Privacy & Data Protection

    Privacy Policy

    Your privacy matters to us. Learn how we collect, use, and protect your personal information.

    Last updated: July 19, 2026

    1. Who We Are

    GenAlpha ("GenAlpha", "we", "us") operates the GenAlpha online learning platform from Tunisia, at Avenue Egypte, Immeuble El Bassatine, 1er Etage, Cité Erriadh, 2084 Borj Cédria, Tunisia. This policy explains what personal data we process about learners, trainers, and site visitors, why we process it, and the choices and rights you have.

    Full registered company details (legal entity name and business registration number) are available on request from our Privacy Contact below.

    GenAlpha has not formally appointed a Data Protection Officer. Instead, questions and requests about privacy should be sent to our Privacy Contact:

    Privacy Contact: privacy@genalpha.tn

    General inquiries: contact@genalpha.tn

    Phone: +216 58 514 144

    2. Personal Data We Collect

    We collect the following categories of personal data, depending on how you use the platform:

    • Account & identity information: name, email address, password (stored hashed by our authentication provider), and account role (learner, trainer, or administrator).
    • Profile information: avatar, bio, phone number, location, website, and (for learners) date of birth, education level, interests, and current status, where you choose to provide them.
    • Trainer verification & professional information: expertise, years of experience, qualifications, LinkedIn profile, professional bio, company logo, and certificate stamp/signature images, plus fiscal/tax status information (e.g. freelancer or "patente" status) used for Tunisian trainer payout compliance.
    • Learning activity: course enrollments, lecture progress, completion status, and last-accessed timestamps.
    • Quiz and assessment data: quiz attempts, answers, and scores.
    • Assignments and project submissions: assignment, mini-project, and capstone submissions, including uploaded files, links, written answers, grades, and trainer feedback.
    • Portfolio information: learner portfolio projects and their visibility setting (private, visible to trainers only, or public).
    • Certificates: issued certificates and the data shown on our public certificate verification page (learner name, course, trainer, and issue date) to anyone who has the certificate link.
    • Reviews and user-generated content: course ratings and written reviews, which may be shown publicly on course pages.
    • Messages and support communications: internal messages between learners and trainers, support tickets, and live chat conversations.
    • Payment and transaction metadata: order and payment records, payment method, amounts, currency, and status. For cash-on-delivery orders we also collect a delivery name, phone number, and address. We do not store full card numbers ourselves — payment is handled by our payment provider(s).
    • Payout and trainer financial information: trainer wallet balances, earnings, settlements, and payout history.
    • Uploaded content and files: images, videos, documents, and other files you upload to courses, assignments, portfolios, or support requests.
    • Device, IP, and security information: IP address, browser/user-agent, and security/audit log entries for actions like sign-in, password changes, and account deletion requests.
    • Cookies and analytics identifiers: see Section 10.
    • AI prompts, inputs, outputs, and feedback: see Section 6.

    3. Where Your Data Comes From

    • Directly from you: when you register, complete your profile, enroll in courses, submit work, write reviews, message other users, or contact support.
    • From a trainer: grades, written feedback, and messages a trainer sends you about your coursework.
    • Automatically through platform use: progress tracking, login events, device/IP information, and analytics events described in Section 10.
    • From connected sign-in providers: if you register or sign in using a third-party account (e.g. Google), we receive the name and email address that provider shares with us.
    • From payment providers: confirmation of payment status for orders you place.

    GenAlpha does not currently operate a separate "organization" or team-account tier — every account is a learner, trainer, or administrator account, so this policy does not describe organization-administrator data flows.

    4. How We Use Your Data & Legal Bases

    Where the GDPR or a similar law applies to your data, we rely on the legal bases below. We do not rely on consent for every activity — most core platform functions are processed as a necessary part of delivering the service you asked for.

    PurposeLegal basis
    Creating and managing your accountContractual necessity
    Delivering purchased or enrolled courses, sessions, and certificatesContractual necessity
    Processing payments and payoutsContractual necessity; legal obligation (accounting/tax)
    Providing AI Tutor, AI Studio, and AI grading featuresContractual necessity (features you actively use)
    Personalizing recommendations based on your enrollmentsLegitimate interests
    Sending essential service communications (OTP codes, receipts, grading notices)Contractual necessity
    Sending optional marketing communicationsConsent
    Analytics and marketing cookies (Section 10)Consent
    Preventing fraud and protecting platform securityLegitimate interests
    Meeting accounting, tax, and other legal obligationsLegal obligation
    Improving platform performance and reliabilityLegitimate interests

    This table is a good-faith mapping based on how the platform currently operates and is not a substitute for qualified legal review of GDPR applicability to your specific situation.

