Aivo AI Learning Technologies Inc. ("AIVO," "we," "us," or "our") provides an AI‑powered adaptive learning platform engineered for neurodiverse K‑12 learners. This Privacy Policy is the primary, comprehensive description of how we collect, use, disclose, retain, secure, and otherwise process personal information, and of the rights and choices available to learners, parents, teachers, schools, and districts.
Documents that form part of this Policy. Read this Policy together with the Children's Privacy / COPPA Compliance Notice, the FERPA Compliance Notice, and the Cookie Policy. Each is incorporated by reference. Where a more specific rule in those notices is more protective of children or students, that rule controls.
1. Our Privacy Principles
These commitments are binding and apply across all products and services:
- Transparency. We tell you what we collect, why, and with whom we share it.
- No sale or rental of learner or family data. We do not sell or rent personal information about learners or their families, and we do not show third‑party advertising on learner‑directed surfaces.
- No third‑party model training on learner data. We do not use personally identifiable learner information — including chat transcripts, Virtual Brain interactions, assessment results, or other learning data — to train, fine‑tune, or otherwise improve any third‑party AI foundation model.
- Data minimization. We collect only what is reasonably necessary, and we apply heightened minimization on surfaces directed to children.
- Purpose limitation. We use personal information only for the purposes described here or compatible purposes, or as you or your school authorize.
- Security by design and default. We apply reasonable administrative, technical, and physical safeguards proportionate to the sensitivity of the data.
- Meaningful control. Parents and schools can access, correct, export, restrict, and delete the information we hold.
- Accountability. We maintain internal policies, vendor controls, and records to support these commitments.
2. Definitions
| Term | Meaning |
|---|---|
| Aggregated data | Information about a group or category from which individual identities have been removed and that is not linked to any individual or device. |
| Applicable Privacy Law | All privacy/data‑protection laws applicable to our processing, including COPPA, FERPA, IDEA, SOPIPA and other U.S. state student‑privacy laws, the CCPA/CPRA and other U.S. state consumer‑privacy laws, the EU GDPR, the UK GDPR, the Swiss FADP, and similar laws. |
| Virtual Brain | The learner's governed profile: AIVO's structured, reviewable representation of how an individual learner learns, used to tune content difficulty, pacing, modality, and sensory presentation. Families review, correct, export, and can delete it. |
| AI‑Enabled Features | Features that rely on machine‑learning models, including the Virtual Brain, AI tutors, and related tools. |
| Child User / Learner | An individual who uses the learning experience, including a child under 13. |
| De‑identified data | Information that cannot reasonably be used to infer information about, or otherwise be linked to, an identifiable individual or device, and that we maintain and use subject to the controls in Section 13. |
| District Agreement | A written agreement between AIVO and a school, district, or institution governing institutional use of the Services, which may include a Data Processing Addendum ("DPA"). |
| Education record | A record directly related to a student and maintained by an educational agency/institution (or by AIVO on its behalf), as defined by FERPA. |
| Integrated Service | A third‑party sign‑in or rostering service (e.g., Google, Clever, ClassLink) you or your school authorize. |
| Parent / Parent User | A parent or legal guardian who creates and manages a family account. |
| Personal information / personal data | Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, as defined by Applicable Privacy Law. |
| Process / Processing | Any operation performed on personal information (e.g., collection, use, storage, disclosure, deletion). |
| School Personnel | A teacher, administrator, therapist, or other authorized staff member of a school or district. |
| Sensitive information | Categories treated as sensitive under Applicable Privacy Law (e.g., precise geolocation, certain identifiers, health/disability information, information about a known child), handled per Section 5.6. |
| Services | The AIVO website (aivolearning.com), the learning application (app.aivolearning.com), our mobile and tablet applications, any AIVO hardware, and related features and content. |
| Sub‑processor | A vendor that processes personal information on AIVO's behalf to help provide the Services. |
3. Scope and Roles
This Policy applies to personal information AIVO processes through the Services. The applicable rules depend on who you are and how AIVO is used:
- Family / direct‑to‑consumer use. When a Parent creates an account and adds one or more learners, AIVO is the controller/business for that account, subject to the parent‑facing commitments here and in the COPPA Notice.
- School / district use. When AIVO is provided to a learner through a school under a District Agreement or School Account, the school is the controller of student education records under FERPA, and AIVO acts as its service provider/processor and "school official" under the school's direction. In that context the FERPA Notice and the District Agreement/DPA control over this Policy with respect to student data.
By using the Services, you acknowledge you have read this Policy and understand the practices described. If you do not agree, do not use the Services.
4. Use by Children and Students
AIVO is designed to be safe for learners of all ages, including children under 13.
