Privacy Policy

Last Updated:

This Privacy Policy explains how DirectiveAI ("we", "us", or "the Company") collects, uses, retains, and discloses personal information when you use our website, products, and services (collectively, the "Services"). We are committed to processing personal information lawfully, fairly, and transparently, in accordance with the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.

This policy applies to all visitors, registered users, and customers of the Services. It does not apply to third-party websites or services, which are governed by their own privacy practices.

1. Data Controller & Contact

DirectiveAI is the data controller responsible for your personal information under this policy, except where we act as a processor on behalf of a customer under a separate Data Processing Agreement (DPA). You may contact us at any time:

Privacy enquiries: privacy@directiveai.org

Data Protection Officer: dpo@directiveai.org

Postal address: available on request.

You may also lodge a complaint with your local data protection authority. We would, however, appreciate the opportunity to address your concerns directly before you do so.

2. Information We Collect

We collect only the categories of personal information necessary to provide and operate the Services.

2.1 Information you provide directly

Account data: name, email address, and a salted hash of your password when you create an account.

Profile data: organization name, role, and preferences you choose to provide.

Support data: the contents of messages and attachments you send to our support or privacy team.

Billing data: billing address and tax identifiers where required to issue invoices. Card numbers are handled by our payment processor and never stored on our infrastructure.

2.2 Information collected automatically

Usage data: pages visited, features used, timestamps, and approximate location derived from IP address.

Technical data: browser type, operating system, device identifiers, and referral URL.

Cookies and local storage: authentication tokens, preferences, and analytics identifiers (see our Cookie Policy).

Educational content you create when using Edu: your messages to the tutor, the tutor's replies, and any photographs of your work that you upload.

2.3 Information we do not collect

We do not collect sensitive personal data (health, racial or ethnic origin, religious beliefs, biometric data) unless you voluntarily submit it, in which case we process it only with your explicit consent.

We do not sell personal information to third parties, and we do not use it for cross-context behavioral advertising.

3. How We Use Your Information

Each purpose below is tied to a legal basis under the GDPR:

Providing the Services: creating and managing accounts, authenticating sessions, and processing transactions. Basis: performance of a contract.

Service improvement: analyzing usage patterns to fix bugs, improve reliability, and develop new features. Basis: legitimate interests.

Security and fraud prevention: detecting abuse, protecting accounts, and investigating incidents. Basis: legitimate interests and legal obligation.

Communications: transactional messages, security alerts, and, where you have opted in, product updates. Basis: contract, consent, or legitimate interests.

Legal compliance: responding to lawful requests from public authorities. Basis: legal obligation.

We will not use your personal information for a purpose incompatible with those listed above without obtaining your consent or otherwise complying with applicable law.

4. Sharing & Sub-processors

We share personal information only as described below, under written agreements that impose equivalent confidentiality and security obligations:

Sub-processors: third parties that process data on our behalf to deliver the Services (cloud hosting, transactional email, analytics). A current list is available on request from privacy@directiveai.org.

Professional advisors: lawyers and accountants bound by confidentiality, to the extent necessary for their engagement.

Legal requirements: where disclosure is required by law, court order, or to protect the rights, property, or safety of DirectiveAI, our users, or the public.

5. International Data Transfers

DirectiveAI operates globally and personal information may be processed in countries other than your country of residence. Where personal information is transferred outside the European Economic Area, the United Kingdom, or Switzerland, we rely on recognized transfer mechanisms, including Standard Contractual Clauses adopted by the European Commission and supplementary measures where required. A copy is available on request.

6. Data Retention

We retain personal information only as long as necessary for the purposes set out in this policy or as required by law:

Account data: for the duration of your account. When you delete your account, we irreversibly destroy your credentials and remove your name and email address, and you can no longer sign in.

Academic records created within an institution using Edu (conversations with the tutor, submissions, assessments and grades) are retained as that institution's record. The institution is the controller of those records and may be subject to statutory retention periods under education law. We retain them on its behalf and delete them on its instruction.

