Privacy Policy · piattaforma empowerEdPrivacy Policy · empowerEd platform
I tuoi dati, e quelli degli studenti. Senza giri di parole.
Your data, and the students'. In plain language.
Questa informativa spiega quali dati passano dalla piattaforma empowerEd, chi ne è responsabile, dove sono custoditi, per quanto tempo e cosa puoi chiedere. Vale per l'accesso da browser su empowereducation.eu e per l'app empowerEd per iOS e Android, ed è raggiungibile dalla schermata di accesso e dalle impostazioni.
This notice explains which data flows through the empowerEd platform, who is responsible for it, where it is stored, for how long and what you can ask. It applies to browser access at empowereducation.eu and to the empowerEd app for iOS and Android, and is reachable from the login screen and the settings.
Versione 1.0 · aggiornata il 9 settembre 2026Version 1.0 · last updated 9 September 2026
00In breve
- La piattaforma è uno strumento della tua scuola. La scuola decide quali dati inserire e perché: è lei il Titolare del trattamento. UniversiData custodisce i dati per conto della scuola, come Responsabile del trattamento (cioè il fornitore che lavora su istruzione della scuola).
- Nessun account per gli studenti. Gli account sono di dirigenti, segreteria, docenti, personale scolastico e genitori o tutori, e li crea la scuola. Non ci si registra da soli.
- I dati scolastici sono custoditi nell'Unione Europea. Non li vendiamo, non li cediamo a terzi per scopi loro, non mostriamo pubblicità, non li usiamo per addestrare modelli di intelligenza artificiale e nessuna decisione sugli studenti viene presa da un automatismo.
- Nessun tracciamento. La piattaforma non profila, non usa strumenti di analisi del traffico, non traccia gli utenti tra app o siti diversi, non usa l'identificativo pubblicitario del telefono (IDFA/AAID) e non chiede il permesso di tracciamento. Da browser usa solo i cookie tecnici necessari all'accesso.
- Per i tuoi diritti, la prima porta è la scuola. Puoi scrivere anche a noi: privacy@universidata.it.
01Chi siamo e come contattarci
La piattaforma empowerEd (School Manager con i suoi moduli, e l'app empowerEd per iOS e Android) è sviluppata e gestita da UniversiData S.r.l., Via Giuseppe Bandi 7, 00128 Roma (RM), Italia, P. IVA e C.F. 17486781002.
Per qualsiasi domanda su questa informativa o sul trattamento dei tuoi dati puoi scrivere al nostro contatto privacy: privacy@universidata.it.
Per assistenza sull'uso della piattaforma: support@universidata.it.
02La scuola e UniversiData: due ruoli diversi
La scuola è il Titolare del trattamento
La scuola che ti ha dato l'accesso decide quali dati raccogliere (anagrafiche, presenze, voti, comunicazioni, documenti, dati amministrativi), per quali finalità e per quanto tempo. Lo fa nell'ambito delle proprie funzioni educative e amministrative, come previsto dalla legge. La scuola ha una propria informativa, che ti è stata consegnata o che puoi chiederle, e, dove previsto, un proprio DPO.
UniversiData è il Responsabile del trattamento
UniversiData fornisce la piattaforma e l'infrastruttura, e tratta i dati solo per conto della scuola e solo secondo le sue istruzioni, sulla base di un accordo scritto (art. 28 GDPR). Vale anche per le notifiche: la scuola decide quando inviarle; il testo che passa da Google e Apple è un avviso generico. Non usiamo i dati scolastici per scopi nostri.
Quando UniversiData è Titolare in proprio
Per pochi dati, necessari a far funzionare e a proteggere la piattaforma, UniversiData decide in autonomia ed è quindi Titolare: i registri tecnici di funzionamento (log), i dati diagnostici sugli errori e le richieste che ci invii direttamente (assistenza, esercizio dei diritti). Trovi i dettagli nella sezione 4.
