For your data protection officer
Data protection for schools
What AILitKit processes, where, and for how long, with a pre-filled impact assessment your school can complete and sign. Policy version: 9 September 2026.
The short version
No pupil accounts. Curriculum content only.
Teachers describe a topic or upload curriculum material, and AILitKit drafts a guide for them to review. Everything on this page comes from our current processing policy and privacy policy.
Keep pupil data out
Do not enter identifiable pupil information, assessment records, safeguarding records, EHCP/SEN documents or staff personal data. AILitKit needs curriculum content only. Warnings and input cleaning do not guarantee anonymisation: information entered accidentally can still be processed and appear in a saved guide or audit evidence. Contact hello@ailitkit.com promptly if this happens.
No pupil accounts
AILitKit is for adult teachers. Pupils do not create accounts or use the platform.
Database in the EU
Supabase in eu-west-1. Hosting on Vercel includes processing in the US.
Zero data retention at our AI provider
ZDR is enabled on our OpenRouter account, and requests require ZDR inference endpoints.
A person reviews on request
Ask for a human review of any refusal or flag. We aim to respond within five working days.
What we process and why
Curriculum content in, a teacher-reviewed guide out
We process teacher account details and the curriculum content a teacher provides, so we can draft, screen and check a guide.
See how guides are made
AI models reached through OpenRouter draft and review each guide. Teachers must review every guide before classroom use.
Read the policy wording
Guide drafting and content review use Luna as the primary model, with Gemini as the configured backup, through OpenRouter. Safeguarding uses Llama Guard and, when needed, a separate Gemini curriculum reviewer. Model developers and the companies operating inference endpoints are not necessarily the same.
See how requests are screened
Automated safeguarding checks read each new request before generation. If no usable verdict is available, generation pauses.
Read the policy wording
Before new generation, automated safeguarding checks read the subject, stage, year group and topic, plus up to the first 1,000 characters each of the teacher description and extracted upload text. Llama Guard gives a first verdict; a Gemini reviewer runs if that verdict is unsafe, unavailable or unreadable. An additional direct OpenAI moderation check runs when configured, under its separate API terms. If no usable safeguarding verdict is available, generation pauses with a retry message. A usable unsafe verdict is preserved if its reviewer fails; hard-block categories cannot be cleared by that reviewer.
See how drafts are checked
Automated checks review a new draft before it is saved. They can miss errors and are not human approval.
Read the policy wording
Before saving a newly generated guide, automated checks review lesson fit, accuracy, activity logic, resources, pupil language and AI literacy. Up to four batches inspect the draft against the teacher brief; one correction cycle is allowed, followed by another review of all batches. Failed or unavailable review prevents the new guide from being saved. Saved review evidence and resolved findings may quote the brief or draft. These checks can miss errors and are not human approval or a dedicated final-output safety classifier. Existing guides are not retrospectively checked; eligible saved guides may be reused.
See what the AI provider keeps
Zero data retention applies to provider processing of prompts and outputs. Your saved guides stay in AILitKit until you delete them.
Read the policy wording
Our OpenRouter account has zero data retention (ZDR) enabled, and requests also require ZDR inference endpoints. This applies to provider processing of prompts and outputs, including retries and fallback. It does not delete your saved AILitKit guides, account records or necessary service metadata. OpenRouter permits temporary in-memory prompt caching under its ZDR policy.
Where it is processed
Check each service and its location
Locations below are the ones our privacy policy confirms. Where none is stated, ask us for the current transfer evidence.
| Service | Purpose | Data | Location |
|---|---|---|---|
| OpenRouter | Luna drafting and content review; Gemini backup; Llama Guard and conditional Gemini safeguarding | Teacher brief, extracted source, draft and review context (ZDR inference routing) | Depends on the inference operator; processing can occur outside the UK/EEA |
| OpenAI (direct, when configured) | Additional moderation | Safeguarding input sample; separate OpenAI API terms | Not stated in our privacy policy; ask us for the current transfer evidence |
| Scaleway | Keyword embeddings | Curriculum terms only | Paris, France (EU) |
| Supabase | Database, authentication, file storage | Account data, guides, safety and audit logs | EU (eu-west-1) |
| Stripe | Payment processing | Email, payment details, subscription state | Not stated in our privacy policy; ask us for the current transfer evidence |
| Resend | Transactional and lifecycle email; delivery-status webhooks (bounce, complaint) | Email address, display name | Not stated in our privacy policy; ask us for the current transfer evidence |
| Vercel | Application hosting, scheduled jobs | Application requests and operational diagnostics | Hosting includes processing in the US |
| Upstash QStash | Guide generation scheduling | Job identifier; retry and dead-letter retention follow account settings | Depends on the service configuration |
Watch out for transfers
Some processing can occur outside the UK/EEA, including Vercel hosting and AI inference routed through OpenRouter. An EU database location does not mean all processing stays in the EU. ZDR limits retention and does not itself establish a transfer mechanism. Do not infer that every processor is DPF-certified.
How long we keep it
Check each retention period
| Record | How long |
|---|---|
| Account data | Remains while your account is active. |
| Saved guides, their input descriptions and review evidence | Remain until you delete the guide or account. Deleted guides have a 30-day undo window and are then purged by scheduled cleanup. |
| Guide-building job records | While a guide is being built, its job record holds the request needed for processing and retries. On completion, failure or expiry, that record loses its input payload and duplicate output. Identifiers, scope, status, timings, usage and support diagnostics remain temporarily: completed jobs are eligible for deletion after 24 hours, and failed or expired jobs after seven days, at the next successful cleanup. The saved guide, its input description and review evidence follow the guide retention period. |
| Uploaded files and extracted text | After successful generation, cleanup deletes the original uploaded file and clears the extracted text from the upload record, keeping filename, type and date. Unused uploads and failed cleanup are eligible for the scheduled sweep once the upload is over one hour old. The sweep runs every 15 minutes; deletion can take longer if a cleanup attempt fails. Relevant source-derived material can remain in the saved guide and its review evidence. |
| Safeguarding audit entries | Remain for the account lifetime. |
| Administrative-actions audit | Retained for 365 days, then purged by a scheduled cleanup job. |
| Stripe webhook event log (event ID, type, timestamp; no card data) | Retained for 90 days to prevent duplicate processing, then deleted by a scheduled cleanup job. Invoices and payment records are held by Stripe under its own retention obligations. |
| Hosting logs and provider backups | Follow their service schedules. Deletion from the active database is not a promise of immediate erasure from every backup. |
Backups follow their own schedule; this is not a promise of immediate erasure from every backup. Account deletion removes account-linked reports, upload records, memberships and safeguarding entries from active storage.
Automated decisions
Ask a person to review a refusal or flag
Guide generation does not grade pupils, decide admissions or progression, or assess individual learners. Automated service checks do decide whether a request can proceed and whether a draft passes review. A second AI model is not human intervention. You can ask a person to review a refusal or flag by contacting hello@ailitkit.com or safeguarding@ailitkit.com; we aim to respond within five working days. A content flag is not a finding of misconduct by a teacher.
Request a human review
Tell us which request was refused or flagged and when.
Start your DPIA
Choose your region, then print or save as PDF
Each template is pre-filled with AILitKit's product details. Your school rates each risk, records the decision and signs it.
How to complete it: read each mitigation, rate the likelihood and severity for your own use, and ask hello@ailitkit.com for any processor agreement or transfer evidence you need before signing.
For schools in England, Scotland, Wales and Northern Ireland. Pre-filled for UK GDPR Article 35.
Data Protection Impact Assessment
AILitKit: AI literacy guide generation platform (UK GDPR Article 35)
Template last updated: 9 September 2026
Data Protection Impact Assessment
UK GDPR Article 35. Template last updated: 9 September 2026
Processing and retention, policy of 9 September 2026
Guide drafting and content review use Luna as the primary model, with Gemini as the configured backup, through OpenRouter. Safeguarding uses Llama Guard and, when needed, a separate Gemini curriculum reviewer. Model developers and the companies operating inference endpoints are not necessarily the same.
