Privacy Policy
How LectaMe handles personal data. We briefly explain what we process, why, with whom we share it and what rights you have.
Last updated: 1 september 2026 · Document version 2.5
Plain-language summary
- We only process the data needed to make LectaMe work — no profiles for advertising.
- Participants in a live session do not need to create an account and use a display name of their own choosing.
- Our primary storage is in the EU (Supabase and Leaseweb in Germany). For a few suppliers outside the EEA we apply recognised safeguards.
- Analytics cookies are only placed after you have given your explicit consent.
- You have the right to access, rectification, erasure, restriction, objection, portability and the withdrawal of consent.
1. Who is LectaMe?
LectaMe is an AI-supported presentation and interaction platform for teachers, trainers and educational institutions. Users can create, import, share and use presentations during interactive sessions in which participants join via a session code or QR code.
LYNT V.O.F. (trading under the name LectaMe)
Rotterdam, Nederland
Email: info@lectame.com
Privacy: privacy@lectame.com
Chamber of Commerce number: 97241229
2. Who does this policy apply to?
This privacy policy applies to:
- Visitors to our website and information pages.
- Teachers, trainers and administrators who have an account or use the guest feature ("Start for free") without an account.
- Participants in live sessions — typically students or course attendees — who join without an account via a session code or QR code.
3. Roles under the GDPR
The General Data Protection Regulation (GDPR) distinguishes between the controller and the processor. For LectaMe the following applies:
- LectaMe is an independent controller for the management of our website, account management, security, billing and operational communication.
- LectaMe is a processor when a school or organisation uses LectaMe to process participants' data in an educational context. The educational institution is then the controller. For that processing we offer a data processing agreement .
4. Which data do we process?
Website visitors
- IP address and technical connection data (User-Agent, language).
- Short technical logs for security and debugging.
- Necessary cookies for session management and consent.
- Optional analytics data, only after explicit consent.
Teachers, trainers and administrators (accounts)
- Email address and (optionally) name.
- Hashed password or OAuth identifier.
- Two-factor authentication if enabled (TOTP secret).
- Account and subscription status, usage credit balance.
- Presentations, slides and settings you have created.
- For paid subscriptions: invoice and payment data (see Mollie below).
Guest users ('Start for free')
- A random identification code in an
HttpOnlycookie (valid for 30 days) so you can find your created presentations again. - The presentations and associated content you have created.
- Limited technical logs related to quota monitoring and abuse prevention (for example IP address).
Participants in live sessions
- A self-chosen display name or pseudonym. First and last name are never required.
- The session code you join and timestamps.
- Answers, responses or contributions you provide during the session.
- Locally on your device (not with us): any personal notes.
Students and participants with a guidance file
If your school or organisation uses our guidance and development environment, a personal file comes with it. Which parts you see depends on the modules your school uses; your school is the controller for this and we are the processor.
- File data: your name, email address, programme, cohort, year and period, your school or organisation and — if you have a work placement — its period.
- Learning goals and progress: the goals you set with actions and deadlines, your self-assessment per work process, your mentor’s assessment, and the progress and points of attention derived from them.
- Portfolio: the evidence you add (files or links), your reflection on it, which learning goal it belongs to and who may see it.
- Feedback and conversations: your feedback questions and the answers to them, who you shared them with, and the conversations you schedule with type, date, participants, summary and agreements.
- Your guidance team: who is linked to you, in which role, from which organisation, what that person may see and until when the link runs.
- Depending on your school’s modules: work placement, exams and exemptions, and your wellbeing reflections in My Growth.
Not all of this is visible to everyone. What you write in the coaching space stays there; see Coaching and assessment are separate.
5. Why do we process this data?
- Providing and maintaining LectaMe.
- Enabling teachers and participants to collaborate during sessions.
- Securing the platform against abuse and attacks.
- Performing agreements with paying users (including billing and statutory administration).
- Optionally improving the product based on aggregated statistics (only after consent).
6. GDPR legal bases
We base our processing on the following legal grounds:
- Performance of a contract — for providing the service to logged-in users and paying customers.
- Legitimate interest — for security, abuse prevention and the operation of the guest flow with quota monitoring.
- Consent — for optional analytics cookies and for features where we explicitly ask for it.
- Legal obligation — for retaining billing and accounting data.
7. Accounts and logging in
You can log in with an email address and password. Passwords are stored hashed by our authentication provider. We support two-factor authentication (TOTP); we recommend it for accounts with sensitive content.
Depending on your account settings, you can also log in via an external provider (such as Google). In that case we only receive from that provider the data needed to create your account: email address and (optionally) name.
8. Presentations, uploads and PowerPoint import
Presentations are stored primarily in the cloud, linked to your account or guest session. For network interruptions we temporarily keep a recovery buffer in your browser's local storage (localStorage); this is automatically overwritten once the cloud version is back in sync.
Uploaded images are kept in cloud storage as long as they are in use in a presentation. When importing a PowerPoint file (.pptx) the file is converted to our internal structure and not retained as the original file; images are stored separately so they remain visible in the presentation.
