National Central University
Uedu Main Site
Explore Uedu
Student Console
Register as Member/Login
Research Informed Consent Center
Survey Center
Teacher Console
Course Setup
Support & Messages
Uptime Data

UeduGPTs

--

Jupyters

7

Local AI

--

Uedu Code

--

CISOSE26 Local AI Uedu Code UG26
中央大學 AQI 71 25°C PM2.5 15
AI Reply Desktop Notifications

Show a desktop notification when the AI TA finishes replying

Chat Message Notifications

Notify me when classmates post messages in the forum

Sound notification

Play an alert sound whenever there is a new notification

Foundation · Data Governance Framework

資料治理框架

This document discloses the governance principles of the Uedu platform, the division of roles and responsibilities, data classification, applicable law, and the relationship with GDPR and Taiwan's Personal Data Protection Act. It serves as the basis for other governance documents.

Document Versionv1.0
Effective Date2026-04-10
Last Updated2026-05-11
Published Online2026-05-11
Legal Review StatusSelf-authored; partner-side review invited
LanguageTraditional Chinese (legal baseline version)

1. Governance stance

Uedu is an AI-assisted teaching platform focused on higher education contexts. The platform simultaneously bears three responsibilities: providing stable teaching services to learners, providing teaching design and analytics tools to Instructors, and providing ethically reviewed data collaboration channels to researchers. The purpose of this governance document is to enable the above three parties, as well as future collaborators, to understand Uedu's position on data handling and the boundaries of responsibility before cooperation begins.

The governance design of this platform is based on the stricter requirements of the EU General Data Protection Regulation (GDPR) and Taiwan's Personal Data Protection Act (PDPA), and is extended to cover the revised Swiss Federal Act on Data Protection (nFADP) and Singapore's Personal Data Protection Act (PDPA), so as to cover current international research collaborations.

This document describes mechanisms that have already been implemented. Planned items not yet implemented are not included in this centre; when implementation is completed, the relevant sections will be updated in step and the version number increased.

1.1 Core principles

PrinciplesDescription
Lawful Basis FirstAlways confirm a lawful basis before any collection; individual consent is the default basis for sensitive categories such as learning traits, physiological sensing and in-depth interviews.
Purpose limitation (Purpose Limitation)The purpose disclosed at the time of collection is the sole basis for processing; processing beyond the original purpose requires separate consent or a new lawful basis.
Data MinimisationThe dataset exported for research will, in principle, be the de-identified version; special exceptions are subject to case-by-case ethics review.
Layered RetentionDirectly identifiable personal data, anonymised research data, and researchers' external exports are subject to three separate retention periods and handling processes, which are detailed in the Privacy and Data Retention Policy.
Transparent & auditable (Transparency & Auditability)Governance stance, sub-processors, IRB summary, and research collaboration terms are published in this framework; external research organisations may review them directly without separate enquiry.
Explicit Research ExceptionFor academic research use, the research exemption under GDPR Art. 89 and the corresponding local law applies, but IRB review is required and the case number must be disclosed in this centre.

2. Role definitions and responsibility split

Under the context of GDPR Art. 4 and Taiwan's Personal Data Protection Act, the main role definitions involved in Uedu platform operations are as follows. This section is central to the governance position; please read each item against the source.

2.1 Data Controller

The data controller of the Uedu platform is Chia-Kai Chang, PhD (Chang Chia-kai), who operates Uedu in his personal capacity as the platform owner and developer. His association with National Central University is limited to the scope of research deployment and academic activities, and does not constitute joint controllership over the Uedu platform or its data infrastructure.

Original wording — controller declaration Uedu is operated by Chia-Kai Chang, PhD, in his personal capacity as the platform owner and developer. Affiliation with National Central University relates to research deployment and academic activities, but does not constitute joint controllership over the Uedu platform or its data infrastructure.

2.2 Data Processor

The Uedu platform commissions certain external vendors as data processors (next-level sub-processors), responsible for specific technical functions such as infrastructure, inference services, authentication, Email delivery, DNS and CDN. The full list, together with each vendor's geographical region and compliance certifications, is published in the 'Sub-processors List'.

2.3 Researcher

A researcher means a natural person or institution authorised under a Researcher Access Agreement to access Uedu platform data within the scope of a specified research project. Researchers bear independent responsibility for personal data processed within the scope of their authorisation, and are subject to the IRB and local legal requirements of their own institution. The three-tier access design set out in the Researcher Authorisation Template maps different levels of sensitivity to corresponding ethical thresholds.

2.4 Platform Owner

This concept overlaps with Data Controller, but is set out separately in the governance documents to emphasise the following responsibilities: (i) the platform source code, prompt templates, database schema and architecture are the intellectual property of the platform owner; (ii) the platform owner bears ultimate responsibility for the content and versioning of the governance documents, and for communication with external partners; (iii) internal delegation of operational authority to maintenance staff does not affect this allocation of responsibility.

2.5 No Joint Controllership

The platform adopts a single-controller model with Uedu as the sole controller, for the following reasons: (i) the platform's data infrastructure is owned and operated by the controller in person; (ii) the collaborating schools are the institutions to which users belong, but do not participate in platform data-processing decisions; (iii) this design avoids the uncertainty in multi-party liability determinations arising from joint controllership under GDPR Art. 26. Teachers from collaborating schools who carry out research beyond the scope of the IRB Umbrella must apply for their own IRB and assume controller responsibility for that research.

3. Data classification

The platform classifies the data under processing into the following three categories, each of which is mapped in the 'Privacy and Data Retention Policy' to specific retention periods and deletion procedures.

