GDPR check

Is Wooclap GDPR compliant? What universities should check

Wooclap is a Belgian platform for live polls, quizzes and interactive questions in lectures, used by universities and schools. This page sets out what Wooclap publicly documents about hosting, its data processing agreement, subprocessors, AI features and security, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Wooclap SA is a Belgian company in Brussels, so it is directly subject to the GDPR. European customers are hosted on AWS in Paris, universities can sign a data processing agreement in which Wooclap acts as processor, and Wooclap publishes a subprocessor table with hosting locations, transfer impact assessments for sensitive transfers, and ISO 27001:2022 certification held since 2024. Wooclap says it does not train AI models on user content and lets organisations disable AI features. The points to check are the handful of US-based subprocessors, what reaches OpenAI when AI analysis is used on student answers, and whether staff use the institutional licence rather than self-service accounts.

What Wooclap documents publicly

This summary reflects Wooclap's privacy policy (last updated 8 September 2026), trust centre, security, GDPR and AI policy pages, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.

TopicWhat the vendor statesSource
Company and establishmentDocumented Wooclap SA, Rue des Pères Blancs 4, 1040 Etterbeek (Brussels), Belgium. The privacy policy names the Belgian Data Protection Authority among the authorities a person can complain to.[1]
Where data is storedDocumented Infrastructure on AWS. At the start of a contract, clients choose Paris (eu-west-3) or, for American clients, Oregon (us-west-2), each across three availability zones. Data is encrypted at rest (AWS KMS, AES-256) and in transit.[2] [3]
Data processing agreementDocumented For universities and business customers, a DPA can be signed and attached to the contract. Wooclap is then a processor and the customer the controller, and the DPA supersedes the online privacy policy. The DPA is listed in the trust centre and requested by email.[4] [1] [5]
SubprocessorsDocumented The privacy policy table names, among others, AWS (France or Oregon), Ably (Europe), Lunaweb GmbH (CloudConvert, Germany), Sentry (Germany), Hotjar (Ireland), Mailjet and Brevo (France), HubSpot (Europe), Customer.io (Europe or US by data location), and US-based Intercom (chat support), Stripe (online payments), Twilio (SMS answers, disabled by default) and Google (website analytics only). Institutional customers get at least 60 days' notice of new subprocessors by default.[1] [4]
International transfersDocumented Transfers outside the EEA rely on an adequacy decision or Commission-approved standard contractual clauses, with a transfer impact assessment based on the EDPB model; TIAs for Intercom and Twilio are available on request. Wooclap says it prioritises subprocessors with European hosting.[1] [4]
AI features and trainingDocumented AI features assist content creation and analyse open-question results. OpenAI is the AI subprocessor, with data in Ireland (or the US for US hosting), under a zero data retention commitment. Wooclap says no personal data is involved in transfers to OpenAI and that it does not use user content or personal data to train AI models. Organisations can disable AI features for all users.[6] [1]
Retention and deletionDocumented Self-service accounts are deleted after three years of inactivity, with warning emails. Organisational customers can ask their account manager to delete contract data. On deletion, identifiers are anonymised and content is deleted. Application logs are kept six months and backups 30 days.[3]
Security certificationsDocumented ISO 27001:2022 certification obtained in May 2024 and renewed in 2025 and 2026, with the certificate available on request. Annual security audits; customers with an organisational licence can request one audit a year at their own cost.[3] [5]
Institution controlsDocumented Single sign-on through eduGAIN, SAML, Shibboleth, CAS, Azure AD and others, support for the GÉANT Data Protection Code of Conduct, and LTI 1.3 for LMS integration.[3] [4]
ChildrenDocumented Wooclap publishes a separate child-friendly privacy policy for use in schools. This matters for universities mainly in outreach to school pupils.[1]

Wooclap deserves credit for a clearly organised trust centre: a subprocessor table that gives each provider's hosting location, named transfer impact assessments, a default 60-day notice period for institutional customers, a clear statement of processor role under a DPA, and a published retention policy that explains what is anonymised and what is deleted.

What this means for a university

Validemic's analysis

Sign the DPA, and make it the governing document. Without a DPA, the online privacy policy describes the relationship, and it is written for individual users [4]. With a DPA, Wooclap is a processor under Article 28 GDPR and the university decides retention and purposes [7]. For campus licences, attach the DPA to the contract and make sure the Paris hosting region is recorded there.

Student data is usually light, but not always. Typical use collects answers to polls and quizzes, sometimes without names. The privacy policy itself encourages users to provide only necessary information and notes that participating in an event may not require a name or email [1]. Risk rises with graded quizzes linked to student identities, open-text answers about personal experiences, or SMS answers, which use Twilio in the US and are off by default [1].

