Skip to main content

AILearn360 Privacy Policy

Version 2.8
Effective: April 14, 2026Last Updated: April 14, 2026

Introduction

AILearn360 respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our learning platform.

Note: This policy covers general platform usage. AI-specific data processing requires separate consent and is covered in the AI Privacy Policy.

Information We Collect

Account Information

  • Name, email address, username
  • Email address, phone number (if provided)
  • Password (hashed), passkey authentication settings
  • Profile language preferences, timezone

Documents and Content

  • PDFs, text files, and other study materials you upload
  • Quizzes, summaries, and notes created from your documents
  • Quiz scores, study session history, progress tracking
  • Notes, annotations, custom quiz questions

Usage and Technical Data

  • Features used, time spent, interaction patterns
  • Browser type, operating system, device identifiers
  • IP address, session data, error logs
  • Aggregated usage statistics, performance metrics

Security and Compliance Data

  • Login attempts, account access history
  • Failed authentication attempts, suspicious activities
  • Account changes, privacy setting modifications
  • Consent records, data processing activities

Antivirus Scanning Data

Purpose: Protect you and other users from malicious files

Legal Basis: Legitimate interest (security and protection of service)

Retention: Scan logs are retained temporarily for monitoring; infected files are quarantined for up to 30 days and deleted after 30 days

Device Tracking Data

  • Browser type, OS, screen resolution, timezone
  • Used for fraud detection and abuse prevention
  • Tracked per device/IP to prevent abuse and enforce limits on how many accounts can be created from the same device or location within a rolling time window
  • Registered devices (max 3 per account)
  • Hardware concurrency, language, platform info

Purpose: Prevent account creation abuse, detect suspicious activity, manage device limits

Legal Basis: Legitimate interest (security, fraud prevention)

Retention: While account is active + 90 days after account deletion

Consent-based analytics

On our website, when you accept analytics cookies, we use Google Tag Manager to load Google Analytics 4 and measure feature usage, login and subscription conversion flows, and site performance.

Legal basis: consent under GDPR and ePrivacy rules. Analytics tags are not loaded before consent.

Controls: you can change or withdraw consent at any time from the cookie banner. Essential cookies continue to work even if analytics consent is refused.

Provider and scope: Google may process analytics data on our behalf to provide measurement and reporting. This setup is limited to the website and does not change server-side processing.

How We Use Your Information

  • Create and manage your account
  • Provide core platform features
  • Process and store your uploaded documents
  • Generate study materials and track progress
  • Provide customer support
  • Process payments and manage subscriptions

    File Processing

    • Extract text content for AI analysis and quiz generation
    • Convert DOCX files to PDF format for security
    • Detect and count pages for optimization and UI
    • Identify tables, forms, and structured data
    • Generate thumbnails and previews
    • Scan for malware
    • Chunk large files to avoid memory issues

    Legal Basis: Legitimate Interest - Article 6(1)(f) GDPR

    File Formats: PDF, DOCX (max 50MB per file)

    Data Sharing and Disclosure

    Payment Processing

    Provider: Stripe

    Purpose: Credit card processing, subscription management

    Data Shared: Billing information, transaction data

    Infrastructure

    Provider: Cloudflare

    Purpose: CDN, DDoS protection, security

    Data Shared: Technical data, IP addresses

    Data Security

    • Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
    • Access Controls: Role-based access, multi-factor authentication
    • Network Security: Firewalls, intrusion detection
    • Secure Development: Security testing and code reviews

    • Staff Training: Regular privacy and security training
    • Data Minimization: Collect only necessary data
    • Access Logging: All data access is logged and monitored
    • Incident Response: Procedures for data breaches and security incidents

    Personal Data Breach Notification

    AiLearn360 implements a Personal Data Breach Notification procedure in compliance with GDPR Articles 33 and 34.

