This Privacy Policy explains how EduCoach collects, uses, shares, and protects your personal data when you use the platform. It is prepared in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Greek law 4624/2019.
We respect your privacy and are committed to transparency: this document explains what data we collect, why, with whom we share it, how long we keep it, and what rights you have.
The Controller of your personal data is [COMPANY NAME], with registered office at [ADDRESS], VAT No. [VAT], Tax Office [DOY] (hereinafter "Provider" or "we").
Contact for personal data matters: hello@educoach.gr
The Provider is not required to appoint a Data Protection Officer (DPO) under Article 37 GDPR. For any data protection matter, you can contact us directly.
We do not knowingly collect special categories of data under Article 9 GDPR (health, ethnic origin, religion, political beliefs, etc.). If you notice such data in posts or submissions to the platform, we ask you to remove them.
We process your data for the following purposes and on the corresponding legal bases under GDPR:
| Purpose | Data categories | Legal basis (Article 6 GDPR) |
|---|---|---|
| Account creation & management | Account details, age confirmation | Contract performance — Art. 6(1)(b) |
| Providing the Service (Chatbot, recommendations, questionnaires) | Profile, conversations | Contract performance — Art. 6(1)(b) |
| Personalization & profiling for recommendations | Profile, usage, conversations | Contract performance — Art. 6(1)(b), or consent — Art. 6(1)(a) |
| Premium payment processing | Payment data | Contract performance — Art. 6(1)(b) |
| Technical operation, security, fraud prevention | Technical data, logs, error data | Legitimate interest — Art. 6(1)(f) |
| Service improvement (statistics, aggregates) | Usage data (aggregated/pseudonymized) | Legitimate interest — Art. 6(1)(f) |
| Communication (important account notifications) | Contract performance — Art. 6(1)(b) | |
| Commercial communication / newsletter | Consent — Art. 6(1)(a) | |
| Compliance with legal obligations | As applicable | Legal obligation — Art. 6(1)(c) |
You may withdraw your consent at any time where processing is based on it, without affecting the lawfulness of prior processing.
We do not sell your personal data. We share it with strictly selected processors bound by data processing agreements (DPAs) under Article 28 GDPR:
| Provider | Purpose | Location | Transfers |
|---|---|---|---|
| Clerk | User authentication, account management | USA | Yes — SCCs |
| Stripe | Premium payment processing | Ireland (EU) / USA | Yes — SCCs |
| Vercel | Platform hosting, website operation | USA (with EU regions available) | Yes — SCCs |
| Vercel Analytics & Speed Insights | Usage & performance statistics (pseudonymized) | USA | Yes — SCCs |
| Sentry | Error logging, technical health monitoring | Germany (EU) / USA | Possibly — SCCs where applicable |
| Google (Gemini) | Conversational AI operation | USA | Yes — SCCs |
| Cohere | Search results relevance reranking | Canada (adequate country) / USA | Where applicable — SCCs |
| Neon (PostgreSQL) | Application data storage (PostgreSQL via Neon) | Within EU | No |
Certain AI providers (Google Gemini, Cohere) and infrastructure providers (Clerk, Stripe, Vercel, Sentry) maintain facilities or personnel in the United States or other countries outside the EEA. For these transfers we apply appropriate safeguards:
You can request a copy of the SCCs by contacting us.
We retain your data only as long as necessary:
| Data category | Retention period |
|---|---|
| Active account | Until deletion by the user or 24 months of inactivity |
| Profile & conversation data | As long as the account is active |
| Payment data (Stripe IDs, invoicing) | 10 years from the last record (tax law) |
| Security / technical operation logs | Up to 12 months |
| Error data (Sentry) | Up to 90 days |
| Data after account deletion | Full deletion within 30 business days; backups retained up to 90 additional days for technical/legal reasons |
| Marketing consent | Until withdrawal |
Notice before deletion for inactivity: You will receive a warning email 30 days before account deletion due to inactivity, so you can reactivate your account.
The Service uses automated processing and profiling to generate personalized study and career recommendations.
Important clarification: This processing does not produce legal effects for you nor significantly affect you within the meaning of Article 22 GDPR. The recommendations are strictly supportive and informational: they are an exploration tool, not decisions taken about you. The final decision always rests with you.
How it works (in plain terms):
Your right: You can request human review of any recommendation and express your view by contacting us.
Further details are included in the AI Use Notice.
Under GDPR, you have the following rights:
How to exercise your rights: By sending an email. We will reply within 30 days (extendable by 60 days in exceptionally complex cases, with notice to you).
Right to lodge a complaint: You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA), Kifisias 1-3, 115 23 Athens, www.dpa.gr.
We take appropriate technical and organizational measures to protect your data, including:
In the event of a data breach that may pose a high risk to your rights, we will notify you without undue delay in accordance with Articles 33-34 GDPR.
The Service is intended for users aged 15 and over, in accordance with Article 21 of Greek law 4624/2019.
Parents/guardians who believe their child has provided data without their consent can contact us.
We may update this Policy from time to time. For substantive changes, we will notify you by email and/or with a prominent in-platform announcement at least 15 days before the changes take effect. The last-updated date appears at the top of the document.
For any question, rights request, or complaint regarding this Policy or the processing of your data:
Email: hello@educoach.gr
Mailing address: [ΕΔΡΑ]
Supervisory authority: Hellenic Data Protection Authority (HDPA), Kifisias 1-3, 115 23 Athens, www.dpa.gr.