Data CategoryContentProcessing level
Student–AI dialogue data Messages sent by the user to the LLM in ClassroomGPT, AIDA, UeduGPTs and similar contexts, and the LLM’s responses. Includes the user identifier, message content, timestamp, and the model version used. Contains directly identifiable personal data; after anonymisation, classified as research data
Learning behaviour records Page clicks, dwell time, assignment submission timestamps, quiz response traces, survey responses, worksheet interaction traces, and so on. Contains directly identifiable personal data; after anonymisation, classified as research data
Derived analytics data Derived values computed by the system, such as Bloom cognitive level evaluation results, Holland RIASEC / Big Five / OEJTS learning trait scale scores, and language complexity indicators. Contains directly identifiable personal data; after anonymisation, classified as research data
Account and profile Name, email, student number, login IP, device identifier, avatar, self-introduction, affiliated school. Directly identifying personal data (PII)
OAuth and authentication credentials Refresh tokens for Google / Apple / GitHub, session keys, and recovery codes for two-factor authentication. Directly identifying personal data (PII)
Physiological sensing data (opt-in) Heart-rate variability, sleep and stress metrics from the Garmin Connect API; health data from Apple HealthKit / Google Health Connect. Special category personal data (GDPR Art. 9); individual consent
Screen recording data (opt-in) Instructor-side screen recording, webcam recording, class audio; student-side screen recording. Contains identifiable personal data; individual consent
In-depth interview data (opt-in) Structured or semi-structured interview recordings, verbatim transcripts. Special category personal data; individual consent
System logs nginx and Flask access logs, error logs. Includes IP address (treated as personal data under GDPR)

4. Applicable law

The governance design of this platform applies the following laws. For detailed mappings by jurisdiction, please see the 'Cross-jurisdiction Compliance Comparison Table' and the Notes for each jurisdiction.

JurisdictionApplicable situationsPriority level
Taiwan Personal Data Protection Act (PDPA)The platform's main servers are located in Taiwan; most users are staff and students at Taiwanese universitiesP0
General Data Protection Regulation (GDPR)When the data subject is in the European Economic Area, or the research collaboration involves EU institutionsP0
Revised Swiss Federal Data Protection Act (nFADP)When involving research collaboration with institutions in SwitzerlandP0
Singapore Personal Data Protection Act (PDPA)When involving research collaboration with institutions in SingaporeP0
Japan's Act on the Protection of Personal Information (APPI)When involving research collaboration with institutions in JapanP1
Personal Information Protection Act (PIPA)When involving research collaboration with institutions in KoreaP1
UK General Data Protection Regulation (UK GDPR)When involving research collaboration with institutions in the United KingdomP1

4.1 GDPR and Taiwan Personal Data Protection Act mapping summary

TopicGDPRTaiwan Personal Data Protection Act
Lawful BasisArt. 6 (general), Art. 9 (special categories)§19, §20 (general), §6 (special)
Informed consentArt. 13–14§8、§9
Data subject rightsArt. 15–22§3
Cross-border transferArt. 44–49§21 (restriction may be imposed by the central competent authority for the relevant industry)
Breach NotificationArt. 33 (notify the supervisory authority within 72 hours)§12 (notify the data subject by appropriate means)
Scientific research exceptionArt. 89 + Recital 159§6 (special categories of personal data) exception: 'academic research institution acting in the public interest'
Supervisory authorityDPA of each member stateNational Development Council Personal Data Protection Office (from 2025)

5. Relationship with the Educational Omics framework

Uedu's research mission is built upon the Educational Omics multimodal learning analytics framework, which breaks down learning phenomena into six dimensions: Cognomics (cognitive processes), Linguomics (language expression), PhysioNeuromics (physiological and neural), Sociomics (social interaction), Environomics (learning environment), and Ethicomics (ethical norms). The data classification and retention policy design of this governance framework particularly takes the following two points into account:

  • Ethical threshold for cross-modal integration: when a research project involves two or more omics dimensions, the risk of re-identification in de-identified data increases; therefore, the "Researcher Authorisation Template" requires Tier 2 / Tier 3 access to undergo IRB review and to sign a re-identification prohibition clause.
  • Ethicomics as the leading dimension: Ethicomics is not only one of the research data dimensions, but also the backbone of platform governance. This governance framework, the IRB summary, and the Researcher Access Agreement together constitute the external verifiability of Ethicomics.

6. Version management of governance documents

All documents in this framework centre adopt the following versioning system:

  • Main version (v2.0, v3.0…): major changes, such as adding jurisdictions, changing the controller's identity, or changing the definition of data categories.
  • Version minor release (v1.1, v1.2…): updates to policy details, such as retention-period adjustments and adding a sub-processor.
  • Revision number (v1.0.1…): typo and formatting fixes, with no substantive policy changes.

Each document displays three separate dates in the header: Effective Date (the governance framework effective start date, aligned with IRB approval date 2026-04-10), Last Updated (the date of the last textual revision for that version), Published Online (the date it was first published online). Version changes update Last Updated in the top right at the same time.

7. Contact point

Privacy Contact[email protected] (Uedu does not separately appoint a DPO within the meaning of GDPR Art. 37; this channel bears equivalent data-protection liaison responsibility and undertakes to respond to data subject requests within 30 days)
Academic Collaboration[email protected]
Emergency report (Breach)[email protected] (please include [URGENT BREACH NOTIFICATION] in the subject line)

This document is the foundational document of the Uedu governance framework; please read it together with the 'Privacy and Data Retention Policy', 'List of Sub-processors', 'Researcher Authorisation Template' and 'IRB Ethics Review Approval Summary'.