- A child under 13 (or under the age of digital consent in their country) may not create an account independently. A Parent must create the account and provide verifiable parental consent, or a school must establish the account under valid school authorization. See the COPPA Notice.
- Minors aged 13–17 may use the Services only under an account established and supervised by a Parent or school.
- We do not knowingly collect personal information from a child under 13 without verifiable parental consent or valid school authorization. If we learn we have, we will delete it promptly. Report concerns to [email protected].
We do not condition a child's participation on collecting more personal information than is reasonably necessary, and we do not use a known child's information for behavioral advertising or third‑party model training.
5. Information We Collect
We organize the personal information we process into the categories below. The detailed inventory in Section 5.1 maps each category to its data elements, sources, purposes, legal bases, recipients, and retention.
- (A) Identifiers & account data — name or username, email, parent contact email, account ID, age band/date of birth, grade level, password (hashed), language and accessibility preferences.
- (B) Learner profile & setup data — questionnaire responses about needs, communication style, sensory profile, and learning preferences; selected functioning level; IEP‑related indicators a Parent or School Personnel chooses to provide.
- (C) Learning content & interaction data — assessment responses, lessons/exercises attempted, answers, hints requested, AI‑tutor messages/prompts and responses, progress, mastery signals, and Virtual Brain session data.
- (D) Device, log & technical data — IP address, device identifiers, browser/app type and version, operating system, referring/exit pages, timestamps, content viewed, features used, session and focus metrics, crash and diagnostic logs.
- (E) Cookie & similar‑technology data — identifiers and preferences set via cookies, local storage, pixels, and SDKs (see the Cookie Policy).
- (F) Roster & school data — name, grade, class assignment, teacher of record, school/district identifier, SSO identifiers, and IEP indicators provided by the school.
- (G) Payment & billing data — tokenized payment reference, card brand, last four digits, billing postal code, billing contact, transaction history (full card numbers are handled by our payment processor, not stored by AIVO).
- (H) Communications & support data — emails, support tickets, survey responses, and their contents.
- (I) Marketing & contact data (adults) — newsletter subscriptions, lead‑form submissions, and engagement metrics on adult‑facing pages.
- (J) Assistive‑input signals — input derived from AAC devices, switch access, or eye‑gaze used to operate the interface (see Section 5.5).
5.1 Data inventory (what, why, how long, who)
| Category | Representative data elements | Primary purpose(s) | Legal basis | Typical recipients | Retention (general) |
|---|---|---|---|---|---|
| (A) Identifiers & account | Name/username, email, parent email, age band, grade, hashed password, preferences | Create/secure account; authenticate; communicate | Contract; LI (security) | Hosting, email, support sub‑processors | Life of account; deleted/de‑identified after closure (see §12) |
| (B) Learner profile & setup | Questionnaire answers, sensory profile, functioning level, IEP indicators | Personalize learning; configure accommodations | Contract; Consent/Legal (sensitive); school direction | Authorized parent/school; hosting | While active; deleted on request/closure |
| (C) Learning & interaction | Assessments, answers, hints, AI‑tutor messages, progress, Virtual Brain data | Deliver & adapt learning; report progress | Contract; LI (improve via de‑identified) | Authorized parent/school; AI model providers (scoped); hosting | While active; deleted on request/closure |
| (D) Device, log & technical | IP, device IDs, browser/OS, logs, session metrics | Operate, secure, debug, prevent abuse | LI (security/reliability); Legal | Hosting, monitoring sub‑processors | Limited period appropriate to security/reliability |
| (E) Cookie data | Cookie/SDK identifiers, preferences | Sign‑in, preferences, analytics (adult), limited marketing (adult) | Consent (non‑essential); LI/Contract (essential) | Analytics/marketing sub‑processors (adult only) | Per Cookie Policy durations |
| (F) Roster & school | Name, grade, class, teacher, school ID, SSO ID, IEP indicators | Provision school accounts; personalize; report | Contract (with school); school direction | Authorized school; SSO/rostering; hosting | Per District Agreement; returned/deleted on termination |
| (G) Payment & billing | Token, card brand, last 4, billing ZIP, invoices | Process payments; prevent fraud; tax/accounting | Contract; Legal | Payment processor; accounting | As required for tax/audit (typically several years) |
| (H) Communications & support | Email/ticket contents, survey responses | Provide support; improve service | LI; Contract | Support/email sub‑processors | As needed plus a limited period |
| (I) Marketing & contact (adults) | Subscription status, lead data, engagement | Outreach to parents/schools; measure campaigns | Consent; LI | Email/marketing sub‑processors | Until unsubscribe + limited period |
| (J) Assistive‑input signals | Eye‑gaze selection coordinates, switch/AAC events | Operate the interface for the learner | Contract; Consent (if biometric law applies) | None beyond operation; hosting | Not retained as a biometric template (see §5.5) |
Representative, not exhaustive; specific elements vary by configuration and plan.