You are responsible for the content you upload or enter. Do not enter personal data, patient data or special categories of personal data for which you have no lawful basis.
9. Live sessions and participants' data
During a live session we process data to make the session work. Participants choose a display name themselves — a pseudonym is sufficient and is our preference. Answers and responses are linked to that display name within the session.
With anonymous participation, it is possible that answers can no longer be linked to one specific person. This may affect the feasibility of certain privacy rights (see below).
Identifiable participation within an organization
When a logged-in student takes part in a live lesson of a teacher within the same organization (school or institution), that participation is not anonymous: the student is identifiable to the teacher. The student is shown a clear notice about this during the lesson.
Within that organization the teacher can view, for their own lessons: name, progress (slides viewed, completed), quiz results, and the personal notes and AI-explanation questions the student made during the lesson. A teacher only sees data from lessons they gave themselves.
The educational institution determines this access in the context of education and is the controller for it; LectaMe facilitates this as processor. Outside a shared organization, participation remains anonymous. This data follows the retention periods of the lesson archive and the guidance line and is deleted on request; questions go through the teacher or the organization.
10. AI generation and AI feedback
LectaMe offers two types of AI features:
- AI lesson generation: Based on the topic, level and learning objectives the teacher enters, our AI system generates a draft presentation.
- AI feedback and summaries: Optionally, a teacher can have summaries or formative feedback generated based on answers from a session.
AI requests are carried out via our AI supplier (see the supplier table below). The content of a prompt — topic, assignments, any case description — is sent to that supplier. The teacher is responsible for not including any personal data, patient data or confidential information in a prompt. Preferably use fictitious cases or pseudonyms.
We do not use your lesson content or participants' answers to train our own AI models. For arrangements with our AI supplier regarding the reuse of data, see the supplier table below.
AI feedback is intended as formative support. It is not a binding assessment and is never used on its own for decisions with legal or similar effects.
11. Practice conversations with an AI character
In the Conversation Trainer you practise a professional conversation with a fictional character. You pick a scenario, you speak or type, and afterwards you get tips on your language and your conversation skills.
- What is sent to our AI supplier: the chosen scenario — which is fixed in our software and is not about a real person — and the conversation transcript, meaning what you say and what the character replies. Your name, email address, class, school and user number are not included.
- There are three AI suppliers in the chain. If a request fails at the first one, the same request moves on to the next. The supplier table below lists which ones.
- Only you can see your practice conversations. Your teacher, your mentor and your school cannot access them. There is no grade and no assessment; the tips are there to learn from.
- The microphone. Speaking is the main route, typing is always available. If you click the microphone, LectaMe uses the speech recognition built into your browser. In Chrome and Edge the browser sends your audio to the browser vendor’s servers to do this; that happens outside LectaMe and falls under your browser’s terms. LectaMe itself stores no audio — only the transcribed text.
Do not name real clients, patients, colleagues or fellow students. The conversation is practice with a made-up person. What you say is transcribed, stored and sent to an AI supplier — so do not mention names or situations that could be traced back to a real person.
Coaching and assessment are separated
In our mentoring and development environments you write things down about your own development. That only works if you know your manager is not reading along. So this is not merely a setting — it is how the system is built.
The promise. Data recorded within LectaMe as coaching data is processed solely for the purpose of professional development and mentoring. It is not disclosed to managers, HR, assessors or other representatives of your employer, and is not used for formal personnel assessment, unless you have deliberately moved that data to the formal space yourself.
- Private. Only you. No mentor, no manager, no assessor. These texts also do not go to an AI model unless you press a button yourself and point out yourself what may be looked at.
- Coaching. You and the mentors linked to you. Who those are is shown by name next to the input field — not as a category, but as people.
- Formal. What counts towards an assessment. A team leader or assessor reads only here, and has no technical access to the coaching space.
The step from coaching to formal is a copy action only you can perform. A copy is placed in your formal file; the original stays unchanged in your coaching space. There is no switch that converts something from coaching to formal.
This separation is also in our data processing agreement, so your employer cannot obtain coaching data through an administrator or an export request either. Two exceptions remain: a legal obligation on us, and a request from you about your own data.
13. Security logs and error monitoring
To secure the platform, we keep logs of failed login attempts, technical errors, blocked requests and relevant security events. These logs may contain IP addresses and technical identifiers. We do not retain them longer than necessary (see retention periods).
We do not use external error monitoring services. Logs are kept in our own infrastructure.
