This Privacy Policy has been prepared by Ayasis Yazılım ve Bilişim Teknolojileri Anonim Şirketi ("Company," "We," "Us," "Our"), located in Çifte Havuzlar Mahallesi Eski Londra Asfaltı Cad. Kuluçka Mrk. D2 Blok Apt. No: 151 /1f/1b06 Esenler/Istanbul, in its capacity as the “Data Controller” with respect to the FeduAI application (“Fedu.AI”), operated by the Company through the website www.fedu.ai. This Policy applies to all individuals (“User/Users”) who use the FeduAI application (“Services”) and has been created to ensure the protection of privacy regarding any data that may be obtained during the use of the application by the Users.
Article 1 – Company's Policies About Student Data
The following promises represent Company's approach to Student Data where appropriate. To the extent that Company handles Student Data on behalf of a Client, our Student Data practices are regulated by our agreements with the Client and our applicable student-facing notifications and rules. Company do not:
- (i) Sell the personal information of students
- (ii) Distribute student information for commercial or non-educational uses.
- (iii) Utilize student data for sales, behavioral advertising, or targeted advertising.
- (iv) Never profile pupils for advertising or business decision-making purposes, unless it is absolutely required to deliver an educational service that a school or instructor has requested.
- (v) Train, optimize, or enhance machine learning or artificial intelligence models including big language models—using student data, or allow any outside AI provider to do so.
- (vi) Use "dark-pattern," manipulative, or dishonest design techniques that compromise students' autonomy or well-being or that incite them to provide more personal information than is required.
- (vii) Unless mandated for a particular educational purpose and authorized by law, do not gather or handle students' precise geolocation data, biometric data, or other sensitive personal information.
- (viii) Company avoids practices that are reasonably likely to cause children to suffer material harm, such as harm relating to their physical, emotional, developmental, or privacy.
The conditions of this Privacy Policy governing personal information handled by Company as a controller remain unchanged, and these promises solely apply to Student Data processed by Company as a service provider or processor on behalf of Schools or other Clients.
Article 2 – Personal Information the Company Collect
Your direct submission of information, information automatically gathered from your usage of the Service, and information obtained via third-party integrations or service providers in the course of delivering the Service are all possible sources of personal information.
Information about you. Educators utilizing our "free" and "plus" subscriptions, school representatives, and website visitors using the Service may provide us with the following personal information, depending on the context in which you communicate with us: (i) contact data (such as name-surname, e-mail adress, phone number, title and company name), (ii) profile data (such as the username that you may set to establish an online account on the Service, profession, school name, grade level(s) served, , classes taught, interests, preferences, information about your participation in our contests, promotions, or surveys, and any other information that you add to your account profile), (iii) communications data derived from our interactions with you, such as when you get in touch with us via the Service, chat tools ), social media, or another method, (iv) commercial data (such as order numbers and transaction histories, that are relevant to or required to finish your subscriptions on or through the Service), (v) marketing data, (including information about how you interact with our marketing messages and your preferences for receiving them), (vi) inputs, prompts, and user-generated content data (including comments, questions, messages, works of ownership, information you generate, transmit, or otherwise make available on the Service, information you upload or use as an input or request, presentations you make and other academic content you generate, and related metadata), (v) other data (audio recordings, performance data, reading/speaking/comprehension skills resulting from your use of the FeduAI application accessed through the website FeduAI, account information transmitted when logging in via Google, Microsoft or other integrations, the date and time of access to FeduAI, the pages visited during your use, device information (device type, operating system, browser type, etc.), as well as any other data you transmit via FeduAI or generated as a result of its use, are processed) (vi) payment data, (vii) inferred or derived data from the categories stated in this section, as well as other data not specifically included here, shall be used in accordance with this Privacy Policy or as otherwise disclosed at the time of collection.
Please refrain from giving us any sensitive personal information on or through the Service or otherwise, including social security numbers, bank account numbers, government identification numbers, information about racial or ethnic origin, political views, religious or other beliefs, health, biological, biometric, or genetic information, criminal background information, or similar information.
