Privacy Policy
Effective date: 1 March 2026 ยท Last updated: April 2026
BC Academy International School ("BC Academy", "we", "us") operates the BC Academy AI platform
(bc-academy-ai.onrender.com), an AI-assisted school management tool for
teachers, students, parents, and administrators. This Privacy Policy explains how we
collect, use, and protect your personal data in compliance with:
- UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)
- UAE Federal Decree-Law No. 26 of 2025 on Child Digital Safety (in force January 2026)
- UAE Ministry of Education AI Guidelines 2026
- KHDA (Knowledge and Human Development Authority) school data regulations
1. Who We Are
BC Academy International School is a KHDA-regulated British curriculum school in Dubai, UAE.
We are the data controller for all personal data processed through the BC Academy AI platform.
This platform is provided exclusively to registered users of BC Academy โ teachers, students,
parents, and administrators โ and is not accessible to the general public.
2. What Data We Collect
From all users (via Google OAuth):
- Name and email address
- Google profile picture URL
- Google OAuth access token and refresh token (stored encrypted)
- Role (teacher, student, parent, or admin)
- Last login timestamp
From students (stored in our database):
- Year group, class name, and age
- Subject grades and term assessments
- Attendance records (present, absent, late counts)
- Personal task list (titles and due dates โ you create these)
From parents:
- Email address (must be pre-registered by the school)
- Link to their child's school account
BCA Assistant conversations (students only):
- Every message you send to BCA Assistant and every reply it sends back are stored in our database as part of a session record (student email, year group, timestamps, transcript).
- An automated review system reads these transcripts to produce pedagogical and safeguarding signals visible to your teachers, parents, and the school's Designated Safeguarding Lead. See Section 4 below for details.
- Messages sent to the AI are processed by Anthropic (Claude) under their data processing terms. Anthropic does not use our student data to train its models.
- Conversations with BCA Assistant by teachers, parents, and administrators are not stored in this persistent way โ they exist only as short-term context for the AI and are cleared on sign-out or server restart.
Via Google Workspace APIs (with your permission):
- Google Classroom: courses, assignments, submissions
- Google Drive: file names and links (not file content)
- Google Calendar: event titles, times, and locations
3. How We Use Your Data
- To provide personalised dashboards with grades, attendance, and schedules
- To power the BCA Assistant with relevant school context
- To allow parents to monitor their child's academic progress
- To enable teachers to manage courses, assignments, and student lists
- To maintain your personal task list
- To detect and comply with age restrictions (BCA Assistant blocked for students under 13)
We do not sell your data, use it for advertising, or share it with
third parties except as described in this policy.
3a. Automated Review of Student BCA Assistant Conversations
BCA Assistant conversations by students are processed by an automated review
system ("AI Insights") designed to support safeguarding and pedagogy. This
section describes what that processing does and who can see the results.
What is extracted:
- Category โ one of: safeguarding concern, wellbeing signal, academic honesty concern, learning struggle, engagement pattern, content policy attempt, or positive learning signal.
- Urgency โ immediate, this week, or background.
- Signal, rationale, and suggested action โ short text describing what was noticed and what an adult might do about it.
- Evidence excerpt โ a short verbatim quote from the student's message that triggered the flag.
Who sees flags, by category:
- Safeguarding signals go ONLY to the Designated Safeguarding Lead. They are NEVER sent automatically to parents. If a disclosure appears to involve a family member, this separation protects the student.
- Wellbeing, academic honesty, content policy attempts โ visible to the student's teachers.
- Engagement patterns โ visible to the student's parents.
- Learning struggles and positive signals โ visible to both teachers and parents.
Human review:
No decision affecting a student is made solely by the automated system.
Flags are suggestions for a human (teacher, parent, or DSL) to consider.
Every flag can be reviewed, annotated, or dismissed by an authorised adult.
Your rights:
You may delete your BCA Assistant chat history and associated review flags
at any time from Settings โ BCA Assistant โ Delete my chat history.
You may also request a copy of what has been stored about your conversations
by contacting admin@bcacad.org.
