← Back to home Español

🛡️ Security & Compliance

What a school (and its legal advisor) needs to know before entrusting us with their community's data. Campus is built to comply with Peru's Law No. 29733 on Personal Data Protection, with the reinforced protection that minors' data requires.

Framework: Law 29733 ✓ TLS / HTTPS ✓ Isolated per school ✓ Daily backups ✓ ARCO
🔒

Encryption in transit

All traffic runs over TLS/HTTPS with HSTS. Passwords are stored as bcrypt hashes; no one —not even us— can read them.

🏛️

Multi-tenant isolation

Each school runs on its own separate database. No school can see another's data: there is no cross-contamination.

💾

Daily backups

Automatic backup of every database each night, with 14-day retention. From the panel, the school can download a CSV export of its data at any time: it is a selection of tables, not the full database dump.

🧾

Access auditing

We log creation and modification of data; viewing a record while holding permission is not logged. <strong>Rejected access attempts are logged at the central gate</strong>: when someone requests a page and permission, plan or platform authority denies it, an entry records who, when, from which IP and what was denied. Not every internal permission check is logged —the menu performs dozens per page— only the attempt to enter. It ships enabled and <strong>the school can turn it off</strong> in its settings. Role-based access control with the least-privilege principle.

♻️

Reversible deletion (soft-delete)

In the modules covered —grades, mocks, tutoring, incidents, lab— data is not hard-deleted: it is marked deleted, can be restored, and is purged after 30 days.

⚖️

ARCO rights

Access, Rectification, Cancellation, and Opposition are exercised from the student's or guardian's own account: the request register is live at every school —it does not depend on the plan or on any switch— and sets the legal deadline in business days under Law 29733. Anyone without an account exercises the same rights through the formal privacy channel.

🗓️

Data retention

Data is kept for the duration of the contract. Upon termination, the school exports it and it is then deleted per a written retention policy.

🌎

Sub-processors and transfers

We publish the full list of providers that process data on our behalf. International transfers are identified and documented; their declaration before the ANPD has not been filed yet.

Who is responsible for what

Under Law No. 29733, the school is the data bank owner and Clase Privada (Campus) is the data processor: we process data only on the school's behalf and per its instructions, to provide the Service. This relationship is formalized in a Data Processing Agreement (DPA) whose security annex summarizes the measures on this page. Status as of today: no DPA is in force with any school yet. The model agreement is drafted and pending legal review; we will put it to each school for signature and update this page once it is available. In the meantime, the processor obligations that agreement sets out —those on this page and in the Terms— bind us all the same.

Artificial intelligence, with safeguards

Some features use external AI models to assist teachers. Before leaving, all text is pseudonymized (names replaced with pseudonyms and DNI/phone-like numbers removed). AI suggestions always go through the teacher's human review, and each school can fully disable AI use while keeping the rest of the Service.

Sub-processors

These are all the providers that process data on our behalf to deliver the Service. Those marked AI process pseudonymized data outside Peru.

Provider Purpose Country Policy
Hostinger International Ltd. Server hosting (shared hosting plan) and database storage. Brazil (São Paulo datacenter), since 2026-07-04; previously USA view
Google Firebase Cloud Messaging (FCM) Delivery of push notifications to the mobile app. USA view
MercadoPago (Mercado Libre) Tuition and subscription payment processing (Checkout Pro). Only when the school enables the gateway. Argentina / Brazil view
SMTP email provider (Google Workspace by default) Sending transactional email (credentials, report cards, notices). Each school may configure its own SMTP server. USA (or as configured by the school) view
Groq, Inc. · AI AI-assisted generation of comments and reports (pseudonymized data). USA view
Cerebras Systems, Inc. · AI AI-assisted generation of comments and reports (pseudonymized data). USA view
Mistral AI · AI AI-assisted generation of comments and reports (pseudonymized data). France (EU) view
OpenAI, L.L.C. · AI AI-assisted generation of comments and reports (pseudonymized data). USA view
OpenRouter, Inc. · AI Routing to AI models (pseudonymized data). USA view
Cohere Inc. · AI AI-assisted generation of comments and reports (pseudonymized data). Canada view
Z.ai (Zhipu AI) · AI AI-assisted generation of comments and reports (pseudonymized data). China view

International transfers are carried out under each provider's contractual safeguards and with prior pseudonymization when the destination is an AI model. Their declaration as a cross-border flow before the National Authority for the Protection of Personal Data (ANPD) is prepared and has not been filed yet; we will publish the filing date here.

Documents and privacy channel

Formal channel for ARCO rights and any data-protection inquiry, attended by Clase Privada's privacy team. The written appointment of a Data Protection Officer (DPO) is pending and will be published here with name and role.