Information about you, your computer or mobile device, and your interactions with the Service, our emails, and our websites may be automatically logged by us and our service providers:
Device information includes the type and version of operating system, manufacturer, model, browser, screen resolution, RAM, disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique identifiers used for security, fraud prevention, and service operation, language settings, mobile device carrier, radio/network information (), and general location information (city, state, or geographic area).Data about your online activities, including the pages or screens you have viewed, the amount of time you have spent on them, the website you visited prior to using the Service, the pages or screens you have navigated between, the information about your activities on a page or screen, the times and duration of your access, and whether you acted on links in our emails or opened our emails..
Article 3 – How We Use and Collect Personal Data
We may use your personal information to: provide the Services, create a membership, verify member information, carry out membership procedures, customize and improve your user experience during access, offer personalized content and services, tailor FeduAI to your preferences and needs, monitor student member progress and contribute to their learning process, enable security features of the Service, communicate with you about the Service, including by sending Service-related announcements, updates, security alerts, and support and administrative messages, establish and maintain your user profile on the Service, facilitate the use of the FeduAI application, carry out necessary transactions for payment if the services are subject to a fee, provide support for the Service, and respond to your requests, questions and feedback, personalize your experience with the Service and our Service-related communications, provide newsletters and surveys, remember your selections and preferences as you navigate webpages, understand your needs and interests, inform you on updates or special offers related to the services, ensure the security of the services, to detect fraudulent activities and enforce the User Agreement, to improve the services, ensure that proper consents are obtain from parents/legal guardians if the user is under 18 years, evaluate your communication request and contact you accordingly, transmit your inputs to our Third-Party AI Providers for processing and to receive outputs, as necessary to fulfill your requests, follow up on your requests and complaints, fulfill our legal obligations arising from consumer protection legislation, e-commerce legislation, commercial electronic message regulations and other applicable laws, enforce the terms and conditions that govern the Service; audit our internal procedures for adherence to legal and contractual obligations or our internal policies; and protect our, your, or others' rights, privacy, safety, or property (including by filing and defending legal claims), prevent, detect, look into, and discourage harmful, fraudulent, unlawful, unethical, or unauthorized activities, such as identity theft and cybercrime, comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, investigations or requests from government authorities, respond to questions and requests submitted via the contact form, inform the User on service upgrades and special offers, comply with applicable laws and regulations, respond to legal requests, court orders, and legal proceedings, and in the case of Users under the age of 18, to ensure that the necessary consents are obtained from parents or legal guardians fulfill our obligations in the event of requests or notifications by authorized institutions or organizations, store your personal data in accordance with legal retention periods, and conduct the Company's archiving and data retention activities.
Your personal information and the personal information of other people whose information we collect may be combined, de-identified, and/or anonymized. By eliminating information that identifies you, we transform personal data into de-identified and/or anonymized data. We may share this aggregated, de-identified, and/or anonymized data with third parties for legitimate business objectives, such as promoting our company and analyzing and improving the Service. De-identified children's data is never shared for advertising or other unrelated commercial purposes, and we never try to re-identify it.
During your visit to and use of FeduAI, certain personal data—such as information on the browser you use, your IP address, your internet connection, your interactions with the site, and similar data—are collected through small text files (Cookies) sent to your hard drive by the website server. These personal data are processed for the purposes of enabling access to our website and benefiting from its features, carrying information between pages on our site, eliminating the need to re-enter information, and—where you provide consent—collecting information on how you use our site in order to improve its performance, remembering your preferences on our site to provide you with convenience, and customizing our website and advertisements according to your interests and preferences. For more detailed information, you can review the Clarification Text on Cookies.
The data collected by the Company through FeduAI may, with the User's explicit consent, be shared with the User's teacher using FeduAI, other Users via the FeduAI leaderboard, and third parties via social media within the scope of disclosing quiz results or similar events. Additionally, the data may be transferred to service providers such as cloud (server) and technical support companies and to authorized public institutions and organizations.
The data collected by the Company through FeduAI is processed based on various legal grounds depending on the nature of the data, including: the requirement for the performance or execution of a contract between the User and the Company for the provision of services via FeduAI; the requirement of processing for the establishment, exercise, or protection of a legal right; the requirement of processing for the Company's legitimate interests, provided that it does not harm the fundamental rights and freedoms of the data subject; and the User's explicit consent.
The Company, or the relevant institutions, has taken appropriate technical and administrative measures within the scope of technological capabilities and cost factors to ensure the security of the information provided to the Company by Users, the information obtained by the Company, and all transactions carried out through FeduAI, in accordance with the nature of such information and transactions. However, despite the Company taking the necessary information security measures, the Company shall not be held liable if confidential information is unlawfully accessed by third parties as a result of attacks on the system.
Personal data related to credit or debit cards entered for the purpose of purchasing Premium Services or updating information on FeduAI is processed independently between the User and the relevant bank or card issuer, without any involvement of the Company. Information such as credit card PINs is not visible to the Company or to any other Users of FeduAI.
To ensure maximum security, credit card details requested on the payment page are not stored on FeduAI or on the servers of any third-party service providers. All payment transactions are carried out directly between the User's device, the relevant bank, and the payment infrastructure provider, without passing through or being recorded by FeduAI.
Article 4 – How We Share Your Personal Data
We may disclose your personal information to the following parties, as well as in any other situations outlined in this Privacy Policy, in other relevant notices, or at the time your information is collected:
- (i) Third parties (such as hosting, information technology, client support, online chat functionality providers, email delivery, marketing, and website analytics) that offer services on our behalf or assist us in running the service or our business.
- (ii) We may share your personal information with third parties when you have given us instructions or given us permission to do so.
- (iii) We might give your personal information to a third-party service if you use it to log into the Service or otherwise connect your Service account to a social media platform or other service. The third party's privacy policy and the settings linked to your third-party service account will control how the third party uses the shared information.
- (iv) Expert consultants, including attorneys, auditors, bankers, and insurers, when needed in the course of their professional services to us.
- (v) Law enforcement, public officials, and private individuals, as we sincerely believe to be required or suitable.
Your personal data may be transferred to (i) comply with requests from authorized institutions or fulfill notification obligations to such institutions, (iii) in case the member is a student, monitor their development within FeduAI. Accordingly, your data may be shared with (a) teacher Users in the case of student Users, (b) other Student Users through the FeduAI leaderboard, and (c) service providers from whom the Company receives support and authorized public institutions and organizations.
The data shared by the User will not be used, under any circumstances, for the benefit of any third party, whether directly or indirectly; nor will it be shared, copied, or published, in whole or in part, with any third party, company, or institution, except as explicitly stated in this Privacy Policy.
Article 5 – Your Options and Rights
We outline the options and rights accessible to all users in this area. Further details regarding the rights of users in Europe are provided below.
- (i) You can review and change specific account information by logging into your account if you created one with us through the Service.
- (ii) By getting in touch with us, you can choose not to receive marketing-related emails. Please be aware that you can still receive service-related and other non-marketing emails even if you decide to unsubscribe from marketing-related emails.
- (iii) For information about cookies employed by the Service and how to control them, see our Clarification Text on Cookies
- (iv) You may set up your device to stop images from loading on the majority of browsers and devices. Follow the directions in your specific browser or device settings to accomplish this.
- (v) To deliver some services, we must gather personal data. We might not be able to offer certain services if you fail to supply the data we designate as necessary or mandatory.
- (vi) You might be able to restrict the information we collect from your social media account or other third-party platform by using the settings in your account with that platform if you decide to connect to the Service through it. Information that we have already acquired from a third party will not be affected if you decide to deny us access to information from that platform.
- (vii) Using your account, you have the option to remove certain content. Please get in touch with us if you would want to request that your account be closed.
Article 6 – Other Provision
Student Data. User may get extra or supplemental privacy policies from Company for particular goods or services that we provide at the time we gather personal data. For instance, the information We gather from students is not covered by our Privacy Policy. To learn more about how we gather and handle students' personal information, please refer to Our Policy Regarding the Company's Practices Concerning Children's Online Privacy.
Information that we process as a service provider on behalf of educational institutions, school districts, government agencies, and our commercial clients (like learning or tutoring centers) ("Client") when we offer them the FeduAI is exempt from this privacy statement. Furthermore, the Family Educational Rights and Privacy Act ("FERPA") may apply to some personal information processed on behalf of our customers. This means that we will only use personal information that is deemed to be "personally identifiable information" kept as part of "education records" (as defined by FERPA) for legitimate educational purposes, such as offering our clients the service.