Usage and technical data: up to 13 months, aggregated where feasible.

Support communications: up to 24 months from last interaction.

Billing records: up to 7 years as required by tax and accounting law.

Security logs: up to 12 months, unless an active investigation requires longer retention.

When retention is no longer required, data is deleted or anonymized. Where a record must survive the deletion of an account, we keep it pseudonymized: your email address is replaced by a keyed hash, so the record is not linked to your identity. Pseudonymized data is still personal data and remains protected by this policy.

7. Edu (educational platform)

Edu is our platform for educational institutions. This section applies in addition to the rest of this policy and prevails over it where they differ.

Who is responsible for your data. When a university or school provides Edu to its students and teachers, that institution is the controller of the personal data processed within it, and DirectiveAI acts as its processor under a written agreement. We process that data only on the institution's documented instructions. Questions about your data are answered first by your institution.

How you get access. Edu accounts are created by invitation from your institution. There is no public sign-up and no purchase inside the applications.

What we process. Your name and institutional email address; your enrolment in courses; your conversations with the tutor and any photographs of your work you upload; and activity metadata such as when you access the platform and how many messages you send.

The tutor. Your messages are sent to a third-party model provider that processes them to generate a reply. We do not authorize that provider to use your content for any other purpose. Do not share personal information you would not want processed this way.

Analytics for teachers. Your teacher sees aggregate measures of the course. Individual measures, such as participation or a suggested grade, are visible only to the teacher of your course and to your institution's administrators, and every consultation of individual data is logged. Where a group is too small for aggregate figures to protect individuals, those figures are suppressed rather than shown.

Deleting your account. You can delete your account from the application at any time, without anyone's approval. We irreversibly destroy your credentials and remove your name and email, and you can no longer sign in. Your academic record is retained as your institution's record, pseudonymized as described in section 6. If your institution invites you again, you can regain access to that record.

8. Security

We implement technical and organizational measures appropriate to the risk of processing, including encryption of data in transit using TLS 1.2 or higher, encryption of data at rest, strict access controls based on least-privilege principles, regular security reviews, and documented incident-response procedures.

No system can be guaranteed completely secure. In the event of a personal data breach affecting your rights or freedoms, we will notify the competent supervisory authority and affected individuals without undue delay, in accordance with Article 34 of the GDPR.

9. Your Privacy Rights

Depending on your jurisdiction, you may exercise the following rights. To do so, contact privacy@directiveai.org. We will respond within one month, extendable by two further months where requests are complex.

Access: receive a copy of the personal information we hold about you.

Rectification: correct inaccurate or incomplete information.

Erasure: request deletion, subject to legal retention obligations.

Restriction: request that we limit processing in certain circumstances.

Portability: receive your data in a structured, machine-readable format.

Objection: object to processing based on legitimate interests or for direct marketing.

Withdraw consent: withdraw consent at any time where processing relies on it, without affecting prior lawfulness.

Residents of California may exercise rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share personal information as defined by the CCPA. To submit a verifiable consumer request, email privacy@directiveai.org.

10. Children's Privacy

The Services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If you believe we have collected information from a child in violation of applicable law, contact privacy@directiveai.org and we will take steps to delete that information.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Updated" date above indicates when the policy was last revised.

Material changes will be notified by email to registered users and by a prominent notice on the website at least 30 days before they take effect.

Non-material changes (clarifications or administrative updates) take effect upon publication.

Archived versions are available on request.

12. Definitions

Personal information: any information relating to an identified or identifiable natural person.

Controller: the entity that determines the purposes and means of processing.

Processor: an entity that processes personal data on behalf of the controller.

Services: the DirectiveAI website, products, and services covered by this policy.

Contact

Questions about your data? Email privacy@directiveai.org and our privacy team will respond within one month.

This document is provided for informational purposes and does not constitute legal advice.