Privacy Policy

Who We Are

AI & Assessment Solutions Pty Ltd (ABN 78 685 561 906) trading as Socratic XR
Effective Date: 18 June 2025

Our websites are: https://socraticxr.com, https://assessmentxr.com, https://xrassessment.com/

Our Privacy Commitment

We're committed to protecting your privacy. This policy explains how we collect, use, and protect your personal information when you use our educational software and website.

Key promises:
• We will never sell, rent, or trade your email address
• We will never publicly display your personal information
• We will not use student data to train AI models
• Your data stays in Australia (except for AI processing via OpenAI)

What Information We Collect

For the purpose of this policy, the definition of “personal information” is any detail that can reasonably identify you – for example your name, email address, photo, IP address.

Required Information

  • Students: First names only (or teacher-assigned nicknames)
  • Teachers/Administrators: Full names, school email addresses, school/organisation name

Optional Information

  • Files uploaded by users (with automatic Personal information filter)
  • Account preferences and settings
  • Communication through contact forms

Technical Information

  • IP addresses for security and session management
  • Web logs and connection information to prevent misuse
  • Cookies for website functionality

Age Restrictions

  • Under 13: Must not use the software
  • Ages 13-17: Requires parental consent obtained by the registered school

How We Use Your Information

We use your information to:

  • Provide and improve our educational software
  • Verify your identity and manage accounts
  • Respond to your questions and feedback
  • Prevent fraud and security issues
  • Send important service updates
  • Conduct research and development (with anonymised data)

We will NOT:

  • Use student data to train AI models
  • Share your information for marketing
  • Sell your data to third parties

Data Storage and Security

Where Your Data Lives

  • Primary storage: Australia (via Vultr servers)
  • AI processing: Temporarily processed in the USA via OpenAI (no training on your data)
  • Backups: Secondary Australian data centers

Security Measures

  • Industry-standard encryption (in transit and at rest)
  • Role-based access controls
  • Regular security training for staff
  • Annual security reviews and testing

By using our software, the registered school acknowledges and agrees to the processing of conversation and file data by OpenAI in the USA and accepts the associated risks as detailed in the End User Licence Agreement.

File Uploads and Privacy Protection

When you upload files:

  • We extract text for educational discussions
  • Our system automatically detects and blocks Personal information
  • While our platform attempts to filter personal information, it is not guaranteed. Schools are responsible for ensuring users do not upload sensitive or unnecessary personal information
  • Schools remain responsible for training users on appropriate uploads and use

Third-Party Processing (OpenAI)

We use OpenAI's API for AI-powered educational features:

  • Data sent: Conversation content and relevant file excerpts only
  • Not sent: Usernames or direct identifiers
  • Promise: OpenAI will not use your data for training their models
  • Location: Processing occurs in the USA
  • We send only the minimum data needed for AI processing to OpenAI in the United States and take reasonable steps, including contractual safeguards, to ensure OpenAI handles that data in line with the Australian Privacy Principles.
  • We'll notify you of any changes to OpenAI's terms

Data Retention

Data TypeWhile ActiveAfter Termination
Student conversations & uploaded filesRetained under school account controlDeleted within 60 days
System logs & analytics13 months, then anonymisedAnonymised data only

Special cases:

  • Sensitive information is deleted immediately if detected
  • Legal requirements may extend retention periods

Your Rights

Access and Correction

  • Use the Teacher Dashboard to view and correct information
  • Contact us for assistance with data requests
  • We aim to respond to access or correction requests within 30 days, free of charge.
  • Where it is lawful and practical (for example, when you send us a general enquiry), you may choose not to tell us who you are or to use a nickname instead.

Deletion

  • Delete your own data through the software
  • Request deletion by contacting us
  • Automatic deletion upon account termination

Other Rights (where applicable)

  • Data portability
  • Restrict processing
  • Object to processing

Lodge complaints with privacy authorities

Cookies and Tracking

We use cookies to:

  • Remember your login and preferences
  • Manage account creation
  • Show relevant notifications
  • Analyse website usage (via Google Analytics)

Third-party cookies may include:

  • Google Analytics (anonymised usage data)
  • Google AdSense (relevant advertising)
  • Social media plugins (Facebook, Twitter, etc.)

You can disable cookies in your browser, but some features may not work properly.

International Visitors

For international visitors to our website (who currently cannot create accounts), we comply with applicable privacy laws. Our software accounts are currently only available to Australian schools and users.

Marketing and Communications

  • We may send service updates and educational content
  • Marketing emails include easy unsubscribe options
  • We don't use sensitive information for marketing
  • Email vendors act only as data processors

Children's Privacy

Special protections for student users:

  • No collection from children under 13
  • Parental consent required for ages 13-17 (obtained by registered schools)
  • Registered schools responsible for managing student access
  • Immediate deletion of any inappropriately collected data

Data Breaches

If a data breach occurs, we will:

  • Contain and assess the incident immediately
  • If a data breach is likely to result in serious harm, we will contain the incident and notify affected schools and the OAIC as soon as practicable; our internal target is within 72 hours. We will report to Australian authorities as required
  • Provide clear information about impacts and remediation

Changes to This Policy

  • We'll notify you 90 days before any changes take effect
  • Notification via email, software, or website
  • Continued use means acceptance of changes
  • You can stop using the service if you disagree

Contact Us

Privacy Officer
AI & Assessment Solutions Pty Ltd
Email: privacy@socraticxr.com

For complaints: Contact us first, or lodge a complaint with the Office of the Australian Information Commissioner (www.oaic.gov.au)

Current Service Providers

ProviderServiceLocationNotes
Vultr LLCPrimary hostingSydney, AustraliaData encrypted at rest & transit
OpenAI LLCAI processingUSANo model training on school data

List updated: 18 May 2025

Summary

This privacy policy ensures your educational data is protected while enabling innovative AI-powered learning experiences. We're committed to transparency, security, and putting educational outcomes first.

For the complete technical details, legal terms, and full policy text, please refer to our complete Privacy Policy accessible to download below: