> For the complete documentation index, see [llms.txt](https://docs.getkita.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.getkita.org/legal-and-support/privacy-policy.md).

# Privacy Policy

Effective date: 17th August 2026

This page explains how Kita Education Ltd looks after personal data. The first part is written for students and for the parents and carers who read it with them. The full policy follows underneath, including the summary school IT and data protection teams need.

{% hint style="info" %}
**Two versions, one page.** The plain-English guide helps you understand the policy. It does not replace it. Where the two differ, the full policy applies.
{% endhint %}

**Version 2.0** · Effective 17 August 2026 · Supersedes the Customer Privacy Notice (23 February 2026), Open Kita Privacy Policy v1.0 (12 May 2026) and Privacy Policy v3 (22 February 2020).

***

### Your information and Kita: a guide for students

Kita is a website that helps you learn to code. A company called Kita Education Ltd runs it. They are based in London.

This guide tells you what happens to your information. Open any box to read more. Each box has a link to the full wording further down the page.

<figure><img src="https://1176288822-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fjzm9nyD2lhxeWS1B64j9%2Fuploads%2FPEd0xQVP6cd4mezZ6kz4%2Fkid-data-locker.png?alt=media&amp;token=c59494e8-58f4-4689-987c-ad323f193d83" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**Not sure about something? Ask a grown-up.** A parent, a carer, or your teacher can read this page with you. You can ask them at any time.
{% endhint %}

<details>

<summary>What Kita knows about you</summary>

Kita keeps this as small as it can.

**If you use Kita at school**, your school is in charge of your information. Your school decides what goes into Kita. Kita holds your name. Or it holds a nickname your teacher picks for you instead.

**If you signed up to Open Kita yourself**, Kita holds:

* a nickname you choose
* your email address
* the month and year you were born (never your full birthday)
* your country
* a grown-up's email address, if you are under 18

Kita never asks for your address. It never asks for your phone number. It never asks for a photo of you.

**In the full policy:** Part A: School Kita · Part B: Open Kita

</details>

<details>

<summary>Why you use a nickname</summary>

You can use a nickname instead of your real name.

**At school**, you pick one, or your teacher picks one for you. Your teacher still knows which work is yours.

**On Open Kita**, you pick your own. Kita only ever sees the nickname.

Either way, a nickname means a stranger cannot work out who you are.

**In the full policy:** Part A: School Kita · Part B: Open Kita

</details>

<details>

<summary>Who can see your work</summary>

**At school**, you and your teacher. That is all. Kita saves your code and your answers so you can both see how you are getting on.

**On Open Kita**, just you, unless you choose to share something.

Your work is never sold. It is never made public unless someone says yes first.

Advertisers never get it. Kita does not build an advert profile of you. It does not follow you around the internet.

**In the full policy:** User generated content · Who we share information with

</details>

<details>

<summary>Do not share anything personal about yourself</summary>

Kita saves what you type. So keep private things out of it.

That means your full name. Your address. Your phone number. Anything private about you or your friends.

Do you need a name or an address to test your program? Make one up.

The same goes for the AI helper. Do not tell it private things.

**In the full policy:** User generated content

</details>

<details>

<summary>The AI helper</summary>

Kita has an AI helper. It gives you feedback on your code.

Here is how it works:

* What you type is **never** used to teach the AI
* Your messages are kept for 90 days. Then they are deleted
* It runs on computers in the UK. Your words do not leave the country
* It never makes a big decision about you. It suggests, and a person decides
* It is sometimes wrong. If a hint looks odd, it might be

**Who turns it on.** At school, your teacher does, and your teacher also picks how much it helps. On Open Kita, you do, and if you are under 18 your parent or carer says yes first.

Kita also keeps track of how your learning is going. It notes which skills you have practised, and where you get stuck. This is so the feedback fits you. At school your teacher can see it. It is never used for anything else.

**In the full policy:** Using generative AI for student feedback · Personalised learning and progress records

</details>

<details>

<summary>How long Kita keeps things</summary>

Not forever.

