Privacy and data protection
Privacy statement
This statement explains what personal data INQULO processes, why it is needed, who controls it, how long it is retained and how you can exercise your rights.
1. Who is responsible
eVäst AB, organisation number 556627-3719, Lingäll 230, 451 97 Uddevalla, Sweden, is the data controller for INQULO account administration, direct subscriptions, website operation, support, security and service improvement. INQULO is part of Praestegaard Group AB and is organised and maintained by eVäst AB.
2. Institutional workspaces
When a school, university, teacher or other customer decides why and how personal data is used inside its private courses or workspaces, that organisation is normally the controller and eVäst acts as processor under its documented instructions and a data-processing agreement. The institution should provide its own notice for that processing. eVäst remains controller for its independent security, billing, legal-compliance and account-management purposes.
3. Data we process
- Account and profile: name, email, password hash, roles, institution, department, professional role, subject areas, verification and account status.
- Learning and workspace: course membership, groups, assignments, uploaded files and metadata, extracted text, notes, annotations, bookmarks, discussions, conversations, citations, review decisions and approved researcher profiles.
- Usage and operations: session identifiers, request IDs, timestamps, IP-derived security events where recorded, browser/request information, feature usage, queue status and audit records.
- Commercial: selected plan, trial and entitlement status, Stripe customer/subscription references, invoice/payment status and tax configuration. Full payment-card data is handled by the payment provider rather than stored by INQULO.
- Communications: contact enquiries, support correspondence and delivery status for service email.
4. Purposes and lawful bases
5. AI and automated processing
Uploaded material and prompts are processed by private INQULO application services and locally hosted models to extract, retrieve and generate requested learning content. They are not used to train public or third-party models. Generated suggestions remain subject to teacher or user judgment. INQULO does not make solely automated decisions that produce legal or similarly significant effects, and teacher analytics report factual activity rather than inferred ability.
6. Recipients and service providers
Data is available only to authorised users according to course and account permissions, authorised eVäst personnel who need it for operation or support, and contracted providers where necessary. Provider categories may include hosting/network infrastructure, payment processing (Stripe), transactional email, backup and professional advisers. Public authorities receive data only where lawfully required. We do not sell personal data or disclose it for behavioural advertising.
7. International transfers
Core application data and local AI processing are hosted on infrastructure controlled by eVäst. A provider such as payment or email delivery may process limited data outside Sweden or the EEA. Where GDPR transfer rules apply, eVäst uses an adequacy decision, approved contractual safeguards or another lawful mechanism and assesses supplementary protection where required. You may request information about applicable safeguards.
8. Retention
Data is retained only for the purpose and period needed. Current operational defaults include a 30-day recovery period for deleted uploads, a 30-day account-deletion grace period, 90 days for email-delivery records and 730 days for audit records; administrators may set documented retention values. Active course and account content remains while needed to provide the service. Billing and accounting records may be retained for the period required by Swedish law. Backups expire on a controlled rotation and deleted data may remain inaccessible in backups until that rotation completes.
9. Security
Measures include encrypted HTTPS transport, private application networks, password hashing, secure HTTP-only session cookies, role and course permissions, audit logging, rate limits, restricted administrative access, bounded file processing, backups and service monitoring. No system can guarantee absolute security. Please report suspected compromise promptly to info@inqulo.com.
10. Your rights
Depending on the circumstances, you may request information and access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Rights can be limited where another person's rights, legal duties, public-interest archiving, legal claims or other GDPR exceptions apply. We may verify identity before acting.
11. Exercising rights and deletion
Authenticated users can export data and submit an account-deletion request in the workspace. You may also contact info@inqulo.com. We normally respond within one month; GDPR permits an extension for complex or numerous requests, with notice. If an institution controls the relevant course data, we may direct the request to that institution or assist it as processor.
12. Complaints
Please contact us first so we can investigate. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with the supervisory authority where you live or work.
13. Required and optional data
Account credentials and the information needed for the selected role are contractual requirements; without them we cannot provide authenticated functions. Optional profile fields and optional features are identified in context. Blocking the essential session cookie prevents sign-in. See Cookie information.
14. Children and student accounts
INQULO is intended for higher education and institution-governed learning. A person who cannot independently enter the agreement should use the service only through an authorised institution or with appropriate guardian involvement. Institutions are responsible for establishing a lawful basis and age-appropriate information where they invite younger learners.
15. Changes and contact
We update this statement when processing or legal requirements materially change and will provide appropriate notice. Previous rights are not removed retroactively. Privacy questions and requests should be sent to info@inqulo.com or by post to eVäst AB at the address above.