PRIVACY POLICY
This Privacy Policy explains how Classify Incorporated ("Classify", the "Company", "we", "us", or "our"), the developer and operator of the Classedge LMS learning management system (the "Platform"), collects, uses, stores, shares, and protects your personal data when you use the Platform, including its web and mobile applications.
We process personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission ("NPC"). By using the Platform, you acknowledge that you have read and understood this Policy.
1. WHO WE ARE AND OUR ROLE
Classify Incorporated develops and operates the Platform and provides it to educational institutions, organizations, and their users (each, a "Partner Institution").
- For account, profile, technical, usage, and AI-interaction data that we collect to operate, secure, and improve the Platform, Classify acts as the Personal Information Controller (PIC).
- For academic and institutional data that a Partner Institution uploads to, generates in, or directs us to process through the Platform (for example, enrollment, grades, and attendance), the Partner Institution is the Personal Information Controller and Classify acts as its Personal Information Processor (PIP) under a data processing agreement. For questions about that data, please also contact your institution.
Privacy questions, requests, or concerns may be directed to our Data Protection Officer ("DPO") using the contact details in Section 15.
2. SCOPE
This Policy applies to all users of the Platform, including students, faculty, staff, administrators, and authorized guests. It covers personal data collected through the Platform and through systems integrated with it, such as a Partner Institution's Registrar/Records Management System ("RMS").
3. PERSONAL DATA WE COLLECT
We may collect and process the following categories of personal data:
- Account and identity data: name, email address, username, encrypted (hashed) password, and one-time passwords (OTP) used for verification and account security.
- Profile data: date of birth, gender, home address, contact/phone number, profile photo, program or course, year level, section, and role (e.g., student, faculty, administrator).
- Academic and learning data: class schedules, subject enrollments, learning materials accessed, activities and assessment submissions, grades and grade records, attendance records (including self-marked attendance during scheduled class time), and gamification data such as quests, points, and ratings.
- Communications data: notifications, in-app messages (including direct messages and group messages on the web Platform), message attachments, reactions, read/unread state, and feedback or support requests you send or receive.
- Technical and usage data: IP address, browser and device information (user agent), login history and timestamps, and security-related events such as failed login or OTP attempts.
- AI interaction data: the content you submit to AI-assisted features and the outputs generated for you.
We do not intentionally collect sensitive personal information beyond what is necessary for legitimate educational and administrative purposes. Please do not submit sensitive personal information (such as health, religious, or political data) unless specifically requested and lawfully required.
4. HOW WE COLLECT PERSONAL DATA
- Directly from you when you create or update your account, complete your profile, or use Platform features.
- From your Partner Institution's records, including its Registrar/Records Management System (RMS), which provides enrollment, subject, schedule, and faculty assignment data.
- Automatically, through your use of the Platform (for example, technical and usage data and security logs).
- From third-party sign-in providers (such as Microsoft or Google) when you choose to log in using an institutional or linked account.
5. PURPOSES AND LAWFUL BASIS FOR PROCESSING
We process your personal data for the following purposes, relying on one or more lawful criteria under RA 10173 — namely your consent, the performance of our contractual obligations, compliance with legal obligations, the instructions of a Partner Institution, and our legitimate interests as the Platform operator:
- To create and administer your account and authenticate your identity (account security, OTP, login monitoring).
- To deliver the Platform's educational features: enrollment, class schedules, learning materials, activities, assessments, grading, and attendance.
- To send notifications, reminders, and important announcements relevant to your use of the Platform.
- To operate messaging and community features (direct messages, group chat, posts) made available through the Platform.
- To provide AI-assisted learning and productivity features.
- To maintain records and generate reports for Partner Institutions as required.
- To secure the Platform, prevent fraud and abuse, and investigate security incidents.
- To operate, maintain, and improve the Platform's functionality, reliability, and user experience.
6. COOKIES AND SIMILAR TECHNOLOGIES
The Platform uses strictly necessary cookies and similar technologies to keep you signed in, maintain your session, protect against cross-site request forgery (CSRF), and remember your preferences. These are essential to the operation of the Platform. Disabling them may prevent you from using certain features.
7. SHARING AND DISCLOSURE OF PERSONAL DATA
We do not sell your personal data. We may share it only as follows:
- With your Partner Institution, and its authorized faculty, staff, and administrators who need it to perform their educational and administrative functions.
- With service providers (sub-processors) who process data on our behalf under appropriate agreements and confidentiality obligations (see Section 8).
- When required by law, or in response to a lawful order or request by a competent authority.
