GDPR • FERPA • COPPA COMPLIANT

Enterprise Privacy Policy

Effective Date: August 21, 2026 • Version 2.5.0 • Applicability: Zoom Cloud Recording Ingestion & Processing

1. Core Architectural Privacy Guarantees

ClassMind AI is architected from the ground up with Privacy-by-Design and Data Minimization principles for international educational institutions, academies, and private tutors:

2. Data Controller vs. Data Processor Roles

Under the EU General Data Protection Regulation (GDPR), UK-GDPR, and the US Family Educational Rights and Privacy Act (FERPA):

3. Categories of Data Processed

We process only the minimum metadata necessary to generate pedagogical reports:

4. Student Privacy: COPPA & FERPA Compliance (School Consent Model)

Protecting student and child privacy is foundational to our mission. ClassMind AI complies with both the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. 6501–6506) and the Family Educational Rights and Privacy Act (FERPA, 34 CFR Part 99):

5. Data Retention & Right to be Forgotten Protocol

ClassMind AI enforces strict data lifecycle boundaries and an automated 2-stage Right to be Forgotten protocol in accordance with GDPR Article 17, FERPA, and Zoom Data Compliance Standards:

6. Zoom App Marketplace Deauthorization & Data Cleanup

When an institutional administrator uninstalls or deauthorizes ClassMind AI from the Zoom App Marketplace, Zoom issues an automated app_deauthorized webhook event. ClassMind AI automatically revokes all OAuth tokens and de-identifies or permanently erases all associated account records within 24 hours in compliance with Zoom Data Compliance Standards.

7. Third-Party Sub-Processors & Infrastructure Security

ClassMind AI engages carefully vetted third-party sub-processors that maintain enterprise-grade security standards (SOC 2 Type II, ISO/IEC 27001, HIPAA/GDPR compliance) and signed Data Processing Addendums (DPAs):

Sub-Processor Purpose & Role Data Center Location Data Retention Guarantee
Oracle Cloud Infrastructure (OCI) Cloud hosting, secure encrypted database (AES-256), and container execution Frankfurt / Amsterdam (EU) Encrypted at rest; tenant-isolated
Groq Cloud Inc. Ultra-fast Whisper large-v3 speech-to-text inference United States / EU Zero retention; ephemeral in-memory processing
Deepgram Inc. High-fidelity diarized audio transcription (nova-2 model) United States Zero retention; no model training
Google Cloud / Vertex AI Pedagogical analysis, CEFR rubrics, and feedback via Gemini 2.5 Flash United States / EU Enterprise zero-data-retention; no foundation model training
ElevenLabs Inc. Multi-lingual speech transcription (Scribe STT engine) United States / EU Zero retention policy on API inputs
Telegram Messenger Inc. Encrypted delivery of generated report cards and alerts to authorized teachers Distributed Global Infrastructure Controlled via Telegram Bot API
Resend / Brevo Transactional email delivery for system notices, compliance confirmations, and digests United States / EU Transient delivery logs purged within 30 days

8. Data Subject Rights & Contact Information

Students, parents, teachers, and school administrators hold full statutory rights under GDPR, CCPA, and FERPA to inspect, export, rectify, and permanently purge personal records. For data requests or privacy inquiries, contact our Data Protection Officer: