Vicky — Privacy Policy

Last updated: 5 September 2026


1. Who Is Responsible for Your Data? (Controller vs. Processor)

Vicky is an enterprise / institutional education platform (B2B). How GDPR roles are assigned matters for contracts and university legal reviews.

1.1 Your university or college is typically the Data Controller

For personal data relating to students, faculty, and staff who access the platform under an institutional subscription, the educational institution that contracted for Vicky (the Data Controller) decides why and how that data is used for its educational and administrative purposes. The institution determines enrollment, cohorts, courses, assignments, and which authorized staff may view progress and analytics.

1.2 Pi tech is the Data Processor

Π ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ (English trade name: Pi Private Company), VAT EL801289442, Greece — referred to in this policy as "Pi tech," "we," "us," or "our" — acts as Data Processor under Article 28 GDPR. We provide the Vicky software, hosting stack, and subprocessors only to process personal data on behalf of the institution and in accordance with our agreement with that institution (including the applicable Data Processing Agreement).

We do not use institutional user data to make independent decisions about students’ academic standing; grading and academic decisions remain with the institution.

Registered office / correspondence: K. Karamanli 67, 546 42 Thessaloniki, Greece

GEMI (General Commercial Registry) number: 153620048000

Processor / privacy contact (technical and contractual inquiries):
Email: privacy@pi-tech.gr
Phone: +30 23120 02793

Institutional Data Protection Officers and legal teams may also request our sub-processor list, standard contractual clauses, and DPA documentation via this address.


2. About This Policy

This Privacy Policy explains how Pi tech, as processor, processes personal data when you use the Vicky platform on behalf of your institution (the controller).

The Vicky platform (the "Service") consists of:

  • The Vicky web portal (for instructors and administrators) — currently offered in production
  • The Vicky VR application (Meta Quest) — currently offered in production
  • The Vicky mobile application (iOS and Android) — not yet released. It is described here so that this policy applies from the day it is published; until then, no processing takes place through it.

This single privacy policy covers these surfaces because they share the same accounts, tenant-scoped data infrastructure, and processing arrangements with subscribing institutions.

This policy is provided in accordance with the EU General Data Protection Regulation (GDPR — Regulation 2016/679), the Greek Data Protection Law (Law 4624/2019), and other applicable data protection law. Determination of the lawful basis for processing personal data about students and staff is primarily the responsibility of your institution as controller; this document describes our processing obligations as processor and transparency for end users.


3. Information We Process (on Behalf of Your Institution)

The following describes categories of personal data processed through the Service under the subscribing institution’s instructions and configuration. Your institution remains responsible for the lawfulness of the processing it instructs us to perform.

3.1 Account Information

When your institution registers you or you create an account within a tenant, we process:

  • Email address — used for authentication and communication
  • Full name — used for personalization and display within the platform
  • Institutional affiliation — university, department
  • Role — student, professor, or administrator

3.2 Usage and Training Data

When you use the Service to complete labs, assessments, and training exercises, we process:

  • Lab attempt data: start and end times, duration, completion status, number of hints used, resets, and critical errors encountered
  • Step-by-step interaction events: which steps were completed, timestamps, and interaction types within a lab scenario
  • Assessment responses: answers submitted during quizzes and assessments, scores, and completion times
  • Assignment status: due dates, submission status, and progress tracking

3.3 AI Interaction Data

When you interact with VICKY, our AI teaching assistant, we process:

  • Chat messages you send to VICKY (text queries about lab content)
  • Lesson engagement data: which slides you viewed, narration playback events, and quiz responses within AI-generated lessons
  • AI-generated content metadata: lesson identifiers, generation timestamps, and content versions

We do not use your chat messages or training data to train any AI model, and our providers are contractually barred from doing so. Prompts may be retained by our AI provider for up to 30 days for abuse monitoring, and cached by us for up to 24 hours to improve response times. Neither is used to train a model.

3.4 Device and Technical Information

The Service automatically processes:

  • Device type: mobile (Android/iOS), VR headset (Meta Quest), or web browser (when using the portal)
  • Operating system and version
  • Application version
  • Network connectivity status (online/offline, for telemetry synchronization)
  • Crash and error reports (non-personally-identifiable diagnostic data)

We do not collect device advertising identifiers (IDFA/GAID).

3.5 Camera Data

The Vicky mobile application accesses your device camera exclusively for augmented reality (AR) lab experiences. Camera frames are processed locally on your device by the AR engine for real-time scene rendering. Camera data is never recorded, stored, transmitted to our servers, or shared with third parties.