- To protect rights and safety, where reasonably necessary to prevent harm, fraud, or abuse, or to enforce our terms.
- In a business transfer, such as a merger, acquisition, or reorganization, subject to appropriate safeguards and applicable law.
8. THIRD-PARTY SERVICES
The Platform relies on the following third-party services, which may process limited personal data strictly for the purposes described:
- Microsoft 365 / Outlook (email and sign-in): delivery of transactional emails and optional institutional sign-in.
- Google (sign-in and reCAPTCHA): optional sign-in and protection against automated abuse.
- Anthropic (Claude AI): processing of inputs and outputs for AI-assisted features.
- OneSignal (push notifications): delivery of push notifications to your devices.
- Microsoft OneDrive (Office-format file storage): Office documents (.pptx, .docx, .xlsx) uploaded by faculty are mirrored to a Classify-controlled OneDrive folder operating under a Microsoft 365 service account, solely to enable in-app previews of those files.
- Sentry (mobile application error and crash reporting): collection of crash stack traces, application version, device model, and operating-system information when the mobile app encounters an error. Sentry is configured to exclude personally identifying information by default; trace data may incidentally include device, OS, and app-version information.
These providers operate under their own privacy policies. We encourage you to review them. We share only the data necessary for each service to function.
9. STORAGE, LOCATION, AND SECURITY
We implement reasonable and appropriate organizational, physical, and technical security measures to protect your personal data against accidental or unlawful destruction, alteration, unauthorized disclosure, or access. These measures include encrypted password storage, access controls based on user roles, account lockout and OTP protections, and security logging. Some of our service providers may store or process data on servers located outside the Philippines. Where this occurs, we take steps to ensure your data continues to receive a comparable level of protection consistent with RA 10173.
On mobile devices, the Platform stores a local copy of academic data, profile information, notifications, and messages on your device in a local database so that you can continue to use the Platform offline. This local copy is protected by your device's operating-system encryption. When you sign out of the mobile app, this local copy is cleared from the device.
10. DATA RETENTION
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, to provide the Platform to Partner Institutions, to comply with our agreements with them, and to meet legal, regulatory, and accreditation obligations. Where Classify acts as a Processor, we retain and dispose of data in accordance with the relevant Partner Institution's instructions. When personal data is no longer required, we will securely dispose of, delete, or anonymize it. When you delete your account through the methods described in Section 11 and Appendix C, we delete or anonymize personal data we control within 30 days, except for records required to be retained by law, by an agreement with your Partner Institution (such as academic records and grade history), or as needed for ongoing legal proceedings.
11. YOUR RIGHTS AS A DATA SUBJECT
Under the Data Privacy Act of 2012, you have the right to:
- Be informed about how your personal data is collected and processed.
- Access the personal data we hold about you.
- Object to or withdraw consent for certain processing.
- Rectify (correct) inaccurate or outdated personal data.
- Erasure or blocking of your personal data under the conditions allowed by law.
- Data portability, to obtain a copy of your data in a commonly used electronic format.
- Damages, for violations of your rights under the law.
- File a complaint with the National Privacy Commission.
To exercise any of these rights, contact our DPO using the details in Section 15. Where the data is controlled by your Partner Institution, we may direct your request to it or act on its instructions. Certain records may be retained where required by law or a Partner Institution's legitimate functions, even after a request.
To exercise the right to erasure, you may (a) use the in-app option under Settings → Profile → Delete Account in the Classedge mobile application, (b) submit a request at https://classedge.hccci.edu.ph/account-deletion/, or (c) email our Data Protection Officer at inquiries@classify.com.ph. We acknowledge requests within 5 business days and aim to complete them within 30 days, except where an extension is permitted under RA 10173. See Appendix C for full details, including which records are deleted and which are retained.
12. CHILDREN AND MINORS
The Platform is intended for users aged 18 or older. A limited number of users may be 16 to 17 years of age (for example, senior high school or dual-enrollment students), and for those users processing is carried out on the lawful basis of the Partner Institution's educational function and, where required, with the consent of a parent or legal guardian arranged through the Partner Institution.
The Platform is not directed at children under 13, and we do not knowingly process the personal data of children under 13. If you believe a child under 13 has provided personal data to the Platform, please contact our Data Protection Officer using the details in Section 15, and we will take prompt steps to delete the data.
13. INTERNATIONAL USERS
The Platform is operated from the Philippines, and your personal data is processed in the Philippines in accordance with the Data Privacy Act of 2012 (RA 10173). If you access the Platform from outside the Philippines, you acknowledge that your data is transferred to and processed in the Philippines.
