Draft pending legal review. Last updated: 19 August 2026.
1. Who we are
WebBoard is an online teaching platform operated by the company identified on the Legal notice page. For students, teachers and staff who use WebBoard through a school, the school is the data controller and WebBoard acts as its processor under a Data Processing Agreement. For personal accounts not linked to any school, and for our own billing and website data, the operator of WebBoard is the controller within the meaning of Art. 4(7) GDPR.
2. Data we process
- Account data: name, email, password (stored hashed), role and language.
- School data (on behalf of the school): class membership, assignments and submissions, grades and attendance, calendar events, messages, uploaded files, and student-profile details a school chooses to record (which may include contact, guardian and, where the school enters them, health-related notes).
- Live-lesson and exam data: where a school enables it, video, audio and screen recordings for live lessons and exam proctoring, captured only after consent.
- Billing data: handled by our payment providers; we store subscription status, not full card numbers.
- Technical data: IP address, device and browser information and essential cookies needed to run the Service; analytics only with consent.
3. Why we process it and our legal basis
To provide the Service (Art. 6(1)(b) GDPR, contract); to keep it secure and prevent abuse (Art. 6(1)(f), legitimate interests); to comply with legal obligations such as accounting and a school's record-keeping duties (Art. 6(1)(c)); and, where we rely on it, with consent (Art. 6(1)(a): analytics cookies, exam recording, marketing emails). Special-category data such as health notes is processed only on the school's documented instructions and lawful basis (Art. 9 GDPR).
4. Children
WebBoard is used by minors through their schools. The school is responsible for the lawful basis and any parental consent required under national law. Where consent for an online service is relied on, the age from which a child can consent alone differs by country: 16 in Croatia and Germany, 15 in France, 14 in Spain and Italy, and 13 in Norway; below that age the holder of parental responsibility must consent or approve. We apply additional safeguards to children's data and minimise what we collect.
5. Who we share data with
We use vetted sub-processors strictly to run the Service: hosting and storage, live-video infrastructure, email delivery, payment processing and sign-in providers. We do not sell personal data. Our current sub-processors, with their locations and transfer safeguards, are listed on the Sub-processors page.
6. International transfers
Our application, database and live-video infrastructure are hosted in the EU. Some sub-processors may process data outside the EEA; where they do, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (Art. 46 GDPR).
7. Retention
For school data, retention is set by the school in line with its legal obligations; we delete or return it on the school's instruction or at the end of the contract. For personal accounts and billing, we keep data only as long as needed for the purpose or as the law requires. Data removed from active systems is purged from backups within our 14-day backup cycle.
8. Your rights
You have the rights of access, rectification, erasure, restriction, objection and data portability (Arts. 15 to 21 GDPR). We respond to requests without undue delay and at the latest within one month. For data held on a school's behalf, contact your school, which decides such requests in light of its retention duties; we assist the school. For personal-account or billing data, contact us directly. You may also lodge a complaint with a supervisory authority: our lead authority is the Croatian Personal Data Protection Agency (AZOP, Selska cesta 136, 10000 Zagreb, azop.hr), and you may equally contact the data protection authority of your own country of residence or work.
9. Security
We use measures including encryption in transit, access controls, tenant isolation, presigned private file access and audit logging. No system is perfectly secure, but we work to protect your data and to notify the supervisory authority and affected parties as required by Arts. 33 and 34 GDPR in the event of a breach.
10. Contact
For privacy questions or to exercise your rights, contact us via the contact page or the addresses on the Legal notice page.