According to FERPA, Company does not unilaterally reveal student data as "directory information." The relevant school or educational agency determines and oversees any designation or disclosure of "directory information" under FERPA in compliance with its own policies, notices, and opt-out procedures. Company only follows the guidelines and any applicable agreements provided by the school when processing student data on its behalf. Our agreements with Client govern how we utilize the information we handle on their behalf. Additionally, our Clients may have privacy rules that regulate how their users' personal information is acquired when using our Service.
These Privacy Policy will specify any rights their Users may have to such personal information (including any rights under FERPA) and regulate how each Client handles personal information. Please get in touch with the relevant client if you have concerns about personal data that Company handles on their behalf or if you would like to exercise your rights about that data.
Storage. We keep personal data in order to achieve the goals for which it was gathered, such as meeting any reporting, accounting, or legal obligations, establishing or defending legal claims, or preventing fraud. The amount, nature, and sensitivity of the personal information, the possible risk of harm from unauthorized use or disclosure of your personal information, the reasons we process your personal information and whether we can accomplish those purposes in another way, and the relevant legal requirements are some of the factors we may take into account when determining the proper retention period for personal information.
Other sites and services. Links to third-party websites, mobile apps, and other online services may be included in the service. Furthermore, our content might be included into websites or other online services that aren't connected to us. We do not promote or imply any affiliation with any third party through these connections and integrations. Third-party websites, mobile applications, and online services are not within our control, and we bear no liability for their deeds. We advise you to review the privacy statements of the other websites, apps, and online services you utilize.
Controls for Display and Account Visibility. The services offered by Company are made to prevent the public disclosure of private information. Certain account details (name, school, role, and profile photo, if supplied) may be accessible to other authorized users within the same school or organization (e.g., managers or other educators) as required to run the service, depending on the service feature and account type. You can modify your profile details and specific visibility settings by signing into your account if display controls are available in your account settings. In the event that a school or other client provisioned or managed your account, they may have control over what information is shared within their environment.
Considerations for Disparate Impact, Bias, and Fairness. Company acknowledges that AI-enabled features may have disparate or unexpected effects and may function differently in different people and groups. We take reasonable measures to assess and lower the danger of unjust outcomes, in line with the educational context of our services. These actions could involve testing, keeping an eye on, and choosing models or setups intended to support dependability, safety, and appropriateness in education.
Company doesn't use profiling or automated decision-making that has legal or comparable consequences. Reviewing outcomes and using professional judgment when implementing them in educational contexts are still the responsibilities of educators and schools. Important points to remember:
Company does not train machine learning or artificial intelligence models using personal data. (i) Company-engaged artificial intelligence service providers are contractually forbidden from using any data processed on Company's behalf for the purpose of training, developing, or enhancing their own models; instead, they function only as service providers. (ii) Unless the applicable law requires a longer retention period, data transmitted through artificial intelligence APIs is erased after thirty (30) or 60 days and kept for a limited time only for purposes including security, compliance, and monitoring of abuse and misuse.
Additional Information for California Residents. If you live in California, we are required by law to give you further details about how we gather, use, and disclose your "personal information" as that term is defined in the California Consumer Privacy Act ("CCPA"). How We Source, Use, and Disclose Information for Business Purposes. The following graphic outlines the types of personal data we gather, where it comes from, and how we utilize and distribute it for commercial objectives.
