SenseiEdu Privacy Policy

Effective Date: May 15, 2026 · Last Updated: May 15, 2026 · Version 1.0

Governing Law: State of Delaware, United States

Designed For: Private, independent, and international schools

Contact: info@senseiedu.com

1. Overview and Scope

SenseiEdu ("SenseiEdu," "we," "us," or "our") provides a cloud-based educational support platform designed exclusively for private, independent, and international schools. Our Services enable authorized school staff to create and manage student support documentation. Certain features optionally use artificial intelligence to assist with drafting sections within student support plans and progress reports.

This Privacy Policy describes how we collect, use, store, process, disclose, and protect information in connection with our Services. It applies to all Users of the SenseiEdu platform.

SenseiEdu serves private, independent, and international schools, which are generally not subject to the Family Educational Rights and Privacy Act (FERPA) or the Individuals with Disabilities Education Act (IDEA), both of which apply to publicly funded schools only. SenseiEdu voluntarily applies FERPA-equivalent Student Data protection principles as a matter of best practice.

This Policy is consistent with applicable privacy and data protection laws, including:

  • The General Data Protection Regulation (EU) 2016/679 (GDPR), for Schools in the European Economic Area;
  • The UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, for Schools in the United Kingdom;
  • The Children's Online Privacy Protection Act (COPPA), where applicable;
  • Applicable US federal and state student privacy laws in all US states where Schools are located.

The Services are intended for use by school staff only. SenseiEdu does not provide accounts or access to students, parents, or guardians.

By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

2. Definitions

"Services" means the SenseiEdu platform, applications, APIs, and all associated features and tools made available to the School.

"School" means any private, independent, or international school contracted with SenseiEdu to use the Services.

"User" means all school personnel authorized by the School to access and use the platform.

"School Administrator" means the primary account holder designated by the School at registration, responsible for managing the School's account and receiving all official notifications from SenseiEdu.

"Student Data" means any information relating to an identifiable student entered into the platform by Users on behalf of the School.

"Student Support Records" means records created and maintained within the platform by Users, including student support plans, progress reports, and notes.

"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection law.

"AI Features" means optional tools powered by OpenAI, available within the platform at the User's discretion, including Chatbot assistance and AI-Assisted Section Drafting features.

"Data Controller" means the entity that determines the purposes and means of processing Personal Data. The School is the Data Controller for Student Data. SenseiEdu is the Data Controller only for its own platform and account data.

"Data Processor" means the entity that processes Personal Data on behalf of a Data Controller. SenseiEdu acts as Data Processor for Student Data — meaning SenseiEdu stores and processes Student Data only on the School's instructions.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.

3. Role of the Parties

3.1 SenseiEdu as Data Processor

With respect to Student Data and Student Support Records, SenseiEdu acts as a Data Processor. SenseiEdu processes such data solely on documented instructions from the School, strictly to provide the Services, and does not, at any time, determine the purposes or means of processing Student Data.

3.2 School as Data Controller

The School acts as the Data Controller for Student Data. The School:

  • Determines what Student Data is entered into the platform;
  • Determines how that data is used within the scope of the Services;
  • Is responsible for ensuring its collection and use of Student Data complies with applicable law;
  • Controls which Users are granted access and at what permission level;
  • Is responsible for responding to student and parent data rights requests relating to Student Data.

3.3 Private School Data Governance

Private and independent schools are generally not subject to FERPA or IDEA. However, many have their own data governance frameworks, parent agreements, and accreditation obligations (NAIS, CIS, IB, Cambridge, or equivalent). The School is responsible for ensuring that its use of SenseiEdu is consistent with those obligations.

3.4 SenseiEdu as Data Controller — Platform Data

SenseiEdu acts as Data Controller for account and platform-related data (User account information, usage logs, authentication data), which it processes to operate, secure, and improve the Services.

4. Information We Collect

4.1 School Information

  • School name, country, and state or region;
  • School address (where provided);
  • School email domain, divisional structure, and academic configuration;
  • Billing contact information provided by the School;
  • School logo.

4.2 User Information

  • First and last name, school-issued email address, and assigned role;
  • Authentication data, including Single Sign-On (SSO) identifier from Google Workspace, and a two-factor authentication verification code delivered by email;
  • Login timestamps and account access logs.

Account registration is restricted to school-issued email addresses. Personal email addresses are not accepted.

4.3 Student Data (Provided by Schools)

SenseiEdu processes Student Data solely as entered or created by Users within the platform. This may include:

  • Student name and grade;
  • Learning profile and evaluation information;
  • Student support plans, progress reports, and notes;
  • Student roster data.

4.4 AI Feature Data

Where a User chooses to activate an AI Feature, relevant Student Data is sent to OpenAI to generate a suggested output. Use of AI Features is entirely optional. See Section 8 for full details.

4.5 Technical and Usage Data

  • IP address, device type, browser type and version;
  • Platform activity logs, session metadata, login timestamps;
  • Security logs, audit trails, and system performance data.

