Legal / Privacy

Privacy Policy

How we collect, use, share and protect personal data across www.zeta42.com and our learning portals — written to be read, not skimmed past.

01Who we are and what this covers

Zeta42 Academy ("Zeta42", "we", "us") is a training institute providing artificial-intelligence and technology education in the Emirate of Abu Dhabi, United Arab Emirates. We are the data controller for the personal data described in this policy — we decide why and how it is processed.

This policy applies to the public website at https://www.zeta42.com, to the booking and enrolment flows, and to every signed-in area of the platform: the student and parent portal (/learn), the instructor portal (/instructor), and the administrative back office (/admin).

We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its implementing regulations. Where we handle data about people located in the European Economic Area or the United Kingdom, we also apply the standards of the GDPR.

02The personal data we collect

We collect only what a training institute genuinely needs to enrol a learner, teach them, take payment, keep them safe on campus, and issue their certificate. The categories below are exhaustive.

Data you give us directly
WhereWhat we collectWhy
Account sign-upName, email address, password (stored only as a salted hash — never in readable form), and your assigned role.To create and secure your account and route you to the right portal.
Contact & enquiry formsName, email, phone number, organisation and the message you write.To answer your enquiry and keep a record of the conversation.
Programme advisorGrade or age band, interests and the answers you give the guided wizard.To recommend a suitable pathway. See AI-assisted features.
Booking & enrolmentParticipant name, email, phone, the cohort chosen, and — for a minor — the linked parent or guardian account.To hold a seat, confirm the booking and contact you about the class.
In-person onboardingEmergency contact name and phone, media consent, medical consent, and an equipment acknowledgement.Duty of care while a participant is on campus.
PaymentsBilling name and email, amount, currency, status and the reference our payment processor returns.To take payment, issue a receipt and resolve disputes.
Data generated as you learn
WhatDetail
ProgressWhich lessons you have opened and completed, and where you left off.
AssessmentQuiz attempts, the answers submitted, scores and pass/fail outcomes.
AttendanceThe date and time of each QR check-in against a scheduled session.
AchievementsCertificates issued, and the experience points, badges and stickers earned in our gamified courses.
Submitted workProjects, builds and files you create or upload in the classroom.
Instructor recordsLesson notes, uploaded teaching resources and observations recorded by your instructor.
Data collected automatically
WhatDetail
Session cookieOne strictly-necessary first-party cookie that keeps you signed in. Detailed in our Cookies Policy.
Security & audit logIP address, browser user-agent, timestamp and the action taken, recorded for sign-ins, role changes, payments and other sensitive operations. Cookie and authorisation headers are stripped before the entry is written.
Server logsStandard request logs generated by our web servers and by Cloudflare, which sits in front of the site.

We do not run any analytics, advertising or tracking technology. There is no Google Analytics, no advertising pixel, no session-recording tool and no third-party marketing tag anywhere on this site.

03Children, students and parents

A substantial part of our work is with school-age students in Grades 4 to 12. We treat their data as our most sensitive category and apply stricter rules to it than the law requires.

  • Access is restricted by design. Onboarding records containing a minor's personal details, emergency contacts and consents are visible only to administrators, the instructor assigned to that cohort, and the linked parent or guardian. This restriction is enforced in the application layer, not left to convention.
  • No profiling or advertising. We never build marketing profiles from a child's data, never use it for behavioural advertising, and never sell or rent it — to anyone, for any price.
  • Media consent is optional and revocable. Photography and video during class happens only where consent was given, and you can withdraw that consent at any time by emailing us. Withdrawal takes effect going forward and we will remove the child from published material where it remains within our control.
  • Medical and emergency information is collected solely so we can act appropriately in an emergency, and is disclosed only to those who need it to respond.
  • Parents can see and act. A linked guardian can review their child's enrolment, progress, attendance and onboarding record from the parent portal, and can exercise every right in Your rights on the child's behalf.

If you believe a child's data has reached us without proper consent, contact us at [email protected] and we will delete it promptly.

04How we use personal data

  • Delivering the service — creating accounts, confirming bookings, running classes, tracking progress, marking quizzes and issuing certificates.
  • Payments — taking fees, issuing receipts, processing refunds and handling chargebacks or disputes.
  • Communication — sending transactional email such as booking confirmations, payment receipts, schedule changes, class reminders and certificate notifications.
  • Safety and duty of care — verifying attendance, and responding appropriately if a participant is unwell or injured on campus.
  • Security and fraud prevention — protecting accounts, detecting abuse, and maintaining the audit trail described above.
  • Improving what we teach — reviewing aggregated, de-identified progress and assessment data to find where a course is not working.
  • Legal and regulatory compliance — meeting accounting, tax and record-keeping obligations in the UAE.

We do not make decisions producing legal or similarly significant effects about you by automated means alone.

06Who we share data with

We do not sell personal data, and we never have. We share it only with the service providers below, each engaged under contract to process data solely on our instructions.

