Compliance Statement
StudyPulse governance, safeguards and legal-alignment commitments





Accessible web versionRead searchable text directly on this page+
Contents
- 1. Purpose and scope
- 2. Compliance framework
- 3. Privacy governance
- 4. Security governance
- 5. Student and child privacy
- 6. Responsible AI governance
- 7. Assessments, certificates, and psychometric features
- 8. Accessibility and inclusion
- 9. Payments and financial data
- 10. Vendors and Subprocessors
- 11. Incident response and notification
- 12. Customer compliance responsibilities
- 13. Certifications and independent assurance
- 14. Compliance requests
- 15. Updates and disclaimer
This document describes StudyPulse compliance principles and operational safeguards.
It is not a claim of certification, legal advice, or a guarantee that every customer use case is compliant.
1. Purpose and scope
StudyPulse is an AI-enabled learning and learning-operations platform for learners, educators, parents and guardians, and organizations. This Compliance Statement summarizes the governance principles StudyPulse uses to support lawful, secure, transparent, and responsible operation of the Service.
Compliance depends on the facts, jurisdiction, configuration, content, and customer instructions. StudyPulse supports customer compliance through contracts, privacy controls, role-based access, data-processing terms, security measures, human-oversight requirements, and assistance with lawful requests. Customers remain responsible for their own legal obligations and use of the Service.
2. Compliance framework
StudyPulse designs policies and controls with reference to legal frameworks that may apply to its operations or customers, including:
- The EU General Data Protection Regulation and UK GDPR, including controller-processor contracts, rights, security, accountability, and international transfer safeguards.
- Applicable U.S. state privacy laws, including service-provider or processor restrictions, consumer rights, and opt-out requirements where applicable.
- The Family Educational Rights and Privacy Act for school-managed education records where StudyPulse qualifies as an outsourced school official or service provider.
- The Children's Online Privacy Protection Act for covered online collection from children under 13, including school-authorized educational use and parental consent requirements.
- Cookie and electronic-communications rules, including consent for non-essential technologies where required.
- The EU Artificial Intelligence Act and other emerging AI rules, including transparency, risk management, human oversight, and prohibited-use considerations where applicable.
- Contract, consumer-protection, accessibility, intellectual-property, breach-notification, and sector-specific requirements applicable to a particular service or customer.
Reference to a law does not mean every law applies to every StudyPulse activity or customer. Applicability is assessed according to role, location, users, and processing context.
3. Privacy governance
- Clear distinction between StudyPulse acting as controller for direct operational data and processor or service provider for organization-managed data.
- Published Privacy Policy, Cookie Policy, Terms and Data Processing Addendum.
- Data minimization and purpose limitation for account, learning, AI, billing, support, and technical data.
- Processes for access, correction, deletion, portability, restriction, objection, consent withdrawal, and appeals where applicable.
- Contractual controls for service providers and material Subprocessors.
- International transfer safeguards where required, including standard contractual clauses or equivalent mechanisms.
- Retention and deletion practices based on service needs, customer instructions, legal obligations, risk, and secure backup cycles.
- No sale of personal data for money and no use of private learner records or private AI conversations for third-party behavioural advertising.
4. Security governance
StudyPulse maintains technical and organizational safeguards designed to protect personal data and platform availability according to risk. Measures may include:
- Role-based access and least-privilege administration.
- Encryption in transit and protected handling of credentials and secrets.
- Authentication, session management, account verification, and multifactor authentication where available or required.
- Secure development, testing, dependency review, logging, monitoring, backups, and change control.
- Incident-response procedures for identification, containment, investigation, remediation, documentation, and notification.
- Vendor due diligence and contractual security and confidentiality obligations.
- User and administrator controls for roles, permissions, content, integrations, and offboarding.
No online service can guarantee absolute security. Customers must protect credentials, devices, networks, administrator accounts, and any external systems connected to StudyPulse.
5. Student and child privacy
- Age-aware registration and authorization expectations for independent and organization-managed accounts.
- Parent or guardian linking through permission-controlled workflows rather than automatic access.
- Role-limited access to grades, progress, attendance, billing, and other learner information.
- Private learner notes and private AI conversations hidden from parents or guardians by default unless a lawful, clearly disclosed setting provides otherwise.
- School-authorized educational use of education records and children's data, with no behavioural advertising based on those records.
- Support for schools and organizations responding to parent, guardian, and eligible student rights.
- Retention limited to the authorized educational purpose, customer instructions, legal requirements, and secure backup cycles.
6. Responsible AI governance
- Transparency that users are interacting with AI features and that outputs may contain errors, bias, or outdated information.
- Human review before AI output is used for official grading, discipline, admissions, employment, safeguarding, clinical, disability, or other high-impact decisions.
