Student privacy
School data needs school authority.
Seneca is designed to preserve a learning record across tools. That promise increases—not reduces—the need for a defined school program, scoped access, and an exit plan.
Roles and purpose
For a school-authorized program, the school would determine the educational purpose and the students and staff permitted to participate. Vindica would process program data only to deliver the documented Seneca service and instructions. Consumer Seneca activity is a separate context and must not be silently made visible to a school.
Minimum-data pilot
- Use a school-generated pseudonymous identifier; do not send a student name, personal email, date of birth, address, or parent contact unless the approved schedule specifically requires it.
- Send observable learning evidence only: item or skill reference, response outcome, timing, assistance state, and necessary provenance.
- Do not send disability, health, discipline, immigration, financial, or free-form counseling records.
- Do not enable audio, free-form transcript, Gmail, or classroom connections by default.
AI processing
Seneca features can send selected responses and relevant learning context to an AI API to generate feedback or structured learning signals. For a school pilot, AI processing is off unless the signed data schedule names the provider, fields, purpose, and configuration. School-program data may not use an unpaid AI tier whose terms permit product improvement.
Access and disclosure
School staff should see only records from their authorized program and role. Vindica’s database is hosted in Singapore. Authorized Vindica personnel may administer and support the service from South Korea. Additional provider locations are listed on the subprocessor page.
Rights and requests
For a school program, students and parents should normally submit access, correction, export, or deletion requests to the school. Vindica will support the school’s verified instructions. A consumer-account request must not automatically erase a school-controlled record that the school is legally required to retain; that conflict must be resolved with the school and reported to the requester.
No compliance shortcut
These controls are a readiness posture, not a certification that Seneca complies with FERPA, COPPA, state student-privacy laws, Korean law, or any school’s policy. Counsel and the school must review the actual facts and agreement before identifiable student data is used.