This Policy Regarding the Company's Practices Concerning Children's Online Privacy ("Policy") explains how Ayasis Yazılım ve Bilişim Teknolojileri Anonim Şirketi ("Company," "We," "Us," "Our") collects and safeguards the Personal Information of American users under the age of thirteen who use Our Service through their Schools.
A person under the age of 18 may be considered a "child" under several state student data privacy regulations, such as Maryland's HB 603. Furthermore, separate or additional rules regarding the collecting and protection of children's or minors' personal data may be imposed by international jurisdictions, such as the European Union, the United Kingdom, Canada, and Australia. As mandated by applicable law or contract, the Company provides student users under the age of eighteen in those jurisdictions with the protections outlined in this Policy.
We may get certain personal information from children who utilize a school's installation of our service. In accordance with COPPA's school-consent exception and other relevant laws, we serve as a service provider and data processor for such Personal Information on behalf of our clients, the schools (who serve as the information's controllers), and parents. Note Our agreements with the Schools regulate how we, as a processor, handle and process this Personal Information. The policies of the relevant school regulate how they process and distribute Personal Information pertaining to the Service. The schools may have their own privacy policies that regulate the Personal Information gathered in connection with their use of Our Service. Although we are unable to directly fulfill requests to exercise these rights with regard to Personal Information for which we act as a processor, we will forward them to the relevant School (or otherwise follow the process that We have agreed upon with the applicable School).
Article 1 – Definitions
"Child/Children": means a user or users of the Service in the United States who are under the age of 13.
"Child Account": means the user account, made available through an Educator, through which a Child has access to and uses the Service.
"Educator/Educators/Teacher": means an individual, or individuals, authorized to act on behalf of the School contracting with Company for use of the Service.
"Parent": refers to a child's legal guardian.
"Personal Information": refers to information about a child that can be used to identify, find, or get in touch with a specific child, either on its own or in conjunction with other information that is reasonably available.
"Service": refers to educational software, websites, mobile applications, and any other online interactive features or services that collect children's personal information and are supplied to schools in accordance with Company's Master Services Agreement or User Agreement.
"School": refers to a school, district, or other educational establishment that has a service agreement with Company.
Article 2 – the Company's Mission
Company does not:
- Sell or share student personal information for non-educational or commercial purposes.
- Utilize student information for marketing, behavioral advertising, and targeted advertising.
- Students should never be profiled for advertising or commercial decision-making, unless it is absolutely required to deliver an educational service requested by a school or educator.
- Permit large language model (LLM) providers to retain student personal information or use information associated with use of our platform to train their models.
- Employ manipulative, deceitful, or "dark-pattern" design strategies that push students to submit more personal data than is necessary or that threaten their autonomy or well-being.
- Unless it is necessary for a particular educational purpose and allowed by law, collect or process accurate geolocation data, biometric data, or other sensitive personal information from students.
The Company avoid practices that are reasonably likely to cause children material harm, such as physical, emotional, developmental, or privacy-related harm.
Article 3 – Access to and Utilization of the Service by Children
Only with the prior consent of a Parent or a School acting on the Parent's behalf may a Child use the Service for legitimate educational purposes. The Company will not collect, use, or disclose any Personal Information relating to Children without the consent of a Parent or School. A School or Teacher who uses the service on behalf of the school may provide such consent by entering into an agreement or accepting User Agreement to use the Service.
Child users may not access or use the Service unless they have first been added by their School or a Teacher. Child users access the Service either through a school-approved single sign-on provider or by entering a room code provided by their School. If we discover that a child's personal information has been gathered via the service without the parent or child's school's authorization, we will take the necessary action to remove the data. Please get in touch with the child's school to ask that We remove the child's personal information from Our systems if you are a parent and find out that your child has a registered account with the service without permission from the parent or school.