Our OpenRouter account has zero data retention (ZDR) enabled, and requests also require ZDR inference endpoints. This applies to provider processing of prompts and outputs, including retries and fallback. It does not delete your saved AILitKit guides, account records or necessary service metadata. OpenRouter permits temporary in-memory prompt caching under its ZDR policy.
Before new generation, automated safeguarding checks read the subject, stage, year group and topic, plus up to the first 1,000 characters each of the teacher description and extracted upload text. Llama Guard gives a first verdict; a Gemini reviewer runs if that verdict is unsafe, unavailable or unreadable. An additional direct OpenAI moderation check runs when configured, under its separate API terms. If no usable safeguarding verdict is available, generation pauses with a retry message. A usable unsafe verdict is preserved if its reviewer fails; hard-block categories cannot be cleared by that reviewer.
Before saving a newly generated guide, automated checks review lesson fit, accuracy, activity logic, resources, pupil language and AI literacy. Up to four batches inspect the draft against the teacher brief; one correction cycle is allowed, followed by another review of all batches. Failed or unavailable review prevents the new guide from being saved. Saved review evidence and resolved findings may quote the brief or draft. These checks can miss errors and are not human approval or a dedicated final-output safety classifier. Existing guides are not retrospectively checked; eligible saved guides may be reused.
Pupil-facing language is targeted using the year group or key stage supplied by the teacher. This is a class-level assumption, not an individual reading-age assessment. Teachers must adapt wording and resources for their actual readers, including SEND and EAL needs, and check third-party tools, links and safeguarding before classroom use.
While a guide is being built, its job record holds the request needed for processing and retries. On completion, failure or expiry, that record loses its input payload and duplicate output. Identifiers, scope, status, timings, usage and support diagnostics remain temporarily: completed jobs are eligible for deletion after 24 hours, and failed or expired jobs after seven days, at the next successful cleanup. The saved guide, its input description and review evidence follow the guide retention period.
After successful generation, cleanup deletes the original uploaded file and clears the extracted text from the upload record, keeping filename, type and date. Unused uploads and failed cleanup are eligible for the scheduled sweep once the upload is over one hour old. The sweep runs every 15 minutes; deletion can take longer if a cleanup attempt fails. Relevant source-derived material can remain in the saved guide and its review evidence.
Guide generation does not grade pupils, decide admissions or progression, or assess individual learners. Automated service checks do decide whether a request can proceed and whether a draft passes review. A second AI model is not human intervention. You can ask a person to review a refusal or flag by contacting hello@ailitkit.com or safeguarding@ailitkit.com; we aim to respond within five working days. A content flag is not a finding of misconduct by a teacher.
Do not enter identifiable pupil information, assessment records, safeguarding records, EHCP/SEN documents or staff personal data. AILitKit needs curriculum content only. Warnings and input cleaning do not guarantee anonymisation: information entered accidentally can still be processed and appear in a saved guide or audit evidence. Contact hello@ailitkit.com promptly if this happens.
Safeguarding audit retains a classifier explanation that may refer to screened content. Allowed decisions keep no input snapshot; flagged decisions also keep the topic and a short description excerpt. Saved guide review evidence follows the guide retention period, including its 30-day undo window. Hosting logs and backups have separate service schedules. The school reviewer should obtain the current processor, transfer and retention evidence and record their own risk decision.
1. Project details
2. Description of data processing
Personal data processed
- Teacher email address (for account and authentication)
- Teacher display name (optional, for personalisation)
- School or trust name (optional)
- Country and, where applicable, emirate, used to apply the right regional framework set and safeguarding context
- Teaching preferences: primary key stage and primary subject
- Onboarding status, communication preferences, and a record of which transactional and lifecycle emails have been sent
- Last successful sign-in timestamp, mirrored from the authentication system. Used for inactivity tracking, re-engagement decisions, and operational visibility in the administrative dashboard.
- Per-user lesson quota state (monthly free allowance and any administrator-granted bonus generations)
- Where applicable: organisation membership and role (member, admin, owner, trust admin), invitation history
- Where applicable: Stripe customer and subscription identifiers, founding-member status and timestamps for founding-conversion reminders
- Curriculum content provided by the teacher (lesson plans, schemes of work, topic descriptions)
- Generated guides, activity selections, input description and content-review evidence
- Safeguarding-classifier audit log (verdict, layer, category, explanation, model, latency). For decisions flagged "sensitive" or "blocked" only, the topic and up to 250 characters of the free-text description, plus a flag if an upload was involved. Allowed decisions retain no input snippet. The upload body is not stored in this log. The classifier explanation may refer to screened material.
- Administrative-actions audit log. One row for every administrator-initiated change to a user account (for example sending a password reset, extending access, suspending or reinstating an account, granting bonus generations, deleting an account, or issuing a customer-support magic-link to sign in as a school owner or admin for a support, billing or demo call). Each row captures the acting administrator, the target account, the action type, a small metadata payload and the timestamp. Retained for 365 days and then purged by a scheduled cleanup job. Visible only to administrators inside the platform.
- Bulk teacher invitation imports. School and trust admins may upload a CSV of colleague email addresses. The parsed rows are stored for the duration of the invitation lifecycle so the admin can re-run, retry or roll back the batch.
- Organisation invitation lifecycle data including declined and bounced timestamps, the bounce reason returned by Resend, and the allowed-email-domain restriction set by the organisation owner.
- In-product course progress and issued certificates, including a unique verification token. The public verification page at /cert/<token> reveals only the holder's display name, the course title, the completion date, and that the certificate is genuine.
- IP address. Processed transiently to enforce per-route rate limits. The rate-limit bucket is held in memory or in a short-lived database row keyed by IP, is not joined to the user account, and is discarded once the rate-limit window has passed (typically minutes). Vercel request logs also record IP for standard hosting observability.
Data teachers must not submit
- Pupil personal data
- Pupil assessment data
- Safeguarding records
- EHCP or SEN documents
- Staff HR data
- Pastoral notes
Data subjects
Teachers (adults) who create accounts. Pupils do not interact with the platform and should not create accounts.
Third-party processors
| Service | Purpose | Data | Location |
|---|---|---|---|
| OpenRouter | Luna drafting and content review; Gemini backup; Llama Guard and conditional Gemini safeguarding | Teacher brief, extracted source, draft and review context (ZDR inference routing) | Depends on the inference operator; processing can occur outside the UK/EEA |
| OpenAI (direct, when configured) | Additional moderation | Safeguarding input sample; separate OpenAI API terms | Not stated in our privacy policy; ask us for the current transfer evidence |
| Scaleway | Keyword embeddings | Curriculum terms only | Paris, France (EU) |
| Supabase | Database, authentication, file storage | Account data, guides, safety and audit logs | EU (eu-west-1) |
| Stripe | Payment processing | Email, payment details, subscription state | Not stated in our privacy policy; ask us for the current transfer evidence |
| Resend | Transactional and lifecycle email; delivery-status webhooks (bounce, complaint) | Email address, display name | Not stated in our privacy policy; ask us for the current transfer evidence |
| Vercel | Application hosting, scheduled jobs | Application requests and operational diagnostics | Hosting includes processing in the US |
| Upstash QStash | Guide generation scheduling | Job identifier; retry and dead-letter retention follow account settings | Depends on the service configuration |
An EU database location does not mean all processing stays in the EU. Where a location is not stated, ask hello@ailitkit.com for the current processor agreement and transfer evidence.
File handling
See the processing and retention section for original-file cleanup, job minimisation and source excerpts retained in guides. Cleanup is retried on failure; there is no absolute one-hour deletion guarantee.
3. Necessity and proportionality
Why is this processing necessary?