5.2 Information you provide
You provide information when you register, complete the intake questionnaire, configure a learner, use the learning experience, subscribe to a paid plan, contact support, respond to surveys, or subscribe to communications.
5.3 Information collected automatically
We and our sub‑processors automatically collect Category (D) and (E) data via your device and via cookies and similar technologies, as detailed in the Cookie Policy. On child‑directed surfaces we limit automatic collection to what is necessary to operate and secure the Services (COPPA internal‑operations exception).
5.4 Information from schools and Integrated Services
Schools provide Category (F) data. If you sign in or are provisioned through an Integrated Service (Google, Clever, ClassLink), we receive account/roster information consistent with the permissions you or your school granted; you can manage what is shared in that service's settings.
5.5 Assistive‑input signals and biometric‑privacy laws
AIVO supports AAC devices, switch access, and eye‑gaze/eye‑tracking control. Where a learner uses eye‑gaze or similar input, AIVO uses the resulting signals only to operate the interface (for example, to determine where on screen the learner is selecting). We do not create a biometric template that identifies the individual, do not use these signals for advertising or profiling, and do not sell or share them. Some jurisdictions regulate "biometric identifiers/information" (for example, the Illinois Biometric Information Privacy Act and similar state laws). If any feature would collect or use a biometric identifier as defined by applicable law, we will provide the specific notice and obtain the written consent that law requires before doing so, and we will publish a retention‑and‑destruction schedule for that data.
5.6 Sensitive information
Some information we process may be "sensitive" under Applicable Privacy Law — for example, disability/special‑education indicators, or the fact that a user is a known child. We collect sensitive information only as necessary to provide and personalize the Services or as directed by a school, apply heightened safeguards, and do not use it to infer characteristics for advertising. Please do not submit unnecessary sensitive information (for example, detailed medical records) into free‑text fields.
6. Sources of Information
We obtain personal information from: (a) you (account holders, parents, School Personnel, and — under supervision — learners); (b) your school or district; (c) Integrated Services you authorize; (d) automatic collection from your device and our Services; (e) our service providers acting on our behalf; and (f) payment processors for billing data.
7. How We Use Information
We use personal information to:
- Provide and operate the Services — create and manage accounts; authenticate; deliver lessons, assessments, AI tutors, and Virtual Brain personalization.
- Personalize learning — tune difficulty, pacing, modality, and sensory presentation to a learner's needs and functioning level.
- Support educators and parents — provide progress reporting and, where authorized, IEP‑aligned tracking and collaboration tools.
- Process payments — manage subscriptions and trials, prevent payment fraud, and send transactional notices.
- Secure the Services — detect, investigate, and prevent fraud, abuse, security incidents, and Terms violations.
- Maintain and improve — debug, analyze, and improve features using aggregated or de‑identified data wherever feasible.
- Communicate — send service, security, and account messages, and (with appropriate consent) optional product communications.
- Comply with law — meet obligations under COPPA, FERPA, IDEA, SOPIPA, GDPR/UK GDPR, CCPA/CPRA, tax, and accounting requirements, and respond to lawful requests.
We do not use personal information for purposes incompatible with those above without providing notice and, where required, obtaining consent.
8. Legal Bases for Processing (EEA, UK, Switzerland)
Where the EU/UK GDPR or Swiss FADP applies, we rely on the bases below. Section 5.1 maps bases to categories.
| Processing activity | Legal basis |
|---|---|
| Creating and operating accounts; delivering the learning experience | Performance of a contract (Art. 6(1)(b)) |
| Securing the Services; preventing fraud/abuse; product analytics on de‑identified data; account communications | Legitimate interests (Art. 6(1)(f)), balanced against your rights |
| Non‑essential cookies; optional marketing; processing requiring consent | Consent (Art. 6(1)(a)) |
| Tax, accounting, legal compliance, and responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
| Special‑category/sensitive data (e.g., disability indicators), where applicable | Explicit consent (Art. 9(2)(a)) or another Art. 9 condition; for students, under the school's instruction and protections |
You may withdraw consent at any time without affecting the lawfulness of prior processing. We balance legitimate interests against your rights and provide an objection mechanism (Section 15).
9. AI, the Virtual Brain, and Automated Decision-Making
Building the learner's model. We use Category (B) and (C) data to build and continuously update that learner's own Virtual Brain and to operate the AI tutors for that learner and their authorized parent/school.
