Privacy Policy

Last Updated: January 2025

At Curricuflow.ai, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our curriculum management platform.

1. Information We Collect

1.1 Information You Provide

We collect information that you voluntarily provide when using our Service:

  • Account Information: Name, email address, organization name, department, and password
  • Curriculum Data: Course information, learning outcomes, syllabi, assessment data, program information, and other educational content you upload or create
  • Profile Information: Job title, role within your institution, and other optional profile details
  • Communication Data: Messages, feedback, and support requests you send to us
  • Payment Information: Billing details processed securely through our payment processor (Stripe)

1.2 Information Collected Automatically

When you access our Service, we automatically collect certain information:

  • Usage Data: Pages visited, features used, time spent, and interaction patterns
  • Device Information: IP address, browser type, operating system, device identifiers
  • Log Data: Access times, error logs, and system activity
  • Cookies and Similar Technologies: Session cookies, preference cookies, and analytics cookies (see Section 8)

1.3 Information from Third Parties

We may receive information from:

  • Authentication Providers: If you sign in using third-party services (e.g., Google, Microsoft), we receive basic profile information
  • Payment Processors: Stripe provides transaction and payment status information
  • Analytics Services: Google Analytics and similar tools provide aggregated usage statistics

2. How We Use Your Information

We use collected information for the following purposes:

2.1 Service Delivery

  • Provide, operate, and maintain the curriculum mapping platform
  • Process your curriculum data and generate reports
  • Enable collaboration features between team members
  • Provide AI-powered features like syllabus analysis and outcome extraction

2.2 Account Management

  • Create and manage your account
  • Process subscriptions and payments
  • Send account-related notifications and updates
  • Verify your identity and prevent unauthorized access

2.3 Communication

  • Respond to your inquiries and support requests
  • Send important service announcements and updates
  • Provide educational content and best practices (with your consent)
  • Send marketing communications (you may opt out at any time)

2.4 Improvement and Analytics

  • Analyze usage patterns to improve our Service
  • Develop new features and functionality
  • Monitor and analyze trends, usage, and activities
  • Detect, prevent, and address technical issues and security threats

2.5 Legal Compliance

  • Comply with applicable laws and regulations
  • Respond to legal requests and prevent fraud
  • Enforce our Terms of Service
  • Protect our rights, privacy, safety, or property

3. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

3.1 Within Your Organization

Curriculum data and account information are shared with team members within your organization according to the access permissions you configure.

3.2 Service Providers

We share information with trusted third-party service providers who assist us in operating our Service:

  • Hosting and Infrastructure: Amazon Web Services (AWS) for data storage and hosting
  • Payment Processing: Stripe for subscription billing and payment processing
  • Email Services: Email service providers for transactional and marketing emails
  • Analytics: Google Analytics for usage analytics (anonymized data)
  • AI Services: OpenAI for AI-powered features like syllabus extraction

These service providers are contractually obligated to protect your data and use it only for the purposes we specify.

3.3 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal processes (subpoenas, court orders)
  • Government or regulatory requests
  • Protection of rights, property, or safety of Curricuflow, users, or the public
  • Prevention of fraud, security threats, or illegal activity

3.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change and provide options regarding your data.

3.5 With Your Consent

We may share your information for any other purpose with your explicit consent.

4. Data Security

We implement industry-standard security measures to protect your information:

4.1 Technical Safeguards

  • Encryption: Data is encrypted in transit (TLS/SSL) and at rest (AES-256)
  • Access Controls: Role-based access controls and multi-factor authentication options
  • Secure Infrastructure: Hosting on secure AWS infrastructure with regular security updates
  • Monitoring: Continuous monitoring for security threats and vulnerabilities
  • Backups: Regular automated backups to prevent data loss

4.2 Organizational Safeguards

  • Limited employee access to personal data on a need-to-know basis
  • Regular security training for staff
  • Incident response procedures for data breaches
  • Regular security audits and vulnerability assessments

4.3 Your Responsibility

While we implement strong security measures, you are responsible for:

  • Maintaining the confidentiality of your account credentials
  • Using strong, unique passwords
  • Enabling multi-factor authentication when available
  • Reporting any suspected unauthorized access immediately

