Who We Are
AI & Assessment Solutions Pty Ltd (ABN 78 685 561 906) trading as Socratic XR
Effective Date: 12 September 2025
Our websites are: https://socraticxr.com, https://assessmentxr.com, https://xrassessment.com/
This summary explains, in plain language, how we handle personal information across our platform and website. It should be read alongside our full Privacy Notice found below.
Our Privacy Commitment
Key promises: • We do not sell your personal data. • We do not use student user data to train AI models. • We only collect what’s reasonably necessary to run the platform and deliver services to schools and universities. • We follow the Australian Privacy Principles and apply equivalent safeguards when relevant laws (e.g., EU/UK GDPR) may apply. |
What Information We Collect
For the purpose of this summary, the definition of “personal information” means any information or opinion about a person where their identity is apparent or can reasonably be worked out – for example your a name, email address, recordings or chat logs tied to a user, or technical identifiers like IP addresses.
Required Information
- Student Users: First names only (or teacher-assigned nicknames)
- Teachers/Administrators: Full names, encrypted password, school email addresses, school/organisation name
Optional Information
- Content you upload and in-app activity (including assessment artifacts, chat logs).
- Account preferences and settings
- Communication through contact forms
- Payment/transaction data where relevant.
Technical Information
- IP addresses for security and session management
- Web logs and connection information to prevent misuse
- Cookies for website functionality
Age Restrictions
- Under 13: Must not use the platform
- If we become aware that under-13 data has been provided contrary to the Platform Access Conditions, we will take reasonable steps to delete it.
- Ages 13-17: Requires parental consent obtained by the registered school. This may include a general, standing or blanket consent.
We actively discourage inputting or uploading sensitive personal information. The platform includes 'best-effort filters' to reduce unnecessary personal data in chatlogs and uploads, but schools and users remain responsible for what they submit.
Why We Use Your Information
We use your information to:
- To provide and operate the SocraticXR platform and services.
- To verify access, manage accounts, process payments, and provide support.
- To maintain security, comply with law, and improve our services (including insights and reporting).
- To send essential service communications (you can opt out of marketing).
We will NOT:
- Use student data to train AI models
- Share your information for third-party marketing
- Sell your data to third parties
How AI Is Used
We use reputable AI providers to enable educational assessment and related features. Where we rely on OpenAI’s API, we have opted out of any use of personal data for model training. We send only the minimum necessary data to deliver the feature, and we do not send student identity information to OpenAI (eg. student names).
Sharing & Sub-processors
We may share personal information with:
- Sub-processors/Service providers who help us host and operate the platform:
- Vultr for hosting in Australia;
- OpenAI for AI processing;
- Storylane for product demos/marketing analytics).
- Professional advisers and parties required by law or in a business transaction.
- All providers are engaged under contractual safeguards and are required to handle data lawfully and securely.
Data Storage and Security
- Primary storage & Backups: Sydney, Australia (via Vultr servers)
- AI processing: Temporarily processed in the USA via OpenAI (no training on your data)
- When we transfer data overseas, we take reasonable steps to ensure protections equivalent to the Australian Privacy Principles (and, where applicable, GDPR mechanisms) are in place.
Security Measures
- Industry-standard encryption (in transit and at rest)
- Role-based access controls
- Regular security training for staff
- Annual security reviews and testing
By using our software, the registered school acknowledges and agrees to the processing of conversation and file data by OpenAI in the USA and accepts the associated risks as detailed in the Customer Agreement.
File Uploads
When you upload files:
- You retain ownership of your material
- We extract text from uploaded documents to enable educational discussions
- Our system automatically detects and blocks Personal information ('best-effort filters')
- While our platform attempts to filter personal information, it is not guaranteed. Schools are responsible for ensuring users do not upload sensitive or unnecessary personal information
- Schools remain responsible for training users on appropriate uploads and use
Data Retention
- We keep personal information only for as long as needed to provide services and meet legal obligations, then de-identify or delete it.
- You can request access, correction, or deletion (subject to legal allowances and operational feasibility).
- Sensitive information is deleted immediately if detected
Your Rights
Access and Correction
- Use the Teacher Dashboard to view and correct information
- Contact us for assistance with data requests
- We aim to respond to access or correction requests within 30 days, free of charge.
- Where it is lawful and practical, you may interact with us without identifying yourself (e.g., general enquiries).
Deletion
- Delete your own data through the platform
- Request deletion by contacting us
- Automatic deletion upon account termination
EU/UK individuals (GDPR / UK GDPR).
Registered accounts for our platform are currently only available to Australian schools and users.
If we become aware that you are a citizen of, or are located within, the European Economic Area or the United Kingdom at the time at which we collect Personal Data about you, or at the time at which we propose to transfer Personal Data about you overseas, we will take steps to ensure that we comply with Articles 45 to 49 of the EU GDPR or Articles 45 to 49 of the UK GDPR (as applicable), in relation to the transfer of your Personal Data overseas. However, you acknowledge that as we conduct our business from and predominantly within Australia, you are required to provide us with written notice of our need to comply with the EU GDPR or UK GDPR in relation to your Personal Data if you wish for us to take steps that are not already set out in this Privacy Notice.
Cookies and Tracking
We use cookies to:
- Remember your login and preferences
- Manage account creation
- Show relevant notifications
- Analyse website usage (via Google Analytics)
Third-party cookies may include:
- Google Analytics (anonymised usage data)
- Google AdSense (relevant advertising)
- Social media plugins (Facebook, Twitter, etc.)
- Storylane Analytics (Interactive demo hosting and analytics for marketing)
You can disable cookies in your browser, but some features may not work properly.
Marketing and Communications
- We may send service updates and educational content
- Marketing emails include easy unsubscribe options
- We don't use sensitive information for marketing
- Email vendors act only as data processors
Data Breaches
We use reasonable technical and organisational measures (e.g., encryption, access controls) to protect personal information. If a notifiable data breach occurs, we will act in line with the Notifiable Data Breaches scheme, including notifying affected individuals and the OAIC where required.
Changes to This Summary
We may update this summary and the full Privacy Notice from time to time. We will post updates on the platform/website, and continued use constitutes acceptance of the updated terms. Please review periodically.
Contact Us
Privacy Officer
AI & Assessment Solutions Pty Ltd
Email: privacy@socraticxr.com
For complaints: Contact us first, or lodge a complaint with the Office of the Australian Information Commissioner (www.oaic.gov.au)
Current Sub-processors
Sub-processor | Service | Location | Notes |
Vultr LLC | Primary Hosting | Sydney, Australia | Data encrypted at rest & transit |
OpenAI LLC | AI processing | USA | No model training on school data |
Storylane, Inc. | Interactive demo hosting and analytics for marketing | USA | Data is encrypted in transit and at rest; Uses cookies to track demo interactions; tracking can be paused until consent on sites that require it |
List updated: 12 September 2025
Summary
For the complete technical details, legal terms, and full text, please refer to our complete Privacy Notice accessible to download below: