Privacy Policy

Who is responsible for your data

  • Registered name: DIALOGIA LABS S.L.
  • Tax ID (CIF): B88834601
  • Product: Dialogia (Dialogia Classroom and Dialogia Questions)
  • Contact: hello@dialogia.org

Dialogia is not always responsible for the same thing

Who decides what your data is used for — and so who you need to complain to — depends on how you came to Dialogia. There are two situations, and it's worth telling them apart because they change who you turn to:

  • If your account was given to you by an institution, the institution is the data controller: it decides what courses exist, which students join and what the platform is used for. Dialogia acts as data processor and handles that data only under its instructions, under Article 28 GDPR. The contract that formalizes this is the data-processing annex to our Contracting Terms.
  • If you signed yourself up, on your own, Dialogia is the data controller for your account data. And if you also bring in students —adults only: minors require an institution—, you are responsible for the data of those students, as a professional educator or organization, and Dialogia processes it on your behalf under the same processing-agreement annex from our Contracting Terms.
  • On the public website at dialogia.org — the contact form, the demo request, visit analytics — the controller is always Dialogia.

Students under 18 are always under an institution. A course with underage students requires an institution, and institutions are only created through the institutional contracting process — there is no self-service way to have minors on the platform. A student does not sign up on their own in Dialogia: they get in because their institution or teacher has added them to a class, and that institution or teacher is responsible for their data, never Dialogia on its own.

Data Protection Officer

[APPOINT DPO] — Dialogia is working out whether it needs to appoint a Data Protection Officer under Article 37 GDPR. Until that question is settled, any data protection query is handled at hello@dialogia.org. If your account depends on an institution, the institution has its own Data Protection Officer, and is the natural point of contact for you.

Data We Collect

From Educators

  • Email address (for account creation and authentication)
  • Knowledge pills extracted from uploaded course materials. In Dialogia Questions the original file is deleted after extraction; in Dialogia Classroom it is kept, because teachers can download it again and retry the extraction
  • Course configuration and settings

From Students

  • In Questions: the questions asked to the AI system, with no account and no name
  • In Classroom: the account (name and email), the submitted work, the conversation with the AI and its assessment

Technical Data

  • Usage logs and analytics data
  • Browser information and IP addresses
  • Cookies and similar tracking technologies

Use of AI Services

Dialogia uses governed AI services to generate educational content (pills) and respond to student queries. Please note that:

  • In Dialogia Questions, the documents you upload are processed and the original is deleted from our servers as soon as extraction succeeds. In Dialogia Classroom, the original remains stored after extraction
  • The extracted knowledge pills (summaries and key information) are retained for educational purposes
  • Course content is shared with Scaleway, our artificial intelligence provider, only during the processing needed to generate educational pills
  • Student questions and relevant course content may be shared with Scaleway to provide AI-powered responses
  • Scaleway processes this data under its own privacy policy, within the European Union, and states that it does not train its models on it
  • What actually reaches our AI service provider (Scaleway): we do not send it any account identifier, or anyone's name or email — the instructions that go with each query do not contain them. What does travel is the text the person writes, exactly as they write it, together with the course material: if someone writes their name inside an answer, that name travels with it. Saying it this way is more accurate than promising that no personal data ever leaves.

Students in Questions: no account

This section describes Questions, where students have no account. Classroom works the other way round and is explained right after: there is an account there, with a name and an email address.

Students use Dialogia with no need for an account. We never ask for a name, an email address or a password, and no account is created. This section details exactly what trace a student's activity leaves — and calls it by its technical name: it is a pseudonymized record, not an anonymous one.

