Introduction
Euclido Inc. (“we,” “our,” “us”) is committed to ensuring the privacy and protection of data collected through our platform, Euclido Assist (“Euclido Assist,” “platform,” “product”). This document outlines how data is collected, used, stored, processed, and shared in connection with Euclido Assist, an enterprise AI agent embedded on university or institute websites. Euclido Assist interacts with end-users (students, applicants, faculty, etc.) on behalf of our customers (universities and institutions) to provide a virtual campus assistant experience. We employ third-party APIs and open-source models to enhance the capabilities of our product, subject to the customer's preferences.
This Data Policy is intended to inform our customers and users about our practices and to help customers ensure that their use of Euclido Assist complies with relevant laws and regulations. This policy forms part of the agreement between Euclido Inc. and our customers. By implementing Euclido Assist, customers agree to adhere to this Data Policy.
Definitions
- Customer: A university, institute, or other educational organization that purchases, implements, and administers Euclido Assist on their website.
- User: Any individual (including, but not limited to, students, applicants, faculty members, or visitors) who interacts with Euclido Assist on a customera's website.
- Personal Data: Any information related to an identified or identifiable natural person, as defined under applicable data protection laws, including but not limited to names, contact details, academic records, and other sensitive information.
- Anonymized Data: Data that has been processed in such a way that the data subject can no longer be identified, whether directly or indirectly.
- Third-Party APIs/Models: External services, including those provided by OpenAI, Llama, or other entities, that may be used to enhance the functionalities of Euclido Assist.
Data Collection
- User Interactions: Euclido Assist collects data from users during their interactions with the platform. This data may include, but is not limited to:
- Input Data: Text, queries, and commands inserted by the user.
- Behavioural Data: Information on how users interact with the AI agent, including session duration, pages visited, and features used.
- Device Data: Information about the user's device, including IP address, browser type, operating system, and cookie identifiers.
- Automatic Data Collection: We may automatically collect data through cookies, web beacons, and similar technologies to enhance user experience and track usage patterns. The types of automatically collected data may include:
- Usage Data: Information on how users interact with the customer’s website while Euclido Assist is active.
- Technical Data: Information on the performance of the AI agent, error logs, and other diagnostic data.
- Data from Third-Party Sources: Customers may opt to integrate third-party services with Euclido Assist, allowing the platform to access additional data from these services. The collection and use of such data will be governed by the data policies of the respective third-party providers.
Log Data
Euclido Inc. collects and processes log data generated by Euclido Assist and the underlying systems to ensure the platform's stability, security, and performance. Log data may include:
- System Logs: Information about the operation of the system, including start-up and shut-down logs, errors, warnings, and performance metrics.
- Access Logs: Records of who accessed the system and when, including user identification (if applicable), IP addresses, and timestamps.
- Application Logs: Logs from the Euclido Assist application, capturing user interactions, API requests, and other events that occur during normal operation.
4.1 Use of Log Data
- Monitoring and Maintenance: Log data is used to monitor the health of the system, diagnose issues, and perform routine maintenance.
- Security: Log data is essential for detecting and responding to security incidents, such as unauthorized access or potential breaches.
- Compliance: Logs may be retained to comply with legal obligations or to provide evidence in case of disputes.
4.2 Log Data Retention
Log data is retained for a period necessary to fulfil the purposes outlined above, typically not exceeding 12 months, unless longer retention is required for legal or operational reasons.
Use of Data
- Provision of Services: The primary use of the collected data is to provide, maintain, and improve the functionalities of Euclido Assist. This includes:
- Responding to user queries and commands.
- Enhancing the accuracy and efficiency of the AI agent through machine learning.
- Customizing the user experience based on past interactions.
- Analytics and Insights: Euclido Inc. will use collected data to generate analytics and insights for customers. These insights may include:
- Usage statistics (e.g., number of interactions, common queries).
- Performance metrics (e.g., response times, accuracy rates).
- User engagement trends (e.g., peak usage times, popular features).
- Anonymized Data Use: We may anonymize personal data to create aggregated datasets for research, statistical analysis, and product development. Anonymized data cannot be used to identify individual users and may be shared with third parties.
- Sharing with Third Parties: Euclido Assist may utilize third-party APIs and open-source models to enhance its capabilities. When data is shared with these third parties, it will be done with strict adherence to anonymity and confidentiality. The data shared with third-party services will be anonymized wherever possible, ensuring that no personal data is disclosed.
