Schoolyear (“we”, “us”, or “our”) is committed to protecting the privacy and security ofyour personal information. This Privacy Policy describes how we collect, use, disclose,and safeguard your personal information.
This Privacy Policy describes the processing of information provided or collected on the site(s) and/or application(s) where this Privacy Policy is posted. This Privacy Policy applies to all users of our service. We follow this Privacy Policy in accordance with applicable law in the places where we operate and process personal information.
The personal information we collect is covered by this Privacy Policy. Please note that our site(s) and/or application(s) may contain links to other sites not owned or controlled by us, and therefore we are not responsible for the privacy practices of those sites. We encourage you to be aware when you leave our sites or applications and to read the Privacy Policy of other sites that may collect your personal information.
When schools, universities, or other organizations (collectively, our “Customers”) use our SaaS services, they typically determine what data to collect and how it is used. In these circumstances, we process personal information on behalf of and under the instructions of our Customers. We do not decide how such information will be used or otherwise processed. Therefore, with respect to personal information our Customers enter into or manage through our application, we act as a data processor, and the Customer is the data controller (or acts in a similar role under applicable privacy laws).
For the personal information we collect directly from individuals—such as information from visitors to our websites, users who sign up for newsletters or other marketing materials, or individuals we may reach out to for sales and marketing—we determine the purposes and means of processing that information. Accordingly, we act as a data controller for this type of personal information.
Customers can assume that all personal data we collect and process in context of our to our SaaS services is guarded by the Data Processing Agreement we have have with them.
This document makes a clear distinction between the two cases by marking some sections as “SaaS Related” or “Schoolyear-Controlled Processing”.
Most of this document is related to the later, since SaaS Related processing is governed by the Data Processing Agreement which we have with our customers. In that case we act as the processor, not the controller and we process data on behalf of that customer. As these agreements may differ between customers, users with specific questions or requests, should direct them at the organisation acting as the controller.
This section describes the personal information we collect with regards to Schoolyear-Controlled Processing. Personal information we process for our SaaS Related activities is not controlled by us but by our customers and is not covered by this section but by the Data Processing Agreement we have with them. As SaaS Related data processing activities may differ between customers, it is not described in this section.
We may collect and process personal information about you, such as:
We may also collect certain information automatically when you visit our website other online marketing material, such as your IP address, browser type, and usage data.
We may receive personal data about you from other sources to supplement data already collected. This may include publicly available data or data provided by third parties. We may combine this data with the data we already have. We will handle this data in accordance with this Privacy Policy and the purposes outlined when the data was collected. We will notify you if there are any material changes to the way we intend to use this data. Please note that we are not responsible for the accuracy of the data provided by third parties or any consequences arising from the use of such data.
By using our services, you agree to the terms and conditions outlined in this Privacy Policy. Your continued use of our services constitutes implicit consent to the collection, processing, and sharing of your personal data as described herein.
We make every effort to ensure that our privacy practices are transparent and understandable. By using our services, you acknowledge that you have read and understand this Privacy Policy.
If you do not agree with any terms outlined in this policy, please refrain from using our services.
The exception to this is the SaaS-Related personal data we process when our services are used by our customers. This processing we perform as requested by our customers governed by the Data Processing Agreement we have with them. In such cases, it is the responsibility of that customer to ensure relevant consent has been granted by the data subject before requesting us to process their personal information.
If there are questions surrounding how this consent is obtained and maintained, or any questions surrounding how consent can be withdrawn, please contact the applicable data controller.
We do not process any Special Categories of Personal Data. More directly relevant, we do not process Personal Data about the education performance of any user. Personal Data like grades may be processed by other tools used by educational customers that are used along side our services, but they are not processed by us.
We collect information you provide for the following purposes:
We will not share your personal information with third-parties, unless explicitly authorized to do so. Please note that when your personal information is shared with an authorized third-party, the information received by that third-party is controlled by that company, and therefore becomes subject to that company’s Privacy Policy.
We may share your personal information with the following categories of recipients:
As a global organization, we may transfer your personal data to countries outside the European Union (EU) or the European Economic Area (EEA). Such transfers may be necessary for the purposes outlined in this Privacy Policy, including providing you with requested products or services, communicating with you, and conducting our business operations effectively.
When we transfer your personal data to countries outside the EU/EEA, we will ensure adequate safeguards are in place to protect your personal data as required by applicable data protection laws and regulations. These safeguards may include (but are not limited to)
By using our services or providing your personal data to us, you consent to the transfer of your personal data as described in this Privacy Policy. If you do not agree to such transfers, please refrain from using our services or providing your personal data to us.
If you have any questions or concerns regarding the transfer of your personal data outside of the EU/EEA or the safeguards we have implemented, please contact us using the contact details provided at the end of this Privacy Policy.
As a data subject, we will provide you with the following rights:
You have the right to request access to your personal data that we process. This means you can ask us to provide you with information about what personal data we hold about you and how we use it.
You can request the correction or updating of your personal data if it is inaccurate or incomplete. We will make the necessary changes and inform any third parties to whom we have disclosed the data.
You can request the deletion of your personal data under certain circumstances. This right is not absolute and can be exercised if the data is no longer necessary, you withdraw consent, or the data processing is unlawful.
You have the right to request the restriction of the processing of your personal data under specific circumstances. This means we will limit the way we use your data but not delete it entirely. This right might be exercised when you contest the accuracy of the data, the processing is unlawful, or you need the data for legal claims.
You can request a copy of your personal data in a structured, commonly used, machine-readable format, or you can ask us to transmit it directly to another data controller where technically feasible. This right is applicable when processing is based on consent or the performance of a contract.