    5. Who Can See Your Data

    • Trainers can see the name, avatar, progress, quiz results, and submissions of learners enrolled in their own courses, so they can teach and grade. Trainers cannot see a learner's email address anywhere in the platform — all communication happens through GenAlpha's internal messaging system.
    • Learners can see a trainer's public profile (name, avatar, bio, expertise) and course content. Learners do not see a trainer's private contact, verification, or financial information.
    • GenAlpha administrators and support staff can access account, course, payment, and support data as needed to operate the platform, resolve support requests, investigate policy violations, and process payouts.
    • Other learners may see your name/avatar on course discussion features, and your rating/review if you post one publicly.
    • Anyone with a certificate link can view the learner name, course, and trainer shown on our public certificate verification page.
    • Portfolio visitors can see portfolio projects you have set to "public" visibility. Projects set to private or "trainers only" are restricted accordingly.

    6. AI Processing

    GenAlpha uses AI in a few specific, opt-in places:

    • AI Tutor (chat assistant): available to learners, trainers, and admins. It uses your recent chat messages plus a summary of your own platform activity (e.g. enrolled courses, quiz scores, pending grading, course revenue) to answer questions. We do not store your chat transcripts in our database; they exist only in your browser session.
    • AI Studio / Course Builder, AI quiz generation, and AI capstone/mini-project/assignment generation: available to trainers. Trainer-provided prompts, course/module context, and text extracted from uploaded course materials are sent to our AI provider to draft course structures, lessons, quizzes, and project briefs. Trainers review and edit AI-generated drafts before publishing.
    • AI-assisted grading feedback: when a trainer requests it, submitted assignment text (and a rubric) is sent to our AI provider, which returns a suggested grade and feedback. The AI never finalizes a grade — a human trainer must review and confirm it before it is recorded.
    • AI narration/video tools: trainers can optionally generate lesson narration or presenter video, which sends lesson text and, where selected, a presenter image to our text-to-speech and video-generation providers.

    Our AI features are currently backed by Microsoft Azure OpenAI Service, ElevenLabs, D-ID, and Cloudinary. We do not use your prompts, submissions, or media to train GenAlpha's own models. We have not published a blanket promise that these external providers never use submitted data for their own model training — this depends on each provider's enterprise contract terms, which we are reviewing; contact us for the current status.

    AI outputs can be inaccurate or generic and are provided as drafts or suggestions, not final decisions. If you believe an AI-generated grade, feedback, or content is wrong, you can ask your trainer (or, for platform-level issues, GenAlpha support) to review and correct it.

    7. Sharing and Service Providers

    We share personal data with the following categories of recipients, only as needed to run the platform:

    • Hosting, database, and file storage providers: Supabase (database, authentication, and file storage) and Microsoft Azure (file/media storage).
    • Payment providers: Tunisian Post ("La Poste Tunisienne") for online payments; cash-office and cash-on-delivery orders involve delivery-related information you provide.
    • Email providers: our transactional email service, used to send OTP codes, receipts, and notifications.
    • AI providers: Microsoft Azure OpenAI Service, ElevenLabs, D-ID, and Cloudinary, as described in Section 6.
    • Analytics and advertising providers: Google (Analytics) and Meta (Pixel), only after you accept the relevant cookie category — see Section 10.
    • Trainers and organization/course staff: as described in Section 5.
    • Professional advisers: accountants, auditors, or lawyers, where necessary.
    • Authorities: courts, regulators, or law enforcement, where we are legally required to disclose information.

    We do not sell your personal information.

    8. International Data Transfers

    GenAlpha is based in Tunisia, and several of the providers listed in Section 7 (including our AI, analytics, and cloud storage providers) operate infrastructure outside Tunisia, including in the European Union and the United States. This means your data may be processed outside your home country.

    We have not yet completed a full contract-by-contract review confirming which specific safeguard (such as Standard Contractual Clauses or an applicable adequacy decision) is in place for each provider. We do not claim a specific transfer mechanism unless we have confirmed it applies. Contact our Privacy Contact if you would like current information about the safeguards used for a particular provider.

