Privacy

Effective Date: 11-Aug-2025

At Schooligio AI LLC (“we,” “us,” or “our”), we are committed to protecting your privacy, especially for students and educators using our AI-powered educational Platform. This Privacy Policy explains how we collect, use, share, and protect your information. It applies to all users, including students, parents, counselors, and Educational Institutions.

We comply with key laws, including FERPA, COPPA (as amended by FTC in 2025, effective June 23, 2025, with enhanced opt-in consents, data security, and school-agent protocols), GDPR, CCPA/CPRA, SOPIPA and equivalent state student privacy laws (e.g., NY Education Law 2-D, FL student privacy mandates), PPRA, the EU AI Act (for high-risk AI in education, including risk assessments and transparency), and NIST AI Risk Management Framework principles (e.g., mapping and mitigating AI risks like bias). We apply GDPR-like rights globally where feasible.

If you are under 13, your Educational Institution must handle consents. We do not knowingly collect data from under-13 users without school-facilitated verifiable parental consent.

We may update this Policy with 30 days’ notice. Continued use constitutes acceptance.

1. Information We Collect

  • Personal Information: Name, email, age, school affiliation (from you or Educational Institutions).
  • Student Data: Grades, learning goals, progress metrics (for personalization).
  • Usage Data: Interactions, device info, IP address, cookies (essential and analytics; we honor Do Not Track signals).
  • AI-Generated Data: Inputs/outputs for service improvement. We collect via user input, automated tools, or third parties (e.g., schools). We minimize collection to what’s necessary.

2. How We Use Your Information

  • To provide and personalize services (e.g., AI recommendations). Schooligio.ai does not use user data to train it’s models.
  • For improvements, including AI model training (using de-identified, anonymized data only; no identifiable student data for training without opt-in consent).
  • For security, compliance, and analytics.
  • Lawful bases under GDPR: Consent, contract performance, legitimate interests (e.g., bias mitigation per EU AI Act). We do not use data for targeted advertising, profiling, or sales. AI uses align with NIST RMF: We conduct bias audits and ensure human oversight.

3. Sharing Your Information

  • With Educational Institutions or authorized users (e.g., counselors).
  • With vendors for services (under DPAs ensuring compliance; no sales).
  • As required by law or to prevent harm.
  • In de-identified form for research/improvements. No sharing for marketing. For under-13 users, sharing follows COPPA school consents.

4. Data Retention

We retain data only as necessary: e.g., personal data for up to 1 year after account inactivity or contract end; usage data for 2 years max. We delete upon request or purpose fulfillment, with automatic triggers for inactivity.

5. Security Measures

We use industry-standard protections:

  • AES-256 encryption at rest/transit.
  • Access controls, multi-factor authentication.
  • Regular vulnerability scans, penetration testing, and employee training.
  • Incident response plan with breach notifications (e.g., within 72 hours under GDPR/CCPA). No system is infallible, but we commit to robust safeguards.

6. Your Rights

Globally, you can:

  • Access, correct, delete, or port your data.
  • Opt out of automated processing (e.g., AI decisions) or object to uses.
  • Withdraw consent (may limit services). Requests: Email support@schooligio.ai; we respond within 30-45 days (per CCPA/GDPR). For CCPA: No data sales; opt-out not applicable. Parents: Request access/deletion for child data per COPPA/FERPA.

7. Children’s Privacy

We comply with COPPA updates (2025): Schools act as agents for under-13 consents; we require documentation. No direct collection from under-13 without verifiable parental opt-in. Data used only for education; deletions upon request.

8. International Data Transfers

Data may be processed in the US, UAE, or EU. We use Standard Contractual Clauses (SCCs) or equivalent safeguards for transfers. UAE lacks GDPR adequacy, but we mitigate risks.

9. AI-Specific Practices

Per EU AI Act and NIST RMF:

  • High-risk classifications: Transparency in AI operations; users informed of AI use.
  • Bias mitigation: Regular audits of training data; anonymization to prevent harms.
  • AI literacy: We provide resources for users to understand AI risks.

10. Accessibility and Additional Commitments

We align with ADA, Section 504, and WCAG for accessibility. If health data is involved (e.g., mental health notes), we treat it sensitively but note HIPAA may not apply unless integrated.

11. Cookies and Tracking

We use cookies for functionality. Manage via browser; analytics cookies require consent where needed.

12. Contact Us

For questions or complaints: support@schooligio.ai. EU users: Contact our Data Protection Officer or lodge with supervisory authorities.

Thank you for trusting Schooligio.ai.