marketing.termsOfService

marketing.termsOfServiceDescription

This is a working draft, published so the product has something honest to link to while AcademiSys is being built. It has not been settled by counsel. Passages in square brackets are decisions that are still open, including the legal entity details. Do not rely on it as final terms.

AcademiSys — Data Responsibility

Draft section for inclusion in the AcademiSys Terms and Conditions

Version: Draft 1.0 Date: 21 September 2026 Status: DRAFT FOR LEGAL REVIEW — not for publication as drafted

Text in [square brackets] marks a decision, a number, or a cross-reference that must be settled before publication. Appendix B lists every one of them in a single checklist.


Section [X] — Your Data and Your Responsibility for It

X.1 Purpose and scope of this section

This section sets out who is responsible for the data you put into AcademiSys, what AcademiSys does with it, and what you confirm every time you upload. It applies to every account, every plan (including free and trial use), and every method of getting data into the service — uploading a file, connecting a source, typing data in, or generating data through use of the service.

Read this section together with the [Privacy Policy] and, where one applies to you, any separate data processing agreement, business associate agreement or institutional agreement signed with AcademiSys. Section X.33 explains which document wins if they conflict.

X.2 Definitions

In this section:

  • "Your Data" means any file, dataset, table, row, column, value, label, note, text or other content that you — or anyone using your account, or anyone you grant access to — upload to, enter into, generate through, derive from, or store in AcademiSys. It includes the original file you upload, every saved version of it, anything produced by cleaning, labelling or analysing it, and any report or export made from it.
  • "Personal Information" (also called "PII") means information that identifies, or could reasonably be used on its own or in combination with other information to identify, a living individual.
  • "Protected Health Information" (also called "PHI") means health, treatment or payment information relating to an identifiable individual, including information that meets the definition of Protected Health Information under the U.S. Health Insurance Portability and Accountability Act (HIPAA) and equivalent categories of health data under other laws.
  • "Sensitive Data" means Personal Information, Protected Health Information, and any other data that is confidential, restricted or regulated by law, by contract, or by the policy of your institution, employer or client. It includes (without limitation): special-category or sensitive personal data under data protection law (such as data revealing health, race or ethnicity, religious or philosophical beliefs, political opinions, trade union membership, genetic or biometric data, sex life or sexual orientation); criminal offence data; children's data; student and education records; financial account and payment data; government identifiers; trade secrets and commercially confidential information; and any data held under a data use agreement, material transfer agreement, licence or non-disclosure agreement.
  • "Data Protection Law" means any law relating to privacy, data protection or data security that applies to your use of AcademiSys, including (as applicable) the UK GDPR, the EU GDPR, HIPAA, the U.S. Family Educational Rights and Privacy Act (FERPA), U.S. state privacy laws, and equivalent laws in any other country.
  • "AcademiSys", "we", "us" and "our" mean [legal entity name, company number, registered address].
  • "You" and "your" mean the person or organisation that holds the account, and anyone using the service through that account.

X.3 You own Your Data

Uploading Your Data to AcademiSys does not transfer ownership of it. As between you and AcademiSys, you keep all rights, title and interest in Your Data.

You grant AcademiSys a worldwide, non-exclusive, royalty-free licence to host, store, copy, transmit, adapt, process and display Your Data, and to create the derived and intermediate forms of it that the service needs in order to work (for example, parsed, indexed, type-detected, cleaned and versioned copies), solely for the purposes of:

  1. providing, maintaining and securing the service for you;
  2. carrying out the operations you instruct, such as labelling, cleaning, analysing, reporting and exporting;
  3. preventing fraud, abuse and security incidents; and
  4. complying with our legal obligations.

This licence exists only so that we can run the service you asked for. It lasts for as long as Your Data is in the service and ends when the data is deleted, except for copies held in routine backups until those backups expire under Section X.26.

[Decision — statistical / aggregate use:] We [do not use / may use] Your Data to train, fine-tune or improve machine learning models. [If "may use", the clause must be rewritten to describe exactly what is used, whether it is aggregated and de-identified first, and how you opt out. Do not leave this ambiguous.]