Model providers. AI‑Enabled Features may call large‑language‑model and other AI APIs operated by third parties. These providers are contractually prohibited from using learner inputs or outputs to train, fine‑tune, or improve their public foundation models, and we scope prompts to avoid sending unnecessary personally identifiable information.
Improving our own service. We may use aggregated or de‑identified data to evaluate and improve our own models and the Services. We do not use personally identifiable learner data to train third‑party foundation models.
Automated decisions and profiling (GDPR Art. 22). AIVO uses automated processing to personalize learning (for example, adjusting difficulty or recommending the next activity). These adjustments support, and do not replace, human judgment: parents, teachers, and therapists retain oversight and control, and Virtual Brain state can be reviewed and, where supported, snapshotted or rolled back. We do not use AI‑Enabled Features to make decisions that produce legal or similarly significant effects about a learner without meaningful human involvement. Where Art. 22 applies, you may request human review of, express your view on, or contest an automated adjustment by contacting [email protected].
10. How We Disclose Information
AIVO does not sell or rent personal information about learners or their families. We disclose personal information only as follows:
| Recipient category | What is shared | Why | Safeguards |
|---|---|---|---|
| Service providers / sub‑processors | Categories as needed for the function | Hosting, monitoring, analytics (adult), email, support, payments | Written contracts limiting use to providing services to us; confidentiality and security obligations |
| AI model providers | Scoped prompt content | Power AI‑Enabled Features | Contractual ban on training/improving public models on our data; data minimization |
| Schools & parents | The relevant learner's activity, results, Virtual Brain progress | Provide the service to the authorized parent/school | Access governed by account roles and District Agreement |
| Authorized collaborators | Learner progress you choose to share | Enable a therapist/tutor invited by the parent/school | Permission‑based; revocable |
| Integrated Services | Identity/roster data you authorize | Sign‑in and rostering | Per your/your school's authorization |
| Legal & safety | Information reasonably necessary | Comply with law; enforce Terms; protect rights/safety | Good‑faith, narrowly tailored; school notice where permitted |
| Corporate transactions | Information as part of a transaction | Merger, acquisition, financing, or asset sale | Successor bound to honor learner/student commitments |
| With consent | As described at the time | Other purposes you authorize | Your, your parent's, or your school's consent |
We do not disclose Child User information for any third party's own marketing, advertising, or profiling.
11. Sub‑Processors
AIVO uses a limited set of vetted sub‑processors, each bound by confidentiality, use‑limitation, and security obligations. Representative categories: cloud hosting/storage; AI model providers; error/performance monitoring; first‑party analytics; transactional email; customer support tooling; payment processing; and SSO/rostering. A current, itemized sub‑processor list (provider, function, data categories, location) is available through the Trust Center or on request to [email protected]. Schools may request advance notice of sub‑processor changes as provided in the District Agreement.
12. Data Retention
We retain personal information only as long as necessary for the purposes described, then delete or de‑identify it. Specific periods vary by legal requirement and District Agreement.
| Data category | Retention trigger | General period |
|---|---|---|
| Account & profile (A) | Account closure | Deleted or de‑identified after closure on our standard retention schedule, subject to legal holds |
| Learner profile, learning & Virtual Brain (B, C) | Verified deletion request or account closure | Deleted or de‑identified after a verified request on our standard retention schedule |
| School/student data (F) | District Agreement termination or school instruction | Returned and/or deleted within the period set by the District Agreement |
| Device/log/technical (D) | Time‑based | Retained for a limited period appropriate to security and reliability |
| Cookie data (E) | Per technology | See Cookie Policy |
| Payment/billing (G) | Tax/accounting requirements | As required by tax and accounting law |
| Communications/support (H) | Resolution + limited period | Resolution plus a limited period |
| Marketing/contact (I) | Unsubscribe + limited period | Until unsubscribe + limited period |
| Backups | Backup rotation | Deleted on the standard backup cycle after primary deletion |
Bracketed periods are defaults to confirm and finalize. Parents and schools may request deletion at any time (Section 16); we honor verified requests under COPPA, FERPA, and other Applicable Privacy Law.
13. De‑Identification and Aggregation
When we de‑identify data, we (a) take reasonable measures to ensure the data cannot be associated with an individual or device, (b) publicly commit to maintain and use it only in de‑identified form, and (c) contractually prohibit recipients from re‑identifying it. We do not attempt to re‑identify de‑identified data except to test our de‑identification processes. We use aggregated and de‑identified data to operate, secure, analyze, and improve the Services and for research consistent with this Policy, FERPA (34 CFR § 99.31(b)), and applicable state law.
