1. Categories of Data Collected and Purposes of Processing
The categories of personal data collected by this platform are enumerated in the Data Governance Framework, §3. The lawful basis for collection and the purposes of processing for each category are set out below:
| Data Category | Purpose of Processing | Lawful Basis |
|---|---|---|
| Account and Profile Data | Identity authentication, access control, personalized instructional services, and course-group membership management | Performance of the Terms of Service agreed to by the user upon registration (GDPR Art. 6(1)(b)) |
| Student–AI Conversation Data | Provision of LLM inference services, personalized learning feedback, and instructor review of classroom interactions | Performance of the Terms of Service; research use is based on individual consent (GDPR Art. 6(1)(a), Art. 6(1)(b)) |
| Learning Behavior Records | Learning dashboard presentation, instructors' class-level analytics, and evidence for course improvement | Performance of the Terms of Service; research use is based on individual consent |
| Derived Analytical Data | Personalized feedback and instructional decision support for teachers | Performance of the Terms of Service; algorithmic processing is disclosed in the documentation of the corresponding features |
| OAuth and Authentication Credentials | Third-party sign-in and two-factor authentication | Performance of the Terms of Service |
| Physiological Sensing Data (Garmin / Apple Health / Google Health Connect) | Personal health dashboard presentation, the PALM state-aware instructional module (where enabled), and research use | Individual consent (GDPR Art. 9(2)(a)); may be withdrawn at any time |
| Screen Recording Data | Instructor-side post-class playback and student-side classroom archives; research use requires individual consent | Individual consent, obtained via a consent form prior to recording |
| In-Depth Interview Data | Qualitative research analysis | Individual consent (GDPR Art. 9(2)(a)); the consent form discloses the research purpose, retention period, and contact information |
| System Logs | System operations, security incident detection, and fulfillment of legal obligations (e.g., investigation of unauthorized access) | Legitimate interests (GDPR Art. 6(1)(f)); compliance with legal obligations (GDPR Art. 6(1)(c)) |
2. Retention Periods
The platform treats "accounts and directly identifying personal data", "platform-side teaching records", and "external exports by researchers" as mutually independent matters, each subject to different retention periods and handling methods.
2.1 Retention period table
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Directly identifying personal data (PII) | Retained for the life of the account; self-service account deletion currently only deactivates the account and does not automatically erase data; full deletion is handled case by case upon email request (see §3) | GDPR Art. 5(1)(e), Art. 17 |
| Platform-side teaching records (AI conversations, learning histories) | Retained permanently; not deleted upon the end of a course or the closure of an individual research project | Proviso to Article 11, Paragraph 3 of the Personal Data Protection Act; IRB protocol (NTU REC 202507EM058) |
| Personal data in backups | Naturally purged through the 30-day rotation cycle | Industry-standard practice |
| Researcher outbound export | Within 5 years of the data generation date | Internal IRB rules |
| Exercise of rights by the data subject | No time limitation | GDPR Art. 15, Art. 20 |
2.2 Personal Data Retention
Account files and directly identifying information are retained for the life of the account. When a user deletes their account through the self-service page, the account is currently only deactivated so that it can no longer be used to log in; personal data is not automatically erased. Users who wish to have their personal data deleted may apply by emailing [email protected], and the platform handles each request individually within the response period set out in §7.3. Personal data in backups persists for up to 30 days due to the routine rotation cycle.
2.3 Platform-side teaching records and research export data
Conversation logs and learning behavior records are platform operational records kept to provide teaching services. They are retained on the platform and are not deleted upon the end of a course or the closure of an individual research project. The platform currently does not apply automatic pseudonymisation or anonymisation to such records. Export data provided for research identifies students only by an internal system user number and does not include names, email addresses, or student ID numbers; it is pseudonymised data. Research use is based on consent individually signed by data subjects and is carried out under GDPR Art. 89 (processing for scientific research purposes) within the approved IRB protocol (NTU REC 202507EM058).
2.4 Researcher Outbound-Export Window
Researchers authorized under a Researcher Access Agreement may request export of raw research data within 5 years of the data generation date. Beyond this 5-year window, the data remains archived within the system for verification and reproducibility purposes and is no longer available for outbound export. This restriction applies only to researcher-side access; data subjects' rights under GDPR Art. 15 and Art. 20 are not subject to this time limit.