Different things are kept for different lengths of time. Then they are deleted safely.

Your AI messages go after 90 days. The detailed record of your learning goes after 12 months. When you stop using Kita, your information is deleted.

**In the full policy:** How long we keep information

</details>

<details>

<summary>Cookies</summary>

A cookie is a small file a website keeps on your device.

Kita uses the cookies it needs to work. One of them keeps you logged in. A few others show how Kita is being used, so it can be made better.

Kita never uses cookies to show you adverts. It never uses them to follow you around the internet.

**In the full policy:** Cookies and automatic technical information

</details>

<details>

<summary>What you can ask for</summary>

You can ask Kita to do three things. So can your parent or carer.

* **Show you** the information it has about you
* **Fix** something that is wrong
* **Delete** your information

Who you ask depends on which Kita you use.

**On Open Kita** ([getkita.io/try/dashboard](https://getkita.io/try/dashboard)), the account is your own, so you can ask Kita directly. Email <hello@getkita.com>.

**At school** ([getkita.io/login](https://getkita.io/login)), your school looks after your information, so ask your teacher first. They will pass the request on.

**In the full policy:** Your rights

</details>

<details>

<summary>If you are not happy</summary>

Tell Kita. Email <hello@getkita.com>. They will try to sort it out.

Still not happy? There is a group called the **ICO**. That is short for the Information Commissioner's Office. Their job is to help people with problems about their information. You can complain to them at [ico.org.uk/make-a-complaint](https://www.ico.org.uk/make-a-complaint).

Is something on Kita worrying you? Is someone being unkind? Tell your teacher or a grown-up you trust. Do it straight away.

**In the full policy:** How to complain

</details>

#### What changes as you get older

Some things depend on how old you are. Pick your age below.

<figure><img src="https://1176288822-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fjzm9nyD2lhxeWS1B64j9%2Fuploads%2F34NtNqVm17FEM038XIkr%2Fkita-growing-up.png?alt=media&amp;token=02e65f33-592c-4b51-beab-b9f58c6d81d0" alt=""><figcaption></figcaption></figure>

{% tabs %}
{% tab title="10 to 12" %}
**A grown-up decides for you.**

You can use Kita at school. Your school sets it up. Your teacher gives you a code or a link to join.

You cannot sign up to Open Kita on your own yet. A parent or carer has to say yes by email first. Until they do, your account will not work.

The **AI helper** and **sharing your work** stay off until a grown-up says yes.

Read this page with a parent, a carer, or your teacher. Ask them anything you are not sure about.

**In the full policy:** Part B: Open Kita
{% endtab %}

{% tab title="13 to 15" %}
**You can sign up on your own.**

13 is the age you can agree to sign up yourself. So you can make an Open Kita account and start using it.

Two things still need a grown-up to say yes: the **AI helper** and **sharing your work**. Kita emails the address you give for your parent or carer. Those two stay off until they reply.

You are starting to make your own choices here. That is fine. But you do not have to work it out alone. Ask a grown-up if you are unsure.

**In the full policy:** Part B: Open Kita
{% endtab %}

{% tab title="16 to 17" %}
**More of the choices are yours.**

You can sign up on your own. You can use the AI helper without an account too.

A parent or carer still says yes to the **AI helper** and to **sharing your work** while you are under 18. They also agree to the terms on your behalf.

Here is what to weigh up before you share work. Anything you share can be seen by other people. Anything you type into the AI helper is stored for 90 days. Neither is used to train AI models, and neither is sold. Sharing is always your own choice. Kita never shares your work for you.

If any of that worries you, check with a parent, a carer, or your teacher first.

**In the full policy:** Part B: Open Kita · Part C: Anonymous AI use
{% endtab %}

{% tab title="Not signed in" %}
**You can try Kita without an account.**

You can try courses. You can make projects. You can join a temporary **Quick Course** and code on a file with other people.

Two things to know:

* Anything you make in a Quick Course is **deleted after 24 hours**. Want to keep it? Make an account.
* You can use the **AI helper** without an account only if you are **13 or over**. You will be asked to confirm that first.