- AI features positioned as learning aids, not substitutes for qualified teachers, advisers, medical professionals, counsellors, or emergency services.
- Restrictions on impersonation, fraud, cheating, unlawful content, discrimination, extraction of protected system information, and unauthorized disclosure of confidential data.
- Private organization data and private learner AI conversations are not intentionally used to train a public or shared general-purpose model without a separate agreement and any required permission.
- Use of de-identified or aggregated information for quality, safety, analytics, and service improvement where it no longer identifies individuals.
- Customer responsibility to configure and supervise AI use according to age, subject, assessment rules, and applicable law.
7. Assessments, certificates, and psychometric features
StudyPulse assessment scores, grades, readiness indicators, and AI-assisted scoring are educational tools and may require educator review. They do not guarantee competence, licensing, admission, employment, accreditation, or regulatory recognition.
Certificates confirm only the information shown and rules configured by the issuing organization. A certificate is not an accredited qualification unless the issuing organization is independently authorized to grant that qualification.
Well-being, behavioural, aptitude, learning-style, or psychometric features are support tools only. They must not be treated as medical diagnoses, disability determinations, or the sole basis for grading, ranking, exclusion, discipline, or certification.
8. Accessibility and inclusion
StudyPulse aims to support accessible and inclusive learning experiences through responsive interfaces, keyboard-aware interaction, readable structure, language and display preferences, and compatibility improvements. Accessibility is an ongoing process, and functionality may vary by content, device, browser, integration, or customer-created material.
Customers are responsible for ensuring that content they upload or create is accessible for their users. Accessibility concerns may be reported to support@studypulse.ai for investigation and reasonable remediation.
9. Payments and financial data
StudyPulse may use third-party payment providers to process subscriptions and transactions. Full card details are normally handled by the payment provider rather than stored directly by StudyPulse. Payment-provider security and compliance obligations are governed by the provider's terms and the services used.
StudyPulse does not claim to be a bank, payment institution, credit provider, escrow service, or financial adviser. Customers are responsible for taxes, lawful billing practices, refunds, and financial-record obligations applicable to their activities.
10. Vendors and Subprocessors
StudyPulse evaluates material vendors according to the service provided, data involved, location, risk, security practices, and contractual protections. Contracts are designed to limit processing to authorized purposes and require confidentiality, security, incident cooperation, and deletion or return as appropriate.
Organization customers may request current material Subprocessor information and relevant data-processing details at support@studypulse.ai.
11. Incident response and notification
StudyPulse maintains a process to receive, assess, contain, investigate, remediate, and document suspected security or privacy incidents. Where a qualifying Personal Data Breach affects organization-managed data, StudyPulse will notify the organization without undue delay and provide available information reasonably needed for its legal assessment.
Notifications to individuals or authorities are made by the party legally responsible, unless StudyPulse has a direct obligation or the parties agree otherwise.
12. Customer compliance responsibilities
- Determine the lawful purpose and legal basis for using StudyPulse.
- Provide privacy notices and obtain consents or authorizations required for learners, children, employees, parents, guardians, and other users.
- Configure roles, permissions, integrations, retention, content visibility, and administrator access appropriately.
- Review AI output and maintain meaningful human oversight.
- Set academic-integrity, grading, safeguarding, accessibility, and acceptable-use rules.
- Respond to rights requests and maintain records required by the customer's regulator or sector.
- Avoid uploading unnecessary medical, biometric, financial, government-identifier, or other highly sensitive information.
- Ensure customer-created learning content and third-party materials are lawful, accurate, accessible, and appropriately licensed.
13. Certifications and independent assurance
Unless StudyPulse expressly provides a current certificate or audit report in writing, this Statement must not be interpreted as a claim that StudyPulse is certified under ISO 27001, SOC 2, PCI DSS, HIPAA, FedRAMP, or another formal assurance program.
StudyPulse may pursue, obtain, expand, or discontinue certifications and assessments as the Service evolves. Any certification applies only to the scope, systems, dates, and entity stated in the official report or certificate.
14. Compliance requests
Customers may request a Data Processing Addendum, Subprocessor information, security documentation, accessibility information, or assistance with a reasonable procurement questionnaire. Availability and level of detail may depend on the plan, confidentiality, security sensitivity, and the nature of the request.
Email: support@studypulse.ai
Website: https://studypulse.ai/
15. Updates and disclaimer
StudyPulse may update this Statement as laws, controls, features, vendors, and assurance activities change. The effective date will be revised.
This Statement provides general information and is not legal advice. It does not create warranties, expand contractual liability, or replace the Terms, Privacy Policy, Data Processing Addendum, order form, or applicable law.