What we store

  • An identifier generated by the student's own browser: It keeps a single conversation coherent, and it persists between sessions in that browser. Educators see it next to the questions, so they can group several as coming from the same browser — but not tell whose
  • The question asked and the answer given
  • The class: The class the question was asked in
  • The date and time of the interaction

What we do not store

  • No name, no email address, no account — no named record of the student
  • No IP address attached to a question. Our technical logs are separate and are not linked back to what a student asked
  • Nothing that lets us, or the educator, put a name to whoever asked

Why we record the time

  • To reconstruct the conversation: The AI needs the order of the messages to answer coherently
  • To give the educator classroom analytics: The pulse of a session, never individual surveillance

Speaking precisely: pseudonymized, not anonymous

We prefer to use the exact term from GDPR (Article 4(5)): these records are pseudonymized. "Anonymous" would mean that no one, by any reasonable means, can ever link them back to a person again — and that is not entirely true here, because the identifier your browser stores lets us locate your records if you provide it yourself (that is how we handle deletion requests). What is true, and what matters, is this: that identifier carries no name, neither we nor the educator can turn it into a person, and the aggregated statistics we keep —counts and topics, built only from groups of five people or more, with no text and no identifiers— are anonymous in the strict sense.

Students in Classroom: with an account

Classroom works the other way round from Questions: getting in requires an account. The institution registers each student, and that account carries a name, an email address and a password. There is no anonymity here, and none is claimed: educators mark work and need to know whose it is.

What we store

  • The account: name, email address and password. The password is stored using a key-derivation function — it is not reversible encryption: not even we can read it — and never in plain text
  • The submitted work: the text of each submission and any files uploaded
  • The conversation with the AI: the messages exchanged while doing the activity
  • The assessment: the appraisal the AI produces and the mark derived from it
  • AI usage: how many requests were made and their cost, to keep spending under control

For how long

  • All of that is kept for a maximum of 48 months, the same window as questions in Questions. After that it is deleted, files included.
  • An educator deleting a course or an activity does not erase the student's work: it stops being visible and keeps running the same 48-month clock.
  • What we keep indefinitely are aggregate statistics on the quality of AI use, containing no text and no personal identifier.

Students under 18

Dialogia is used in secondary education and vocational training, so a large share of its students are under 18. This section explains what we do differently and, above all, what we do not do.

We do not ask anyone's age

Dialogia does not collect any student's date of birth or age, and has no way of knowing whether a given person is a minor. This is a deliberate choice: asking for someone's age would mean collecting one more personal data point from an especially protected group, and the only thing it would do is trigger protections we prefer to apply a different way.

That other way is the course's educational stage, which the institution or the teacher declares when they create it. If the course is secondary education or vocational training, the protections apply to the whole course, without singling anyone out. A nineteen-year-old repeating their final year of upper-secondary school gets the same protective treatment as their seventeen-year-old classmates, and that is exactly what we want: protection does not depend on getting anyone's age right.

Who authorizes the use

Article 8 GDPR and Article 7 of Ley Orgánica 3/2018, Spain's data protection act, set the age from which a minor can consent by themselves to the processing of their data in information-society services — currently fourteen in Spain, with a reform under way to raise it.

That age does not apply to Dialogia, because the processing of student data does not rely on the minor's consent. It relies on the relationship between students and their institution: it is the institution that decides to bring Dialogia into its teaching activity, that determines the legal basis that applies — normally the performance of a public-interest task or the execution of the educational relationship — and that informs families. Dialogia processes that data on the institution's behalf and does not ask any student for consent.

What changes in a course with students under 18

  • Internet access starts turned off. The assistant does not search the web or open links unless a teacher deliberately turns it on for a specific activity.
  • Data is deleted at the end of the school year, not after 48 months: submissions, conversations with the AI, logged questions and files are removed at the annual close. We notify the institution 30 days beforehand, and again 7 days beforehand, so it can download whatever it wants to keep.
  • The assistant carries additional wellbeing and conduct instructions, so it knows what to do when a conversation stops being academic: it does not stand in for an adult, it does not give clinical advice, and it refers the matter to whoever should handle it.
  • There is no advertising, no data is sold, and no commercial profile is built. Never, at any stage, but it's worth stating explicitly here.
  • No decision with legal or similarly significant effects is made in an automated way. The assessment the AI generates is a proposal addressed to the teacher, who reviews it and decides; the grade is always theirs.

Identity in Questions doesn't exist, and an alert doesn't reconstruct it

In Dialogia Questions students have no account and we do not know who anyone is. When the system detects signs in a question that someone may be struggling, it alerts the teacher that something has happened in that class — never who wrote it, because we do not know and we are not going to find out. The alert exists so that an adult pays attention to the group, not to single out a person.

