Try Interactive Demo

GDPR Compliance Statement

GDPR Compliance Statement

Effective date: July 28, 2026

CampusThreads Network Corp. provides a platform that helps educational institutions manage student-ambassador programmes and communicate with prospective students. This statement explains how we support compliance with the EU General Data Protection Regulation (GDPR) when it applies to our services.

This statement should be read with the applicable customer agreement, Data Processing Agreement (DPA), and our Privacy Policy. If those documents conflict, the signed customer agreement and DPA control for Customer Data.

Our role

For personal data that an educational institution, school, or other customer uploads to or collects through CampusThreads (“Customer Data”), the customer normally decides why and how that data is used. The customer is therefore the data controller and CampusThreads acts as its data processor, processing Customer Data to provide and support the service and on the customer’s documented instructions.

CampusThreads is an independent controller for personal data it uses for its own business administration and relationship with customers or prospective customers, such as business-contact information, billing and account-management records, and information collected through our website or direct communications.

Customers remain responsible for determining an appropriate lawful basis, providing notices to their users, and responding to requests that concern their own processing. CampusThreads provides reasonable assistance to customers with GDPR obligations as described in the applicable DPA and law.

Data and purposes

Depending on the features a customer chooses to use, Customer Data may include account, identity, role, and contact information; profile information and user-submitted content, including messages and programme activity; communications metadata; technical and security information; and customer-authorised integration data. We process Customer Data to provide, secure, troubleshoot, and support the service; prevent misuse; and meet legal obligations. Optional analytics, AI, communications, and integrations are used only when the relevant feature is enabled or authorised for the customer.

The service is not designed for customers to upload unnecessary special-category personal data. Customers should not submit it unless they have assessed the need and have a valid legal basis and appropriate safeguards.

Security and confidentiality

CampusThreads maintains technical and organisational measures designed to protect Customer Data against unauthorised or unlawful processing and accidental loss, destruction, or damage. These measures include access controls, least-privilege practices, multi-factor authentication for relevant administrative access, encryption in transit and at rest for managed production data stores, security logging and monitoring, secure development practices, and incident-response procedures. Access is limited to authorised personnel and service providers with a need to know who are subject to confidentiality obligations.

Service providers and transfers

We use service providers to operate parts of the service, including cloud hosting, authentication, communications delivery, monitoring, analytics, approved AI features, and customer-authorised integrations. A provider receives only the data needed for its role. Customer Data may be processed in Canada, the United States, or other locations where CampusThreads or authorised service providers operate. Where a restricted international transfer is involved, we use an appropriate transfer mechanism and supplementary safeguards where required by applicable law and the DPA. Current customers may request information about subprocessors relevant to their use of the service at team@campusthreads.co.

Data-subject requests

Individuals may have rights under the GDPR, including rights of access, rectification, erasure, restriction, objection, portability, and rights related to certain solely automated decisions. The availability of a right depends on the circumstances and applicable law.

If a request concerns Customer Data, individuals should ordinarily contact the educational institution or other customer that controls the data. If CampusThreads receives such a request, we will direct it to the relevant customer where appropriate and assist the customer as required by the DPA and applicable law. Requests about data for which CampusThreads is the controller may be sent to team@campusthreads.co. We will respond without undue delay and within the time limits required by applicable law.

Retention, deletion, and incidents

We retain Customer Data for the duration of the customer relationship unless a customer gives a documented instruction or the parties agree otherwise. At the end of an engagement, we delete or return Customer Data in accordance with the DPA and documented instructions, generally within 30 days, subject to legal holds, legal or regulatory obligations, or an agreed contractual retention period. Deleted data is removed from active production systems; encrypted, access-controlled backup copies may remain until their recovery-retention period expires.

We investigate suspected security incidents under our incident-response process. If we confirm a personal-data breach affecting Customer Data, we notify the affected customer without undue delay in accordance with the DPA and applicable law.

Contact and updates

Questions about this statement or privacy may be sent to:
CampusThreads Network Corp.
11 Ordnance St.
Toronto, ON
Canada
team@campusthreads.co

We may update this statement to reflect changes to our service, legal requirements, or privacy practices. We will post the current version and effective date on this page.