top of page

Privacy Policy

Last updated: August 10, 2026
Effective: September 9, 2026

 

Notice: This updated policy has been published in advance and will take effect on September 9, 2026. Until then, the current version remains in effect. [View the current policy.]

This Policy explains how TeachAid collects, uses, shares, stores and protects personal information.

TeachAid is operated by:

1000662662 Ontario Corporation, doing business as TeachAid
515 Winston Road, Unit 23
Grimsby, Ontario L3M 0C8
Canada
nadeem@teachaid.ca
 

1. When this Policy applies

This Policy applies to TeachAid’s websites, educator accounts, subscriptions, support, communications, curriculum tools and interactive classroom features.
 

TeachAid acts independently when it processes information for:

  • Adult account management

  • Security

  • Billing

  • Support

  • Business communications

  • Legal compliance

  • Corporate records
     

When TeachAid processes Student Data or other school-controlled information through an authorised enterprise, pilot or sandbox, TeachAid acts on the school or district’s instructions under the applicable agreement and DPA.
 

A school email address alone does not establish school authorisation or a formal processor or school-official relationship.
 

2. Information we collect

Adult account and professional information

We may collect:

  • Name

  • Email address

  • Authentication details

  • Profile photo

  • Account identifier

  • School, district or organisation

  • Role and title

  • Grade and subject

  • Curriculum region

  • Language and instructional preferences

  • Subscription and licence information

  • Workspace membership

  • Administrator status
     

Educator and customer content

We may process:

  • Prompts and instructions

  • Uploaded documents and images

  • Curriculum materials

  • District standards and frameworks

  • Generated units, lessons, slides and assessments

  • User edits

  • Curriculum maps

  • Scope-and-sequence materials

  • Shared workspace content

  • Comments and collaboration history

  • Sharing activity
     

Student activity information

TeachAid may process:

  • First name or nickname

  • Teacher-issued activity code

  • Teacher or activity identifier

  • Answers and notes

  • Drawings

  • Timestamps

  • Limited session and technical information needed to operate and secure the activity

Students do not create accounts.
 

Technical and usage information

We may collect:

  • IP address

  • Browser and device type

  • Operating system

  • Session identifiers

  • Authentication and security events

  • Login and activity dates

  • Feature use

  • Unit titles and creation dates

  • Performance, diagnostic, crash and error information

  • Necessary cookies
     

Billing, support and business information

We may process:

  • Billing contact information

  • Subscription and invoice details

  • Transaction and tax records

  • Support requests

  • Correspondence

  • Training and meeting records

  • Feedback

  • Procurement information

  • Contract records
     

Full payment-card details are handled by TeachAid’s payment provider rather than stored directly by TeachAid.
 

Connected-service information

When an adult user signs in with Google or Microsoft, we may receive:

  • Name

  • Email address

  • Unique account identifier

  • Profile photo, where available

  • Authentication tokens
     

When a user connects Google Drive or a supported Microsoft storage service, we may process:

  • Access and refresh tokens

  • Account email

  • Files or folders selected by the user

  • Files TeachAid creates or exports at the user’s request

  • Related file metadata
     

We do not access connected files or accounts beyond the permissions granted and the functions requested by the user.
 

Adult marketing information

We may process adult business-contact information for demonstrations, events, product updates, surveys and other permitted communications.
 

Student Data is not placed in advertising, marketing, event, campaign or sales CRM systems.
 

3. How information is collected

Information may come from:

  • You

  • Your school, district or administrator

  • Your use of the Services

  • Google or Microsoft when you authorise sign-in or an integration

  • Payment and service providers

  • Customer support and business communications

  • Public professional sources, where law permits
     

4. How we use information

TeachAid uses information to:

  • Provide and personalise the Services

  • Authenticate users

  • Generate and store educational materials

  • Process selected curriculum documents and standards

  • Operate interactive classroom activities

  • Support enterprise workspaces and curriculum mapping

  • Administer organisations, licences and subscriptions

  • Process payments

  • Provide onboarding, training and support

  • Maintain security and prevent misuse

  • Investigate incidents

  • Monitor reliability and performance

  • Communicate with adult users

  • Improve the safety, usability and effectiveness of the Services

  • Comply with contracts and law

  • Establish or defend legal claims
     

Depending on the activity and jurisdiction, TeachAid may rely on contract, customer instructions, legitimate interests, consent, legal obligations or another lawful basis.
 

Where processing is based on consent, the consent may be withdrawn.