Important: No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

5. Data Retention

We retain your information for as long as necessary to provide our Service and fulfill the purposes outlined in this Privacy Policy:

  • Active Accounts: We retain your data while your account is active and you use our Service
  • Deleted Accounts: After account deletion, we retain your data for 30 days to allow for account recovery, then permanently delete it
  • Legal Requirements: Some data may be retained longer if required by law or for legitimate business purposes (e.g., billing records, audit logs)
  • Anonymized Data: We may retain anonymized usage data indefinitely for analytics and product improvement

You may request deletion of your data at any time by contacting us at hello@curricuflow.ai.

6. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

6.1 Access and Portability

  • Right to Access: Request a copy of the personal information we hold about you
  • Data Portability: Export your curriculum data in standard formats (CSV, JSON)

6.2 Correction and Deletion

  • Right to Correct: Update or correct inaccurate personal information
  • Right to Delete: Request deletion of your personal information (subject to legal obligations)

6.3 Control and Objection

  • Right to Object: Object to certain processing activities (e.g., marketing communications)
  • Right to Restrict: Request limitation of processing in certain circumstances
  • Right to Withdraw Consent: Withdraw consent for data processing where consent was the legal basis

6.4 How to Exercise Your Rights

To exercise any of these rights, contact us at hello@curricuflow.ai. We will respond to your request within 30 days. You may also:

  • Update your account information directly in your account settings
  • Export your data using our built-in export features
  • Opt out of marketing emails using the unsubscribe link in any email
  • Delete your account from your account settings

7. International Data Transfers

Our Service is operated from Canada, and your information may be transferred to and stored in Canada or other countries where our service providers operate.

If you are located in the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, please note that your information may be transferred to countries that may not have the same data protection laws as your jurisdiction. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

8. Cookies and Tracking Technologies

8.1 Types of Cookies We Use

  • Essential Cookies: Required for the Service to function (e.g., authentication, security)
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Help us understand how users interact with our Service (Google Analytics)
  • Marketing Cookies: Track conversions and ad performance (if applicable)

8.2 Managing Cookies

You can control cookies through your browser settings. Note that disabling essential cookies may affect the functionality of our Service. Most browsers allow you to:

  • View and delete existing cookies
  • Block third-party cookies
  • Block all cookies
  • Delete cookies when you close your browser

8.3 Third-Party Analytics

We use Google Analytics to analyze usage of our Service. Google Analytics uses cookies to collect information about your use of the Service. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

9. Children's Privacy

Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@curricuflow.ai, and we will delete such information.

10. Educational Data and FERPA Compliance

We understand the sensitive nature of educational data. While Curricuflow is designed for institutional use by faculty and administrators (not students), we recognize that curriculum data may be considered educational records under FERPA (Family Educational Rights and Privacy Act) in certain contexts.

  • We act as a service provider under the direction of educational institutions
  • We do not use curriculum or assessment data for any purpose other than providing the Service
  • We do not disclose educational data to third parties except as directed by you or required by law
  • Institutions maintain control over their curriculum data and can export or delete it at any time

11. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

11.1 California Rights

  • Right to Know: Request information about the personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the "sale" of personal information (Note: We do not sell personal information)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

11.2 Information We Collect (CCPA Categories)

  • Identifiers: Name, email address, IP address
  • Commercial Information: Subscription and payment history
  • Internet Activity: Usage data, interaction with our Service
  • Professional Information: Job title, organization, department
  • Education Information: Curriculum data, course information (as provided by you)

11.3 How to Exercise California Rights

To exercise your California privacy rights, email us at hello@curricuflow.ai with "California Privacy Request" in the subject line. We will verify your identity and respond within 45 days.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email or through a prominent notice in the Service
  • Provide at least 30 days' notice before the changes take effect

Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: hello@curricuflow.ai

Subject Line: Privacy Inquiry

Mailing Address:
Curricuflow.ai
Suite 220, 162-2025 Corydon Avenue
Winnipeg, MB R3P 0N5
Canada

We will respond to your inquiry within 30 days.


By using Curricuflow.ai, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.