Security & Privacy (GDPR)

AI4Schools Privacy Notice (GDPR)

(operated by ODYSSEY EDUCATIONAL TECHNOLOGY HUB SINGLE MEMBER P.C.)

Last updated: 28 December 2025

Provider: ODYSSEY EDUCATIONAL TECHNOLOGY HUB SINGLE MEMBER P.C. (ODYSSEY EDUCATIONAL TECHNOLOGY HUB ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε.)
VAT ID (ΑΦΜ): 803052981
Tax office: KEFODE Attikis (ΚΕΦΟΔΕ ΑΤΤΙΚΗΣ)
Business address: 28 Oktovriou 11, TK 16672, Vari, Greece
Start date: 31/10/2025
Email: odyssey@odyssey.edu.gr

This Privacy Notice explains how Odyssey processes personal data in connection with the AI4Schools Service. It is intended to provide transparency under the EU General Data Protection Regulation (GDPR).

1. Roles: controller and processor

  • Individual accounts (direct purchase/use): Odyssey typically acts as the data controller for account, billing, and Service operations.
  • Organisation accounts (schools/institutions): the school/institution typically acts as the data controller for teacher/student data used for educational purposes; Odyssey typically acts as a data processor under the school’s instructions (subject to configuration and contract).
  • Odyssey may act as an independent controller for limited data needed for legal obligations (e.g., tax/accounting records) and platform security.

2. Categories of personal data we process

Depending on configuration and use, we may process:

  • Account and contact data: name, email, organisation/school name, role (teacher/admin), authentication identifiers.
  • Billing and transaction data: purchases, invoices, VAT-related fields, transaction identifiers (payment card data is typically processed by payment providers).
  • Service usage and technical data: credits balance and usage, subscription status, timestamps, device/browser data, diagnostic and security logs.
  • Chat history and educational interaction data: prompts, messages, attachments/files, and generated Outputs.
  • Audio and speech data: user audio is streamed and only temporarily buffered to complete processing; AI-generated audio outputs may be stored for playback/continuity.
  • Support communications: support requests, correspondence, and troubleshooting information.

3. Minors’ personal data (students)

  • AI4Schools may be used by minors under teacher/school supervision.
  • Schools are encouraged to use pseudonymous student identifiers where feasible and to avoid entering unnecessary personal data.
  • Teachers/schools remain responsible for supervision and appropriate classroom policies, including safeguarding and age-appropriate use.
  • Odyssey does not intentionally use student content for targeted advertising.

4. Purposes of processing

  • To provide, operate, and secure the Service (authentication, functionality, Credits accounting).
  • To generate Outputs via AI processing.
  • To provide customer support and troubleshooting.
  • To prevent abuse, fraud, and security incidents, including protections relevant to minors.
  • To meet legal obligations (accounting, tax, compliance).
  • To maintain and improve performance and reliability (primarily via technical and aggregated signals; content use is minimised).

5. Legal bases (GDPR)

  • Contract necessity: operating the Service and delivering purchased features.
  • Legal obligations: tax and accounting requirements.
  • Legitimate interests: security, abuse prevention, and Service reliability.
  • Consent: where required for specific optional processing (e.g., non-essential cookies/analytics).

For Organisation Accounts, the school as controller determines the legal basis for student/teacher processing and provides any required notices and consents.

6. OpenAI and data sent to the AI Provider

AI functionality is provided using OpenAI services. To generate Outputs, we transmit relevant portions of User Content and limited technical metadata to OpenAI.

  • What is sent: content you submit (text, prompts, files, and—when enabled—transient audio streams or transcripts as technically required), plus limited metadata needed to process the request.
  • Why it is sent: to generate Outputs and deliver the requested features.
  • Provider rules: processing by OpenAI is subject to OpenAI’s contractual terms, policies, and technical settings applicable to the services used.

7. Retention (including chat history)

Chat history is retained for up to five (5) years to provide continuity, support, and operational accountability. Individuals or Organisation administrators may mark chats as deleted; marked items are removed from user-visible interfaces and standard retrieval workflows.

Deletion may be subject to technical constraints (e.g., backups) and legal obligations (e.g., dispute preservation, tax/accounting). Other records (e.g., invoices) are retained as required by applicable law.

8. Data sharing (recipients)

We may share personal data with:

  • OpenAI (to provide AI processing).
  • Hosting and infrastructure providers (cloud hosting, storage, monitoring).
  • Payment providers (for payments; they may act as independent controllers for payment data).
  • Professional advisors (legal, audit) under confidentiality.
  • Public authorities where required by law or to protect rights, safety, and security.

We do not sell personal data.

9. International transfers

Depending on provider and infrastructure locations, data may be processed outside the EEA. Where required, we implement appropriate safeguards and legal mechanisms for transfers (e.g., contractual clauses and supplementary measures) and limit transfers to what is necessary.

10. Security

We implement technical and organisational measures appropriate to risk, including access controls, least-privilege permissions, encryption in transit, monitoring, and incident response processes. No system is perfectly secure; users should avoid submitting unnecessary sensitive personal data.

11. Your rights

Subject to GDPR conditions and exceptions, individuals may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (where processing is consent-based).

For Organisation Accounts, rights requests should typically be routed through the school as controller; Odyssey will assist the controller as required.

12. Complaints

You may lodge a complaint with the competent supervisory authority. In Greece, this is the Hellenic Data Protection Authority.

13. Cookies and similar technologies

If the Service uses cookies or similar technologies (e.g., for authentication, session management, analytics), we provide appropriate notices and controls where required by law.

14. Changes to this Privacy Notice

We may update this Privacy Notice from time to time. We will post the updated version and revise the “Last updated” date.

15. Contact

Privacy requests: privacy@ai4schools.eu
Support: support@ai4schools.eu