For the researcher's safekeeping obligations after export, the per-export destruction declaration mechanism, and how data is handled when a research project closes, seeInstructions for handling data after research closure.
3. Deletion Process
This section describes what currently actually happens when a user deletes their account, as well as the parts not yet implemented.
3.1 Self-service account deletion (current practice)
- After the user confirms by entering their password on the "Delete Account" page, the account is marked as deleted and the user is logged out
- The account can no longer be used to log in thereafter
- Account data such as name, email, and student ID number, as well as conversations, AI interactions, and learning behavior records, remain in the platform database and are not automatically deleted, pseudonymised, or anonymised
- Teachers may still see the user's past content in course records
- The system currently does not send a deletion confirmation email and does not provide a link to cancel the deletion; if you need assistance after deletion, please email [email protected]
3.2 Full deletion and removal from research data (by email request)
- To have your personal data deleted, or to request that your data be removed from research use, please email [email protected] or contact the principal investigator
- The platform responds within the period set out in §7.3 and handles each request individually; where the exceptions in §5 apply, handling may be postponed until the relevant matter has concluded
- Those who only wish their data not to be used for research may withdraw consent in the Research Informed Consent Center; after withdrawal, the data is no longer used for new research analyses or external exports, and platform services, course rights, and grades are not affected
- Copies already exported by researchers are kept and destroyed by the researchers themselves under the Consent Form for Educational Data Export; see Instructions for handling data after research closure for details
3.3 Items not yet implemented
The following mechanisms are currently not implemented, and this policy does not present them as current practice:
- A grace period after deletion, a deletion confirmation email, and a link to cancel deletion
- Automatic permanent deletion of directly identifying personal data when a time limit expires
- Automatic pseudonymisation or anonymisation of conversation and learning behavior records
- Automatic unlinking of security audit records (setting
user_idtoNULL)
4. Handling of Backup Data
- Daily backups are retained for 30 days on a rolling rotation basis
- Personal data in backups is naturally purged through the 30-day rotation cycle
- Personal data is not selectively excised from backup files (industry-standard practice)
5. Exceptions
In the following circumstances, retention periods may be extended until the conclusion of the relevant matter or the expiry of the legal obligation:
- Pending disputes, legal proceedings, or investigations by competent authorities: the relevant data is retained until the matter concludes
- Compliance with legal obligations (taxation, research records, grant accounting): retained until the legal obligation expires
Under such exceptional circumstances, the relevant data is managed in segregated storage, is not included in research datasets, and is not exported.
6. Cross-Border Transfers
The platform's primary servers are located in the server facilities of National Central University, Taiwan. Cross-border transfers occur in the following circumstances:
- LLM inference services: the default LLM provider is located in the United States (OpenAI, L.L.C.). Uedu has enabled Zero Data Retention (ZDR) on its OpenAI API usage; input and output data are not retained after real-time processing.
- European research collaborations: for research collaborations involving European data subjects, inference may be re-routed to the Switzerland North or West Europe region of the Microsoft Azure OpenAI Service, processed under Microsoft's EU Data Boundary commitments. The choice of region is decided jointly with the partner institution to align with its data residency requirements.
- Email delivery: transactional email is sent via Mailgun (EU region).
- DNS / DDoS protection / CDN: via the global edge network of Cloudflare, Inc.; requests from European users are primarily handled by Cloudflare's European nodes.
The lawful bases and mechanisms for cross-border transfers vary by jurisdiction; see the Cross-Jurisdiction Compliance Matrix and the notes for each jurisdiction. For full vendor disclosure, see the Sub-Processor List.
