Declare AI

Privacy Policy

Version 1.1 | Effective from [insert date] | Last updated [insert date]

1. Who we are

Declare AI Ltd (“Declare AI”, “we”, “us”, “our”) provides Declare AI, a software tool for higher-education institutions that lets students generate structured AI declarations for their assignments and gives institutions a verifiable record of those declarations.

This Privacy Policy explains what personal data Declare AI processes, how we process it, and the rights you have under UK data protection law. It is written to be read in plain English wherever possible, with technical and legal references kept to what is necessary.

Registered company: Declare AI Ltd, registered in England and Wales [insert company number].

Registered office: [insert registered address].

ICO registration: [insert ICO reference number once ICO registration is complete].

2. Who this policy applies to

This policy applies to:

If you are a UK university and you have signed a contract with Declare AI Ltd to provide the service to your students and staff, your institution is the data controller of your students’ and staff’s personal data. Declare AI Ltd acts as a data processor on your institution’s behalf under a Data Processing Agreement (DPA) you have signed with us under Article 28 of the UK GDPR.

3. What personal data we process

3.1 What we process by design (pseudonymous-only)

Declare AI is built so that we process the absolute minimum personal data needed to provide the service. Specifically, when a student or lecturer launches Declare AI from their institution’s LMS, we receive the following information from the LMS via the LTI 1.3 / LTI Advantage protocol:

3.2 What we do NOT process

These items are explicitly excluded from our processing by architectural choice:

3.3 Declaration content

When a student generates an AI declaration, the structured declaration text is stored against the pseudonymous_hash for the duration of the institutional retention period. The declaration content describes which AI tools the student used and for what purposes; it does not contain identifying information about the student beyond what they themselves include.

3.4 Institutional administrator accounts

Institutional administrators access an administrative portal separately from the LTI launch flow. For administrator accounts we process: name, work email address, role at the institution, and authentication credentials managed by our authentication provider. Administrator authentication is governed by a separate access agreement signed by the institution.

3.5 Website visitors (declareai.co.uk)

When you visit declareai.co.uk we process limited information needed to deliver the website and prevent abuse: see our Cookie Policy for cookie-level detail. We do not use third-party advertising or behavioural-tracking cookies.

4. Lawful basis for processing

Under the UK GDPR we must have a lawful basis for processing personal data. The lawful basis we rely on depends on the processing:

4.1 Student and lecturer LTI use — Article 6(1)(e) (public task)

UK universities are public bodies exercising official authority in the conduct of academic assessment. Declare AI is provided to support that official authority. The processing of student and lecturer data through Declare AI is conducted under Article 6(1)(e) of the UK GDPR — “processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.” Your institution remains the data controller; we act as the processor on its behalf.

4.2 Institutional administrator accounts — Article 6(1)(b) (contract)

Administrator account processing is conducted under Article 6(1)(b) — “processing is necessary for the performance of a contract” — specifically the contract between Declare AI Ltd and the institution.

4.3 Website use — Article 6(1)(f) (legitimate interests)

Limited website operational data is processed under Article 6(1)(f) — our legitimate interest in operating and securing our website. We balance this interest against the data subjects’ rights and freedoms. You can object to this processing at any time using the contact details below.

5. Who we share your data with

Declare AI does not sell or rent personal data to anyone, ever. We share personal data only with the sub-processors listed below, each of whom acts on our documented instructions under a written contract that includes Article 28 UK GDPR processor obligations.

5.1 Current sub-processors

The authoritative sub-processor register — including service categories, data processed, security attestation links, DPA status, and dates last verified — is published at declareai.co.uk/sub-processors.

Sub-processor Service Location
Supabase Inc. Managed PostgreSQL database and authentication European Union (Frankfurt region)
Render, Inc. LTI tool compute at app.declareai.co.uk European Union (Frankfurt region)
Functional Software, Inc. (Sentry) Application error tracking (PII scrubbed at SDK level before transmission) European Union
Vercel Inc. Marketing website hosting at declareai.co.uk European Union (Frankfurt or Dublin region)
GitHub, Inc. Source code and continuous-integration infrastructure United States and European Union

If we add, change, or remove a sub-processor, we will notify our institutional customers at least 30 days in advance.

5.2 Disclosures we may be legally required to make

We may be required to disclose personal data to law enforcement, regulators (including the Information Commissioner’s Office), or courts where this is required by law. We will inform institutional data controllers of any such disclosure unless legally prohibited from doing so.

6. How long we retain personal data

Pseudonymous declaration records: retained for 7 years from generation by default, in line with UK higher education misconduct retention norms. Each institution may configure a different retention period in its Data Processing Agreement with us.

Audit trail records: retained for the same period as the underlying declarations. Audit records older than 2 years are archived to cold storage and remain retrievable but cannot be modified.

Verification metadata: Declaration ID metadata used to power the public verification page may be retained indefinitely for verification page integrity. The pseudonymous_hash is dropped at the end of the retention period.

Administrator accounts: retained for the duration of the institutional contract; deleted within 30 days of contract termination.

Website analytics: aggregate-only; no individual records retained beyond 12 months.

7. International data transfers

Declare AI is committed to keeping personal data within the UK and the European Economic Area (EEA). All sub-processors listed above are configured to process data within the EU. We are committed to moving to UK-only data residency in Year 2 of operation, when we will migrate to Cloudflare Workers with UK Points of Presence.

If we ever need to transfer personal data outside the UK/EEA, we will only do so under one of the appropriate safeguards permitted by UK GDPR (Articles 46–49), and we will update this policy and notify institutional data controllers in advance.

8. Your rights

Under the UK GDPR you have a number of rights in relation to your personal data. These rights apply to data Declare AI holds:

If you are a student or lecturer using Declare AI through your institution, please direct rights requests in the first instance to your institution’s Data Protection Officer. Your institution is the data controller and we will support them in responding to your request. If your institution directs you to us, or if you are a website visitor, contact us using the details in section 11.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk

9. How we keep your data safe

Declare AI is built with privacy and security as architectural principles, not afterthoughts:

10. Cookies

Our use of cookies and similar technologies is described in our separate Cookie Policy: declareai.co.uk/cookies.

11. How to contact us

For questions about this Privacy Policy or about how Declare AI processes personal data:

Email: privacy@declareai.co.uk

Post: Declare AI Ltd, [insert registered address].

If you are a student or lecturer, please contact your institution’s Data Protection Officer in the first instance.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our service, in our sub-processor list, or in applicable law. Where the change is material we will notify institutional data controllers at least 30 days in advance. The current version, effective date, and last-updated date are shown at the top of this policy.

13. Document history

Date Version Change
[insert effective date] 1.0 Initial publication.