Answerable to the same rules you are.
We acknowledge the risks of AI in education and build for the regulation rather than around it. Everything on this page is what a DPO or procurement officer asks about first.
Educational AI falls under Annex III of the Act, and we design accordingly: documented purpose, human oversight of teaching decisions, and transparency to the student that they are talking to an agent.
Lawful basis, data minimisation, retention limits and data-subject requests are handled as first-class product behaviour, not policy text. Interactions are screened and personal data filtered out.
For institutions in the United States we operate as a school official under FERPA: course data is used only to deliver the service you configured, is never sold, and is never used to build a profile of a student outside their course.
The interface targets WCAG 2.1 AA — keyboard operable, screen-reader labelled, and contrast-checked, so a public institution can adopt it without an exemption.
Straight answers, before you ask us.
On infrastructure we control, for the duration you configure. Retention is set per course, and deleting a course removes its conversations and indexed files. Processing locations are named in your data-processing agreement.
It is grounded in what you upload and cites the page. You set how far it may go beyond the syllabus, and you can see every answer it gave.
Course staff, within their course. Interactions used to improve the service are screened and stripped of personal data first.
Nothing to install. For a full rollout we work through your standard data-processing paperwork and answer security questionnaires directly.
No. ChatTutor supports learning; assessment stays with the teacher. That boundary is deliberate and it is what keeps the risk profile low.