X.4 You are responsible for Your Data

You are solely responsible for Your Data. That responsibility covers:

  • what Your Data contains;
  • where it came from and how it was collected;
  • whether you were and remain entitled to upload it and to have AcademiSys process it;
  • whether it is accurate, complete, current and suitable for what you use it for;
  • the choices you make when labelling, cleaning, transforming, filtering, analysing and reporting on it; and
  • the decisions you, or anyone else, take on the basis of results produced from it.

AcademiSys supplies the tools. You decide what to put into them, what to do with the output, and what it means.

X.5 What you confirm each time you upload

Each time you upload or enter Your Data, and for as long as it remains in the service, you represent and warrant to AcademiSys that:

  1. Right and permission. You have the right, and hold every permission, authorisation and lawful basis required, to upload Your Data and to have AcademiSys process it on your behalf on its servers.
  2. Notices and consents. You have given every notice and obtained every consent, authorisation and approval that applies — including, where relevant, consent from the individuals the data is about, the notices required by Data Protection Law, ethics or institutional review board approval, and permission under any data use agreement, material transfer agreement, licence, grant condition or funder requirement. Those permissions are still valid and have not been withdrawn or expired.
  3. No breach. Uploading Your Data and having it processed does not breach any agreement, policy or law that applies to you, including any confidentiality obligation, employment or institutional policy, non-disclosure agreement, licence term, court order or regulatory direction.
  4. Minimisation and de-identification. You have removed, de-identified, pseudonymised or aggregated anything you are not permitted to disclose to a service provider, and you are uploading no more Personal Information than you actually need for your purpose.
  5. Third-party rights. Your Data does not infringe or misappropriate anyone's intellectual property, privacy, publicity, confidentiality or other rights.
  6. Lawful content. Your Data is not unlawful in itself, was not obtained unlawfully, and is not subject to any export control, sanctions restriction or secrecy regime that would prohibit its transfer to or processing by AcademiSys.
  7. No malicious code. Your Data contains no virus, malware, or code designed to disrupt, damage or gain unauthorised access to any system.
  8. Authority. If you are uploading on behalf of an organisation, you are authorised by that organisation to do so and to accept these terms on its behalf.

These confirmations are continuous. If any of them stops being true, you must immediately stop uploading the affected data and, where it matters, delete it from the service and tell us if the law requires it.

X.6 Provenance, third-party and secondary data

If Your Data was collected by someone else, obtained from a repository, purchased, licensed, scraped, shared with you by a collaborator, or is otherwise secondary data, you remain fully responsible for confirming that its terms of supply permit you to upload it to a third-party cloud service and to have that service process it. Restrictions commonly found in data use agreements — such as "no transfer to third parties", "processing on institutional systems only", "no cloud storage", or country-specific storage requirements — are your responsibility to check and comply with. AcademiSys has no visibility of those terms and does not check them.

X.7 Accuracy, completeness and fitness of Your Data

AcademiSys processes Your Data as it finds it. We do not verify that it is accurate, complete, representative, correctly coded, correctly typed or fit for any particular purpose, and we do not correct it unless you instruct an operation that does so.

Automated checks, warnings, quality indicators, suggested cleaning steps and validation messages produced by the service are aids to your judgment, not assurances. Acting on them, ignoring them, or not seeing them remains your decision and your responsibility. Results, statistics, models, charts and reports produced by AcademiSys reflect the data you supplied and the operations you chose; they are not professional, clinical, legal, financial or research advice, and they must not be used as the sole basis for any decision affecting an individual's health, rights, finances, employment or education.

X.8 Data you must not upload

You must not upload to AcademiSys:

  1. data you do not have the right to upload, or whose upload would breach any of the confirmations in Section X.5;
  2. data whose lawful processing requires a written agreement that AcademiSys has not signed with you (see Section X.11);
  3. [payment card data subject to PCI-DSS];
  4. [classified, national-security or government-restricted data];
  5. data subject to a legal or contractual requirement that it be stored only in a particular country or on particular systems, unless AcademiSys has confirmed in writing that it meets that requirement;
  6. data obtained through unauthorised access, deception, or breach of another service's terms;
  7. content that is unlawful, that depicts or facilitates the abuse or exploitation of children, or whose possession is itself an offence; and
  8. [any other category you decide to exclude].

