1. Categories of Data Collected and Purposes of Processing
The categories of personal data collected by this platform are enumerated in the Data Governance Framework, §3. The lawful basis for collection and the purposes of processing for each category are set out below:
| Data Category | Purpose of Processing | Lawful Basis |
|---|---|---|
| Account and Profile Data | Identity authentication, access control, personalized instructional services, and course-group membership management | Performance of the Terms of Service agreed to by the user upon registration (GDPR Art. 6(1)(b)) |
| Student–AI Conversation Data | Provision of LLM inference services, personalized learning feedback, and instructor review of classroom interactions | Performance of the Terms of Service; research use is based on individual consent (GDPR Art. 6(1)(a), Art. 6(1)(b)) |
| Learning Behavior Records | Learning dashboard presentation, instructors' class-level analytics, and evidence for course improvement | Performance of the Terms of Service; research use is based on individual consent |
| Derived Analytical Data | Personalized feedback and instructional decision support for teachers | Performance of the Terms of Service; algorithmic processing is disclosed in the documentation of the corresponding features |
| OAuth and Authentication Credentials | Third-party sign-in and two-factor authentication | Performance of the Terms of Service |
| Physiological Sensing Data (Garmin / Apple Health / Google Health Connect) | Personal health dashboard presentation, the PALM state-aware instructional module (where enabled), and research use | Individual consent (GDPR Art. 9(2)(a)); may be withdrawn at any time |
| Screen Recording Data | Instructor-side post-class playback and student-side classroom archives; research use requires individual consent | Individual consent, obtained via a consent form prior to recording |
| In-Depth Interview Data | Qualitative research analysis | Individual consent (GDPR Art. 9(2)(a)); the consent form discloses the research purpose, retention period, and contact information |
| System Logs | System operations, security incident detection, and fulfillment of legal obligations (e.g., investigation of unauthorized access) | Legitimate interests (GDPR Art. 6(1)(f)); compliance with legal obligations (GDPR Art. 6(1)(c)) |
2. Retention Periods
This platform adopts a three-tier retention strategy that treats directly identifying personal data, anonymized research data, and the researcher outbound-export window as three mutually independent matters, each subject to distinct retention periods and handling procedures.
2.1 Retention Period Reference Table for the Three Categories
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Directly identifying personal data (PII) | Permanent deletion completed within 30 days of a deletion request | GDPR Art. 5(1)(e), Art. 17 |
| Personal data in backups | Naturally purged through the 30-day rotation cycle | Industry-standard practice |
| Anonymized research data | Retained long-term under the approved IRB protocol | GDPR Recital 26, Art. 89 |
| Researcher outbound export | Within 5 years of the data generation date | Internal IRB rules |
| Exercise of rights by the data subject | No time limitation | GDPR Art. 15, Art. 20 |
2.2 Personal Data Retention
Personal data is retained only for the period necessary for the original purpose of collection. Account profiles and directly identifying information are subject to a layered deletion process, completed within 30 days of a deletion request or account termination; personal data contained in backups persists for at most 30 days due to routine rotation cycles, after which it is naturally purged.
2.3 Long-Term Retention of Anonymized Research Data
Upon completion of the deletion process, conversation logs and learning behavior records are irreversibly anonymized: pseudonym identifiers replace the original identifiers, and the linkage table between pseudonyms and real identities is destroyed within the same transaction. The resulting dataset no longer constitutes personal data under GDPR Art. 4(1) and Recital 26, and is retained long-term for scholarly research purposes under GDPR Art. 89 (processing for scientific research purposes) pursuant to the approved IRB protocol (NTU REC 202507EM058).
2.4 Researcher Outbound-Export Window
Researchers authorized under a Researcher Access Agreement may request export of raw research data within 5 years of the data generation date. Beyond this 5-year window, the data remains archived within the system for verification and reproducibility purposes and is no longer available for outbound export. This restriction applies only to researcher-side access; data subjects' rights under GDPR Art. 15 and Art. 20 are not subject to this time limit.