Article 4 – Personal Information the Company Collect
Information given through usage of the Service
Company only collect data from children that is logically required for them to use the service for school-approved educational objectives. Personal information is collected by Company when users access and utilize the Service. Company will only collect the user's first and last name in order to create an account when a child joins a room that their teacher has created. The student will be asked to log in with their SSO credentials if the school chooses to use their school-approved provider. The provider will then supply Company with the following details: (i) Child's first & last name, (ii) Student email address, (iii) School enrollment information such as grade level and School ID.
Article 5 – Data Collected Automatically
(I) Usage information
Certain "Usage Information" may be automatically gathered by us and/or Our Service providers each time users—including children—access and utilize the Service. For instance, we might gather data about how frequently a user uses particular features. The browser and operating system a user is using, all of the sections of Our Service that they visit, the time of day they utilized the Service, and other details are examples of Usage Information. Usage Information may be used for a number of reasons, such as choosing suitable material to show users and improving the Service in various ways.
(II) Device information
IP addresses or other unique identifiers (referred to as "Device Identifiers") may be gathered by us and/or our service providers for any computer, smartphone, or other device (collectively, a "Device") that is used to access the Service, including by children. Each person's device is identified by its Device Identifier, which is a number that is automatically assigned to the device used to access the Service. The physical location of the device used to access the service, the internet service provider (ISP), the date and time of a user's visit, the language and type of the browser, the referring and exit pages and URLs, the amount of time spent on specific pages, the parts of the service that users use, the links that users click, search terms, operating system, traffic and related statistics, keywords, and/or other general browsing or usage information are all examples of the information that certain mobile service providers may also give to Us or Our third-party service providers. If a user choose to send or grant access to Us, the Service may also have access to files, including metadata, that are stored on a Device.
(III) Information collected via cookies and other tracking Technologies
In order to help Our users, including Children, and give them a more personalized experience, to enable the technical operation of the Service, to improve the efficiency and usability of the Service, and for analytics purposes, We and/or Our service providers may use "cookies"—a small file sent to your computer by a website or device to allow the website or app to store information which uniquely identifies you—or other similar technologies to collect data. Some (or all) of the Service's capabilities and features might not be accessible if users disable cookies in their browser or device's settings.
Article 6 – Machine Learning and Artificial Intelligence
As approved by the School, Company provides features powered by artificial intelligence to facilitate educational use of the Service. Company does not develop, retrain, or enhance machine learning or artificial intelligence models for general, commercial, or non-educational uses using Children's Personal Information. With our AI providers, we have instituted "zero data retention," meaning that any materials, prompts, submissions, or student work submitted by a child may be processed temporarily by AI features to produce outputs that are requested at that moment and are not saved or used again for AI training or enhancement.
The Company adheres to stringent privacy guidelines that are in line with SOC 2, COPPA, and FERPA. Personally identifiable information (PII) is never sold or used for training, and is not retained by our AI providers. Safety, openness, and compliance are given top priority in every classroom at Company, which was founded with education in mind.
Article 7 – How We Use Personal Data
Children's personal information is used by Company only for the reasons listed below, which are approved by the relevant school and in line with reasonable educational goals.
Company has the right to use a child's personal data to:
- (i) Deliver and manage the Service for the Child as permitted by the School.
- (ii) Activate and support the features and functions required for the Child to use the Service effectively.
- (iii) Meet applicable legal obligations, respond to lawful requests, and comply with legal proceedings, including subpoenas and requests from public authorities.
- (iv) Safeguard the rights, privacy, security, and property of the Company, Schools, Children, and others, including asserting or defending legal claims and conducting internal audits to ensure compliance with legal, contractual, and policy requirements.
- (v) Enforce the terms governing the Service.
- (vi) Detect, prevent, investigate, and address fraudulent, harmful, unauthorized, unethical, or unlawful activities, including cybersecurity threats and misuse of the Service.
- (vii) Reasonably necessary to operate, secure, support, and maintain the Service, including troubleshooting issues, respond to errors, ensure system reliability, and protect the safety and integrity of the Service.
