Oxira (Classti) provides Classti Teacher, a digital platform dedicated to managing teachers' affairs within schools. We are committed to protecting the privacy of the Application's users and to processing their personal data transparently, responsibly, and in compliance with the Saudi PDPL, Egyptian Personal Data Protection Law No. 151 of 2020, and the requirements of Google Play and Apple App Store.
The platform enables teachers to manage classes and students, record attendance, record grades, upload assignments and educational files, exchange educational notifications, conduct school communication, and complete administrative and educational workflows.
Important note: The Application is a teacher management platform used by schools and educational institutions. It does not provide a private tutoring marketplace, a public social network, or an e-commerce marketplace.
- Personal Data: Any data that may lead to identifying an individual directly or indirectly.
- Sensitive Data: Includes racial or tribal origin, religious/political beliefs, criminal/security data, biometric and genetic data, health data, and precise geographic location.
- Processing: Any operation on personal data by any means, including collection, storage, modification, use, disclosure, transfer, and destruction.
- Data Subject (User): The teacher using the Application, the student whose data is entered, or any natural person whose data appears in the system.
- Data Controller: The entity that determines the purposes and means of processing personal data.
- Processor: The party that processes personal data on behalf of the Controller.
- School/Educational Institution: The educational entity that employs the teacher and grants them access to the Application.
- Competent Authority: SDAIA in Saudi Arabia; the Egyptian Personal Data Protection Center in Egypt.
The Data Controller is Oxira (Classti). In certain cases, the school or educational institution may act as an independent or joint controller with respect to its students' and staff data. For any privacy matter, please refer to Section 22.
This policy applies to all personal data collected and processed through the Classti Teacher application on Android and iOS, any associated services or backend systems, and any communication between you and the Company in the context of using the Application.
This policy does not apply to third-party websites or applications that may be accessed through links within the Application.
5.1 User Profile Data
- Full name, email address, phone number, profile photo.
- Job title, subject specialization, qualifications, academic and professional certificates.
5.2 Identity Verification Data
- National ID, residency ID, passport, professional licenses, and supporting verification documents.
Some of this data (such as the National ID and biometric data) is sensitive and is treated with a higher level of protection.
5.3 Student-Related Data
- Student names, attendance records, grades, assignments, academic notes, and educational records.
This data is entered by the teacher during their duties, and the Application processes it on behalf of and for the benefit of the school.
5.4 Uploaded Content
- Images, documents, PDF files, and educational attachments.
5.5 Location Data
- Precise geographic location (GPS) and approximate location — collected only when you activate features that require it and after obtaining your permission. You may withdraw this permission at any time from your device settings.
5.6 Technical Data
- Device information, device model, OS version, app version, device identifiers, IP address, log data, and network information.
5.7 Biometric Data (Biometric Authentication)
The Application supports biometric authentication via Face ID, Touch ID, and fingerprint. The matching process takes place locally on your device — we do not collect, store, or transmit your fingerprint or facial features to our servers; we only receive the success or failure result of the authentication.
- Consent: Where you grant explicit consent to process your data for a specific purpose (such as location services or sensitive data).
- Performance of a Contract: Where processing is necessary to provide the Application's services.
- Legal Obligation: Where processing is necessary to fulfill a legal obligation on the Company.
- Legitimate Interest: Such as securing the system and combating fraud, without prejudice to data subject rights.
- Educational/Institutional Interest: Where student data is processed on behalf of the school for its legitimate educational functions.
- Creating and managing user accounts and verifying teacher identity.
- Enabling core functions: managing classes, recording attendance, recording grades, uploading assignments and files.
- Sending educational and administrative notifications and enabling school communication.
- Verifying qualifications and professional licenses.
- Securing access through biometric authentication or passwords.
- Improving Application performance and user experience through analytics and crash reports.
- Complying with legal and regulatory obligations and responding to competent authority requests.
- Protecting system and user security and combating fraud and misuse.
8.1 Google Firebase Services
- Firebase Authentication: To manage login and account authentication.
- Firebase Analytics: To collect usage statistics and analyze user behavior on an aggregate basis.
- Firebase Crashlytics: To monitor app crashes and diagnostic error reports.
- Firebase Cloud Messaging (FCM): To send push notifications.
- Firebase Remote Config: To manage Application settings remotely.
- Firebase Cloud Storage: To store files and uploaded content.
8.2 Google Maps Platform
To display maps and provide location-based services when needed.
8.3 Camera and Image Picker Services
To allow uploading of images and documents from the device gallery or camera.
8.4 Secure Local Storage
To store some data in encrypted form on your device to facilitate the operation of the Application.
8.5 Biometric Authentication (Face ID / Touch ID / Fingerprint)
Managed through the OS interfaces (Apple / Android); biometric data is not transmitted to our servers.
We collect — primarily through Firebase Analytics, Crashlytics, and performance monitoring tools — the following for service improvement:
- Screen views, user properties, custom events, and feature usage metrics.
- Crash reports, diagnostics information, and performance monitoring data.
This data is used in aggregated and statistical form and is not used for advertising targeting. You can control some of these activities from your device or Application settings.
- Student data is collected and processed exclusively for legitimate educational and administrative purposes on behalf of the school.
- The Application does not allow students to create personal accounts directly; their data is entered by authorized teachers.
- The school is responsible for obtaining necessary parental or guardian consents where required by law before entering minor students' data.