3. Deletion Process
The platform's layered deletion and PII anonymization mechanisms are fully implemented. The process comprises three stages:
3.1 Stage 1 (T+0, immediate) — Soft-Delete Grace Period
- The account is immediately deactivated and the profile is removed from all active interfaces
- The user can no longer sign in, and the account is not visible to other users
- The system sends a confirmation email stating that permanent deletion will be executed after 30 days
- The user may request cancellation of the deletion within 30 days via the link in the email
3.2 Stage 2 (T+30 days) — Permanent Hard Deletion of PII + Unlinking of Security Records + Anonymization of Conversation Data
- Directly identifying personal data (name, email, student ID, avatar, self-introduction, date of birth) is permanently deleted and cannot be recovered
- Security audit records (sign-in IP, session IP change history, failed sign-in records, 2FA verification records, location records, etc.) follow the unlinking model:
user_idis set toNULL, and the records themselves are retained in the system as de-identified data for security incident tracing; under GDPR Recital 26 they no longer constitute personal data (see §9.3) - The user's conversations, AI interactions, and learning behavior records are simultaneously re-keyed to a pseudonym ID
- The linkage table between the real identity and the pseudonym is destroyed within the same transaction and is never persisted
- Thereafter, this data is irreversibly anonymized and no longer constitutes personal data as defined in GDPR Art. 4(1)
3.3 Stage 3 (post-anonymization) — Research Data Retention
- Anonymized data is retained long-term for scholarly research purposes under the approved IRB protocol
- Governed by GDPR Recital 26 (anonymized data falls outside the scope of personal data) and Art. 89 (scientific research purposes)
- Researchers analyze this data through authorized interfaces; outbound export is limited to 5 years from data generation
4. Handling of Backup Data
- Daily backups are retained for 30 days on a rolling rotation basis
- Personal data in backups is naturally purged through the 30-day rotation cycle
- If a backup restore involves deleted accounts, the Stage 2 process is re-triggered
- Personal data is not selectively excised from backup files (industry-standard practice)
5. Exceptions
In the following circumstances, retention periods may be extended until the conclusion of the relevant matter or the expiry of the legal obligation:
- Pending disputes, legal proceedings, or investigations by competent authorities: the relevant data is retained until the matter concludes
- Compliance with legal obligations (taxation, research records, grant accounting): retained until the legal obligation expires
Under such exceptional circumstances, the relevant data is managed in segregated storage, is not included in research datasets, and is not exported.
6. Cross-Border Transfers
The platform's primary servers are located in the server facilities of National Central University, Taiwan. Cross-border transfers occur in the following circumstances:
- LLM inference services: the default LLM provider is located in the United States (OpenAI, L.L.C.). Uedu has enabled Zero Data Retention (ZDR) on its OpenAI API usage; input and output data are not retained after real-time processing.
- European research collaborations: for research collaborations involving European data subjects, inference may be re-routed to the Switzerland North or West Europe region of the Microsoft Azure OpenAI Service, processed under Microsoft's EU Data Boundary commitments. The choice of region is decided jointly with the partner institution to align with its data residency requirements.
- Email delivery: transactional email is sent via Mailgun (EU region).
- DNS / DDoS protection / CDN: via the global edge network of Cloudflare, Inc.; requests from European users are primarily handled by Cloudflare's European nodes.
The lawful bases and mechanisms for cross-border transfers vary by jurisdiction; see the Cross-Jurisdiction Compliance Matrix and the notes for each jurisdiction. For full vendor disclosure, see the Sub-Processor List.
7. Data Subject Rights
7.1 List of Rights
| Right | Corresponding Provisions | How to Exercise |
|---|---|---|
| Right of access | GDPR Art. 15; Taiwan PDPA §3 | Email [email protected] |
| Right to rectification | GDPR Art. 16; Taiwan PDPA §3 | Edit directly on the user settings page, or by email |
| Right to erasure (right to be forgotten) | GDPR Art. 17; Taiwan PDPA §11 | The "Delete My Account" entry on the user settings page |
| Right to restriction of processing | GDPR Art. 18 | By email |
| Right to data portability | GDPR Art. 20 | By email (see the disclosure in §7.2) |
| Right to object | GDPR Art. 21 | By email |
| Right to withdraw consent | GDPR Art. 7(3) | Toggle on the consent settings page of the corresponding feature, or by email |
7.2 Disclosure Regarding the Right to Data Portability
The self-service interface currently implemented on this platform is the "Delete My Account" entry point; a self-service data download interface corresponding to GDPR Art. 20 has not been implemented, and there is no short-term plan to launch one. Data subjects may exercise data portability requests under GDPR Art. 20 and the Taiwan PDPA by emailing [email protected]; a response is provided within 30 days.
