In plain language
This page explains what data are used, why, who receives them, how long they are kept, and how to exercise your rights. A recovery email is optional and kept separate from tutoring records.
Activation is blocked until the controller/DPO approves every field, lawful basis, processor, transfer, retention rule, and rights procedure.
- Controller
- [CONTROLLER IDENTITY AND ADDRESS REQUIRED]
- DPO / privacy contact
- [DPO CONTACT REQUIRED]
- Purposes
- [APPROVED EDUCATIONAL AND RESEARCH PURPOSES REQUIRED]
- Lawful bases
- [GDPR ARTICLES 6 AND, IF APPLICABLE, 9 REQUIRED]
- Recipients/processors
- [APPROVED PROCESSOR LIST AND REFERENCES REQUIRED]
- Retention
- [RETENTION SCHEDULE AND DELETION DATE REQUIRED]
Data and safeguards
The approved notice must describe account and pseudonymous identifiers, tutoring messages, session/progress data, formative estimates, security records, optional questionnaire responses, identity-vault separation, EU location, provider egress controls, and any residual risks.
Your rights
The controller must provide verified procedures for access, correction, deletion, restriction, objection, portability where applicable, complaint, and withdrawal from optional research without affecting ordinary tutoring.
International transfers and automation
[TRANSFER MECHANISM, DPIA, AND AUTOMATED-DECISION ASSESSMENT REQUIRED]
Data categories and identity separation
The approved notice must separately list account and pseudonymous learner codes, class and session metadata, tutoring messages, progress and formative estimates, security/audit records, optional questionnaire answers, research linkage keys, and an optional verified recovery email. Teacher references and recovery email remain in the protected identity vault, separated from tutoring and research records; the final architecture and access roles require approval. A pending email never enables password reset, and teacher-assisted recovery remains available.
[APPROVED DATA-CATEGORY INVENTORY, IDENTITY-SEPARATION DIAGRAM, ACCESS ROLES, AND RECOVERY-EMAIL RETENTION REQUIRED]
Processors, transfers, and use limitations
The final notice must name each hosting and AI recipient/processor, its role, EEA location, any international transfer, transfer mechanism, and approval reference. Contracted providers may process participant data only on documented controller instructions and must not use it to train general-purpose models or for their own purposes.
[APPROVED PROVIDER RECIPIENTS, EU ENDPOINTS, DPA/SCC/TIA REFERENCES, NO-TRAINING TERMS, AND SUBPROCESSORS REQUIRED]
Minors and educational decisions
Real participant activation requires the institution to attest that each participant is at least 14 and to document any additional guardian or institutional authorization required by law or ethics review. MentorShip must not make solely automated decisions that produce legal or similarly significant educational effects; admission, discipline, access, advancement, official grading, and comparable decisions require accountable human review and a challenge route.
[AGE ATTESTATION, GUARDIAN RULE, HUMAN-REVIEW OWNER, AND CHALLENGE PROCESS REQUIRED]
Exercising rights and complaints
Use the approved controller/DPO channel to request access, rectification, erasure, restriction, objection, or portability where applicable. The final process must state identity checks, response times, escalation, and lawful limits. You may also complain to the Spanish Data Protection Agency (AEPD).
[VERIFIED RIGHTS REQUEST CHANNEL, IDENTITY-CHECK PROCESS, DEADLINES, AND DPO ESCALATION REQUIRED]