03Chi usa la piattaforma
La piattaforma è riservata alle scuole clienti di UniversiData e alle persone che la scuola autorizza:
- dirigenti, segreteria e personale amministrativo, per la gestione della scuola: anagrafiche, iscrizioni, orari, comunicazioni, adempimenti e amministrazione;
- docenti e personale scolastico, per il registro, le presenze, le valutazioni e le comunicazioni;
- genitori e tutori, per seguire l'andamento scolastico dei propri figli, giustificare assenze, ricevere comunicazioni e gestire le pratiche con la scuola.
Si accede da browser su empowereducation.eu o dall'app empowerEd, con le stesse credenziali e le stesse regole. Gli account li crea la scuola. Non esiste una registrazione libera e gli studenti non hanno un account: i loro dati compaiono nella piattaforma perché li inserisce la scuola, e sono visibili solo al personale autorizzato e ai genitori o tutori collegati a quello studente. I dati dell'account sono richiesti dalla scuola: senza, l'accesso non è possibile.
04Quali dati passano dalla piattaforma
| Categoria | Esempi | Chi li inserisce | Chi decide (Titolare) |
|---|---|---|---|
| Dati dell'account | nome e cognome, email, ruolo (dirigente, segreteria, docente, genitore), classi o studenti collegati, identificativo utente, identificativo del dispositivo per le notifiche dell'app | la scuola; il dispositivo per le notifiche | la scuola |
| Credenziali di accesso | email e password. La password è conservata solo in forma cifrata non reversibile: nemmeno UniversiData può leggerla DA CONFERMARE (dev): algoritmo di hashing | tu | la scuola |
| Dati scolastici degli studenti | anagrafica, classe, presenze e assenze, giustificazioni, voti e valutazioni, note e annotazioni, comunicazioni scuola-famiglia | la scuola (docenti, segreteria); i genitori per le giustificazioni | la scuola |
| Dati amministrativi | iscrizioni e ammissioni, dati di fatturazione e pagamenti delle famiglie, contratti e presenze del personale, orari DA CONFERMARE: elenco dei moduli attivi nella v1 (Admission, BudgetEd, RDA, GDPR Hub…) e cosa gestiscono | la scuola; i genitori per le proprie pratiche | la scuola |
| Dati sensibili, in particolare sulla salute (art. 9 GDPR) | informazioni di salute rilevanti per la vita scolastica: allergie, diete, esigenze educative speciali (PEI, PDP), certificati medici a corredo delle assenze e, se gestita nella piattaforma, la scelta sull'insegnamento della religione | la scuola; i genitori quando allegano un certificato | la scuola |
| Documenti e foto | allegati caricati (giustifiche, certificati, circolari, documenti d'iscrizione, altri documenti) | personale scolastico, docenti, genitori | la scuola |
| Registro degli accessi | chi ha aperto quale informazione e quando | raccolti automaticamente | la scuola |
| Log tecnici di server e rete | browser o modello e sistema operativo del dispositivo, versione dell'app, indirizzo IP, data e ora delle richieste, segnalazioni di errore | raccolti automaticamente | UniversiData |
| Richieste dirette | email di assistenza o di esercizio dei diritti che ci invii | tu | UniversiData |
Se accedi dal browser
La piattaforma usa solo cookie tecnici di sessione, necessari a riconoscerti dopo l'accesso e a proteggere la sessione: per questi la legge non richiede consenso, e per questo non c'è un banner. Non ci sono cookie di analisi o di profilazione. DA CONFERMARE (dev): nessun analytics né script di terzi sulla piattaforma web.
Se usi l'app
Face ID e impronta digitale. Se attivi lo sblocco biometrico, il riconoscimento avviene interamente sul tuo dispositivo tramite il sistema operativo. L'app riceve solo l'esito ("riconosciuto" o "non riconosciuto"): nessun dato biometrico lascia il telefono né arriva a UniversiData.