    What is a Personal Data Breach

    A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

    Notification to the Supervisory Authority (GDPR Art. 33)

    72 hours: Within 72 hours of becoming aware of a personal data breach, AiLearn360 will notify the competent supervisory authority (Garante per la Protezione dei Dati Personali for Italy, or the lead authority in case of cross-border processing) unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

    The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach and mitigate its possible adverse effects, and the contact details of our Data Protection Officer.

    Where notification is not made within 72 hours, it will be accompanied by an explanation of the reasons for the delay and may be provided in phases.

    Communication to Data Subjects (GDPR Art. 34)

    Without undue delay: Without undue delay

    When a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, AiLearn360 will communicate the breach to the affected data subjects without undue delay. The communication will describe the nature of the breach and contain the information required by GDPR Art. 33(3).

    Communication to data subjects is not required if: (a) appropriate technical and organisational protection measures were applied to the affected data (e.g., encryption); (b) subsequent measures have been taken that eliminate the high risk; or (c) it would involve disproportionate effort, in which case a public communication or equivalent measure will be used.

    Our Internal Breach Response Process

    1. 1.Detection and containment (target: within 4 hours of detection)
    2. 2.Risk assessment and classification (target: within 24 hours)
    3. 3.Notification to supervisory authority if required (target: within 72 hours)
    4. 4.Communication to affected users if required (target: without undue delay)
    5. 5.Post-incident review and remediation plan (target: within 30 days)

    To report a suspected personal data breach, contact our Data Protection Officer immediately at [email protected].

    Data Retention

    • Active Accounts: Data retained while account is active
    • Inactive Accounts: Data deleted after 3 years of inactivity
    • Deleted Accounts: Data deleted within 90 days of account deletion
    • Backup Data: Removed from backups within 12 months

    Security and Compliance Data

    • Access Logs: Retained for 90 days
    • Security Incidents: Retained for 2 years for compliance
    • Consent Records: Retained for 3 years after withdrawal
    • Audit Trails: Retained for required legal compliance periods

    Your Rights

    Right to Access

      Right to Rectification

      • Correct inaccurate data
      • Complete incomplete data
      • Update your account information

      Right to Erasure

      • Data is no longer necessary
      • You withdraw consent (for consent-based processing)
      • Data has been unlawfully processed
      • Deletion is required by law

      Right to Data Portability

      • Export your data in a structured, machine-readable format
      • Transfer data to another provider
      • Use our data export tools in account settings

      Data Export Details:

      • Profile, preferences, subscription details
      • All generated content
      • Quiz history and results
      • Reading progress and analytics
      • AI chat conversation history
      • Consent records
      • Activity logs

      Export Format: JSON

      Processing Time: Usually instant, up to 24 hours for large accounts

      Right to Object

      • Processing based on legitimate interests
      • Direct marketing communications
      • Automated decision-making

      Right to Restrict Processing

      • You dispute data accuracy
      • Processing is unlawful but you don't want deletion
      • We no longer need the data but you need it for legal claims

      How to Exercise Your Rights

      • Contact: [email protected]
      • Response Time: We respond within 30 days (or 90 days for complex requests).

      Requirements:

      • Clear identification of yourself
      • Specific request and legal basis
      • Relevant account information

      International Data Transfers

      EU Data Residency

      • Primary Storage: European Union (Italy)
      • Backup Locations: EU member states only
      • Processing Location: EU unless explicitly disclosed

      Third Party Transfers

      • Adequacy Decisions: Transfers to countries with adequate protection
      • Standard Clauses: EU-approved SCCs for other transfers
      • Binding Rules: Used by some multinational providers
      • Consent: We may rely on your consent if other safeguards are unavailable

      US Transfers

      • Data Privacy Framework: If provider is certified
      • Standard Contractual Clauses: With additional safeguards
      • Encryption: All data encrypted in transit and at rest

      Children's Privacy

      • Minimum Age: 18 years old
      • Age Verification: Users must confirm they are 18 or older at signup

      • Account Suspension: Accounts of underage users are suspended immediately
      • Data Deletion: All data deleted within 30 days
      • Parent Contact: We will attempt to contact parent/guardian if possible

      Contact Information and Complaints

      Privacy Contact

      Supervisory Authority

      You may also contact your local data protection authority.

