Our Privacy Policy
GDPR and EU AI Act
This statement explains how LUDIA processes personal data under the EU General Data Protection Regulation, Regulation (EU) 2016/679 (GDPR), and how LUDIA aligns with the EU Artificial Intelligence Act, Regulation (EU) 2024/1689 (the AI Act). It is written for IT and data-protection professionals. A plain-language summary appears in Section 3.3.
3.1 Data controller
Controller: LUDIA is currently operated by Elizabeth Stark while a formal legal entity is registered. On incorporation, the incorporated entity operating LUDIA will become the controller and this statement will be updated to reflect the registered entity, legal form, and registered office address. Contact for privacy matters: hello@askludia.com. A postal address is available on request via this email. Data Protection Officer: LUDIA has assessed that a DPO is not required under Article 37(1) GDPR. LUDIA is not a public authority, does not carry out regular and systematic monitoring of data subjects on a large scale, and does not process special categories of data as a core activity. Privacy enquiries can be directed to hello@askludia.com. EU representative (Article 27 GDPR): Not applicable. Elizabeth Stark, the current controller, is established in the EU (Germany). This will remain not applicable once the formal entity is incorporated, as it will also be established in Germany.3.2 Scope
This statement covers the LUDIA web-based service (the "Service") accessible at askludia.com. It does not cover third-party websites that link to or from the Service. Where another party (for example, an educational institution) embeds or directs users to LUDIA, that party remains the controller for any data it determines the means and purposes of.
3.3 Plain-language summary
We collect as little personal data as possible.
Your chat messages are stored in your own browser during the session and are automatically deleted when you close the tab. They are never written to LUDIA's servers. If you want to keep a chat, you can download it and re-upload it in a future session — that choice is entirely yours.
Your preferences (such as your chosen theme and text size) are stored in your own browser. We do not hold them on our servers.
When you send a message, it travels to our AI provider so a reply can be generated. The provider processes it in memory and deletes it once the reply is sent. LUDIA does not log or retain message content.
You can ask us for a copy of any personal data we hold about you, ask us to correct it, or ask us to delete it. You can also complain to your national data protection authority.
3.4 Categories of personal data processed
3.4.1 Chat content
The text of your messages and any files you attach. This is passed to the AI model provider in real time so a reply can be generated. The provider processes it in working memory and deletes it once the reply is returned. LUDIA does not write chat content to any server-side storage.
During the active session, chat history is held in your browser's session storage. Session storage is automatically cleared when you close the tab or browser. If you wish to save a conversation, you may download it; re-uploading it in a future session is your choice.
3.4.2 User preferences
Settings you configure within LUDIA — such as your preferred theme or text size — are stored in your browser's local storage. This data never leaves your device and is not accessible to LUDIA's servers. It persists until you clear your browser data.
3.4.3 Analytics
LUDIA uses Vercel Web Analytics to understand aggregate usage of the Service (for example, overall page view counts and coarse visitor geolocation, such as country and region). This tool is cookieless: visitors are identified by a hash generated from the incoming request rather than a persistent identifier or IP address, and that hash is automatically discarded after 24 hours. Vercel does not store information that would allow reconstruction of an individual's browsing session or their re-identification. LUDIA does not configure any custom events that would send chat content, preferences, or other personal data to Vercel Analytics.
3.4.4 Cookies and similar technologies
LUDIA does not use cookies. No first-party cookies, no third-party cookies, no advertising cookies, no cross-site tracking. Vercel Web Analytics (see 3.4.3) is cookieless. See Section 3.14 for details on browser storage.
3.4.5 Data we do not collect
- Server-side logs of chat content. Messages pass through our infrastructure in transit only and are not logged.
- Voice recordings. LUDIA has no speech-to-text or text-to-speech.
- Precise location data.
- Biometric data.
- Account data. LUDIA does not require an account. No account data is collected.
- Special categories under Article 9 GDPR (race, ethnic origin, religion, trade union membership, genetic data, biometric data for identification, health, sex life, sexual orientation, political opinions) unless a user voluntarily enters them as chat content. Such content is still subject to the rules in this statement and is not separately analyzed or retained.