5. Artificial-intelligence processing

TeachAid may send approved AI providers:

  • Educator prompts

  • Selected uploads

  • Curriculum standards

  • District or customer materials

  • Generated content

  • Context needed to provide a requested feature
     

TeachAid does not use Customer Content or Student Data to train general-purpose AI models and requires its AI providers not to do so.
 

Student names, responses, notes and drawings are not sent to AI providers.
 

TeachAid’s AI provider may retain limited abuse-monitoring records for up to 30 days under its business API terms. TeachAid does not enable optional response storage for general product use.
 

TeachAid may use de-identified or aggregated information to improve security, reliability, capacity, workflows and product effectiveness. We do not attempt to re-identify that information.
 

De-identified Student Data is used only as permitted by the applicable customer agreement and law.
 

6. Google and Microsoft data

TeachAid uses Google and Microsoft information only to provide the sign-in, import, export or storage feature authorised by the user.
 

TeachAid does not use connected-account data for advertising, unrelated profiling or general-purpose AI training.
 

TeachAid’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google requires clear disclosure and limits on how applications use information received through Google APIs.
 

Microsoft account information is processed according to the permissions shown during Microsoft’s consent process and the requested TeachAid feature.
 

Users may disconnect an integration through the available account settings or by contacting TeachAid.

Files exported to Google or Microsoft remain in the user’s external account until the user deletes them there.
 

7. Service providers and subprocessors

TeachAid uses providers supporting:

  • Hosting and storage

  • Backups

  • Authentication

  • AI processing

  • Realtime classroom updates

  • Error monitoring

  • Email and support

  • Payments

  • Adult-facing analytics

  • Customer relationship management

  • Connected integrations
     

Providers may use information only for authorised purposes and must follow appropriate confidentiality, privacy, security and deletion requirements.
 

TeachAid maintains its current subprocessor list at teachaid.ca/subprocessors.
 

The list identifies each provider’s function, location and whether it may process Customer Data or Student Data.
 

TeachAid may also disclose information:

  • At the customer’s direction

  • To authorised organisational users

  • Where required by valid legal process

  • To protect safety, rights or security

  • To investigate misuse

  • To establish or defend legal claims
     

For school-controlled information, TeachAid will notify the school before compelled disclosure where legally permitted.
 

If TeachAid is involved in a merger, acquisition, financing, reorganisation or sale, information may transfer to a successor that must assume applicable privacy and contractual obligations.
 

8. Administrator access

In an authorised enterprise deployment, administrators may access information permitted by the agreement and product configuration, including:

  • Organisational membership

  • User names and work email addresses

  • Login and activity dates

  • Usage reports

  • Unit titles and creation dates

  • Aggregate activity

  • Shared workspace content

  • Curriculum maps

  • Authorised student activity information
     

Administrators do not see the full content of private educator drafts unless that access is clearly disclosed and authorised.
 

9. What TeachAid does not do

TeachAid does not:

  • Sell personal information

  • Sell Student Data

  • Rent Student Data

  • Use Student Data for behavioural advertising

  • Use Student Data for marketing

  • Build commercial student profiles

  • Place Student Data in sales or marketing systems

  • Use Customer Content or Student Data for general-purpose AI training

  • Use customer content or identity in marketing without written permission

  • Use session replay

  • Allow contractors without an authorised operational need to access customer or student information
     

10. Cookies and analytics

TeachAid uses necessary cookies and similar technologies for:

  • Authentication

  • Security

  • Session continuity

  • Preferences

  • Core functionality
     

Adult-facing websites and educator pages may use limited analytics, including Google Analytics and Vercel Analytics, to measure traffic and improve performance.
 

Non-essential analytics are subject to consent where required.
 

Student activity pages do not use:

  • Advertising pixels

  • Behavioural advertising

  • Retargeting

  • Visitor-identification pixels

  • Marketing analytics

  • Session replay
     

Teacher-selected embedded media may cause the third-party media provider to receive ordinary technical information when the content is loaded.
 

11. International processing

TeachAid is based in Canada.
 

Core database, file storage and primary backups are hosted in Canada.
 

Some authorised providers process information in the United States and other countries for application hosting, authentication, AI processing, payments, analytics and related services.
 

Information processed outside a person’s home jurisdiction may be subject to the laws and lawful access procedures of that location.
 

Where required, TeachAid uses safeguards such as:

  • Data-protection agreements

  • International-transfer terms

  • Standard contractual clauses

  • Encryption

  • Access restrictions

  • Transfer assessments
     

A specific regional-residency commitment applies only where it appears in a signed agreement and is supported by the applicable deployment.
 