14. Security
We use commercially reasonable administrative, technical, and physical safeguards proportionate to the sensitivity of the data, including encryption of data in transit (TLS) and encryption at rest for sensitive data stores, role‑based and least‑privilege access, multi‑factor authentication for administrative access, secure development practices, logging and monitoring, regular security testing, vendor due diligence, and an incident‑response program. No system is perfectly secure, and we cannot guarantee absolute security. For details, see the Security page. Report concerns to [email protected].
15. Your Rights and Choices
Depending on your location and role, you may have rights to:
- Know/Access — obtain confirmation of processing and a copy of the personal information we hold, including categories, sources, purposes, and recipients.
- Correct — fix inaccurate or incomplete information.
- Delete — request deletion of your information (subject to legal exceptions and retention).
- Portability — receive certain information in a structured, commonly used, machine‑readable format and, where feasible, have it transmitted to another controller.
- Restrict/Object — restrict or object to certain processing, including processing based on legitimate interests and direct marketing.
- Withdraw consent — where processing is based on consent.
- Opt out of "sale"/"sharing"/targeted advertising — note AIVO does not sell or share personal information or use it for cross‑context behavioral advertising.
- Limit use of sensitive information — where provided by law.
- Non‑discrimination / no retaliation — for exercising your rights.
- Lodge a complaint — with a supervisory authority or regulator.
Role‑specific routing: Parents may exercise these rights for a Child User. Where AIVO is used under a District Agreement, requests to access, correct, or delete education records are directed to and handled by the school, and AIVO assists the school.
16. How to Exercise Your Rights
- Submit a request to [email protected] (or [email protected] for child/student data). Tell us the right you wish to exercise and the account/learner involved.
- Verification. We verify your identity and authority before acting, using information associated with the account; for parental requests we confirm the parent relationship; for authorized‑agent requests we require proof of authorization.
- Response timing. We respond within the timeframe required by Applicable Privacy Law — generally within 45 days under U.S. state laws (extendable by an additional 45 days with notice) and within one month under the GDPR/UK GDPR (extendable by two further months for complex requests, with notice).
- Fees. Most requests are free; we may charge a reasonable fee or decline a manifestly unfounded or excessive request, as permitted by law, and will explain any such decision.
- Appeals. Where a U.S. state law provides an appeal right, you may appeal a denial by replying to our decision; we will inform you of the outcome and of your right to contact your state attorney general.
You can also manage much of your information directly in your account (Section, below).
16.1 Account settings and controls
Within your account you can update contact information, change your password, manage notification preferences, configure accessibility/sensory settings, view and download learning records, manage collaborator access, and (subject to retention) delete your account. Parent Users manage these settings for linked Child Users. School Personnel manage rosters and student‑level settings within their dashboard, subject to district policy and the District Agreement.
17. U.S. State Privacy Disclosures
17.1 California (CCPA/CPRA and SOPIPA)
Categories collected (last 12 months) and the corresponding statutory categories: identifiers (A, F); customer‑records information (A, G); commercial information (G); internet/network activity (D, E); geolocation (approximate, from IP) (D); professional/education information (B, C, F); inferences for personalization (C); and sensitive personal information limited to disability/special‑education indicators and the fact of being a known child (B, F). Sources, purposes, and recipients are described in Sections 5–11.
Sale/Share. AIVO does not "sell" or "share" personal information for cross‑context behavioral advertising, and does not knowingly sell or share the personal information of consumers under 16.
Sensitive personal information. We use it only for permitted business purposes (to provide and secure the Services) and do not use it to infer characteristics; we therefore are not required to offer, but will honor, a "Limit the Use of My Sensitive Personal Information" request.
SOPIPA. As a K‑12 service, we do not use covered student information for targeted advertising, do not build non‑educational profiles, and do not sell student information.
Your rights (know, access, delete, correct, opt‑out, limit, non‑discrimination) and how to exercise them are in Sections 15–16. Authorized agents may submit requests with proof of authorization. We honor Global Privacy Control on adult‑facing surfaces where required.
17.2 Other U.S. states
Residents of states with comprehensive privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, and others as they take effect — may have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. Many of these laws exempt FERPA‑covered data and certain education/nonprofit processing; where they apply to our processing, we honor the rights they provide. Several require honoring universal opt‑out signals (e.g., GPC), which we do on adult‑facing surfaces where applicable. Submit requests under Section 16; appeal rights are described in Section 16(5).
18. EEA, UK, and Swiss Disclosures (GDPR/FADP)
If you are in the EEA, UK, or Switzerland: our legal bases are in Section 8; your rights are in Section 15 (access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and the right to lodge a complaint with your supervisory authority). For data‑protection inquiries, contact [email protected]. International transfers are addressed in Section 19. We do not engage in solely automated decision‑making with legal or similarly significant effects without the safeguards described in Section 9.