Keeping Children Safe in Education 2026, in force from 1 September 2026, is the current statutory safeguarding guidance. It carries AI-specific provisions including AI-generated imagery, deepfakes, and AI-simulated interaction. Teachers need practical support to integrate AI literacy into their existing curriculum. AILitKit processes curriculum content to generate tailored, framework-aligned AI literacy guides, reducing teacher workload and supporting consistent quality.
Is the processing proportionate?
The school must assess necessity and proportionality for its own use. The service minimises completed-job data and uses ZDR inference, but input descriptions, guide content and review evidence remain with saved guides. Identifying information can be submitted accidentally.
Lawful basis
Article 6(1)(b), contract performance (account management and guide generation). Article 6(1)(f), legitimate interests (service improvement, security, abuse prevention, and the layered safeguarding classifier).
4. Risks identified and mitigations
Rate the likelihood and severity of each risk for your own use, after reading the mitigation. We describe the product controls; your school records the rating and the decision.
| # | Risk | Likelihood | Severity | Mitigation |
|---|---|---|---|---|
| 1 | Teachers upload documents containing personal data (for example pupil names in lesson plans) | Clear warnings are displayed before upload. After successful generation, cleanup deletes the original uploaded file and clears the extracted text from the upload record, keeping filename, type and date. Unused uploads and failed cleanup are picked up by a scheduled sweep once the upload is over one hour old; the sweep runs every 15 minutes, and deletion can take longer if a cleanup attempt fails. Relevant source-derived material can remain in the saved guide and its review evidence. Contact hello@ailitkit.com promptly if identifying information was uploaded. | ||
| 2 | AI-generated content contains factual errors or inappropriate suggestions, or covers a safeguarding-sensitive topic without appropriate framing | Before new generation, automated safeguarding checks read the subject, stage, year group and topic, plus up to the first 1,000 characters each of the teacher description and extracted upload text. Llama Guard gives a first verdict. A curriculum-aware Gemini reviewer runs if that verdict is unsafe, unavailable or unreadable, and considers whether a flagged topic fits an established curriculum context (for example GCSE Biology reproduction). Hard-block categories cannot be cleared by that reviewer. An additional direct OpenAI moderation check runs when configured, under its separate API terms. If no usable safeguarding verdict is available, generation pauses with a retry message. Before a new guide is saved, automated checks review lesson fit, accuracy, activity logic, resources, pupil language and AI literacy; failed or unavailable review prevents the guide from being saved. These checks can miss errors and are not human approval. Every guide is labelled as AI-generated, teachers must review it before classroom use, and concerns can be reported to hello@ailitkit.com. | ||
| 3 | Pupil personal data entered in text input fields | Input warnings advise against entering personal data. The platform is teacher-only with no pupil accounts, and guide generation needs curriculum content only (topics, not names). Warnings and input cleaning do not guarantee anonymisation: information entered accidentally can still be processed and appear in a saved guide or audit evidence. | ||
| 4 | Data processed outside the school’s own country by service providers | Our OpenRouter account has zero data retention (ZDR) enabled, and requests also require ZDR inference endpoints. This applies to provider processing of prompts and outputs, including retries and fallback. It does not delete saved AILitKit guides, account records or necessary service metadata, and OpenRouter permits temporary in-memory prompt caching under its ZDR policy. ZDR limits retention and does not itself establish a transfer mechanism. Some processing can occur outside the UK, including Vercel hosting and AI inference routed through OpenRouter. Consider the current processor agreements, actual destinations and applicable transfer safeguards, such as the UK Addendum to the EU Standard Contractual Clauses or the IDTA where required. Do not infer that every processor is DPF-certified. The Supabase database (eu-west-1) and Scaleway embeddings (Paris) use EU locations. Task scheduling sends a job identifier to Upstash QStash; its location, retries and dead-letter retention follow the service configuration. | ||
| 5 | Organisation administrators see colleague metadata and flagged safeguarding decisions in a school or trust account | School and trust admins see a member roster (name, email, role, status), can manage seats, and can see safeguarding decisions flagged as "sensitive" or "blocked" for accounts in their organisation. They never see allowed decisions, and never see a colleague's guides unless the colleague shares them. Access is enforced by database row-level security and lets the designated safeguarding lead step in if a colleague is repeatedly hitting the gate. Disclosed in the Privacy Policy and Terms. | ||
| 6 | Internal audit logs (safeguarding decisions, Stripe idempotency, administrative alerts) retained for safety and reconciliation | Safeguarding-decision rows are minimised at write time. Allowed decisions keep verdict and decision metadata only, with no input snippet. Sensitive or blocked decisions also keep the topic and up to 250 description characters, plus a flag if an upload was involved; the upload body is not stored in this log. The organisation-admin dashboard shows these rows truncated at render time; this is a view of the same row, not a separate copy. Subject, key stage and year group are not duplicated into this log; they live on the guide row. Safeguarding rows are tied to the user and removed from active storage on account deletion. The Stripe webhook log holds event identifiers only, no card data, and is not tied to a user account. Retention is disclosed in the Privacy Policy. | ||
| 7 | Incorrect automated refusal or misinterpretation of a content flag | Automated checks decide whether content proceeds; they do not grade pupils or decide admissions or progression. A second model is not human review. A person can review a refusal or flag via hello@ailitkit.com or safeguarding@ailitkit.com. Assess whether any use has legal or similarly significant effects under the applicable rules; do not assume every content check meets that threshold. | ||
| 8 | Super-admin impersonation of a school owner or admin via a customer-support magic-link | AILitKit operations staff may issue a single, time-limited sign-in link to a school's owner email (or, where there is no owner, the most recently active admin) to investigate a support request, reproduce a billing or generation issue, or run a demo. The link expires within approximately one hour. Every issuance is recorded to the administrative-actions audit log with the operations user, the target account, the timestamp and the support context; the audit row is retained for 365 days. The capability is restricted to verified super-admin accounts. Use is disclosed in the Privacy Policy under “Customer support access (impersonation)”. A future enhancement will notify the affected school owner of any new impersonation event; schools can request their full impersonation history at any time. | ||
| 9 | Public certificate verification reveals holder display name, course title and completion date by token | Anyone holding a certificate's verification token can open its verification page without an account and see the holder's display name, the course title, the completion date, and confirmation that the certificate is genuine. No other personal data is shown. Holders can rotate or revoke a certificate on request. | ||
| 10 | Bulk teacher invitation CSVs contain colleague email addresses processed before the invitee has had an opportunity to consent | Bulk imports are run only by school or trust admins. The invitee receives a transactional activation email which is the Article 14 disclosure point: it identifies AILitKit as the controller for the teacher account record, names the originating school admin, and explains the processing. The invitee may decline or not activate the account, in which case the row is retained for the invitation lifecycle and then removed. | ||
| 11 | EU AI Act classification and Article 50 transparency | Guide generation supports teacher planning; it does not grade pupils, decide admissions or progression, or proctor exams. Every guide is labelled as AI-generated, and the layered checks are described in the Privacy Policy and the Safeguarding statement. Regulatory assessment depends on the actual purpose and deployment; this template is not a certification. Record your school's own assessment here. |
5. Consultation
This assessment should be reviewed by your school's Data Protection Officer (DPO) or data protection lead before adopting AILitKit. If residual risks remain high after mitigation, consult the Information Commissioner's Office (ICO) at ico.org.uk before proceeding.
6. Decision
Recommendation
This template records product controls, not an approved risk rating. The school must confirm its intended use, processor agreements, transfers, access and retention, evaluate the remaining risks and record its decision below.
This DPIA template is pre-filled with AILitKit product details and is provided to help schools meet their obligations under UK GDPR Article 35. Schools should adapt this assessment to reflect their own policies and circumstances. Template prepared by IN&ED (inanded.com).