The purpose of this disclosure is to inform data subjects of the current request channel before they exercise this right, so that they do not search the interface in vain and mistakenly conclude that the right does not exist.
7.3 Exercise Procedure and Response Deadlines
- All written requests are committed to a response within 30 days of receipt of complete information
- Where a request involves complex identity verification or extensive data retrieval, the deadline may be extended to 60 days, with the reason for the extension communicated within the original 30-day period
- Responses may take the form of: fulfilling the request, partially fulfilling it (with an explanation of the limitations), or refusing it with reasons and information on complaint channels
- No fee is charged for exercising rights, but the platform reserves the right to refuse manifestly repetitive or abusive requests
8. Cookies and Similar Technologies
This platform uses only the session cookies strictly necessary to maintain sign-in state and authenticate identity. It uses no third-party tracking cookies, deploys no advertising cookies, and embeds no tracking tools that transmit user behavior to external parties, such as Google Analytics or Facebook Pixel. Cookies expire upon sign-out or session expiry.
Because this platform uses no tracking cookies, no "cookie consent banner" appears when users enter the platform. This design reflects the data minimization principle and is not an evasion of consent obligations.
9. Processing of Network Address (IP) Information
Network addresses (IP addresses) constitute personal data under CJEU judgment C-582/14 (Breyer v. Bundesrepublik Deutschland), the broad interpretation of the Taiwan Personal Data Protection Act, and the definitions of personal data in most jurisdictions. This platform adopts a three-layer processing model that separates lawful bases and retention periods by purpose:
9.1 Three-Layer Processing Model
| Layer | Purpose | Retention Period | Lawful Basis |
|---|---|---|---|
| L1. Edge and System Logs | nginx access logs; system operations, debugging, DDoS mitigation, and traffic analysis | 30–90 day rotation | Legitimate interests (GDPR Art. 6(1)(f)) |
| L2. Application-Layer Security Records | Sign-in sessions (user_session.ip_address IP at the moment of sign-in, last_seen_ip most recent activity IP), session IP change auditing (user_session_ip_history), 2FA attempt records, failed sign-in auditing (user_login_failures), anomalous sign-in detection, account-compromise recovery assistance, and survey response source auditing |
Up to 1 year; hard-deleted together with permanent account deletion | Legitimate interests; performance of the Terms of Service (GDPR Art. 6(1)(b), (f), Art. 32) |
| L3. Country-Level Geolocation | Identification of cross-border collaborations; jurisdiction-specific routing (e.g., re-routing European collaborations to Azure EU regions); publicly disclosed country-level visitor distribution (aggregate statistics) | Computed in real time; not stored long-term | Legitimate interests; compliance with legal obligations (GDPR Art. 6(1)(f), (c)) |
9.2 Distinction Between Recording and Use
Pursuant to its security obligations (GDPR Art. 32), this platform records IP data within the system; such recording does not amount to tracking or behavioral profiling — these are distinct concepts in both law and engineering.
Events for which this platform records IP addresses:
- Successful sign-ins (
user_session.ip_address,last_seen_ip) and failed sign-ins (user_login_failures) - 2FA verification attempts (
user_totp_attempts,user_2fa_email_codes) - Session IP change auditing (
user_session_ip_history, appended upon IP change) - Survey response source auditing (
survey_responses.ip_address)
This platform does not use IP data for the following purposes (even where the data already exists in the system):
- Research analysis of individual movement trajectories (no temporal profiling of where a user has been based on IP changes)
- Fine-grained location research at the street or township level (IP data is inherently unreliable at this granularity)
- Behavioral profiling, automated decision-making, or advertising delivery
- Public disclosure of any individual user's IP or of derived geographic information capable of re-identifying an individual
IP data is queried only in the following circumstances: assisting users in tracing account compromise, security incident investigations (DDoS, credential stuffing, spam, etc.), lawful requests by competent authorities, and platform operations debugging.
Collection of precise personal location (GPS coordinates) is subject to a separate opt-in consent mechanism, limited to users aged 18 or over; see the User Location Management page at /environment/locations. Location authorization and IP processing are independent workflows; withdrawing one does not affect the other.