4. Children's Data and Under-13 Protection
UAE Law Compliance: In accordance with UAE Federal Decree-Law No. 26 of 2025
and UAE Ministry of Education AI Guidelines 2026, the BCA Assistant assistant is
disabled for all students under 13 years of age. This is enforced at
the API level and cannot be bypassed.
Students under 13 may access the platform for viewing their grades, attendance, and
personal tasks, but they cannot use the BCA Assistant.
Parents or guardians of students under 13 may contact the school to request a review
of what data is stored about their child, or to request deletion.
5. Data Retention
- User accounts: Retained while the student is enrolled. Deleted within 30 days of leaving the school.
- Student BCA Assistant conversations and review flags: Retained for the duration of your enrolment unless you delete them from Settings. The school performs a school-wide retention review at the end of each academic year and may purge conversations older than the current school year.
- Short-term AI conversation context (teachers, parents, admins): Held in memory for 7 days of inactivity, then cleared. Not persisted in our database beyond that window.
- Grades and attendance: Retained for the academic year in which they were recorded.
- Google OAuth tokens: Refreshed on login and updated in the database. Cleared when you delete your account.
- Personal tasks: Retained until you delete them or request account deletion.
6. Third-Party Services
We use the following trusted third-party services:
- Google (Alphabet Inc.) โ OAuth authentication and Google Workspace APIs (Classroom, Drive, Calendar). Governed by Google's Privacy Policy.
- Anthropic PBC โ AI responses are processed by Claude (Haiku model). Governed by Anthropic's Privacy Policy. Student personal data is never used for AI model training.
- Century Tech Ltd โ Adaptive learning platform used by the school. When a teacher views class or student progress through BCA Academy AI, queries are made to Century Tech's Connect API using a school-level API key. Century Tech acts as a separate data controller for the learning data it holds. Governed by Century Tech's Privacy Policy.
- Supabase Inc. โ Secure database hosting for user profiles, grades, tasks, and BCA Assistant chat history.
- Render Services Inc. โ Application hosting. Located in the United States.
7. Your Rights
Under UAE PDPL and applicable law, you have the right to:
- Access โ request a copy of the personal data we hold about you
- Rectification โ request correction of inaccurate data
- Deletion โ request deletion of your account and all associated data
- Restriction โ request that we limit how we use your data
- Objection โ object to processing of your personal data
You can exercise two types of deletion directly from the platform:
- Delete only your BCA Assistant chat history โ keeps your account, grades, attendance, and tasks. Settings โ BCA Assistant โ Delete my chat history.
- Delete your entire account โ removes your profile, grades, attendance, tasks, parent links, and chat history. Settings โ Data & Privacy โ Delete My Data.
For access requests, rectification, restriction, or objection, contact our
Data Protection Officer (see contact details below). We will respond within 30 days.
Note on safeguarding records: if an automated review flag was
created before you deleted your chat history, the flag and its evidence quote
are deleted along with the chat. The school's separate safeguarding records
(outside this platform) are governed by the school's safeguarding policy and
UAE child-protection law, not this Privacy Policy.
8. Data Security
- All data is transmitted over HTTPS (TLS 1.2+)
- Session cookies are httpOnly and samesite=lax to prevent cross-site attacks
- OAuth tokens are stored server-side โ never exposed to the browser
- The Supabase service key is backend-only and never sent to the client
- Role-based access control ensures users can only see their own data
9. Content Policy and AI Compliance
The BCA Assistant is configured with strict content filters appropriate for a school
environment in the UAE. All AI interactions are governed by:
- UAE Ministry of Education AI Guidelines 2026
- KHDA school content regulations
- UAE federal law and Islamic cultural values
The AI will not produce content that conflicts with UAE law, public morals, or
the school's safeguarding policy. Any serious welfare concerns raised in chat
are directed to the school's Designated Safeguarding Lead (DSL).
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update
the "Last updated" date at the top. For significant changes, we will notify registered
users via email or through a notice in the platform.
Contact Us
For privacy-related enquiries, data access requests, or to exercise your rights
under UAE PDPL: