1. Introduction
This Privacy Policy explains how Fjordbyte AS (org. nr. 933 773 477) ("Fjordbyte", "we", "us") processes personal data when you or your institution use the Lectora platform — an AI-assisted grading and feedback tool for higher education that integrates with the Canvas learning management system (LMS).
We have written this policy to comply with the EU General Data Protection Regulation (GDPR), the Norwegian Personal Data Act (Personopplysningsloven), and the guidance issued by the Norwegian Data Protection Authority (Datatilsynet) for the education sector.
This policy describes:
- What personal data we collect, and from whom
- Why we process it and on what legal basis
- Who we share it with, and where it is processed geographically
- How long we keep it
- The rights you have, and how to exercise them
- How to contact us, our privacy contact, and the supervisory authority
If anything in this policy is unclear, write to lectora@fjordbyte.no.
2. Who is the data controller?
Lectora is used in three distinct ways. The controller and processor roles differ in each. Find the scenario that matches you:
2.1 You are an individual educator using Lectora with a personal Canvas access token
You signed up for Lectora yourself, generated a Personal Access Token in your Canvas account, and pasted it into Lectora. Your institution has not signed a Master Service Agreement with us.
- For your own personal data (your name, email, login activity): Fjordbyte AS is the controller.
- For the student work you upload, the rubrics, the grades you generate: you, as the educator, are operating as the data controller (or as a representative of your institution's controllership, depending on your institution's policies). Fjordbyte is the processor, processing this data on your instructions.
You confirm in our Terms of Service that you have authority from your institution to use Lectora to process student work. If you are uncertain whether you have this authority, do not upload student work and contact your institution's data protection officer first.
2.2 Your institution has signed a Master Service Agreement with Fjordbyte
Your institution installed Lectora as an LTI 1.3 application in Canvas. You access it through institutional single sign-on.
- For all student and educator data flowing through Lectora: your institution is the data controller. Fjordbyte is the processor, governed by the Data Processing Agreement (DPA) signed between Fjordbyte and your institution.
- For data Fjordbyte collects independently to operate the service (account metadata, billing contacts, security logs): Fjordbyte AS is the controller.
2.3 You started in scenario 2.1, and your institution later signed a Master Service Agreement
This is a controller transition. See Section 11.
3. What personal data we collect
The categories of data we collect depend on which mode you use.
3.1 Account & authentication data
| Data | Purpose | Source |
|---|---|---|
| Name | Identification, addressing in emails | You at signup, or your institution via LTI/SSO |
| Email address | Authentication, notifications | You at signup, or via SSO |
| Profile image (optional) | UI personalisation | Canvas (if available) |
| Password hash (PAT mode only) | Authentication | You at signup, hashed before storage |
| Canvas user ID | Linking your Lectora account to your Canvas identity | Canvas |
| Canvas access token (PAT or OAuth) | Authorised API access to Canvas on your behalf | You (PAT) or Canvas OAuth flow (LTI) |
Canvas access tokens are encrypted at rest using AES-256-GCM with key rotation support.
3.2 Course and assignment data
| Data | Purpose | Source |
|---|---|---|
| Course title, code, semester | Organising work within Lectora | Canvas |
| Assignment text, rubric, point values | Grading context for the AI | Canvas |
| Solution manuals, reference files (uploaded by you) | Grading context for the AI | You |
3.3 Student submission data
| Data | Purpose | Source |
|---|---|---|
Submission text (body), URLs, attachments | Grading and feedback generation | Canvas |
| Extracted text from PDF/DOCX submissions | AI processing | Lectora extracts on your behalf |
| Submission metadata (attempt number, timestamps, file types) | Audit and grading workflow | Canvas |
| Student name and email | Linking grades back to Canvas users | Canvas |
Important: In the grading flow, Lectora replaces direct student identifiers — name, email address and student ID — with internal identifiers before content is sent to an AI provider. AI outputs are linked back to students within Lectora's own systems. An institution may instruct us otherwise in writing; absent such an instruction, direct identifiers are not sent.
Course material that an educator or institution uploads to a knowledge base may itself contain personal data. Such material is processed by our OCR and knowledge-base providers as listed in Section 5.
