secrets respond to the technical need to grant secure access and to evidence who accessed. Clase Privada, as processor, does not collect this data on its own account nor use it for any purpose other than providing the Service.

Express consent. Consent is given in writing to the school — normally in the enrolment contract or the admission form — and it is the school that keeps and evidences it. Campus also ships a consent registry inside the platform, versioned against this policy, which each school may enable; until the school enables it, the platform neither captures nor stores consents and the record exists only in the school's own documents. Campus does not request consent on the school's behalf, nor assume it.

Restricted access: who sees them. Sensitive data is consulted one person at a time, in that person's record, by those with a direct relationship to them. The health, special educational needs, psychology and wellbeing, and school violence categories do not leave in bulk: they are excluded from bulk imports, list views, Excel/CSV exports, the list API and data embedded in the HTML. Two exceptions, stated here because they are real: (a) student credentials and QR codes are generated and printed per classroom — that is their purpose, to issue the card — and remain under the access control of whoever issues them; (b) the database backup is a full dump and therefore contains all of the above: it is not downloadable from the product, it is stored outside the public directory and, when the school configures an encryption key, the artifact is additionally stored encrypted with AES-256. The clinical detail of a support plan is visible only to staff holding the psychology role; the rest of the teaching team sees only the arrangement to apply in class, never the diagnosis. At rest, medical notes and special educational needs — of the student and of the applicant — are stored encrypted (AES-256) in the database; the remaining categories are protected by this access control and the measures described in §6. The school's audit log records the creation and modification of this data, and also access attempts rejected at the central gate: when permission, the contracted plan or platform authority denies a page, an entry records who attempted it, when, from which IP address and what was denied. What is logged is the attempt to enter, and not every internal permission check: the menu performs dozens per page to decide what to show, and logging those would bury what matters. This logging ships enabled and the school can turn it off in its settings; while it is off, those denials are not recorded. Rejections that happen inside a module, past the gate, are logged by that module once it implements them. Merely viewing a record by someone who does hold permission is not logged.

How long they are kept and how they are deleted. For as long as the student's relationship with the school lasts, this data lives in their record. Two automatic windows are enforced by the system today:

Each school may shorten or extend those windows for its own institution. That automatic step does not reach blood type, the tutoring file — including its health notes — or wellbeing support plans: their content stays with the student record, and their deletion is decided by the school — the data bank owner — when handling a cancellation request (§4). The audit log is not automatically purged: it is the evidence of processing that Law No. 29733 requires to be demonstrable. Retention of the record after the student leaves the school is set by each school in its own records policy; Campus neither imposes nor enforces a window of its own for that.

3. Purpose and legal basis

Data is processed exclusively to:

Legal basis: processing is grounded in the contractual relationship between the school (owner) and the family/educational community, and in the consent of the parent/guardian for minors' data (see §7). We do not sell, rent, or share personal data with third parties for advertising purposes.

4. Data subject ARCO rights

Anyone whose data is processed in Campus has the rights of Access, Rectification, Cancellation, and Opposition (ARCO), plus information and portability, under Law No. 29733:

Formal channel and deadlines: requests are addressed to the school (owner) or to our privacy channel privacidad@claseprivada.com. We handle access within 20 business days and rectification, cancellation, and opposition within 10 business days of receipt, per the Regulation of Law No. 29733. If our response is unsatisfactory, you may turn to the National Authority for the Protection of Personal Data (ANPD).

5. National Registry of Personal Data Protection (RNPDP)

Law No. 29733 requires personal data banks to be registered with the National Registry of Personal Data Protection (RNPDP) of the ANPD. That registration is the school's duty, as owner of the data bank; Campus, as processor, generates the platform's personal-data inventory and provides technical assistance for the procedure. Campus does not file on the school's behalf, does not verify it and holds no evidence that it was done: if you need to confirm your school's registration, ask your school.

6. Storage and security

More detail in our Trust Center — Security & Compliance.

7. Minors' data

Campus processes data of underage students. Protecting minors is the highest bar of the Peruvian framework (Law No. 29733 and the Children and Adolescents Code). Therefore:

8. Sub-processors

To provide the Service we rely on the following providers who process data on our behalf. Each is bound by the processing and security terms of its own service agreement, which we accept when contracting it and whose policy we link in the last column. Beyond that, there is no separately negotiated processing agreement with each provider.

Provider Purpose Country Policy
Hostinger International Ltd. Server hosting (shared hosting plan) and database storage. Brazil (São Paulo datacenter), since 2026-07-04; previously USA view
Google Firebase Cloud Messaging (FCM) Delivery of push notifications to the mobile app. USA view
MercadoPago (Mercado Libre) Tuition and subscription payment processing (Checkout Pro). Only when the school enables the gateway. Argentina / Brazil view
SMTP email provider (Google Workspace by default) Sending transactional email (credentials, report cards, notices). Each school may configure its own SMTP server. USA (or as configured by the school) view
Groq, Inc. · AI AI-assisted generation of comments and reports (pseudonymized data). USA view
Cerebras Systems, Inc. · AI AI-assisted generation of comments and reports (pseudonymized data). USA view
Mistral AI · AI AI-assisted generation of comments and reports (pseudonymized data). France (EU) view
OpenAI, L.L.C. · AI AI-assisted generation of comments and reports (pseudonymized data). USA view
OpenRouter, Inc. · AI Routing to AI models (pseudonymized data). USA view
Cohere Inc. · AI AI-assisted generation of comments and reports (pseudonymized data). Canada view
Z.ai (Zhipu AI) · AI AI-assisted generation of comments and reports (pseudonymized data). China view

9. AI-assisted processing

Some features (report comments, conclusions) use AI models from the providers marked AI in the table above, located outside Peru. Therefore:

10. International transfers

Some sub-processors (AI providers, Firebase, email and hosting, whose datacenter is in São Paulo, Brazil) process data outside Peru. These transfers are carried out under each provider's contractual safeguards and with prior pseudonymization when the destination is an AI model. Their declaration as a cross-border flow before the ANPD is prepared and has not been filed yet; we will publish the filing date here.

11. Data retention

Academic data is kept for the duration of the contract with the school. Upon termination the account becomes read-only and the school has its grace period to export its information. Deletion afterwards is not a calendar automatism: the system flags the school for deletion when the grace period expires, but the final erasure additionally requires an explicit operator approval recorded outside the platform. Backups already taken disappear through their own 14-day rotation.

12. Data Protection Officer (DPO) and contact

The written appointment of a Data Protection Officer (DPO) is pending and will be published here with name and role. In the meantime, the formal privacy channel —the same one used to exercise the ARCO rights of §4— is attended by Clase Privada's privacy team:

13. Changes to this policy

We may update this policy. Each version is identified by a number (Version 2.0) and an effective date. Substantial changes are communicated to schools and, where applicable, a new consent is requested.

← Back to Campus