Privacy Policy

Last updated: Sept 24, 2025

1. Introduction

This Privacy Policy explains how XFocus AS ("the company", "we", "our", "us") processes personal data when providing educational platform services to schools and educational institutions. We are committed to protecting personal data in accordance with applicable laws and regulations, in particular the General Data Protection Regulation (GDPR).

XFocus is exclusively available to educational institutions. We do not offer individual accounts or direct-to-consumer services.

2. Data Processing Roles

2.1 School as Data Controller

Educational institutions (schools, districts, or organizations) act as Data Controllers, determining the purposes and means of processing personal data for their students, teachers, and staff.

2.2 XFocus AS as Data Processor

XFocus AS acts exclusively as a Data Processor, processing personal data on behalf of and under the instructions of schools for:

  • Student personal data and educational records
  • Teacher and staff account information
  • Class and project content
  • Learning activity data
  • Assessment and progress tracking

2.3 Limited Controller Role

XFocus AS acts as Data Controller only for:

  • School billing and contract information
  • Administrative contact details
  • Direct support communications with school administrators
  • Platform usage analytics (aggregated and anonymized)

2.4 Contact Information

For questions about data processing, please contact:

Email: support@xfocus.no

Schools should refer to our Data Processing Agreement for detailed processor obligations and requirements.

3. What personal data we process and why

3.1 General

We collect, store, and process personal data that is necessary for us to provide our services to you. You provide this data directly when registering or interacting with our applications.

3.2 Educational Platform Services

As instructed by schools, we process the following categories of personal data:

  • Student and teacher names (may be pseudonymized)
  • Email addresses
  • User roles (student, teacher, administrator)
  • Class and school affiliations
  • Educational content and submissions
  • Learning progress and assessment data
  • Platform usage patterns

This data is processed solely to provide educational services as directed by the school.

3.3 Customer Support and Communication

If you contact us by email or other written communication, we will process your personal data to respond to your inquiries and maintain dialogue.

Legal basis: GDPR Article 6(1)(b) (necessary for the performance of a contract) or Article 6(1)(f) (legitimate interest in handling requests and maintaining contact).

3.4 Website and App Usage

Our IT systems log activity on our websites and applications. This includes IP address, links clicked, browser information, and device data. These logs may be analyzed in cases of hacking, cyberattacks, or criminal activity.

Legal basis: GDPR Article 6(1)(f), where our legitimate interest in securing systems outweighs the privacy impact.

3.5 Billing and Accounting

We are legally required to maintain accounting records for five years after the end of the financial year. Such records may contain necessary personal data to enable invoicing and payment. Processing of payments is done through Stripe.

3.6 Data Usage Summary

The following table summarizes how we use your personal data:

Data TypePurposeLegal BasisRetention
Email addressAccount access, notificationsContractActive account + 30 days
NameUser identificationContractActive account + 30 days
School/Class dataService deliveryContractActive account + 30 days
IP addressSecurity, fraud preventionLegitimate interest90 days
Browser infoTechnical supportLegitimate interest90 days
Payment dataBilling, accountingContract, legal obligation5 years

4. Storage and Security

Your data is stored on secure servers within the EEA. We use recognized technical solutions to protect your data against unauthorized access, disclosure, alteration, and destruction.

5. Use of Subcontractors and Third-Party Services

We use subcontractors for IT and administrative services. Where these subcontractors process personal data, we have entered into Data Processing Agreements requiring compliance with data protection regulations and restricting processing to what is necessary for service delivery.

5.1 Sub-Processors

For a complete list of our sub-processors and third-party services, please refer to our Data Processing Agreement. All sub-processors are bound by appropriate data protection agreements and are regularly audited for compliance.

6. Disclosure of Personal Data to Third Parties

We will not share, sell, or transfer your personal data to third parties without your consent, unless required to fulfill our agreement with you or to comply with legal obligations or court orders.

7. Transfer of Data Outside the EEA

Your personal data will not be transferred outside the EU/EEA unless required by law or legal order.

8. Your Rights

Students, teachers, and other individuals whose data is processed have the following rights under GDPR:

Right of access:Request a copy of your personal data and verify lawful processing.
Right to rectification:Request correction of inaccurate or incomplete data.
Right to erasure/anonymization:Request anonymization of your data where no valid reason for processing exists. We will anonymize rather than delete to maintain service integrity.
Right to object:Object to processing based on legitimate interest if specific circumstances apply.
Right to restriction:Request suspension of processing in certain cases (e.g., data accuracy checks).
Right to data portability:Request transfer of your data to another party.

You also have the right to file a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe our processing violates GDPR. See: www.datatilsynet.no

To exercise these rights, individuals should first contact their school's data protection officer. Schools can contact us directly for assistance.

9. Retention and Anonymization

We keep your personal data only as long as necessary to fulfill the purposes described above or as required by law. After that, the data will be anonymized rather than deleted.

Anonymization means removing or modifying personal identifiers so that data can no longer be attributed to you. We may retain anonymized data for statistical analysis and service improvement.

10. Changes to this Privacy Policy

XFocus AS reserves the right to update this Privacy Policy when necessary. Updated versions will be published on our website with the date of the latest revision.

XFocus | Manage all student-led projects in one place