Review cadence. IN&ED reviews this template at least every six months and immediately when a new processing activity is added, a new sub-processor is engaged, a sub-processor's data-handling terms change, or the statutory frameworks named above change. Schools should re-review their own completed copy on the same cadence and whenever their own policies change.
For data-protection questions, contact hello@ailitkit.com. For safeguarding questions, contact safeguarding@ailitkit.com.
Data Protection Impact Assessment
AILitKit: AI literacy guide generation platform (EU GDPR Article 35)
Template last updated: 9 September 2026
Data Protection Impact Assessment
EU GDPR Article 35. Template last updated: 9 September 2026
Processing and retention, policy of 9 September 2026
Guide drafting and content review use Luna as the primary model, with Gemini as the configured backup, through OpenRouter. Safeguarding uses Llama Guard and, when needed, a separate Gemini curriculum reviewer. Model developers and the companies operating inference endpoints are not necessarily the same.
Our OpenRouter account has zero data retention (ZDR) enabled, and requests also require ZDR inference endpoints. This applies to provider processing of prompts and outputs, including retries and fallback. It does not delete your saved AILitKit guides, account records or necessary service metadata. OpenRouter permits temporary in-memory prompt caching under its ZDR policy.
Before new generation, automated safeguarding checks read the subject, stage, year group and topic, plus up to the first 1,000 characters each of the teacher description and extracted upload text. Llama Guard gives a first verdict; a Gemini reviewer runs if that verdict is unsafe, unavailable or unreadable. An additional direct OpenAI moderation check runs when configured, under its separate API terms. If no usable safeguarding verdict is available, generation pauses with a retry message. A usable unsafe verdict is preserved if its reviewer fails; hard-block categories cannot be cleared by that reviewer.
Before saving a newly generated guide, automated checks review lesson fit, accuracy, activity logic, resources, pupil language and AI literacy. Up to four batches inspect the draft against the teacher brief; one correction cycle is allowed, followed by another review of all batches. Failed or unavailable review prevents the new guide from being saved. Saved review evidence and resolved findings may quote the brief or draft. These checks can miss errors and are not human approval or a dedicated final-output safety classifier. Existing guides are not retrospectively checked; eligible saved guides may be reused.
Pupil-facing language is targeted using the year group or key stage supplied by the teacher. This is a class-level assumption, not an individual reading-age assessment. Teachers must adapt wording and resources for their actual readers, including SEND and EAL needs, and check third-party tools, links and safeguarding before classroom use.
While a guide is being built, its job record holds the request needed for processing and retries. On completion, failure or expiry, that record loses its input payload and duplicate output. Identifiers, scope, status, timings, usage and support diagnostics remain temporarily: completed jobs are eligible for deletion after 24 hours, and failed or expired jobs after seven days, at the next successful cleanup. The saved guide, its input description and review evidence follow the guide retention period.
After successful generation, cleanup deletes the original uploaded file and clears the extracted text from the upload record, keeping filename, type and date. Unused uploads and failed cleanup are eligible for the scheduled sweep once the upload is over one hour old. The sweep runs every 15 minutes; deletion can take longer if a cleanup attempt fails. Relevant source-derived material can remain in the saved guide and its review evidence.
Guide generation does not grade pupils, decide admissions or progression, or assess individual learners. Automated service checks do decide whether a request can proceed and whether a draft passes review. A second AI model is not human intervention. You can ask a person to review a refusal or flag by contacting hello@ailitkit.com or safeguarding@ailitkit.com; we aim to respond within five working days. A content flag is not a finding of misconduct by a teacher.
Do not enter identifiable pupil information, assessment records, safeguarding records, EHCP/SEN documents or staff personal data. AILitKit needs curriculum content only. Warnings and input cleaning do not guarantee anonymisation: information entered accidentally can still be processed and appear in a saved guide or audit evidence. Contact hello@ailitkit.com promptly if this happens.
Safeguarding audit retains a classifier explanation that may refer to screened content. Allowed decisions keep no input snapshot; flagged decisions also keep the topic and a short description excerpt. Saved guide review evidence follows the guide retention period, including its 30-day undo window. Hosting logs and backups have separate service schedules. The school reviewer should obtain the current processor, transfer and retention evidence and record their own risk decision.
1. Project details
2. Description of data processing
Personal data processed
- Teacher email address (for account and authentication)
- Teacher display name (optional, for personalisation)
- School or trust name (optional)
- Country and, where applicable, emirate, used to apply the right regional framework set and safeguarding context
- Teaching preferences: primary key stage and primary subject
- Onboarding status, communication preferences, and a record of which transactional and lifecycle emails have been sent
- Last successful sign-in timestamp, mirrored from the authentication system. Used for inactivity tracking, re-engagement decisions, and operational visibility in the administrative dashboard.
- Per-user lesson quota state (monthly free allowance and any administrator-granted bonus generations)
- Where applicable: organisation membership and role (member, admin, owner, trust admin), invitation history
- Where applicable: Stripe customer and subscription identifiers, founding-member status and timestamps for founding-conversion reminders
- Curriculum content provided by the teacher (lesson plans, schemes of work, topic descriptions)
- Generated guides, activity selections, input description and content-review evidence
- Safeguarding-classifier audit log (verdict, layer, category, explanation, model, latency). For decisions flagged "sensitive" or "blocked" only, the topic and up to 250 characters of the free-text description, plus a flag if an upload was involved. Allowed decisions retain no input snippet. The upload body is not stored in this log. The classifier explanation may refer to screened material.
- Administrative-actions audit log. One row for every administrator-initiated change to a user account (for example sending a password reset, extending access, suspending or reinstating an account, granting bonus generations, deleting an account, or issuing a customer-support magic-link to sign in as a school owner or admin for a support, billing or demo call). Each row captures the acting administrator, the target account, the action type, a small metadata payload and the timestamp. Retained for 365 days and then purged by a scheduled cleanup job. Visible only to administrators inside the platform.
- Bulk teacher invitation imports. School and trust admins may upload a CSV of colleague email addresses. The parsed rows are stored for the duration of the invitation lifecycle so the admin can re-run, retry or roll back the batch.
- Organisation invitation lifecycle data including declined and bounced timestamps, the bounce reason returned by Resend, and the allowed-email-domain restriction set by the organisation owner.
- In-product course progress and issued certificates, including a unique verification token. The public verification page at /cert/<token> reveals only the holder's display name, the course title, the completion date, and that the certificate is genuine.
- IP address. Processed transiently to enforce per-route rate limits. The rate-limit bucket is held in memory or in a short-lived database row keyed by IP, is not joined to the user account, and is discarded once the rate-limit window has passed (typically minutes). Vercel request logs also record IP for standard hosting observability.
Data teachers must not submit
- Pupil personal data
- Pupil assessment data
- Safeguarding records
- EHCP or SEN documents
- Staff HR data
- Pastoral notes
Data subjects
Teachers (adults) who create accounts. Pupils do not interact with the platform and should not create accounts.
Third-party processors
| Service | Purpose | Data | Location |
|---|---|---|---|
| OpenRouter | Luna drafting and content review; Gemini backup; Llama Guard and conditional Gemini safeguarding | Teacher brief, extracted source, draft and review context (ZDR inference routing) | Depends on the inference operator; processing can occur outside the UK/EEA |
| OpenAI (direct, when configured) | Additional moderation | Safeguarding input sample; separate OpenAI API terms | Not stated in our privacy policy; ask us for the current transfer evidence |
| Scaleway | Keyword embeddings | Curriculum terms only | Paris, France (EU) |
| Supabase | Database, authentication, file storage | Account data, guides, safety and audit logs | EU (eu-west-1) |
| Stripe | Payment processing | Email, payment details, subscription state | Not stated in our privacy policy; ask us for the current transfer evidence |
| Resend | Transactional and lifecycle email; delivery-status webhooks (bounce, complaint) | Email address, display name | Not stated in our privacy policy; ask us for the current transfer evidence |
| Vercel | Application hosting, scheduled jobs | Application requests and operational diagnostics | Hosting includes processing in the US |
| Upstash QStash | Guide generation scheduling | Job identifier; retry and dead-letter retention follow account settings | Depends on the service configuration |
An EU database location does not mean all processing stays in the EU. Where a location is not stated, ask hello@ailitkit.com for the current processor agreement and transfer evidence.