7. Data Subject Rights
7.1 List of Rights
| Right | Corresponding Provisions | How to Exercise |
|---|---|---|
| Right of access | GDPR Art. 15; Taiwan PDPA §3 | Email [email protected] |
| Right to rectification | GDPR Art. 16; Taiwan PDPA §3 | Edit directly on the user settings page, or by email |
| Right to erasure (right to be forgotten) | GDPR Art. 17; Taiwan PDPA §11 | The "Delete Account" page can deactivate your account (see §3.1); for full deletion of personal data, please email [email protected] |
| Right to restriction of processing | GDPR Art. 18 | By email |
| Right to data portability | GDPR Art. 20 | By email (see the disclosure in §7.2) |
| Right to object | GDPR Art. 21 | By email |
| Right to withdraw consent | GDPR Art. 7(3) | Toggle on the consent settings page of the corresponding feature, or by email |
7.2 Disclosure Regarding the Right to Data Portability
The only self-service interface the platform currently offers is the "Delete Account" page (which deactivates the account; see §3.1). A self-service data download interface corresponding to GDPR Art. 20 is currently not implemented, and there are no plans to launch one in the near term. Data subjects may exercise data portability requests under GDPR Art. 20 and Taiwan's Personal Data Protection Act by emailing [email protected]; we will respond within 30 days.
The purpose of this disclosure is to inform data subjects of the current request channel before they exercise this right, so that they do not search the interface in vain and mistakenly conclude that the right does not exist.
7.3 Exercise Procedure and Response Deadlines
- All written requests are committed to a response within 30 days of receipt of complete information
- Where a request involves complex identity verification or extensive data retrieval, the deadline may be extended to 60 days, with the reason for the extension communicated within the original 30-day period
- Responses may take the form of: fulfilling the request, partially fulfilling it (with an explanation of the limitations), or refusing it with reasons and information on complaint channels
- No fee is charged for exercising rights, but the platform reserves the right to refuse manifestly repetitive or abusive requests
8. Cookies and Similar Technologies
This platform uses only the session cookies strictly necessary to maintain sign-in state and authenticate identity. It uses no third-party tracking cookies, deploys no advertising cookies, and embeds no tracking tools that transmit user behavior to external parties, such as Google Analytics or Facebook Pixel. Cookies expire upon sign-out or session expiry.
Because this platform uses no tracking cookies, no "cookie consent banner" appears when users enter the platform. This design reflects the data minimization principle and is not an evasion of consent obligations.
9. Processing of Network Address (IP) Information
Network addresses (IP addresses) constitute personal data under CJEU judgment C-582/14 (Breyer v. Bundesrepublik Deutschland), the broad interpretation of the Taiwan Personal Data Protection Act, and the definitions of personal data in most jurisdictions. This platform adopts a three-layer processing model that separates lawful bases and retention periods by purpose:
9.1 Three-Layer Processing Model
| Layer | Purpose | Retention Period | Lawful Basis |
|---|---|---|---|
| L1. Edge and System Logs | nginx access logs; system operations, debugging, DDoS mitigation, and traffic analysis | 30–90 day rotation | Legitimate interests (GDPR Art. 6(1)(f)) |
| L2. Application-Layer Security Records | Sign-in sessions (user_session.ip_address IP at the moment of sign-in, last_seen_ip most recent activity IP), session IP change auditing (user_session_ip_history), 2FA attempt records, failed sign-in auditing (user_login_failures), anomalous sign-in detection, account-compromise recovery assistance, and survey response source auditing |
No automatic purge is currently configured; not deleted together with the account (see §3, §9.3) | Legitimate interests; performance of the Terms of Service (GDPR Art. 6(1)(b), (f), Art. 32) |
| L3. Country-Level Geolocation | Identification of cross-border collaborations; jurisdiction-specific routing (e.g., re-routing European collaborations to Azure EU regions); publicly disclosed country-level visitor distribution (aggregate statistics) | Computed in real time; not stored long-term | Legitimate interests; compliance with legal obligations (GDPR Art. 6(1)(f), (c)) |
9.2 Distinction Between Recording and Use
Pursuant to its security obligations (GDPR Art. 32), this platform records IP data within the system; such recording does not amount to tracking or behavioral profiling — these are distinct concepts in both law and engineering.
Events for which this platform records IP addresses:
- Successful sign-ins (
user_session.ip_address,last_seen_ip) and failed sign-ins (user_login_failures) - 2FA verification attempts (
user_totp_attempts,user_2fa_email_codes) - Session IP change auditing (
user_session_ip_history, appended upon IP change) - Survey response source auditing (
survey_responses.ip_address)
This platform does not use IP data for the following purposes (even where the data already exists in the system):
- Research analysis of individual movement trajectories (no temporal profiling of where a user has been based on IP changes)
- Fine-grained location research at the street or township level (IP data is inherently unreliable at this granularity)
- Behavioral profiling, automated decision-making, or advertising delivery
- Public disclosure of any individual user's IP or of derived geographic information capable of re-identifying an individual
IP data is queried only in the following circumstances: assisting users in tracing account compromise, security incident investigations (DDoS, credential stuffing, spam, etc.), lawful requests by competent authorities, and platform operations debugging.
