1. Who we are
Clases (“we,” “us”) operates clases.community, a community learning platform. Community owners decide what they teach, whom they invite, and which optional messaging channels they connect. Questions about this policy or personal information may be sent to privacy@clases.community; product support is available at support@clases.community.
2. Scope and roles
This policy applies to visitors, account holders, community members, community owners, and people who communicate with a Clases-powered community through a connected channel. Depending on the activity, Clases may decide how platform data is used, or process data for a community owner acting as the organization responsible for its members and communications. A community must give its members its own notices where its purposes differ from those described here.
3. Information we process
We process account and profile details; authentication and security signals; community membership, roles, course activity, submissions, certificates and preferences; purchases and transaction references; support requests; device, cookie and analytics events; and content a person creates or sends. Connected channels may provide a phone number or provider user ID, display name, workspace/tenant/bot identity, message and attachment content, consent state, delivery status, timestamps, and provider account metadata. We do not need a provider access token in public content: connection credentials are encrypted and separated from ordinary product data.
4. Why we process information
We use information to provide accounts and learning communities; authenticate and secure the service; connect identities and deliver requested messages; remember consent and opt-out choices; process payments; personalize learning; prevent abuse, spam and fraud; diagnose reliability; meet legal obligations; and improve the product with aggregated or appropriately controlled analytics. Where consent is required, it is requested separately and may be withdrawn. Accepting Terms is not, by itself, consent to promotional SMS or WhatsApp.
5. Community owners and authored communications
Community owners choose members, content, schedules, and connected-channel messages. They must have authority to upload member data and must obtain any required messaging consent. Clases processes those instructions subject to safety, law, provider rules, and member choices. A member should contact the community first about community-authored content and may also contact Clases.
6. Cookies and analytics
We use necessary cookies for sign-in, security, language, consent, and service operation. With the choice required in the visitor’s region, we may use analytics to understand performance and adoption. Browser or account controls can change optional choices; disabling necessary storage may prevent sign-in.
7. Connected messaging channels
Channel features apply only when a community enables them. Providers transport messages under their own terms and privacy notices. Clases does not sell message content or SMS/phone opt-in data, and does not share such consent with unrelated parties for their own marketing.
A community owner connects its own WhatsApp Business Account (WABA) and phone number through Meta Embedded Signup. We receive the WABA/phone-number IDs, public business identity, the Meta administrator’s app-scoped connector identity, template status, number quality/tier, delivery events, member phone identity, message content and timestamps needed to provide the conversation. Meta also processes these data. Free-form business replies generally depend on Meta’s service window; business-initiated or out-of-window messages require an approved template. The community is responsible for Meta charges and lawful consent. Members may ask the community to stop, use a supported opt-out command, block the number, or contact us. Disconnecting or a valid Meta deletion request removes eligible credentials, identities, queued content and provider metadata.
Telegram
A community authorizes a Telegram bot. We map the Telegram user/chat identity to the relevant community identity, and process messages, commands, attachments and delivery metadata needed for the bot. Telegram processes the transport. Users may revoke consent, stop the bot, disconnect the linked identity, or request deletion. Bot privacy mode and administrator choices may limit what the bot can see.
Slack
A workspace administrator authorizes the Clases app and its requested OAuth scopes. We process workspace/team, channel, member and thread identifiers, messages passed to the app, delivery events and the encrypted authorization credential. Slack processes transport and workspace data. Workspace admins can remove the app; users can stop interacting with it and request access or deletion through their organization or Clases.
Microsoft Teams
A tenant or team administrator authorizes the Clases app. We process Microsoft tenant, team, conversation and user identifiers, messages sent to the app, conversation references and delivery results. Microsoft processes the transport. Tenant policy may control access. Administrators can uninstall or revoke the app, and users can exercise rights through their organization or Clases.
SMS
Where SMS is offered, a platform- or community-controlled number may send program messages through a messaging provider and carriers. We process the phone number, affirmative opt-in evidence, program/source, message and delivery records, STOP/HELP/UNSTOP choices, quiet-hours/time-zone signals, and billing segments. Message and data rates may apply. Consent must be specific and not a condition of purchase. We honor supported STOP requests promptly (and no later than applicable legal deadlines), permit HELP, and use UNSTOP only after a valid resubscription. Carriers and providers process delivery; number portability and delivery are not guaranteed. United States programs may also require A2P 10DLC brand and campaign registration; that operational registration does not replace individual consent.
8. Providers and international transfers
We use hosting, storage, security, analytics, payment, support, AI, and communications providers, including Meta, Telegram, Slack, Microsoft and an SMS provider when the related channel is enabled. Data may be processed outside the person’s country. We use contractual and organizational safeguards required for the transfer and disclose or update subprocessors as applicable. Providers may independently process data under their own notices.
9. Retention
We retain account and community data while needed to provide the service and then delete or de-identify it under documented schedules. Pending channel content is kept only for delivery/retry and support; resolved quarantine and provider-health telemetry are targeted for deletion within 30 days. Consent, security, fraud, transaction and legal records may be retained longer when needed to prove choices, protect users, keep financial records, resolve disputes or comply with law. Backups expire on controlled rotation. A deletion request removes eligible live data promptly but cannot erase records another law requires us to retain; retained records are minimized and excluded from normal product use.
10. Security
We use access controls, row-level authorization, encryption in transit, encrypted channel credentials, logging restrictions, monitoring, backups and incident procedures appropriate to the risk. No service is perfectly secure. Users and community owners must protect accounts, restrict provider permissions, and report suspected compromise promptly.
11. Choices and data rights
Depending on location, a person may request access, correction, deletion, restriction, objection or portability, withdraw consent, or appeal a decision. Account settings and channel commands provide some controls directly. Requests may be sent to privacy@clases.community or through the data-rights page. We verify requests and may ask for information necessary to protect the account. People may complain to their local data-protection or consumer authority. We do not discriminate for exercising a legal right.
12. Children
Clases is not directed to children who cannot lawfully consent to the service in their location. A school, guardian or community serving minors must have appropriate authority and safeguards. Contact us if information was submitted without required permission.
13. Changes
We may update this policy as products, providers or law change. The version and effective date identify the operative text. Material changes receive notice where required. A channel section does not mean that channel is available to every community.
14. Contact
Privacy and data-rights questions: privacy@clases.community. Product support: support@clases.community. Include the community name and channel, but never send an access token, password, or full payment-card number.
