Draft section for inclusion in the AcademiSys Terms and Conditions
Version: Draft 1.0 Date: 21 September 2026 Status: DRAFT FOR LEGAL REVIEW — not for publication as drafted
Text in [square brackets] marks a decision, a number, or a cross-reference that must be settled before publication. Appendix B lists every one of them in a single checklist.
This section sets out who is responsible for the data you put into AcademiSys, what AcademiSys does with it, and what you confirm every time you upload. It applies to every account, every plan (including free and trial use), and every method of getting data into the service — uploading a file, connecting a source, typing data in, or generating data through use of the service.
Read this section together with the [Privacy Policy] and, where one applies to you, any separate data processing agreement, business associate agreement or institutional agreement signed with AcademiSys. Section X.33 explains which document wins if they conflict.
In this section:
Uploading Your Data to AcademiSys does not transfer ownership of it. As between you and AcademiSys, you keep all rights, title and interest in Your Data.
You grant AcademiSys a worldwide, non-exclusive, royalty-free licence to host, store, copy, transmit, adapt, process and display Your Data, and to create the derived and intermediate forms of it that the service needs in order to work (for example, parsed, indexed, type-detected, cleaned and versioned copies), solely for the purposes of:
This licence exists only so that we can run the service you asked for. It lasts for as long as Your Data is in the service and ends when the data is deleted, except for copies held in routine backups until those backups expire under Section X.26.
[Decision — statistical / aggregate use:] We [do not use / may use] Your Data to train, fine-tune or improve machine learning models. [If "may use", the clause must be rewritten to describe exactly what is used, whether it is aggregated and de-identified first, and how you opt out. Do not leave this ambiguous.]
You are solely responsible for Your Data. That responsibility covers:
AcademiSys supplies the tools. You decide what to put into them, what to do with the output, and what it means.
Each time you upload or enter Your Data, and for as long as it remains in the service, you represent and warrant to AcademiSys that:
These confirmations are continuous. If any of them stops being true, you must immediately stop uploading the affected data and, where it matters, delete it from the service and tell us if the law requires it.
If Your Data was collected by someone else, obtained from a repository, purchased, licensed, scraped, shared with you by a collaborator, or is otherwise secondary data, you remain fully responsible for confirming that its terms of supply permit you to upload it to a third-party cloud service and to have that service process it. Restrictions commonly found in data use agreements — such as "no transfer to third parties", "processing on institutional systems only", "no cloud storage", or country-specific storage requirements — are your responsibility to check and comply with. AcademiSys has no visibility of those terms and does not check them.
AcademiSys processes Your Data as it finds it. We do not verify that it is accurate, complete, representative, correctly coded, correctly typed or fit for any particular purpose, and we do not correct it unless you instruct an operation that does so.
Automated checks, warnings, quality indicators, suggested cleaning steps and validation messages produced by the service are aids to your judgment, not assurances. Acting on them, ignoring them, or not seeing them remains your decision and your responsibility. Results, statistics, models, charts and reports produced by AcademiSys reflect the data you supplied and the operations you chose; they are not professional, clinical, legal, financial or research advice, and they must not be used as the sole basis for any decision affecting an individual's health, rights, finances, employment or education.
You must not upload to AcademiSys:
If you are unsure whether a category applies to your data, do not upload it until you have resolved the question. AcademiSys cannot resolve it for you.
You decide what data to upload, why, and what to do with it. AcademiSys processes it on your behalf and on your documented instructions — which, for ordinary use of the service, are the operations you carry out in the product.
Where Data Protection Law applies:
AcademiSys does not review, inspect, verify, classify, approve or vet Your Data, and has no obligation to do so. We cannot determine, and do not determine, whether a given file contains Personal Information, Protected Health Information or any other Sensitive Data, whether you were entitled to upload it, whether a particular law applies to it, or whether your use of it is lawful. Those determinations are yours alone, and nothing in the service — including any automated detection, warning, label or absence of one — should be treated as AcademiSys making them for you.