4.6 Cookies

We use authentication and session cookies, security cookies, and preference cookies necessary for platform operation. We also use Google Analytics to measure website traffic. We do not use advertising or behavioral tracking cookies.

5. Legal Bases for Processing (GDPR / UK GDPR)

For Schools in the EEA or UK, SenseiEdu processes Personal Data on the following legal bases under GDPR Article 6:

  • Article 6(1)(b) — performance of the contract between SenseiEdu and the School;
  • Article 6(1)(f) — legitimate interests for platform security, fraud prevention, and audit logging;
  • Article 6(1)(c) — legal obligations.

Where Student Data includes sensitive categories (GDPR Article 9), the School is responsible for ensuring it has legal authority to enter it.

6. How We Use Information

SenseiEdu uses information only for the following purposes:

  • To provide, operate, maintain, and improve the Services;
  • To enable creation and management of student support plans and progress reports;
  • To provide AI Features to Users who choose to use them;
  • To create and maintain User accounts and support the School Administrator;
  • To maintain platform security, integrity, and performance;
  • To comply with applicable legal obligations;
  • To respond to support requests from authorized school personnel;
  • To detect, investigate, and prevent fraudulent or unauthorized activity.

SenseiEdu does not use Personal Data or Student Data for advertising, behavioral profiling, data brokerage, or resale.

7. Student Data Commitments

"No Sale of Student Data" — SenseiEdu does not sell, rent, license, or transfer Student Data to any third party for commercial purposes, under any circumstances.

"No Advertising Use" — Student Data is never used for targeted advertising, behavioral advertising, or the creation of advertising profiles.

"No AI Model Training" — Identifiable Student Data is not used to train, fine-tune, or improve any AI or machine learning model. SenseiEdu may use aggregated, anonymized, de-identified data to monitor and improve platform performance.

"Purpose Limitation" — Student Data is processed only to provide the Services to the School. No secondary use is permitted.

"Access Controls" — Access to Student Data is restricted to Users based on role-based permissions configured by the School.

"Data Minimization" — SenseiEdu only collects Student Data that Users actively enter into the platform.

"No Third-Party Profiling" — Student Data is not shared with third parties for profiling, research, or commercial analytics.

"Voluntary FERPA Alignment" — SenseiEdu voluntarily applies FERPA-equivalent principles as a baseline standard of Student Data protection.

8. Artificial Intelligence Features

8.1 What Our AI Features Do

SenseiEdu provides AI Features powered by OpenAI. AI Features are currently available for:

  • Chatbot assistance — AI-powered chat for platform questions and account queries;
  • Present level of performance generation;
  • Custom goal generation;
  • Progress report notes;
  • Goal progress generation.

Use of AI Features is entirely at the User's discretion. All professional judgment remains with the User.

8.2 How AI Processes Student Data

When a User activates an AI-Assisted Section Drafting Feature, the Student Data entered for that purpose is sent to OpenAI to generate a suggested output. The output is returned to the User for review, editing, and approval before any use. Student Data is never sent to OpenAI without a User actively choosing to use an AI Feature.

8.3 Human Oversight — Always Required

All AI-generated outputs are suggestions only. No AI output is applied to a student's record without explicit review and action by a User. Users retain full professional responsibility for all decisions regarding individual students.

8.4 AI Data Commitments

  • Student Data submitted to AI Features is used solely to generate the requested output for that User session;
  • Under OpenAI's current API policy, AI inputs may be retained for up to 30 days for safety monitoring, then deleted;
  • Identifiable Student Data is not used to train, retrain, or fine-tune any AI model;
  • AI outputs are stored within the School's account under the same access controls as all other Student Data.

8.5 Third-Party AI Providers

SenseiEdu uses OpenAI as a sub-processor under OpenAI's Data Processing Addendum, which prohibits OpenAI from using submitted data for any purpose other than performing the contracted services.

8.6 AI Output Ownership

As between SenseiEdu and the School, the School owns all AI-Generated Output produced from its Users' inputs.

9. How and When We Share Data

9.1 Within the School

Student Data is accessible only to authorized Users within the School's account, based on role-based permissions configured by the School Administrator.

9.2 Service Providers and Sub-processors

We engage a limited number of third-party service providers. Each receives only the minimum data necessary:

  • Microsoft Azure — stores and processes all platform data including Student Data;
  • Google Workspace — provides SSO authentication (User name, email, domain only);
  • Azure Monitor — security monitoring (IP addresses and network metadata);
  • OpenAI — processes Student Data for AI Feature outputs;
  • Google Analytics — anonymized website usage data only.

9.3 Legal Requirements

We may disclose data where required by applicable law, court order, or regulatory authority. We will notify the affected School prior to disclosure where legally permitted.

9.4 Business Transfers

In the event of a merger, acquisition, or sale, Student Data may be transferred to a successor entity, which will be required to honor the terms of this Policy.

