資料安全政策
我們如何透過技術與制度層層守護您的學習資料,從加密傳輸、權限控管到雙因素驗證,建立值得信賴的教育資料環境。
Core Values Statement
Why data security matters for educational platforms
In the era of digital learning, students' learning history, interaction records and personal data are all stored on education platforms. These data not only include learning outcomes, but also involve personal privacy. Uedu understands the importance of data security and is committed to providing all users with a safe and trustworthy learning environment.
We believe that only by ensuring data security and privacy can teachers and students focus on teaching and learning, fully realising the benefits of AI-assisted teaching while also safeguarding every user's rights and interests.
Our commitment to users
Protect privacy
Strictly protect users' personal data; never disclose it externally without consent
Secure transmission
Uses industry-standard encryption technology to ensure secure data transmission
Compliance management
Comply with the requirements of the Personal Data Protection Act and other relevant regulations
Security first
Your trust is the driving force behind our continued progress
Data collection and use
What Data We Collect
| Data Type | Details | Purpose of Collection |
|---|---|---|
| Account Information | Name, Email, student number | Identity verification Course Management |
| Learning behaviour data | Open-ended Q&A, Socratic Q&A, assignments, discussions, quiz marks | Learning analytics Grade calculation |
| System usage records | Login time, IP address, device information | Security protection System optimisation |
| AI conversation records | Conversation content with the virtual teaching assistant, interaction history | Personalised learning AI optimisation |
Data usage notes
Provides a personalised learning experience
Based on your Learning history and interaction records, the AI teaching assistant can provide learning suggestions and feedback more closely aligned with your needs
Course Management and grade calculation
Instructors can manage Courses, track Students’ learning progress, and conduct objective and fair assessment of grades through the system
System performance optimisation
Analyse user behaviour to improve system performance, fix bugs, and provide a more stable and smoother user experience
Research Analysis (De-identified)
When conducting research related to educational technology, all research data are de-identified and cannot be traced back to individual identities
Instructions for using research data
Data are collected by default for system optimisation, but only the data of users who have signed the [Research Informed Consent Form] will be used for academic research. You may choose whether to take part in the research; not taking part will not affect any function of your use of the system.
Data protection measures
Technical Safeguards
SSL/TLS encrypted transmission
All data transmission uses the HTTPS protocol and SSL/TLS encryption to ensure that data cannot be intercepted or tampered with during transmission
Encrypted database storage
Sensitive data (such as passwords) are stored using a non-reversible encryption algorithm, so even if the database is stolen, the original content cannot be restored
Regular security updates
Continuously monitor system vulnerabilities, and regularly update software versions and security patches
Firewall and intrusion detection system
Deploy a firewall to filter malicious traffic, and monitor abnormal behaviour in real time through an intrusion detection system
Scheduled backup mechanism
Automatically back up important data every day and store it off-site, ensuring data is not lost due to accidents
Administrative Safeguards
Access control
Uses role-based access control (RBAC) to ensure that users can only access data within their authorisation scope. Students may only view their own learning records, and Instructors may only view student data for the courses they teach
Employee Confidentiality Agreement
All system administrators and development team members have signed confidentiality agreements, undertaking not to disclose or misuse user data
Super TA confidentiality agreement
Ordinary course TAs cannot browse students' full AI conversation records. For a teacher to allow a TA to browse or export course conversation records (Super TA), the teacher must first sign an authorization consent form and the TA must personally sign a confidentiality agreement; the authorization lasts one month, after which the TA automatically reverts to an ordinary TA
Regular security audits
Regular system security checks and vulnerability scans are carried out to ensure security measures operate effectively
Incident response plan
Establish a complete cyber security incident response process so that, if an anomaly occurs, investigation and remedial measures can be launched immediately
Account security mechanisms
Two-factor authentication (2FA)
LaunchedUedu supports TOTP (Time-based One-Time Password) two-factor authentication, adding a second layer of security to your account. Once enabled, logging in requires not only your password but also the 6-digit dynamic verification code generated by the authenticator application; even if the password is leaked, an attacker still cannot access your account.
Supports mainstream authenticator apps such as Authy, Google Authenticator and Microsoft Authenticator.
You can enable it in Personal Settings after logging in
Mandatory 2FA for Teachers, TAs and administrators
To protect the security of Student personal data, users with the following rolesmust enable two-step verification and cannot disable it themselves:
- System administrator — can access all user data and system settings on the platform
- Course Instructor — can view course activity statistics, and download students' AI dialogue records and Learning history
- Course TAs — may view course activity statistics and students' learning histories, and may view the full messages of Socratic Dialogue and Simulated Debate sessions in "Dialogue Grading"; Super TAs authorized by the teacher may additionally browse and export course conversation records
Under Articles 18 and 20-1 of the Personal Data Protection Act, the platform is obliged to take appropriate security maintenance measures to prevent personal data from being stolen, altered, damaged, lost or disclosed. For details, please see the two-factor authentication policy page.
