GAT Labs Student Data Privacy Policy
Effective October 4th, 2026.
To view the previous version of our Student Data Privacy Policy,
click here
Scope of this Policy
This policy applies to GAT Labs services and applications used by educational institutions. Optional or premium products that involve additional or specialized processing of student data, including GAT Taskmaster – are also subject to the applicable product-specific disclosures set forth in Addendum A of this policy. Taskmaster requires separate authorization by the school or district before deployment.
What information we collect and what we use it for
GAT Labs provides cloud-based auditing, management, security, alerting, and reporting services for Google Workspace environments.
GAT Labs processes student data only as necessary to provide, secure, maintain and support the services authorized by the Customers in accordance with the applicable Privacy policy and Terms of Service.
Depending on the services and features enabled by the school or district GAT Labs may collect and process student personally identifiable information (PII) data. This may include identifiers and account information such as name, email address, phone number, IP addresses, only at the level necessary to provide services to educational domains.
Student information may be obtained from two primary sources of information:
- First, authorized GAT Labs services may retrieve information directly from Google Workspace through Google APIs which may include students’ first and last names, email addresses, phone numbers (only if applicable), student Google IDs, geolocation data, UDID, grades and other Google Workspace information required for the authorized service.
- Second, where the school has deployed an applicable GAT Labs Chrome extension, GAT Labs may process information relating to browsing and online activity, such as geolocation data, browser type, browsing access time, time spent on site, page views, referring URLs where enabled.
GAT Labs does not make student personal information publicly available.
How we gather, store and protect your information
Student data is treated as confidential and is hosted exclusively on Google Cloud Platform (GCP). Data transmitted between Google Workspace for Education and GAT Labs is protected in transit using HTTPS/TLS and other appropriate security controls.
GAT Labs uses a multi-tenant architecture with technical and logical controls designed to segregate Customer data and prevent unauthorized access between Customer environments.
GAT Labs maintains technical and organizational security measures designed to protect student information, including encryption, network and application security controls, access controls, password protections, and multi-factor authentication for appropriate systems and personnel.
GAT Labs maintains technical and administrative controls designed to protect the confidentiality, integrity, and availability of the information we process. Additional information about our controls, policies, and procedures can be reviewed on the GAT Labs Trust Report subject to applicable access requirements.
Employees and contractors with authorized access to Customer information are subject to confidentiality obligations and must complete applicable privacy and data security training during onboarding and periodically thereafter. Access is granted according to the principle of least privilege, based on job responsibilities, and is subject to regular review.
GAT Labs conducts regular security audits, internal vulnerability assessments, and external and internal penetration testing to evaluate and improve the effectiveness of our security controls.
GAT Labs is headquartered in the European Union, and maintains a privacy and security program designed to comply with applicable data-protection requirements, including the GDPR. GAT Labs also maintains SOC 2 Type 2 certification. When providing services to U.S. K-12 schools, GAT Labs maintains contractual, technical, and organizational safeguards designed to support Customers’ compliance with applicable student-privacy requirements, including FERPA and COPPA. Where GAT Labs processes education records under FERPA’s school official framework, such information is processed only for the institutional purposes authorized by the school or district and subject to applicable use and redisclosure restrictions.
How we assist with protecting your students’ data and help to embrace healthy digital behavior
GAT Labs is committed to protecting student information and provides schools and districts with tools designed to support student safety and responsible digital activity. Customers determine how these features are configured and used within their educational environments.
GAT Shield Alert Rules and Site Access Control features allow schools to monitor and manage students’ online activity, and may assist Customers in meeting applicable requirements associated with Children’s Internet Protection Act (CIPA).
Your rights to control your data collection
GAT Labs does not claim ownership of student data. Schools and districts retain their applicable rights and control over student data, and GAT Labs processes such data only for authorized purposes in connection with the services provided to the Customer.
Schools
GAT Labs services are generally deployed and administered by authorized Google Workspace super administrators acting on behalf of a school or district. The school or district authorizes GAT Labs to process student data through the applicable service agreement, Terms of Service and other applicable data-processing terms.
Schools and districts retain control over their student data and may request access to, correction of, export of, or deletion of data processed by GAT Labs, subject to applicable contractual requirements, technical limitations, retention obligations and applicable law.
An authorized domain administrator may access, export, or correct available auditing data using functionality provided within applicable GAT Labs products.
Other requests concerning access to, correction of, or deletion of student data may be submitted to support@generalaudittool.com
Parents
Some GAT Labs services may process personal information relating to children under the age of 13. Where COPPA applies, GAT Labs processes such information in accordance with applicable COPPA requirements and the authorization provided by the relevant school or district. GAT Labs also works with Customers to support applicable federal and state student-privacy requirements.
Parents and guardians may have rights under applicable law to review information concerning their child, request correction or deletion of certain information, or request that certain collection or processing cease. Requests involving education records should generally be directed first to the student’s school or district, which controls the educational account and determines the appropriate response under applicable law.
Parents or guardians wishing to exercise applicable rights should contact their school’s Data Privacy Office (DPO) or district administrator. GAT Labs will assist the school or district with appropriate requests in accordance with applicable law and contractual obligations. Questions may also be copied or directed to support@generalaudittool.com.