File handling
See the processing and retention section for original-file cleanup, job minimisation and source excerpts retained in guides. Cleanup is retried on failure; there is no absolute one-hour deletion guarantee.
3. Necessity and proportionality
Why is this processing necessary?
The EU AI Act and national curriculum frameworks increasingly require AI literacy in schools. Teachers need practical support to integrate AI literacy into their existing curriculum. AILitKit processes curriculum content to generate tailored, framework-aligned AI literacy guides, reducing teacher workload and supporting consistent quality.
Is the processing proportionate?
The school must assess necessity and proportionality for its own use. The service minimises completed-job data and uses ZDR inference, but input descriptions, guide content and review evidence remain with saved guides. Identifying information can be submitted accidentally.
Lawful basis
Article 6(1)(b), contract performance (account management and guide generation). Article 6(1)(f), legitimate interests (service improvement, security, abuse prevention, and the layered safeguarding classifier).
4. Risks identified and mitigations
Rate the likelihood and severity of each risk for your own use, after reading the mitigation. We describe the product controls; your school records the rating and the decision.
| # | Risk | Likelihood | Severity | Mitigation |
|---|---|---|---|---|
| 1 | Teachers upload documents containing personal data (for example pupil names in lesson plans) | Clear warnings are displayed before upload. After successful generation, cleanup deletes the original uploaded file and clears the extracted text from the upload record, keeping filename, type and date. Unused uploads and failed cleanup are picked up by a scheduled sweep once the upload is over one hour old; the sweep runs every 15 minutes, and deletion can take longer if a cleanup attempt fails. Relevant source-derived material can remain in the saved guide and its review evidence. Contact hello@ailitkit.com promptly if identifying information was uploaded. | ||
| 2 | AI-generated content contains factual errors or inappropriate suggestions, or covers a safeguarding-sensitive topic without appropriate framing | Before new generation, automated safeguarding checks read the subject, stage, year group and topic, plus up to the first 1,000 characters each of the teacher description and extracted upload text. Llama Guard gives a first verdict. A curriculum-aware Gemini reviewer runs if that verdict is unsafe, unavailable or unreadable, and considers whether a flagged topic fits an established curriculum context (for example GCSE Biology reproduction). Hard-block categories cannot be cleared by that reviewer. An additional direct OpenAI moderation check runs when configured, under its separate API terms. If no usable safeguarding verdict is available, generation pauses with a retry message. Before a new guide is saved, automated checks review lesson fit, accuracy, activity logic, resources, pupil language and AI literacy; failed or unavailable review prevents the guide from being saved. These checks can miss errors and are not human approval. Every guide is labelled as AI-generated, teachers must review it before classroom use, and concerns can be reported to hello@ailitkit.com. | ||
| 3 | Pupil personal data entered in text input fields | Input warnings advise against entering personal data. The platform is teacher-only with no pupil accounts, and guide generation needs curriculum content only (topics, not names). Warnings and input cleaning do not guarantee anonymisation: information entered accidentally can still be processed and appear in a saved guide or audit evidence. | ||
| 4 | Data processed outside the school’s own country by service providers | Our OpenRouter account has zero data retention (ZDR) enabled, and requests also require ZDR inference endpoints. This applies to provider processing of prompts and outputs, including retries and fallback. It does not delete saved AILitKit guides, account records or necessary service metadata, and OpenRouter permits temporary in-memory prompt caching under its ZDR policy. ZDR limits retention and does not itself establish a transfer mechanism. Some processing can occur outside the EEA, including Vercel hosting and AI inference routed through OpenRouter. Consider the current processor agreements, actual destinations and applicable transfer safeguards, such as EU Standard Contractual Clauses. Do not infer that every processor is DPF-certified; EU database storage does not establish end-to-end EU processing. The Supabase database (eu-west-1) and Scaleway embeddings (Paris) use EU locations. Task scheduling sends a job identifier to Upstash QStash; its location, retries and dead-letter retention follow the service configuration. | ||
| 5 | Organisation administrators see colleague metadata and flagged safeguarding decisions in a school or trust account | School and trust admins see a member roster (name, email, role, status), can manage seats, and can see safeguarding decisions flagged as "sensitive" or "blocked" for accounts in their organisation. They never see allowed decisions, and never see a colleague's guides unless the colleague shares them. Access is enforced by database row-level security and lets the designated safeguarding lead step in if a colleague is repeatedly hitting the gate. Disclosed in the Privacy Policy and Terms. | ||
| 6 | Internal audit logs (safeguarding decisions, Stripe idempotency, administrative alerts) retained for safety and reconciliation | Safeguarding-decision rows are minimised at write time. Allowed decisions keep verdict and decision metadata only, with no input snippet. Sensitive or blocked decisions also keep the topic and up to 250 description characters, plus a flag if an upload was involved; the upload body is not stored in this log. The organisation-admin dashboard shows these rows truncated at render time; this is a view of the same row, not a separate copy. Subject, key stage and year group are not duplicated into this log; they live on the guide row. Safeguarding rows are tied to the user and removed from active storage on account deletion. The Stripe webhook log holds event identifiers only, no card data, and is not tied to a user account. Retention is disclosed in the Privacy Policy. | ||
| 7 | Incorrect automated refusal or misinterpretation of a content flag | Automated checks decide whether content proceeds; they do not grade pupils or decide admissions or progression. A second model is not human review. A person can review a refusal or flag via hello@ailitkit.com or safeguarding@ailitkit.com. Assess whether any use has legal or similarly significant effects under the applicable rules; do not assume every content check meets that threshold. | ||
| 8 | Super-admin impersonation of a school owner or admin via a customer-support magic-link | AILitKit operations staff may issue a single, time-limited sign-in link to a school's owner email (or, where there is no owner, the most recently active admin) to investigate a support request, reproduce a billing or generation issue, or run a demo. The link expires within approximately one hour. Every issuance is recorded to the administrative-actions audit log with the operations user, the target account, the timestamp and the support context; the audit row is retained for 365 days. The capability is restricted to verified super-admin accounts. Use is disclosed in the Privacy Policy under “Customer support access (impersonation)”. A future enhancement will notify the affected school owner of any new impersonation event; schools can request their full impersonation history at any time. | ||
| 9 | Public certificate verification reveals holder display name, course title and completion date by token | Anyone holding a certificate's verification token can open its verification page without an account and see the holder's display name, the course title, the completion date, and confirmation that the certificate is genuine. No other personal data is shown. Holders can rotate or revoke a certificate on request. | ||
| 10 | Bulk teacher invitation CSVs contain colleague email addresses processed before the invitee has had an opportunity to consent | Bulk imports are run only by school or trust admins. The invitee receives a transactional activation email which is the Article 14 disclosure point: it identifies AILitKit as the controller for the teacher account record, names the originating school admin, and explains the processing. The invitee may decline or not activate the account, in which case the row is retained for the invitation lifecycle and then removed. | ||
| 11 | EU AI Act classification and Article 50 transparency | Guide generation supports teacher planning; it does not grade pupils, decide admissions or progression, or proctor exams. Every guide is labelled as AI-generated, and the layered checks are described in the Privacy Policy and the Safeguarding statement. Regulatory assessment depends on the actual purpose and deployment; this template is not a certification. Record your school's own assessment here. |
5. Consultation
This assessment should be reviewed by your school's Data Protection Officer (DPO) or data protection lead before adopting AILitKit. If residual risks remain high after mitigation, consult the your national Data Protection Authority before proceeding.