- (i) Categories of Personal Information Collected: Contact information (e.g., name, email address, organization, role, phone number, mailing address including state/province, country)
Sources of Personal Information: You, through your use of the Service
Reasons for Using Personal Data (for further details, read "How We Use the Data We Collect"): Deliver the requested services and client support, talk to you, examine use and customize the services, enhance the offerings, for debugging, security, and fraud prevention, observe the law's requirements
Shares of Personal Data for Business Objectives: Services suppliers, when a legitimate request is made, policy enforcement, in the case of a business transaction with entities, with your permission - (ii) Categories of Personal Information Collected: Financial and transactional data (such as and payment account details)
Sources of Personal Information: You
Reasons for Using Personal Data (for further details, read "How We Use the Data We Collect"): Fees for processing services, converse to you, observe the law's requirements
Shares of Personal Data for Business Objectives: Processors of payments, when a legitimate request is made, policy enforcement, in the case of a business transaction, with entities, with your permission - (iii) Categories of Personal Information Collected: Login information (e.g., account name/username)
Sources of Personal Information: You, using your device
Reasons for Using Personal Data (for further details, read "How We Use the Data We Collect"): Deliver the services and client support, examine use and customize the services, enhance the offerings, for diagnostics, security, and fraud prevention, observe the law's requirements
Shares of Personal Data for Business Objectives: Service suppliers, when a legitimate request is made, police enforcement, in the case of a business transaction with entities, with your permission - (iv) Categories of Personal Information Collected: Information about the device and the internet (such as the IP address, operating system, browser type, and the geographical location deduced from the IP address, among other similar details)
Sources of Personal Information: You, through your use of the Service
Reasons for Using Personal Data (for further details, read "How We Use the Data We Collect"): Deliver the requested services and client support, talk communicate with you, examine use and customize the services, enhance the offerings, for debugging, security, and fraud prevention, observe the law's requirements
Shares of Personal Data for Business Objectives: Service suppliers, when a legitimate request is made, police enforcement, in the case of a business transaction with entities, with your permission. - (v) Categories of Personal Information Collected: Information on how you use the services, such as when and how you use them, and what material you engage with on them
Sources of Personal Information: You, through your use of the Service
Reasons for Using Personal Data (for further details, read "How We Use the Data We Collect"): Deliver the services and client support, examine use and customize the services, enhance the offerings, for debugging, security and fraud prevention, observe the law's requirements.
Shares of Personal Data for Business Objectives: Service suppliers, when a legitimate request is made, police enforcement, in the case of a business transaction with entities, with your permission.
Please be aware that the student data we process is not depicted in the above graphic. Please refer to our Student Data Policy for further details on our privacy policies regarding student data. In summary, under a student data privacy agreement, student data is processed exclusively on behalf of particular educational institutions. You should get in touch with the educational institution directly if you have concerns about its privacy policies.
The CCPA gives you the right to obtain specific details about your personal information if you live in California. In particular, the CCPA permits you to ask us to:
- Inform you about the categories of personal information we collect or disclose about you; the categories of sources of such information; the business or commercial purpose for collecting your personal information; and the categories of third parties with whom we share/disclose personal information.
- Provide access to and/or a copy of certain personal information we hold about you.
- Delete certain personal information we have about you.
- Provide you with information about the financial incentives that we offer to you, if any.
Additionally, the CCPA guarantees you the ability to exercise your rights without facing discrimination (as defined by current legislation). Please be aware that California law may exempt some information from such inquiries. For instance, in order to offer you our services, we require specific information. Before answering a request, we shall also take appropriate measures to confirm your identification. In order to match at least two validation points with the data we have on file about you, we might ask you for validation information. We have the right, but not the responsibility, to ask you for more information if we are unable to validate you using this approach.
Additionally, if Company has gathered your personal information as a result of a Client's (as previously mentioned) usage of our services, Company does so in accordance with the relevant Customer's instructions. In order to speed up the processing of your request, please direct your question to the appropriate customer if any of these situations apply to you and you would want to view or remove any personal data we have gathered on you. Nevertheless, as required by the relevant regulations and when appropriate, we offer our customers reasonable assistance in implementing their choices. Please email us at info@fedu.ai if you are an authorized agent submitting a request on behalf of a California consumer, or if you would want more information about your legal rights under California law or would like to exercise any of them. If a business "sells" personal data, as defined by the CCPA, it is entitled to certain protections. Company doesn't take part in any activities that the CCPA would classify as "sales" of personal data.
Under the "Shine the Light" law in California, residents have the right, in specific situations, to ask us for information about how we share specific types of personal data (as defined by the law) with outside parties for their direct marketing needs. Your personal data is never given to outside parties for their own direct marketing campaigns. Company does not respond to Do Not Track ("DNT") signals from web browsers because it does not follow users over time or across third-party websites. Furthermore, we do not yet respond to these signals because there is currently no industry standard about what a service should do, if anything, when it receives them.
Other US State Laws. The United States' data protection laws are constantly changing, and several states have passed comprehensive privacy laws as well as student data privacy regulations tailored to education. Depending on the situation, these rules might be applicable to Company's use of personal data.
