How we protect personal data under UK and EU data protection regulations.
Last updated: 26 January 2026
Compliant with UK Data Protection Act 2018
Compliant with EU General Data Protection Regulation
Data Processing Agreement for institutional customers
We only collect data necessary for the service
Delete your data at any time upon request
Export your data in machine-readable format
HigherEd-AI Ltd is the data controller responsible for your personal data.
For organisations using HiEd.ai through an institutional subscription, the institution typically acts as the data controller for student data, with HiEd.ai acting as a data processor under a Data Processing Agreement (DPA).
We process personal data under the following lawful bases as defined by Article 6 of the GDPR:
Processing necessary to provide our AI tutoring services:
Processing necessary for our legitimate business interests:
Processing required to comply with legal requirements:
Where required, we obtain explicit consent for:
| Data Category | Purpose | Retention |
|---|---|---|
| Name, Email | Account identification | Duration of account |
| Voice recordings | AI conversation delivery | As per institutional agreement |
| Conversation transcripts | Assessment & learning review | As per institutional agreement |
| Class enrolment data | Access control | Duration of enrolment |
| Data Category | Purpose | Retention |
|---|---|---|
| Email address | Account identification | Until account deletion |
| Voice recordings | AI tutoring sessions | 90 days or until deletion request |
| Conversation history | Conversation memory feature | Until account deletion |
| Payment information | Processing purchases | As required by law (6 years) |
Under UK and EU data protection law, you have the following rights regarding your personal data:
Request a copy of all personal data we hold about you. We will respond within 30 days.
Request correction of inaccurate personal data we hold about you.
Request deletion of your personal data ("right to be forgotten").
Request limitation of processing while we verify accuracy or legitimacy.
Receive your data in a structured, machine-readable format (JSON).
Object to processing based on legitimate interests or for direct marketing.
To exercise any of these rights, contact us at dpo@hied.ai. We will respond within 30 days. For institutional users, please contact your institution's data protection officer first.
We use the following third-party service providers (sub-processors) to deliver our services. All sub-processors are contractually bound to process data only as instructed and to implement appropriate security measures.
| Sub-Processor | Purpose | Location | DPA |
|---|---|---|---|
| ElevenLabs Inc. | AI voice synthesis and conversational AI | EU (via EU data residency option) | ✓ |
| Google Cloud Platform (Firebase) | Authentication, database, file storage | EU (europe-west1) | ✓ |
| Vercel Inc. | Website hosting and serverless functions | EU region deployment | ✓ |
| Stripe Inc. | Payment processing (Private Learner accounts) | EU/US with SCCs | ✓ |
We notify institutional customers of any changes to our sub-processor list. Individual users can request notification of changes by emailing dpo@hied.ai.
We prioritise keeping data within the UK and EU. Where data transfer outside the EEA is necessary, we ensure appropriate safeguards are in place:
Copies of relevant Standard Contractual Clauses are available upon request.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
For more details, see our Security & Privacy page.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
Our incident response procedures are tested annually and align with GDPR Article 33 & 34 requirements.
For educational institutions and organisations, we provide a comprehensive Data Processing Agreement that covers:
To request a DPA: Email info@hied.ai with your institution details. We typically process DPA requests within 5 business days.
If you are not satisfied with our response to a data protection concern, you have the right to lodge a complaint with a supervisory authority:
Website: ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
EU residents may also contact their local data protection authority.
For any questions about this GDPR compliance information or to exercise your data rights:
We aim to respond to all data protection enquiries within 5 business days, and to complete data subject access requests within 30 days as required by GDPR.
We provide comprehensive DPAs for institutional customers. Get in touch to request one.