1. Information We Collect
Perfect Aptitude collects strictly the minimum amount of personal data necessary to provide seamless, secure educational and translation services:
- Account Profile Data: Full name, institutional email address, assigned academic role (`Teacher`, `Student`, `Institution Admin`), and cryptographic password hashes.
- Classroom & Interactive Data: Session attendance logs, live translated speech segments, book conversion requests (`PDF/OCR`), and generated revision summaries.
- Multimodal Audio Samples: Temporary voice inputs captured during Automatic Speech Recognition (ASR) vocabulary assessments or live classroom broadcasting.
2. Processing & Use of Data
Your personal and educational data is processed exclusively for the operation and improvement of your academic institution's learning hub. We utilize this information to authenticate users across roles, route real-time WebSocket translation streams, calculate institutional token consumption, and deliver personalized learning feedback.
We never sell, rent, or monetize personal data or student records to third-party advertisers or data brokers.
3. AI Sub-Processors & Zero Data Retention (ZDR)
To power our multilingual classroom capabilities, we integrate with enterprise cloud and artificial intelligence providers under strict Zero Data Retention (ZDR) and confidentiality addendums:
- Google Cloud Platform (GCP): Utilized for Cloud Translation APIs, Cloud Vision OCR, Document AI, and Gemini language processing. API requests sent to GCP are encrypted in transit (`TLS 1.3`) and are processed transiently without being stored or logged for public AI training.
- OpenAI Inc.: Utilized for Whisper ASR speech-to-text and GPT-4o intelligence endpoints. Under our enterprise API terms, data transmitted to OpenAI is discarded immediately upon response completion and is never retained.
- Amazon Web Services (AWS Polly): Utilized for high-fidelity neural Text-to-Speech (TTS) generation. Audio synthesis payloads are processed on-demand and stored exclusively within your institution's private storage directory.
4. FERPA & GDPR Student Protections
Perfect Aptitude is engineered from the ground up to uphold the Family Educational Rights and Privacy Act (FERPA) and the General Data Protection Regulation (GDPR):
- FERPA Compliance: All student records, quiz attempts, and diagnostic assessments are designated as confidential educational records under direct institutional authority. School administrators maintain full administrative power to inspect or purge student profiles.
- GDPR Rights: For users within the European Economic Area (EEA), our legal basis for processing is the performance of institutional contracts and legitimate educational interest. Users retain the right to data portability, rectification, and erasure (`Right to be Forgotten`).
5. Private Storage & Asset Protection
All converted books, uploaded PDF study materials, and synthesized audio (`.mp3`) files are stored within secure, access-controlled directories managed by our `PrivateStorage` engine. These files are protected by cryptographic token verification (`ProductionHardening::signed_tts_url`) and cannot be accessed or indexed by unauthorized external parties or public web crawlers.
6. Cookies & Session Management
Our platform employs strictly functional, secure cookies and cryptographic nonces (`_wpnonce`, `_ajax_nonce`) required to maintain authenticated user sessions and protect against Cross-Site Request Forgery (CSRF). We do not deploy behavioral tracking cookies or third-party advertising pixels.
7. Your Rights & Data Access
Depending on your jurisdiction, you have the right to request a complete export of your personal profile data, request corrections to inaccurate information, or request account deletion. If your account is linked to an active Institution, data deletion requests are coordinated directly with your Institution Administrator to ensure compliance with institutional archiving policies.
8. Data Security & Encryption
We enforce rigorous security standards across all platform layers. Data in transit is secured via industry-standard `HTTPS / TLS 1.3` encryption. Sensitive credentials, API keys, and private tokens are encrypted at rest using AES-256 and managed via our `SecretResolver` framework.
9. Contact Our Data Protection Officer (DPO)
If you have questions regarding data privacy, sub-processor compliance, or FERPA/GDPR data rights, please contact our Data Protection Officer at:
privacy@perfectaptitude.com
Perfect Aptitude Inc. — Office of Data Governance