If you are unsure whether a category applies to your data, do not upload it until you have resolved the question. AcademiSys cannot resolve it for you.

X.9 The role of each party

You decide what data to upload, why, and what to do with it. AcademiSys processes it on your behalf and on your documented instructions — which, for ordinary use of the service, are the operations you carry out in the product.

Where Data Protection Law applies:

  • You act as the controller (or as a processor acting for another controller) in respect of Personal Information in Your Data. AcademiSys acts as the processor or service provider.
  • Where HIPAA applies, you act as the covered entity or as a business associate, and AcademiSys would act as your business associate or subcontractor only under a signed Business Associate Agreement (see Section X.11).
  • You are responsible for meeting the controller's obligations — lawful basis, notice, consent, data subject rights, records of processing, impact assessments, and any approvals your institution requires.

AcademiSys does not review, inspect, verify, classify, approve or vet Your Data, and has no obligation to do so. We cannot determine, and do not determine, whether a given file contains Personal Information, Protected Health Information or any other Sensitive Data, whether you were entitled to upload it, whether a particular law applies to it, or whether your use of it is lawful. Those determinations are yours alone, and nothing in the service — including any automated detection, warning, label or absence of one — should be treated as AcademiSys making them for you.

X.10 Sensitive Data is permitted — and the responsibility for it is yours

AcademiSys permits Sensitive Data, including Personal Information and Protected Health Information, to be uploaded to and processed on its servers. Permitting it is a technical and commercial statement about what the service accepts. It is not advice, confirmation or assurance that you may lawfully upload any particular data.

To the fullest extent permitted by law, AcademiSys is not responsible or liable for:

  1. your decision to upload Personal Information, Protected Health Information or any other Sensitive Data;
  2. whether you held the rights, consents, approvals, ethical clearances or lawful bases needed to upload it or to have it processed;
  3. the presence of Sensitive Data in a dataset you believed did not contain any, including Sensitive Data in free-text fields, notes, filenames, column headers, identifiers, metadata or residual columns;
  4. any failure by you to de-identify, pseudonymise, redact, minimise or aggregate data before uploading it;
  5. any breach of an agreement, institutional policy, ethics approval, licence, law or regulation arising from your uploading, storing, processing, labelling, sharing, exporting or downloading of Sensitive Data;
  6. any claim by an individual whose Personal Information or Protected Health Information you uploaded, or by your institution, employer, client, funder or data supplier; or
  7. any investigation, enforcement action, penalty, fine, notification obligation, remediation cost or reputational loss arising from any of the above.

Nothing in this Section X.10 limits AcademiSys's own obligations as a processor or service provider under Data Protection Law, or excludes liability that cannot lawfully be excluded (see Section X.31).

X.11 Regulatory arrangements (BAA, DPA, transfer safeguards)

Some data can only lawfully be processed by a service provider under a signed written arrangement — for example a Business Associate Agreement under HIPAA, a data processing agreement with transfer safeguards under the UK or EU GDPR, or a school-official arrangement under FERPA.

[Decision — choose (a) or (b) and delete the other:]

(a) If AcademiSys offers these agreements:

Such an arrangement applies to your account only if AcademiSys has entered into it with you in writing. Where signed, it forms part of these terms and prevails over this section to the extent of any conflict. If no such arrangement is in place, you must not upload data whose lawful processing depends on one, and you accept full responsibility if you do.

(b) If AcademiSys does not offer them:

AcademiSys does not currently enter into Business Associate Agreements or equivalent regulatory arrangements. You must not upload data whose lawful processing depends on one. If you do so, you do it entirely at your own risk and you are solely responsible for the consequences.

X.12 What AcademiSys stores, and why

To provide the service, AcademiSys stores server-readable versions of your datasets. This is what allows you to label, clean, save, analyse and report on your data, keep your work between sessions, and reopen it on another device or in another browser.

This means Your Data is stored on AcademiSys's servers and is readable by the service in order to process it. It is not held only in your browser. Storing it in this form is a necessary part of the service; if you do not agree to it, the service cannot take in your data (see Section X.24).

Alongside the data itself, AcademiSys stores the information needed to run the service — such as dataset structure and column types, the operations you performed, version history, audit and access logs, and usage and diagnostic records.