Sul tuo telefono l'app conserva la chiave di accesso alla sessione e una copia temporanea dei contenuti visualizzati e degli allegati aperti, protetti dai sistemi di cifratura del dispositivo: sono strettamente necessari a far funzionare l'app e non servono ad altro. DA CONFERMARE (dev): durata della sessione; se la scuola o UniversiData possono revocare l'accesso da remoto in caso di telefono perso.
L'app non accede alla rubrica, alla posizione geografica o al microfono. Usa la fotocamera e la galleria solo quando scegli tu di scattare o allegare una foto o un documento. Puoi revocare in qualsiasi momento i permessi di fotocamera e notifiche dalle impostazioni del telefono. DA CONFERMARE (dev): elenco dei permessi dichiarati in app.json.
05Perché trattiamo i dati e su quale base
Dati trattati per conto della scuola
Questa informativa integra e non sostituisce quella della scuola, che per i dati scolastici è l'informativa ai sensi degli artt. 13 e 14 GDPR. Le finalità le stabilisce la scuola: gestione del registro, delle presenze, delle valutazioni, delle comunicazioni con le famiglie (comprese le notifiche dell'app), delle iscrizioni, della segreteria e degli adempimenti amministrativi. La base giuridica è quella indicata dalla scuola. Di regola, per le scuole statali e paritarie, l'istruzione è un compito di interesse pubblico previsto dalla legge (art. 6.1.e e 6.1.c GDPR); i dati sulla salute sono trattati per motivi di interesse pubblico rilevante nel settore dell'istruzione, come previsto dal Codice privacy italiano (art. 9.2.g GDPR e art. 2-sexies D.lgs. 196/2003). Per le scuole private non paritarie fa fede l'informativa della scuola. In caso di divergenza fa fede sempre l'informativa della scuola. UniversiData, come Responsabile, esegue queste operazioni per conto della scuola senza definirne le finalità.
Dati trattati da UniversiData in proprio
- Far funzionare la piattaforma e tenerla sicura (log tecnici, diagnostica errori, prevenzione di accessi non autorizzati): interesse legittimo di UniversiData alla sicurezza e alla continuità del servizio (art. 6.1.f GDPR), che risponde anche all'obbligo di sicurezza del trattamento verso la scuola (art. 32). Puoi opporti a questo trattamento per motivi legati alla tua situazione particolare (art. 21).
- Rispondere alle tue richieste di assistenza o di esercizio dei diritti: obbligo di legge per le richieste sui diritti (art. 6.1.c e art. 12 GDPR) e interesse legittimo a rispondere a chi chiede assistenza (art. 6.1.f).
06Chi può vedere i dati
Ogni persona vede solo ciò che serve al suo ruolo. Un docente vede le proprie classi. Un genitore vede solo i propri figli. La segreteria e la dirigenza vedono quello che la scuola ha stabilito per il loro ruolo. Per gli studenti maggiorenni la scuola stabilisce quali informazioni restano visibili ai genitori. Ogni accesso viene tracciato in un registro.
Il personale tecnico di UniversiData può accedere ai dati solo nell'ambito dei servizi di manutenzione, assistenza e sicurezza previsti dal contratto con la scuola, con accessi nominativi e registrati, ed è vincolato alla riservatezza.
Comunichiamo dati ad autorità pubbliche solo se un obbligo di legge ce lo impone, informandone la scuola salvo che la legge lo vieti.
07Fornitori e dove stanno i dati
Per fornire la piattaforma ci avvaliamo di alcuni fornitori tecnici, nominati sub-responsabili (fornitori dei fornitori) con accordi che li vincolano alle stesse garanzie che diamo alla scuola. L'elenco è lo stesso allegato all'accordo con la scuola, che lo conosce e lo approva. PRIMA DI PUBBLICARE: la tabella deve coincidere con l'elenco nel DPA firmato dalle scuole.