Children's personal information is never used by Company for research and development. Company uses aggregated, anonymized, or de-identified data that cannot be reasonably used to identify a child for any product enhancement, analytics, or development efforts that go beyond providing immediate operational support. Company doesn't try to re-identify aggregated or de-identified data, nor does it use children's personal information for unrelated commercial purposes.
De-identified and aggregated data. By eliminating information that could be used to fairly identify a child, Company may produce aggregated, anonymized, or de-identified data from children's personal information. As long as the data cannot be used to reasonably identify a child and is not used for advertising, profiling, or unrelated commercial purposes, Company may use and share such aggregated or de-identified data for legitimate business purposes, such as analyzing, maintaining, and improving the Service with permission. Only with the permission of the parent or school, as mandated by applicable legislation, may Company gather, use, or disclose a child's personal information for reasons not previously mentioned.
Companies does not engage in behavioral profiling, cross-context tracking, targeted advertising, or the sale of children's personal information.
Article 8 – How We Share Personal Information
If the School agrees otherwise, we may disclose a Child's Personal Information to the following parties:
- (i) Subject to the terms of the agreement between Company and the relevant school, We may disclose a Child's Personal Information to the Child's School and its Teachers. The way educators handle Children's Personal Information is beyond of our control and is not our responsibility. As previously mentioned, if you are a Parent and have inquiries concerning the Personal Information We process, please contact your Child's School.
- (ii) Third parties (like hosting, IT, customer care, and email delivery providers) that perform services for us or assist us in running the service or Our business may get personal information from us.
- (iii) When appropriate, we may disclose personal information to professionals who provide us with professional services, such as attorneys, auditors, bankers, and insurance.
- (iv) If we sincerely believe it is required or appropriate for the compliance and protection purposes outlined above, we may disclose personal information to law enforcement, government agencies, and private parties.
A warning about the Company content that is not included in the Service, third-party content, and links to other websites. Third parties may host and serve some of the content made available through the Service. Furthermore, Company has no control over third-party websites or material that are linked to through the Service and are subject to the privacy policies and business practices of those third parties. Please be aware that Company content may appear on websites that are unrelated to us and over which we have no control. These outside parties might gather data on their own. Company disclaims all liability and responsibility for any third party's privacy or business policies.
Teachers and other students at the child's school may view a child's information through their linked accounts, depending on the features that the school activates.
Article 9 – How Schools and Parents are Able to Access and Manage Children's Personal Information
The School that has a contract with Company to use the service is in charge of the gathering, upkeep, and use of any Personal Information. Schools can review, manage, or delete a Child's information by contacting us at info@fedu.ai.
For assistance, including questions about your rights to review, remove, and refuse to permit further collection of your Child's personal information, please get in touch with your Child's school if you are a parent and have concerns about your Child's Personal Information in relation to using Our Service. To opt out of sharing such Personal Information, you must get in touch with your child's school, as they are the ones that authorize and provide Child Accounts. Without permission from your Child's School, Company unable to remove, alter, or disclose any Personal Information about your Child from the Service.
Article 10 – Other Provision
Data Minimization. Company incorporates privacy-by-design principles into the design of its services, ensuring that the greatest level of privacy protection is enabled by default for student users. Only the bare minimum of Personal Information that is reasonably required for a Child to access and use the Service for valid educational reasons permitted by the relevant School is collected, used, disclosed, and retained by us. Beyond what is necessary to use the service, children are not encouraged nor compelled to contribute personal information, and optional data elements (if any) are by default disabled unless activated by the school or educator, as appropriate. Company creates user experiences that are intelligible for the target age range and give age-appropriate justifications for our data practices.
Age-Related Design and Children's Better Interests. Age-appropriate design principles and the obligation to behave in the best interests of children whose Personal Information is processed through the Services guide Company's design, development, and operation of its services.
Taking Age Ranges and Developmental Needs into Account. When creating features, interfaces, and data practices that interact with students, Company takes into account the age ranges and developmental traits of the kids who are most likely to use the services. This takes into account variations in kids' comprehension of data practices, decision-making skills, and safe digital environment navigation.
