INQULOAsk the minds behind the ideas

Privacy and data protection

Privacy statement

This statement explains what personal data INQULO processes, why it is needed, who controls it, how long it is retained and how you can exercise your rights.

Effective: 3 October 2026 · Controller contact: info@inqulo.com

1. Who is responsible

eVäst AB, organisation number 556627-3719, Lingäll 230, 451 97 Uddevalla, Sweden, is the data controller for INQULO account administration, direct subscriptions, website operation, support, security and service improvement. INQULO is part of Praestegaard Group AB and is organised and maintained by eVäst AB.

2. Institutional workspaces

When a school, university, teacher or other customer decides why and how personal data is used inside its private courses or workspaces, that organisation is normally the controller and eVäst acts as processor under its documented instructions and a data-processing agreement. The institution should provide its own notice for that processing. eVäst remains controller for its independent security, billing, legal-compliance and account-management purposes.

3. Data we process

  • Account and profile: name, email, password hash, roles, institution, department, professional role, subject areas, verification and account status.
  • Learning and workspace: course membership, groups, assignments, uploaded files and metadata, extracted text, notes, annotations, bookmarks, discussions, conversations, citations, review decisions and approved researcher profiles.
  • Usage and operations: session identifiers, request IDs, timestamps, IP-derived security events where recorded, browser/request information, feature usage, queue status and audit records.
  • Commercial: selected plan, trial and entitlement status, Stripe customer/subscription references, invoice/payment status and tax configuration. Full payment-card data is handled by the payment provider rather than stored by INQULO.
  • Communications: contact enquiries, support correspondence and delivery status for service email.

4. Purposes and lawful bases

PurposeTypical lawful basis
Create accounts, provide plans, courses and requested functionsPerformance of a contract or steps requested before a contract
Operate institutional workspaces under customer directionProcessor instructions; the institution determines its own basis
Billing, bookkeeping, tax and legally required recordsContract and legal obligation
Secure the service, prevent abuse, maintain audit trails and diagnose faultsLegitimate interests in a safe, reliable service and, where applicable, legal obligation
Respond to support, privacy and contact requestsContract, legitimate interests or legal obligation according to the request
Optional functionality that legally requires permissionConsent, which may be withdrawn prospectively

5. AI and automated processing

Uploaded material and prompts are processed by private INQULO application services and locally hosted models to extract, retrieve and generate requested learning content. They are not used to train public or third-party models. Generated suggestions remain subject to teacher or user judgment. INQULO does not make solely automated decisions that produce legal or similarly significant effects, and teacher analytics report factual activity rather than inferred ability.

6. Recipients and service providers

Data is available only to authorised users according to course and account permissions, authorised eVäst personnel who need it for operation or support, and contracted providers where necessary. Provider categories may include hosting/network infrastructure, payment processing (Stripe), transactional email, backup and professional advisers. Public authorities receive data only where lawfully required. We do not sell personal data or disclose it for behavioural advertising.

7. International transfers

Core application data and local AI processing are hosted on infrastructure controlled by eVäst. A provider such as payment or email delivery may process limited data outside Sweden or the EEA. Where GDPR transfer rules apply, eVäst uses an adequacy decision, approved contractual safeguards or another lawful mechanism and assesses supplementary protection where required. You may request information about applicable safeguards.

8. Retention

Data is retained only for the purpose and period needed. Current operational defaults include a 30-day recovery period for deleted uploads, a 30-day account-deletion grace period, 90 days for email-delivery records and 730 days for audit records; administrators may set documented retention values. Active course and account content remains while needed to provide the service. Billing and accounting records may be retained for the period required by Swedish law. Backups expire on a controlled rotation and deleted data may remain inaccessible in backups until that rotation completes.

9. Security

Measures include encrypted HTTPS transport, private application networks, password hashing, secure HTTP-only session cookies, role and course permissions, audit logging, rate limits, restricted administrative access, bounded file processing, backups and service monitoring. No system can guarantee absolute security. Please report suspected compromise promptly to info@inqulo.com.

10. Your rights

Depending on the circumstances, you may request information and access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Rights can be limited where another person's rights, legal duties, public-interest archiving, legal claims or other GDPR exceptions apply. We may verify identity before acting.

11. Exercising rights and deletion

Authenticated users can export data and submit an account-deletion request in the workspace. You may also contact info@inqulo.com. We normally respond within one month; GDPR permits an extension for complex or numerous requests, with notice. If an institution controls the relevant course data, we may direct the request to that institution or assist it as processor.

12. Complaints

Please contact us first so we can investigate. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with the supervisory authority where you live or work.

13. Required and optional data

Account credentials and the information needed for the selected role are contractual requirements; without them we cannot provide authenticated functions. Optional profile fields and optional features are identified in context. Blocking the essential session cookie prevents sign-in. See Cookie information.

14. Children and student accounts

INQULO is intended for higher education and institution-governed learning. A person who cannot independently enter the agreement should use the service only through an authorised institution or with appropriate guardian involvement. Institutions are responsible for establishing a lawful basis and age-appropriate information where they invite younger learners.

15. Changes and contact

We update this statement when processing or legal requirements materially change and will provide appropriate notice. Previous rights are not removed retroactively. Privacy questions and requests should be sent to info@inqulo.com or by post to eVäst AB at the address above.