Who We Are
AI & Assessment Solutions Pty Ltd (ABN 78 685 561 906) trading as Socratic XR
Effective Date: 18 June 2025
Our websites are: https://socraticxr.com, https://assessmentxr.com, https://xrassessment.com/
Our Privacy Commitment
We're committed to protecting your privacy. This policy explains how we collect, use, and protect your personal information when you use our educational software and website.
Key promises: • We will never sell, rent, or trade your email address • We will never publicly display your personal information • We will not use student data to train AI models • Your data stays in Australia (except for AI processing via OpenAI) |
What Information We Collect
For the purpose of this policy, the definition of “personal information” is any detail that can reasonably identify you – for example your name, email address, photo, IP address.
Required Information
- Students: First names only (or teacher-assigned nicknames)
- Teachers/Administrators: Full names, school email addresses, school/organisation name
Optional Information
- Files uploaded by users (with automatic Personal information filter)
- Account preferences and settings
- Communication through contact forms
Technical Information
- IP addresses for security and session management
- Web logs and connection information to prevent misuse
- Cookies for website functionality
Age Restrictions
- Under 13: Must not use the software
- Ages 13-17: Requires parental consent obtained by the registered school
How We Use Your Information
We use your information to:
- Provide and improve our educational software
- Verify your identity and manage accounts
- Respond to your questions and feedback
- Prevent fraud and security issues
- Send important service updates
- Conduct research and development (with anonymised data)
We will NOT:
- Use student data to train AI models
- Share your information for marketing
- Sell your data to third parties
Data Storage and Security
Where Your Data Lives
- Primary storage: Australia (via Vultr servers)
- AI processing: Temporarily processed in the USA via OpenAI (no training on your data)
- Backups: Secondary Australian data centers
Security Measures
- Industry-standard encryption (in transit and at rest)
- Role-based access controls
- Regular security training for staff
- Annual security reviews and testing
By using our software, the registered school acknowledges and agrees to the processing of conversation and file data by OpenAI in the USA and accepts the associated risks as detailed in the End User Licence Agreement.
File Uploads and Privacy Protection
When you upload files:
- We extract text for educational discussions
- Our system automatically detects and blocks Personal information
- While our platform attempts to filter personal information, it is not guaranteed. Schools are responsible for ensuring users do not upload sensitive or unnecessary personal information
- Schools remain responsible for training users on appropriate uploads and use
Third-Party Processing (OpenAI)
We use OpenAI's API for AI-powered educational features:
- Data sent: Conversation content and relevant file excerpts only
- Not sent: Usernames or direct identifiers
- Promise: OpenAI will not use your data for training their models
- Location: Processing occurs in the USA
- We send only the minimum data needed for AI processing to OpenAI in the United States and take reasonable steps, including contractual safeguards, to ensure OpenAI handles that data in line with the Australian Privacy Principles.
- We'll notify you of any changes to OpenAI's terms
Data Retention
Data Type | While Active | After Termination |
Student conversations & uploaded files | Retained under school account control | Deleted within 60 days |
System logs & analytics | 13 months, then anonymised | Anonymised data only |
Special cases:
- Sensitive information is deleted immediately if detected
- Legal requirements may extend retention periods
Your Rights
Access and Correction
- Use the Teacher Dashboard to view and correct information
- Contact us for assistance with data requests
- We aim to respond to access or correction requests within 30 days, free of charge.
- Where it is lawful and practical (for example, when you send us a general enquiry), you may choose not to tell us who you are or to use a nickname instead.
Deletion
- Delete your own data through the software
- Request deletion by contacting us
- Automatic deletion upon account termination
Other Rights (where applicable)
- Data portability
- Restrict processing
- Object to processing
Lodge complaints with privacy authorities
Cookies and Tracking
We use cookies to:
- Remember your login and preferences
- Manage account creation
- Show relevant notifications
- Analyse website usage (via Google Analytics)
Third-party cookies may include:
- Google Analytics (anonymised usage data)
- Google AdSense (relevant advertising)
- Social media plugins (Facebook, Twitter, etc.)
You can disable cookies in your browser, but some features may not work properly.
International Visitors
For international visitors to our website (who currently cannot create accounts), we comply with applicable privacy laws. Our software accounts are currently only available to Australian schools and users.
Marketing and Communications
- We may send service updates and educational content
- Marketing emails include easy unsubscribe options
- We don't use sensitive information for marketing
- Email vendors act only as data processors
Children's Privacy
Special protections for student users:
- No collection from children under 13
- Parental consent required for ages 13-17 (obtained by registered schools)
- Registered schools responsible for managing student access
- Immediate deletion of any inappropriately collected data
Data Breaches
If a data breach occurs, we will:
- Contain and assess the incident immediately
- If a data breach is likely to result in serious harm, we will contain the incident and notify affected schools and the OAIC as soon as practicable; our internal target is within 72 hours. We will report to Australian authorities as required
- Provide clear information about impacts and remediation
Changes to This Policy
- We'll notify you 90 days before any changes take effect
- Notification via email, software, or website
- Continued use means acceptance of changes
- You can stop using the service if you disagree
Contact Us
Privacy Officer
AI & Assessment Solutions Pty Ltd
Email: privacy@socraticxr.com
For complaints: Contact us first, or lodge a complaint with the Office of the Australian Information Commissioner (www.oaic.gov.au)
Current Service Providers
Provider | Service | Location | Notes |
Vultr LLC | Primary hosting | Sydney, Australia | Data encrypted at rest & transit |
OpenAI LLC | AI processing | USA | No model training on school data |
List updated: 18 May 2025
Summary
This privacy policy ensures your educational data is protected while enabling innovative AI-powered learning experiences. We're committed to transparency, security, and putting educational outcomes first.
For the complete technical details, legal terms, and full policy text, please refer to our complete Privacy Policy accessible to download below: