Legal
Privacy Policy
This policy explains what personal data Aula handles, why we handle it, and the choices and rights you have. It applies to our website, web app and native iOS and Android apps.
Last updated September 16, 2026
Who we are and our role
Aula is a white-label learning platform operated by [Company legal name], [Registered office address] ("we", "us"). Organisations such as schools, universities, training companies and independent creators ("Customers" or "tenants") use Aula to run their own branded academies.
We play two different roles depending on the data:
- Controller for data about our own Customers and website visitors, such as account owners, billing contacts, sales enquiries and website analytics.
- Processor for data that Customers upload or that their learners, teachers and parents generate inside a Customer academy. In that case the Customer decides how the data is used, and its own privacy notice applies. We act only on the Customer's documented instructions.
If you are a learner, parent or teacher at an academy powered by Aula, please contact that organisation first about your data. We will support them in responding.
Personal data we handle
Depending on how you use Aula, we may handle:
- Account data: name, email address, password (stored only as a secure hash), role (owner, admin, teacher, student or parent), language preference and profile photo.
- Sign-in data: identifiers received when you choose to sign in with Google, GitHub or Microsoft, or through your organisation's SAML or OIDC single sign-on, and two-factor authentication settings.
- Learning data: enrolments, lesson progress, quiz attempts and scores, assignment submissions and feedback, attendance, grades, report cards, transcripts, certificates, points, badges and bookmarks.
- Communications: discussion posts, direct messages, announcements, reviews and notifications.
- Live class data: participation, attendance and, where the organiser enables it, recordings.
- Billing data: plan, invoices and payment status. Card details are collected and stored by our payment provider, Stripe, not by us.
- Technical data: IP address, device and browser type, app version, session identifiers, log and audit-log entries.
- Enquiry data: information you send us through contact, demo or support forms.
How and why we use data
We use personal data to:
- provide, secure and maintain the platform, including authentication, sessions and tenant data isolation;
- deliver courses, video, live classes, messaging, notifications and the other features a Customer enables;
- process subscriptions and course purchases, and send invoices and transactional emails;
- provide support and respond to enquiries;
- detect, investigate and prevent fraud, abuse and security incidents, including through audit logs;
- improve reliability and performance using aggregated or de-identified information;
- comply with legal obligations.
Where we act as controller, we rely on the following legal bases: performance of a contract (providing the service you signed up for), legitimate interests (securing and improving Aula, B2B marketing to business contacts), legal obligation (tax, accounting, lawful requests) and consent where required (for example optional marketing emails or non-essential cookies). You can withdraw consent at any time.
We do not sell personal data, and we do not use learner data from Customer academies for advertising.
Children and students
Aula is used by schools and other organisations that may enrol minors. In those cases the school or organisation is the controller and is responsible for obtaining any consent required from parents or guardians under applicable law.
Parent accounts can be linked to a child's student account so the parent can follow progress, attendance and grades. Children's data is used only to provide the educational service; we do not use it for advertising or to build marketing profiles.
We do not knowingly allow children to create a Aula Customer account themselves. If you believe a child's data has been provided to us without proper authorisation, contact the relevant school or write to privacy@example.com.
Retention and security
We keep personal data for as long as needed for the purposes described above. Customer academy data is kept for the duration of the Customer's subscription and then deleted or returned in line with our agreement with the Customer. Billing records are kept for as long as tax and accounting laws require. Logs are kept for a limited period for security and troubleshooting.
We protect data with measures appropriate to the risk, including:
- tenant data isolation enforced in the database with PostgreSQL row-level security;
- encryption in transit (TLS) and hashed passwords;
- two-factor authentication and enterprise single sign-on options;
- role-based access controls with granular permissions;
- audit logs of significant administrative actions;
- scoped API keys and signed webhooks for integrations.
No system is perfectly secure. If you discover a vulnerability, please report it to security@example.com.
Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete your data;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with your local data protection authority.
If your data is held inside a Customer academy, send your request to that organisation; we will help them respond. For data we control, email privacy@example.com. We may need to verify your identity before acting on a request, and we will respond within the time limits set by applicable law.
International transfers
Aula relies on service providers that may process data in countries other than your own. Where personal data is transferred outside the European Economic Area, the United Kingdom or other regions with transfer restrictions, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, together with supplementary measures where needed.
You can request more information about the safeguards we use by writing to privacy@example.com.
Contact us
For privacy questions or requests, contact [Company legal name] at privacy@example.com or by post at [Registered office address].
For security issues, write to security@example.com. For general help with your account, write to support@example.com.