Legal

Privacy Policy

Last updated: 25 May 2026

1. Who we are

Tortin ("we", "us", "our") operates the Tortin Teaching OS available at app.tortin.com. The service is provided jointly by:

  • Tortin LLC — QFC No. 04399, Office No. 4, Floor No. 9, QFC Tower 1, Doha, Qatar.
  • Tortin Ventures Sàrl — CHE-142.665.855, Chemin des Tattes 7b, 1222 Vésenaz, Switzerland.

For any privacy question, contact shez@gettortin.com.

2. Who this policy is for

Tortin is intended for professors, instructors and university-level students. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, contact us and we will delete it.

3. What we collect

  • Account data — name, email, role (professor or student), institution, password hash.
  • Course content — sessions, materials, assessments, submissions, grades, peer evaluations.
  • Interaction data — AI tutor conversations, session attendance, live-session activity.
  • Technical data — IP address, browser type, device, session timestamps (for security and abuse prevention).

4. Why we process it (GDPR Art. 6 lawful bases)

  • Contract — to deliver the platform you signed up for.
  • Legitimate interest — security, fraud prevention, product analytics.
  • Consent — optional features such as marketing emails. You can withdraw consent at any time.
  • Legal obligation — tax, accounting, responding to lawful requests.

5. Artificial intelligence

Tortin uses AI to power the in-course tutor, draft assessment rubrics, and assist with grading. Grades drafted by AI are clearly labelled and released only after a professor reviews them. You are interacting with an AI system, not a human, whenever you see an "AI-assisted" badge (EU AI Act Art. 50 transparency).

We send the minimum content required to generate a response (your question, a short slice of course materials) to third-party AI model providers acting as our processors under data-processing agreements. No personal data is used to train third-party foundation models.

We may use anonymised, aggregated interaction data — with direct identifiers removed and no output tied to an individual — to evaluate and fine-tune Tortin's own internal tutor and professor-assistance models. This data is never used to train third-party foundation models and is never sold or shared for advertising.

AI tutor conversations are private to the student. Professors and course co-teachers cannot read individual tutor conversations. They receive only de-identified, aggregated insights: personal identifiers are stripped from question text, and themes are withheld unless raised by a minimum number of students.

6. Who we share data with (sub-processors)

  • Cloud hosting & database — our backend infrastructure provider.
  • AI model providers — generic third-party large-language-model APIs used to power the tutor and grading helpers.
  • Email delivery — to send transactional notifications.

We never sell personal data. We do not share student data with advertisers.

7. International transfers

Data may be processed in Switzerland, the European Union, Qatar and the United States. Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses or an applicable adequacy decision (Switzerland is recognised as adequate by the EU).

8. Retention

  • Account data — kept while the account is active. If you deactivate, your login is disabled and your submissions are retained for the institutional grade-appeal period, then anonymised (GDPR Art. 17(3)).
  • Course content — kept while the course exists; professors can delete at any time.
  • AI tutor chats — kept while the course is active; configurable retention coming soon.
  • Backups — purged within 35 days of the source record being deleted.

9. Your rights

Under GDPR, the Swiss FADP, and (where applicable) FERPA you can:

  • Access a copy of your data.
  • Correct inaccurate data.
  • Request deletion ("right to be forgotten") — available from Settings → Account.
  • Object to or restrict processing.
  • Port your data to another service.
  • Lodge a complaint with your supervisory authority (e.g. the EDÖB in Switzerland, your national DPA in the EU).

To exercise any right, email shez@gettortin.com. We respond within 30 days.

10. Security

Passwords are hashed; all traffic is encrypted in transit (TLS); row-level security restricts data access to authorised users; new passwords are checked against the Have I Been Pwned breach database.

11. Changes

We will notify registered users by email of material changes at least 14 days before they take effect.

This document is a plain-language summary. It is not legal advice. If you need tailored advice, consult a qualified lawyer in your jurisdiction.