**In the full policy:** Part C: Anonymous AI use
{% endtab %}
{% endtabs %}

#### When to ask a grown-up

There are four points where a grown-up can help you:

<figure><img src="https://1176288822-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fjzm9nyD2lhxeWS1B64j9%2Fuploads%2FQnuIS8zlYWRMgtYGSjop%2Fkita-when-to-ask.png?alt=media&amp;token=51f6f23f-40d1-4c2a-98e6-078590bf7dfd" alt=""><figcaption></figcaption></figure>

1. **When you join.** A parent, carer or teacher can read this page with you and help you set up your account.
2. **When the AI helper is turned on.** If you are under 18, your parent or carer says yes to this.
3. **When you share your work.** If you are under 18, your parent or carer says yes to this too.
4. **When you want to see, change or delete your information.** At school, ask your teacher. On Open Kita, the account is yours, so you can ask Kita yourself.

You can ask for help at any other time too. You do not have to wait for one of these.

#### For parents and carers

This section carries the detail behind the simpler explanations above. The two sit side by side deliberately: the student guide is shorter, not less honest.

{% tabs %}
{% tab title="Consent" %}
**Under 13.** An Open Kita account does not function until you confirm by email. Sharing and AI features stay off until then.

**13 to 17.** Your child can use Open Kita straight away, but sharing and AI features stay off until you confirm by email.

**At school.** The school is the data controller and handles consent and safeguarding through its own policies. Raise any question about your child's data with the school first.

Consent can be withdrawn at any time. Using Kita is not conditional on agreeing to general data processing. Where consent is the lawful basis for something specific, it is requested separately.

**In the full policy:** Part B: Open Kita · Lawful bases and data protection rights
{% endtab %}

{% tab title="The AI" %}
Kita's AI provider is Microsoft Azure OpenAI Service, hosted in the **UK South region**. Prompts and outputs do not leave the UK.

Your child's inputs are **never** used to train, retrain or improve AI models, and are not shared with OpenAI.

AI output is advisory. Kita does not make automated decisions about students that have legal or similarly significant effects. Teachers review everything and hold final judgement.

Kita aligns with the UK Government's Generative AI Product Safety Standards for education. Content moderation and safety controls are built in.

AI messages are kept for 90 days, then deleted.

**In the full policy:** Using generative AI for student feedback · Part C: Anonymous AI use
{% endtab %}

{% tab title="Where data lives" %}
Hosting is in the **UK and the EEA** (Ireland and Germany). AI processing is in the **UK** only.

Some processors sit outside the UK: a payment provider and documentation and analytics providers in the US, and a provider in Singapore. Each transfer is covered by the UK International Data Transfer Agreement or EU Standard Contractual Clauses. Every processor is bound by a data processing agreement.

You can request a copy of the safeguards for any transfer by emailing <hello@getkita.com>.

**In the full policy:** Who we share information with · International data transfers
{% endtab %}

{% tab title="Marketing" %}
Personal data is never sold.

Personal data of anyone **under 18** is never used for marketing. Neither is student data provided through a school.

Only Open Kita users aged 18 or over are asked to opt in to product updates and marketing, and they can unsubscribe at any time.

Kita does not use behavioural advertising cookies or student profiling cookies.

**In the full policy:** Teacher and administrator data · Cookies and automatic technical information
{% endtab %}

{% tab title="Exercising rights" %}
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent all apply. Kita responds within one month.

**Route your request correctly.** If your child uses Kita through a school, the school or teacher is the data controller, so make the request to them. For everything else, email <hello@getkita.com>.

Safeguarding records are the one exception to erasure: schools and Kita may be legally required to retain them.

**In the full policy:** Your rights
{% endtab %}

{% tab title="Talking about it together" %}
Four questions that work well with a child of any age using Kita:

1. **"Show me your nickname on Kita."** Opens up why they are not using their real name, and who can see it.
2. **"What would you type in if a program asked for your address?"** The most-broken rule, caught before it happens.
3. **"Show me what the AI helper said to you."** Makes AI feedback something you look at together, not something that happens privately.
4. **"Who do you think can see this project?"** Checks their mental model against reality before they share anything.