- We do not use student data for marketing, advertising, or behavioral profiling purposes.
- We apply strict access controls limiting student data access to authorized teachers and administrators only.
- Parents and schools are granted the right to access, correct, or delete a student's data as guaranteed by law.
Given the Application's reliance on global cloud infrastructure (such as Google Firebase), some data may be processed or stored outside Saudi Arabia or Egypt. When any international transfer occurs, we commit to:
- Ensuring the transfer does not prejudice the protection level guaranteed under Saudi and Egyptian law.
- Relying on service providers with appropriate protection safeguards (e.g., standard contractual clauses and recognized security certifications).
- Limiting transfers to what is necessary for the specified processing purposes.
- Obtaining necessary regulatory approvals from the competent authority where required by law.
- Firebase Cloud Storage and other Firebase services.
- Secure local storage on the device (in encrypted form).
- Approved cloud infrastructure providers.
| Data Category |
Retention Period |
| Account data |
For the duration of account activity; deleted or anonymized within a reasonable period after account closure, unless otherwise required by law. |
| Identity verification documents |
For the period necessary for verification and regulatory compliance, then securely deleted. |
| Student educational records |
As determined by the school and its regulatory requirements, then deleted or returned to the institution. |
| Uploaded files |
Until deleted by the user or institution, or until account closure and expiry of the legal period. |
| Analytics data |
For a limited period in aggregated form, per the service provider's settings. |
| Crash reports |
For a limited period for diagnostic and performance improvement purposes, then automatically deleted. |
- Encryption in Transit: Using secure protocols (TLS/HTTPS) to protect data while in transit.
- Encryption at Rest: To protect data stored on servers and devices.
- Role-Based Access Control (RBAC): Limiting data access to those who need it to perform their duties.
- Password Hashing: Passwords are not stored in plain text.
- Continuous Security Monitoring: To detect and respond to unusual activity.
- Incident Response Procedures: For an organized response to any security incident.
- Taking immediate measures to contain the breach and limit its effects.
- Assessing the nature, scope, and affected data.
- Notifying the competent authority (SDAIA / Egyptian Personal Data Protection Center) within the prescribed regulatory period.
- Notifying affected data subjects when the breach has a serious impact on their privacy or rights, as required by law.
- Documenting the incident and measures taken to prevent recurrence.
Under the Saudi Personal Data Protection Law (PDPL)
- Right to Know: The legal basis and purpose of collecting your data.
- Right of Access: To view your personal data held by us.
- Right to Obtain a Copy: In a clear and legible format.
- Right to Correction: To correct inaccurate or incomplete data.
- Right to Request Destruction: To request deletion of data no longer needed.
- Right to Withdraw Consent: At any time where processing is based on consent.
Under Egyptian Law No. 151 of 2020
- Right of access and knowledge of your personal data.
- Right to review, correct, and update the processed data.
- Right to erasure (deletion) of personal data.
- Right to object to processing or its results.
- Right to withdraw consent to processing.
- In-App Deletion: You can request account deletion directly from within the Application via the dedicated settings.
- Data Deletion Requests: You may also submit a request through the contact details in Section 22.
- Processing Timeline: We strive to process deletion requests within a reasonable period not exceeding the prescribed regulatory periods.
- Legal Exceptions: We may retain some data to fulfill a legal obligation, settle disputes, or where linked to educational records subject to school requirements. Data is deleted as soon as the retention purpose ceases.
As a mobile application, we do not use cookies in the traditional website sense. However, we may use similar technologies such as device identifiers, local storage keys, and analytics tools for operating, improving, and securing the Application as set out in Sections 8 and 9. If web-based services are made available in the future, separate cookie notices will apply where necessary.
The Application does not currently rely on fully automated processing that produces legal or material effects without human intervention. Should we add AI or machine learning features in the future, we commit to:
- Clearly disclosing the nature of these features and the data they use before activating them.
- Not using minor students' data to train AI models without a valid legal basis.
- Ensuring appropriate human oversight of any decisions that may materially affect the data subject.
- Enabling you to object to automated processing and request a human review where guaranteed by law.
- Applying controls of transparency, fairness, and non-bias in the design of these features.
We may update this policy from time to time to reflect changes in our practices or regulatory requirements. When we make material changes, we will notify you through an in-app notification or via email. We recommend reviewing this policy periodically.
For users in the Kingdom of Saudi Arabia: this policy is governed by the applicable laws of the Kingdom, and the competent judicial authorities in the Kingdom have jurisdiction over any dispute.
For users in the Arab Republic of Egypt: this policy is governed by the applicable laws of Egypt, and the competent Egyptian courts have jurisdiction over any dispute.
For any inquiry, request, or complaint regarding this policy or the processing of your personal data, please contact us via:
🏢 Oxira (Classti)
📧 info@oxira.sa
👤 Data Protection Officer (DPO): Ibrahim Hassan
📮 I.salah@oxira.sa
📞 +966596694021
You also have the right to file a complaint with the competent authority:
- In the Kingdom of Saudi Arabia: The Saudi Data and Artificial Intelligence Authority (SDAIA).
- In the Arab Republic of Egypt: The Egyptian Personal Data Protection Center.
Acknowledgment
This document constitutes the official Privacy Policy of the Classti Teacher application, prepared for publication on the website and within the application on the Google Play and Apple App Store.