Understanding how we protect your personal data and your rights under GDPR and the Irish Data Protection Act.
You have the right to request a copy of all personal data we hold about you, including your assessment results, profile information, and usage data.
Request Your DataAlso known as the "right to be forgotten," you can request complete deletion of your account and all associated data. We will process deletion requests within 30 days.
Request Data DeletionYou can update or correct any inaccurate personal information directly in your profile settings or by contacting support.
You can request that we limit how we use your data in certain circumstances.
You can receive your data in a structured, machine-readable format to transfer to another service.
You can object to certain types of data processing, including direct marketing.
In accordance with Irish educational guidelines (Circular 0035/2017) and GDPR, students under 18 require parental or guardian consent to access certain assessment features:
If you have questions about how we handle your data, want to exercise your rights, or have concerns about data protection, please contact:
Data Protection Contact
CourseCompass
📧 Email: [email protected]
🌐 Website: www.coursecompass.ie/data-protection
⏱️ Response Timeframe
We aim to respond to all data protection requests within 30 days as required by GDPR Article 12.
CourseCompass uses AI-powered analysis to generate personalized course recommendations and subject interest insights. All AI-generated content is clearly labeled as such.
AI Models We Use:
Under the EU AI Act, our educational guidance systems are classified as "Limited Risk", requiring transparency obligations which we fulfill through clear labeling and this disclosure.
We retain personal data only as long as necessary:
All data is hosted within the European Economic Area (EEA) using Supabase's EU infrastructure (Frankfurt/Dublin regions). We do not transfer personal data outside the EEA without adequate safeguards.
All processors have signed Data Processing Agreements (DPAs) as required by GDPR Article 28.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, CourseCompass will notify the Irish Data Protection Commission within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly, without undue delay, by email to the address on their account. All breaches are logged internally regardless of severity. Suspected breaches can be reported to [email protected].