Ask them while they are actually on Kita. The answers mean more with the screen in front of you.

Revisit the conversation when something changes: a new school, a first personal device, or a birthday that unlocks a feature.
{% endtab %}
{% endtabs %}

#### The rules, in short

Kita is for learning to code. So keep it friendly:

* **Be kind.** No mean, rude or hurtful messages or code
* **Do not share anything personal.** Not about yourself, and not about anyone else
* **Do not snoop or break things.** No getting into other people's accounts
* **Do not share your password.** Not with anyone except your parent or carer

Break the rules and your teacher or Kita might give you a warning. Your account could be paused.

***

### The full policy

{% hint style="info" %}
The student guide that closes this policy is reproduced at the top of this page, where students will actually find it.
{% endhint %}

This Privacy Policy explains how Kita Education Ltd ("Kita", "we", "us") processes personal data across our products:

* **Part A, School Kita:** Kita used by schools, multi-academy trusts, local authorities, and other education providers.
* **Part B, Open Kita:** the version of Kita freely available on the web to individual teachers and students.
* **Part C, Anonymous AI use:** the Open Kita AI assistant used without an account.

Sections after Parts A–C apply to all products unless stated otherwise.

#### Summary for school IT and data protection teams

|                            |                                                                                                           |
| -------------------------- | --------------------------------------------------------------------------------------------------------- |
| **Hosting location**       | UK / EEA (Ireland, Germany)                                                                               |
| **Student data collected** | Minimal, no full dates of birth                                                                           |
| **AI use**                 | Teacher-controlled; student inputs never used for model training                                          |
| **Cookies**                | Essential, plus analytics to understand how the service is used, with no advertising or student profiling |
| **Contact**                | <hello@getkita.com>                                                                                       |

#### Who we are

**Organisation:** Kita Education Ltd, 65 Alfred Road, London, W2 5EU\
**Email:** <hello@getkita.com>

Kita is designed as an educational tool, built on data minimisation and safeguarding principles.

We design our services in line with the ICO's Age Appropriate Design Code (Children's Code), taking into account children's needs, ages, and stages of development.

#### Our roles under UK GDPR at a glance

| Data                                                | Data Controller                            | Kita's role    |
| --------------------------------------------------- | ------------------------------------------ | -------------- |
| Student data entered by a school (School Kita)      | The school                                 | Data Processor |
| Teacher, administrator, and business contact data   | Kita                                       | n/a            |
| Open Kita self-signup users (teachers and students) | Kita                                       | n/a            |
| Student data entered by an Open Kita teacher        | The teacher / their school or organisation | Data Processor |
| Anonymous AI assistant use                          | Kita                                       | n/a            |

### Part A: School Kita

#### How data protection works

**Schools as Data Controllers.** Where Kita is used by a school, multi-academy trust, local authority, or other education provider, that organisation is the Data Controller for student personal data. The school determines which students are given access to Kita, what student personal data is entered, and how the platform is used for teaching, learning, and assessment.

**Kita as Data Processor.** Kita processes student personal data only on the documented instructions of the school and in accordance with UK GDPR. We do not determine the purposes or means of processing student personal data.

#### What student information we process

When used by schools, the only student personal data processed is:

* A personal identifier (student's name, or a teacher-assigned identifier/pseudonym)
* An age declaration (over or under 13 years)

The over/under-13 age declaration is self-reported, not independently verified, and is used solely to support compliance and safeguarding controls, not profiling or automated decision-making. Kita does not collect or store a student's full date of birth.

Kita does not verify student age; responsibility for age assurance, parental consent, and safeguarding remains with the school as Data Controller.

#### Single sign-on

Where a school signs in via a supported identity provider (for example a Google or Microsoft school account), the identity provider shares the data needed to authenticate the user, typically name, school email address, and a unique identifier. Kita processes this solely on school instructions and only to provide the service.

