This Privacy Notice explains how Andrei Ioan Rada ("Notevio", "we", "us") collects, uses, shares, and protects personal data when you use the Notevio service and website (the "Service"). Andrei Ioan Rada is the data controller for personal data processed through the Service.
1. Data we collect
- Account data: name, email address, login credentials, authentication provider (e.g. Google) identifiers.
- Content you upload: lecture notes, PDFs, text, and other study materials you submit to be processed by the Service.
- Usage data: study sessions, answers, mastery/progress data, feature usage, error logs.
- Device and technical data: IP address, browser type, device identifiers, timestamps.
- Support communications: messages you send to us.
2. How we use your data
- Create and secure your account (contract, legitimate interests).
- Provide the Service, including AI-generated flashcards, MCQs, summaries, and adaptive practice (contract).
- Prevent fraud, abuse, and security incidents (legitimate interests, legal obligation).
- Improve the Service and fix bugs (legitimate interests).
- Respond to support requests (contract, legitimate interests).
- Comply with legal obligations (legal obligation).
3. AI processing
Content you upload is sent to third-party AI model providers to generate study materials. We do not sell your content, and we instruct providers to process it only to return the requested outputs. AI outputs may be inaccurate; verify anything important before relying on it.
4. Sharing your data
We share personal data only with:
- Service providers / subprocessors: hosting, database, authentication, AI model providers, analytics, and error tracking, acting on our instructions.
- Merchant of Record — Paddle.com Market Limited: for sale of subscriptions, checkout, payments, tax compliance, invoicing, refunds, and subscription management. Paddle acts as an independent controller for the payment transaction. See paddle.com/legal/privacy.
- Professional advisers (legal, accounting) where necessary.
- Authorities where required by law.
5. International transfers
Some of our providers are located outside your country, including outside the UK/EEA. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
6. Retention
We keep personal data for as long as your account is active. Where you hold a paid subscription, we retain account, subscription, and billing-related data until the paid subscription period has fully ended, plus 30 days thereafter, so that we can evidence that the payment cycle has closed and handle any refund or chargeback. After that window we delete or anonymise the data, except where a longer period is required by law (for example invoice and tax records, which Paddle retains as Merchant of Record). Uploaded content and generated study materials are deleted when you delete them or when you close your account. Backups are rotated on a rolling basis.
7. Data Processing Agreement (DPA)
This section forms a data processing agreement between you (or your organisation) and Andrei Ioan Rada. For account and usage data we act as controller. Where a customer, such as a school or organisation, uses the Service to upload content relating to other people, we act as processor on that customer's behalf and the terms below apply.
7.1 Subject matter, duration, nature and purpose
We process personal data to provide the Service — generating flashcards, multiple-choice questions, summaries, and adaptive practice from submitted study material, and storing progress. Processing lasts for the duration of the account or subscription, plus the retention window described in section 6.
7.2 Personal data and data subjects
- Data types: account identifiers (name, email, provider ID), uploaded study content, study progress and answers, technical and log data.
- Data subjects: account holders and students using the Service.
7.3 Our obligations as processor
- Process personal data only on the controller's documented instructions, including for international transfers, unless required otherwise by law.
- Ensure that personnel authorised to access personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures, including encryption in transit, access controls, and row-level authorization (see section 8).
- Assist the controller, taking into account the nature of processing, with responding to data subject requests and with security, breach notification, and impact assessment obligations.
- Notify the controller without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the engagement, subject to the retention window in section 6 and legal retention duties.
- Make available the information reasonably necessary to demonstrate compliance with these obligations, and allow for reasonable audits or inspections.
7.4 Subprocessors
You give general authorisation for us to engage subprocessors for hosting, database, authentication, AI model processing, analytics, and error tracking, and for Paddle.com Market Limited as Merchant of Record. Each subprocessor is bound by data protection obligations no less protective than those in this section. We will give notice before adding or replacing a subprocessor, and you may object on reasonable data protection grounds.
7.5 International transfers
Transfers outside the UK/EEA rely on the safeguards described in section 5, such as Standard Contractual Clauses or an adequacy decision.
7.6 DPA requests
To request a countersigned DPA, an up-to-date subprocessor list, or further information, contact andersgeko+notevio@gmail.com.
8. Your rights
Subject to applicable law, you may have the right to:
- Access, correct, or delete your personal data.
- Restrict or object to processing.
- Receive a portable copy of your data.
- Withdraw consent where processing is based on consent.
- Complain to your local data protection supervisory authority.
To exercise these rights, contact us at the email below. We aim to respond within one month.
9. Security
We use appropriate technical and organisational measures, including encryption in transit, access controls, and row-level authorization, to protect personal data. No system is 100% secure.
10. Cookies
We use strictly necessary cookies and local storage for authentication and preferences (e.g. language, theme). Payment provider pages may set additional cookies governed by Paddle.
11. Children
The Service is not directed at children under 13, and we do not knowingly collect their data.
12. Changes
We may update this Notice. Material changes will be communicated through the Service or by email.
13. Contact
Andrei Ioan Rada — andersgeko+notevio@gmail.com