Privacy Policy

What personal data PROODOS collects, why, on what legal basis, for how long, and what rights you have over it.

Document version: v2_20260816

1. About this policy

This is the Privacy Policy for PROODOS, a doctoral research platform for teacher professional development in artificial intelligence literacy, developed at the International Hellenic University (IHU), Thessaloniki.

This is version 2 of this policy, effective and last updated on August 16, 2026. Version 1 (August 15, 2026) said we could not yet confirm where Google processes the text you write, under what contractual terms, or which subprocessors are involved. We have since confirmed all three from Google's own published terms, and Section 5 now states them — including the part you would rather not hear, which is that your text is not confined to Europe.

It explains what personal data PROODOS collects, why, on what legal basis, for how long, and what rights you have over it. Read it alongside two other documents: the AI Disclosure and Research Participation texts you were shown when you registered, and the AI Impact Assessment, linked at the bottom of this page, which explains the platform's AI features in more depth.


2. Who is responsible for your data — the data controller

Under the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the data controller for the research conducted through PROODOS is:

  • George Kokkonis, MSc, PhD, Assistant Professor, Department of Information and Electronic Engineering, School of Engineering, International Hellenic University — Scientific Supervisor of the research, acting in his institutional capacity.

Address: International Hellenic University, Alexander Campus, P.O. Box 141, 574 00 Sindos, Thessaloniki, Greece.

The research is conducted day to day by:

  • John Dourvas, PhD Researcher, International Hellenic University.

Both are named here so you know who is responsible for your data and who carries out the research itself.

Contact for privacy requests: idourvas@ihu.gr.

Data Protection Officer: Prof. Kalliopi Kalambouka, dpo@ihu.gr, (+30) 2310-013.204.


3. What data we collect

  • Account details: your name, email address, and a securely hashed password.
  • Profile information you give us at onboarding: subject area, grade level, years of teaching experience, school location, class size, your AI experience and the AI tools you use, your learning goals, your preferred communication style, and, optionally, age range, gender, and primary language.
  • What you write on the platform: your module reflections, any AI-dispute comments, your practice-Sandbox prompts, and the AI-generated feedback, reflection prompts, and developmental narratives produced from them.
  • Your AI Literacy Scale for Teachers (AILST) questionnaire responses, at up to three points across the programme.
  • Records of your consent choices: what you agreed to, when, and the IP address you connected from at that moment. The IP address is automatically removed from the record after 30 days.
  • Technical and usage data: your login session, whether you have opened the always-on help assistant and how many messages you exchanged with it (never the content of those messages), and your module-completion timestamps.
  • A history of changes to certain profile fields (such as subject area, grade level, and teaching experience) is kept internally for research-integrity purposes.

4. Why we process your data, and on what legal basis

We rely on different legal grounds for different things we do with your data, because they are genuinely different situations:

  • Creating your account, tracking your progress through the 15 modules, and issuing your certificate: necessary to provide the programme you registered for (performance of a contract).
  • Generating AI feedback on what you write in your reflections and in the practice Sandbox: also necessary to provide the programme, because it is a core feature of it (performance of a contract). This applies whether or not you have agreed to research participation below — AI feedback is a platform feature, not a research activity by itself, and declining research participation does not switch it off.
  • Using your platform activity, reflections, and AILST responses as data for the doctoral research: only with your separate, freely given, and revocable consent, given at onboarding.
  • Sharing a limited set of your structured data for further, separately approved research: only with your separate, optional, revocable consent.
  • Keeping a record of what you consented to and when, for as long as the research-ethics process requires: a legal obligation arising from that process.
  • Keeping you logged in securely and protecting the platform against misuse: our legitimate interest in operating the platform safely.

5. The AI feature: how your writing reaches Google's AI service

When you write a reflection, use the practice Sandbox, or use several of the platform's other AI-assisted features, the text you write is sent to a Google generative-AI service to generate the feedback, prompts, or narrative you then see. The platform's code identifies the model in use as Gemini 2.5 Flash, accessed with an API key rather than through a Google Cloud enterprise account.

The account this platform uses has active billing, which means Google's paid-tier terms apply to this specific service rather than its free-tier terms. Two things follow from that:

  • the content you send is not used to train or improve Google's own models, and
  • Google logs prompts and responses for a limited period for abuse-detection purposes, as its paid-tier terms require.

Google's own paid-tier terms also state that it will process your prompts and responses under its 'Data Processing Addendum for Products Where Google is a Data Processor' (business.safety.google/processorterms). In plain terms: for this service Google acts as a processor working on our instructions, not as an independent controller deciding for itself what to do with your writing.

Where that processing happens is less contained, and you should know it. Google's terms say this data 'may be stored transiently or cached in any country in which Google or its agents maintain facilities'. So your text is not confined to Europe, and we do not control where it goes. For transfers out of the European Economic Area, that Addendum relies on the EU-US Data Privacy Framework where the receiving Google entity is certified under it, and on Standard Contractual Clauses otherwise. Google publishes the list of subprocessors it uses at business.safety.google/subprocessors.

One detail we still cannot confirm: which Google legal entity is our counterparty for this particular account. The Addendum leaves that to the underlying service agreement rather than fixing it. We are telling you this rather than glossing over it, and this section will be updated, with a new version number, once we can state it.

The platform's separate AI Impact Assessment explains, as our own assessment rather than a settled legal ruling, why we currently classify this AI use as limited-risk under the EU AI Act.


6. How long we keep your data, and what happens when the research ends

We keep your research data — what you wrote, your AILST responses, your module activity — for three years after data collection for this research ends. The three-year clock starts from the day data collection for the study stops, not from when the wider doctoral project finishes, which you have no way of tracking from outside it.

At the end of those three years, your account and your data go through the same transformation you can also request at any time from the Privacy dashboard: everything you wrote in your own words is deleted outright, your name, email address, and IP address are removed, and what remains is a small set of structured variables (subject area, grade level, teaching experience, AILST scores, module-completion timestamps) with no link back to a name or account you control. We describe this as a transformation rather than call the result "anonymous": whether the remaining data can genuinely no longer identify anyone is a legal question we are treating carefully rather than assuming.

Your PROODOS account and your access to the platform are not affected by this three-year research window. If you are still using the platform once the research data-collection period ends, you keep your account and keep using PROODOS as normal; only the research-data side of what you contributed is transformed as described above.


7. Your data is not a transferable asset

PROODOS may, in the future, be developed into a broader product beyond this doctoral research; that possibility exists and is a separate matter from your data. Regardless of that: the data collected from you under the consents described here would not be sold, licensed, or transferred to any commercial entity, and would not travel with the platform if it were ever sold or licensed as software. It stays held for the research it was collected for, under this policy, for as long as this policy says.


8. Data shared for secondary research

Separately from participating in this research, you may also give a second, optional consent for a narrower use: sharing a limited set of your structured data — subject area, grade level, years of teaching experience, your AILST responses, and your module-completion data — for further research analyses, approved separately through the IHU research-ethics process. This consent never includes anything you wrote in your own words; free text is excluded from it by design. You can decline this consent, or withdraw it later, without any effect on your participation in the main research or your access to the platform.

Short extracts from what you write may also be quoted directly in the dissertation and in academic publications arising from it. Every such quotation is anonymised before it appears — your name, your school, and any detail that could identify you, your colleagues, or your students is removed or altered. You are never named.


9. Your rights, and how to use them

  • Access: download a full copy of your personal data in JSON format from the Privacy dashboard's export option.
  • Rectification: correct most of your profile information yourself, at any time, from your profile page.
  • Withdraw consent: revoke each consent you gave independently, from the Privacy dashboard. Withdrawing the AI Disclosure acknowledgment logs you out and asks you to re-acknowledge it before continuing; withdrawing research participation or data sharing does not log you out.
  • Erasure: request the anonymisation described in section 6 above at any time, from the Privacy dashboard. This action is irreversible and requires a typed confirmation.
  • Object: contact idourvas@ihu.gr to object to how your data is processed, or with any other question about it.
  • Complain: you can also lodge a complaint directly with the supervisory authority — see section 13 below — independently of contacting us first.

10. Cookies, sessions, and technical data

  • Session cookie: keeps you logged in and remembers where you are in onboarding. It contains no content you wrote, only technical identifiers, and is cleared when you log out.
  • CSRF cookie: a security cookie that protects the forms on this platform from cross-site forgery. Standard for the software this platform is built on.
  • The platform's own code does not set any advertising or cross-site tracking cookies.
  • A single browser-storage item remembers your voice-input language preference on modules that offer voice input. It holds a language code only.
  • Your IP address is recorded only at the moment you give or decline a consent, stored on that consent record, and automatically cleared after 30 days. It is not otherwise logged by the platform.
  • Every page on this platform, including this one, loads three third-party code libraries from external content-delivery networks (jsdelivr.net, the Tailwind CSS CDN, and Cloudflare's cdnjs) to render its styling and icons. These providers can see the IP address and browser information of every visitor who loads a PROODOS page, independently of anything you do on the platform.

11. Security, and what we have not yet verified

What we can currently confirm:

  • Passwords are stored using the standard secure password hashing built into the platform's software framework, never as plain text.
  • Most of the platform requires you to be logged in; pages containing personal data are not publicly reachable.
  • Administrative access to participant data through the platform's internal administration tool is restricted to designated staff accounts.

What we have not yet verified, stated plainly rather than assumed:

  • We have not verified that automated rate-limiting or bot-protection is in place on login or registration.
  • The platform is currently run in an active-development configuration. Its production hosting arrangements are not yet finalised, and we will confirm and disclose them here before the pilot begins.

12. Other things worth knowing

  • There is no "forgot password" email flow on this platform. If you lose access to your account, contact the research team directly at idourvas@ihu.gr — there is no automated self-service password reset.
  • The development team takes periodic full backups of the platform's database as part of normal engineering practice, separate from the retention period described in section 6.
  • The always-on help assistant (Aletheia) does not store the content of your questions or its answers; only that you used it, when, and how many messages you exchanged are recorded.

13. Legal framework and how to complain

This processing is governed by the EU General Data Protection Regulation (Regulation 2016/679) and Greek Law 4624/2019.

If you believe your data has been mishandled, contact us first at idourvas@ihu.gr or the Data Protection Officer at dpo@ihu.gr. You also have the right to lodge a complaint directly with the Hellenic Data Protection Authority, independently of contacting us:

  • Address: Kifisias 1-3, 115 23 Athens, Greece
  • Website: www.dpa.gr
  • Email: complaints@dpa.gr

14. Changes to this policy

This is version 2 of this policy, effective August 16, 2026. If we make a material change in the future, we will update the version number and date above and describe what changed here.

What changed since version 1 (August 15, 2026): Section 5 no longer says we are unable to confirm how Google handles the text you write. We confirmed it from Google's published terms and now state it — that Google acts as a processor under a named Data Processing Addendum, that your text may be stored or cached in any country where Google maintains facilities rather than staying in Europe, which transfer safeguards apply, and where Google's subprocessor list is published. One point remains open and is named there.

We do not currently have an automated way to notify existing participants directly when this policy changes. Please check this page periodically, or ask us.