PRIVACY POLICY FOR EDUCATORS

CRITICAL LIABILITY NOTICE FOR EDUCATORS

BY CREATING AN ACCOUNT, YOU ACKNOWLEDGE THE FOLLOWING:

  1. YOU ARE THE CONTROLLER: You (the Educator/Institution) act as the Data Controller for all learner data. Novelcore acts strictly as a Data Processor.
  2. STRICT PSEUDONYMIZATION: You are generally PROHIBITED from uploading the real names, email addresses, or identifiable data of learners to this platform. You must exclusively use Pseudonyms (codes).
  3. KEY MANAGEMENT: You are solely responsible for maintaining the “Key” (the link between codes and real people) on your own secure local systems. Novelcore must never possess this key.

CONSENT: You certify that you have obtained valid legal consent as a choice under free will from all learners (and parents for minors) to process their data on this platform.

  1. INTRODUCTION AND SCOPE

This Privacy Policy explains how NOVELCORE manages data when Educators, Organizations, and Institutions (“Users”) operate courses on the augMENTOR platform. This Policy applies to all data processing activities conducted through the platform in accordance with the General Data Protection Regulation (GDPR).

The platform operates on the principle of pseudonymization, meaning we process only coded learner identifiers rather than identifiable personal data.

Questions or concerns? Reading this privacy policy will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at [email protected] 

 

  1. LEGAL FRAMEWORK AND ROLES

2.1. Platform Operator and Data Management

NOVELCORE (the “Company”) maintains and operates the augMENTOR platform. Under GDPR Articles 4 and 24, roles are defined as follows:

  • Data Controller: The Educator acts as the Controller for all learner data.
  • Data Controller: Novelcore acts as Controller only for Educator personal data (your billing and login info).
  • Data Processor: Novelcore acts as Processor for the pseudonymized learner interaction data you upload.

     

2.2. Legal Instruments

The relationship between Novelcore (Processor) and the Educator (Controller) is governed by a Data Processing Agreement (DPA), as required by Article 28(3) GDPR. By using the platform, you agree to the terms of the Standard DPA.

 

  1. EDUCATOR RESPONSIBILITIES AND LIABILITY

This section defines your absolute obligations. Failure to comply constitutes a breach of contract.

3.1. The Pseudonymization Requirement

You (The Educator) are responsible for ensuring all learners are enrolled using pseudonyms (codes) to which only you (The Educator) have the key (access).

  • Requirement: You must use codes like “Student-01” or “ClassA-ID99”.
  • Prohibition: You must NOT use real names, government IDs, or personal emails as usernames for learners.
  • Key Security: You must maintain the pseudonymization key separately from NOVELCORE systems.

 

3.2. The Consent Requirement

You (The Educator) are responsible for collecting and securely maintaining signed or documented consent forms from all participating learners.

  • Minors: For learners under the age of digital consent (typically 16 in many EU countries, with lower ages in others), you must obtain consent from the holders of parental responsibility.
  • Transparency: You must inform learners that their data is being processed by Novelcore for analytics purposes.

     

3.3. Strict Liability Exclusion

Novelcore is NOT responsible for:

  1. Any data uploaded by the Educator in an un-pseudonymized form (real names) in violation of this Policy.
  2. The Educator’s failure to collect valid consent.
  3. The Educator’s failure to respond to learner rights requests.

Indemnification: By using this platform, the Educator agrees to indemnify Novelcore against any liability arising from the Educator’s failure to pseudonymize data correctly or obtain necessary consents.

  1. DATA COLLECTION AND LAWFUL BASIS

4.1. Educator Personal Data (You)

  • Data Collected: Name, email address, organization, login credentials, and system activity logs.
  • Lawful Basis: Contract Performance (Article 6(1)(b) GDPR). We need this data to provide you with the service.

     

4.2. Pseudonymized Learner Data (Your Students)

  • Data Collected: Unique pseudonym (User ID), course interaction logs, quiz scores, and progress metrics.
  • Excluded Data: We do NOT collect biometrics, health data, religious beliefs, or real names.
  • Lawful Basis: Legitimate Interest (Article 6(1)(f) GDPR) for the purpose of platform improvement, analytics, and quality assurance.
  • Legitimate Interest Balancing: This is justified because the data is pseudonymized (minimized risk) and provides significant educational benefit.

 

  1. DATA SECURITY AND TECHNICAL SAFEGUARDS

Novelcore adheres to Privacy by Design. We implement the following Article 32 security measures:

  • Encryption: All data is encrypted in transit (TLS 1.3+) and at rest (AES-256).
  • Access Control: We utilize strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA).
  • Data Residency: All data is stored exclusively within the European Union.
  • Sub-processors: We utilize cloud infrastructure providers (e.g., AWS/Azure EU Regions) that are strictly bound by DPAs and Standard Contractual Clauses.

 

  1. DATA RETENTION

6.1. Educator Data

Retained for the duration of your active account plus 90 days after termination (to allow for reactivation/export). Financial records are retained for six years, as per tax laws.

6.2. Learner Data

Retained for the duration of the course. Upon your request to delete a course or account, learner data is anonymized or deleted within 30 days.

 

  1. RIGHTS OF THE DATA SUBJECT

7.1. Educator Rights

You have the right to Access, Rectification, Erasure, Restriction, and Portability of your own account data. Contact our DPO at [email protected] to exercise these rights.

7.2. Learner Rights (Executed via YOU)

Because Novelcore cannot identify learners (we only hold codes), learners must exercise their rights through the Educator.

  • If a learner requests data access or deletion, YOU (the Educator) must identify the corresponding pseudonym and instruct Novelcore to act on that specific ID.

 

  1. DATA BREACH NOTIFICATION

In the event of a personal data breach, Novelcore will notify the Hellenic Data Protection Authority (HDPA) within 72 hours. We will also notify affected Educators without undue delay, providing the nature of the breach and recommended mitigation steps.

 

  1. CONTACT INFORMATION

Co founder & Legal representative

  • Email: [email protected]
  • Address: Mavromichali 104, Athina 114 72
  • Phone: +30 6936742161

Supervisory Authority

By proceeding, you certify that you have the authority to bind your institution to these terms regarding data privacy and liability.