Data processing addendum
How Baja Labs processes workspace data on your instructions, and the measures around it.
Draft pending review. This page is maintained by the operator of Classroom by Baja Labs and has not yet been reviewed by counsel. It describes how the service is actually run today.
Last updated 2026-09-08
Roles
For the content inside a workspace, the workspace owner is the controller and Baja Labs is the processor: the operator handles that content to run the service and on the controller’s instructions, not for its own purposes. For account records and service logs the operator is a controller in its own right.
Subject matter and duration
Processing lasts as long as the workspace exists, plus the time it takes for deletions to roll out of nightly backups. The subject matter is the operation of a collaborative workspace: storing, organising, transmitting, rendering and searching the content your team puts into it.
Categories of data and data subjects
Data subjects are the workspace’s members, guests, and anyone whose details your team records in it (for example a form respondent). Categories are whatever your team chooses to store: identifiers, contact details, documents, files and free text. Do not put special-category data (health, biometrics, and the rest) into Classroom — the service is not built for it and this addendum does not cover it.
Instructions
The operator processes workspace content only to provide, secure and support the service, and on the controller’s documented instructions — which, in practice, are the actions taken in the product. Workspace content is not sold, is not used to train models, and is not used to build profiles.
Confidentiality and access
Access to production data is limited to the operator’s personnel who need it to run the service, under confidentiality obligations. Administrative access is through per-person credentials, gated by the operator’s identity provider; database credentials live in a secrets vault, not in code or in configuration files.
Security measures
- Data at rest in a self-hosted PostgreSQL database on the operator’s own hardware in Helsinki, Finland, with no public database port: applications reach it through an authenticated private tunnel with an allow-listed egress.
- Tenant isolation enforced in the database itself by row-level security, not only in application code, so a query that forgets its workspace filter still returns nothing it should not.
- TLS on every connection between browser, app and services.
- Uploads in a private bucket, reachable only through short-lived signed URLs issued after a permission check.
- Optional two-factor sign-in, visible session management, and rate limits on authentication and other abusable surfaces.
- Nightly encrypted backups held off-box.
- Service-to-service calls authenticated with signed requests; internal services carry no public URL.
Subprocessors
The operator uses the providers listed on the subprocessors page, each bound to comparable obligations. Workspace admins are notified before a new subprocessor that can reach workspace content is added, and may object.
International transfers
Content at rest stays in the EU (Finland). Processing, delivery and support involve providers that operate outside the EU, including in the United States — the subprocessors page names each one and what it touches. Those transfers rely on the providers’ standard contractual clauses.
Assisting the controller
The operator will help the controller answer data-subject requests and meet its own security and impact-assessment duties. Members can already correct their own profile and close their own account from the account page; a workspace admin can export and delete workspace content. For anything those two paths do not cover, contact the operator.
Breach notification
On becoming aware of a personal-data breach affecting workspace content, the operator will notify the affected workspace admins without undue delay, with what is known: what happened, what data was involved, and what is being done.
Return and deletion
On termination, a workspace admin can export the workspace and then purge it, which removes its rows. Copies inside nightly backups age out on the backup rotation. Ask the operator if you need written confirmation.
Audit
The operator will answer reasonable written questions about these measures and share what evidence it has. There is no third-party audit report today; this page says so rather than implying one exists.
Questions about this page? Contact your workspace owner — they hold the operator relationship for your workspace.