Legal / Privacy
Privacy Policy
How we collect, use, share and protect personal data across www.zeta42.com and our learning portals — written to be read, not skimmed past.
01Who we are and what this covers
Zeta42 Academy ("Zeta42", "we", "us") is a training institute providing artificial-intelligence and technology education in the Emirate of Abu Dhabi, United Arab Emirates. We are the data controller for the personal data described in this policy — we decide why and how it is processed.
This policy applies to the public website at https://www.zeta42.com, to the booking and enrolment flows, and to every signed-in area of the platform: the student and parent portal (/learn), the instructor portal (/instructor), and the administrative back office (/admin).
We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its implementing regulations. Where we handle data about people located in the European Economic Area or the United Kingdom, we also apply the standards of the GDPR.
02The personal data we collect
We collect only what a training institute genuinely needs to enrol a learner, teach them, take payment, keep them safe on campus, and issue their certificate. The categories below are exhaustive.
| Where | What we collect | Why |
|---|---|---|
| Account sign-up | Name, email address, password (stored only as a salted hash — never in readable form), and your assigned role. | To create and secure your account and route you to the right portal. |
| Contact & enquiry forms | Name, email, phone number, organisation and the message you write. | To answer your enquiry and keep a record of the conversation. |
| Programme advisor | Grade or age band, interests and the answers you give the guided wizard. | To recommend a suitable pathway. See AI-assisted features. |
| Booking & enrolment | Participant name, email, phone, the cohort chosen, and — for a minor — the linked parent or guardian account. | To hold a seat, confirm the booking and contact you about the class. |
| In-person onboarding | Emergency contact name and phone, media consent, medical consent, and an equipment acknowledgement. | Duty of care while a participant is on campus. |
| Payments | Billing name and email, amount, currency, status and the reference our payment processor returns. | To take payment, issue a receipt and resolve disputes. |
| What | Detail |
|---|---|
| Progress | Which lessons you have opened and completed, and where you left off. |
| Assessment | Quiz attempts, the answers submitted, scores and pass/fail outcomes. |
| Attendance | The date and time of each QR check-in against a scheduled session. |
| Achievements | Certificates issued, and the experience points, badges and stickers earned in our gamified courses. |
| Submitted work | Projects, builds and files you create or upload in the classroom. |
| Instructor records | Lesson notes, uploaded teaching resources and observations recorded by your instructor. |
| What | Detail |
|---|---|
| Session cookie | One strictly-necessary first-party cookie that keeps you signed in. Detailed in our Cookies Policy. |
| Security & audit log | IP address, browser user-agent, timestamp and the action taken, recorded for sign-ins, role changes, payments and other sensitive operations. Cookie and authorisation headers are stripped before the entry is written. |
| Server logs | Standard request logs generated by our web servers and by Cloudflare, which sits in front of the site. |
We do not run any analytics, advertising or tracking technology. There is no Google Analytics, no advertising pixel, no session-recording tool and no third-party marketing tag anywhere on this site.
03Children, students and parents
A substantial part of our work is with school-age students in Grades 4 to 12. We treat their data as our most sensitive category and apply stricter rules to it than the law requires.
- Access is restricted by design. Onboarding records containing a minor's personal details, emergency contacts and consents are visible only to administrators, the instructor assigned to that cohort, and the linked parent or guardian. This restriction is enforced in the application layer, not left to convention.
- No profiling or advertising. We never build marketing profiles from a child's data, never use it for behavioural advertising, and never sell or rent it — to anyone, for any price.
- Media consent is optional and revocable. Photography and video during class happens only where consent was given, and you can withdraw that consent at any time by emailing us. Withdrawal takes effect going forward and we will remove the child from published material where it remains within our control.
- Medical and emergency information is collected solely so we can act appropriately in an emergency, and is disclosed only to those who need it to respond.
- Parents can see and act. A linked guardian can review their child's enrolment, progress, attendance and onboarding record from the parent portal, and can exercise every right in Your rights on the child's behalf.
If you believe a child's data has reached us without proper consent, contact us at [email protected] and we will delete it promptly.
04How we use personal data
- Delivering the service — creating accounts, confirming bookings, running classes, tracking progress, marking quizzes and issuing certificates.
- Payments — taking fees, issuing receipts, processing refunds and handling chargebacks or disputes.
- Communication — sending transactional email such as booking confirmations, payment receipts, schedule changes, class reminders and certificate notifications.
- Safety and duty of care — verifying attendance, and responding appropriately if a participant is unwell or injured on campus.
- Security and fraud prevention — protecting accounts, detecting abuse, and maintaining the audit trail described above.
- Improving what we teach — reviewing aggregated, de-identified progress and assessment data to find where a course is not working.
- Legal and regulatory compliance — meeting accounting, tax and record-keeping obligations in the UAE.
We do not make decisions producing legal or similarly significant effects about you by automated means alone.
