Privacy · Governance draft
Privacy Policy
This draft explains the personal information the current PRAGO AI service is designed to use. Controller identity, lawful-basis decisions, retention periods and international-transfer wording require formal approval.
Governance draft — not yet legally approved
This page is a structured launch draft for business and legal review. It describes the intended operating position without replacing statutory rights or professional legal advice. Items requiring a decision are listed at the end.
01
Who is responsible
The legal entity acting as data controller, its registered address and any appointed privacy contact must be inserted following business and legal approval. General enquiries currently go to support@pragoai.co.uk.
02
Information used by the service
The platform processes account identity and contact details, authentication and security records, purchased entitlements, course and lesson progress, practice and Mock Exam activity, Trainer conversation state, promotion and order records, and support enquiries submitted by the learner.
Payment-card details are intended to be collected by the configured payment provider rather than stored in PRAGO’s application database. This must be verified in production before live charging.
03
Why information is used
Information is used to create and secure accounts, provide purchased learning access, preserve progress, operate assessments and Trainer continuity, process orders, prevent misuse, respond to enquiries and maintain service reliability.
The lawful basis for each purpose—including contract, legitimate interests, consent or legal obligation—must be approved and documented before this policy is finalized.
04
AI-assisted learning data
Trainer prompts, lesson context and conversation state may be processed to provide the requested teaching experience. Production provider terms, retention controls, data location and any opt-out or human-review process require business/privacy approval.
05
Service providers and sharing
The service may rely on infrastructure, email, payment and AI providers acting under appropriate contractual controls. A final named processor list and the circumstances in which disclosure may be legally required must be approved before launch.
06
International transfers
No universal statement about data location or international transfer safeguards is made in this draft. Actual provider regions and the appropriate transfer mechanism must be verified and documented.
07
Retention
Account, learning, assessment, order, security and support records should be retained only for approved operational, contractual and legal purposes. Exact retention schedules and deletion/anonymization rules remain to be approved.
08
Security
The application uses access controls, signed sessions, protected credentials and learner-isolation controls. No online service can promise absolute security; incident handling and notification obligations will follow applicable law and approved procedures.
09
Your choices and rights
Depending on applicable law, individuals may have rights concerning access, correction, deletion, restriction, objection, portability or complaints. The applicable rights, identity-verification process, response times and supervisory authority must be confirmed for the launch jurisdiction.
10
Contact and changes
Privacy questions may be sent to support@pragoai.co.uk. Material changes should be dated and communicated in an appropriate way once the final policy and operating process are approved.
Business / legal approval required before final publication
- Controller identity, registered address, privacy contact and launch jurisdictions.
- Record of processing purposes and lawful basis for each data category.
- Named processors, data locations, retention settings and transfer safeguards.
- Trainer/provider data handling, human-review and deletion arrangements.
- Retention schedule, data-subject request process and regulator details.
Draft version 0.1 · prepared 6 September 2026 · contact: support@pragoai.co.uk