Security design details
Encrypted key storage
TOTP keys are stored in the database using Fernet symmetric encryption. Even if the database is compromised, an attacker cannot obtain the original keys
Rescue code mechanism
When 2FA is enabled, the system generates 10 one-time recovery codes, stored as SHA-256 hashes. If you cannot use an authenticator, you can log in with a recovery code
Brute-force protection
Five consecutive verification failures will lock the account for 15 minutes, preventing attackers from brute-forcing the verification code
Email Reset and Cooldown Period
If you lose your authenticator and recovery codes, you can request a reset by email. To prevent abuse, reset requests are subject to a 24-hour cooling-off period
User rights
Under the Personal Data Protection Act, you have the following rights over your personal data:
Right to query
You can view all your data in the system at any time
Right to rectification
If you find an error in your personal information, you may request a change or correction
Deletion right
Under specific conditions, you may request deletion of your personal data
Self-management
On the "Personal Data Management" page, you can delete your account yourself
How do I exercise my rights?
• After logging in, go to the [Personal Data Management] page to view, edit or delete your personal data
• If you need assistance, please contact our customer support team
Data retention and deletion
Data retention period
Course data retention period
Course-related data (AI conversations, assignments, discussions, grades, etc.) are platform operational records and are not deleted when the course ends
They are retained in order to:
• Allow you to look up your learning history
• Support credit certification needs
• Assist academic research within the scope of the research consent you have signed; data exported by researchers does not include names, email addresses, or student ID numbers
Account data retention period
Basic account data (name, email, student ID number, etc.) is retained with the account; deleting your account currently does not automatically erase this data
You may delete your account at any time:
• The account is deactivated immediately and can no longer be used to log in
• No new usage records are generated after deactivation
• If you want your personal data fully deleted, please email [email protected]
Data handling after deleting an account
Important Information
After you delete your account, the system currently handles it as follows:
- Account deactivated: the account is marked as deleted, you are logged out, and you can no longer log in with this account
- Data remains on the platform: your name, email, student ID number, AI conversations, and learning records are not automatically deleted or anonymised; teachers may still see your past content in course records
- Research data: data exported by researchers does not include names, email addresses, or student ID numbers, and exported copies are kept and destroyed by researchers under the consent form; if you only wish your data not to be used for research, you can withdraw consent in the Research Informed Consent Center
- Email us for full deletion: if you want your personal data deleted, or your data removed from research use, please email [email protected]; we will handle your request individually and reply within 30 days
Please note: once your account is deleted, you cannot restore it yourself. Please proceed with care.
Third-party services
To provide a higher-quality AI-assisted teaching service, Uedu has integrated the following third-party services. We strictly require all partners to comply with data protection standards.
Third-party services we use
OpenAI GPT model AI service
Service purpose: provides intelligent conversation and learning support features for the virtual teaching assistant
Data transfer: when you interact with the virtual assistant, the dialogue content is transmitted to OpenAI over SSL encryption for processing
Data processing policy: OpenAI commits not to use data sent via API to train its public models. For more information, please refer to OpenAI Privacy Policy
Data transfer security safeguards
• SSL-encrypted transmission: all data transmission with third-party services uses the HTTPS protocol and SSL/TLS encryption technology
• Minimised data transmission: only necessary data is transmitted; irrelevant personally identifiable information is not transmitted
• Regular security review: regularly review the security and Privacy Policy of third-party services
Data breach response
Although we have taken strict security measures, we still cannot completely rule out the risk of a data breach. If a data breach incident unfortunately occurs, we will handle it according to the following process:
Respond immediately
Once a breach is discovered, immediately activate the response mechanism, stop the source of the breach, and carry out damage control
Survey assessment
Thoroughly investigate the cause of the breach and the scope of its impact, and assess the potential risks to users
Notify users
Notify affected users by email within 72 hours after confirming the breach
Notification mechanism
If a data breach occurs, we will notify you in the following ways:
- Email notification: sent to the Email inbox used at registration
- System announcement: publish an announcement on the platform homepage
- On-site notification: warning messages are displayed in the notification centre after login
The notification will include: the type of leaked data, the possible scope of impact, the remedial measures we have taken, and the protective actions you should take.
Remedial measures
Contact person
If you have any questions about data security or notice anything unusual, please contact us immediately
Regulatory compliance
Uedu strictly complies with the relevant laws and regulations of the Republic of China, ensuring the legality and propriety of data processing.
Personal Data Protection Act (Taiwan)
We fully comply with the requirements of the Republic of China Personal Data Protection Act (PDPA), ensuring that the collection, processing and use of personal data all meet legal requirements.
Collection legality
Collect personal data only within the scope permitted by law, and clearly state the purpose of collection
Lawfulness of processing
Data processing is limited to specific purposes and must not exceed the scope of the original collection purpose
Security maintenance
Adopt appropriate security measures to prevent personal data from being stolen, altered, damaged or disclosed
Rights of the parties
Safeguard the rights of data subjects to enquire about, rectify and erase personal data
Legal basis:
Regulations of the Republic of China on the Protection of Personal Data (amended on 30 December 2015)
View full legal text
Other relevant regulations
In addition to the Personal Data Protection Act, we also comply with the following relevant laws and regulations:
- Implementation Rules for the Personal Data Protection Act for Computer-Processed Personal Data
- Ministry of Education-related data protection regulations
- Academic Research Ethics Guidelines
- Act Governing Information Security
This policy was last updated on September 14, 2026
We reserve the right to amend this policy at any time. If there are material changes, we will notify you by email or a system announcement.
Please contact Assistant Professor Chia-Kai Chang, Center for General Education, National Central University
[email protected] 03-4227151 #33415