You have the right to object to the processing of your personal data, including processing based on legitimate interests or for direct marketing purposes. We will stop processing your data for such purposes unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which has legal or significant effects on you. You may request human intervention in the decision-making process. We will inform you when such decisions are made, provide you with the opportunity to express your point of view, and ensure there are human interventions available.
Please note that within our SaaS application we take a strong stance against automated decision-making or profiling. We believe it should always be the invigilator in charge that makes any decision with regards to the continuation of an exam, as our software does not have all the relevant context. Furthermore, our application does not use personal data between multiple exam sessions of the same student to raise notifications to an invigilator, as we believe each session should be fresh chance.
If we process your personal data based on your consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
Any requests submitted by data subjects will be assessed for validity before being processed, including confirming the identity of the data subject.
With regards to SaaS-Related processing, we rely on the data controller to action any requests related to the access rights noted above, and as such, will forward all such requests to the data controller once received. If there are questions surrounding the status of any access requests, please contact the applicable data controller.
We implement and maintain reasonable and appropriate technical and electronic safeguards to protect the security of your personal information from loss, misuse, unauthorized access, disclosure, alteration, or destruction.
While we implement these security measures to protect your data, it is important to understand that no online platform can guarantee absolute security. Therefore, we encourage you to take necessary, best-practice security precautions such as strong, unique passwords and being cautious with the sharing of login credentials.
In the event of a data breach or security incident, we will take immediate action to isolate and resolve the incident based on our incident response resolution procedures, notify relevant authorities, and inform affected data subjects in compliance with applicable data protection laws.
With regards to SaaS-Related processing, the data security we implement and maintain is described in our Data Progressing Agreement with the data controller.
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal or contractual requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, as well as applicable legal requirements.
Upon expiration of the applicable retention period, we will securely delete or anonymize your personal data in accordance with applicable laws and regulations.
With regards to SaaS-Related processing, the data retention and disposal policies we apply are described in our Data Progressing Agreement with the data controller.
We may use “cookies” (or similar tracking technology) on our website. Cookies are text files that our web server may place on your hard disk to store your preferences. When you visit our website, you will be presented with a cookie banner or pop-up requesting your consent to use non-essential cookies. You have the right to accept or decline the use of such cookies. Your consent can be managed and changed at any time through your device or browser settings.
Cookies, by themselves, do not provide us with any Personal Identifyable Information unless you explicitly choose and consent to provide this information to us. Once you choose and consent to provide PII, however, this information may be linked to the data stored in the cookie. If you choose to turn off collection of cookies through your device or browser, certain features of our service may not function properly without the aid of cookies.
Our website may also incorporate third-party cookies and tracking technologies. These technologies are subject to the privacy policies and practices of the respective third parties. We encourage you to review the privacy policies of these third parties for information on how they collect and use your personal data.
We do not knowingly collect any information from minors. In situations where personal data from anyone under the age of 16 is needed for data processing activities, we will obtain authorization from an appropriate parent or guardian. If such authorization is unable to be obtained, data processing activities for that data subject will be terminated. In the event that we discover that a minor under the age of 16 has provided PII to us, we will make efforts to delete the information ASAP. If you have concerns about our website or service offering, wish to find out if your child has accessed our services, or wish to remove your child’s personal data from our servers, please contact us at support@schoolyear.com
With regards to our SaaS-related processing, we rely on the data controller to obtain authorization from an appropriate parent or guardian prior to requesting us to process the child’s data being processed. If there are questions surrounding how this consent is obtained and maintained, or any questions surrounding how consent can be withdrawn, please contact the applicable data controller.
If the processing of personal data about you is subject to European Union (EU) data protection law, you have certain rights with respect to that data. Please refer to section “Data Subject Rights” above for a listing of these rights.
Additionally, our processing of your personal data is based on specific legal bases as defined in EU data protection law. Please refer to section “Data Sharing” above for a listing of these legal bases.
The SaaS-Related processing we do is performed in the locations specified in the Data Processing Agreement with have with each customer. Note that, unless agreed differently, we host our SaaS service within the EU.
Personal Information we processes for purposes other that delivering our SaaS service to our customers, may be hosted in various locations around the world as they may depend on the location and jurisdiction you are accessing our site and services from. If you are visiting our site or any other online marketing material, please be aware that you personal data may be transferred outside the country you are visiting from. Note that these transfers are compliant with the GDPR when applicable.
For Customers with an out-dated data processing agreement, from before April 2025, the data processing agreement covers the personal data we process in the SaaS-application itself, but not related services such as support and SLA-notifications. For these customers and in these cases, we do act as the Controller and the Schoolyear-Controlled processing sections of this policy do apply. You can reach out to your organisation to understand if this applies to you.
We process the following data as controller if this applies to: Name, role, email address, business phonenumber and conversation history. We do this for the purpose of providing support to you and to improve our support services. We delete our phone records after one year and delete the related email tickets when a Customer closes their account with us.
We periodically review this Privacy Policy and may make updates to reflect changes in our practices, for legal reasons, or to meet new regulatory requirements. Your continued use of our services following any notice of changes to this Privacy Policy means you accept such changes. Please refer to the “Effective Date” above for details on when this Policy was last updated. In case we update our Privacy Policy, we will notify our customers.
If you have any questions, concerns, or requests regarding your personal data or this Privacy Policy, please contact us at support@schoolyear.com. For specific requests relating to your rights as a data subject including the rights noted in section “Data Subject Rights” noted above, please request your inquiry to be forwarded to our Data Protection Officer (DPO).
Schoolyear B.V.
Magistratenlaan 138
5223 MB 's-Hertogenbosch, The Netherlands
Last changed: April 14th, 2025