Camera access requires your explicit device-level permission, which you can revoke at any time through your device settings.

3.6 Feedback and Support Data

If you voluntarily submit feedback or bug reports through the app, we process:

  • The text of your feedback
  • An optional screenshot (only if you choose to attach one from your photo library)
  • Device and app version information for debugging purposes

4. Legal Basis for Processing

Article 6 GDPR — role of the controller: For personal data of students and staff, the subscribing institution (Data Controller) determines the applicable lawful basis (e.g. performance of a contract with the data subject, legitimate interests of the institution, legal obligation, or consent where required). Pi tech does not substitute for the institution’s assessment; our Data Processing Agreement records that we process only on documented instructions from the controller, except where EU or Member State law requires us to process data independently (e.g. court order).

Article 28 GDPR — processor obligations: Pi tech processes personal data necessary to deliver the subscribed Vicky functionality: authentication, lab delivery, assessments, telemetry, analytics visible to authorized institutional users, AI features configured by the institution, security, and support.

The table below describes typical purposes and common lawful bases that institutions rely on when using education platforms of this kind. It is informational for transparency and DPO review; your institution’s privacy notices and contracts govern the definitive legal basis for your data.

Typical processing purposeTypical basis chosen by institutionsGDPR Article (indicative)
Account creation, authentication, lab and assessment deliveryPerformance of contract / legitimate tasks of the institutionArt. 6(1)(b) / (e)
Progress reports and analytics for authorized instructorsLegitimate interests of the institution (education oversight) or contractArt. 6(1)(f) / (b)
AI features (VICKY) as part of the subscribed serviceAs determined by the controller in its agreements and noticesPer controller
Platform reliability, security, abuse preventionLegitimate interests (security) and processor obligationsArt. 6(1)(f); Art. 32
Optional feedback screenshot attachmentConsent (where the institution or we collect consent for that specific act)Art. 6(1)(a)

Objections and consent: To object to processing or to withdraw consent for processing where the institution relies on consent, contact your institution’s data protection contact in the first instance. You may also contact privacy@pi-tech.gr so we can route the request to the appropriate controller or assist under Art. 28(3)(e).


5. Special Categories of Data

The Service is an educational training platform for health science students. While the platform delivers medical training content (e.g., anatomy labs, clinical procedures), the training data we collect relates to educational performance and engagement, not to the health status of any individual.

We do not process special categories of personal data as defined in Article 9 of the GDPR (including health data, biometric data, or genetic data). The AR camera data is processed locally on your device and never reaches our servers.

If the nature of a specific lab scenario were to involve the processing of special category data in the future, we would obtain explicit consent and update this policy before such processing begins.


6. How We Use Your Information

On behalf of the Data Controller (your institution), we process personal data for the following purposes, within the scope of our subscription and DPA:

  • Provide the Service: authenticate your account, deliver lab and assessment content, track assignment progress, and personalize your learning experience as configured by the institution
  • Generate analytics and progress reports: make aggregated and individual training metrics available to authorized professors and administrators of your institution through the platform
  • Improve the platform: analyze usage patterns in aggregate to improve reliability and UX of the software (not for unrelated marketing)
  • Deliver AI-powered features: provide VICKY features as subscribed and configured (e.g. narration, chat, lessons)
  • Ensure platform security and integrity: detect and prevent misuse, enforce tenant isolation and role-based access, maintain security
  • Communicate operational updates: service-related notifications tied to assignments and platform operation
  • Respond to support requests: address feedback and bug reports you submit through the channels provided

We do not sell personal data or use institutional user data for third-party advertising or marketing profiling unrelated to the subscribed educational Service.


7. How Personal Data Is Made Available or Entrusted

We do not sell, rent, or trade personal data. As processor, we do not “share” student data for unrelated commercial purposes. Data flows as follows:

7.1 Visibility Within Your Institution (Controller’s Organization)

Lab completions, assessment scores, progress metrics, and related analytics are available only to authorized users (e.g. instructors and administrators) within your institution’s tenant, as configured by the controller. This visibility is the core function of the platform for education oversight. The institution defines who may see which data; our role is to enforce tenant isolation and role-based access in the product.