| Servizio | Fornitore | Dove sono trattati i dati | Cosa tratta |
|---|---|---|---|
| Server e database della piattaforma | DA CONFERMARE (dev): fornitore | DA CONFERMARE (dev): regione, deve essere UE | tutti i dati dell'account, scolastici e amministrativi |
| Archiviazione di documenti e foto | DA CONFERMARE (dev): fornitore | DA CONFERMARE (dev): regione UE | allegati caricati |
| Recapito delle notifiche push dell'app | Google (Firebase Cloud Messaging) e Apple (APNs) | UE e Stati Uniti. Google LLC e Apple Inc. aderiscono all'EU-U.S. Data Privacy Framework (decisione di adeguatezza della Commissione europea del 10 luglio 2023); in subordine si applicano le clausole contrattuali standard (decisione 2021/914). Puoi chiederne copia a privacy@universidata.it | l'identificativo tecnico del dispositivo e un avviso generico, senza dati scolastici |
| Email di servizio (inviti, accesso, recupero password) | DA CONFERMARE (dev): fornitore e regione | DA CONFERMARE | indirizzo email e contenuto del messaggio |
| Posta per assistenza e richieste | DA CONFERMARE: fornitore della casella (es. Microsoft 365) e regione | DA CONFERMARE | le email che ci invii |
| Diagnostica errori | DA CONFERMARE (dev): se presente (es. Firebase Crashlytics, Sentry), altrimenti togliere la riga. Se presente nell'app, un SDK che legge identificativi sul telefono richiede un opt-in (art. 122 Codice privacy): scrivere "attiva solo se la abiliti nelle impostazioni". | DA CONFERMARE | dati tecnici sull'errore, senza contenuti scolastici |
I dati scolastici sono custoditi in server situati nell'Unione Europea. L'unico flusso verso fornitori che operano anche fuori dall'UE è il recapito delle notifiche push dell'app, che non contengono dati scolastici: la notifica ti avvisa che c'è una novità e il contenuto si carica solo quando apri l'app.
08Per quanto tempo conserviamo i dati
- Dati scolastici, amministrativi e dell'account: per tutta la durata del contratto tra la scuola e UniversiData, secondo i tempi di conservazione stabiliti dalla scuola. Alla fine del contratto la scuola può esportare i dati in un formato utilizzabile; poi li cancelliamo entro DA CONFERMARE: 30/60/90 giorni, come nel DPA, salvo diversa istruzione della scuola o obblighi di legge.
- Account di una singola persona: fino a quando la scuola lo chiude (ad esempio a fine anno scolastico, per un docente che cambia scuola o un genitore il cui figlio si trasferisce) o su tua richiesta, vedi la sezione 11.
- Log tecnici e dati diagnostici: DA CONFERMARE (dev): es. 12 mesi, poi cancellati o resi anonimi.
- Copie di sicurezza (backup): cifrate e sovrascritte entro DA CONFERMARE (dev): es. 30 giorni dalla cancellazione del dato.
- Richieste di assistenza o esercizio dei diritti: per il tempo necessario a gestirle e, se serve, a dimostrare di averle gestite (fino a 24 mesi).
09Come proteggiamo i dati
- Comunicazioni cifrate tra browser o app e server (HTTPS/TLS). DA CONFERMARE (dev): cifratura a riposo sul database e sullo storage.
- Password conservate solo in forma cifrata non reversibile; recupero password tramite link a tempo inviato alla tua email.
- Accessi per ruolo e registro degli accessi, come descritto nella sezione 6.
- Copie di sicurezza cifrate e infrastruttura progettata per resistere ai guasti.
- Nell'app, sblocco biometrico opzionale gestito dal dispositivo.
- Sistema di gestione certificato ISO/IEC 27001 (sicurezza delle informazioni) e ISO 9001 (qualità).
- In caso di violazione dei dati, informiamo la scuola senza ingiustificato ritardo, così che possa adempiere ai propri obblighi verso le persone interessate e il Garante.
Maggiori dettagli nella pagina Sicurezza.
10I tuoi diritti
Hai diritto di accedere ai dati che ti riguardano (e, come genitore o tutore, a quelli di tuo figlio), di farli correggere, di chiederne la cancellazione, di chiedere di bloccarne l'uso (limitazione), di opporti al trattamento quando si basa su un interesse legittimo o su un compito di interesse pubblico, di riceverli in un formato leggibile da una macchina nei casi previsti dalla legge, e di proporre reclamo al Garante per la protezione dei dati personali o all'autorità del tuo Paese.