Collection of precise personal location (GPS coordinates) is subject to a separate opt-in consent mechanism, limited to users aged 18 or over; see the User Location Management page at /environment/locations. Location authorization and IP processing are independent workflows; withdrawing one does not affect the other.
9.3 Account and Data Deletion Process
This section describes how location data, IP addresses, and security audit records are handled upon deletion:
- User deletes location data (via "Delete All" / "Delete One"): the
deleted_atcolumn ofuser_locationsis timestamped (soft delete); the record is no longer returned in user-facing lists or counts. - User deletes account: the account is deactivated (see §3.1); IP and security audit records (
user_session/user_session_ip_history/user_login_failures/user_locations, etc.) are currently not automatically unlinked from the user and remain in the system. To have them deleted or unlinked, please apply by email as described in §3.2.
Once records have been unlinked upon request (user_id set to NULL), they can no longer be attributed to a specific data subject and, under GDPR Recital 26, fall outside the scope of personal data; the records themselves are retained for tracing security incidents (GDPR Art. 32, Recital 49).
When a user withdraws authorization for location research, the time of withdrawal is recorded in user_research_consent.revoked_at_utc. Any data subject wishing to access or delete their own data may email [email protected].
9.4 Special Channel for Complete Physical Deletion
Self-service deletion on this platform currently only deactivates the account (§3.1); deletion of personal data is handled upon email request (§3.2).
The platform recognizes that certain data subjects in special privacy circumstances (for example, divorce counterparties subjected to domestic violence, political dissidents, journalists protecting sources, or persons whose physical safety is under threat) may wish to obtain complete physical deletion, such that their data cannot persist in the system in any form. For such requests:
- Please email [email protected] with the subject line "Physical deletion request" and a brief description of the situation (no supporting documents required)
- The platform will assess each case and respond within 30 days, and will carry out complete physical deletion (including at the next backup rotation) subject to applicable legal obligations
- This channel does not affect the default policy for other users; nor will the platform subject data subjects who exercise this right to any adverse treatment
- Exception: where such data concerns a pending dispute, legal proceeding, or investigation by a competent authority (§5 Exceptions), physical deletion will be deferred until the matter concludes
10. Minor Users
The platform's primary use context is instructional activity at institutions of higher education, and most users are adult university students aged 18 or over. Where minor users at partner senior high schools are involved (the first partner school being Taipei Municipal Nangang High School):
- The consent basis is parental/legal-guardian consent (a parental consent form), supplemented by the student's own independent consent
- Research data involving minor users preferentially adopts stricter de-identification standards upon export
- No behavioral profiling or automated decision-making is applied to minor users
11. Breach Notification
- Upon discovery of a personal data breach, the supervisory authority of the affected jurisdiction is notified within 72 hours pursuant to GDPR Art. 33 (in cases governed by the Taiwan PDPA, affected individuals are notified in an appropriate manner pursuant to §12 thereof)
- Where the breach is likely to result in a high risk to data subjects' rights, data subjects are notified directly pursuant to GDPR Art. 34
- The platform's breach notification contact is [email protected]; please mark the subject line [URGENT BREACH NOTIFICATION]
12. Policy Changes
Changes to this policy are managed under the versioning regime of the Data Governance Framework, §6. Material changes (major-version increments) are announced on the Center's home page 30 days before taking effect and notified to registered users by email. Minor-version and patch-level updates are disclosed in the version history section of the Center's home page.
13. Contact Points
| Privacy Contact | [email protected] |
|---|---|
| Breach Notification | [email protected] (subject line: [URGENT BREACH NOTIFICATION]) |
| Academic Collaboration | [email protected] |
For the governance position and role definitions underlying this document, see the Data Governance Framework; for disclosure of external vendors involved in data processing, see the Sub-Processor List.