Last updated 9 July 2026

Privacy Policy

Who we are

Academqo provides education institution management software. This Privacy Policy explains how Academqo, with registered office at de Winterstraat 30, 5703XW in Helmond, the Netherlands. Registered under KvK: 98051997, VAT: NL005306680B37 ("Academqo", "we", "us", or "our"), processes personal data when you use our website and platform.

For privacy enquiries contact privacy@academqo.com.

Roles under GDPR

Depending on the processing activity:

  • Academqo acts as controller for website, account, billing, and platform administration data relating to institution administrators and our direct relationship with subscribing institutions.
  • Academqo acts as processor for personal data that institutions upload or generate about students, teachers, and other end users in the course of delivering educational services. In those cases, the institution is the controller and our Data Processing Agreement applies.

Data we collect

We may process the following categories of personal data:

  • Account data: name, email address, authentication credentials, role assignments, and institution membership
  • Institution data: institution name, subdomain, branding, programs, classes, schedules, enrollments, assignments, and related operational records
  • User-generated content: messages, submissions, files, and other content uploaded through the Service
  • Usage and technical data: actions within the platform, logs, device and browser information, IP address, and security events required to operate and protect the Service
  • Billing data: subscription status, Stripe customer identifiers, and billing metadata. Payment card details are processed directly by Stripe and are not stored by Academqo

We process personal data for the following purposes:

  • To provide, operate, and support the Service (performance of a contract)
  • To manage subscriptions, billing, and account administration (performance of a contract and legitimate interests)
  • To secure the platform, prevent abuse, and maintain tenant isolation (legitimate interests and legal obligations)
  • To comply with legal, tax, and regulatory obligations (legal obligation)
  • To improve reliability and functionality of the Service (legitimate interests, where permitted)

Where we rely on legitimate interests, we balance those interests against your rights and expectations.

Student and minor data

Institutions are responsible for determining the lawful basis and notices required for processing student data, including data relating to minors where applicable. Academqo processes such data only on the institution's documented instructions through the Service.

Retention

We retain personal data for as long as necessary to provide the Service and fulfil the purposes described in this policy.

  • While a subscription is active, institution and user data is retained to operate the Service.
  • After cancellation, termination, or a verified deletion request, relevant data is soft-deleted and then purged or anonymised within 90 days.
  • Limited data may be retained longer where required by law, for accounting and billing records, fraud prevention, dispute resolution, or security logging.
  • Backup copies may persist for a limited period before being overwritten in the ordinary course of operations.

Processors and sub-processors

We use trusted service providers to deliver the Service. Current sub-processors include:

  • Supabase (EU region) — database, authentication, storage, and related infrastructure
  • Stripe — subscription billing and payment processing
  • Cloudflare — media storage, content delivery, and related infrastructure services
  • Resend — transactional email delivery

We require processors to process personal data only on our instructions and subject to appropriate contractual safeguards.

International transfers

Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or other mechanisms permitted under applicable data protection law.

Security

We implement appropriate technical and organisational measures designed to protect personal data, including access controls, tenant isolation, encryption in transit, and operational monitoring. No method of transmission or storage is completely secure.

Your rights

Under the GDPR, where Academqo acts as controller, you may have the right to request access, rectification, erasure, restriction, portability, and to object to certain processing. You may also withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.

You may lodge a complaint with your local supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.

To exercise your rights, contact privacy@academqo.com. We may need to verify your identity before responding. Where Academqo processes data on behalf of an institution, we may direct you to the institution as controller.

Cookies

Our use of cookies is described in our Cookie Notice.

Changes

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by other appropriate means.

Contact

Privacy enquiries: privacy@academqo.com

Support enquiries: support@academqo.com