Apart from California, Company also complies with relevant criteria under other state privacy and student data protection legislation in the United States, such as but not limited to:
- Colorado (Colorado Privacy Act)
- Connecticut (Connecticut Data Privacy Act)
- Delaware (Delaware Personal Data Privacy Act)
- Florida (Florida Digital Bill of Rights)
- Iowa (Iowa Consumer Data Protection Act)
- Indiana (Indiana Consumer Data Protection Act)
- Montana (Montana Consumer Data Protection Act)
- Oregon (Oregon Consumer Privacy Act)
- Texas (Texas Data Privacy and Security Act)
- Utah (Utah Consumer Privacy Act)
- Virginia (Virginia Consumer Data Protection Act)
- New York (Education Law §2-d, where Company processes Student Data on behalf of New York educational institutions)
You might have specific rights to your personal information, depending on the law in effect and where you live. These rights could include the following:
- seek access to personal data; request that inaccurate personal data be corrected;
- request that personal data be deleted;
- request a copy of specific personal data where mandated by law; and, if appropriate,
- choose not to participate in specific processing operations, such as individualized marketing or profiling.
Countries differ in the extent and availability of these rights, which may also be influenced by Company's function as a controller or as a processor or service provider working on behalf of a school or other customer. Requests for privacy rights pertaining to personal information, including student data, that Company processes on behalf of a school or other customer may need to be sent to the relevant school or customer in compliance with the relevant laws.
Company complies with relevant state privacy and student data protection legislation while responding to requests for valid privacy rights. For further information or to submit a request, please email info@fedu.ai. As needed or allowed by law, we may take reasonable measures to confirm your identity and the legitimacy of the request.
Notification for Users in the UK and Europe. Where users in the UK and Europe are affected by this notice. Only those in the European Economic Area (also known as "Europe," as stated at the top of this Privacy Policy) and the United Kingdom ("UK") are covered by the information in this "Notice to European and UK users" section.
In this Privacy Policy, references to "personal information" shall be interpreted as referring to "personal data" (as defined by the GDPR), which is information about individuals from which they can be identified or directly identifiable. With regard to the processing of your personal data covered by this Privacy Policy for the purposes of European data protection laws (such as the EU GDPR and the "UK GDPR" (as and where applicable, the "GDPR"), Company is the controller.
When Company handles personal data on behalf of its clients—which include educational institutions, school districts, and other schools—who are the data controllers, Company is acting as a data processor. Under these conditions, Company only handles personal data in accordance with the written directives of the relevant educational establishment, and this processing is controlled by an agreement for the processing of data or comparable contractual provisions.
EU-US + UK Extension Data Privacy Framework. According to the U.S. Department of Commerce, Company conforms with the EU–U.S. Data Privacy Framework (EU–U.S. DPF) and the UK Extension to the EU–U.S. DPF.
The DPF Principles and Supplemental Principles, which include but are not restricted to:
- Giving information about how personal data is collected, used, and processed;
- Providing people with options and ways to refuse specific data uses where necessary;
- Keeping Up Accountability Moving Forward transfers of private information to outside parties;
- Putting security measures in place to safeguard personal information;
- Maintaining the Purpose and Integrity of Data restriction in line with the terms stated at the time of transfer;
- Maintaining Recourse, Enforcement, and Liability processes to handle specific complaints or concerns; and giving people access methods to examine, update, or remove their personal data.
Observance Of The GDPR's Data Protection Guidelines. The data protection principles outlined in the EU General Data Protection Regulation ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and relevant data protection regulations are followed by Company while processing personal data. These guidelines serve as a framework for how we manage personal data and how we plan, run, and evaluate our services.
Specifically, Company follows these guidelines:
- (i) Lawfulness, equality, and transparency:We process personal data in a way that is lawful, fair, and transparent. This includes relying on the proper legal bases and giving clear and easily accessible information about our data processing procedures.
- (ii) Limitation of reason:We only gather and use personal information for clear, specific, and justifiable purposes. We never process personal information in a way that is inconsistent with those goals.
- (iii) Data minimization:We work to make sure that personal information is sufficient, pertinent, and kept to a minimum given the goals for which it is handled.
