Data Security & Privacy

Enterprise-grade security designed for higher education. Your data stays protected, compliant, and under your control.

🇪🇺

EU Data Residency

Servers located within the European Union

🔒

End-to-End Encryption

All data encrypted in transit and at rest

SOC 2 Type 2 Certified

Independently audited security controls

📋

GDPR Compliant

UK and EU data protection requirements

🏥

Healthcare Ready

BAA available for healthcare training

🚫

No AI Training

Your data is never used to train models

Security & Privacy FAQs

Where is my data stored?

All conversation data is processed and stored on servers located within the European Union. We use enterprise-grade infrastructure with EU data residency to ensure your data never leaves the region. This supports compliance with UK and EU data protection requirements.

Is the platform GDPR compliant?

Yes. Our platform and practices are designed to align with GDPR requirements, including lawful data processing, adherence to data subject rights, and appropriate security measures. We have a Data Processing Agreement available for institutional customers.

What security certifications do you have?

Our infrastructure providers (Google Cloud, Vercel) are SOC 2 Type 2 certified and ISO 27001 compliant.

Are conversations encrypted?

Yes. All data transmitted to and from the platform uses end-to-end encryption. This protects conversation audio and transcripts both in transit and at rest.

Who can access student conversation recordings?

Only authorised users within your institution can access recordings. Lecturers can review conversations for students enrolled in their classes. Students can access their own recordings for self-reflection. We do not access conversation content except where required for technical support or legal compliance.

How long is data retained?

By default, conversation recordings and transcripts are retained for the duration of your subscription plus a reasonable period for assessment purposes. You can request earlier deletion at any time. We also offer zero-retention configurations for institutions with stricter requirements.

Can I delete student data?

Yes. As a data controller, you can request deletion of any student data at any time. We honour data subject access requests and deletion requests in accordance with GDPR. Contact us at info@hied.ai to initiate a deletion request.

Is the platform suitable for use with sensitive scenarios?

Yes. The platform is designed to handle professionally sensitive training scenarios—such as safeguarding conversations, mental health discussions, or confidential client interactions. Our security measures ensure this content is protected. However, we recommend not using real personal data in practice scenarios; fictional case studies work best.

Do you use conversation data to train AI models?

No. Conversation content submitted through the platform is not used to train our AI models. Your data remains yours and is used solely to deliver the service to you.

What happens if there's a data breach?

We maintain incident response procedures aligned with GDPR requirements. In the unlikely event of a personal data breach, we would notify affected institutions within 72 hours and work with you to fulfil any regulatory reporting obligations.

Can we sign a Data Processing Agreement (DPA)?

Yes. We provide a standard DPA for institutional customers that covers GDPR requirements, data processing purposes, security measures, and sub-processor details. Contact us at info@hied.ai to request one.

Is the platform suitable for NHS or healthcare training?

Our infrastructure supports healthcare compliance requirements. We can provide Business Associate Agreements (BAAs) and configure enhanced privacy settings for healthcare training contexts. Contact us to discuss your specific requirements.

Data Controller Information

Data Controller: HigherEd-AI Ltd

Location: Belfast, Northern Ireland, United Kingdom

Contact: tony@hied.ai

Founder & Director: Tony McGinn

For data protection enquiries, data subject access requests, or to exercise your rights under GDPR, please contact us at the email address above.

Questions about security?

Our team is happy to discuss your institution's specific security and compliance requirements.