9.3 Account and Data Deletion Process
For data-subject deletion requests, this platform applies an unlinking model rather than physical hard deletion. Specifically:
- User deletes location data (via "Delete All" / "Delete One"): the
deleted_atcolumn ofuser_locationsis timestamped (soft delete); the record is no longer returned in user-facing lists or counts. - User deletes account: directly identifying personal data (name, email, student ID, avatar, self-introduction) is permanently deleted per §3.2; IP and security audit records (
user_session/user_session_ip_history/user_login_failures/user_locations, etc.) are unlinked from the user by settinguser_idtoNULL, while the records themselves are retained in the system.
Once unlinked, the records can no longer be attributed to a specific data subject and fall outside the scope of personal data under GDPR Recital 26; they are retained for the purpose of security incident tracing (GDPR Art. 32, Recital 49). This design simultaneously satisfies:
- The data subject's right to erasure (GDPR Art. 17): the linkage to that user has been severed
- Security obligations (GDPR Art. 32): historical attack patterns remain analyzable
- The storage limitation principle (GDPR Art. 5(1)(e)): data by which the data subject is identifiable is subject to a retention period (namely, the lifetime of the account); anonymized data is not so limited
This design also applies to a user's withdrawal of location research authorization (marked via user_research_consent.revoked_at_utc), survey response IP records, and all other L2 security records. For any data subject's access or deletion request concerning their own data, please email [email protected].
9.4 Special Channel for Complete Physical Deletion
The platform's default deletion policy (§3.2 + §9.3) applies an "unlinking plus security-audit retention" model, which suffices to satisfy the GDPR Art. 17 right to erasure for the vast majority of users.
The platform recognizes that certain data subjects in special privacy circumstances (for example, divorce counterparties subjected to domestic violence, political dissidents, journalists protecting sources, or persons whose physical safety is under threat) may wish to obtain complete physical deletion, such that their data cannot persist in the system in any form. For such requests:
- Email [email protected] with the subject line "Physical Deletion Request" and a brief description of your circumstances (no documentary proof is required, but you must explain why the default unlinking model is insufficient to protect you)
- The platform will assess each case and respond within 30 days, and will carry out complete physical deletion (including at the next backup rotation) subject to applicable legal obligations
- This channel does not affect the default policy for other users; nor will the platform subject data subjects who exercise this right to any adverse treatment
- Exception: where such data concerns a pending dispute, legal proceeding, or investigation by a competent authority (§5 Exceptions), physical deletion will be deferred until the matter concludes
This dual-track design (the default unlinking model plus an exceptional physical-deletion channel) allows the platform to preserve both the security capability most users value — the ability to trace anomalous account activity — and the fundamental right of the few users in special circumstances to have their data disappear entirely.
10. Minor Users
The platform's primary use context is instructional activity at institutions of higher education, and most users are adult university students aged 18 or over. Where minor users at partner senior high schools are involved (the first partner school being Taipei Municipal Nangang High School):
- The consent basis is parental/legal-guardian consent (a parental consent form), supplemented by the student's own independent consent
- Research data involving minor users preferentially adopts stricter de-identification standards upon export
- No behavioral profiling or automated decision-making is applied to minor users
11. Breach Notification
- Upon discovery of a personal data breach, the supervisory authority of the affected jurisdiction is notified within 72 hours pursuant to GDPR Art. 33 (in cases governed by the Taiwan PDPA, affected individuals are notified in an appropriate manner pursuant to §12 thereof)
- Where the breach is likely to result in a high risk to data subjects' rights, data subjects are notified directly pursuant to GDPR Art. 34
- The platform's breach notification contact is [email protected]; please mark the subject line [URGENT BREACH NOTIFICATION]
12. Policy Changes
Changes to this policy are managed under the versioning regime of the Data Governance Framework, §6. Material changes (major-version increments) are announced on the Center's home page 30 days before taking effect and notified to registered users by email. Minor-version and patch-level updates are disclosed in the version history section of the Center's home page.
13. Contact Points
| Privacy Contact | [email protected] |
|---|---|
| Breach Notification | [email protected] (subject line: [URGENT BREACH NOTIFICATION]) |
| Academic Collaboration | [email protected] |
For the governance position and role definitions underlying this document, see the Data Governance Framework; for disclosure of external vendors involved in data processing, see the Sub-Processor List.