Who we are
Academqo provides education institution management software. This Privacy Policy explains how Academqo, with registered office at de Winterstraat 30, 5703XW in Helmond, the Netherlands. Registered under KvK: 98051997, VAT: NL005306680B37 ("Academqo", "we", "us", or "our"), processes personal data when you use our website and platform.
For privacy enquiries contact privacy@academqo.com.
Roles under GDPR
Depending on the processing activity:
- Academqo acts as controller for website, account, billing, and platform administration data relating to institution administrators and our direct relationship with subscribing institutions.
- Academqo acts as processor for personal data that institutions upload or generate about students, teachers, and other end users in the course of delivering educational services. In those cases, the institution is the controller and our Data Processing Agreement applies.
Data we collect
We may process the following categories of personal data:
- Account data: name, email address, authentication credentials, role assignments, and institution membership
- Institution data: institution name, subdomain, branding, programs, classes, schedules, enrollments, assignments, and related operational records
- User-generated content: messages, submissions, files, and other content uploaded through the Service
- Usage and technical data: actions within the platform, logs, device and browser information, IP address, and security events required to operate and protect the Service
- Billing data: subscription status, Stripe customer identifiers, and billing metadata. Payment card details are processed directly by Stripe and are not stored by Academqo
Purposes and legal basis
We process personal data for the following purposes:
- To provide, operate, and support the Service (performance of a contract)
- To manage subscriptions, billing, and account administration (performance of a contract and legitimate interests)
- To secure the platform, prevent abuse, and maintain tenant isolation (legitimate interests and legal obligations)
- To comply with legal, tax, and regulatory obligations (legal obligation)
- To improve reliability and functionality of the Service (legitimate interests, where permitted)
Where we rely on legitimate interests, we balance those interests against your rights and expectations.
Student and minor data
Institutions are responsible for determining the lawful basis and notices required for processing student data, including data relating to minors where applicable. Academqo processes such data only on the institution's documented instructions through the Service.
Retention
We retain personal data for as long as necessary to provide the Service and fulfil the purposes described in this policy.
- While a subscription is active, institution and user data is retained to operate the Service.
- After cancellation, termination, or a verified deletion request, relevant data is soft-deleted and then purged or anonymised within 90 days.
- Limited data may be retained longer where required by law, for accounting and billing records, fraud prevention, dispute resolution, or security logging.
- Backup copies may persist for a limited period before being overwritten in the ordinary course of operations.
Processors and sub-processors
We use trusted service providers to deliver the Service. Current sub-processors include:
- Supabase (EU region) — database, authentication, storage, and related infrastructure
- Stripe — subscription billing and payment processing
- Cloudflare — media storage, content delivery, and related infrastructure services
- Resend — transactional email delivery
We require processors to process personal data only on our instructions and subject to appropriate contractual safeguards.
International transfers
Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or other mechanisms permitted under applicable data protection law.
Security
We implement appropriate technical and organisational measures designed to protect personal data, including access controls, tenant isolation, encryption in transit, and operational monitoring. No method of transmission or storage is completely secure.
Your rights
Under the GDPR, where Academqo acts as controller, you may have the right to request access, rectification, erasure, restriction, portability, and to object to certain processing. You may also withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.
You may lodge a complaint with your local supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.
To exercise your rights, contact privacy@academqo.com. We may need to verify your identity before responding. Where Academqo processes data on behalf of an institution, we may direct you to the institution as controller.
Cookies
Our use of cookies is described in our Cookie Notice.
Changes
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by other appropriate means.
Contact
Privacy enquiries: privacy@academqo.com
Support enquiries: support@academqo.com