A chi rivolgerti. Per i dati scolastici e amministrativi (voti, presenze, note, documenti, pratiche) la richiesta va alla scuola, che è il Titolare e che risponde tramite la segreteria o il proprio DPO. Noi la aiutiamo a darti seguito. Per i dati tecnici e le richieste dirette puoi scrivere a privacy@universidata.it. Se scrivi a noi per una richiesta che compete alla scuola, la inoltriamo e te lo diciamo.
Rispondiamo entro un mese, prorogabile di due nei casi complessi. È gratuito.
11Come cancellare il tuo account
Puoi chiedere in qualsiasi momento la cancellazione del tuo account empowerEd. Vale sia per l'accesso da browser sia per l'app: l'account è lo stesso.
- Dalla piattaforma o dall'app: Impostazioni → Account → "Richiedi la cancellazione dell'account". DECISIONE (dev): Apple (linea guida 5.1.1) e Google richiedono che la cancellazione si possa avviare dall'app, non solo via email; la sola disattivazione non basta. Serve questo bottone, con conferma della scuola dietro.
- Scrivendo alla tua scuola (segreteria o DPO), che gestisce gli account.
- Scrivendo a noi a privacy@universidata.it dall'indirizzo email associato all'account, indicando la scuola. Verifichiamo la richiesta con la scuola e procediamo.
Cosa viene cancellato: l'account viene disattivato subito e cancellato entro DA CONFERMARE: 30 giorni dalla conferma, insieme ai dati che ti identificano come utente (email, credenziali, ruolo, identificativo, dispositivi registrati per le notifiche).
Cosa resta: i dati scolastici e amministrativi degli studenti (voti, presenze, documenti, pratiche) appartengono al fascicolo dello studente e sono conservati dalla scuola per gli obblighi di legge. Per lo stesso motivo, se lavori nella scuola, il tuo nome resta associato ai voti, alle note e ai documenti che hai firmato. La cancellazione dell'account non li elimina: per quelli la richiesta va alla scuola.
Cancellare l'app dal telefono non cancella l'account.
12Minori
La piattaforma non è destinata all'uso diretto da parte di minori e non prevede account per gli studenti. I dati degli studenti minorenni sono trattati dalla scuola nell'esercizio delle sue funzioni, e i genitori o tutori esercitano i diritti per loro conto. Se veniamo a conoscenza di un account creato per un minore al di fuori di quanto stabilito dalla scuola, lo segnaliamo alla scuola, che decide.
13Modifiche a questa informativa
Se cambiamo qualcosa di sostanziale (nuovi fornitori, nuove finalità, nuovi moduli con nuove categorie di dati) aggiorniamo questa pagina, ne informiamo le scuole e, quando serve, lo segnaliamo nella piattaforma. La data in cima indica l'ultima versione. Le versioni precedenti si possono richiedere a privacy@universidata.it.
In caso di differenze tra la versione italiana e quella inglese prevale il testo italiano. Questa informativa riguarda la piattaforma empowerEd. Per il sito universidata.it valgono la privacy policy del sito e la cookie policy.
00In short
- The platform is a tool of your school. The school decides which data to enter and why: it is the Data Controller. UniversiData stores and processes data on the school's behalf, as Data Processor (the provider working on the school's instructions).
- No accounts for students. Accounts belong to school leaders, office staff, teachers, other school staff and parents or guardians, and are created by the school. There is no self sign-up.
- School data is stored in the European Union. We do not sell it, we do not share it with third parties for their own purposes, we show no advertising, we do not use it to train artificial intelligence models, and no decision about students is made by an automated process.
- No tracking. The platform does not profile users, uses no traffic analytics, does not track users across apps or websites, does not use the phone's advertising identifier (IDFA/AAID) and does not ask for tracking permission. In the browser it uses only the technical cookies needed to log in.