### Part B: Open Kita

#### How data protection works

Open Kita is freely available on the web to individual teachers and students. For self-signup users, Kita is the Data Controller and processes personal data on the basis of consent and, where applicable, contract.

Where Open Kita is used by a teacher with their students, the teacher (and their school or organisation) is the Data Controller for student personal data they enter, and Kita acts as Data Processor on their instructions. Reasonable measures are taken to ensure teachers are aligned with a school or organisation and are able to assume this responsibility.

#### What information we collect, use and why

We collect some information about you to help us provide our services. We only collect what we need to make sure everything runs smoothly and safely:

* A personal identifier (self-selected pseudonym or display name)
* An email address
* Month and year of birth (never the full date of birth)
* Country
* For users under 18: a parent/guardian's email address

Month and year of birth are collected to apply age-appropriate safeguards. The age declaration is self-reported and is used solely to support compliance and safeguarding controls, not profiling or automated decision-making.

**Parental consent.** Users under 18 must provide a parent/guardian's email address. We email the parent/guardian to give or decline consent. Before consent is given, under-18 users have restricted access: they may not use the sharing or AI features. Users under 13 may not use the platform until parental confirmation is received.

Open Kita does not verify user age using technology; responsibility for age assurance sits with parents/guardians (and teachers, where they have obtained consent), and safeguarding remains with the teacher and school as Data Controller where applicable.

### Part C: Anonymous AI use on Open Kita

This part applies when the Open Kita AI assistant is used without an account. Where Open Kita is used with an account, Part B applies.

#### Summary

* AI processing location: UK (Azure OpenAI, UK South region)
* Anonymous AI use is for ages 13 and over only. Age is self-declared
* We collect only what you type into the assistant, plus limited technical data for security
* We don't ask for personal data, and you shouldn't enter it
* Your prompts are not used to train AI models
* Prompts are stored for 90 days, then deleted

#### Who can use the assistant anonymously

You can use the Open Kita AI assistant without signing in. Before you start using the assistant, you'll be asked to confirm you are aged 13 or over and to agree to this policy. If you are under 13, you cannot use the AI assistant anonymously. Younger users can access AI features through an account with the appropriate parental consent (see Part B).

#### What we collect and why

* **What you type into the assistant.** To generate a response
* **Limited technical information** (IP address, browser type, and access logs). To provide the service, keep it secure, and prevent misuse

We do not ask for your name, email, or date of birth for anonymous use, and we don't link your prompts to an identity. You are strongly discouraged from typing personal information (your own or anyone else's) into the assistant. Kita does not request this information, does not filter it out for you, and is not responsible for personal data you choose to enter.

**Lawful basis:** consent (you actively agree before use). The age confirmation supports safeguarding and compliance controls and is not used for profiling or automated decision-making.

#### How the assistant handles your data

* Messages are processed by Azure OpenAI Service in the United Kingdom (UK South region). Your data stays in the UK.
* Your prompts are not used to train AI models. Azure OpenAI does not use prompts or completions to train, retrain, or improve its models, and does not share them with OpenAI.
* AI responses are advisory only; we do not use AI to make automated decisions about you.
* What you type into the assistant is stored for 90 days on our servers, then deleted. Technical/security logs are kept only as long as needed for security and legal compliance.

Because anonymous use isn't linked to an identity, we usually can't connect a specific prompt back to you to action an individual-rights request. If you have questions or concerns, contact <hello@getkita.com>.

### All products

#### Using generative AI for student feedback

We use closed generative AI tools to help provide feedback on student work. Teachers can disable these features on a course-wide basis.

Kita aligns with the UK Government's Generative AI Product Safety Standards for use in educational settings. Our AI provider is Microsoft Azure OpenAI Service, hosted in the UK (UK South region).