6. Decision
Recommendation
This template records product controls, not an approved risk rating. The school must confirm its intended use, processor agreements, transfers, access and retention, evaluate the remaining risks and record its decision below.
This DPIA template is pre-filled with AILitKit product details and is provided to help schools meet their obligations under EU GDPR Article 35. Schools should adapt this assessment to reflect their own policies and circumstances. Template prepared by IN&ED (inanded.com).
Review cadence. IN&ED reviews this template at least every six months and immediately when a new processing activity is added, a new sub-processor is engaged, a sub-processor's data-handling terms change, or the statutory frameworks named above change. Schools should re-review their own completed copy on the same cadence and whenever their own policies change.
For data-protection questions, contact hello@ailitkit.com. For safeguarding questions, contact safeguarding@ailitkit.com.
Data Protection Assessment
AILitKit: AI literacy guide generation platform (UAE Federal Decree-Law No. 45/2021 (PDPL), where applicable)
Template last updated: 9 September 2026
Data Protection Assessment
UAE Federal Decree-Law No. 45/2021 (PDPL), where applicable. Template last updated: 9 September 2026
Processing and retention, policy of 9 September 2026
Guide drafting and content review use Luna as the primary model, with Gemini as the configured backup, through OpenRouter. Safeguarding uses Llama Guard and, when needed, a separate Gemini curriculum reviewer. Model developers and the companies operating inference endpoints are not necessarily the same.
Our OpenRouter account has zero data retention (ZDR) enabled, and requests also require ZDR inference endpoints. This applies to provider processing of prompts and outputs, including retries and fallback. It does not delete your saved AILitKit guides, account records or necessary service metadata. OpenRouter permits temporary in-memory prompt caching under its ZDR policy.
Before new generation, automated safeguarding checks read the subject, stage, year group and topic, plus up to the first 1,000 characters each of the teacher description and extracted upload text. Llama Guard gives a first verdict; a Gemini reviewer runs if that verdict is unsafe, unavailable or unreadable. An additional direct OpenAI moderation check runs when configured, under its separate API terms. If no usable safeguarding verdict is available, generation pauses with a retry message. A usable unsafe verdict is preserved if its reviewer fails; hard-block categories cannot be cleared by that reviewer.
Before saving a newly generated guide, automated checks review lesson fit, accuracy, activity logic, resources, pupil language and AI literacy. Up to four batches inspect the draft against the teacher brief; one correction cycle is allowed, followed by another review of all batches. Failed or unavailable review prevents the new guide from being saved. Saved review evidence and resolved findings may quote the brief or draft. These checks can miss errors and are not human approval or a dedicated final-output safety classifier. Existing guides are not retrospectively checked; eligible saved guides may be reused.
Pupil-facing language is targeted using the year group or key stage supplied by the teacher. This is a class-level assumption, not an individual reading-age assessment. Teachers must adapt wording and resources for their actual readers, including SEND and EAL needs, and check third-party tools, links and safeguarding before classroom use.
While a guide is being built, its job record holds the request needed for processing and retries. On completion, failure or expiry, that record loses its input payload and duplicate output. Identifiers, scope, status, timings, usage and support diagnostics remain temporarily: completed jobs are eligible for deletion after 24 hours, and failed or expired jobs after seven days, at the next successful cleanup. The saved guide, its input description and review evidence follow the guide retention period.
After successful generation, cleanup deletes the original uploaded file and clears the extracted text from the upload record, keeping filename, type and date. Unused uploads and failed cleanup are eligible for the scheduled sweep once the upload is over one hour old. The sweep runs every 15 minutes; deletion can take longer if a cleanup attempt fails. Relevant source-derived material can remain in the saved guide and its review evidence.
Guide generation does not grade pupils, decide admissions or progression, or assess individual learners. Automated service checks do decide whether a request can proceed and whether a draft passes review. A second AI model is not human intervention. You can ask a person to review a refusal or flag by contacting hello@ailitkit.com or safeguarding@ailitkit.com; we aim to respond within five working days. A content flag is not a finding of misconduct by a teacher.
Do not enter identifiable pupil information, assessment records, safeguarding records, EHCP/SEN documents or staff personal data. AILitKit needs curriculum content only. Warnings and input cleaning do not guarantee anonymisation: information entered accidentally can still be processed and appear in a saved guide or audit evidence. Contact hello@ailitkit.com promptly if this happens.
Safeguarding audit retains a classifier explanation that may refer to screened content. Allowed decisions keep no input snapshot; flagged decisions also keep the topic and a short description excerpt. Saved guide review evidence follows the guide retention period, including its 30-day undo window. Hosting logs and backups have separate service schedules. The school reviewer should obtain the current processor, transfer and retention evidence and record their own risk decision.
1. Project details
2. Description of data processing
Personal data processed
- Teacher email address (for account and authentication)
- Teacher display name (optional, for personalisation)
- School or trust name (optional)
- Country and, where applicable, emirate, used to apply the right regional framework set and safeguarding context
- Teaching preferences: primary key stage and primary subject
- Onboarding status, communication preferences, and a record of which transactional and lifecycle emails have been sent
- Last successful sign-in timestamp, mirrored from the authentication system. Used for inactivity tracking, re-engagement decisions, and operational visibility in the administrative dashboard.
- Per-user lesson quota state (monthly free allowance and any administrator-granted bonus generations)
- Where applicable: organisation membership and role (member, admin, owner, trust admin), invitation history
- Where applicable: Stripe customer and subscription identifiers, founding-member status and timestamps for founding-conversion reminders
- Curriculum content provided by the teacher (lesson plans, schemes of work, topic descriptions)
- Generated guides, activity selections, input description and content-review evidence
- Safeguarding-classifier audit log (verdict, layer, category, explanation, model, latency). For decisions flagged "sensitive" or "blocked" only, the topic and up to 250 characters of the free-text description, plus a flag if an upload was involved. Allowed decisions retain no input snippet. The upload body is not stored in this log. The classifier explanation may refer to screened material.
- Administrative-actions audit log. One row for every administrator-initiated change to a user account (for example sending a password reset, extending access, suspending or reinstating an account, granting bonus generations, deleting an account, or issuing a customer-support magic-link to sign in as a school owner or admin for a support, billing or demo call). Each row captures the acting administrator, the target account, the action type, a small metadata payload and the timestamp. Retained for 365 days and then purged by a scheduled cleanup job. Visible only to administrators inside the platform.
- Bulk teacher invitation imports. School and trust admins may upload a CSV of colleague email addresses. The parsed rows are stored for the duration of the invitation lifecycle so the admin can re-run, retry or roll back the batch.
- Organisation invitation lifecycle data including declined and bounced timestamps, the bounce reason returned by Resend, and the allowed-email-domain restriction set by the organisation owner.
- In-product course progress and issued certificates, including a unique verification token. The public verification page at /cert/<token> reveals only the holder's display name, the course title, the completion date, and that the certificate is genuine.
- IP address. Processed transiently to enforce per-route rate limits. The rate-limit bucket is held in memory or in a short-lived database row keyed by IP, is not joined to the user account, and is discarded once the rate-limit window has passed (typically minutes). Vercel request logs also record IP for standard hosting observability.
Data teachers must not submit
- Pupil personal data
- Pupil assessment data
- Safeguarding records
- EHCP or SEN documents
- Staff HR data
- Pastoral notes
Data subjects
Teachers (adults) who create accounts. Pupils do not interact with the platform and should not create accounts.