10. International Data Transfers

SenseiEdu's primary data infrastructure is located in the United States. Transfers from other jurisdictions are subject to the following safeguards:

  • For EEA Schools: Standard Contractual Clauses (Module 2, Controller to Processor);
  • For UK Schools: UK International Data Transfer Agreement (IDTA);
  • For all other jurisdictions: applicable national data protection laws with appropriate additional safeguards.

All international transfers are supplemented by encryption in transit and at rest, and access controls limiting data access to authorized personnel only.

11. Data Security

SenseiEdu implements the following safeguards:

  • All data encrypted using TLS 1.2 or higher (HTTPS) in transit;
  • Student Data and account data encrypted at rest using industry-standard encryption;
  • All data stored exclusively within Microsoft Azure (SOC 2, ISO 27001);
  • Two-factor authentication mandatory for all accounts;
  • Single Sign-On (SSO) via Google Workspace supported;
  • Role-based access controls within the School's account;
  • Staff access strictly limited and subject to confidentiality obligations;
  • All platform activity logged for security monitoring.

12. Data Breach Notification

In the event of a confirmed or reasonably suspected breach, SenseiEdu will:

  • Notify the affected School without undue delay, and within 72 hours where practicable;
  • Provide the School with sufficient information to fulfill its own notification obligations;
  • Take immediate steps to contain, investigate, and remediate the breach;
  • Cooperate fully with the School in any breach investigation;
  • Document the breach and all remedial steps taken.

The School, as Data Controller, is responsible for notifying students, parents, guardians, and regulatory authorities as required.

13. Data Retention and Deletion

SenseiEdu retains data only for as long as necessary to provide the Services:

  • Active accounts: all Student Data and School Data is retained. Schools may export at any time;
  • User-initiated deletion: permanently deleted within 30 days. Backups deleted within 90 days. Irreversible;
  • Account termination: 30-day read-only grace period for export, then permanent deletion;
  • Free Trial: may be deleted after 180 days of inactivity following 14 days' written notice;
  • Security logs: retained up to 12 months;
  • Anonymized data: may be retained indefinitely.

14. Data Rights

14.1 Student Data Rights

All requests from students, parents, or guardians relating to Student Data must be directed to the School. SenseiEdu does not respond to such requests directly.

14.2 GDPR / UK GDPR Rights (EEA and UK Schools)

Individuals whose Personal Data is subject to GDPR or UK GDPR have the following rights:

  • Right of access (Article 15);
  • Right to rectification (Article 16);
  • Right to erasure — "right to be forgotten" (Article 17);
  • Right to restriction of processing (Article 18);
  • Right to data portability (Article 20);
  • Right to object to processing (Article 21);
  • Right not to be subject to solely automated decision-making (Article 22).

For Student Data, these rights are exercised through the School. You have the right to lodge a complaint with your local supervisory authority.

14.3 California Rights (CCPA / CPRA)

California residents have the following rights:

  • Right to know what Personal Information is collected and how it is used;
  • Right to delete Personal Information;
  • Right to correct inaccurate Personal Information;
  • Right to opt out of sale (SenseiEdu does not sell Personal Information);
  • Right to non-discrimination for exercising these rights.

14.4 User Account Rights

Users may update their account information and download and export available student records directly within the platform at any time.

15. Children's Privacy and COPPA

SenseiEdu is a platform used exclusively by school staff. Students do not create accounts, access the platform, or interact with SenseiEdu's Services directly. Accordingly:

  • SenseiEdu does not knowingly collect Personal Information directly from children under the age of 13;
  • All Student Data is entered into the platform by authorized Users only;
  • SenseiEdu processes Student Data (which may relate to minors) solely as Data Processor on behalf of the School.

Where Student Data includes information about children under 13, the School is responsible for complying with COPPA and any equivalent local law.

16. Data Processing Agreement

SenseiEdu offers a formal Data Processing Agreement (DPA) to all Schools. The DPA supplements this Privacy Policy and covers:

  • Subject matter, nature, and purpose of processing;
  • Categories of data subjects and types of data processed;
  • Duration and deletion obligations;
  • Technical and organizational security measures;
  • Sub-processor authorization and management;
  • Data subject rights assistance;
  • Standard Contractual Clauses (SCCs) and UK IDTA for international transfers.

Schools in the EEA or UK requiring a signed DPA may request one at info@senseiedu.com.

17. Changes to This Policy

A material change is any change that meaningfully affects the rights or obligations of Schools or Users. For material changes, SenseiEdu will provide at least 30 days' advance written notice by email to the School Administrator.

Non-material changes, such as clarifications or formatting updates, will be reflected by a site update only.

Continued use of the Services following the effective date of any material change constitutes acceptance of the updated Policy.

18. Contact

For questions, concerns, or rights requests relating to this Privacy Policy, please contact SenseiEdu at info@senseiedu.com.

Our registered address is Delaware, United States. We respond to all inquiries within 30 days, or within the timeframe required by applicable law.

© 2026 SenseiEdu. All Rights Reserved.