3.4 Grading and feedback data
| Data | Purpose | Source |
|---|---|---|
| AI-drafted scores | Educator review and approval | Lectora generates |
| AI-drafted written feedback (strengths, suggestions, corrections) | Educator review and approval | Lectora generates |
| Educator edits, approvals, and publication actions | Workflow state | You |
| Reviewer identity, review timestamps | Audit trail | Lectora records on each review/publish action |
3.5 Chat and assistant data
| Data | Purpose | Source |
|---|---|---|
| Your messages to the Lectora teacher assistant (retained while your account is active; deleted or irreversibly anonymised within 30 days of account closure, and automatically once a session has been inactive for 12 months) | AI response generation, conversation history | You |
| Per-student daily feedback-chat usage counters | Rate limiting (deleted after 30 days) | Lectora records |
3.6 Technical and operational data
| Data | Purpose | Source |
|---|---|---|
| IP address | Security, rate limiting, abuse prevention | Network |
| Browser type / user-agent | Compatibility, debugging | Network |
| Session cookies, authentication tokens | Keeping you signed in | Lectora |
| Application logs, error reports | Diagnosing and fixing issues | Lectora |
| Anonymised usage events (feature interactions) | Product improvement (aggregate only) | Lectora |
3.7 Billing data (institutions only)
| Data | Purpose | Source |
|---|---|---|
| Institution name, billing contact | Invoicing | Your institution |
| Subscription details, invoice history | Account management | Lectora and Stripe |
Lectora does not store payment card data. Card details are processed exclusively by Stripe (PCI DSS Level 1 certified).
3.8 Prospect data (sales outreach)
This category applies if you are receiving outreach emails from Lectora before you have signed up — typically because you are a course leader, department head, or member of academic staff at a higher-education institution we believe Lectora is relevant to.
| Data | Purpose | Source |
|---|---|---|
| Name and work email | Initial professional contact | Publicly available professional listings (university web pages, LinkedIn, conference programmes) |
| Job title, institution, department | Targeting relevance | Same as above |
| Engagement metadata (email opens, link clicks, replies) | Adjusting outreach cadence; suppressing further contact when there is no interest | Lectora's outreach tooling (HubSpot Sales Hub) |
We do not buy, scrape at scale, or build behavioural profiles of prospects. The data is collected in the public professional context, processed under legitimate interest (see Section 4), and you can opt out at any time using the unsubscribe link in any email we send you or by writing to lectora@fjordbyte.no. On opt-out we suppress further contact and delete the prospect record within 30 days unless we have another lawful basis to retain it (e.g. an active sales conversation you initiated).
3.9 Marketing-website enquiry data
This category applies if you asked us for something through a form on our marketing website lectora.io — for example the validation study — rather than signing up for Lectora itself.
| Data | Purpose | Source |
|---|---|---|
| Work email address | Sending you the document you asked for, and material corrections to it | You, in the form on lectora.io |
| Preferred language | Sending the document in the language you were reading | Derived from the page you submitted from |
| Engagement metadata (whether that email was opened, whether its links were clicked) | Understanding whether the document is actually read. Collected only if you separately tick the box for it — it is not required to receive the document, and is never pre-ticked | Our email tooling (HubSpot) |
This is a distinct subscription from the newsletter in Section 3.8 and from Pipeline A: it carries the one document you asked for and material corrections to it, nothing else. You can unsubscribe from any email we send you, or by writing to lectora@fjordbyte.no.
Note that this measurement happens in your email client rather than on lectora.io, so it is not covered by the website's cookie banner — which is why it is disclosed here and consented to at the point of submission.
4. Legal bases for processing
Under GDPR Art. 6, each processing activity has a legal basis:
| Activity | Legal basis |
|---|---|
| Operating your Lectora account | Contract performance (Art. 6(1)(b)) — our agreement with you or your institution |
| Processing student work for grading | In institutional mode: our Data Processing Agreement on behalf of the institution. In PAT mode: your instructions as the operating controller, with your warranty of authority |
| Security monitoring, fraud prevention, abuse detection | Legitimate interest (Art. 6(1)(f)) — operating a secure service |
| Transactional emails (account, security, billing) | Contract performance (Art. 6(1)(b)) |
| Aggregated, anonymised product analytics | Legitimate interest (Art. 6(1)(f)) — improving the service |
| Retaining irreversibly anonymised data — after customer content is returned, or when the retention periods in Section 7 expire — to improve Lectora | Outside the scope of the GDPR — anonymised data is not personal data (Art. 4(1), Recital 26). For institutional customers this is additionally agreed in the DPA and the institutional agreement. Customer content is never used to train or fine-tune AI models |
| Marketing emails to opted-in subscribers (Pipeline A — newsletter, product updates, case studies) | Consent (Art. 6(1)(a)) + Markedsføringsloven §15 |
| Sending a document a visitor asked for on lectora.io (Pipeline C — e.g. the validation study), and keeping them informed of material corrections to that one document | Consent (Art. 6(1)(a)) + Markedsføringsloven §15. A separate, narrowly scoped subscription — not the newsletter. Every send carries an unsubscribe link |
| Measuring whether such a requested document email is opened, or its links clicked | Consent (Art. 6(1)(a)), asked for separately from the send itself. This measurement is not necessary to deliver the document, so making delivery conditional on it would undermine the consent (Art. 7(4)). Declining it does not withhold the document, and it is never pre-ticked |
| Sales outreach to prospects in their professional capacity (Pipeline B — 1:1 emails from a Lectora team member to a professionally-relevant contact) | Legitimate interest (Art. 6(1)(f)) — balanced against the prospect's professional context. A written Legitimate Interest Assessment (LIA) is kept on file. Every outreach email contains a one-click unsubscribe link and a link to this policy. |
| Compliance with legal obligations (e.g. accounting records) | Legal obligation (Art. 6(1)(c)) |
Student submission text may incidentally contain special-category personal data (GDPR Art. 9) — for example a health-related case study, or content revealing a student's beliefs. Lectora processes such content only as an incidental consequence of the educational task and never deliberately solicits it. The legal basis is Art. 9(2)(j) (archiving for scientific or educational purposes) combined with the safeguards in Section 8 of this policy.