We extend the data-subject rights described in Section 11 substantively to all users regardless of location. Users in the European Union or European Economic Area, the United Kingdom, or California may exercise rights available to them under the General Data Protection Regulation (GDPR), UK GDPR, or California Consumer Privacy Act (CCPA) respectively by contacting our Data Protection Officer using the details in Section 15. We have not appointed an EU or UK representative at this time; please direct requests to the Data Protection Officer.
14. CHANGES TO THIS POLICY
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will publish the updated version on the Platform and, where appropriate, ask you to review and accept it before continuing to use the Platform. The "Effective date" and "Version" above indicate the current version.
15. HOW TO CONTACT US
For privacy questions or to exercise your rights, contact our Data Protection Officer:
Data Protection Officer — Classify Incorporated Address: Allah Valley Drive, Surallah, South Cotabato Email: inquiries@classify.com.ph
APPENDIX A — APP STORE AND GOOGLE PLAY PERMISSIONS AND PURPOSES
This appendix summarizes the device permissions the mobile application requests, why each is requested, and how the Platform's data collection maps onto Google Play's Data Safety categories. It is provided as a transparency aid and as the source of truth for the corresponding app store submission forms.
A.1 iOS — Permission usage strings
| Permission | Required or optional | Purpose | Usage string shown to the user |
|---|---|---|---|
| Camera | Optional (per-feature) | Take a new profile photo. | Allow HCCCI to access your camera / Allow HCCCI to use your camera so you can take a new profile photo. |
| Microphone | Optional (per-feature) | Capture audio in the camera pipeline (required by the camera framework even when audio is not recorded). | Allow HCCCI to access your microphone |
| Photo Library | Optional (per-feature) | Choose an existing photo as a profile photo. | Allow HCCCI to access your photos so you can change your profile photo. |
| Background notifications (remote-notification) | Required for push delivery | Process push notifications delivered while the app is in the background. | (No user-facing string; declared in UIBackgroundModes.) |
A.2 Android — Declared permissions
| Permission | Required or optional | Purpose |
|---|---|---|
| android.permission.CAMERA | Optional (per-feature) | Take a new profile photo. |
| android.permission.RECORD_AUDIO | Optional (per-feature) | Required by the camera pipeline when capturing media. |
| Push notification permission (POST_NOTIFICATIONS, Android 13+) | Optional | Receive in-app notifications from your Partner Institution. |
A.3 Google Play — Data Safety mapping
| Data type | Collected | Shared with third parties | Purpose | User can request deletion |
|---|---|---|---|---|
| Personal info — Name, email, user ID | Yes | No (processed by named sub-processors only) | App functionality; Account management | Yes — see Appendix C |
| Personal info — Address, phone, date of birth | Yes | No | App functionality; Account management | Yes — see Appendix C |
| Photos and videos — Profile photo | Yes | No | App functionality; Account management | Yes — see Appendix C |
| Files and docs — Faculty Office files | Yes (faculty) | Yes (Microsoft OneDrive, named in §8 and Appendix B) | App functionality | Yes — see Appendix C |
| Messages — Direct and group messages, attachments, reactions | Yes (web) | No | App functionality; Communications | Yes — see Appendix C |
| App activity — In-app actions, page views, gamification | Yes | No | App functionality; Analytics (internal) | Yes — see Appendix C |
| App info and performance — Crash logs, diagnostics | Yes | Yes (Sentry, named in §8 and Appendix B) | App functionality; Diagnostics | Yes — see Appendix C |
| Device or other IDs — Push device token | Yes | Yes (OneSignal, named in §8 and Appendix B) | App functionality; Communications | Yes — see Appendix C |
All collected data is encrypted in transit (HTTPS/TLS). The Platform does not collect data for advertising or third-party analytics, and does not share data with advertising networks.
APPENDIX B — SUB-PROCESSOR LIST
We engage the sub-processors listed below to deliver the Platform. Each operates under contractual confidentiality and security obligations and processes personal data only on Classify's documented instructions or as required by applicable law. We update this list when sub-processors are added or replaced.