- For your rights, the first door is your school. You can also write to us: privacy@universidata.it.
01Who we are and how to reach us
The empowerEd platform (School Manager with its modules, and the empowerEd app for iOS and Android) is developed and operated by UniversiData S.r.l., Via Giuseppe Bandi 7, 00128 Rome (RM), Italy, VAT and tax code 17486781002.
For any question about this notice or about the processing of your data, write to our privacy contact: privacy@universidata.it.
For help using the platform: support@universidata.it.
02The school and UniversiData: two different roles
The school is the Data Controller
The school that gave you access decides which data to collect (personal details, attendance, grades, communications, documents, administrative data), for which purposes and for how long. It does so within its educational and administrative functions, as provided by law. The school has its own privacy notice, which it has given you or which you can request, and, where required, its own DPO.
UniversiData is the Data Processor
UniversiData provides the platform and the infrastructure, and processes data only on behalf of the school and only on its instructions, under a written agreement (Art. 28 GDPR). This includes notifications: the school decides when to send them; the text that passes through Google and Apple is a generic alert. We do not use school data for our own purposes.
When UniversiData is a Controller in its own right
For a small set of data needed to run and protect the platform, UniversiData decides on its own and is therefore the Controller: technical logs, diagnostic data about errors, and the requests you send us directly (support, exercise of rights). Details are in section 4.
03Who uses the platform
The platform is reserved to UniversiData's client schools and to the people each school authorises:
- school leaders, office and administrative staff, to run the school: personal records, enrolments, timetables, communications, compliance and administration;
- teachers and school staff, for the register, attendance, assessments and communications;
- parents and guardians, to follow their children's progress, justify absences, receive communications and handle their paperwork with the school.
Access is through the browser at empowereducation.eu or through the empowerEd app, with the same credentials and the same rules. Accounts are created by the school. There is no open registration and students do not have an account: their data appears in the platform because the school enters it, and it is visible only to authorised staff and to the parents or guardians linked to that student. Account data is required by the school: without it, access is not possible.
04Which data flows through the platform
| Category | Examples | Who enters it | Who decides (Controller) |
|---|---|---|---|
| Account data | name and surname, email, role (school leader, office, teacher, parent), linked classes or students, user identifier, device identifier for app notifications | the school; the device for notifications | the school |
| Login credentials | email and password. The password is stored only in irreversibly encrypted form: not even UniversiData can read it TO CONFIRM (dev): hashing algorithm | you | the school |
| Students' school data | personal details, class, attendance and absences, justifications, grades and assessments, notes and remarks, school-family communications | the school (teachers, office); parents for justifications | the school |
| Administrative data | enrolments and admissions, families' billing and payment data, staff contracts and attendance, timetables TO CONFIRM: list of modules active in v1 (Admission, BudgetEd, RDA, GDPR Hub…) and what they handle | the school; parents for their own paperwork | the school |
| Sensitive data, in particular health data (Art. 9 GDPR) | health information relevant to school life: allergies, diets, special educational needs (individual education plans), medical certificates attached to absences and, if managed in the platform, the choice about religious education | the school; parents when attaching a certificate | the school |
| Documents and photos | uploaded attachments (justifications, certificates, notices, enrolment documents, other documents) | school staff, teachers, parents | the school |
| Access log | who opened which information and when | collected automatically | the school |
| Server and network technical logs | browser or device model and operating system, app version, IP address, date and time of requests, error reports | collected automatically | UniversiData |
| Direct requests | support emails or requests to exercise your rights that you send us | you | UniversiData |
If you log in from the browser
The platform uses only technical session cookies, needed to recognise you after login and to protect the session: the law requires no consent for these, which is why there is no banner. There are no analytics or profiling cookies. TO CONFIRM (dev): no analytics or third-party scripts on the web platform.
If you use the app
Face ID and fingerprint. If you enable biometric unlock, recognition happens entirely on your device through the operating system. The app only receives the result ("recognised" or "not recognised"): no biometric data leaves the phone or reaches UniversiData.