19. International Data Transfers
AIVO operates the Services in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States and other locations where we or our sub‑processors operate. Where we transfer personal data out of the EEA, UK, or Switzerland, we use appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, supplemented by additional technical and organizational measures (such as encryption and access controls) and a transfer‑impact assessment where appropriate. You may request more information about our transfer mechanisms at [email protected].
20. Other Jurisdictions
Residents of jurisdictions such as Canada (PIPEDA/provincial laws), Brazil (LGPD), and Australia (Privacy Act) may have additional rights under local law. Contact [email protected] to exercise any such rights; we will respond as required by applicable law.
21. Cookies and Similar Technologies
AIVO uses cookies and similar technologies (local storage, pixels, SDKs) primarily on adult‑facing surfaces, classified as Strictly Necessary, Functional, Performance/Analytics, and limited Targeting (adult‑only). On child‑directed surfaces we use only Strictly Necessary cookies under COPPA's internal‑operations exception. Manage preferences via our cookie banner, browser controls, and the footer preference link. Full detail — including an itemized cookie inventory and durations — is in the Cookie Policy.
22. Third‑Party Links and Services
The Services may link to or integrate with third‑party websites/services not operated by AIVO. This Policy does not apply to them, and we are not responsible for their practices. Review the privacy policies of any third‑party service you use.
23. Applicant and Personnel Information
If you apply for a role at AIVO through our portal, an external recruiting platform (e.g., Greenhouse, Lever, LinkedIn), an event, or a referral, we collect: contact details; professional and employment history (resume/CV, cover letter, work samples); education information; references; voluntary EEO information (where permitted and never used in hiring decisions); and, where required for the role and authorized in writing, background‑check information collected by a vetted screening provider. We use this to evaluate your application, communicate with you, comply with employment/immigration/equal‑opportunity laws, and onboard you if hired; with your separate consent, we may keep your application on file to consider you for future roles. We share it only with personnel involved in hiring, recruiting/background‑check vendors under contract, and as required by law. We do not sell applicant information. Withdraw or request deletion at [email protected].
24. Data Breach Notification
We maintain an incident‑response program (see the Security page). If a security incident affects personal information, we will notify affected individuals, parents, and/or schools, and any regulators, without undue delay and within the timeframes required by applicable law (for example, GDPR's 72‑hour regulator notification where the breach is reportable, and applicable U.S. state breach‑notification deadlines). For schools, we coordinate notification consistent with FERPA, applicable state data‑breach laws, and the District Agreement, and we provide the information schools need to meet their own obligations.
25. Changes to This Policy
We may update this Policy. For material changes, we will post a notice on the Services and/or email the address associated with your account, and — where COPPA requires — obtain renewed parental consent before applying material changes to the collection or use of children's information. The "Last updated" date indicates the latest revision; we will keep prior versions available on request. Continued use after changes take effect constitutes acceptance.
26. How to Contact Us
| Topic | Contact |
|---|---|
| General privacy questions and data‑subject requests | [email protected] |
| COPPA, FERPA, and other student‑data matters | [email protected] |
| Security reports | [email protected] |
| EEA/UK/Swiss data‑protection contact | [email protected] |
Aivo AI Learning Technologies Inc. 1400 Van Buren Street NE, Suite 200 Minneapolis, MN 55413, USA
This Policy describes our practices for transparency. Specific contractual commitments to a school or district are set out in the applicable District Agreement and DPA, which control over this Policy with respect to that institution's data.
# Annexes (Detailed Schedules)
These annexes provide element‑level granularity supporting the body of this Policy. Bracketed values are configuration‑ or operations‑specific and should be confirmed before publication.