- (iv) Accuracy:We take reasonable measures to guarantee that personal information is correct and, where needed, updated, and to promptly correct or remove any inaccurate information.
- (v) Limitation on retention:We only keep personal information for as long as is required to meet legal requirements, fulfill the purposes for which it is processed, or as otherwise allowed by applicable agreements.
- (vi) Authenticity and privacy:We put in place the proper organizational and technical safeguards to guard against unauthorized or illegal processing of personal data as well as unintentional loss, destruction, or damage.
Our legal justifications for handling. The General Data Protection Regulation (GDPR) mandates that we have a "legal basis" for each of the uses of your personal information. The following is a list of our legal justifications for processing the personal data you provide in this Privacy Policy;
- (i) We are going to enter into or have already entered into a contract with you that requires us to fulfill certain obligations.
- (ii) Your interests and fundamental rights do not supersede our legitimate interests when it is required for those interests.
- (iii) In situations where we must adhere to a legal or regulatory requirement.
- (iv) When we have your express consent to treat the data for the specified purpose.
The legal bases we depend on for the relevant purposes for which we use your personal information are listed below; see "How we use your personal information" for more details on these purposes and the data types involved.
- (i) Categories of personal information involved: Contact Data, Profile Data, Communications Data, Transactional Data, User-Generated Content Data, Payment Data, Data from Third Party Sources, Device Data
Purpose: Business and service delivery
Legal Basic: Contractual requirement - (ii) Categories of personal information involved: Contact Data, Profile Data, Communications Data, Transactional Data, User-Generated Content Data, Payment Data, Data from Third Party Sources, Device Data, Location Data
Purpose: Personalization of services
Legal Basic: We have a right to want to give you an excellent service that is tailored to you and keeps track of your choices and preferences, consent for any optional cookies that may be used in this way. - (iii) Categories of personal information involved: Contact Data, Profile Data, Location Data, Device Data
Purpose: Analytics and service enhancement
Legal Basic: In order to improve our services, we have a genuine interest in giving you good service and analyzing how you use them. Consent for any optional cookies that may be used in this way. - (iv) Categories of personal information involved: Contact Data, Profile Data, Transactional Data, Marketing Data
Purpose: Direct marketing
Legal Basic: We have a right to use marketing communications to increase awareness of our organization's activities and objectives. Consent, in situations or in countries where sending any specific marketing communications requires consent under applicable data protection regulations. - (v) Categories of personal information involved: Any and all data types relevant in the circumstances
Purpose: Observance and defense
Legal Basic: Adherence to the law, justifiable interests. - (vi) Categories of personal information involved: Any and all data types relevant in the circumstances
Purpose: Data exchange in relation to corporate control changes
Legal Basic: We have a right to want to grow our organization in order to make sure that its objectives and operations are successful. - (vii) Categories of personal information involved: Any and all data types relevant in the circumstances
Purpose: To produce de-identified, anonymized, and/or aggregated data
Legal Basic: We can take action to make sure that our services and the way we utilize personal information are as non-intrusive as feasible because we have a legitimate interest in doing so and because we think it is in your best interests as well. - (viii) Categories of personal information involved: Any and all data types relevant in the circumstances
Purpose: Additional applications
Legal Basic: If the relevant additional use is consistent with the original reason why the personal information was gathered, the original legal basis will be used. consent, in the event that the relevant additional use conflicts with the original intent behind the collection of the personal data.
Storage. In accordance with the GDPR and UK GDPR principles of storage limitation, personal data about individuals residing in Europe or the UK is only kept for as long as is required to fulfill the purposes outlined in this Privacy Policy, to adhere to applicable legal requirements, or as otherwise allowed under applicable contracts.
Additional details. No private or sensitive information. We request that you refrain from giving us any sensitive personal information on or through the services, or in any other way, including social security numbers, information about your race or ethnic origin, political views, religion or other beliefs, health, biometrics or genetic traits, criminal history, or trade union membership. You must agree to our processing and use of any sensitive personal information you give us when using the services in compliance with this Privacy Policy. You must not submit such sensitive personal information through our services if you do not agree to our processing and use of such information.
We don't use automated profiling or decision-making that has legal or comparable substantial consequences as part of the Service.