12. Retention and deletion

TeachAid keeps information only as long as reasonably needed for the applicable purpose, customer instructions, security, legal obligations, disputes and contract enforcement.
 

Adult accounts

Adult account information and content are generally retained while the account remains active.

Verified account, content, access, correction and deletion requests are ordinarily completed in active systems within 30 days.
 

Billing, tax, contract, fraud-prevention and legal records may be retained where required by law or reasonably needed for legitimate business records.
 

Self-serve student activities

Student responses in self-serve activities are retained for no longer than 12 months after the activity’s last use, unless:

  • The educator deletes them sooner

  • A documented ongoing instructional need applies

  • Law requires a shorter period

Self-serve TeachAid is not intended to act as a permanent student-record archive.
 

Enterprise Student Data

Schools and districts control enterprise Student Data retention through their agreement and written instructions.
 

Unless a controlling agreement states otherwise, TeachAid retains enterprise Student Data during the contract term and deletes it from active systems within 30 days after:

  • Contract termination

  • A verified customer instruction

  • The end of an agreed retention period
     

The customer may request an export before deletion.
 

Backups

Deleted information may remain in protected backup copies until those copies expire under TeachAid’s documented backup schedule.
 

Backup copies are isolated from normal use. If a backup is restored, applicable deletion instructions are reapplied.
 

Backup information is deleted within the period required by the applicable agreement and otherwise within 60 days after active-system deletion.
 

Once information has been securely deleted, it may no longer be recoverable.
 

TeachAid may retain a record that deletion occurred without retaining the deleted Student Data itself.
 

13. Privacy rights

Depending on location, a person may have rights to:

  • Access personal information

  • Correct inaccurate information

  • Delete information

  • Restrict or object to processing

  • Withdraw consent

  • Receive a portable copy

  • Opt out of certain marketing

  • Appeal a denied request

  • Complain to a regulator
     

Requests may be sent to nadeem@teachaid.ca.
 

TeachAid may verify identity, authority and organisational role.
 

Verified requests are ordinarily completed within 30 days or sooner where law or contract requires.

Where a school controls the information, parents, students and educators should normally submit the request through the school. TeachAid will assist the school.
 

TeachAid will not discriminate against a person for exercising a privacy right.
 

14. Students and children

Educator accounts are intended for adults.
 

Students use only teacher-created activities and do not create accounts.
 

Before collecting student responses, the educator must confirm school authorisation, an educational purpose and required notices and consents.
 

For children under 13 in the United States, TeachAid relies on school authorisation only for school-authorised educational use and not for unrelated commercial purposes.
 

TeachAid remains responsible for its own COPPA obligations and provides schools with notice of its collection, use, disclosure, access and deletion practices. The FTC permits school consent only for the educational context and requires the operator to provide the school with appropriate notice and access and deletion rights.
 

More information appears in the Student Privacy Policy.
 

15. Security and incidents

TeachAid maintains safeguards appropriate to the sensitivity of the information, including:

  • Encryption in transit and at rest

  • Multi-factor authentication for privileged access

  • Role-based access and least privilege

  • Logical customer separation

  • Restricted administrative access

  • Security and error monitoring

  • Protected independent backups

  • Restoration testing

  • Incident-response procedures

  • Workforce confidentiality

  • Privacy and security training

  • Access removal when no longer required
     

TeachAid follows a security-control approach informed by the NIST Cybersecurity Framework and related industry practices.
 

This does not mean that TeachAid is SOC 2, ISO 27001 or CMMC certified unless TeachAid separately publishes evidence of that certification.
 

No system can guarantee complete security.
 

TeachAid investigates suspected incidents and makes legally required reports and notifications.

For enterprise customers, TeachAid’s standard commitment is to notify the affected customer without undue delay and within 24 hours after confirming that an incident affected that customer’s Protected Data. A controlling signed agreement may impose additional requirements.
 

Canadian organisations must assess and report qualifying breaches and retain records of security-safeguard breaches.
 

16. Changes and contact

TeachAid will provide at least 30 days’ notice of material changes.
 

Urgent legal or security changes may take effect sooner, with notice as soon as practicable.
 

Contact:

Nadeem Aljaber, Privacy Contact
1000662662 Ontario Corporation dba TeachAid
515 Winston Road, Unit 23
Grimsby, Ontario L3M 0C8
Canada
nadeem@teachaid.ca

  • Twitter
  • Instagram
  • LinkedIn

bottom of page