PRIVACY
Privacy Policy
How EduDrive Inc. collects, uses, discloses and protects personal information — including student data processed on behalf of education clients — under Canadian privacy law.
Last updated: 10 July 2026
1. Who we are
EduDrive Inc. ("EduDrive", "we", "us") is an edtech studio and education-AI consultancy headquartered at 489 College Street, Suite 201, Toronto, ON M6G 1A5, Canada. Business Number: 462835197 RC0001. We design and deliver adaptive learning, intelligent tutoring, content generation, formative assessment support, accessibility features and LMS integration for schools, colleges, universities and training providers.
This Privacy Policy explains our practices regarding personal information collected through edudrive.pro, our contact channels and client engagements. It is written to comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and to acknowledge Ontario's Freedom of Information and Protection of Privacy Act (FIPPA) where we process records on behalf of Ontario public-sector education clients.
2. Privacy Officer
Our Privacy Officer oversees compliance with this policy and responds to access requests. Contact: [email protected] or EduDrive Inc., 489 College Street, Suite 201, Toronto, ON M6G 1A5, Canada. Telephone: +1 (416) 712-4085.
3. Scope — website visitors and clients
This policy covers:
- Visitors to edudrive.pro who browse pages, submit contact forms or manage cookie preferences;
- Prospective and current client representatives who correspond with us about project scope, retainers or learning pilots;
- Personal information we process as a service provider when building AI-driven learning tools for client organizations, which may include student data supplied by those clients under separate data-processing agreements.
When we act solely as a processor of student records on a client's behalf, the client's privacy policy and statutory obligations may also apply. We follow client instructions and contractual data-governance terms in those cases.
4. Information we collect
4.1 Website and contact data
When you submit our contact form, we collect your name, email address, subject selection and message content. We record PIPEDA consent at the time of submission. We do not use hidden fields filled by bots (honeypot submissions are discarded without storage).
When you visit our site, we may collect technical data such as IP address, browser type, device type, referring URL and pages viewed. Optional analytics cookies — used only with your consent — may collect aggregated usage statistics. See our Cookie Policy.
4.2 Client engagement data
During discovery, prototype and production delivery, we collect business contact details, role descriptions, project documentation, curriculum materials, assessment rubrics and — where required for the build — de-identified or pseudonymized learner interaction logs. We collect only what is necessary for the contracted project scope.
4.3 Student data
Student-data privacy is central to our work. When a client engages us to build adaptive learning or intelligent tutoring tools, we may process:
- Learner identifiers as supplied by the client (often pseudonymous IDs rather than legal names);
- Interaction logs (questions asked, hints received, responses submitted);
- Formative assessment results and knowledge-tracing signals used for personalised learning paths;
- Accessibility preference settings where inclusive-learning features are enabled.
We do not request student data beyond what the client authorizes. We do not sell student records. We do not use student interaction data to train general-purpose models for unrelated products without explicit written consent from the client.
5. Purposes of collection and use
We collect and use personal information for purposes that a reasonable person would consider appropriate, including:
- Responding to enquiries about learning pilots, edtech projects and retainers;
- Performing contracted services — adaptive learning builds, content generation, automated feedback systems, LMS integration and model QA;
- Maintaining academic-integrity safeguards and educator-review audit trails;
- Complying with legal obligations and defending legal claims;
- Improving website security and, with consent, analysing aggregated site usage;
- Managing billing, contracts and client communications.
We identify purposes at or before collection. If we need to use information for a new purpose, we will seek consent or ensure a permitted legal basis exists under PIPEDA.
6. Legal bases and consent
PIPEDA requires meaningful consent for collection, use and disclosure of personal information. For contact-form submissions, you provide express consent via the PIPEDA checkbox. For client projects, consent and authority flow from the client's agreement and their authority over student records.
You may withdraw consent for marketing communications at any time by emailing [email protected]. Withdrawal may limit our ability to provide ongoing services where information is required by contract or law.
7. Student-data minimisation and retention
We apply data minimisation: if a pilot can be validated with synthetic or de-identified cohorts, we prefer that approach. Production systems store only fields required for tutoring, formative assessment or accessibility features.
Retention periods are defined per contract. Typical practice:
- Contact-form data: up to twenty-four months after last correspondence unless a client relationship continues;
- Project artefacts containing student interactions: duration of contract plus a defined wind-down period (usually ninety days) unless law or the client requires longer retention;
- Aggregated, de-identified analytics: may be retained for internal quality improvement with no re-identification attempted.
At retention end, we securely delete or anonymize data unless litigation or regulatory hold requires otherwise.
8. Disclosure to third parties
We do not sell personal information. We may disclose information to:
- Sub-processors assisting with hosting, model inference or development tooling, bound by confidentiality and data-processing terms;
- Professional advisers (legal, accounting) under privilege;
- Regulators or law enforcement when required by valid legal process;
- The client organization that supplied student data, as part of normal project delivery.
Where sub-processors operate outside Canada, we disclose this to clients and implement contractual safeguards appropriate to PIPEDA's cross-border accountability requirements. Details appear in project data-processing schedules.
9. Security safeguards
We implement administrative, technical and physical safeguards proportionate to sensitivity, including access controls, encryption in transit (TLS), encryption at rest for production learner data stores, role-based permissions, logging and staff confidentiality training. No method of transmission over the Internet is perfectly secure; we commit to notifying affected clients and regulators of breaches where required by law.
10. Ontario FIPPA and public-sector clients
When serving Ontario school boards, colleges or universities subject to FIPPA, we align processing activities with client privacy impact assessments. We assist clients in responding to access requests where our systems hold relevant records. We do not disclose personal information held on behalf of a FIPPA institution except on client instruction or lawful requirement.
11. Your rights under PIPEDA
Subject to legal exceptions, you have the right to:
- Access personal information we hold about you and receive an account of its use and disclosure;
- Request correction of inaccurate or incomplete information;
- Challenge our compliance with PIPEDA;
- File a complaint with the Office of the Privacy Commissioner of Canada (OPC) if concerns are unresolved.
Submit access or correction requests to [email protected]. We respond within thirty days in most cases, or inform you of lawful extensions.
OPC contact: 30 Victoria Street, Gatineau, QC K1A 1H3 — www.priv.gc.ca — 1-800-282-1376.
12. Cookies and similar technologies
Essential cookies support basic site function. Analytics cookies are optional and activated only after consent via our cookie banner. Your choice is stored locally for six months. Full details: Cookie Policy.
13. Children's privacy
Our website is directed at education professionals and organizational decision-makers, not children. We do not knowingly collect personal information directly from individuals under sixteen through edudrive.pro. Student data in client projects is controlled by the client institution's policies and consent frameworks.
14. Changes to this policy
We may update this Privacy Policy to reflect legal, technical or business changes. Material updates will be posted here with a revised "Last updated" date. Continued use of the website after changes constitutes notice; active client contracts may receive direct notification where changes affect processing terms.
15. Automated decision-making
EduDrive builds adaptive learning and analytics tools that may produce recommendations or draft feedback for educator review. We do not make solely automated decisions about individuals that produce legal or similarly significant effects without human involvement on our marketing website. In client projects, any automated flag or recommendation is designed to route to an educator or designated staff member for approval before action is taken against a learner record. Clients define escalation paths in project documentation. If you believe an automated process we operate on behalf of your institution has affected you, contact your institution first; we will support their response under contract.
16. Contact summary
EduDrive Inc., Privacy Officer, 489 College Street, Suite 201, Toronto, ON M6G 1A5, Canada. Email: [email protected]. Phone: +1 (416) 712-4085.