AcademiSys permits Sensitive Data, including Personal Information and Protected Health Information, to be uploaded to and processed on its servers. Permitting it is a technical and commercial statement about what the service accepts. It is not advice, confirmation or assurance that you may lawfully upload any particular data.
To the fullest extent permitted by law, AcademiSys is not responsible or liable for:
Nothing in this Section X.10 limits AcademiSys's own obligations as a processor or service provider under Data Protection Law, or excludes liability that cannot lawfully be excluded (see Section X.31).
Some data can only lawfully be processed by a service provider under a signed written arrangement — for example a Business Associate Agreement under HIPAA, a data processing agreement with transfer safeguards under the UK or EU GDPR, or a school-official arrangement under FERPA.
[Decision — choose (a) or (b) and delete the other:]
(a) If AcademiSys offers these agreements:
Such an arrangement applies to your account only if AcademiSys has entered into it with you in writing. Where signed, it forms part of these terms and prevails over this section to the extent of any conflict. If no such arrangement is in place, you must not upload data whose lawful processing depends on one, and you accept full responsibility if you do.
(b) If AcademiSys does not offer them:
AcademiSys does not currently enter into Business Associate Agreements or equivalent regulatory arrangements. You must not upload data whose lawful processing depends on one. If you do so, you do it entirely at your own risk and you are solely responsible for the consequences.
To provide the service, AcademiSys stores server-readable versions of your datasets. This is what allows you to label, clean, save, analyse and report on your data, keep your work between sessions, and reopen it on another device or in another browser.
This means Your Data is stored on AcademiSys's servers and is readable by the service in order to process it. It is not held only in your browser. Storing it in this form is a necessary part of the service; if you do not agree to it, the service cannot take in your data (see Section X.24).
Alongside the data itself, AcademiSys stores the information needed to run the service — such as dataset structure and column types, the operations you performed, version history, audit and access logs, and usage and diagnostic records.
Your Data is stored and processed in [region(s)]. Processing may also take place in [other countries where we or our sub-processors operate].
Where Data Protection Law restricts transfers of Personal Information across borders, those transfers are made under [standard contractual clauses / the UK international data transfer addendum / adequacy / other mechanism]. If your data must remain in a specific country or region, do not upload it unless AcademiSys has confirmed in writing that it can meet that requirement.
AcademiSys uses third-party infrastructure and service providers to host, store, secure and operate the service. A current list is available at [link]. These providers process Your Data only to provide their services to AcademiSys, under written terms that impose data protection and confidentiality obligations at least as protective as those in this section. AcademiSys remains responsible to you for their performance of those obligations.
[Decision: how you notify changes to the sub-processor list — e.g. 30 days' notice via the list page or email, with a right to object.]
You can mark columns as sensitive in Label Data. Where you have done so, AcademiSys will warn you before you download data containing marked columns.
This feature depends entirely on you marking your data correctly and completely. It:
The absence of a warning is not a statement that data is not sensitive. AcademiSys is not responsible for data that was sensitive but unmarked, for a marking that was wrong or incomplete, or for any consequence of relying on — or not receiving — a warning.
Agreeing to these terms does not authorise AcademiSys to send Your Data to third-party artificial intelligence providers.
What is never sent. AcademiSys does not transmit the rows, cell values or file contents of Your Data to any third-party AI provider. Cleaning, transformation, statistical analysis, charts and reports are computed by AcademiSys's own deterministic processing on AcademiSys-controlled infrastructure. This is enforced in the software, not only by policy: the outbound channels validate every field of a request against a fixed list and refuse to transmit anything else.
What is sent, and only to interpret what you asked for. Two features send a small, fixed set of information to a model provider so the service can understand your request:
Your own words are sent as you write them. If you type a value from your data into a question, that value is sent with the question. We screen requests for obvious identifiers — such as email addresses, national identifiers, telephone numbers and pasted tables — and refuse them, but we cannot detect every value you might type. Do not put data values into free-text fields.
Providers. Where these features are enabled, requests are routed to a third-party model provider: currently Google Gemini by default, with Anthropic and OpenAI as configurable alternatives. Where no provider is configured, these features are unavailable and nothing is sent.
