Privacy Notice
- Last updated
- 25 August 2026
- Version
- 2026-08-25-v1
- Published by
- Prodia Systems Limited
1. Who is responsible for your data
The controller for the processing described here is Prodia Systems Limited, the company that operates the EyeSay AAC brand.
Prodia Systems Limited27 Pembroke Street UpperDublin 2D02 X361IrelandCompany No. 822962Registered in Ireland. Private company limited by shares.contact@prodiasystems.comWe have not appointed a statutory Data Protection Officer. Data protection questions and requests go to contact@prodiasystems.com.
2. What this notice covers
EyeSay is delivered across two separate origins, and they behave very differently:
- eyesayaac.com — this public website. Marketing and legal information only. It holds no account system, no communication data and no database access.
- console.eyesayaac.com — the authenticated product for adults, and the communicator app itself. Accounts, configuration and the communicator's device-local state live there.
3. Data we process from this website
| What | Where it comes from | What we do with it |
|---|---|---|
| Your name, email address, role and setting, and anything you type into the early access form | Given by you, voluntarily | Assessing and replying to an early access request |
| Email correspondence | Given by you when you write to us | Answering your question and keeping a record of the exchange |
| Your cookie/storage choice | Stored in your own browser when you make a choice | Remembering that choice and its version. No identifier is attached |
| Technical request data such as IP address, user agent, requested URL and timestamps | Generated automatically by our hosting provider when your browser requests a page | Serving the site, security, abuse prevention and diagnosing faults |
There is no advertising technology, no cross-site tracking, no fingerprinting and no behavioural profiling on this website. No analytics or marketing provider is currently installed; see the cookie notice for the current inventory.
The early access form on this website is a staging form: it does not transmit or store your entry anywhere, and the page tells you so when you submit it. If and when it is wired to a backend, that backend will be a lead-only store with no access to communicator data, and this notice will be updated first.
4. Data in the EyeSay console
The console is for adults: guardians, parents, speech and language therapists, teachers and team members. When an adult creates an account there we process:
- account identity and sign-in data (email address, authentication records);
- the configuration an adult creates for a communicator: profile name, vocabulary definitions, motor slot map, routines, and the people, places, things, interests and activities that make up that communicator's world;
- team membership and role, so the right adults can see the right profile;
- derived measures such as vocabulary breadth, number of independent selections, unresolved word searches, the mix of communication functions used, and access errors;
- version and audit records of configuration changes, so a change can be traced.
Any personal data an adult enters about a communicator, including a child, is personal data about that child. We process it on the instruction of the account holder in order to provide the service.
5. The communicator's own words
Concretely, in the current build: the utterances a communicator selects, the photos used in Show Me, any microphone input used by a browser listening feature, and continuous location are not sent to us and not stored in our cloud. Speech is produced by the device's own built-in voices.
We will not promise absolutes we cannot keep. A device is not a vault: anyone with physical access to an unlocked device, or a device-level backup service configured by its owner, may be able to reach locally stored data. Adults choose which features to enable, and a future feature that would change this design would require a notice update and a clear choice before it operated.
See the child privacy notice for the layered, plain-language version written for communicators and their guardians.
6. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Serving this website, keeping it available and secure | Legitimate interests (Art. 6(1)(f)) — operating and protecting our own service |
| Remembering your cookie choice; storage strictly necessary to deliver the site | Legal obligation and legitimate interests for the record of choice; the underlying storage is exempt from consent as strictly necessary |
| Setting optional analytics or marketing storage, if ever installed | Consent (Art. 6(1)(a)) plus ePrivacy consent. Off unless you switch it on |
| Handling an early access request and replying to you | Legitimate interests, and steps at your request prior to a contract (Art. 6(1)(b)) |
| Providing console accounts and the EyeSay service to account holders | Performance of a contract (Art. 6(1)(b)) |
| Configuration of a communicator profile by a guardian or authorised professional | Performance of the contract with the adult account holder; for under-16 profiles, guardian-controlled setup rather than a child's click |
| Derived insight measures shown to the adult team | Performance of a contract; legitimate interests in improving product safety and quality, assessed as balanced because no raw transcript is used |
| Security logging, abuse prevention and audit records | Legitimate interests and, where applicable, legal obligation |
| Optional newsletter, if you ever ask for one | Consent, separately given and withdrawable at any time |
Where we rely on legitimate interests we have considered your interests and rights, and you can object at any time — see section 11.
7. Recipients and processors
We do not sell personal data and we do not share it for advertising. We use a small number of service providers who process data on our instructions under Article 28 contracts. Website providers and console providers are listed separately in the service provider register.
We may also disclose data to professional advisers, or to a public authority or court where we are legally required to do so.
8. International transfers
Our aim is that personal data for EyeSay is hosted in the EU/EEA. Where a provider processes data outside the EEA, transfers are made on a valid Chapter V mechanism — normally the European Commission's Standard Contractual Clauses, together with the provider's supplementary technical measures such as encryption in transit and at rest.
We will not state a specific hosting region or transfer mechanism in this notice unless it is confirmed in our provider configuration. The provider register records what is currently confirmed and what is still to be confirmed before a public commercial launch.
9. How long we keep data
- Early access enquiries and correspondence: kept while the programme is open and for up to 24 months after our last contact, then deleted.
- Console account and configuration data: kept for as long as the account is active. On closure, we delete or anonymise it within 90 days, except where a legal retention obligation applies.
- Derived insight measures: kept with the profile and deleted with it.
- Audit and version records: retained for up to 24 months so a configuration change can be traced.
- Security and server logs: short-lived, normally weeks rather than months, per our hosting provider's retention.
- Your cookie choice: stored in your browser for up to 12 months, or until you clear it or change it.
- Communicator message history: held on the device, under the control of the communicator and the adults who manage that device. Not retained by us.
Where a period above is expressed as a principle rather than a fixed number, it is because the retention depends on a provider setting we will confirm before public launch. We keep only what we need, for as long as we need it.
10. Security
Traffic is encrypted in transit. Console data sits behind authentication with row-level access rules so an account only reaches the profiles it is entitled to, sensitive communication content is kept device-local by design, access follows least privilege, and dependencies are updated. More detail, and how to report a vulnerability, is in the security statement.
11. Your rights
Under the GDPR and the Data Protection Act 2018 you have the right of access, rectification, erasure, restriction of processing, objection to processing based on legitimate interests, and data portability where the processing is by automated means and based on consent or contract. Where we rely on consent you may withdraw it at any time, which does not affect processing already carried out.
A child has these rights in their own name. In practice a guardian usually exercises them on the child's behalf, and we take the child's own views into account where we reasonably can. How to make a request, and what proportionate identity checks we may need, is set out in your data rights.
We do not carry out automated decision-making producing legal effects, profiling for advertising, or emotion recognition. See the AI and automation notice.
12. Complaints
Please raise a concern with us first at contact@prodiasystems.com — we would like the chance to put it right. You also have the right to lodge a complaint with the Irish Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland (dataprotection.ie), or with the supervisory authority in your EU/EEA country of residence or work.
13. Changes to this notice
We update this notice when the product changes. Each version carries a date and a version stamp, shown at the top of this page. Where a change materially affects you we will make it prominent rather than silent, and where a change requires consent we will ask before the new processing begins.
The terms that govern console accounts are the platform terms. The console itself is at console.eyesayaac.com.