1. Purpose
This Artificial Intelligence (AI) Usage & Governance Policy defines how AI technologies are used within the Platform and establishes governance, risk management, transparency, and compliance principles.
The policy is designed to ensure lawful, ethical, secure, and responsible use of AI, aligned with:
- EU General Data Protection Regulation (GDPR)
- EU Artificial Intelligence Act (AI Act)
- Applicable U.S. privacy laws (e.g., CCPA/CPRA and equivalents)
- Contractual commitments with AI service providers (e.g., OpenAI, Deepgram)
2. Scope
This policy applies to:
- All AI-enabled features within the Platform
- All employees, contractors, and partners involved in AI design, deployment, or oversight
- All personal and non-personal data processed through AI systems
3. AI System Overview
3.1 AI Use Cases
AI is used exclusively as a supporting and assistive technology for the following purposes:
- Service and lesson personalization
- Automation of content production (e.g., lesson materials, exercises)
- Data aggregation and migration from internal data sources
- Text processing, image generation, and text-to-speech services
- Transcription of lessons (teacher-side only) and AI-assisted summary/topic generation
AI systems do not make legally binding, automated decisions about individuals.
3.2 AI Model Type
- The Platform uses general-purpose AI models (GPAI) provided by OpenAI.
- Models are used as-is and are not retrained or fine-tuned by Global LT.
- No proprietary or internally trained models are used.
- Speech-to-text transcription is provided by Deepgram.
3.3 Model Training
- Global LT does not train AI models.
- No client, user, or internal data is used for training AI systems.
- Contracts with OpenAI explicitly prohibit the use of Platform data for model training.
- Deepgram processes transcription data solely to provide the service; Global LT has opted out of Deepgram’s model-improvement program, ensuring transcription data is not used to train or improve Deepgram’s models.
3.4 Teacher Transcription
Overview: The Platform includes an optional lesson transcription feature that captures audio exclusively from the teacher's microphone during a lesson. Student audio is never transcribed.
Transcription outputs: When enabled, the transcript is used to generate:
- A lesson summary
- Topics and teaching items that support follow-up activity generation for students
Consent and control: At the start of each eligible lesson, the teacher is prompted to enable transcription. Teachers may pause, resume, or stop transcription at any time during the lesson. Enabling transcription constitutes an affirmative opt-in and grans Global LT the right, without any fees or royalty, to use the recording and the resulting derived outputs for the purposes described in this section.
Audio isolation: Transcription captures audio exclusively from the teachers' local microphone via the browser's getUserMedia API. This API returns on the local device microphone; it cannot return another participant's audio stream. The student's audio travels over a separate WebRTC path (via the video provider) and is never passed to the transcription pipeline. Isolation is therefore enforced by the browser security model, not by a configurable flag.
Note: As with any microphone, the teacher's mic may acoustically capture student audio played aloud through the teacher's speakers. This constitutes acoustic bleed into the teacher's own microphone, not capture of the student's audio stream. Use of a headset or enabling echo cancelation is recommended to mitigate this.
3.4.1 Data Handling & Retention
The following data handling controls apply to the transcription feature:
- The raw transcript is sent to OpenAI for summary and topic generation only, with storage disabled (store=false).
- After summary and topics are successfully generated and saved, the raw transcript is deleted from the session record.
- If generation fails, the raw transcript may be retained temporarily to allow for retry processing. A cleanup job removes stale transcripts after the applicable retention window.
- Only derived outputs required for product functionality (e.g., lesson summary, topics) are retained. The full raw transcript is not retained once processing is complete.
3.4.2 Speech Provider Privacy Controls
- Deepgram model-improvement opt-out: transcription data is processed solely to deliver the service and is not used by Deepgram to train or improve its models.
- PCI/SSN redaction is enabled: transcript output automatically masks detected payment-card numbers and Social Security Number patterns before any downstream processing.
3.4.3 Intellectual Property & Consent Notice
By enabling transcription, the teacher:
- Consents to the recording and transcription of their voice during the lesson.