ProviderPurposeWhat they receive
StripePayment processing and receiptsBilling name, email, amount, and the card details you enter directly into their checkout.
CloudflareCDN and DNS, bot protection (Turnstile), file storage (R2) and video delivery (Stream)IP address and request metadata; stored course files and lesson videos.
Microsoft 365Sending transactional emailRecipient name and email address, and the message content.
Google Cloud (Vertex AI)The AI advisor and tutor featuresThe text of your prompts and the relevant course context. See AI-assisted features.
HostingerServer hosting for our application and databaseHosting infrastructure only — no independent access to or use of the data.

We may also disclose personal data where we are legally required to — to a court, regulator or law-enforcement authority acting within its powers — or where disclosure is necessary to establish, exercise or defend a legal claim. If our business is restructured or transferred, personal data may pass to the acquiring entity under the same protections, and we will tell you before that happens.

07AI-assisted features

Some parts of the platform — the programme advisor and the in-course tutor — are powered by Google's Gemini models running on Vertex AI. When you use them, your prompt and the relevant course context are sent to that service to generate a response.

  • Your inputs are not used to train third-party foundation models. Vertex AI is used under Google Cloud's enterprise terms, which exclude customer data from model training.
  • AI output is a suggestion, not advice. Course recommendations and tutoring responses are reviewed by our academic team where they inform a real decision.
  • Please do not paste sensitive personal information — identification numbers, medical details, payment credentials — into an AI chat field. Nothing in these features requires it.

08International transfers

Our application and database are hosted on servers we control. Some of the providers listed above operate globally, so personal data may be processed outside the United Arab Emirates.

Where data leaves the UAE, we transfer it only to a jurisdiction recognised as providing an adequate level of protection, or under contractual safeguards — such as standard contractual clauses — that impose protections equivalent to those required by the PDPL. You can ask us for details of the safeguards applying to a specific transfer.

09How long we keep it

We keep personal data only as long as we need it for the purpose it was collected, then delete or anonymise it.

RecordRetention period
Account and enrolment recordsFor the duration of the relationship, then 3 years after your last activity.
Financial records (payments, receipts, invoices)5 years from the end of the relevant tax period, as UAE tax law requires.
Learning records and certificatesRetained long-term so we can verify a certificate on request, unless you ask us to remove them.
Onboarding, consent and emergency-contact records2 years after the last session of the cohort.
Contact form and enquiry submissions2 years from the last contact.
Security and audit logs12 months.

10How we protect it

  • All traffic is encrypted in transit over HTTPS/TLS.
  • Passwords are stored as salted hashes and are never recoverable in readable form — not even by us.
  • Role-based access control governs every portal; staff see only what their role requires, and access to a minor's records is restricted to administrators, the assigned instructor and the linked guardian.
  • Stored course files, receipts and certificates are never exposed directly from the storage bucket. Every file is served through our own authenticated, enrolment-checked endpoint, so storage locations and credentials are never visible to a browser.
  • Sensitive operations are audited — sign-ins, role changes, impersonation and payment events are logged with actor, timestamp and IP.
  • Administrative interfaces are protected by session authentication with bot protection on public forms.

No system is perfectly secure. If a personal data breach occurs that is likely to prejudice your privacy, we will notify the UAE Data Office and affected individuals without undue delay, as the PDPL requires.

11Your rights

Under the PDPL — and, where it applies, the GDPR — you have the following rights over your personal data:

  • Access — obtain confirmation that we process your data and receive a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted, subject to records we must keep by law.
  • Restriction — ask us to limit processing while a dispute about accuracy or legitimacy is resolved.
  • Portability — receive your data in a structured, machine-readable format, or have it transferred to another controller where technically feasible.
  • Objection — object to processing based on our legitimate interests, and to direct marketing at any time.
  • Withdraw consent — withdraw any consent you have given, including media consent, without affecting processing already carried out.
  • Complain — lodge a complaint with the UAE Data Office if you believe we have handled your data unlawfully.

To exercise any of these, email [email protected] from the address on your account, or write to us at 91 Al Ftaymi St, Al Nahyan – E25, Abu Dhabi, United Arab Emirates. We respond within 30 days. We may ask you to verify your identity first — particularly for a request concerning a child — so that we do not disclose someone's data to the wrong person. Exercising your rights is free; we may charge a reasonable fee only for a manifestly unfounded or excessive repeat request.

12Marketing communications

Transactional email — booking confirmations, receipts, schedule changes, class reminders, certificate notifications — is part of the service and is sent to everyone with an active enrolment.

Promotional email about new programmes or workshops is sent only with your consent, and every such message carries a working unsubscribe link. We do not send marketing email to a student's own address where that student is a minor; where consent has been given, it goes to the linked parent or guardian.

14Changes to this policy

We update this policy as the platform develops or the law changes. The "last updated" date at the top always reflects the current version. If a change materially affects how we use your personal data, we will tell you by email or through a notice in the portal before it takes effect.

15Contact us

For any question about this policy, or to exercise a right, contact us at [email protected] or +971 58 587 8942.

Zeta42 Academy · 91 Al Ftaymi St, Al Nahyan – E25, Abu Dhabi, United Arab Emirates

Related policies

Questions about this policy

Write to [email protected] or call +971 58 587 8942. Zeta42 Academy, 91 Al Ftaymi St, Al Nahyan – E25, Abu Dhabi, United Arab Emirates.