Age Estimation and Safe Defaults. By default, Company sets up elements that interact with students with safeguards that give kids a high degree of privacy and security. The goal of these defaults is to restrict feature exposure, analysis, and data collecting to what is deemed reasonably required for instructional purposes. Unless otherwise mandated by law, Company does not require children to provide additional personal information for the purpose of age verification. Instead, it may apply age-appropriate protections based on specific indicators, grade-level or age-related information provided by the school, or other reasonable methods.
Elements of In-Product Safety Associated with Child Development. Reasonable in-product safety elements that are in line with kids' developmental phases and educational purposes are incorporated into Company. These elements could include: (i) age-appropriate communications, directions, and interfaces; design strategies aimed at lowering the possibility that minors will unintentionally or needlessly divulge personal information; (ii) features that help teacher or school oversight, where appropriate; and controls and barriers meant to deter destructive, violent, or improper usage of the services.
Standard for the Best Interests of Children. Company designs and runs the Services with the best interests of the children in mind. In carrying out this responsibility, Company: (i) gives children's privacy, safety, dignity, and wellbeing precedence over business or involvement-based reasons; (ii) stays away from forceful, manipulative, or misleading design techniques that could take advantage of children's weaknesses or promote excessive data disclosure; (iii) restricts data practices to those that are deemed reasonably required to uphold safety and security and deliver educational functionality.
Risk Evaluation and Continuous Evaluation. Company evaluates and records the predictable risks of material harm to children that result from its product development and student-facing data practices, and it puts in place appropriate controls to reduce those risks. When there are significant changes to the Services, data flows, or functionality that impact children, these assessments are evaluated and updated as needed.
Impact Assessments of Data Protection. For features and products that handle student personal data, Company performs and keeps track of documented Data Protection Impact Assessments, or "DPIAs." Every DPIA analyzes the flow of data, finds any threats to students' rights and welfare, records precautions and mitigating actions, and determines if the product is made and used with the safety of kids in mind.
Parent Monitoring. At this time, Company does not include features that let a parent or legal guardian keep an eye on or see how a student uses the service. Before allowing any parent or guardian monitoring features, Company would amend this Policy and provide schools advance notice.
Data Retention, Storage, and Erasure. Company keeps personal data for as long as necessary to complete the processing task. Upon termination or expiration of a school or district contract, unless a longer retention period is required by applicable law, Company will, at the customer's direction, delete or return all student personal data within 60 days. Upon request, Company will also offer a formal certification of deletion. We shall cooperate with the School's verified data erasure request.
Sub-processors. In order to process Student Personal Information on its behalf in connection with the Service, Company may work with third-party service providers, sub-processors, and technology partners (such as those that offer statistics, hosting services, support for customers, safety, and application programming interfaces, or "APIs").
Security. As outlined in Company's Privacy Policy, we maintain appropriate administrative, technical, and physical safeguards intended to maintain the availability and confidentiality of Personal Information processed by Company in compliance with the terms agreed upon by the Child's School.
Modification of the Policy. Company retains the right to make changes to this Policy at any time. Unless a shorter notice period is necessary to address legal, safety, or business obligations, we will use reasonable efforts to give the applicable School advance notice of any material changes to this Policy that affect how Student Personal Information is collected, used, or shared before the changes take effect. The effective date at the top of this notice will also be amended, and the revised version will be accessible via our website and other suitable methods. The date indicated in the notice sent to schools is when material changes will take effect. After the effective date, a School's continued use of the Service indicates that its users have accepted the amended Policy.
Contact. The Company's contact details are as follows: Title: Ayasis Yazılım ve Bilişim Teknolojileri Anonim Şirketi Address: Çifte Havuzlar Mahallesi Eski Londra Asfaltı Cad. Kuluçka Mrk. D2 Blok Apt. No: 151 /1f/1b06 Esenler/İstanbul Phone: +90 212 483 72 92 Fax: +90 212 483 72 91 E-mail: info@ayasis.com