- Grants Global LT the right to use, without any fees or royalty, the recording and resulting outputs (e.g., summaries, generated topics) for product functionality and capability development, including potential use in a separate product.
- Acknowledge that derived outputs (such as summaries and generated topics) may help develop Global LT’s activity-generation capabilities.
4. Data Usage & Personal Data
4.1 Personal Data Processed
AI systems may process limited personal data strictly necessary for personalization, including:
- Language preferences
- Previous lesson data
- Learning interests
- Teacher voice recordings (teacher transcription feature only; processed transiently as described in Section 3.4)
Direct identifiers (e.g., name, email address) are not passed to GPAI services where feasible.
4.2 Pseudonymization
- Data is not formally pseudonymized.
- Identifying information is minimized and excluded from AI prompts whenever possible.
- Data minimization principles are applied at all integration points.
- PCI/SSN redaction is applied to transcription outputs before use (see Section 3.4.2)
4.3 Children and Minors
At this time, minors do not use AI-enabled features of the Platform for language training or learning activities.
The Platform does not process personal data of minors through artificial intelligence systems, nor does it use information related to minors for AI-generated content, personalization, or recommendations.
Any information associated with minors is handled exclusively through non-AI system functionalities and in accordance with applicable data protection and children’s privacy laws.
5. Transparency & User Awareness
- Users are informed when AI is used to generate or assist with content.
- Users are informed that AI-generated content may contain errors or inaccuracies.
- Human review and correction mechanisms are always available.
- Teachers are explicitly informed at the start of each lesson when transcription is available, and are given granular controls to enable, pause, or stop transcription at any time.
6. Decision-Making & Explainability
- The decision-making logic of GPAI models is not fully explainable due to the nature of generative AI.
- The Platform does not rely on AI outputs as the sole basis for high-impact decisions.
- AI is used to support, not replace, human judgment.
- AI systems are never used to make automated or individualized decisions affecting minors.
7. Risk Management & Quality Assurance
7.1 Model Risk Management
- Models are used with extensive error handling and defensive programming.
- Inputs and outputs are validated and filtered for unsuitable or harmful content.
- Content classification, moderation, and safety checks are applied where applicable.
- Teacher transcription outputs are subject to automated redaction (PCI/SSN) prior to any downstream AI processing.
7.2 Testing & Monitoring
- AI outputs are tested internally before being released to customers.
- Ongoing monitoring for quality, bias, and safety issues is performed.
- Issues are logged, reviewed, and mitigated according to internal procedures.
8. EU AI Act Alignment
8.1 Risk Classification
- AI features are assessed under the EU AI Act risk framework.
- Education-related AI use cases may fall under limited-risk or high-risk categories and are managed accordingly.
8.2 Human Oversight
- All AI-generated outputs remain subject to human oversight.
- AI systems cannot independently determine learner outcomes, assessments, or eligibility decisions.
9. Security & Confidentiality
- All data exchanged with AI providers is encrypted in transit.
- Access to AI configurations and prompts is role restricted.
- Vendor security and compliance documentation are reviewed regularly.
- Teacher transcription data is transmitted to Deepgram and OpenAI over encrypted channels; OpenAI requests for transcript processing are made with storage disabled.
10. Third-Party AI Providers
- Only approved AI providers may be used.
- Providers must contractually commit to:
- No training on Platform data
- Industry-standard security controls
- Compliance with applicable privacy laws
Approved providers currently include OpenAI (language model services) and Deepgram (speech-to-text transcription). Both providers are contractually bound to the commitments above.
11. Governance & Accountability
All AI initiatives and practices are overseen by a cross-functional AI Governance Committee responsible for policy enforcement, risk review, and ongoing accountability.
- AI Governance Lead: Oversight of AI use and compliance
- Data Protection Lead: Privacy and GDPR compliance
- Engineering & Product Teams: Technical implementation and safeguards
12. Policy Enforcement
Violations of this policy may result in access restrictions, retraining requirements, or disciplinary action.
Next Review Date: 2027-01-27