7.2 Sub-processors Engaged by Pi tech (Processor’s Processors)

Pi tech uses the following sub-processors to host and operate the Service on behalf of our institutional customers. Each relationship is governed by Article 28 GDPR and our agreements with the controller; sub-processors are bound by contract to process data only on documented terms:

ProcessorLocationPurposeData ProcessedDPA in Place
Supabase Inc.EU (Frankfurt, Germany)Database hosting, authentication, serverless functions, file storageAll platform dataYes
Microsoft Ireland Operations Ltd (Azure OpenAI Service)EU Data Boundary — Frankfurt, GermanyPrimary AI generation for VICKYChat messages, lesson context — see §3.3 for retentionYes
Google LLC (Gemini API)USA (EU SCCs)Secondary AI generation for specific featuresChat messages, lesson context — see §3.3 for retentionYes
ElevenLabs Inc.USA (EU SCCs)Text-to-speech generation for VICKY narrationNarration text and the student’s first name (for name-pronunciation clips) — processed transiently, not storedYes
Apple Inc.USA (EU adequacy)iOS app distribution, crash reportingDevice identifiers, crash logsPlatform terms
Google LLC (Play Store)USA (EU adequacy)Android app distribution, crash reportingDevice identifiers, crash logsPlatform terms
Unity TechnologiesUSA (EU SCCs)AR/VR runtime engine, content delivery network (CCD)Device type, content download metadataPlatform terms

We maintain an up-to-date list of sub-processors for institutional customers and their DPOs. Request the current list at privacy@pi-tech.gr.

7.3 Law Enforcement or Regulatory Authorities

We may disclose information where required by EU or Member State law, by a lawful request, or to protect vital interests, consistent with Article 28(3)(a) and our obligations as processor. Where feasible, we will direct such requests to the Data Controller unless prohibited by law.

7.4 Business Transfers

If Pi tech undergoes a merger, acquisition, or asset sale, processing of personal data will continue only under terms that preserve controller and data subject rights, and institutional customers will be notified as required by contract and law. End users may receive notice where appropriate.


8. Your Rights Under the GDPR

As a data subject, your rights under the GDPR (access, rectification, erasure, restriction, portability, objection, etc.) are exercised primarily in relation to the Data Controlleryour institution — which determines the purposes of processing.

RightHow to exercise (typical)
Access, rectification, erasure, restriction, portability, objectionContact your institution’s data protection office or the contact given in your university’s notices first.
Assistance from Pi techEmail privacy@pi-tech.gr. We will acknowledge the request and, as processor, assist the controller in responding within a reasonable time, or forward your request where contractually required.
Withdraw consent (where consent is the basis)Through your institution and any in-app controls offered for optional features.

Response timelines follow Article 12 GDPR as implemented by the controller; Pi tech supports timely responses as required under Article 28(3)(e).

Verification: The controller (and Pi tech when assisting) may request identity verification to prevent unauthorized disclosure.

Complaints to a supervisory authority: You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement — often your institution’s lead supervisory authority or the Hellenic Data Protection Authority (HDPA) for processing in Greece:

Hellenic Data Protection Authority (HDPA)
Kifisias 1-3, 115 23 Athens, Greece
Phone: +30 210 6475600
Website: https://www.dpa.gr
Email: contact@dpa.gr


9. Automated Decision-Making and Profiling

This section describes the automated processing the Service performs. Whether any of it produces legal effects concerning you, or similarly significantly affects you within the meaning of Article 22 of the GDPR, depends on how your institution — as controller — uses the results, for example whether a quiz score carries academic weight. Where it does, the rights described in Section 8 apply, and we support your institution in honouring them.

  • Automated grading of quizzes: Quiz answers are scored by the platform automatically, with no human in the loop. The comparison is deterministic — each answer is matched against the answer key your instructor set for that question — and no AI model takes part in producing the score. The platform also computes a pass or fail result against the passing threshold set for that assessment. The platform does not currently provide instructors with a way to change a score once it has been recorded. If you believe a score is wrong, contact your instructor or your institution, who can raise it with us.

  • AI-derived learning profile (profiling): VICKY uses an AI model to derive, from your conversations and training activity, a per-topic picture of what you appear to have understood and where you appear to be struggling — including an estimated mastery level, a confidence score, key facts, and weak areas. This picture is stored against your account and is fed back into VICKY's prompt, so it shapes the guidance VICKY gives you next. This is profiling within the meaning of Article 4(4) of the GDPR. It is not used to grade you and does not contribute to the score described above. Within your institution this picture is available to administrators; your instructors do not have access to it. Our platform staff can access it for support and quality purposes.