Data Sharing
- Sharing with Customers: Data collected through Euclido Assist will be shared with the respective customer via an admin panel and analytics dashboard. Customers will have access to detailed reports and real-time data on how users interact with the AI agent.
- Sharing with Third Parties: Euclido Inc. may share anonymized data with third-party service providers to enhance the performance of Euclido Assist. This sharing is subject to the following conditions:
- Contractual Obligations: We will ensure that third parties are contractually bound to use the data only for the purposes of providing their services to Euclido Inc. and the customer.
- Data Anonymization: Personal data will be anonymized to the greatest extent possible before being shared with third parties.
- Compliance with Laws: We will comply with all applicable data protection laws when sharing data with third parties.
- Legal Requirements: We may disclose data if required by law or in response to valid requests by public authorities (e.g., a court or a government agency).
Data Security
- Security Measures: Euclido Inc. implements a range of security measures to protect data from unauthorized access, disclosure, alteration, or destruction. These measures include, but are not limited to:
- Encryption: Data in transit and at rest is encrypted using industry-standard protocols.
- Access Controls: Access to data is restricted to authorized personnel only, and all access is logged and monitored.
- Regular Audits: Security practices are regularly audited to ensure compliance with industry standards.
- Customer Responsibilities: While Euclido Inc. takes extensive measures to protect data, customers are responsible for ensuring the security of the data within their own systems, including maintaining the confidentiality of admin credentials and monitoring access to the Euclido Assist admin panel.
Data Retention
- Retention Period: Euclido Inc. retains personal data for as long as necessary to fulfill the purposes outlined in this Data Policy, unless a longer retention period is required or permitted by law. Specifically:
- User Interaction Data: Retained for the duration of the customer’s contract and for a reasonable period thereafter to allow for performance analysis and potential legal claims.
- Anonymized Data: May be retained indefinitely for research and development purposes.
- Data Deletion: Upon the termination of a customer’s contract, Euclido Inc. will delete or anonymize all personal data related to that customer, unless retention is required by law. Customers may request the deletion of specific data at any time, subject to applicable legal requirements.
User Rights
- Access and Correction: Users have the right to request access to the personal data we hold about them and to request corrections if the data is inaccurate or incomplete.
- Data Portability: Users may request a copy of their personal data in a structured, commonly used, and machine-readable format.
- Right to Object: Users have the right to object to the processing of their personal data for specific purposes, such as direct marketing or profiling.
- Data Deletion: Users may request the deletion of their personal data, subject to certain exceptions (e.g., if the data is required for legal reasons or if anonymized data is necessary for the operation of Euclido Assist).
CI/CD Pipeline
- CI/CD Process: Euclido Inc. employs a Continuous Integration and Continuous Deployment (CI/CD) pipeline to ensure that updates to Euclido Assist are delivered efficiently, securely, and without disruption to the service.
- Continuous Integration: Regular integration of code changes from multiple contributors into a shared repository, followed by automated testing to detect and address issues early.
- Continuous Deployment: Automated deployment of tested code changes to the production environment, ensuring that updates are delivered quickly and consistently.
- Data Handling in CI/CD:
- Testing Data: In the CI/CD pipeline, anonymized or synthetic data is used during testing to ensure privacy.
Compliance with Laws
Euclido Inc. is committed to ensuring that all data collection, processing, and sharing activities are conducted in compliance with applicable data protection laws, including but not limited to:
- General Data Protection Regulation (GDPR): for customers in the European Economic Area.
- California Consumer Privacy Act (CCPA): for customers in California, USA.
- Children’s Online Privacy Protection Act (COPPA): for interactions involving users under the age of 13, where applicable.
Customers are responsible for ensuring that their use of Euclido Assist complies with any additional local data protection laws.
Changes to This Data Policy
Euclido Inc. reserves the right to update or modify this Data Policy at any time. Any changes will be communicated to customers through the admin panel and, where required by law, through direct notifications. Continued use of Euclido Assist after any changes indicates acceptance of the new terms.
Contact Information
For any questions, concerns, or requests regarding this Data Policy or the data practices of Euclido Assist, customers and users may contact us at:
Euclido Inc.
19 Amos Ave,
Waterloo, ON
Canada
Email: privacy@euclido.com
Phone: +1 (226) 978-8443This Data Policy is effective as of 1/9/2024, and is designed to be comprehensive, transparent, and in full compliance with all relevant legal and regulatory requirements.