Privacy Policy
Last Updated: September 2026
Our Privacy Standard: McFLAI AS is built around European data residency. Your account data is stored in the European Union, and we keep reliance on third parties to a minimum. Where a feature does depend on a provider outside the EU, we tell you below and explain how that data is protected.
This Privacy Policy describes how McFLAI AS ("the Company", "We", "Us") collects, uses, and protects your information — on our websites (including crafting-tomorrow.eu, parentbites.eu and their subdomains), in our newsletters and webinars, and in the contact records we keep. By using our Pathfinder platform, you consent to the data practices described in this policy.
1. Where Your Data Lives
Your account data and family charters are stored in the European Union (our database is in Madrid; our application hosting is with IONOS in Germany). Some features rely on third parties: if you sign in with Google or Microsoft, your sign-in is handled by those US-headquartered providers and some data is processed outside the EU, under Standard Contractual Clauses and the EU–US Data Privacy Framework. You can avoid this by signing in with an email address and a password instead. Our website fonts are self-hosted, so loading a page makes no request to any third-party font network.
Within the EU, our runtime database and chat storage run on Firebase (Google Cloud), and generative AI features are powered by Mistral and Teuken models via IONOS infrastructure.
2. Data Collection & Usage
Personal Identifiers
To provide access and manage user accounts, we collect:
- Name and Email address (via Google or Microsoft Authentication).
- Institutional or School affiliation.
Technical Logging ("Flight Recorder")
Our application includes a local debugging tool called a "Flight Recorder." This tool captures a rolling log of your last 100 interactions (such as page views and clicks) to assist in technical support. This data is only transmitted to our Firebase database if you proactively click "Submit Feedback." If no feedback is submitted, these logs remain on your local device and are cleared upon session end.
Site Usage Analytics
We measure basic site usage with our own privacy-respecting analytics, hosted entirely within the EU. We do not use cookies. We do not store IP addresses. We do not assign persistent identifiers, and we cannot link a visit on one day to a visit on another. We do not share any analytics data with third parties. The data we collect is limited to pages viewed, country, device class, browser family, referring site, and aggregated engagement signals.
Hosting Cookies
Our hosting provider (IONOS) may set a small technical cookie used for load distribution and infrastructure-level visitor counting. It contains no personal data and is not accessed or used by us for any analytics or profiling purpose.
3. Newsletters, Webinars and the People We Work With
Beyond our websites, we keep a contact database and run a newsletter system. Both run on servers we operate ourselves at Scaleway in Paris, France, with nightly backups in Scaleway storage in Paris. This section covers the Crafting Tomorrow newsletter, the ParentBites Community mailing, our webinars and the contacts we keep.
Newsletters
- Signing up: on parentbites.eu, on news.crafting-tomorrow.eu, or by ticking the newsletter box when you register for a webinar. We send nothing until you click the link in our confirmation e-mail (double opt-in). The legal basis is your consent (Art. 6(1)(a) GDPR).
- What we keep: your e-mail address, your name if you give one, the mailings you chose, and the time and IP address of your confirmation, as proof of your consent. If you consented another way, such as on a webinar form or in a conversation, we also note where and in what words.
- Sending: our newsletter software (listmonk) runs on our own servers. The mails go out through Brevo (Sendinblue SAS, France), which processes the data on servers in the EU. Brevo tells us when a mail cannot be delivered, and an address that fails for good is taken off our lists.
- No tracking of individuals: we do not record which subscriber opened a mail or clicked a link. We only see totals per mailing.
- Leaving: every mail has a one-click unsubscribe link, free of charge and without logging in. The same page lets you change your details, download your data or delete it, or stop all mail from us. When you unsubscribe, we keep a record that you did, so that you are not mailed again by mistake; if you delete your data instead, it is removed from our newsletter system.
Webinars
- Registration: our webinars run on Microsoft Teams. Microsoft processes the registration for us under its data-protection terms; our Microsoft 365 tenant is in the EU, and Microsoft is certified under the EU–US Data Privacy Framework for any data that reaches the US.
- What we take from it: your name, e-mail address, organisation if you give it, the registration date and your answers to our checkboxes. We copy them into our contact database to run the event and to send you a reminder on the day (Art. 6(1)(b) GDPR).
- Mails afterwards: we send you follow-up material, such as the slides or a link to watch the recording, only if you ticked the follow-up box, and our newsletter only if you ticked the newsletter box and then confirmed your address.
- Recordings: we may record a webinar so that people can watch it later, and Teams shows everyone a notice when recording starts. If you switch on your camera or microphone, you may be seen or heard in the recording; if you would rather not be, keep them off and ask your question in writing. We do not send recordings out: we keep them on our own servers in the EU, where you can watch them, for example as an event recap on parentbites.eu. We may use short clips for marketing and on social media, but only clips that show our team and the speakers — never participants. We do this in our legitimate interest in making the sessions available (Art. 6(1)(f) GDPR). You can object at any time, and we will then remove your contribution from the recording where we can.
