LUCA Privacy Notice

This Privacy Notice explains how personal data is collected, used, and protected when you use Lancaster University Careers Assistant (LUCA)

LUCA is operated by Lancaster University and forms part of a Proof of Value project exploring AI-supported career support.

This notice should be read alongside Lancaster University’s overarching data protection policies.

Data Controller

Lancaster University is the Data Controller for personal data processed through Hidden Gems.

If you have any questions about this notice or how your data is handled, you can contact the University through its established data protection channels.

Lawful Basis for Processing

LUCA processes personal data under the following lawful bases:

  • Public task – processing is necessary for the performance of the University’s public task in providing student services and enhancing student experience
  • Legitimate interests – to evaluate, improve, and safely operate digital services
  • Consent – where optional features are offered, such as preference setting or future contextual features

You can withdraw consent for optional features at any time without affecting access to core services.

Not all of the above rights are absolute and some may only apply in specific circumstances. For further information on your rights, please visit this webpage.

What Personal Data We Collect

Depending on how you use LUCA, we may collect user identifiers or preferences.

LUCA does not require you to provide special category or sensitive personal data.

How We Use Your Data

Personal data is used to Deliver and personalise the LUCA experience.

Data is not used for advertising, marketing, or commercial profiling.

Use of Artificial Intelligence

LUCA uses AI technologies to support learning and recommendation.

Key safeguards include:

  • AI outputs are advisory and exploratory, not authoritative
  • AI does not make decisions about individuals
  • Personal data is not used to train external AI models
  • AI services operate in no-training and no-retention modes where applicable
  • Outputs are subject to monitoring and review

Data Sharing and Third Parties

Personal data from LUCA is not sold or shared for commercial purposes.

Access may be provided to authorised University staff for:

  • Service operation and support
  • Moderation and governance
  • Evaluation of the Proof of Value

Where third-party services are used to enable AI functionality, they are configured in line with University data protection and security standards.

Data Retention

Personal data is retained only for as long as necessary to:

  • Provide the LUCA service
  • Evaluate the Proof of Value
  • Meet legal, audit, and governance requirements

Session-based AI interaction data is retained for a limited period and automatically removed in line with institutional standards.

Your Data Protection Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion where appropriate
  • Object to or restrict certain processing

Requests can be made through Lancaster University’s data protection processes.

Raising Concerns

If you have concerns about how your data is used within LUCA, you can:

  • Use feedback options within iLancaster
  • Contact the Innovation Team via ISS
  • Raise a concern through the University’s data protection channels

Changes to This Privacy Notice

This Privacy Notice may be updated as LUCA evolves.

Significant changes will be communicated through iLancaster or the LUCA website.