3.5 Purposes and lawful bases of processing (Article 6 GDPR)
| Purpose | Categories of data | Lawful basis |
|---|---|---|
| Generate replies to your chats | Chat content (in transit) | Performance of a contract, Art. 6(1)(b) |
| Operate and deliver the Service | Infrastructure data processed by hosting provider as part of service delivery | Legitimate interests, Art. 6(1)(f) |
| Prevent abuse, fraud, and unlawful use | Infrastructure request patterns (via hosting provider) | Legitimate interests, Art. 6(1)(f); legal obligation, Art. 6(1)(c) where applicable |
| Compliance with legal obligations | All categories as required | Legal obligation, Art. 6(1)(c) |
| Understand aggregate usage of the Service | Anonymised analytics data (page views, via Vercel Web Analytics) | Legitimate interests, Art. 6(1)(f) |
A balancing test (Article 6(1)(f) legitimate-interest assessment) is on file for each processing activity that relies on legitimate interests.
3.6 Recipients and sub-processors (Article 28 GDPR)
LUDIA shares personal data only with the following categories of recipients, each acting as a processor under Article 28 GDPR:
- AI model provider: Google LLC, United States (Google Cloud Vertex AI). Purpose: generate chat replies using the Gemma 4 open-weight model, accessed via Vercel AI Gateway and routed exclusively to Google Cloud Vertex AI — no other AI Gateway provider serves this traffic. Chat content is processed in working memory only. Google does not write inference inputs or outputs to disk, does not use them to train or fine-tune any model, and deletes them once the reply is returned, under a Zero Data Retention agreement Vercel has negotiated with Google for this model. Google Cloud Vertex AI is governed by Google's own Cloud Data Processing Addendum (cloud.google.com/terms/data-processing-addendum), which Google states applies automatically to Google Cloud services. We have asked Vercel to confirm in writing that this addendum, and Google's status as a disclosed sub-processor, extends to traffic routed through AI Gateway; this statement will be updated once that is confirmed.
- Hosting provider: Vercel Inc, United States. Purpose: serve the LUDIA web application, route AI model requests to Google Cloud Vertex AI via Vercel AI Gateway, and provide aggregate, cookieless usage analytics via Vercel Web Analytics (see Section 3.4.3). A Data Processing Addendum is incorporated by reference into Vercel's Terms of Service and is available at vercel.com/legal/dpa.
A current sub-processor list is available on request from hello@askludia.com.
3.7 International transfers (Chapter V GDPR)
Both sub-processors are based in the United States. Transfers rely on the following lawful mechanisms:
- Vercel Inc: Vercel is certified under the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795).
- Google LLC: Certified under the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795). Google's Cloud Data Processing Addendum also incorporates Standard Contractual Clauses under Article 46(2)(c) GDPR as a supplementary transfer mechanism, alongside encryption in transit (TLS 1.2 or higher) and the Zero Data Retention commitment described in Section 3.6. We have asked Vercel to confirm these instruments formally extend to AI Gateway traffic; see Section 3.6.
A Transfer Impact Assessment (Schrems II) is on file for each transfer that relies on SCCs. Copies are available to supervisory authorities on request.
3.8 Retention
| Data type | Retention | Reason |
|---|---|---|
| Chat content (browser session storage) | Cleared automatically when the session ends | Privacy by design; user controls their own data |
| Chat content in transit (Google Vertex AI) | Deleted from memory once the reply is returned. Requests are routed only to Google Cloud Vertex AI under a verified Zero Data Retention agreement; Google does not log or retain prompt or completion content for this traffic. | Zero Data Retention agreement enforced by Vercel AI Gateway |
| User preferences (browser local storage) | Retained until the user clears their own browser data | Required for continuity of user settings |
| Application backups | Encrypted, rotated, fully overwritten within 35 days; no user data is included | Disaster recovery for application code and configuration only |
| Analytics data (Vercel Web Analytics) | Anonymised at collection; not linked to an individual, so standard personal-data retention limits do not apply. See Vercel's own retention terms for the underlying aggregate data. | Understand aggregate usage of the Service |
3.9 Security measures (Article 32 GDPR)
- TLS 1.2 or higher for all data in transit.
- No user data is written to durable server-side storage, minimizing the attack surface for data-at-rest exposure.
- Role-based access control, principle of least privilege, and quarterly access reviews.
- Multi-factor authentication for all staff access to production systems.