Not AI providers. Error reporting and product analytics use separate third-party processors which are not AI providers and are described in the [Privacy Policy].
AcademiSys maintains technical and organisational measures appropriate to the risk, designed to protect Your Data against unauthorised access, loss, alteration and disclosure. These include [encryption in transit and at rest, access controls and least privilege, tenant isolation and row-level security, logging and monitoring, vulnerability management, backup and recovery, and personnel confidentiality obligations and training].
No service can be guaranteed secure. AcademiSys does not warrant that the service will be uninterrupted, error-free or immune from unauthorised access, and does not guarantee that Your Data cannot be lost, corrupted or accessed without authorisation.
Security of Your Data is shared. You are responsible for:
If AcademiSys becomes aware of a personal data breach or security incident affecting Your Data, we will notify you without undue delay and [within N hours of becoming aware], and will provide the information reasonably available to us so that you can meet your own notification obligations.
Deciding whether an incident must be reported to a regulator or to affected individuals, and making any such report, is your responsibility as controller. AcademiSys will provide reasonable assistance. AcademiSys is not responsible for incidents caused by your acts or omissions, by your users or collaborators, by credentials you failed to protect, or by systems outside our control.
If more than one person can access your account or workspace, everyone with access can see the data available to it. You are responsible for who those people are, for what they do, and for ensuring they are permitted to see Your Data.
If your account is administered by an organisation — an employer, university, department or client — that organisation may be able to access, control, export or delete data in the account, and may exercise your rights under these terms.
When you download, export, print, share or otherwise take Your Data out of AcademiSys, it leaves our systems and our protections. From that point, securing, transmitting, storing and disposing of it is entirely your responsibility, and AcademiSys has no control over and no liability for what happens to it.
If an individual contacts AcademiSys to exercise a right in relation to Personal Information in Your Data — access, correction, deletion, portability, objection, restriction, or an equivalent right under HIPAA or other law — we will, unless the law requires otherwise, refer them to you and tell you about the request.
Responding is your responsibility. AcademiSys will provide reasonable assistance, taking into account the nature of the processing and the information available to us, [at no charge / at our reasonable cost]. You can locate, correct, export and delete Your Data yourself using the service.
If AcademiSys receives a binding legal demand for Your Data — a court order, subpoena, warrant, or regulatory or law-enforcement request — we will, where legally permitted, notify you before disclosing anything, so that you have the opportunity to respond or challenge it. Where we are legally prohibited from notifying you, or where there is an imminent risk to life or safety, we may comply without notice.
By accepting these terms and uploading data, you acknowledge these terms of use and consent to AcademiSys processing your account's data on its servers, including Personal Information and Protected Health Information, for the purposes described in Section X.3.
You may withdraw that consent at any time at [where in the product]. Withdrawal:
Withdrawal does not affect the lawfulness of processing carried out before it.
AcademiSys retains Your Data for as long as your account is active, or until you delete it.
You may delete individual datasets, versions or your whole account at any time at [where in the product]. Deletion removes the data from the live service. Copies may persist in routine, encrypted backups for up to [N days], after which they expire and are overwritten in the ordinary course.
After your account is closed, AcademiSys will delete or irreversibly anonymise Your Data within [N days], except where we are required to retain it by law, or need to retain it to establish, exercise or defend legal claims — in which case we will retain only what is necessary, for only as long as necessary, and will continue to protect it under these terms.
[Decision: do you offer an export window after cancellation? If so, state its length here.]
AcademiSys is not a backup service, an archive, or your system of record. Backups exist to help us recover the service, not to give you a restore-on-request facility, and [are not available for individual restores / may be restored on request, at our discretion].
You should keep your own copy of any data that matters to you. To the extent permitted by law, AcademiSys is not liable for loss, corruption or unavailability of data you did not retain elsewhere.
AcademiSys does not routinely monitor the contents of Your Data and is under no obligation to do so. We may, however, remove Your Data, restrict processing, or suspend or terminate access where we reasonably believe that:
Where the law permits, we will tell you before or promptly after acting, and will restore access if the reason no longer applies.