If you are a parent or legal guardian and want to know what Dialogia holds about your child's activity, the way to do it is through the institution: it is the data controller and the one able to identify the person. We will give it all the support it needs to answer you. And if you would rather read a short, plain-language explanation, it is here: Dialogia, plainly explained.

Purpose of Processing

We process your data for the following purposes:

  • Educational services: To provide AI-powered educational tools and content generation
  • Platform functionality: To enable course creation, management, and student interaction
  • Research and improvement: To improve our educational tools, using only aggregated, anonymous statistics (counts and topics with a five-person threshold, with no text and no identifiers). Individual student data is not used for this purpose: it is processed only on the controller's behalf, as part of the service
  • Communication: To send important updates about your account and our services
  • Legal compliance: To meet our legal obligations and protect our legitimate interests

Legal Basis for Processing

  • Contract performance: Processing necessary to provide our educational services
  • Legitimate interest: For business operations, platform security, and product improvement based on aggregated, anonymous statistics. Legitimate interest is not used as a basis for processing individual student data
  • Consent: Where you have explicitly agreed to specific processing activities
  • Legal obligation: Where required by applicable law

Who we share data with

We do not sell personal data to anyone, or hand it over for advertising purposes. What we do is rely on a short list of providers to keep the platform running. When Dialogia acts as data processor for an institution, these providers are sub-processors and work under the same obligations we take on ourselves.

This is the complete list, by name. If we ever add or change one, you will see it here:

  • Scaleway S.A.S. (France) — AI models, storage of uploaded documents, email delivery and hosting. It is the provider that receives the text of queries and course material. It processes data within the European Union.
  • Clouding.io (Spain) — hosting, as an alternative or complement to the above. European Union.
  • AlphaAI Technologies Inc., operating as Tavily (United States) — web search and reading links, only when a teacher has turned on internet access for an activity. It is the only transfer outside the European Economic Area within the product, and it is detailed in the international transfers section.
  • Getnet (Spain) — payment gateway. It processes no data today: card payment is not built yet, and until it is, no information reaches it. We list it now so that nobody finds out through a silent change on the day it goes live.
  • Plausible Insights OÜ (Estonia, with servers in Germany) — analytics for visits to the public website dialogia.org. It uses no cookies and tracks no one across sites. It plays no part in the product, so no student data ever passes through it.
  • Google — only to show the thumbnail of a video embedded in the public website, and only after the visitor expressly accepts it. If they do not accept it, nothing is requested from Google.

The public website also contains a link to book a demo with Calendly. It is not on the list because it is not a sub-processor: it is a link the visitor chooses to click, it loads nothing on our pages, and if you book there it is Calendly that processes your data directly, under its own policy. The cookie policy describes it.

In addition, we may disclose data to public authorities when a law requires us to, or to defend our own rights or those of others before a court.

If this list changes

When Dialogia acts as processor for an institution, we will notify the institution at least 30 days in advance of adding or replacing any sub-processor, so it can object on reasonable grounds before the change takes effect. If it objects and we cannot find an alternative acceptable to both parties, the institution may terminate the contract without penalty.

The technical detail of what goes out, where to and under what condition is kept up to date in an internal inventory we hand over to any institution that asks for it: it is the document a Data Protection Officer needs for their record of processing activities.

Data Retention

In courses with students under 18, the general period below does not apply: it is the school year. At the annual close — 31 August, unless the institution sets a different date — submissions, conversations with the AI, logged questions, wellbeing alerts and files for that course are deleted. The periods that follow apply to courses for adults, and to anything that does not depend on a specific course.