AI features may:

* Generate itemised, formative feedback on code
* Highlight common errors
* Suggest next steps for learning

Safeguards:

* AI systems are restricted to providing feedback within the platform
* Student inputs are never used to train AI models
* Content moderation and safety controls are built in to reduce the risk of harmful or inappropriate outputs
* Use of AI is controllable by the teacher, and student interactions with AI can be supervised by the school
* Access to data is role-based and logged
* Teachers remain responsible for oversight and final judgement
* Kita does not make automated decisions about students that have legal or similarly significant effects under UK GDPR

#### Personalised learning and progress records

To personalise feedback and help teachers support their students, Kita builds and stores learning records derived from platform activity. These may include skill and progress estimates, common errors and misconceptions, engagement patterns, and teacher notes, and may be produced with the help of automated analysis. They are used solely for teaching, learning, and teacher oversight. It is never used for advertising, and never sold or shared for other purposes.

Automated analysis may highlight where a student might need teacher attention; teachers always review this and make any decisions. Kita does not make automated decisions about students that have legal or similarly significant effects under UK GDPR.

Detailed learning records are retained for up to 12 months; aggregated or summarised records may be kept for the duration of the service. Records are deleted on erasure requests, except safeguarding records, which schools and Kita may be legally required to retain.

We may also use anonymised and aggregated data, which can no longer identify any individual, to understand how Kita is used and to improve the platform.

#### Payments

Where a school or user pays for Kita, payments are handled by our payment provider (such as Stripe) or by bank transfer. Payment card details are collected and processed by the payment provider under its own terms and safeguards. Kita never stores full card numbers. We keep billing records (billing contact details, transaction and invoice records) for accounting and legal purposes.

#### User generated content

Kita stores code submissions and text responses so teachers and students can view progress and receive feedback. Users are strongly discouraged from including personal data (names, contact details, sensitive information) in code, responses, or comments. Kita does not request this information and is not responsible for personal data voluntarily included by users.

#### Teacher and administrator data

Kita acts as Data Controller for personal data relating to teachers, administrators, and school staff. This may include:

* Name and work email address
* Role and organisation
* Account credentials
* Support communications

This data is processed to provide the service, manage accounts, ensure security, and communicate essential service information. Where you opt in (over-18s only), we also use your email address to send product updates and marketing communications, and you can unsubscribe at any time. If you contact us or submit a form on our website (for example an enquiry or sign-up form), we use the details you provide to respond and to send any communications you have requested.

#### Cookies and automatic technical information

Kita uses essential cookies required for authentication and platform functionality, together with analytics and monitoring tools that help us understand how the service is used and operate and improve it, for example pages visited, features used, and performance and error data. We do not use behavioural advertising or student profiling cookies.

Like most online services, Kita automatically processes limited technical information (such as IP address, browser type, and access logs) where necessary to provide the service, maintain security, prevent misuse, and comply with legal obligations. This information is not used for advertising, profiling, or tracking students across services.

#### Lawful bases and data protection rights

Under UK GDPR, we must have a lawful basis for processing personal data. We rely on the following, depending on the context:

* **Contract.** Processing necessary to provide the Kita platform and related services
* **Legal obligation.** Processing required to comply with legal and regulatory requirements
* **Legitimate interests.** Limited processing to operate, secure, and improve the service, where this does not override individual rights
* **Consent.** Where explicitly required (for example: Open Kita account signup, use of the platform by under-18s, optional communications, or research participation)

#### Your rights

Under UK GDPR, individuals have the right to:

* **Access.** Request a copy of their personal data
* **Rectification.** Request correction of inaccurate or incomplete data
* **Erasure.** Request deletion of personal data, where applicable
* **Restriction.** Request limits on how data is processed
* **Portability.** Request transfer of personal data
* **Object.** Object to processing based on legitimate interests
* **Withdraw consent.** Where processing is based on consent

We will respond to rights requests without undue delay and within one month.

* Where a school or teacher is the Data Controller, student data rights should be exercised via them
* All other rights requests can be made by contacting <hello@getkita.com>

#### How long we keep information

<figure><img src="https://1176288822-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fjzm9nyD2lhxeWS1B64j9%2Fuploads%2FTYo9wtpJs0pfkSeiCTM7%2Fkita-how-long.png?alt=media&amp;token=4f3808f5-f297-4290-9774-1da0eee3448b" alt=""><figcaption></figcaption></figure>

We do not keep your information forever, only as long as we need it, and then we get rid of it safely.

