
Schoox and GDPR
CertReports found no public GDPR evidence for Schoox as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 27 Mar 2024
- Expires or valid through
- 23 Feb 2027
- Scope
- The Schoox Application: is a SaaS-based Learning Management System which is hosted within the United States (US), Canada (CA) and United Kingdom (UK) in mutually exclusive environments. Personal Data may be input and transferred by the client to the application from the originating country, which may be outside of the U.S. or UK for the purpose of supporting the Learning Management requirements of the client. Additionally, Schoox may be required on the explicit direction on behalf of the client to transfer personal data from locations outside of the US or UK to the Schoox application in the US. In this role, Schoox provides support to the application as a Data Processor. As a standard practice, as a Data Processor, Schoox does not access or disclose personal information within the Application unless directed by the Client or in support of the Contract and agreement. Schoox relies on the Swiss-U.S. Data Privacy Frameworks and the UK Extension to transfer Swiss and UK personal information to the U.S.. Data collected may be used for the following purposes: provision of services, offering and improving the service, surveys, communication, advertising, user engagement, marketing, lead generation, legal compliance. Information collected is used to take steps to conclude a contract with customers, or to provide our services to customers. Schoox may also use these personal data for our legitimate purpose of contacting you with newsletters, marketing or promotional materials and other information concerning our activities that may be of interest to you. Schoox as. Processor: The types of data collected as a processor which are provided by the customer/controller to provision the service under the contact are as follows: First Name, Last Name, Business Email Address, Country/Location, usernames, and passwords. As a standard practice Schoox does not disclose personal information to any third-party or unauthorized party for any reason. Data collected as processor is utilized to provide the service for clients/customers as contractually obligated. Should Schoox be required to disclose any personal data to third parties, it will not do so unless fully authorized by the client agreement or in accordance with support of the agreement, or applicable law. Schoox as a Controller: Schoox’s direct methods of personal data collection include through our website, marketing, sales outreach, and third party provided information. This information is used solely to contact individuals and or organizations about sales, advertising or marketing prospects of Schoox products. The types of third parties may include those entities which assist with sales, marketing, advertising, social media, and outreach according to the data provided and consented by the individual. Data collected as a controller are as follows: First Name, Last Name, Business Email Address, Country/Location. You may opt out of this collection, and any disclosure of personal information to a third party is relegated to only be used on behalf of Schoox and at Schoox’ direction, and not for any other purpose. No data is sold to any third party. Data Collected is First Name, Last Name, Business Email/Contact information. HR Schoox employee data: Schoox, collects personal information regarding employees as required for HR and employment-based obligations for the US, UK, and EU. Swiss HR data is not collected as there are no entities or employees in Switzerland. Data Collected for HR purposes are as follows: First Name, Last Name, Address, Country, Employment records, Job Title. Personal data is kept for only HR-related purposes and is not disclosed to third parties for purposes other than HR and employment required use. No personal employee data is provided to third parties for marketing, or non-HR related purposes. For all EU and UK based employees, local law and jurisdiction takes precedence over what personal data is provided and disclosed. Restriction of personal data by the individual for non-HR /direct employment requirements is provided to the data subject and does not in any way hinder or restrict employment, or employment opportunities. The types of third parties may include those entities which assist with support of the employee and employment relationship while tenured at the company.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Schoox, LLC: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 6a98bee70a |
- Kind
- listing
- Issued or listed
- 6 May 2019
- Scope
- Schoox SaaS Application: The Schoox Application is a SaaS based Learning Management System which is hosted solely within the United States. Personal Data may be input and transferred by the client to the application from the originating country, which may be outside of the U.S. for the purpose of supporting the Learning Management requirements of the client. Additionally, Schoox may be required on the explicit direction on behalf of the client to transfer personal data from locations outside of the US to the Schoox application in the US. In this role, Schoox provides support to the application as a Data Processor. As a standard practice, as a Data Processor, Schoox does not access or disclose personal information within the Application unless directed by the Client or in support of the Contract and agreement. Schoox as a Company: Schoox may collect or obtain Personal Data about you, if you are located outside of the United States this information may be transferred from a location outside of the U.S. to the U.S. through the following methods: directly from you (e.g., where you contact us); in the course of our relationship with you (e.g., if you make a purchase); when you make your Personal Information public, when you download, install, or use any of our Services; when you visit our Services; when you register to use any part of the Services; when you volunteer Personal Data about yourself in public areas of the Services; when you interact with any third party content or advertising; we may also receive Personal Information about you from third parties. • Purposes of Data Collection: For data collection methods as described for Schoox as a Company the following examples of uses of this Personal Information may be used for: o Provision of Services to you o Offering and Improving the Service o Surveys o Communication o Advertising o User Engagement o Marketing o Lead Generation o Legal Compliance
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Schoox Inc.: Inactive | Live pagesha256 a2eae128d3 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Schoox GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the HR and HRIS category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No HR and HRIS vendor has GDPR evidence in the index yet.