On your phone the app keeps the session key and a temporary copy of the content you viewed and the attachments you opened, protected by the device's encryption: they are strictly necessary to run the app and serve no other purpose. TO CONFIRM (dev): session duration; whether the school or UniversiData can revoke access remotely if the phone is lost.
The app does not access your contacts, location or microphone. It uses the camera and the photo library only when you choose to take or attach a photo or a document. You can revoke camera and notification permissions at any time in your phone settings. TO CONFIRM (dev): list of permissions declared in app.json.
05Why we process data and on what legal basis
Data processed on behalf of the school
This notice supplements and does not replace the school's own, which for school data is the notice under Arts. 13 and 14 GDPR. The purposes are set by the school: managing the register, attendance, assessments, communications with families (including app notifications), enrolments, the school office and administrative duties. The legal basis is the one indicated by the school. As a rule, for state and state-recognised schools, education is a task in the public interest laid down by law (Art. 6.1.e and 6.1.c GDPR); health data is processed for reasons of substantial public interest in the field of education, as provided by the Italian Privacy Code (Art. 9.2.g GDPR and Art. 2-sexies Legislative Decree 196/2003). For private, non-recognised schools, the school's own notice applies. In case of any divergence, the school's notice always prevails. UniversiData, as Processor, carries out these operations on the school's behalf without defining their purposes.
Data processed by UniversiData in its own right
- Running the platform and keeping it secure (technical logs, error diagnostics, prevention of unauthorised access): UniversiData's legitimate interest in the security and continuity of the service (Art. 6.1.f GDPR), which also meets its security obligation towards the school (Art. 32). You can object to this processing on grounds relating to your particular situation (Art. 21).
- Answering your requests for support or to exercise your rights: legal obligation for rights requests (Art. 6.1.c and Art. 12 GDPR) and legitimate interest in answering support requests (Art. 6.1.f).
06Who can see the data
Everyone sees only what their role requires. A teacher sees their own classes. A parent sees only their own children. Office staff and school leaders see what the school has decided for their role. For adult students, the school decides which information remains visible to parents. Every access is recorded in a log.
UniversiData's technical staff can access data only within the maintenance, support and security services provided for in the contract with the school, with named and logged access, and is bound by confidentiality.
We disclose data to public authorities only when a legal obligation requires it, informing the school unless the law prohibits it.
07Providers and where data lives
To deliver the platform we rely on a few technical providers, appointed as sub-processors (our providers' providers) under agreements that bind them to the same guarantees we give the school. The list is the one attached to the agreement with the school, which knows and approves it. BEFORE PUBLISHING: the table must match the list in the DPA signed by the schools.
| Service | Provider | Where data is processed | What it handles |
|---|---|---|---|
| Platform servers and database | TO CONFIRM (dev): provider | TO CONFIRM (dev): region, must be EU | all account, school and administrative data |
| Storage of documents and photos | TO CONFIRM (dev): provider | TO CONFIRM (dev): EU region | uploaded attachments |
| App push notification delivery | Google (Firebase Cloud Messaging) and Apple (APNs) | EU and United States. Google LLC and Apple Inc. adhere to the EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023); as a fallback, the standard contractual clauses (Decision 2021/914) apply. You can request a copy at privacy@universidata.it | the technical device identifier and a generic alert, with no school data |
| Service emails (invitations, access, password recovery) | TO CONFIRM (dev): provider and region | TO CONFIRM | email address and message content |
| Mailbox for support and requests | TO CONFIRM: mailbox provider (e.g. Microsoft 365) and region | TO CONFIRM | the emails you send us |
| Error diagnostics | TO CONFIRM (dev): if present (e.g. Firebase Crashlytics, Sentry), otherwise remove this row. If present in the app, an SDK reading device identifiers needs an in-app opt-in (Art. 122 Italian Privacy Code): write "active only if you enable it in the settings". | TO CONFIRM | technical data about the error, no school content |
School data is stored on servers located in the European Union. The only flow to providers that also operate outside the EU is the delivery of the app's push notifications, which contain no school data: the notification tells you there is something new, and the content is loaded only when you open the app.