    9. Data Retention

    • Active account data: kept for as long as your account is active.
    • Account deletion requests: when you request deletion, we disable your account immediately and sign you out everywhere. Learner accounts are permanently deleted within 30 days of the request unless you contact support to cancel it; trainer deletion requests are reviewed by our team before permanent deletion.
    • Transaction, payout, and accounting records: retained for as long as required to meet Tunisian accounting, tax, and dispute-resolution obligations, even after an account is deleted.
    • Course progress, certificates, and portfolio projects: retained while your account is active, and certificates remain independently verifiable via their verification link after account deletion so credentials stay checkable by third parties.
    • Trainer verification documents: retained while you are an active trainer and for a limited period afterward to resolve any outstanding compliance, payout, or dispute matters.
    • Assignments, submissions, messages, and support tickets: retained while your account is active and for a reasonable period afterward in case of disputes or appeals.
    • AI interaction data: AI Tutor chats are not stored server-side. AI content-generation requests and grading-suggestion logs are retained for as long as needed for billing (AI credits) and quality/abuse review.
    • Security and audit logs: retained for security investigation and accountability purposes.
    • Marketing consent records: retained until you withdraw consent, plus a short period to evidence that withdrawal.

    We have not yet finalized exact numeric retention periods for every category above beyond the 30-day learner account-deletion window; those are being finalized with legal input and will be reflected here once confirmed.

    10. Cookies and Tracking

    We use the following categories of cookies and similar technologies:

    • Essential: sign-in session cookies, your language preference, and your cookie-preference choice itself. These cannot be switched off because the platform cannot function without them.
    • Analytics (optional): Google Analytics, used to understand platform usage. Loaded only if you accept analytics cookies.
    • Marketing (optional): Meta Pixel, used to measure and improve our advertising. Loaded only if you accept marketing cookies.

    You can manage these choices at any time on our Cookie Preferences page, reachable from the footer of every page. Rejecting analytics or marketing cookies is just as easy as accepting them, and non-essential cookies are not loaded until you make a choice.

    11. Data Security

    We use reasonable technical and organizational measures to protect your information, including:

    • Encryption in transit (HTTPS/TLS) for all traffic to and from the platform.
    • Row-level database access rules that restrict data access by account role.
    • Password verification before sensitive actions such as account deletion.
    • Security audit logging of sensitive account actions.

    No method of storage or transmission is completely secure, and we cannot guarantee absolute security. We do not claim to run a formal recurring third-party security audit program, dedicated staff privacy/security training curriculum, or a documented incident-response runbook at this time; if you discover a vulnerability, please report it to our Privacy Contact.

    12. Your Rights and How to Exercise Them

    Depending on your location and the legal basis that applies, you may have the right to:

    • Access a copy of your personal data.
    • Rectification: correct inaccurate or incomplete information.
    • Erasure: request deletion of your personal data.
    • Portability: receive certain data in a structured format.
    • Restriction or objection: limit or object to certain processing.
    • Withdraw consent for any processing based on consent (e.g. marketing, analytics/marketing cookies) at any time, without affecting processing already carried out.

    You can request account deletion directly from your dashboard settings (a password-verified request). For other requests, email our Privacy Contact at privacy@genalpha.tn from your registered email address so we can verify your identity; we may ask for additional verification for sensitive requests. We aim to respond within a reasonable time and will let you know if we need more time.

    Some information — such as financial, tax, or fraud-prevention records, or data needed to keep a certificate verifiable — may need to be retained even after a deletion request, as described in Section 9.

    If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In Tunisia, this is the Instance Nationale de Protection des Données Personnelles (INPDP). If you are in the European Economic Area, you may also contact your local supervisory authority.

    13. Children and Minors

    GenAlpha's services are intended for users who meet the minimum age required to enter into a binding agreement in their country of residence. We do not currently operate a separate parent/guardian-authorization flow or organization-managed student account type. We are finalizing a specific minimum-age policy with legal input; until then, we ask that account holders confirm they meet this requirement when registering.

    If you believe a child has provided us with personal data without appropriate authorization, please contact our Privacy Contact and we will review and remove it as appropriate.

    14. Changes to This Policy

    We may update this privacy policy from time to time to reflect changes in our platform, providers, or legal requirements. We will update the "Last updated" date above, and for material changes we will also post a prominent notice on the platform or email registered users before the change takes effect.