- Regular vulnerability scanning, dependency monitoring, and patch management.
- Centralized audit logging with tamper-evident storage.
- Documented incident response plan, with a 72-hour breach notification process to the supervisory authority under Article 33 GDPR, and notification to affected data subjects without undue delay where required by Article 34.
- Annual review of technical and organizational measures.
3.10 Your rights under GDPR
You have the following rights with respect to your personal data:
- Access (Article 15): confirmation of processing and a copy of your personal data.
- Rectification (Article 16): correction of inaccurate or incomplete data.
- Erasure (Article 17), also known as the right to be forgotten.
- Restriction (Article 18): limitation of processing in defined circumstances.
- Data portability (Article 20): receipt of your data in a structured, commonly used, machine-readable format and, where technically feasible, direct transmission to another controller.
- Object (Article 21): object to processing based on legitimate interests.
- Not be subject to automated decision-making (Article 22) with legal or similarly significant effects. LUDIA does not make such decisions about you. See Section 3.13.
- Withdraw consent (Article 7(3)) at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact hello@askludia.com. We respond within one month, extendable by a further two months for complex or numerous requests, per Article 12(3) GDPR. We may need to verify your identity before responding.
Note that because LUDIA does not retain chat content on its servers, some rights (such as access and erasure of chat content) may not require action from us — that data already exists only in your own browser and is under your direct control.
3.11 Right to lodge a complaint (Article 77 GDPR)
You may lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, place of work, or the place where you believe an infringement has taken place. A directory of national data protection authorities is maintained by the European Data Protection Board at edpb.europa.eu.
3.12 Children's data
LUDIA is intended for use by educators and other adults, and is not directed at children. Our AI model provider's own terms require users to be 18 or older, so visitors are asked to confirm they are 18 or older before using the Service (see Section 3.14 for how this confirmation is stored). We do not knowingly collect personal data from anyone under 18.
We strongly recommend that educators do not enter personally identifying information about students into LUDIA.
Share the question, not the student. If the words on your screen would let someone identify a real child or location, remove them before you press send.
3.13 Automated processing and profiling (Article 22 GDPR)
LUDIA uses a large language model to generate chat replies. This constitutes automated processing under GDPR. It does not, however, constitute automated decision-making with legal or similarly significant effects within the meaning of Article 22(1), because:
- LUDIA produces informational and pedagogical replies, not decisions about the user.
- LUDIA does not assign you a score, grant or deny a request, or take any action with legal effect on you.
- LUDIA does not build a persistent profile across sessions.
If LUDIA ever introduces processing that meets the Article 22 threshold, this statement will be updated and the safeguards required by Article 22(3) GDPR will be provided, including the right to obtain human intervention, to express a point of view, and to contest the decision.
3.14 Cookies and similar technologies
LUDIA does not set cookies. The Service does not place any first-party or third-party cookies on the user's device. LUDIA uses one cookieless analytics tool, Vercel Web Analytics (described in 3.4.3), which identifies visitors via a request hash rather than a persistent identifier or cookie. No advertising, marketing, fingerprinting, or cross-site tracking technologies are used.
Because no cookies are stored, no cookie consent banner is displayed. Article 5(3) of the ePrivacy Directive (Directive 2002/58/EC, as amended by Directive 2009/136/EC) requires consent only where information is stored on, or accessed from, a user's device. Vercel Web Analytics does not store or access anything on the user's device — it derives its hash from the incoming request itself — so it falls outside this requirement. LUDIA separately uses three forms of browser storage, all strictly necessary and covered by the Article 5(3) exemption:
- Session storage holds your chat history for the duration of your active session and is automatically cleared when you close the tab or browser. This storage is used solely to display your conversation while the tab is open.
- Local storage holds your preferences — such as your chosen theme and text size — so that your settings are remembered between visits. This data never leaves your device.
- Local storage (age confirmation) records that you confirmed you are 18 or older, so you are not asked again on later visits. This is a simple yes/no record with no other information attached, and never leaves your device.
None of these forms of storage is used for tracking, profiling, or analytics purposes, and none involves data being transmitted to LUDIA's servers.
3.15 EU AI Act compliance (Regulation (EU) 2024/1689)
The EU AI Act entered into force on 1 August 2024 and applies in phases through 2026 and 2027. LUDIA is classified and operated as follows.