The consequences of any party’s refusal to collect data may result in GAT Labs’ inability to provide services in accordance with the provisions of the contract.
Data retention and termination
GAT Labs retains student information only for as long as necessary for the purpose for which it was collected. Unless a shorter retention period applies, Customer student data is deleted from GAT Labs’ active systems within 31 days following expiration or termination of the applicable Customer contract. Data retained in backups, security logs, or other limited systems is deleted or rendered inaccessible in accordance with GAT Labs’ applicable retention schedules and legal obligations.
Data breach response plan
GAT Labs maintains an incident-response and data-breach response plan. In the event of a security incident involving Customer student information, GAT Labs will investigate and respond to the incident and will notify affected Customers in accordance with applicable law and applicable contractual notification requirements.
How we disclose information
GAT Labs adheres to the highest standards of privacy and security policy. GAT Labs strictly enforces the following disclosure rules:
- No Commercial Use: GAT Labs does not sell, trade, lease, or rent information about your students, or any other data we collect, to anyone.
- No Advertising or Marketing: GAT Labs never uses student data to target advertisements or marketing materials to students or families.
- No Third-Party AI Training: GAT Labs does not disclose, share, or utilize student data to train third-party artificial intelligence (AI) or machine learning (ML) models, nor do we permit our vendors, subprocessors, or contractors to do so. GAT Labs does not utilize student data to train proprietary, core commercial models, except for localized, security-focused functional optimizations within authorized premium services (as detailed in Addendum A).
Any third-party vendors or sub-processors utilized by GAT Labs to deliver our services are contractually bound to data privacy and security standards at least as strict as those outlined in this policy.
Third-party service providers:
GAT Labs will not disclose student information to any third party, except to authorized GAT Labs contractors who help us deliver our services to Customers. These contractors are limited to specific operational categories, including:
- Cloud Infrastructure Provider – Google Cloud Platform (GCP): To securely host and store student data on the Google Cloud Platform.
- Customer Support Tools & Ticketing Systems: To log, manage, troubleshoot, and resolve customer service and technical requests.
All GAT Labs contractors have signed legally binding Non-Disclosure Agreements and are committed to the same high security standards as GAT Labs employees. Both employees and contractors are authorized to access student information only as necessary to perform the specific work required by their role. GAT Labs operates strictly on the principle of least privilege, and we perform regular access control reviews to eliminate unnecessary access. Additionally, all personnel must complete annual data safety awareness training, and we maintain strict procedures to immediately revoke access upon termination of cooperation.
Business transfers:
In the event of a merger, dissolution, or similar corporate event, or sale of all or substantially all of our assets, we expect that the information we collect will be transferred to the surviving entity or acquiring entity. All such transfers will be subject to our obligations regarding the privacy and confidentiality of such personal information as set out in this privacy policy.
Student information must be kept confidential during these processes, without compromise.
Disclosure to public authorities:
GAT Labs may disclose student information where required to comply with the applicable law, a valid court order, or other legally binding process.
Privacy Policy changes
GAT Labs may update this Privacy Policy from time to time to reflect changes in our services, privacy practices, security measures, or applicable legal requirements. Material changes will be posted on our website and communicated to Customers in accordance with applicable contractual or legal requirements. Where appropriate, Customers will be notified in advance using the contact information associated with their account.
Contact information:
If you have any privacy or complaint concerns, please contact the GAT DPO Team at dpo@generalaudittool.com
For urgent matters, call us on +353 1 678 9070
GAT Labs’ headquarters are located at:
12 Hume Street,
Dublin 2,
D02 XN44, Ireland
You can also submit a formal complaint to the iKeepSafe Safe Harbor consumer complaint email address at COPPAPrivacy@ikeepsafe.org
Addendum A: GAT Taskmaster Privacy Policy Disclosure
Use of Built-In, In-House Artificial Intelligence for Security, Assignment Integrity, and User Authentication
- Product Scope: This Addendum applies exclusively to schools and districts that separately authorize and deploy the premium GAT Taskmaster product. Taskmaster is not enabled as part of the GAT Labs’ standard services unless the Customer affirmatively authorizes its deployment.
- AI Processing & Model Optimization: Taskmaster utilizes proprietary artificial intelligence based on large numerical and statistical machine learning models (LNMs) developed entirely by GAT Labs. This model operates within a secure, isolated computing environment. GAT Labs deploys and optimizes this model for the sole purpose of supporting the product’s internal security operations. Any data processing, optimization, or local model calibration is performed strictly to maintain, analyze, and improve the accuracy of user authentication and assignment integrity functions.
- Data Types Collected: For identity-verification and assignment-integrity purposes, Taskmaster analyzes limited behavioral biometric data consisting strictly of typing patterns, rhythms, and cadence categories (keystroke dynamics). Taskmaster does not collect physiological biometrics such as facial, fingerprint, or iris data.
- Regulatory Compliance: In accordance with 16 CFR § 312.2 (COPPA), the data processed by this model is used exclusively to maintain and analyze the functioning of the service, verify student identity, and prevent unauthorized access or fraud. GAT Labs does not use this data to profile individual students for commercial gain, serve targeted advertisements, or share data with third-party AI platforms. This localized processing strictly limits data utilization to the internal functional exceptions permitted under the Children’s Online Privacy Protection Act (COPPA) and the School Official exception of FERPA.