Privacy Policy
Last updated: January 2025
Operated by ClassResponse (CRS) — a Bangladesh-based education technology platform. We are committed to protecting your privacy in accordance with the Digital Security Act, 2018 and other applicable Bangladeshi laws.
1. Information We Collect
Account Information (Teachers)
- Full name and institutional / professional email address
- Institution or organisation name
- Account creation date and login activity timestamps
- Subscription plan and billing transaction records
Platform Usage Data
- Courses, semesters, and sessions you create
- Question templates and CLO (Course Learning Outcome) sets
- AI analytics usage counts and saved report data
- Feature usage patterns used to improve the platform (see Section 5)
Student Response Data
Student feedback is collected completely anonymously. CRS does not collect, store, or process any personally identifiable information from students. Responses are identified only by a random anonymous ID, a session reference, and a timestamp. No names, emails, or device identifiers are ever linked to individual student responses.
2. How We Use Your Information
- Service delivery — to operate your account, process payments, and provide all platform features
- Analytics — to generate feedback reports and statistics for your sessions and courses
- Security — to detect fraud, prevent abuse, and maintain platform integrity
- Support — to respond to your queries and resolve technical issues
- Platform improvement — see Section 5 below
3. Third-Party Services
Supabase (Database & Authentication)
Your account data and platform content are securely stored using Supabase, which is hosted on AWS infrastructure. Data is encrypted at rest and in transit. Supabase’s privacy practices are described at supabase.com/privacy.
SSLCommerz (Payment Processing)
Subscription payments are processed by SSLCommerz, a Bangladesh Bank-licensed payment gateway. CRS does not store your card or banking details. SSLCommerz is responsible for the security of payment data under Bangladesh Bank regulations.
Google Gemini (AI Analytics)
AI Feature Data Disclosure
When you use the AI Insights feature, aggregated and anonymised session data (question text, response distributions, and statistical summaries) is transmitted to the Google Gemini API for processing. No personally identifiable information — of you or your students — is included in these transmissions.
- AI feature usage is entirely opt-in — data is only sent to Gemini when you explicitly click an AI analytics button
- Google’s processing of that data is governed by the Google Gemini API Terms of Service and Google Privacy Policy
- CRS has no control over how Google handles, stores, or uses data once it is submitted to the Gemini API
- By using any AI Analytics feature, you acknowledge and accept Google’s applicable policies
- CRS is not liable for Google’s data practices on data submitted to the Gemini API
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to any third party. Data may be shared only in the following limited circumstances:
- With infrastructure providers (Supabase, SSLCommerz, Google Gemini) solely to provide the service, as described above
- When required by Bangladeshi law, a court order, or a lawful request by a government authority
- To protect the rights, safety, or property of CRS, our users, or the public
- In connection with a business transfer or acquisition, where the acquiring party agrees to honour this policy
5. Use of Data to Improve CRS
CRS may use aggregated, non-personally-identifiable platform usage data to improve our services. This includes:
- Analysing feature usage patterns to prioritise development
- Identifying common issues or performance bottlenecks
- Improving AI prompt quality and response accuracy over time
- Generating platform-level statistics (e.g., total sessions created, average response rates)
This analysis is always performed on aggregated data. Individual user data is never disclosed or used in identifiable form for this purpose. We will not use your data to train third-party AI models without your explicit consent.
6. Data Security
- All data is transmitted over HTTPS (TLS encryption)
- Row-Level Security (RLS) ensures each user can only access their own data
- Passwords are hashed and never stored in plain text (managed by Supabase Auth)
- Access to production systems is restricted to authorised personnel only
7. Student Privacy
CRS is designed with student anonymity as a core principle:
- No student registration or login is required to submit feedback
- Responses are identified only by a random anonymous identifier
- No IP addresses, device fingerprints, or cookies are stored alongside responses
- Teachers cannot identify which student submitted a particular response
- Anonymous response data is never shared with any third party except as part of aggregate platform statistics
8. Data Retention
- Active accounts: Data is retained for the duration of your account
- After account deletion: Personal data is deleted within 30 days; anonymised aggregate statistics may be retained
- Billing records: Transaction records are retained for 7 years as required by Bangladesh tax and financial regulations
- Anonymous feedback: May be retained indefinitely in anonymised form for institutional trend analysis
9. Your Rights
As a registered user you have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — update inaccurate or incomplete information via your profile settings
- Deletion — request deletion of your account and associated personal data
- Portability — download your own data in CSV format via the Data Download feature in your profile
- Objection — object to specific processing activities where we rely on legitimate interest
To exercise any of these rights, contact us at classresponsesystem@gmail.com. We will respond within 30 days.
10. Cookies
CRS uses only essential cookies for authentication and session management. We do not use advertising cookies, tracking pixels, or any third-party analytics cookies. You can disable cookies in your browser, but doing so will prevent you from logging in to the platform.
11. Governing Law
This Privacy Policy is governed by the laws of the People’s Republic of Bangladesh, including the Digital Security Act, 2018 and related regulations issued by the Bangladesh Telecommunication Regulatory Commission (BTRC). Any disputes shall be resolved under Bangladeshi jurisdiction.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes via email or an in-platform notice at least 14 days before the change takes effect. Continued use of CRS after the effective date constitutes acceptance of the revised policy.
13. Contact
For privacy-related questions, data requests, or concerns, contact our privacy team at classresponsesystem@gmail.com.