      Dispute Resolution

      • Internal Process: Contact our privacy team first
      • Mediation: Available through EU dispute resolution mechanisms
      • Legal Action: Your rights under applicable law are preserved

      Automated Decision Making

      • Fraud Detection: Risk scoring for suspicious activities
      • Performance Optimization: System resource allocation

      • We do not engage in automated profiling of individuals
      • We do not make automated decisions affecting your legal rights
      • We do not engage in discriminatory automated processing

      Human Review: Significant automated decisions are subject to human review, and you may request human review.

      Data Protection Impact Assessment (DPIA)

      Under Art. 35 GDPR, a Data Protection Impact Assessment is required only when processing is "likely to result in a high risk to the rights and freedoms of natural persons". AiLearn360 has formally assessed its processing activities and determined that none of the EDPB high-risk criteria (WP248) or the categories listed by the Italian Garante (Deliberazione 467/2018) are triggered.

      Our assessment (documented at docs/DPIA-NOT-APPLICABLE.md) concludes that no DPIA is required. The reasons are:

      • No special categories of data under Art. 9 GDPR are processed.
      • No profiling or automated decision-making with legal or significant effects (Art. 22 GDPR).
      • No large-scale processing (AiLearn360 is a micro-enterprise under EU definition).
      • No vulnerable data subjects (the service is gated by an 18+ age check).
      • No high-risk AI system under EU AI Act Annex III is deployed (all 11 use cases are classified Limited Risk).

      This assessment will be re-evaluated annually or earlier if any of the trigger events defined in the DPIA-not-applicable document occurs.

      For questions about this assessment, contact our Data Protection Officer at [email protected].

      Marketing and Communications

      Transactional Communications

      • Account notifications and security alerts
      • Billing and subscription updates
      • Service announcements and maintenance notices
      • Legal and compliance communications

      Cookies and Tracking

      We only use essential cookies that do not require consent. We do not use analytics/marketing cookies without consent.

      Reference: See Cookie Policy

      Changes to This Policy

      Policy Updates

      • Changes in our data processing practices
      • New legal requirements
      • Service improvements and new features
      • User feedback and best practices

      Notification Process

      • Material Changes: 30 days advance notice via email
      • Minor Updates: Notice in your account dashboard
      • Immediate Changes: Possible for urgent legal or security reasons

      Continued Use: Continued use of the service after changes means you accept the updated policy. You may delete your account if you disagree.

      Contact Information

      Privacy Contact

      Supervisory Authority

      You may also contact your local data protection authority.

      Dispute Resolution

      • Internal Process: Contact our privacy team first
      • Mediation: Available through EU dispute resolution mechanisms
      • Legal Action: Your rights under applicable law are preserved

      Document Format and Accessibility

      These legal documents (Privacy Policy, AI Privacy Policy, Terms of Service, Cookies Policy) are published exclusively in HTML format.

      HTML ensures full compliance with the European Accessibility Act (Directive 2019/882) and WCAG 2.1 AA: assistive technologies can navigate semantic HTML, screen readers work natively, and content is fully indexable by search engines and AI agents. PDFs are not used because they frequently fail accessibility audits and cannot be updated in real time.

      PDF on request: If you require a signed PDF copy for contractual, archival, or compliance purposes, contact our Data Protection Officer at [email protected]. We provide PDFs on legitimate request within 30 days.

      Each legal document carries a clearly visible version number and last-updated date on its page. The version history is preserved in our internal legal repository.

      Document Information

      Document ID: PP-EN-2.4

      Classification: Public Legal Document

      Last Legal Review: October 16, 2025

      Next Review Date: November 17, 2026

      Language Note: This document is available in multiple languages. In case of conflicts, the English version prevails.