The People We Work With
- Business contacts: if you work with us or we are in talks — as a school, company or partner — we keep your name, work contact details, organisation, role and a record of our contact in a CRM we host ourselves (EspoCRM). We do this to prepare or carry out our work together (Art. 6(1)(b) GDPR) or, for other business contacts, because we have a legitimate interest in keeping in touch with people in their professional role (Art. 6(1)(f) GDPR). You can object at any time, and we will delete your record.
- ParentBites community: if you take part in the ParentBites community, we keep one record per person so that we know which mailings and events you signed up for (Art. 6(1)(f) GDPR). If you have a ParentBites account, we check once whether its e-mail address is already on our mailing list, so that we offer you the mailing only if it is not.
- Meeting notes: after a meeting we keep a short summary of decisions and next steps. We never store a recording or transcript, and never health, family or other sensitive details.
- No assumed consent: working with us never puts you on a newsletter. You receive one only if you signed up for it.
How Long We Keep It
- Newsletter subscriptions: until you unsubscribe or delete your data. When you unsubscribe, we keep a record that you did, so that you are not mailed again by mistake.
- Webinar registrations without any consent: 12 months after the event.
- Webinar recordings: for as long as we offer the session as a recording or recap.
- Meeting summaries: 3 years after the meeting, or 1 year after our work together ends, whichever comes first.
- Contacts with no activity: deleted after 24 months.
- Clients: for the length of our relationship plus 2 years. Invoices and contracts are kept separately, for the period the law requires.
- Server logs of these systems (IP address, address requested, time): overwritten within days.
- Backups: nightly copies are kept for 90 days, so an erased record is gone from our backups within 90 days. If we ever restore a backup, we re-apply the erasures made since.
If We Did Not Get Your Details From You
Some records reach us from a webinar registration handled by Microsoft, or from the contact system we used before. This policy is how we tell you about them. You can object or ask us to delete your details at any time.
4. Artificial Intelligence & Curriculum Data
AI Integrity
We use AI to support educational outcomes while maintaining strict privacy boundaries:
- No Training: Your inputs and personal data are never used to train or improve the underlying AI models (Mistral/Teuken).
- Contextual Accuracy: We connect to official governmental APIs including Norway (Udir) and Finland (ePerusteet) to ensure AI responses align with national curriculum standards.
5. Third-Party Services
We do not sell your data. We share it only with the following service providers, each for the purpose named:
- IONOS: Cloud infrastructure and AI model hosting.
- Google/Firebase: Authentication and runtime data storage.
- Microsoft: Authentication services and registration for our Teams webinars.
- Scaleway (France): Servers in Paris for our newsletter and contact systems, their backups and our internal e-mail notifications.
- Brevo (France): Sending our newsletters, from servers in the EU.
6. Links & Embedded Content
We link to news and articles from third parties. Once you click through, that site's own privacy policy applies and what happens there is beyond our control.
Our own video — including webinar recordings — is hosted on our EU infrastructure (IONOS) and streamed through our own backend, so no third-party video service is involved and only our servers see your request. Where we instead embed a third-party video (for example YouTube or Vimeo), it loads from that provider, which may see your IP address or set its own cookies when the video plays; for YouTube we use its privacy-enhanced "no-cookie" embed.
7. Institutional Compliance & Children's Privacy
As an EdTech provider, McFLAI often acts as a Data Processor for schools or municipalities (the Data Controllers). We do not knowingly collect data from children under the age of 13 without appropriate authorization from the educational institution or legal guardian, in accordance with national laws in Norway.
8. Your Rights & Data Retention
You can access, correct, export, or delete your data at any time via our contact page. For our newsletters you can also do this yourself from the link at the foot of every mail. You can withdraw a consent at any time; this does not affect what we did before you withdrew it. You can also object to any processing we base on legitimate interest. We delete your account data and family charter when you delete your account. We keep payment and invoice records for the period required by law. How long we keep newsletter and contact data is listed in section 3. We respond to data requests within one month. You also have the right to lodge a complaint with a data-protection supervisory authority. Our main establishment is in Oslo, so the authority responsible for us is Datatilsynet, the Norwegian Data Protection Authority (datatilsynet.no); you can also complain to the authority in the EU or EEA country where you live or work.
9. Contact Information
For privacy inquiries or to exercise your data rights, please contact:
McFLAI AS
Huldreveien 6J, 0781 Oslo, Norway
Email: support@crafting-tomorrow.eu