X.13 Where data is stored, and international transfers

Your Data is stored and processed in [region(s)]. Processing may also take place in [other countries where we or our sub-processors operate].

Where Data Protection Law restricts transfers of Personal Information across borders, those transfers are made under [standard contractual clauses / the UK international data transfer addendum / adequacy / other mechanism]. If your data must remain in a specific country or region, do not upload it unless AcademiSys has confirmed in writing that it can meet that requirement.

X.14 Sub-processors and infrastructure providers

AcademiSys uses third-party infrastructure and service providers to host, store, secure and operate the service. A current list is available at [link]. These providers process Your Data only to provide their services to AcademiSys, under written terms that impose data protection and confidentiality obligations at least as protective as those in this section. AcademiSys remains responsible to you for their performance of those obligations.

[Decision: how you notify changes to the sub-processor list — e.g. 30 days' notice via the list page or email, with a right to object.]

X.15 Marking sensitive columns is a convenience, not a safeguard

You can mark columns as sensitive in Label Data. Where you have done so, AcademiSys will warn you before you download data containing marked columns.

This feature depends entirely on you marking your data correctly and completely. It:

  • does not detect, discover, infer or classify sensitive data;
  • does not encrypt, redact, mask, tokenise, restrict or delete anything;
  • does not change how the data is stored, processed, transmitted or backed up;
  • does not prevent download, export, sharing or use of marked data; and
  • does not constitute a determination by AcademiSys about the nature of your data.

The absence of a warning is not a statement that data is not sensitive. AcademiSys is not responsible for data that was sensitive but unmarked, for a marking that was wrong or incomplete, or for any consequence of relying on — or not receiving — a warning.

X.16 AI providers and automated processing

Agreeing to these terms does not authorise AcademiSys to send Your Data to third-party artificial intelligence providers.

What is never sent. AcademiSys does not transmit the rows, cell values or file contents of Your Data to any third-party AI provider. Cleaning, transformation, statistical analysis, charts and reports are computed by AcademiSys's own deterministic processing on AcademiSys-controlled infrastructure. This is enforced in the software, not only by policy: the outbound channels validate every field of a request against a fixed list and refuse to transmit anything else.

What is sent, and only to interpret what you asked for. Two features send a small, fixed set of information to a model provider so the service can understand your request:

  1. The words you type, verbatim — the analysis request you write, and the instructions you give in the cleaning and analysis prompt.
  2. For request understanding only: your column names, each column's general type (such as numeric, categorical or date), and the number of distinct values in each column. No cell values, value labels, summary statistics, row counts, dataset names or file names are included.

Your own words are sent as you write them. If you type a value from your data into a question, that value is sent with the question. We screen requests for obvious identifiers — such as email addresses, national identifiers, telephone numbers and pasted tables — and refuse them, but we cannot detect every value you might type. Do not put data values into free-text fields.

Providers. Where these features are enabled, requests are routed to a third-party model provider: currently Google Gemini by default, with Anthropic and OpenAI as configurable alternatives. Where no provider is configured, these features are unavailable and nothing is sent.

Not AI providers. Error reporting and product analytics use separate third-party processors which are not AI providers and are described in the [Privacy Policy].

X.17 Security: what AcademiSys does

AcademiSys maintains technical and organisational measures appropriate to the risk, designed to protect Your Data against unauthorised access, loss, alteration and disclosure. These include [encryption in transit and at rest, access controls and least privilege, tenant isolation and row-level security, logging and monitoring, vulnerability management, backup and recovery, and personnel confidentiality obligations and training].

No service can be guaranteed secure. AcademiSys does not warrant that the service will be uninterrupted, error-free or immune from unauthorised access, and does not guarantee that Your Data cannot be lost, corrupted or accessed without authorisation.

X.18 Security: what you must do

Security of Your Data is shared. You are responsible for:

  1. keeping your account credentials confidential and not sharing logins;
  2. [enabling and maintaining multi-factor authentication where offered];
  3. deciding who to invite, share with or grant access to, and removing access promptly when someone no longer needs it — including when they leave your team or organisation;
  4. everything done under your account, whether or not you authorised it;
  5. securing the devices and networks you use to access the service;
  6. securing every copy of Your Data that you download, export or send elsewhere; and
  7. telling us promptly at [security contact] if you believe your account has been compromised or Your Data has been accessed without authorisation.