5. Who we share your data with (subprocessors)
We use the third-party providers listed below to operate Lectora. Each is bound by a written Data Processing Agreement and contractual data-protection safeguards. The full operational details and contact information for each provider are in our DPA's Bilag B (annex of subprocessors); a public-facing summary lives at /subprocessors.
| Provider | Role | Data processed | Region |
|---|---|---|---|
| Vercel Inc. | Application hosting (Next.js, serverless compute, edge), Vercel Analytics, Speed Insights and firewall | All application traffic in transit | EU (Frankfurt, fra1) — access from the USA for operations and support, under EU SCCs |
| Vercel AI Gateway (operated by Vercel Inc.) | Routing layer for part of the AI functionality | Prompt, context and model response; usage metadata | EU/USA under EU SCCs — forwards to the model provider's region listed below |
| Supabase Pte. Ltd. / Supabase, Inc. | PostgreSQL database and object storage | All application data, course files, submissions, knowledge-base material, accounts and sessions | EU (Frankfurt, AWS eu-central-1) — support access from the USA and Singapore, under EU SCCs |
| OpenAI Ireland Ltd. | AI inference (grading, feedback, assistant) | Pseudonymised text, submission content (no direct student identifiers). Files uploaded for grading and question extraction are transient and deleted after processing; knowledge-base search runs on Fjordbyte's own vector index in Supabase (EU), not at OpenAI | EU (Europe region) — no training on customer data. Global endpoint under EU SCCs for development and for features not yet in the EU region |
| Google Cloud EMEA Ltd. (Gemini) | AI inference (alternate models, via Vercel AI Gateway) | Pseudonymised text (no direct student identifiers) | EU/EEA — no training on customer data |
| Anthropic Ireland, Ltd. (Claude) | AI inference — approved and planned; not enabled in production | Pseudonymised text (no direct student identifiers) | EU/EEA — no training on customer data; API inputs and outputs deleted within 30 days |
| Mistral AI SAS | OCR and image understanding for knowledge-base documents | Uploaded course material, which may contain personal data if the institution includes it | EU (France) — no third-country transfer; zero data retention on the production account |
| Inngest, Inc. | Background job orchestration | Internal job identifiers and job metadata only — never submissions or grading material | USA — see the transfer note in Section 6 |
| Plus Five Five, Inc. (Resend) | Transactional email delivery | Recipient address, message metadata | USA — covered by SCCs |
| Functional Software, Inc. (Sentry) | Error monitoring and performance tracing | Error messages, stack traces, URLs, browser and device data, pseudonymous user ID | EU (Frankfurt, Germany) — region locked in code |
| PostHog, Inc. / PostHog GmbH | Product analytics, feature flags, experimentation, session replay and error tracking | Event data, page views, pseudonymous user ID | EU (Germany, AWS) — region locked in code |
| Stripe Payments Europe Ltd. | Billing (institutions only) | Billing contacts, invoice data | EU/global — covered by Stripe DPA + SCCs |
The detailed Subprocessors page contains DPA links, sub-processor lists for each provider, and update notifications.
This list reflects DPA Bilag B as of 24 August 2026. If the subprocessor roster changes, both the DPA and this policy are updated, and institutions are notified per the DPA's notification clause (Bilag B punkt B.1).