05Our legal basis for processing
| Basis | When we rely on it |
|---|---|
| Performance of a contract | Delivering the course you booked, taking payment, issuing your certificate. |
| Consent | Media consent, optional marketing email, and non-essential processing. You may withdraw consent at any time without affecting what was lawful beforehand. |
| Legitimate interests | Securing the platform, preventing fraud, keeping audit records, and improving our courses — balanced against your rights and never applied to a child's data for marketing. |
| Legal obligation | Tax, accounting and other statutory record-keeping. |
| Protection of vital interests | Acting on emergency contact or medical information where someone's health or safety is at risk. |
07AI-assisted features
Some parts of the platform — the programme advisor and the in-course tutor — are powered by Google's Gemini models running on Vertex AI. When you use them, your prompt and the relevant course context are sent to that service to generate a response.
- Your inputs are not used to train third-party foundation models. Vertex AI is used under Google Cloud's enterprise terms, which exclude customer data from model training.
- AI output is a suggestion, not advice. Course recommendations and tutoring responses are reviewed by our academic team where they inform a real decision.
- Please do not paste sensitive personal information — identification numbers, medical details, payment credentials — into an AI chat field. Nothing in these features requires it.
08International transfers
Our application and database are hosted on servers we control. Some of the providers listed above operate globally, so personal data may be processed outside the United Arab Emirates.
Where data leaves the UAE, we transfer it only to a jurisdiction recognised as providing an adequate level of protection, or under contractual safeguards — such as standard contractual clauses — that impose protections equivalent to those required by the PDPL. You can ask us for details of the safeguards applying to a specific transfer.
09How long we keep it
We keep personal data only as long as we need it for the purpose it was collected, then delete or anonymise it.
| Record | Retention period |
|---|---|
| Account and enrolment records | For the duration of the relationship, then 3 years after your last activity. |
| Financial records (payments, receipts, invoices) | 5 years from the end of the relevant tax period, as UAE tax law requires. |
| Learning records and certificates | Retained long-term so we can verify a certificate on request, unless you ask us to remove them. |
| Onboarding, consent and emergency-contact records | 2 years after the last session of the cohort. |
| Contact form and enquiry submissions | 2 years from the last contact. |
| Security and audit logs | 12 months. |
10How we protect it
- All traffic is encrypted in transit over HTTPS/TLS.
- Passwords are stored as salted hashes and are never recoverable in readable form — not even by us.
- Role-based access control governs every portal; staff see only what their role requires, and access to a minor's records is restricted to administrators, the assigned instructor and the linked guardian.
- Stored course files, receipts and certificates are never exposed directly from the storage bucket. Every file is served through our own authenticated, enrolment-checked endpoint, so storage locations and credentials are never visible to a browser.
- Sensitive operations are audited — sign-ins, role changes, impersonation and payment events are logged with actor, timestamp and IP.
- Administrative interfaces are protected by session authentication with bot protection on public forms.
No system is perfectly secure. If a personal data breach occurs that is likely to prejudice your privacy, we will notify the UAE Data Office and affected individuals without undue delay, as the PDPL requires.
11Your rights
Under the PDPL — and, where it applies, the GDPR — you have the following rights over your personal data:
- Access — obtain confirmation that we process your data and receive a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted, subject to records we must keep by law.
- Restriction — ask us to limit processing while a dispute about accuracy or legitimacy is resolved.
- Portability — receive your data in a structured, machine-readable format, or have it transferred to another controller where technically feasible.
- Objection — object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent — withdraw any consent you have given, including media consent, without affecting processing already carried out.
- Complain — lodge a complaint with the UAE Data Office if you believe we have handled your data unlawfully.
To exercise any of these, email [email protected] from the address on your account, or write to us at 91 Al Ftaymi St, Al Nahyan – E25, Abu Dhabi, United Arab Emirates. We respond within 30 days. We may ask you to verify your identity first — particularly for a request concerning a child — so that we do not disclose someone's data to the wrong person. Exercising your rights is free; we may charge a reasonable fee only for a manifestly unfounded or excessive repeat request.
12Marketing communications
Transactional email — booking confirmations, receipts, schedule changes, class reminders, certificate notifications — is part of the service and is sent to everyone with an active enrolment.
Promotional email about new programmes or workshops is sent only with your consent, and every such message carries a working unsubscribe link. We do not send marketing email to a student's own address where that student is a minor; where consent has been given, it goes to the linked parent or guardian.
13Links to other sites
Our website links to third-party sites, including our services arm at build.zeta42.com and our social media profiles. We are not responsible for their content or privacy practices. Read their policies before giving them your data.
14Changes to this policy
We update this policy as the platform develops or the law changes. The "last updated" date at the top always reflects the current version. If a change materially affects how we use your personal data, we will tell you by email or through a notice in the portal before it takes effect.
15Contact us
For any question about this policy, or to exercise a right, contact us at [email protected] or +971 58 587 8942.
Zeta42 Academy · 91 Al Ftaymi St, Al Nahyan – E25, Abu Dhabi, United Arab Emirates
Related policies
Questions about this policy
Write to [email protected] or call +971 58 587 8942. Zeta42 Academy, 91 Al Ftaymi St, Al Nahyan – E25, Abu Dhabi, United Arab Emirates.