X.19 Security incidents

If AcademiSys becomes aware of a personal data breach or security incident affecting Your Data, we will notify you without undue delay and [within N hours of becoming aware], and will provide the information reasonably available to us so that you can meet your own notification obligations.

Deciding whether an incident must be reported to a regulator or to affected individuals, and making any such report, is your responsibility as controller. AcademiSys will provide reasonable assistance. AcademiSys is not responsible for incidents caused by your acts or omissions, by your users or collaborators, by credentials you failed to protect, or by systems outside our control.

X.20 Accounts, users, collaborators and shared access

If more than one person can access your account or workspace, everyone with access can see the data available to it. You are responsible for who those people are, for what they do, and for ensuring they are permitted to see Your Data.

If your account is administered by an organisation — an employer, university, department or client — that organisation may be able to access, control, export or delete data in the account, and may exercise your rights under these terms.

X.21 Exports, downloads and data leaving the service

When you download, export, print, share or otherwise take Your Data out of AcademiSys, it leaves our systems and our protections. From that point, securing, transmitting, storing and disposing of it is entirely your responsibility, and AcademiSys has no control over and no liability for what happens to it.

X.22 Requests from individuals about their data

If an individual contacts AcademiSys to exercise a right in relation to Personal Information in Your Data — access, correction, deletion, portability, objection, restriction, or an equivalent right under HIPAA or other law — we will, unless the law requires otherwise, refer them to you and tell you about the request.

Responding is your responsibility. AcademiSys will provide reasonable assistance, taking into account the nature of the processing and the information available to us, [at no charge / at our reasonable cost]. You can locate, correct, export and delete Your Data yourself using the service.

X.23 Requests from authorities and legal process

If AcademiSys receives a binding legal demand for Your Data — a court order, subpoena, warrant, or regulatory or law-enforcement request — we will, where legally permitted, notify you before disclosing anything, so that you have the opportunity to respond or challenge it. Where we are legally prohibited from notifying you, or where there is an imminent risk to life or safety, we may comply without notice.

X.24 Consent: giving it and withdrawing it

By accepting these terms and uploading data, you acknowledge these terms of use and consent to AcademiSys processing your account's data on its servers, including Personal Information and Protected Health Information, for the purposes described in Section X.3.

You may withdraw that consent at any time at [where in the product]. Withdrawal:

  • blocks new data from being taken in — no new uploads or ingestion will be accepted;
  • does not delete, move or convert data already saved — anything already stored stays stored until you delete it under Section X.25;
  • does not switch the service to browser-only storage. There is no browser-only fallback. Without consent, ingestion stops rather than continuing in another form; and
  • may make parts of the service unusable, because storing server-readable versions of your datasets is how the service works.

Withdrawal does not affect the lawfulness of processing carried out before it.

X.25 Retention, deletion and account closure

AcademiSys retains Your Data for as long as your account is active, or until you delete it.

You may delete individual datasets, versions or your whole account at any time at [where in the product]. Deletion removes the data from the live service. Copies may persist in routine, encrypted backups for up to [N days], after which they expire and are overwritten in the ordinary course.

After your account is closed, AcademiSys will delete or irreversibly anonymise Your Data within [N days], except where we are required to retain it by law, or need to retain it to establish, exercise or defend legal claims — in which case we will retain only what is necessary, for only as long as necessary, and will continue to protect it under these terms.

[Decision: do you offer an export window after cancellation? If so, state its length here.]

X.26 Backups and your own copy

AcademiSys is not a backup service, an archive, or your system of record. Backups exist to help us recover the service, not to give you a restore-on-request facility, and [are not available for individual restores / may be restored on request, at our discretion].

You should keep your own copy of any data that matters to you. To the extent permitted by law, AcademiSys is not liable for loss, corruption or unavailability of data you did not retain elsewhere.