Third-party processors
| Service | Purpose | Data | Location |
|---|---|---|---|
| OpenRouter | Luna drafting and content review; Gemini backup; Llama Guard and conditional Gemini safeguarding | Teacher brief, extracted source, draft and review context (ZDR inference routing) | Depends on the inference operator; processing can occur outside the UK/EEA |
| OpenAI (direct, when configured) | Additional moderation | Safeguarding input sample; separate OpenAI API terms | Not stated in our privacy policy; ask us for the current transfer evidence |
| Scaleway | Keyword embeddings | Curriculum terms only | Paris, France (EU) |
| Supabase | Database, authentication, file storage | Account data, guides, safety and audit logs | EU (eu-west-1) |
| Stripe | Payment processing | Email, payment details, subscription state | Not stated in our privacy policy; ask us for the current transfer evidence |
| Resend | Transactional and lifecycle email; delivery-status webhooks (bounce, complaint) | Email address, display name | Not stated in our privacy policy; ask us for the current transfer evidence |
| Vercel | Application hosting, scheduled jobs | Application requests and operational diagnostics | Hosting includes processing in the US |
| Upstash QStash | Guide generation scheduling | Job identifier; retry and dead-letter retention follow account settings | Depends on the service configuration |
An EU database location does not mean all processing stays in the EU. Where a location is not stated, ask hello@ailitkit.com for the current processor agreement and transfer evidence.
File handling
See the processing and retention section for original-file cleanup, job minimisation and source excerpts retained in guides. Cleanup is retried on failure; there is no absolute one-hour deletion guarantee.
3. Necessity and proportionality
Why is this processing necessary?
The UAE Ministry of Education mandates AI literacy integration across all K-12 schools from the 2025-26 academic year. Teachers need practical support to integrate AI literacy into their existing curriculum. AILitKit processes curriculum content to generate tailored, framework-aligned AI literacy guides, reducing teacher workload and supporting consistent quality.
Is the processing proportionate?
The school must assess necessity and proportionality for its own use. The service minimises completed-job data and uses ZDR inference, but input descriptions, guide content and review evidence remain with saved guides. Identifying information can be submitted accidentally.
Lawful basis
School reviewer to confirm the lawful basis and applicable federal or free-zone requirements for the intended processing.
4. Risks identified and mitigations
Rate the likelihood and severity of each risk for your own use, after reading the mitigation. We describe the product controls; your school records the rating and the decision.
| # | Risk | Likelihood | Severity | Mitigation |
|---|---|---|---|---|
| 1 | Teachers upload documents containing personal data (for example pupil names in lesson plans) | Clear warnings are displayed before upload. After successful generation, cleanup deletes the original uploaded file and clears the extracted text from the upload record, keeping filename, type and date. Unused uploads and failed cleanup are picked up by a scheduled sweep once the upload is over one hour old; the sweep runs every 15 minutes, and deletion can take longer if a cleanup attempt fails. Relevant source-derived material can remain in the saved guide and its review evidence. Contact hello@ailitkit.com promptly if identifying information was uploaded. | ||
| 2 | AI-generated content contains factual errors or inappropriate suggestions, or covers a safeguarding-sensitive topic without appropriate framing | Before new generation, automated safeguarding checks read the subject, stage, year group and topic, plus up to the first 1,000 characters each of the teacher description and extracted upload text. Llama Guard gives a first verdict. A curriculum-aware Gemini reviewer runs if that verdict is unsafe, unavailable or unreadable, and considers whether a flagged topic fits an established curriculum context (for example GCSE Biology reproduction). Hard-block categories cannot be cleared by that reviewer. An additional direct OpenAI moderation check runs when configured, under its separate API terms. If no usable safeguarding verdict is available, generation pauses with a retry message. Before a new guide is saved, automated checks review lesson fit, accuracy, activity logic, resources, pupil language and AI literacy; failed or unavailable review prevents the guide from being saved. These checks can miss errors and are not human approval. Every guide is labelled as AI-generated, teachers must review it before classroom use, and concerns can be reported to hello@ailitkit.com. | ||
| 3 | Pupil personal data entered in text input fields | Input warnings advise against entering personal data. The platform is teacher-only with no pupil accounts, and guide generation needs curriculum content only (topics, not names). Warnings and input cleaning do not guarantee anonymisation: information entered accidentally can still be processed and appear in a saved guide or audit evidence. | ||
| 4 | Data processed outside the school’s own country by service providers | Our OpenRouter account has zero data retention (ZDR) enabled, and requests also require ZDR inference endpoints. This applies to provider processing of prompts and outputs, including retries and fallback. It does not delete saved AILitKit guides, account records or necessary service metadata, and OpenRouter permits temporary in-memory prompt caching under its ZDR policy. ZDR limits retention and does not itself establish a transfer mechanism. Confirm the applicable UAE or free-zone transfer requirements, actual destinations and current processor agreements with your data-protection contact. ZDR is not a transfer mechanism. The Supabase database (eu-west-1) and Scaleway embeddings (Paris) use EU locations. Task scheduling sends a job identifier to Upstash QStash; its location, retries and dead-letter retention follow the service configuration. | ||
| 5 | Organisation administrators see colleague metadata and flagged safeguarding decisions in a school or trust account | School and trust admins see a member roster (name, email, role, status), can manage seats, and can see safeguarding decisions flagged as "sensitive" or "blocked" for accounts in their organisation. They never see allowed decisions, and never see a colleague's guides unless the colleague shares them. Access is enforced by database row-level security and lets the designated safeguarding lead step in if a colleague is repeatedly hitting the gate. Disclosed in the Privacy Policy and Terms. | ||
| 6 | Internal audit logs (safeguarding decisions, Stripe idempotency, administrative alerts) retained for safety and reconciliation | Safeguarding-decision rows are minimised at write time. Allowed decisions keep verdict and decision metadata only, with no input snippet. Sensitive or blocked decisions also keep the topic and up to 250 description characters, plus a flag if an upload was involved; the upload body is not stored in this log. The organisation-admin dashboard shows these rows truncated at render time; this is a view of the same row, not a separate copy. Subject, key stage and year group are not duplicated into this log; they live on the guide row. Safeguarding rows are tied to the user and removed from active storage on account deletion. The Stripe webhook log holds event identifiers only, no card data, and is not tied to a user account. Retention is disclosed in the Privacy Policy. | ||
| 7 | Incorrect automated refusal or misinterpretation of a content flag | Automated checks decide whether content proceeds; they do not grade pupils or decide admissions or progression. A second model is not human review. A person can review a refusal or flag via hello@ailitkit.com or safeguarding@ailitkit.com. Assess whether any use has legal or similarly significant effects under the applicable rules; do not assume every content check meets that threshold. | ||
| 8 | Super-admin impersonation of a school owner or admin via a customer-support magic-link | AILitKit operations staff may issue a single, time-limited sign-in link to a school's owner email (or, where there is no owner, the most recently active admin) to investigate a support request, reproduce a billing or generation issue, or run a demo. The link expires within approximately one hour. Every issuance is recorded to the administrative-actions audit log with the operations user, the target account, the timestamp and the support context; the audit row is retained for 365 days. The capability is restricted to verified super-admin accounts. Use is disclosed in the Privacy Policy under “Customer support access (impersonation)”. A future enhancement will notify the affected school owner of any new impersonation event; schools can request their full impersonation history at any time. | ||
| 9 | Public certificate verification reveals holder display name, course title and completion date by token | Anyone holding a certificate's verification token can open its verification page without an account and see the holder's display name, the course title, the completion date, and confirmation that the certificate is genuine. No other personal data is shown. Holders can rotate or revoke a certificate on request. | ||
| 10 | Bulk teacher invitation CSVs contain colleague email addresses processed before the invitee has had an opportunity to consent | Bulk imports are run only by school or trust admins. The invitee receives a transactional activation email which is the Article 14 disclosure point: it identifies AILitKit as the controller for the teacher account record, names the originating school admin, and explains the processing. The invitee may decline or not activate the account, in which case the row is retained for the invitation lifecycle and then removed. | ||
| 11 | EU AI Act classification and Article 50 transparency | Guide generation supports teacher planning; it does not grade pupils, decide admissions or progression, or proctor exams. Every guide is labelled as AI-generated, and the layered checks are described in the Privacy Policy and the Safeguarding statement. Regulatory assessment depends on the actual purpose and deployment; this template is not a certification. Record your school's own assessment here. |
5. Consultation
This assessment should be reviewed by your school's Data Protection Officer (DPO) or data protection lead before adopting AILitKit. If residual risks remain high after mitigation, consult the UAE Data Office before proceeding.
