Skip to main content

Privacy Policy

How Discentik collects, uses, and protects your personal data under the GDPR.

Draft pending legal review. This is a working template and is not yet legally binding final copy. Please review with qualified counsel before relying on it.

Who we are (data controller)

Discentik ("we", "us") provides interactive AI-skills training. For the purposes of the EU General Data Protection Regulation (GDPR), the data controller is Julio Macias Gonzalez, trading as Discentik, at [business correspondence address required before launch]. You can reach us about privacy at support@discentik.com or through the Contact page. Where your organisation assigns you training, your employer is the controller of your participation data and we act as a processor on their behalf.

Data we collect

  • Account details — name, email, organisation, role, public-profile details, and any profile photo you upload.
  • Learning activity — course progress, completion, certificates, and (unless you opt out) per-stage analytics such as time spent, attempts, and your exercise prompts and the AI responses.
  • Communications — messages you send us (e.g. support or contact enquiries).
  • Trust and safety records — reports, appeal reasons, administrator case notes, and evidence that authorised administrators submit to investigate account or course safety concerns.
  • Technical & usage data — limited information needed to operate and secure the service (e.g. session and authentication data) and, with your consent, product-analytics events (pages visited, features used, and page-performance measurements) via PostHog. Performance measurements exclude page text and element details. We do not use advertising or cross-site tracking.

Why we use it and our legal basis

  • To deliver the service (provide courses, track progress, issue certificates, give AI feedback) — performance of a contract.
  • To secure and improve the platform — our legitimate interests, balanced against your rights.
  • To investigate reports, prevent abuse, and preserve accountable moderation decisions — our legitimate interests and, where applicable, legal obligations.
  • Optional analytics and preference cookies — your consent, which you can withdraw at any time (see the Cookie Policy).
  • To meet legal obligations — where the law requires it.

We do not sell your personal data and we do not use it for automated decisions with legal or similarly significant effects.

AI processing

Exercise content you submit is processed by OpenAI to generate feedback. Profile photos and course cover images are sent to OpenAI for automated content-safety screening before they can be published in public storage. Private evidence images uploaded by authorised Platform administrators are also sent to OpenAI for automated content-safety screening before storage. Screening determines whether an image upload is accepted; a human administrator remains responsible for every moderation investigation and enforcement decision. Do not submit confidential or personal data you are not authorised to share. AI output may be inaccurate and is not professional advice.

Service providers (processors)

We share data only with providers that process it on our behalf under data-processing agreements:

  • Supabase — hosting, database, and authentication (project hosted in the EU).
  • OpenAI — generating exercise feedback and screening profile photos, course covers, and administrator-uploaded moderation evidence images for content-safety concerns.
  • PostHog — product analytics (EU-hosted), used only with your analytics consent.
  • Resend — sending transactional emails (e.g. invitations, assignment reminders), when enabled.

International transfers

We aim to keep personal data within the European Economic Area (our database and authentication are hosted in the EU). Where a provider processes data outside the EEA (for example certain AI providers), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Contact us for details.

How long we keep it

We keep account and learning data for as long as your account is active and as needed to provide the service, then delete or anonymise it within a reasonable period ([retention period, e.g. 24 months after account closure]) unless a longer period is required by law. You can request deletion at any time.

Private moderation evidence images are scheduled for deletion after 90 days. They remain protected for longer while an investigation, appeal, enforcement, or legal hold is active. The case timeline and audit metadata may be retained separately to document the decision and meet security or legal obligations.

Your rights

Under the GDPR you have the right to:

  • access a copy of your data;
  • rectify inaccurate data;
  • erase your data ("right to be forgotten");
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent at any time, without affecting prior processing.

You can access, export, or delete your account and data from your profile ("Delete account") and opt out of analytics from your profile or the cookie settings. To exercise any right, contact us via the Contact page. You also have the right to lodge a complaint with the Irish Data Protection Commission or your local EEA supervisory authority.

Security

We use access controls and row-level security so users and organisations can only see data they are authorised to access, and we restrict access to personal data to what is needed to run the service.

Children

Discentik is intended for professional learning and is not directed at children. We do not knowingly collect data from anyone under [16].

Changes & contact

We may update this policy; we will post changes here and, where required, notify you. Questions about this policy or your data? Reach us through the Contact page or at support@discentik.com.