You are responsible for keeping your own records of your processing and of the permissions you relied on. AcademiSys will make available the information reasonably necessary to demonstrate compliance with its obligations as a processor, and will cooperate with your reasonable, documented compliance requests [subject to the audit terms in the data processing agreement, where one is in place].
You will defend, indemnify and hold harmless AcademiSys, its affiliates and their officers, employees and agents against any claim, demand, action, proceeding, investigation, fine, penalty, loss, liability, damage, cost and reasonable legal expense arising out of or in connection with:
This indemnity does not apply to the extent the claim arises from AcademiSys's own breach of these terms, negligence or wilful misconduct.
To the fullest extent permitted by law, and except as expressly stated in these terms, AcademiSys gives no warranty, express or implied, regarding:
The service is a tool. It does not provide professional, clinical, legal, financial, regulatory or research advice, and it does not certify, approve or validate your data or your conclusions.
AcademiSys's liability in connection with this section is subject to the exclusions and limitations in Section [limitation-of-liability section reference].
Nothing in these terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that Data Protection Law prohibits us from excluding. Nothing in this section relieves AcademiSys of its own obligations as a processor or service provider under Data Protection Law, or of any obligation in a signed data processing agreement or business associate agreement.
AcademiSys may update this section as the service, the law or our providers change. Where a change materially reduces your rights or materially increases your obligations, we will give you [N days'] notice at [email / in-product notice] before it takes effect. Continuing to use the service after it takes effect means you accept it. If you do not accept it, you may stop uploading, export your data, and close your account.
If there is a conflict between documents, the following order applies, highest first:
Sections X.4, X.5, X.6, X.7, X.10, X.20, X.21, X.29, X.30, X.31, X.33 and this X.34 survive termination or expiry of your account and of these terms.
Questions about this section, data protection or security: [privacy@ / security@ address, postal address, and the name and contact details of your data protection officer or representative if you are required to have one].
The point of the section above is that the product does not have to say all of it. These are the short forms that link to it.
A.1 — Consent checkbox (required once per account, before first ingestion)
I confirm I have the right to upload this data and to have AcademiSys process it on my behalf, and I agree to the Data Responsibility terms, including processing of personal information (PII) and protected health information (PHI) on AcademiSys servers.
A.2 — Persistent line under the upload control (every upload, no interaction)
You are responsible for the data you upload. Sensitive data is permitted; your dataset contents are never sent to AI providers. Data Responsibility terms →
A.3 — Expandable "what this means" panel (optional, collapsed by default)
- AcademiSys stores server-readable versions of your datasets so you can label, clean, save, analyse and report on them, and reopen your work on another device. - Sensitive data is permitted. You can mark sensitive columns in Label Data and will be warned before downloading marked data. - Your dataset contents are never sent to AI providers. - You can withdraw consent at any time. Withdrawal blocks new uploads; it does not delete data already saved. - Read the full Data Responsibility terms →
A.4 — Withdrawal setting, help text
Withdrawing consent blocks new data from being taken in. It does not delete data already saved — delete that separately. There is no browser-only mode: without consent, uploads stop.
A.5 — Download warning for marked columns
This download includes columns you marked as sensitive: [column names]. Once downloaded, protecting this file is your responsibility.
A.6 — Free-text field hint (goal, notes, questions)
Don't include personal or health information here.
Every bracket in the draft, in one list.
Legal entity and contacts
The two decisions that matter most
Accuracy checks against the running product *(these are representations; an inaccurate one is a misrepresentation, not a typo)*
Numbers and periods
Scope choices
Three deliberate drafting choices, so the reasoning is visible rather than inferred:
*Draft prepared 21 September 2026 for review by qualified counsel in each jurisdiction where AcademiSys operates. Not legal advice.*
With your permission, Academisys records only a closed acquisition channel and pseudonymous evidence so we can understand which public pages lead to signups. We do not store browsing URLs, query strings, network addresses, or device profiles. Rejecting does not affect the product.