Privacy Policy
At Square1 Ai (“Square1 Ai,” “we,” “our,” or “us”), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and protect your information. This Privacy Policy also reflects our commitment to transparency and compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA), the Children’s Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), India’s Digital Personal Data Protection Act, 2023 and DPDP Rules 2025 (DPDP Act), and Sri Lanka’s Personal Data Protection Act No. 9 of 2022 (PDPA).
By using or accessing Square1 Ai in any manner, you acknowledge that you accept the practices and policies described below, and you consent to the collection, use, and disclosure of your information as set forth in this Privacy Policy.
Your use of Square1 Ai’s Services is at all times subject to our Terms of Service, which incorporates this Privacy Policy. Any terms not defined here have the meanings given in the Terms.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting a notice on our website, sending you an email, or other appropriate means. Continued use of the Services after changes are posted constitutes acceptance of the revised Policy.
1. What This Policy Covers
This Policy covers how we treat both Personal Data and Operational Data collected when you install, access, or use Square1 Ai.
- Personal Data — Information that identifies or can be used to identify you, such as your name, email address, phone number, date of birth, school or institution name, and role (student, teacher, or parent).
- Operational Data — Technical information generated through your use of the platform, such as device type, browser version, IP address, session duration, and usage patterns.
2. Information We Collect
2.1 — Information You Provide
- Account Information: Name, email address, phone number, date of birth, school or institution name, and role (student, teacher, or parent).
- Profile Data: Profile photo, grade level, subjects of interest, and learning preferences.
- Payment Information: Billing name, address, and payment details processed securely via our third-party payment provider. We do not store complete payment card numbers.
- Communications: Feedback, support requests, waitlist submissions, and any messages you send through the platform.
2.2 — Information Collected Automatically
- Device & Browser Data: IP address, browser type and version, operating system, device identifiers, and screen resolution.
- Usage Data: Pages visited, features used, session duration, referral URLs, and clickstream data.
- Cookies & Similar Technologies: See Section 11 for details on cookies, pixels, and local storage.
2.3 — Information from Third Parties
- Single Sign-On Providers: If you sign in via Google or another SSO provider, we receive your name, email, and profile picture as permitted by your account settings.
- Educational Institutions: Schools or districts may share student roster data with us to provision accounts under a data processing agreement.
3. How We Use Your Information
We use the data we collect to:
- Provide, operate, and maintain our AI-enhanced learning platform.
- Personalise your learning experience, including adaptive content recommendations.
- Process transactions and manage your account.
- Communicate with you about updates, security alerts, and support.
- Analyse usage trends to improve our services and develop new features.
- Comply with legal obligations and enforce our Terms of Use.
- Detect, prevent, and address fraud, abuse, or security incidents.
- Manage waitlist registrations and send related notifications.
4. Legal Basis for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases. Where India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies, consent is required for processing of Indian users, and we do not rely on “legitimate interest” as a legal basis under the DPDP Act.
- Consent — Marketing communications, non-essential cookies, and waitlist sign-ups.
- Contract — Account creation, service delivery, and payment processing.
- Legitimate Interest — Analytics, product improvement, fraud prevention, and security (not relied upon for Indian users under the DPDP Act).
- Legal Obligation — Tax compliance, responding to lawful requests, and regulatory reporting.
5. Sharing & Disclosure
We do not sell your personal data. We may share information with the following categories of recipients:
- Service Providers: Hosting, analytics, payment processing, email delivery, and customer support vendors operating under data processing agreements.
- Educational Institutions: Progress reports and usage data shared with schools or districts under FERPA-compliant agreements.
- Legal & Safety: When required by law, regulation, or legal process, or to protect the rights, safety, or property of Square1 Ai, our users, or the public.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.
6. Data Retention
We retain personal data only as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
- Active Accounts: Data is retained for the duration of the account’s active use, plus a reasonable wind-down period.
- Inactive Accounts: Accounts inactive for 24 months may be anonymised or deleted after notice.
- Legal Holds: Certain data may be retained longer when required for legal proceedings or regulatory audits.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Under GDPR (EU/EEA/UK)
- Access — Request a copy of your personal data.
- Rectification — Correct inaccurate or incomplete data.
- Erasure — Request deletion of your data (“Right to be Forgotten”).
- Restriction — Limit processing in certain circumstances.
- Data Portability — Receive your data in a structured, machine-readable format.
- Objection — Object to processing based on legitimate interests.
- Withdraw Consent — Where processing relies on consent, withdraw at any time.
Under CCPA / CPRA (California)
- Right to Know — Categories and specific pieces of personal information collected.
- Right to Delete — Request deletion of personal information.
- Right to Opt-Out — Opt out of the sale or sharing of personal information.
- Right to Non-Discrimination — Equal service and pricing regardless of exercising privacy rights.
- Right to Correct — Request correction of inaccurate personal information.
Under Sri Lanka PDPA
- Access, rectification, erasure, and restriction of processing rights as provided under the Personal Data Protection Act No. 9 of 2022.
- Right to lodge a complaint with the Data Protection Authority of Sri Lanka.
Under India DPDP Act (2023)
- Right to confirmation and access — Request confirmation of whether we process your personal data, and request a summary of the personal data and processing activities (including identities of data fiduciaries and data processors with whom data has been shared), where required by the DPDP Rules. Response within 90 days where required.
