Legal

Data Protection

Our commitments for handling student and institutional data safely.

Last updated: 8 July 2026

Template notice: this document is a starting template and not legal advice. Placeholders in [brackets] must be completed, and the final text reviewed by qualified counsel, before publication.

Our promise

Learning data is sensitive — especially for children. We treat it that way. We collect only what a learner’s experience needs, use it only to teach and report to authorised adults, and never sell it or use it for advertising.

Roles

When an institution uses Learnax, the institution is the data controller for its students’ data and Learnax acts as a data processor, handling that data on the institution’s documented instructions under a data processing agreement.

Regulatory alignment

  • DPDP Act (India) — lawful processing, purpose limitation, and verifiable parental consent for children handled via the institution.
  • GDPR (EU/UK) — lawful basis, data-subject rights, and appropriate safeguards for any international transfers.
  • COPPA (US) — school-authorised collection of information from under-13 students for educational use only.

[Confirm the exact regulatory scope that applies to your deployment with counsel.]

Consent for children

Where learners are children, the institution is responsible for obtaining any required parental or guardian consent before accounts are created. Learnax provides the tools and documentation to support this.

Data minimisation and purpose

  • We collect only the data needed to deliver and improve learning.
  • Student data is used to personalise learning and to report progress to authorised teachers, parents and admins.
  • We do not build advertising profiles from student data.

Security measures

  • Encryption of data in transit (and at rest where supported).
  • Role-based access controls and least-privilege access.
  • Logging, monitoring and regular review of access.
  • Vetted sub-processors bound by contractual data-protection obligations.

Retention and deletion

Institutions can request export or deletion of their data. On the end of a contract, we delete or return institutional data within a defined window, subject to any legal retention requirements. [Specify the retention window in your DPA.]

Sub-processors and hosting

Learnax runs on reputable cloud infrastructure and uses AI processing providers under data-protection contracts. A current list of sub-processors and hosting regions is available to institutions on request, and data-residency options can be discussed during onboarding.

Incident response

We maintain an incident-response process and will notify affected institutions of any personal-data breach without undue delay, in line with applicable law.

Contact

For a Data Processing Agreement, sub-processor list, or any data-protection question, contact admin@learnax.ai. See also our Privacy Policy.