08For how long we keep data
- School, administrative and account data: for the whole duration of the contract between the school and UniversiData, according to the retention periods set by the school. At the end of the contract the school can export the data in a usable format; we then delete it within TO CONFIRM: 30/60/90 days, as in the DPA, unless the school instructs otherwise or the law requires otherwise.
- An individual's account: until the school closes it (for example at the end of the school year, for a teacher who changes school or a parent whose child transfers) or on your request, see section 11.
- Technical logs and diagnostics: TO CONFIRM (dev): e.g. 12 months, then deleted or anonymised.
- Backups: encrypted and overwritten within TO CONFIRM (dev): e.g. 30 days of the data being deleted.
- Support or rights requests: for as long as needed to handle them and, where necessary, to prove they were handled (up to 24 months).
09How we protect data
- Encrypted communication between browser or app and servers (HTTPS/TLS). TO CONFIRM (dev): encryption at rest on the database and storage.
- Passwords stored only in irreversibly encrypted form; password recovery through a time-limited link sent to your email.
- Role-based access and access log, as described in section 6.
- Encrypted backups and infrastructure designed to withstand failures.
- In the app, optional biometric unlock handled by the device.
- Management system certified to ISO/IEC 27001 (information security) and ISO 9001 (quality).
- In the event of a data breach, we inform the school without undue delay, so it can meet its obligations towards the people concerned and the supervisory authority.
More details on the Security page.
10Your rights
You have the right to access the data concerning you (and, as a parent or guardian, your child's), to have it corrected, to request its erasure, to ask that its use be blocked (restriction), to object to processing based on legitimate interest or on a task in the public interest, to receive it in a machine-readable format where the law provides for it, and to lodge a complaint with the Italian Data Protection Authority (Garante) or your local supervisory authority.
Who to contact. For school and administrative data (grades, attendance, notes, documents, paperwork) the request goes to the school, which is the Controller and answers through its office or its DPO. We help the school follow up. For technical data and direct requests you can write to privacy@universidata.it. If you write to us about a request that belongs to the school, we forward it and let you know.
We answer within one month, extendable by two in complex cases. Free of charge.
11How to delete your account
You can ask at any time for your empowerEd account to be deleted. This applies to both browser and app access: the account is the same.
- From the platform or the app: Settings → Account → "Request account deletion". DECISION (dev): Apple (guideline 5.1.1) and Google require that deletion can be started from within the app, not only by email; deactivation alone is not enough. This button is needed, with the school's confirmation behind it.
- By writing to your school (office or DPO), which manages accounts.
- By writing to us at privacy@universidata.it from the email address linked to the account, naming the school. We verify the request with the school and proceed.
What is deleted: the account is deactivated immediately and deleted within TO CONFIRM: 30 days of confirmation, together with the data that identifies you as a user (email, credentials, role, identifier, devices registered for notifications).
What remains: students' school and administrative data (grades, attendance, documents, paperwork) belongs to the student's record and is kept by the school under its legal obligations. For the same reason, if you work at the school, your name stays attached to the grades, notes and documents you signed. Deleting the account does not remove them: for that, the request goes to the school.
Uninstalling the app from your phone does not delete the account.
12Children
The platform is not intended for direct use by minors and provides no accounts for students. Data about underage students is processed by the school in the exercise of its functions, and parents or guardians exercise rights on their behalf. If we become aware of an account created for a minor outside what the school has established, we report it to the school, which decides.
13Changes to this notice
If we change something substantial (new providers, new purposes, new modules with new categories of data) we update this page, inform the schools and, where needed, flag it in the platform. The date at the top shows the latest version. Previous versions can be requested at privacy@universidata.it.
In case of differences between the Italian and English versions, the Italian text prevails. This notice covers the empowerEd platform. For the universidata.it website, the website privacy policy and the cookie policy apply.