X.27 Monitoring, removal and suspension

AcademiSys does not routinely monitor the contents of Your Data and is under no obligation to do so. We may, however, remove Your Data, restrict processing, or suspend or terminate access where we reasonably believe that:

  1. this section has been breached;
  2. Your Data is unlawful, infringing, or falls within Section X.8;
  3. continued processing exposes AcademiSys, you or a third party to legal liability or security risk; or
  4. we are required to act by law, by a regulator, or by a valid legal demand.

Where the law permits, we will tell you before or promptly after acting, and will restore access if the reason no longer applies.

X.28 Records and cooperation

You are responsible for keeping your own records of your processing and of the permissions you relied on. AcademiSys will make available the information reasonably necessary to demonstrate compliance with its obligations as a processor, and will cooperate with your reasonable, documented compliance requests [subject to the audit terms in the data processing agreement, where one is in place].

X.29 Indemnity

You will defend, indemnify and hold harmless AcademiSys, its affiliates and their officers, employees and agents against any claim, demand, action, proceeding, investigation, fine, penalty, loss, liability, damage, cost and reasonable legal expense arising out of or in connection with:

  1. Your Data;
  2. your breach of any confirmation, warranty or obligation in this section;
  3. your upload, storage, processing, labelling, sharing, export or download of Personal Information, Protected Health Information or other Sensitive Data;
  4. any claim by an individual whose data you uploaded, or by your institution, employer, client, funder, collaborator or data supplier; and
  5. any decision made by you or anyone else on the basis of results produced from Your Data.

This indemnity does not apply to the extent the claim arises from AcademiSys's own breach of these terms, negligence or wilful misconduct.

X.30 Disclaimers regarding Your Data

To the fullest extent permitted by law, and except as expressly stated in these terms, AcademiSys gives no warranty, express or implied, regarding:

  • the legality, provenance, accuracy, completeness, currency, representativeness or fitness for any purpose of Your Data;
  • the correctness, reliability or suitability of any result, statistic, model, chart, cleaning step or report produced from Your Data; or
  • your compliance, or your ability to comply, with any law, regulation, policy, ethics approval or agreement that applies to you.

The service is a tool. It does not provide professional, clinical, legal, financial, regulatory or research advice, and it does not certify, approve or validate your data or your conclusions.

X.31 Limitation of liability

AcademiSys's liability in connection with this section is subject to the exclusions and limitations in Section [limitation-of-liability section reference].

Nothing in these terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that Data Protection Law prohibits us from excluding. Nothing in this section relieves AcademiSys of its own obligations as a processor or service provider under Data Protection Law, or of any obligation in a signed data processing agreement or business associate agreement.

X.32 Changes to this section

AcademiSys may update this section as the service, the law or our providers change. Where a change materially reduces your rights or materially increases your obligations, we will give you [N days'] notice at [email / in-product notice] before it takes effect. Continuing to use the service after it takes effect means you accept it. If you do not accept it, you may stop uploading, export your data, and close your account.

X.33 Order of precedence

If there is a conflict between documents, the following order applies, highest first:

  1. a signed Business Associate Agreement or data processing agreement between you and AcademiSys;
  2. a signed institutional, enterprise or order agreement;
  3. this section;
  4. the rest of these Terms and Conditions;
  5. the Privacy Policy and any other policy referenced in these terms.

X.34 Survival

Sections X.4, X.5, X.6, X.7, X.10, X.20, X.21, X.29, X.30, X.31, X.33 and this X.34 survive termination or expiry of your account and of these terms.

X.35 Contact

Questions about this section, data protection or security: [privacy@ / security@ address, postal address, and the name and contact details of your data protection officer or representative if you are required to have one].


Appendix A — In-product copy

The point of the section above is that the product does not have to say all of it. These are the short forms that link to it.

A.1 — Consent checkbox (required once per account, before first ingestion)

I confirm I have the right to upload this data and to have AcademiSys process it on my behalf, and I agree to the Data Responsibility terms, including processing of personal information (PII) and protected health information (PHI) on AcademiSys servers.