  • Educator account data: Until account deletion or 30 days after unsubscription
  • Original course files: In Dialogia Questions, they are deleted as soon as they are processed into knowledge pills. In Dialogia Classroom, they are kept for as long as the course exists; when the course is deleted, they go at the next retention purge (end of the school year for courses with students under 18, 48 months otherwise).
  • Knowledge pills: Deleted when the educator removes them or deletes their account
  • Student questions (pseudonymized): The record of each question —linked to a browser identifier, never to a name— is kept as part of the service (the course history and the educator's classroom analytics) for a maximum of 48 months; in courses with students under 18, only until the school year ends. After that period it is deleted. What we keep indefinitely are aggregated statistics drawn from those records (volumes by class and month, and recurring topics), which include neither the text of any question nor any identifier. Deleting a course hides its classes, but does not erase questions already asked within that period
  • Chat conversation memory: Deleted after 7 days. Only the last 24 hours are ever used to answer a student
  • Student work in Classroom: Submissions, AI conversations, assessments and files are kept for a maximum of 48 months. An educator deleting a course or an activity does not erase them: they stop being visible and keep running the same clock
  • Usage analytics: Retained in aggregated form for platform improvement

Your Rights

Under GDPR and applicable data protection laws, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a structured format
  • Object: Object to processing based on legitimate interests
  • Withdraw consent: Where processing is based on consent

How to exercise them

  • In Classroom, through your institution. The institution decides what the data is used for; Dialogia processes it on their behalf. Requests are therefore handled through them. If you write to us directly, we will put you in touch with the right people.
  • In Questions there is nobody to identify. We ask for no name, no email and no account, so we cannot tell which of the stored questions are yours. The regulation covers this case and does not require us to collect extra data just to be able to identify you. We can locate and delete them if you give us the identifier your own browser stored.
  • Response time: one month from the request, extendable by two further months if it is particularly complex, telling you beforehand.
  • Without a request the general period applies: data is kept for a maximum of 48 months and deleted after that anyway.

What survives an erasure

The aggregate statistics. Once aggregated, the data no longer shows who did what: they are counts and topics built from the activity of many people, with no text and no identifiers. Data protection law expressly allows keeping information for statistical and research purposes, which is why those statistics are neither deleted nor able to be linked back to a person.

Filing a complaint with the supervisory authority

If you believe we have not handled your request properly, or that the processing of your data does not comply with the law, you can file a complaint with the Agencia Española de Protección de Datos (the Spanish data protection authority) (C/ Jorge Juan 6, 28001 Madrid — www.aepd.es). You do not need to complain to us first, although we appreciate the chance to resolve it beforehand. If the controller is your institution and it belongs to an autonomous community with its own authority — Catalonia, the Basque Country or Andalusia — the complaint may fall to that authority instead.

Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. This includes encryption, access controls, and regular security assessments.

International Transfers

Almost all processing takes place within the European Union: the AI models, document storage, email delivery, hosting and website analytics. There is a single outflow outside the European Economic Area within the product, and we describe it in full because claiming nothing goes out would be false.

What goes out, and when

That outflow is the provider the assistant uses to query the internet, Tavily (AlphaAI Technologies Inc., United States). It is sent one of these two things, and nothing else:

  • A search string drafted by the AI model itself, when it decides it needs current information. It is not the student's message as such, but it draws on the conversation and may contain recognizable fragments of what was written. We would rather say it this way than call it a fully de-linked piece of data.
  • A link's address, exactly as it was pasted, when someone pastes a link and asks for it to be discussed. The address of an article or a news item is not personal data; a link address used to share a private document can carry it inside, and in that case the content of that link would be downloaded from the United States.

The person's identifier, name, email or any account data is never transferred. The identifier is used only within our own systems, to attribute the cost of the query, and never enters the request.

Who controls whether it happens

  • Internet access is turned on activity by activity, and a teacher decides it. Without that, nothing is searched and no links are read.
  • In courses with students under 18 that switch starts off. A minor only reaches this outflow if their teacher has deliberately turned it on for a specific activity.
  • Dialogia Questions —the chat with no account— does not use this provider at all. Nothing leaves the European Union from the product with no named identification.

Under what safeguards

The provider states SOC 2 Type II and ISO/IEC 27001:2022 certification, and uses the European Commission's standard contractual clauses with its own providers. [LAWYER REVIEW] — the data-processing agreement with this provider has been requested and is pending signature; until it is signed, the safeguards described are its public policy, not a contractual obligation to Dialogia. This paragraph will be updated once the agreement is closed.

Updates to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes through email or platform notifications.

Contact Us

For any questions about this privacy policy or to exercise your rights, contact the Dialogia team at hello@dialogia.org.

Last updated: 23 August 2026.