Look closely at the AI analysis of open answers. Wooclap states that no personal data is involved in transfers to OpenAI [6]. Open-text answers written by students can still contain names or personal details, so the university should decide whether AI analysis is allowed for sessions that collect free text, and tell lecturers how to use it. The ability to disable AI for the whole organisation is a useful control [6].

US subprocessors are peripheral but present. Core hosting stays in Paris for European customers [2], while support chat, payment and SMS run through US providers with SCCs and TIAs [1]. For most universities these touch staff account data rather than student answers, but they belong in the records of processing.

DPIA likelihood. Ordinary anonymous polling is unlikely to meet the Article 35 threshold of likely high risk [7]. Using Wooclap for graded assessment with identified students, or collecting sensitive opinions, calls for at least a documented screening. Our DPIA screening tool gives a first view.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Wooclap before approving it

  1. Can we review the DPA before signing, and does it fix the Paris (eu-west-3) region for all our data, including backups?
  2. Which subprocessors process data from our users in practice under an institutional licence, and which apply only to self-service accounts or the public website?
  3. When AI analyses open-question answers, exactly what text is sent to OpenAI, and how is personal data in student answers handled?
  4. Can AI features be disabled from our admin dashboard for selected groups rather than for everyone?
  5. How are existing staff self-service accounts brought under our institutional licence, and what happens to their past content?
  6. Can we receive the ISO 27001 certificate, its scope and the latest audit summary?
  7. What retention applies to event data under an institutional contract, as opposed to the three-year inactivity rule for self-service accounts?
  8. Can we see the transfer impact assessments for Intercom and Twilio?

The EU AI Act angle

Wooclap's AI features generate questions and analyse open answers. As general productivity functions they do not match the education uses listed as high-risk in Annex III, which include evaluating learning outcomes and monitoring students during tests [8]. If AI-assisted analysis or AI-generated quizzes were used to grade students, that line would deserve a closer look. Wooclap's AI policy says it would follow the GDPR and the AI Act, and seek user consent, if it ever considered training models on user content [6]. The obligation that applies now is Article 4: deployers must take measures to support the AI literacy of staff using AI systems on their behalf [9]. Emotion recognition in education is prohibited by Article 5(1)(f) [10]; we found no such feature in Wooclap's documentation. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [11].

Sources

  1. Wooclap Privacy Policy (last updated 8 September 2026), retrieved 7 October 2026
  2. Wooclap Trust Center, retrieved 7 October 2026
  3. Security at Wooclap, retrieved 7 October 2026
  4. Data privacy and GDPR, Wooclap, retrieved 7 October 2026
  5. Wooclap Trust Center, legal documents section (Data Processing Agreement available from dpo@wooclap.com), retrieved 7 October 2026
  6. Artificial Intelligence at Wooclap, retrieved 7 October 2026
  7. Regulation (EU) 2016/679 (GDPR), Articles 28 and 35, text read from the Publications Office copy, retrieved 7 October 2026
  8. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
  9. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  10. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  11. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Wooclap's privacy policy, trust centre, security, GDPR and AI policy pages, and the relevant EU legal texts, on 7 October 2026. The data processing agreement itself is provided on request and was not reviewed. Statements about Wooclap come from those pages; our own interpretation is labelled as Validemic's analysis. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it.

This page is not legal advice and does not say whether any particular use of Wooclap complies with the GDPR. If you work for Wooclap and see an error, or a document has been updated, please contact us and we will correct it.

Frequently asked questions

Is Wooclap GDPR compliant?

No tool is GDPR compliant on its own. Wooclap SA is a Belgian company, hosts European customers on AWS in Paris, offers a data processing agreement to universities in which it acts as processor, publishes its subprocessors and has held ISO 27001:2022 certification since 2024. How a university configures and uses it still matters.

Where does Wooclap store data?

Wooclap says its infrastructure runs on Amazon Web Services and that clients choose a hosting region when the contract starts: Paris (eu-west-3) in France or, for American clients, Oregon (us-west-2) in the United States.

Will Wooclap sign a data processing agreement?

Yes, for universities and other organisational customers. Wooclap's GDPR page says a DPA can be signed and attached to the contract, that Wooclap is then a processor and the customer the controller, and that the DPA supersedes the online privacy policy. The DPA is requested from dpo@wooclap.com.

Does Wooclap use AI, and does it train on our data?

Wooclap's AI features help create content and analyse open-question results, using OpenAI as subprocessor with data in Ireland for European hosting. Wooclap says it does not use user content or personal data to train AI models, and organisations can disable AI features for all users.

Does Wooclap support university single sign-on?

Wooclap's security page lists eduGAIN, the GÉANT Data Protection Code of Conduct, SAML, Shibboleth, CAS and Azure AD among supported methods, plus LTI 1.3 for LMS integration with Moodle, Canvas, Blackboard, Brightspace and others.