A.2 — Persistent line under the upload control (every upload, no interaction)

You are responsible for the data you upload. Sensitive data is permitted; your dataset contents are never sent to AI providers. Data Responsibility terms →

A.3 — Expandable "what this means" panel (optional, collapsed by default)

- AcademiSys stores server-readable versions of your datasets so you can label, clean, save, analyse and report on them, and reopen your work on another device. - Sensitive data is permitted. You can mark sensitive columns in Label Data and will be warned before downloading marked data. - Your dataset contents are never sent to AI providers. - You can withdraw consent at any time. Withdrawal blocks new uploads; it does not delete data already saved. - Read the full Data Responsibility terms →

A.4 — Withdrawal setting, help text

Withdrawing consent blocks new data from being taken in. It does not delete data already saved — delete that separately. There is no browser-only mode: without consent, uploads stop.

A.5 — Download warning for marked columns

This download includes columns you marked as sensitive: [column names]. Once downloaded, protecting this file is your responsibility.

A.6 — Free-text field hint (goal, notes, questions)

Don't include personal or health information here.


Appendix B — Decisions to settle before publication

Every bracket in the draft, in one list.

Legal entity and contacts

  1. X.2 — AcademiSys legal entity name, company number, registered address.
  2. X.35 — privacy and security contact addresses; DPO or representative, if required.
  3. X.18 — security incident reporting address.

The two decisions that matter most

  1. X.11 — do you sign Business Associate Agreements / data processing agreements? Choose (a) or (b). This is the largest single exposure decision in the section.
  2. X.3 — do you use customer data to train or improve models? If yes, the clause must be rewritten precisely, with an opt-out.

Accuracy checks against the running product *(these are representations; an inaccurate one is a misrepresentation, not a typo)*

  1. X.16 — confirm no dataset contents reach any AI provider on any path, including error reporting, support tooling, logs and diagnostics. Then state exactly what non-content text or metadata does.
  2. X.17 — confirm each listed security measure is actually in place; delete any that is not.
  3. X.15 — confirm the warning fires on every download path that can include marked columns.
  4. X.24 — confirm withdrawal genuinely blocks ingestion and does not silently fall back.

Numbers and periods

  1. X.13 — storage region(s), processing countries, transfer mechanism.
  2. X.19 — incident notification window (hours).
  3. X.25 — backup retention window (days); post-closure deletion window (days); export window after cancellation, if any.
  4. X.26 — whether individual restores from backup are offered at all.
  5. X.32 — notice period for material changes.

Scope choices

  1. X.8 — confirm the prohibited categories. Payment card data and classified data are the usual two; add anything your infrastructure cannot support.
  2. X.14 — sub-processor list URL and how changes are notified.
  3. X.22 — whether assistance with individual rights requests is free or charged.
  4. X.31 / X.33 — cross-references to your existing limitation-of-liability section and Privacy Policy.

Appendix C — Notes for your lawyer

Three deliberate drafting choices, so the reasoning is visible rather than inferred:

  1. "Not responsible" is framed as risk allocation, not as a denial of duty. Section X.10 disclaims responsibility for *your decision to upload* Sensitive Data and for *your entitlement* to do so. It does not purport to remove AcademiSys's own processor obligations, because under the GDPR and HIPAA those run to regulators and data subjects and cannot be contracted away. X.10's closing paragraph and X.31 say so explicitly. A clause drafted the other way would likely be read down or struck, and would weaken the rest of the section by association.
  1. Consent to PII/PHI processing sits in the contract, with a short confirmation in product. The brief is that a full consent flow at upload is too heavy. The draft therefore carries the substance in the terms (X.24) and keeps a one-line confirmation plus a link at the upload point (Appendix A.1). Worth your view on whether, for special-category data in the jurisdictions AcademiSys serves, contract acceptance plus a linked confirmation is sufficient, or whether a separate affirmative consent is needed for accounts handling health data specifically.
  1. The sensitive-column feature is described as a labelling aid with no protective effect. This is deliberate and slightly unflattering to the feature. A product that offers a "mark as sensitive" control invites the argument that users reasonably relied on it as a safeguard; X.15 forecloses that by stating plainly what it does not do.

*Draft prepared 21 September 2026 for review by qualified counsel in each jurisdiction where AcademiSys operates. Not legal advice.*

Optional first-party measurement

With your permission, Academisys records only a closed acquisition channel and pseudonymous evidence so we can understand which public pages lead to signups. We do not store browsing URLs, query strings, network addresses, or device profiles. Rejecting does not affect the product.