    VICKY also derives a second, separate profile about how you learn rather than what you know — an estimated expertise level, a preferred learning style, the topics you ask about, and simple measures of how you use VICKY (questions per session, how often you follow up or ask for clarification). It is used to pitch VICKY's explanations at the right level. Unlike the picture above, this one IS visible to your instructors within your institution, because it is pedagogically useful to them; it contains no assessment of your competence and never affects a grade.

  • AI-generated content: VICKY generates lessons and chat responses using AI models. These outputs are educational content, not decisions about you.

  • Progress analytics: The platform computes metrics (completion rates, practice frequency) from your training data. These metrics inform your instructors.

  • Entitlement and access checks: The platform automatically verifies your enrollment and role to determine which content you can access. This is a contractual necessity, not a decision based on profiling.


10. Data Retention

Pi tech retains personal data only as long as necessary to provide the subscribed Service and in line with the controller’s instructions and our DPA, unless a longer period is required by law. Institutional customers may define certain retention needs in their agreement; the table below reflects current platform defaults:

Data TypeRetention PeriodJustification
Account data (name, email, role)Retained while account is active; deleted within 30 days of deletion request or account deactivationContractual necessity
Training attempt data (lab completions, scores)Duration of enrollment plus 2 academic yearsAcademic record requirements and institutional compliance
Step-level interaction events (detailed in-lab telemetry)90 days, then automatically purgedPlatform improvement; limited retention by design
Session metadata (session-level details)Redacted after 365 days (detailed session data removed; aggregate metrics retained)Analytics accuracy with minimal data retention
AI chat messagesStored on your account so you can return to them. Deleted with the conversation, and with your account (see §10). A platform-wide maximum age is being set; your institution may agree a different period with us in its DPA.Continuity of learning; your institution's retention terms
Feedback reports1 year after submissionSupport resolution tracking
Crash and diagnostic logs90 daysDebugging and platform stability

After the retention period expires, data is either permanently deleted or irreversibly anonymized so that it can no longer be associated with you.


11. Data Security

Pi tech implements technical and organizational measures appropriate to the risk, in accordance with Article 32 GDPR and our obligations as processor:

Technical measures:

  • Encryption in transit: all communications between your device and our servers use TLS 1.2 or higher
  • Encryption at rest: Supabase encrypts stored data at rest; authentication tokens on your device are stored in the secure enclave (iOS Keychain / Android Keystore)
  • Row-Level Security (RLS): database-level policies enforce that each user can only access data they are authorized to see
  • Tenant isolation: each institution's data is logically separated at the database level, preventing cross-tenant data access
  • Access controls: role-based access control (RBAC) ensures that students, professors, and administrators have access only to the data relevant to their role

Organizational measures:

  • Principle of least privilege: internal access to production data is restricted to authorized personnel only
  • Data Processing Agreements: all sub-processors are bound by DPAs in accordance with Art. 28 GDPR
  • Regular security reviews: we conduct periodic reviews of our security measures and access controls
  • Incident response: we maintain a data breach response procedure (see Section 12)

12. Data Breach Notification

As processor, if we become aware of a personal data breach affecting data we process on behalf of a controller, we will:

  1. Notify the affected Data Controller (the institution) without undue delay after becoming aware of the breach, in accordance with Article 33(2) and Article 28(3)(f) GDPR, providing information required to enable the controller to meet its Article 33(1) obligations toward supervisory authorities
  2. Support the controller in assessing whether the supervisory authority and/or data subjects must be notified under Articles 33 and 34 GDPR
  3. Document the breach and remediation measures as required by Article 33(5) and our DPA

Controllers are responsible for notifying the competent supervisory authority within 72 hours where required, and for communicating to affected data subjects when Article 34 applies. Pi tech will not unilaterally replace the controller’s statutory role in those notifications.


13. International Data Transfers

Your personal data is primarily stored and processed within the European Economic Area (EEA), specifically in Supabase's EU data center in Frankfurt, Germany (eu-central-1).

Where data is transferred to processors outside the EEA (see Section 7.2), we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR:

  • Standard Contractual Clauses (SCCs): adopted by the European Commission (Decision 2021/914), supplemented with a Transfer Impact Assessment (TIA) where required
  • Adequacy decisions: where the European Commission has determined that the recipient country ensures an adequate level of data protection
  • Additional technical measures: including encryption in transit, pseudonymization where feasible, and contractual restrictions on onward transfers

You may request a copy of the relevant transfer safeguards by contacting privacy@pi-tech.gr.