The retention periods below apply to personal data for which Kita acts as Data Controller. Student personal data processed on school or teacher instructions is retained only as long as required by the controller, or deleted on request. Upon termination of a school's use of Kita, student personal data is deleted or returned to the school within an agreed timeframe, unless retention is required by law. Upon termination of an Open Kita user account, data is deleted unless retention is required by law.

| Data                                      | What it covers                                                                                              | Retention                                                                                                        |
| ----------------------------------------- | ----------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- |
| **Names and contact details**             | Personal details used for service delivery, account management, and marketing (over-18s only for marketing) | 2 years after the last interaction or service provision, unless longer retention is justified                    |
| **Account information**                   | Registration details, login credentials, and account-related data                                           | 2 years after account closure or last activity, unless longer retention is required for legal reasons            |
| **AI conversation data**                  | Messages exchanged with AI features, including the anonymous assistant                                      | 90 days from creation                                                                                            |
| **Learning progress records**             | Derived records supporting personalised feedback and teacher insight                                        | Detailed records up to 12 months; aggregated summaries for the duration of the service                           |
| **Billing and payment records**           | Billing contacts, transactions, and invoices (never full card numbers)                                      | 6 years, in line with UK accounting and tax requirements                                                         |
| **Website user information**              | User journeys, cookies, and analytics data                                                                  | 1 year from collection, unless longer retention is justified for analytics or legal compliance                   |
| **Marketing preferences** (over-18s only) | Consent records and communication preferences                                                               | Until consent is withdrawn or 2 years from last engagement, whichever is sooner                                  |
| **Research data**                         | Data collected for research or archiving purposes                                                           | 6 months from the end of the research project, unless longer retention is required for legal or archival reasons |
| **Safeguarding information**              | Data related to safeguarding and legal compliance                                                           | As required by law, or 6 years, given the sensitive and compliance-driven nature                                 |
| **Queries, complaints, or claims**        | Records of interactions related to disputes or claims                                                       | 3 years from resolution, in line with UK legal and contractual record-keeping practice                           |

#### Who we share information with

We share personal information only when necessary to provide our services.

**Data Processors**

| Processor                               | Location      | Purpose                         |
| --------------------------------------- | ------------- | ------------------------------- |
| Authentication provider                 | EEA (Ireland) | User login and authentication   |
| Hosting/storage provider                | EEA (Ireland) | Secure data hosting and storage |
| Asset hosting                           | UK            | Hosting content and assets      |
| AI/LLM provider, Microsoft Azure OpenAI | UK            | AI feature processing           |
| Database provider                       | EEA (Germany) | Database hosting                |
| Payment provider (such as Stripe)       | US, with SCCs | Payment processing              |
| Analytics providers (as appointed)      | n/a           | Usage and performance analytics |
| Documentation provider                  | US, with SCCs | Usage and performance analytics |

All processors are bound by data processing agreements and appropriate safeguards.

#### International data transfers

Where necessary, we transfer personal information outside the UK with appropriate safeguards in place (UK IDTA / EU Standard Contractual Clauses). Data may be processed in:

* United Kingdom
* European Economic Area (Ireland, Germany)
* United States (with SCCs)
* Singapore (with SCCs)

For further information or to obtain a copy of the safeguards for any of these transfers, contact <hello@getkita.com>.

#### Keeping data safe

We use industry-standard security measures aligned with ISO 27001 principles, including:

* Encryption in transit and at rest
* Access controls and authentication
* Least-privilege, role-based access with logging
* Regular security monitoring and updates

#### How to complain

If you have any concerns about our use of your personal data, you can complain to us using the contact details at the top of this notice. If you remain unhappy after raising a complaint with us, you can complain to the ICO:

Information Commissioner's Office\
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF\
Helpline: 0303 123 1113\
Website: [ico.org.uk/make-a-complaint](https://www.ico.org.uk/make-a-complaint)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.getkita.org/legal-and-support/privacy-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