| Sub-processor | Role | Personal data processed | Region | Transfer safeguard |
|---|---|---|---|---|
| Microsoft 365 (Outlook SMTP, Microsoft Entra SSO, OneDrive) | Email delivery, institutional single sign-on, Office-file storage for in-app previews | Email addresses, OAuth tokens, faculty-uploaded Office files | United States and global Microsoft data centers | DPA §21 Processor-Subcontractor obligations; Standard Contractual Clauses where applicable |
| Anthropic (Claude AI) | AI-assisted learning and productivity features | User prompts and AI outputs from AI-assisted features (web only at this time) | United States | DPA §21 Processor-Subcontractor obligations; Standard Contractual Clauses where applicable |
| OneSignal | Push notification delivery | User external ID, device push token, notification payload | United States | DPA §21 Processor-Subcontractor obligations; Standard Contractual Clauses where applicable |
| Google reCAPTCHA | Bot and abuse protection on login and OTP flows | Anonymized client-side risk signals | United States and global Google data centers | DPA §21 Processor-Subcontractor obligations; Standard Contractual Clauses where applicable |
| Sentry | Mobile crash and error reporting | Stack traces, application version, device model, operating-system information; personally identifying information excluded by default | United States or European Union depending on deployment | DPA §21 Processor-Subcontractor obligations; Standard Contractual Clauses where applicable |
| PowerSync | Offline-first mobile sync infrastructure | Encrypted bi-directional replication of records the user is authorized to access | United States | DPA §21 Processor-Subcontractor obligations; Standard Contractual Clauses where applicable |
Note on Partner Institution data. Your Partner Institution's Registrar/Records Management System (RMS) is a source of registrar data (enrollment, schedule, student identity) that is imported into the Platform. The RMS is operated by your Partner Institution and is included here for transparency as a data source, not as a Classify sub-processor.
APPENDIX C — DATA SUBJECT REQUEST AND ACCOUNT DELETION PROCESS
This appendix sets out the practical process for exercising your rights under the Data Privacy Act of 2012, including the right to access, correct, port, or delete your personal data. It applies to all users of the Platform.
C.1 How to submit a request
You may submit a Data Subject Request, including a request to delete your account and personal data, through any of the following channels:
- In-app (mobile only): Open the Classedge mobile application, go to Settings → Profile → Delete Account, and confirm. The app will ask you to re-authenticate before submitting the request.
- Web form: Submit a request at
https://classedge.hccci.edu.ph/account-deletion/. You will be asked for your account email and the type of request. - Email: Contact our Data Protection Officer at
inquiries@classify.com.ph. We may ask you for information sufficient to verify your identity (for example, matching against the email on file) before acting on the request.
We acknowledge receipt of requests within 5 business days. We aim to complete account deletion and other Data Subject Requests within 30 days of acknowledgment, except where applicable law permits an extension.
C.2 What we delete on account deletion
Upon completing an account-deletion request, we delete or anonymize the following personal data we control:
- Account credentials and authentication records (email, hashed password, one-time passwords).
- Profile data (date of birth, gender, nationality, home address, phone number, profile photo, identification numbers, year level, program, section).
- Gamification records (quests, points, streaks, badges, ratings).
- Direct messages, group messages, and attachments authored by you, subject to the retention rules in Section C.3 for course-channel messages where retention is required by the Partner Institution.
- Notification preferences and in-app notification records.
- Login history older than the 90-day forensic-retention window described in Section C.3.
- Mobile application error and crash records (Sentry breadcrumbs) older than the standard provider retention period.
- AI interaction data (prompts and outputs) from AI-assisted features, except where retention is required by law or by an active legal hold.
C.3 What we retain after account deletion, and why
The following records are retained where required by law, by an agreement with your Partner Institution, or by an overriding legitimate interest:
- Academic records. Grades, attempt records, attendance, and related academic evidence are retained per the Partner Institution's policies, accreditation requirements, and applicable law. These records are processed under the Partner Institution's authority (we act as Personal Information Processor for them).
- Legal-consent records. Your acceptances of the EULA, this Privacy Policy, and other legal documents (with the version, timestamp, IP address, and user agent at the time of acceptance) are retained as an immutable compliance record. We may anonymize the user reference where the rest of the account is deleted.
- Operational audit logs. Application audit logs generated by our internal logging system are retained for the operational retention window required to investigate security incidents.
- Records subject to ongoing legal proceedings. Where a legal hold or active investigation requires preservation of records, we will retain them until the matter is resolved.
C.4 Appeal and complaint path
If you disagree with the scope of a Data Subject Request response, including a decision to retain certain records under Section C.3, you may escalate to our Data Protection Officer at the address in Section 15. If your concern is not resolved to your satisfaction, you may file a complaint with the National Privacy Commission of the Philippines at https://privacy.gov.ph or, where applicable, with the supervisory authority in your jurisdiction.
If you believe your data privacy rights have been violated, you may also file a complaint with the National Privacy Commission (NPC) through its official channels at privacy.gov.ph.