6. Decision
Recommendation
This template records product controls, not an approved risk rating. The school must confirm its intended use, processor agreements, transfers, access and retention, evaluate the remaining risks and record its decision below.
This assessment is pre-filled with AILitKit product details and is provided to help schools meet their applicable data-protection obligations. Schools should adapt this assessment to reflect their own policies and circumstances. Template prepared by IN&ED (inanded.com).
Review cadence. IN&ED reviews this template at least every six months and immediately when a new processing activity is added, a new sub-processor is engaged, a sub-processor's data-handling terms change, or the statutory frameworks named above change. Schools should re-review their own completed copy on the same cadence and whenever their own policies change.
For data-protection questions, contact hello@ailitkit.com. For safeguarding questions, contact safeguarding@ailitkit.com.
AILitKit vendor privacy assessment
US school district vendor review document
Last updated: 9 September 2026
AILitKit vendor privacy assessment
For US school district vendor review. Last updated: 9 September 2026
Processing and retention, policy of 9 September 2026
Guide drafting and content review use Luna as the primary model, with Gemini as the configured backup, through OpenRouter. Safeguarding uses Llama Guard and, when needed, a separate Gemini curriculum reviewer. Model developers and the companies operating inference endpoints are not necessarily the same.
Our OpenRouter account has zero data retention (ZDR) enabled, and requests also require ZDR inference endpoints. This applies to provider processing of prompts and outputs, including retries and fallback. It does not delete your saved AILitKit guides, account records or necessary service metadata. OpenRouter permits temporary in-memory prompt caching under its ZDR policy.
Before new generation, automated safeguarding checks read the subject, stage, year group and topic, plus up to the first 1,000 characters each of the teacher description and extracted upload text. Llama Guard gives a first verdict; a Gemini reviewer runs if that verdict is unsafe, unavailable or unreadable. An additional direct OpenAI moderation check runs when configured, under its separate API terms. If no usable safeguarding verdict is available, generation pauses with a retry message. A usable unsafe verdict is preserved if its reviewer fails; hard-block categories cannot be cleared by that reviewer.
Before saving a newly generated guide, automated checks review lesson fit, accuracy, activity logic, resources, pupil language and AI literacy. Up to four batches inspect the draft against the teacher brief; one correction cycle is allowed, followed by another review of all batches. Failed or unavailable review prevents the new guide from being saved. Saved review evidence and resolved findings may quote the brief or draft. These checks can miss errors and are not human approval or a dedicated final-output safety classifier. Existing guides are not retrospectively checked; eligible saved guides may be reused.
Pupil-facing language is targeted using the year group or key stage supplied by the teacher. This is a class-level assumption, not an individual reading-age assessment. Teachers must adapt wording and resources for their actual readers, including SEND and EAL needs, and check third-party tools, links and safeguarding before classroom use.
While a guide is being built, its job record holds the request needed for processing and retries. On completion, failure or expiry, that record loses its input payload and duplicate output. Identifiers, scope, status, timings, usage and support diagnostics remain temporarily: completed jobs are eligible for deletion after 24 hours, and failed or expired jobs after seven days, at the next successful cleanup. The saved guide, its input description and review evidence follow the guide retention period.
After successful generation, cleanup deletes the original uploaded file and clears the extracted text from the upload record, keeping filename, type and date. Unused uploads and failed cleanup are eligible for the scheduled sweep once the upload is over one hour old. The sweep runs every 15 minutes; deletion can take longer if a cleanup attempt fails. Relevant source-derived material can remain in the saved guide and its review evidence.
Guide generation does not grade pupils, decide admissions or progression, or assess individual learners. Automated service checks do decide whether a request can proceed and whether a draft passes review. A second AI model is not human intervention. You can ask a person to review a refusal or flag by contacting hello@ailitkit.com or safeguarding@ailitkit.com; we aim to respond within five working days. A content flag is not a finding of misconduct by a teacher.
Do not enter identifiable pupil information, assessment records, safeguarding records, EHCP/SEN documents or staff personal data. AILitKit needs curriculum content only. Warnings and input cleaning do not guarantee anonymisation: information entered accidentally can still be processed and appear in a saved guide or audit evidence. Contact hello@ailitkit.com promptly if this happens.
Safeguarding audit retains a classifier explanation that may refer to screened content. Allowed decisions keep no input snapshot; flagged decisions also keep the topic and a short description excerpt. Saved guide review evidence follows the guide retention period, including its 30-day undo window. Hosting logs and backups have separate service schedules. The school reviewer should obtain the current processor, transfer and retention evidence and record their own risk decision.
1. Vendor information
2. Student data
Does this product collect student personal information?
Does this product collect student-generated content?
Is student data shared with third parties?
3. FERPA
Does this product access student education records?
FERPA designation
Directory information
4. COPPA
Is this product directed at children under 13?
Does this product collect information from children under 13?
Parental consent
5. Data practices
Data collected
- Teacher email address (for account and authentication)
- Teacher display name (optional)
- School name (optional)
- Teaching preferences (grade level, subject area)
- Curriculum content provided by the teacher
- Generated AI literacy guides and their review evidence
Data teachers must not submit
- Student data of any kind
- Staff HR data
- Safeguarding records
Data retention
AI processing
Data location
- Database: EU, eu-west-1 (Supabase)
- Application hosting: Vercel, including processing in the US
- AI inference: depends on the inference operator; ZDR routing
- Embeddings: EU (Scaleway, Paris)
6. Sub-processors
| Service | Purpose | Data | Location |
|---|---|---|---|
| OpenRouter | Luna drafting and content review; Gemini backup; Llama Guard and conditional Gemini safeguarding | Teacher brief, extracted source, draft and review context (ZDR inference routing) | Depends on the inference operator; processing can occur outside the UK/EEA |
| OpenAI (direct, when configured) | Additional moderation | Safeguarding input sample; separate OpenAI API terms | Not stated in our privacy policy; ask us for the current transfer evidence |
| Scaleway | Keyword embeddings | Curriculum terms only | Paris, France (EU) |
| Supabase | Database, authentication, file storage | Account data, guides, safety and audit logs | EU (eu-west-1) |
| Stripe | Payment processing | Email, payment details, subscription state | Not stated in our privacy policy; ask us for the current transfer evidence |
| Resend | Transactional and lifecycle email; delivery-status webhooks (bounce, complaint) | Email address, display name | Not stated in our privacy policy; ask us for the current transfer evidence |
| Vercel | Application hosting, scheduled jobs | Application requests and operational diagnostics | Hosting includes processing in the US |
| Upstash QStash | Guide generation scheduling | Job identifier; retry and dead-letter retention follow account settings | Depends on the service configuration |
7. Security measures
- Encryption in transit: HTTPS only, enforced with HSTS
- Row-level security on all database tables
- Pupil-identifying input prohibited; accidental disclosure remains a risk
- Authentication via Supabase Auth
- Original uploaded files deleted after successful generation, with a scheduled sweep for unused uploads
8. District approval
This vendor privacy assessment is pre-filled by AILitKit (operated by IN&ED) and is provided to help US school districts evaluate the product under FERPA, COPPA, and state privacy laws. The district records its own decision.
Prepared by IN&ED (inanded.com) | Contact: hello@ailitkit.com
Reference and support
Ask us for evidence
Data protection questions
Processor agreements, transfer evidence and data requests.
hello@ailitkit.com