Annex A — Detailed Processing Register (Element‑Level)
| # | Data element | Where collected | Source | Purpose(s) | Sensitive? | Basis | Recipients | Retention |
|---|---|---|---|---|---|---|---|---|
| 1 | Parent/guardian full name | Registration | U | Account ownership; billing; notices | N | K | Hosting, email, payment | Life of account plus a deletion window |
| 2 | Parent email address | Registration; direct notice | U | Authenticate; COPPA notice/consent; service messages | N | K,O | Hosting, email | Life of account plus a deletion window |
| 3 | Parent password (hashed+salted) | Registration | U | Authentication | N | K | Hosting | Life of account |
| 4 | Learner display name/username | Learner setup | U,S | Identify learner in account | N | K | Hosting, authorized parent/school | Life of account plus a deletion window |
| 5 | Learner age band / grade | Learner setup; roster | U,S | Age‑appropriate content; protections | N | K | Hosting, authorized parent/school | Life of account |
| 6 | Learner date of birth (if provided) | Learner setup | U | Age verification where required | N | K,O | Hosting | Minimized; [as required] |
| 7 | Functioning level selection | Setup; adaptive engine | U,S,A | Decouple content vs. interface complexity | N | K | Hosting | Life of account |
| 8 | Sensory/display mode (Standard/Calm/High Contrast) | Setup; in‑app | U,L | Accessibility personalization | N | K | Hosting | Life of account |
| 9 | Intake questionnaire responses | Onboarding | U,S | Personalize learning; configure accommodations | Y* | K,E | Hosting, authorized parent/school | Life of account plus a deletion window |
| 10 | Disability / special‑education indicators | Setup; roster (school) | U,S | Personalize; support IEP tracking | Y | E,K,S‑direction | Hosting, authorized school/IEP team | Per school instruction |
| 11 | IEP goals/accommodations (if provided) | School config | S | Support IEP‑aligned tracking | Y | S‑direction | Authorized school/IEP team | Per District Agreement |
| 12 | Assessment items & responses | Learning use | L | Measure mastery; adapt | N | K | Hosting; authorized parent/school | Life of account plus a deletion window |
| 13 | Lessons/exercises attempted & answers | Learning use | L | Deliver & adapt learning | N | K | Hosting; authorized parent/school | Life of account plus a deletion window |
| 14 | Hints requested | Learning use | L,A | Scaffold learning | N | K | Hosting | Life of account |
| 15 | AI‑tutor prompts & responses | AI features | L,A | Provide tutoring; personalize | N* | K | Hosting; AI model providers (scoped) | Life of account plus a deletion window |
| 16 | Virtual Brain model state / session data | Adaptive engine | A,L | Personalize difficulty, pacing, modality | N* | K | Hosting | Life of account; snapshot/rollback supported |
| 17 | Progress / mastery signals | Adaptive engine | A | Reporting; adaptation | N | K | Hosting; authorized parent/school | Life of account plus a deletion window |
| 18 | Session & focus metrics | App telemetry | A | Operate; improve (de‑identified) | N | F | Hosting, monitoring | Limited period |
| 19 | IP address | All surfaces | A | Security; fraud prevention; approximate geo | N | F,O | Hosting, monitoring | Limited period (security logs) |
| 20 | Device identifier / type | All surfaces | A | Operate; secure; debug | N | F | Hosting, monitoring | Limited period |
| 21 | Browser/app type & version, OS | All surfaces | A | Compatibility; security | N | F | Hosting, monitoring | Limited period |
| 22 | Crash & diagnostic logs | Apps | A | Reliability; debugging | N | F | Hosting, monitoring | Limited period |
| 23 | Cookie/SDK identifiers | Adult surfaces | A | Sign‑in; preferences; analytics (adult) | N | C,F | Analytics/marketing (adult only) | Per Cookie Policy |
| 24 | Roster: class, teacher of record, school ID | School provisioning | S,I | Provision; personalize; report | N | K,S‑direction | Authorized school; SSO/rostering | Per District Agreement |
| 25 | SSO identifiers (Google/Clever/ClassLink) | SSO sign‑in | I | Authenticate; roster | N | K | Hosting; SSO provider | Life of account |
| 26 | Payment token / card brand / last 4 | Checkout | U,P | Process payments; fraud prevention | N | K,O | Payment processor; accounting | As required by tax law |
| 27 | Billing postal code / contact | Checkout | U | Tax; invoicing; fraud signals | N | K,O | Payment processor; accounting | [5–7]y |
| 28 | Transaction / invoice history | Billing | A,P | Accounting; support; tax | N | K,O | Accounting | [5–7]y |
| 29 | Support tickets & email content | Support | U,S | Provide support; improve | N* | F,K | Support/email vendors | Resolution plus a limited period |
| 30 | Survey responses | Feedback | U,S | Improve service | N | C,F | Survey/email vendors | Limited period |
| 31 | Marketing subscription status (adults) | Sign‑up forms | U | Outreach to parents/schools | N | C,F | Email/marketing vendors | Until unsubscribe + limited |
| 32 | Collaborator (therapist/tutor) identity | Invitation | U,S | Enable authorized collaboration | N | K | Authorized parent/school | While access granted |
| 33 | Eye‑gaze selection coordinates | Assistive input | L,A | Operate the interface for the learner | N** | K,C | None beyond operation; hosting | Not retained as biometric template (§5.5) |
| 34 | Switch/AAC input events | Assistive input | L,A | Operate the interface | N** | K | Hosting | Transient/operational |
| 35 | Applicant data (if you apply for a role) | Careers portal | U,V | Evaluate application; comply with law | N* | K,O,C | Recruiting/background vendors | Per §23 |
\ May contain sensitive details if a user volunteers them in free text; we ask users not to submit unnecessary sensitive information. \ Used only to operate the interface; not used to create a biometric identifier. If a feature would collect a biometric identifier as defined by applicable law, we provide the required notice and obtain consent first.*
Annex B — U.S. State Privacy Rights & Response Windows
General framework; FERPA‑covered student data and certain education/nonprofit processing may be exempt under several state laws, in which case those exemptions apply. Where a law applies to our processing, we honor the rights it grants.
| State / Law | Core consumer rights | Response deadline | Extension | Cure period (as applicable) | Universal opt‑out honored |
|---|---|---|---|---|---|
| California (CCPA/CPRA) | Know, access, delete, correct, opt‑out of sale/share, limit sensitive PI, non‑discrimination | 45 days | +45 days w/ notice | [As provided] | Yes — GPC (adult surfaces) |
| Virginia (VCDPA) | Access, correct, delete, portability, opt‑out (targeted ads/sale/profiling), appeal | 45 days | +45 days | — | Not mandated; we honor opt‑outs |
| Colorado (CPA) | Access, correct, delete, portability, opt‑out, appeal | 45 days | +45 days | [60‑day cure (sunset per statute)] | Yes — universal opt‑out signal |
| Connecticut (CTDPA) | Access, correct, delete, portability, opt‑out, appeal | 45 days | +45 days | [Cure (sunset per statute)] | Yes — universal opt‑out signal |
| Utah (UCPA) | Access, delete, portability, opt‑out (targeted ads/sale) | 45 days | +45 days | [30‑day cure] | Not mandated |
| Texas (TDPSA) | Access, correct, delete, portability, opt‑out, appeal | 45 days | +45 days | [30‑day cure] | Yes — universal opt‑out signal |
| Oregon (OCPA) | Access (incl. list of specific third parties), correct, delete, portability, opt‑out, appeal | 45 days | +45 days | [Cure (sunset per statute)] | Yes |
| Montana (MCDPA) | Access, correct, delete, portability, opt‑out, appeal | 45 days | +45 days | [Cure (sunset per statute)] | Yes |
| Other states (as effective) | Generally access/correct/delete/portability/opt‑out/appeal | Typically 45 days | Typically +45 days | Varies | Where required |
How to appeal. If we decline a request, reply to our decision to appeal; we will respond within the period the applicable law requires (commonly 45–60 days) and inform you how to contact your state attorney general.
Annex C — Identity Verification Tiers
To protect against unauthorized access, we match the verification we require to the sensitivity and risk of the request.
| Request type | Verification we typically require | Rationale |
|---|---|---|
| Update preferences / unsubscribe | Control of the account email | Low risk |
| Access/portability of account data | Confirm control of account credentials/email; match account attributes | Moderate risk |
| Access/deletion of a child's data (family account) | Confirm parental relationship + control of the parent account; additional confirmation where doubt exists | High sensitivity (child data) |
| Deletion of account/learning data | Re‑authenticate; confirm intent; cooling‑off confirmation | Irreversible action |
| Authorized‑agent request | Written authorization from the consumer; verification of both agent and consumer where required | Prevent fraudulent agents |
| Student‑record request (school account) | Routed to and authenticated by the school | School controls the education record |
We do not require you to create an account solely to make a request, and we do not use information collected for verification for any other purpose.
Annex D — International Transfer Safeguards by Recipient Type
| Recipient type | Location(s) | Transfer mechanism / safeguard |
|---|---|---|
| AIVO (controller/processor) | United States | SCCs / UK IDTA where receiving EEA/UK/Swiss data; supplementary measures (encryption, access controls); transfer‑impact assessment |
| Cloud hosting sub‑processor | See the subprocessor register | SCCs (processor module) flowed down; provider certifications |
| AI model provider(s) | See the subprocessor register | SCCs flowed down; contractual ban on training/improving public models; data minimization |
| Payment processor | See the subprocessor register | SCCs where applicable; PCI‑DSS environment |
| Support/email vendors | See the subprocessor register | SCCs where applicable; confidentiality & security terms |
You may request copies of the relevant transfer mechanism (with commercial terms redacted) at [email protected].
Annex E — Notice at Collection Summary (CCPA)
At or before collection, we collect the categories in Section 17.1 for the purposes in Section 7, retain them per Section 12 and Annex A, and do not sell or share personal information. This Policy serves as our notice at collection; a short‑form notice may also be presented at the point of collection with a link here.