data_protocol // effective 2026-01-01

privacy
policy.

this policy describes how LUCY OS collects, processes, and protects data across all institutional nodes.

[01]

Responsible Party vs Operator Definition

Under POPIA (Protection of Personal Information Act) and GDPR, the educational institution is the 'Responsible Party' (or Data Controller) directing data operations. LUCY OS acts strictly as the 'Operator' (or Data Processor), processing institutional data solely on documented instructions under a mandatory Data Processing Addendum (DPA) to limit platform liabilities.

[02]

Data Scope & Juristic Persons Protection

We collect institutional data (legal names, contact info), identity data (names, emails, active roles), and operational logs (grades, attendance, security hashes). Unlike standard frameworks, we explicitly extend POPIA's protections to 'juristic persons' (corporate schools/bodies), treating business data with the identical safeguards applied to personal student records.

[03]

Cryptographic Isolation & Row-Level Security

All data ingested is housed in a PostgreSQL cluster. We employ strict PostgreSQL Row-Level Security (RLS) policies at the database layer to ensure complete cryptographic and operational tenant isolation, making cross-tenant data leakage mathematically and architecturally impossible.

[04]

Data Minimization & Minimizing AI Subprocessor Risks

OpenAI is engaged as an AI subprocessor. Prompt payloads are stripped of extraneous PII at the platform boundary. Crucially, we enforce a strict Zero Data Retention (ZDR) policy with OpenAI, excluding prompts and responses from abuse monitoring logs entirely. No AI outputs are used for generative foundational model training.

[05]

Subprocessor Risk Management

We leverage Vercel (for ephemeral frontend delivery and perimeter DDoS shield) and Supabase (for database storage, encryptions at rest via AES-256, and TLS 1.3 transit tunnels). All subprocessors are legally bound to support local and global data compliance mandates, and data residency settings restrict primary storage regions to specified jurisdictions.

[06]

Data Portability & Deletion Rights

Responsible parties retain absolute ownership over all raw data and may execute a full structured export at any time via the Admin Ledger or direct APIs. Individual users (faculty, parents, students) can request deletion, correction, or access to their records through their school's administrators.

[07]

Data Retention & Purging Lifecycle

Active institution files are kept for the duration of the subscription. Upon contractual termination, all personal and operational data is permanently purged and overwritten within 30 days. System audit logs are retained for 7 years to satisfy regulatory compliance.

[08]

Emergency Breach Notification & Incident Response

In the event of a security compromise or unauthorized data disclosure, LUCY OS will notify the institutional Responsible Party within 72 hours of verification. As an Operator, we provide complete forensic details (impact scope, mitigation measures) to enable the institution to fulfill its reporting duties to the Information Regulator.

[09]

Governing Law & Regulatory Inquiries

This privacy protocol is governed by the laws of Ethiopia, aligned with the Ethiopian Data Protection Proclamation and harmonized with GDPR. For inquiries, DPA contracts, or compliance questions, contact our security officer at lucyosck21@gmail.com.