Security and GDPR
Safe AI Use at School
Data Processing Agreement
The data processing agreement is in accordance with the Privacy Covenant for Education.
Subprocessors
The data processing agreement of AI-School is leading for the list of subprocessors involved in AI-School's data processing. The summary below is based on the Edu-V processor appendix, version 1.0 dated July 6, 2026. Other suppliers or internal administrative systems are not included here if they fall outside this scope.
Privacy at BFL and Stability AI
Black Forest Labs (BFL/FLUX) and Stability AI are image providers, but not subprocessors of AI-School. They do not receive personal data from AI-School. This is technically enforced in the backend.
Setting Permissions
AI-School security works based on roles with permissions.
View History
AI-School offers the ability to set visibility of student or staff chat history per role. This can be configured in the admin section under Permissions.
Retention Periods
AI-School offers the ability to set retention periods per collection. A collection is a set of similar data. For example, there is a "Schools" collection and a "Chats" collection.
Leaving the App
When a person temporarily leaves the app, it is advisable to set the account to inactive.
Database Structure
Each customer in AI-School receives a separate database in Google Cloud. Security rules can be set on this database, and the administrator can set permissions for reading and writing to this database per role.
Server Security
Personal data used within the application is stored on servers within the European Economic Area.