14. Cookies and Similar Technologies

Web Portal

The Vicky web portal uses strictly necessary cookies only:

  • Authentication cookies: maintaining your login session
  • Preference cookies: storing your language and display settings

These cookies are exempt from the consent requirement under the ePrivacy Directive (Directive 2002/58/EC, Art. 5(3)) because they are strictly necessary for the provision of the Service.

We do not use analytics cookies, advertising cookies, third-party tracking pixels, or similar tracking technologies on the web portal.

Mobile and VR Applications

The mobile and VR applications do not use cookies or web-based tracking technologies. Usage telemetry is collected as described in Section 3.2 and processed under the legal bases described in Section 4.


15. Children's Privacy

The Service is designed for university-level health science education and is not directed at children. We do not knowingly collect personal information from individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction).

If you are a parent or guardian and believe that your child has provided personal information to us, please contact us at privacy@pi-tech.gr. If we become aware that we have collected personal data from a child below the applicable age without valid parental consent, we will take steps to delete that information promptly.


16. Links to Third-Party Services

The Service may contain links to third-party websites or services (for example, institutional websites or external educational resources). We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party service you access.


17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

  • For minor changes: we will update the "Last updated" date at the top of this page.
  • For material changes: we will provide a prominent notice within the Service (such as an in-app notification or banner) and, where required, seek your consent before the changes take effect.

We encourage you to review this Privacy Policy periodically. The current version will always be available at https://vickylabs.ai/privacy-policy.


18. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the Hellenic Republic (Greece), including:

  • Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR)
  • Greek Law 4624/2019 (transposing the GDPR and Directive 2016/680 into national law)
  • Directive 2002/58/EC (ePrivacy Directive) as transposed into Greek law

Any disputes arising from or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Thessaloniki, Greece.


19. Contact Us

Institutional customers (controllers): For DPA, sub-processor, transfer mechanism, or breach coordination inquiries — privacy@pi-tech.gr.

End users (students, staff): For rights requests, contact your institution’s data protection contact first; you may copy privacy@pi-tech.gr so Pi tech can assist the controller as processor.

Pi Private Company (Π ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ) — VAT EL801289442
Processor / privacy contact: privacy@pi-tech.gr
Phone: +30 23120 02793
Registered office: K. Karamanli 67, 546 42 Thessaloniki, Greece
GEMI number: 153620048000
Website: https://pi-tech.gr

Supervisory Authority: Hellenic Data Protection Authority (HDPA) Kifisias 1-3, 115 23 Athens, Greece Phone: +30 210 6475600 Email: contact@dpa.gr Website: https://www.dpa.gr


Appendix A: Additional Rights for Users in Other Jurisdictions

California (USA) — California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)

If you are a California resident using the Service under an institutional subscription, your school or university is typically the business responsible for CCPA notices and rights for student data; Pi tech acts as a service provider / processor under contract. You may exercise CCPA rights through your institution and via privacy@pi-tech.gr for requests we can fulfill as service provider.

Rights (summary): know, delete, correct, opt out of sale/sharing (we do not sell personal information or share it for cross-context behavioral advertising), non-discrimination.

Categories of personal information that may be processed through the Service (CCPA categories): identifiers (name, email), education information, internet/electronic network activity (usage telemetry), professional or employment information (institutional role). Precise geolocation is not collected for tracking.

Sale / sharing: We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

United Kingdom — UK GDPR

If you are in the United Kingdom, your rights under the UK General Data Protection Regulation (UK GDPR) mirror those described in Section 8 of this policy. The competent supervisory authority for UK users is the Information Commissioner's Office (ICO): https://ico.org.uk.

Brazil — Lei Geral de Proteção de Dados (LGPD)

If you are in Brazil, your rights under the LGPD are substantially similar to those described in Section 8. The competent authority is the Autoridade Nacional de Proteção de Dados (ANPD).


This privacy policy covers all Vicky surfaces: the web portal and the VR application (Meta Quest), both currently in production, and the mobile application (iOS and Android), which is not yet released.

*Pi tech acts as Data Processor under Article 28 GDPR for personal data processed in the Service on behalf of subscribing educational institutions, which act as Data Controllers for their students’ and staff data. This document does not replace the institution’s own privacy notices or the parties’ Data Processing Agreement.*