You have specific rights to your personal data under European data protection regulations. If you live in Europe, you can request that we do the following with regard to the personal data we have on you:
- You will be able to access your personal information and receive information about how we process it.
- Make any necessary updates or corrections to your personal data.
- Delete your personal data if there is no valid reason for us to keep processing it. If you have used your right to object to processing, you can also request that we delete or remove your personal data.
- Give yourself or a chosen third party a machine-readable copy of your personal data. Limit. Limit how your personal information is processed, for instance, if you want us to verify its accuracy or the purpose of its processing.
- You have the right to object to our processing of your personal data when we are using it for legitimate purposes. You can also object when we are using your data for direct marketing.
- You have the option to revoke your consent at any moment if we use your personal information with it.
These requests can be sent to info@fedu.ai by email or at the above postal address. In order to complete your request and verify your identity, we can ask you for specific information. If we reject any request you may make, whether in full or in part, we will notify you of our reasons at the time, subject to any legal restrictions.
We put in place the necessary safeguards to guarantee a level of protection that is nearly equal to that provided by applicable European data protection laws when we transfer personal information to recipients who are based in nations that are not the subject of an adequacy decision by the European Commission or the UK Government. These precautions could consist of: (i) standard contract provisions that have been authorized by the UK authorities or the European Commission; or (ii) additional legal transmission methods that are allowed by relevant data protection regulations.
Under applicable data protection legislation, we may rely on derogation in some situations, such as when a transfer is required to fulfill a contract or where we have received express consent. For more details regarding the precise transfer mechanism used for a given data transfer, get in touch with Company.
Overview of the Supplemental Incident Response Plan. A high-level summary of Company's incident response procedures may be seen below. Please email info@fedu.ai for more information about our issue response protocols. In order to detect, evaluate, address, and resolve suspected or verified security incidents, Company keeps a documented incident response program. When a possible incident is discovered, Company looks into it right away, determines whether any student data or personal information may have been impacted, and takes the necessary actions to contain, mitigate, and fix the issue.
Breach Notification. When required by applicable law or contractual obligations, Company will inform affected individuals, Customers (including Schools), and appropriate regulatory or governmental authorities promptly and within the timeframes mandated by law.
Modification of the Policy. The Company may update, modify, or repeal the provisions of this Privacy Policy at any time. In such cases, Users will be informed via the services/products or through other means such as e-mail. Any updated, amended, or repealed provision shall become effective for the User as of the date of its publication. Continued use of the Company's services or products following such changes shall be deemed as acceptance of the updated terms by the User. The Company reserves the right to make any changes it deems necessary to this Privacy Policy as well as to the products, services, offers, and campaigns presented to the User. Such changes shall become effective as soon as they are announced by the Company via FeduAI or through other appropriate channels.
Data Sharing. If the User provides FeduAI with data belonging to third parties, the User is obliged to comply with all obligations under the relevant legislation regarding this transfer. If the User provides FeduAI with data belonging to third parties, it is assumed that the User has provided the necessary information to the third parties and obtained their explicit consent in accordance with the relevant legislation. Accordingly, it is recommended that the User ensures that s/he has informed third parties, obtained their explicit consent to provide the data to the Company, and directed data owners to read the Company's Privacy Policy in order to understand how the Company processes personal data before transferring third-party data to FeduAI. The Company shall not be liable in any way if third parties make any claims, complaints, and/or assert any rights as a result of such a transfer by the User. The Company may use the contact information of Users who have given their consent to communicate with the User regarding the Company's products and services. The User always has the option to refuse to receive commercial electronic messages sent with their consent.
E-mail message. The Company may use the contact information of Users who have given their consent to communicate with the User regarding the Company's products and services. The User always has the option to refuse to receive commercial electronic messages sent with their consent.
Contact. The Company's contact details are as follows:
Title: Ayasis Yazılım ve Bilişim Teknolojileri Anonim Şirketi
Address: Çifte Havuzlar Mahallesi Eski Londra Asfaltı Cad. Kuluçka Mrk. D2 Blok Apt. No: 151 /1f/1b06 Esenler/İstanbul
Phone: +90 212 483 72 92
Fax: +90 212 483 72 91
E-mail: info@ayasis.com