- Right to correction — Request correction of inaccurate or incomplete personal data.
- Right to erasure — Request deletion of personal data, where applicable under the DPDP Act.
- Right to grievance redressal — Submit grievances to us for handling and resolution. Our Grievance Officer will acknowledge and resolve your grievance within 7 working days; if you are unsatisfied with the resolution, you may escalate your complaint to the Data Protection Board of India.
- Right to nomination — Nominate a person to exercise specified rights on your behalf, where applicable under the DPDP Act.
- Right to withdraw consent — Where processing relies on consent, withdraw consent at any time (subject to applicable law).
To exercise any of these rights, please contact us at privacy@square1ai.com. We will respond within 30 days (or within other timeframes required by applicable law).
8. Children's Privacy (COPPA)
We take children’s privacy seriously. In compliance with COPPA, we do not knowingly collect personal information from children under the age of 13 without verifiable parental consent.
- Where a child’s school has consented on behalf of a parent as a COPPA-permitted “school official,” data will be used solely for educational purposes.
- Parents or guardians may review, request deletion of, or refuse further collection of their child’s data by contacting us.
- We do not serve targeted advertising to children under 13.
Under India DPDP Act (Children Under 18)
- For Indian users under 18, a “child” is defined as any individual under the age of 18, and verifiable parental consent is mandatory before any processing of personal data.
- Parental consent may be verified through government-authorised mechanisms including DigiLocker virtual tokens and Aadhaar-based OTP verification (or other methods prescribed by the Data Protection Board of India).
- Tracking and behavioural monitoring of children is prohibited (except where strictly necessary for educational purposes and child safety).
- Targeted advertising directed at children is categorically banned, and our AI personalisation for Indian users under 18 is designed to use session-based, non-longitudinal methods that do not constitute “tracking or behavioural monitoring.”
9. Student Data & FERPA
When we process student education records on behalf of an educational institution, we act as a “school official” under FERPA. In this capacity:
- We use student education records solely for the educational purposes defined in our agreement with the institution.
- We do not disclose student education records to third parties except as permitted under FERPA or directed by the institution.
- We maintain reasonable security measures to protect student records from unauthorised access.
- Parents and eligible students may direct rights requests to their educational institution.
10. International Data Transfers
Square1 Ai is based in Sri Lanka and our servers may be located in different jurisdictions. When we transfer personal data across borders, we ensure adequate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions where applicable.
- Binding corporate rules or equivalent protections under the Sri Lanka PDPA.
- Where India’s DPDP Act applies, international transfers are made only where permitted under the DPDP Act and supported by appropriate safeguards, including using the DPDP “blacklist model” (i.e., transfers are made only to jurisdictions not identified as restricted/blacklisted by the Data Protection Board of India). For clarity, Sri Lanka is not treated as a restricted/blacklisted jurisdiction under this model.
11. Cookies & Tracking Technologies
We use cookies and similar technologies for the following purposes:
- Essential Cookies: Enable core functionality such as authentication and security.
- Analytics Cookies: Help us understand how visitors interact with our platform (e.g., Google Analytics).
- Preference Cookies: Remember your settings, language, and display preferences.
You can manage your cookie preferences through our consent management tool (powered by Cookiebot) displayed upon your first visit. You may also adjust cookie settings in your browser at any time.
12. Data Security
We implement industry-standard technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Regular vulnerability assessments and penetration testing.
- Role-based access controls and multi-factor authentication for internal systems.
- Incident response procedures, including India’s DPDP breach-notification approach: CERT-In notification within 6 hours of detection of a cyber security incident, Data Protection Board of India (DPBI) notification without delay, and a detailed follow-up report within 72 hours. The report includes the nature and extent of the breach, likely impact, root cause analysis, mitigation measures, and a summary of individual notifications. Affected users will be notified without applying a materiality threshold (and for breaches affecting Indian users under 18, parents/guardians will also be notified directly).
While no system is 100% secure, we continuously review and improve our security practices.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Posting the revised policy on this page with an updated “Last Updated” date.
- Sending an email notification to registered users when required by law.
- Displaying an in-app notification for significant changes.
Continued use of our platform after any modification constitutes your acceptance of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
For EU/EEA residents, you also have the right to lodge a complaint with your local Data Protection Authority. For Sri Lankan residents, complaints may be directed to the Data Protection Authority of Sri Lanka.
For India’s DPDP Act (2023), you may submit grievances and data requests to our Grievance Officer at grievance.india@square1ai.com. The Grievance Officer will acknowledge and resolve your grievance within 7 working days; if you are unsatisfied with the resolution, you may escalate your complaint to the Data Protection Board of India.
DPDP Act penalty warning: non-compliance may lead to penalties under the DPDP Act, including up to ₹200 crore for breach-notification failures and children’s data violations, and up to ₹250 crore for security failures. Repeated penalty instances may result in the Data Protection Board of India directing blocking of access to our services in India.
This Privacy Policy is compliant with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA), the Children’s Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), and Sri Lanka’s Personal Data Protection Act No. 9 of 2022 (PDPA), and India’s Digital Personal Data Protection Act, 2023 and DPDP Rules 2025 (DPDP Act).
Last updated: March 20, 2026