Compliance · GDPR Art. 35
DPIA Summary
Public summary of Keypra's Data Protection Impact Assessment for the combined processing of behavioural telemetry and AI-graded competence scoring.
Last updated: May 2026 (rev. 2)
1. Why a DPIA
GDPR Article 35(3)(a) requires a Data Protection Impact Assessment for “a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects”.
Keypra's combined feature surface — typing-cadence behavioural telemetry, AI-graded competence assessment, and the existence of employer-side surfaces in the Enterprise product — falls close enough to that threshold that we maintain a full internal DPIA and publish this public summary. It is voluntary disclosure, not an admission that the underlying processing is high-risk.
2. Processing described
- Behavioural Telemetry. Keystroke-cadence, pause and revision counts, session duration, “thinking ratio”. Consent-gated. Methodology at Behavioural Telemetry.
- AI-graded Competence Assessment. Four-rubric (0–25) scoring with a 60/100 pass mark; AI Maturity composite (70% objective + 30% self-reported). Methodology at Competence Methodology.
- Enterprise visibility surfaces. Org admin, manager, and lecturer dashboards. Aggregate-only; per-person classifications are blocked at the RPC layer.
3. Necessity and proportionality
Behavioural telemetry and competence grading are the non-substitutable mechanisms by which Keypra delivers its core promise — measurable AI fluency improvement. Without them the learner has no feedback loop and the employer has no programme-level ROI signal. Less-intrusive alternatives (e.g. self-reported skill only) were rejected because they fail the evidentiary standard expected by Enterprise buyers.
4. Risks identified
- Function creep. Behavioural data being used for employment decisions outside the trained purpose.
- Re-identification of low-volume cohorts. Aggregate dashboards where small departments could expose individual members.
- Automated grading errors. AI grader producing a result that materially mis-represents the learner.
- Cross-border transfer of profiling data. AI grading routes through model providers outside the EEA.
5. Mitigations in place
- Employer-side classification ban. RPC-level block on exposing
mastery_status,tier,ali_scoreor derived badges to org admins, managers or lecturers. Per-person telemetry is member-private only. - k-anonymity (k ≥ 3). All aggregate Enterprise dashboards suppress buckets with fewer than three members.
- Contestability (Art. 14 EU AI Act). Every AI-graded result includes a
[CONTEST]row that routes to human review atprivacy@keypra.comwith a 72-hour acknowledgement and one-month resolution SLA. - Contractual no-employment-decision clause. Terms §10a and DPA §8b bind Enterprise customers as deployers under Art. 4 of the EU AI Act not to use Keypra outputs for hiring, promotion or discipline.
- Demographic-blind grading. The grader receives only the prompt text and scenario, never protected characteristics. See Fairness Methodology.
- Transfer safeguards. EU-US Data Privacy Framework or Standard Contractual Clauses on every cross-border AI provider; full mapping on the Sub-Processors page.
- Consent ledger. Append-only record of every consent grant, revoke and renewal; methodology and 3-year retention disclosed in Privacy §5.
5a. Internal AI literacy (EU AI Act Art. 4)
Article 4 of the EU AI Act requires providers and deployers of AI systems to ensure a sufficient level of AI literacy among the staff and other persons dealing with the operation and use of those systems. Keypra OÜ is, as at the date of this summary, a single-person micro-enterprise: the founder and director (Ferenc Szilágyi) holds end-to-end product, security and compliance responsibility for the platform and is the author of the public methodology pages linked above. There is therefore no separate staff cohort to train; the literacy obligation is discharged by the founder's continuous involvement in the EU AI Act, GDPR, DSA and ePrivacy work evidenced in the changelog and these methodology pages. If Keypra hires additional staff with access to the AI features, an internal AI-literacy programme will be introduced before such staff are granted production access, and that change will be reflected in the next revision of this DPIA summary.
6. Residual risk
After mitigations, residual risk is assessed as low to moderate: the most material remaining risk is contractual breach by an Enterprise customer using Keypra data for an employment decision in violation of Terms §10a. This risk is addressed through (a) contractual liability, (b) the structural impossibility of obtaining per-person scores from the platform in the first place, and (c) the published [CONTEST] channel.
7. Review cycle
The full internal DPIA is reviewed at least once per calendar year, on each material change to the grading rubric, behavioural metric set, or Enterprise visibility surface, and on each addition of a new AI model provider that processes prompt content. The current internal version is available to Enterprise customers under NDA on request to enterprise@keypra.com.
See also: Behavioural Telemetry · Competence Methodology · Fairness Methodology · Privacy Policy