← ClassOvation

Data Processing Addendum

Last updated: September 2026

This addendum supplements our Terms of Service and Privacy Policy. It is written so a studio can execute it by exchanging emails with us — no portal or signature tool required.

1. Parties & roles

This addendum is between EMSERO LLC, operator of ClassOvation (“Processor,” “we”), and the studio identified in the signature block below (“Controller,” “studio”). The studio is the data controller for the family and student information it enters into ClassOvation — it decides what is collected, from whom, and why. EMSERO is a data processor, acting only on the studio's instructions as expressed through its configuration and use of the platform.

2. Instructions

EMSERO processes personal data only as necessary to provide the ClassOvation service — registration, scheduling, billing, communication, and the other features the studio uses — and as otherwise instructed in writing by the studio (including through support requests). EMSERO will notify the studio if an instruction, in EMSERO's reasonable opinion, would violate applicable data protection law.

3. Scope of data

Includes, without limitation: student names, dates of birth, addresses, photos, allergy and medical/special-needs notes, guardian contact information, and payment-adjacent data (billing address; card details are held by Stripe, not EMSERO — see Section 5).

4. Minors' data

The studio represents that it has obtained whatever parental or guardian consent applicable law requires before entering a minor's information into the platform. EMSERO does not collect information directly from children and has no independent relationship with the minors whose data a studio enters — the studio maintains that relationship. EMSERO will not use student or minor data for advertising, will not sell it, and will not share it beyond the subprocessors named in Section 6.

[Counsel to confirm whether COPPA or a state student-data-privacy law applies to this arrangement. ClassOvation's direct relationship is with studios and parents, not children, and student data is entered by an adult on a minor's behalf rather than collected from the minor — a fact pattern that plausibly falls outside COPPA's “directed to children” trigger, but that determination should come from counsel given the volume of under-13 data involved.]

5. Security measures

EMSERO maintains, at minimum, the following measures:

  • Database-enforced tenant isolation: every studio's data lives in a shared, multi-tenant database, but row-level security policies — enforced by a non-superuser application role with no bypass privilege — confine each query to the studio it is authorized for, as a backstop independent of the application's own authorization checks.
  • Multi-factor authentication (TOTP) available to studio staff accounts.
  • Encryption in transit for all traffic to the service, and encryption at rest for backups.
  • Nightly, independently stored backups (Fly volume snapshots plus an offsite encrypted copy in Amazon S3), with restore drills — an untested backup is not treated as a backup.
  • Secrets (API keys, database credentials) held in a managed secret store, never in source control, with least-privilege access.
  • Structured error and security logging, with automated alerting on server errors and on payment-ledger integrity drift.

[Counsel + Brian to confirm whether any further certification (e.g., SOC 2) should be represented here — none is claimed today, and this addendum should not imply one that does not exist.]

6. Subprocessors & change notice

The studio consents to EMSERO's use of the subprocessors named in the Privacy Policy as of the date of this addendum: Stripe (payment processing), Resend (email delivery), Fly.io (application hosting), Amazon Web Services (encrypted backup storage), Sentry (error monitoring), Expo (mobile push delivery), and Anthropic (AI model for staff-requested assistance) — plus any SMS provider the studio itself configures. EMSERO will update the Privacy Policy and provide reasonable advance notice before adding a new subprocessor that will process the studio's data.

7. Breach notification

EMSERO will notify the affected studio without undue delay upon confirming a data breach affecting that studio's data, and in any case within 72 hours of confirmation. Notification will include what is known at the time: the nature of the incident, the categories and approximate volume of data involved, and remediation steps taken or planned. The studio is responsible for notifying its own families and any regulator its state requires; EMSERO will support that notification with the facts it has. See our breach-response plan for how EMSERO handles an incident internally.

8. Audit

On reasonable written request, no more than once per year absent a suspected incident, EMSERO will provide the studio with information reasonably necessary to demonstrate compliance with this addendum (e.g., a summary of the security measures in Section 5). [Counsel to confirm whether a stronger audit right — on-site, or via a named independent auditor — should be offered, and under what confidentiality terms.]

9. Data return & deletion on termination

On termination, EMSERO will make the studio's data available for export for a reasonable period, after which data is deleted or anonymized per our data retention policy: financial and business records are retained for their audit/legal lifetime per applicable recordkeeping law, and operational data with no ongoing purpose (tokens, telemetry, audit logs) is purged on a schedule. [Counsel to confirm whether this addendum should commit to a specific export window rather than “reasonable.”]

10. Studio's own obligations

The studio remains responsible for the accuracy of the data it enters, for obtaining any consents applicable law requires, and for its own compliance obligations as a business serving minors — obligations that exist independent of, and in addition to, anything EMSERO provides.

11. Liability

This addendum is governed by the liability terms of the Terms of Service between the studio and EMSERO. [Counsel to confirm whether this addendum needs its own liability treatment for data-specific claims, separate from the general Terms of Service cap.]

12. Execution

A studio executes this addendum by having an authorized representative email support@classovation.com from the address associated with its ClassOvation account, stating the studio's legal name and confirming agreement to this addendum as published at this URL on the date of that email. EMSERO will reply confirming receipt; both emails together constitute the signed addendum. Either party may instead execute a countersigned copy by mutual agreement.

Processor: EMSERO LLC, operator of ClassOvation

Controller (studio): ____________________________

Authorized signatory name & title: ____________________________

Date: ____________________________

This is a template pending review by counsel — it is not legal advice, and EMSERO recommends a studio have its own counsel review it before signing. See also our Terms of Service and Privacy Policy.