14. Which suppliers do we share data with?
We use carefully selected suppliers. With each supplier we have, where applicable, concluded a data processing agreement or equivalent safeguard.
| Supplier | Service | Location | Safeguard |
|---|---|---|---|
| Leaseweb Netherlands B.V. | VPS-hosting en gegevensopslag | Amsterdam, Nederland | Verwerking binnen EER. |
| Cloudflare Inc. | CDN, DNS, edge-beveiliging en AI-inferentie | Wereldwijd edge-netwerk | EU-US Data Privacy Framework (DPF) gecertificeerd; aanvullend Standard Contractual Clauses via Cloudflare DPA. |
| Groq, Inc. | AI-inferentie | Verenigde Staten | Standard Contractual Clauses + interface-waarschuwing tegen invoer van persoonsgegevens. |
| Mistral AI SAS | AI-inferentie | Frankrijk (EER) | Verwerking binnen EER. Hergebruik van invoer voor modeltraining uitgeschakeld in de accountinstellingen. |
| Mollie B.V. | Betalingsverwerking | Amsterdam, Nederland | Verwerking binnen EER. |
| Resend, Inc. | Transactionele e-mail | Verenigde Staten (EU-routes beschikbaar) | Standard Contractual Clauses; dataminimalisatie (alleen noodzakelijke transactionele berichten). |
| Google Ireland Ltd. | Optionele website-analytics | EU + VS | EU-US Data Privacy Framework; IP-anonimisatie ingeschakeld; geen verwerking zonder consent. |
We do not sell personal data, do not use it for advertising and do not pass it on to third parties other than as described in this table or where legally required.
15. Transfers outside the EEA
Our primary storage is located within the European Economic Area. For suppliers whose processing (partly) takes place outside the EEA, we apply safeguards such as the EU-US Data Privacy Framework or Standard Contractual Clauses, as indicated in the table above. This concerns in particular our AI supplier (United States) and the global edge network of our CDN supplier.
16. Retention periods
We do not retain personal data longer than necessary for the purpose for which we collected it. The main periods:
| Category | Retention period |
|---|---|
| Account data and presentations | Up to 30 days after a deletion request (cooling-off); permanently deleted thereafter. Remnants in rotating backups disappear according to our hosting provider's backup schedule. |
| Guest session (cookie 'Start for free') | 30 days after the last activity. |
| Live sessions, participant schema and answers | Until the teacher deletes them or cancels their account; for inactive sessions set at a maximum of 12 months after the session ends. |
| Error logs | Maximum 30 days. |
| Security logs | Maximum 12 months. |
| Optional analytics | According to the Google Analytics setting (default 14 months), only after consent. |
| Cookie preferences | Until you change or withdraw them. |
| Invoices and accounting | 7 years (statutory tax retention obligation). |
| Lesson archive of a live lesson | If you follow a lesson while signed in, it goes into your archive under My lessons and stays there until you delete it yourself. If you follow it without signing in, it is deleted automatically at most 11 months after it was last opened. Your teacher can also link a lesson to your class afterwards; it then appears under My lessons marked as given by your teacher, even if you were absent. You can delete it yourself. |
| Practice conversations in the Conversation Trainer | The transcript and the tips are deleted after 180 days; the session record itself after 12 months. |
| Assignment work without an account (share code) | The self-chosen name is removed after 6 months of inactivity, the work itself after 12 months. Work a teacher has linked to a student account follows the retention period for ordinary assignment work from that moment on. |
17. Privacy rights
Under the GDPR you have the following rights:
- Right of access to the data we process about you.
- Right to rectification of inaccurate data.
- Right to erasure ("right to be forgotten").
- Right to restriction of processing.
- Right to object to processing based on a legitimate interest.
- Right to portability of your data in a machine-readable format.
- Right to withdraw consent given at any time.
- Right to lodge a complaint with the supervisory authority (see "Contact and complaints").
Would you like to exercise a right? Email privacy@lectame.com or use (for logged-in users) the export and delete options in your settings.
18. Privacy requests from students and participants
If you do have an account and a guidance file, your school or organisation is the controller. You can always view your data in the environment itself, and a request for correction or deletion goes through your school. You may also submit a request about your own data directly to us; we will then coordinate with your school, because it decides what must remain in the file.
Participants in a live session do not have an account. When a school or organisation uses LectaMe as a processor, participants' privacy requests go through that school or organisation. They are the controller and can request deletion or access from us on the participant's behalf.
With fully anonymous participation (pseudonym only, no other identifying characteristics) it is possible that answers can no longer be linked to a specific person. In that case a deletion or access request cannot be fully complied with.
19. Minors
LectaMe is intended for use in an educational context, in which minors can participate via a session code under the responsibility of their school. We do not knowingly collect account data of children under 16 without parental or school authorisation. Do you suspect that an account was created improperly? Contact us at privacy@lectame.com.
20. Security in outline
We take appropriate technical and organisational measures to protect your data, such as encryption of connections, storage within a shielded EU platform, role-based access, monitoring and logging. You will find a more detailed explanation on the security page.
21. Changes to this policy
We may amend this privacy policy from time to time. We announce substantial changes via the website or, for logged-in users, by email. The date of the most recent version appears at the bottom of this page.
22. Contact and complaints
Questions about this policy or about the processing of your data? Email us at privacy@lectame.com. General questions can also go to info@lectame.com.
Do you disagree with our response? You always have the right to lodge a complaint with the Autoriteit Persoonsgegevens.
LYNT V.O.F. (trading as LectaMe)
Rotterdam, Nederland
Chamber of Commerce 97241229
Email: privacy@lectame.com
See also
Document version 2.5 · Last updated on 1 september 2026.
Questions? Email privacy@lectame.com.