3.15.1 System classification
- LUDIA is an AI system intended to interact directly with natural persons (Article 50(1) AI Act). Users are informed they are interacting with an AI system through this statement and through in-product notices.
- LUDIA generates synthetic text. Under Article 50(2), outputs are marked, where technically feasible and reliable, in a machine-readable format detectable as artificially generated.
- LUDIA is not a high-risk AI system within the meaning of Article 6 and Annex III of the AI Act. It is not deployed for biometric identification, critical infrastructure, education that determines access or admissions, employment decisions, access to essential services, law enforcement, migration, the administration of justice, or democratic processes.
- LUDIA is built on the Gemma 4 open-weight model, hosted and operated by Google LLC via Google Cloud Vertex AI, accessed through Vercel AI Gateway. As a deployer, LUDIA complies with the deployer obligations in Articles 26 and 50.
3.15.2 Prohibited practices (Article 5)
LUDIA does not engage in any AI practice prohibited by Article 5, including:
- Subliminal or purposefully manipulative techniques.
- Exploitation of vulnerabilities of specific groups.
- Social scoring by public or private actors.
- Predictive policing based solely on profiling.
- Untargeted scraping of facial images for facial recognition databases.
- Emotion inference in the workplace or in educational institutions, except for medical or safety reasons.
- Biometric categorization to infer sensitive attributes.
- Real-time remote biometric identification in publicly accessible spaces for law enforcement.
In particular, LUDIA does not perform emotion inference in educational contexts.
3.15.3 Transparency obligations (Article 50)
LUDIA informs users at the point of first interaction that they are interacting with an AI system. AI-generated text outputs are marked as such in metadata where the channel supports it.
3.16 Data Protection Impact Assessment (Article 35 GDPR)
A Data Protection Impact Assessment has been completed for LUDIA. Headline conclusions:
- Risk of profiling: low. No persistent profile is built across sessions.
- Risk of sensitive-data exposure: low. Chat content is not retained on LUDIA servers and exists only in the user's own browser during the session.
- Risk of re-identification from logs: low. LUDIA does not log chat content server-side.
- Risk of unlawful third-country transfers: addressed through the EU–US Data Privacy Framework (Vercel, and Google in its own capacity) and Standard Contractual Clauses under Google's Cloud Data Processing Addendum. Written confirmation that these instruments formally extend to AI Gateway traffic has been requested from Vercel and is pending (see Section 3.6).
The DPIA is available to supervisory authorities on request.
3.17 Changes to this statement
This statement will be updated when our practices change, when EU law requires, or at the next scheduled review. Material changes will be announced at askludia.com/policy-updates. Where we have your contact details and a change is significant, we will notify you by email at least 30 days before it takes effect.
References
Council of the European Union & European Parliament. (2002). Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector. Official Journal of the European Communities, L 201, 37–47. https://eur-lex.europa.eu/eli/dir/2002/58/oj
Council of the European Union & European Parliament. (2009). Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 [amending Directive 2002/58/EC]. Official Journal of the European Union, L 337, 11–36. https://eur-lex.europa.eu/eli/dir/2009/136/oj
Council of the European Union & European Parliament. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). Official Journal of the European Union, L 119, 1–88. https://eur-lex.europa.eu/eli/reg/2016/679/oj
Council of the European Union & European Parliament. (2019). Directive (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019 on the accessibility requirements for products and services. Official Journal of the European Union, L 151, 70–115. https://eur-lex.europa.eu/eli/dir/2019/882/oj
Council of the European Union & European Parliament. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L series, 12 July 2024. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
European Commission. (2021). Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679. Official Journal of the European Union, L 199, 31–61. https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
European Commission. (2023). Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU–US Data Privacy Framework. Official Journal of the European Union, L 231, 118–229. https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj
European Data Protection Board. (n.d.). Guidelines, recommendations, best practices. https://www.edpb.europa.eu/our-work-tools/general-guidance/guidelines-recommendations-best-practices_en
World Wide Web Consortium. (2023, October 5). Web content accessibility guidelines (WCAG) 2.2 (W3C Recommendation). https://www.w3.org/TR/WCAG22/
Last reviewed: 16 July 2026. Next scheduled review: 16 July 2027.