6. International data transfers
Customer content — submissions, grades, feedback, chat and knowledge-base material — is processed within the EU/EEA:
- Application hosting: EU (Frankfurt)
- Database: EU (Frankfurt)
- File storage: EU (Frankfurt)
- AI inference: EU (Europe region for OpenAI; EU/EEA for Google, Anthropic and Mistral)
- Error monitoring and product analytics: EU (Frankfurt for Sentry; Germany for PostHog) — region-locked in code
A small number of operational services are hosted outside the EEA:
- Email (Resend): USA, under EU SCCs
- Background-job orchestration (Inngest): USA — receives only internal identifiers and job metadata, never submissions or grading material
Where a transfer outside the EU/EEA occurs, it is governed by the EU Commission's Standard Contractual Clauses (Decision 2021/914) and, where the provider is certified, the EU–US Data Privacy Framework. Supplementary measures are in place: encryption in transit (TLS 1.2+), encryption at rest (AES-256), and contractual data-use restrictions.
For Inngest specifically, our current basis is Inngest's standard data-processing terms combined with strict data minimisation — Inngest receives internal identifiers and job metadata only, never personal data or content — and end-to-end encryption of event payloads. A signed DPA incorporating the EU Standard Contractual Clauses will be put in place, and this section will be updated when it is.
7. How long we keep your data
| Data category | Retention |
|---|---|
| Account data (name, email, profile) | While your account is active; deleted within 30 days of account closure |
| Canvas OAuth tokens | Refreshed proactively before expiry; revoked + purged 7 days after they go stale (institutional mode) |
| Canvas Personal Access Tokens | Until you replace or delete the token, or close your account |
| Course and assignment data | While the course exists in Lectora; deletable on request |
| Student submissions, AI-generated grades and feedback — institutional customers | Institutional customers: retained for the term of the agreement. On termination all personal data is returned in a structured, machine-readable format, and then deleted within 30 calendar days — including at subprocessors. This mirrors Annex C, section C.6 of the DPA. |
| Student submissions, AI-generated grades and feedback — individual (PAT) users | Retained while the course exists in Lectora. 90 days after you delete or archive the course — and in any event within 30 days of account closure — submissions, grades and feedback are irreversibly anonymised: every identifier linking the data to a person is removed, and content that cannot be reliably de-identified is deleted. The anonymised remainder is retained in aggregate form to improve Lectora (Section 4). You can request full deletion instead at any time (Section 9). |
| Per-student feedback-chat usage counters | 30 days (automatic deletion) |
| Application logs and security telemetry | Up to 90 days: platform runtime logs at Vercel are short-lived (plan-dependent, days up to 30); errors and traces at Sentry EU are retained 90 days; session recordings, where enabled, 30–90 days at PostHog EU per plan |
| Billing records | As required by Norwegian accounting law (5 years) |
| Audit-trail records (security events, governance transitions) | 5 years (aligned with the Norwegian Bookkeeping Act) |
You can request deletion of data Fjordbyte holds about you at any time (Section 9). Where Fjordbyte is processor and the institution is controller, deletion requests should be addressed to your institution first; Fjordbyte will act on the institution's instructions per the DPA.
8. Security
We protect your data with industry-standard technical and organisational measures, including:
- Encryption in transit: TLS 1.2+ for all connections to Lectora and to upstream providers
- Encryption at rest: AES-256 for database storage; AES-256-GCM with key rotation for stored Canvas tokens
- Access control: role-based access within Lectora; principle of least privilege for engineering access; multi-factor authentication required for administrative accounts
- Network security: Vercel Firewall (WAF) and rate limiting protect against abuse
- Subprocessor controls: every subprocessor is reviewed for security posture; SOC 2 / ISO 27001 certifications preferred
- Audit logging: security-relevant actions are logged with timestamps and actor identity
- AI provider isolation: customer content sent to AI providers contains no direct personal identifiers; outputs are linked back internally
- Backups: automated daily database backups at Supabase, retained for 7 days, with access control. Note that database backups do not include files in object storage; a separate protection measure for stored files is tracked in the engineering backlog
Full technical and organisational measures (TOMs) are documented in the DPA's security annex for institutional customers.
9. Your rights
Under GDPR Art. 13–22, you have the following rights:
- Right of access (Art. 15) — get a copy of the personal data we hold about you
- Right to rectification (Art. 16) — correct inaccurate data
- Right to erasure (Art. 17) — request deletion ("right to be forgotten")
- Right to restriction (Art. 18) — limit how we process your data
- Right to data portability (Art. 20) — receive your data in a machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interest
- Right to withdraw consent (Art. 7(3)) — for any processing based on consent
- Right to lodge a complaint with the supervisory authority (Section 14)
If your institution is the data controller (LTI mode), you should direct rights requests to your institution first. Fjordbyte will support the institution in fulfilling such requests per the DPA.
To exercise these rights with Fjordbyte, write to lectora@fjordbyte.no. We respond within 30 days (extendable by 60 days for complex requests, with notice).
10. Cookies and tracking
Lectora uses the minimum cookies necessary to operate the service:
- Strictly necessary cookies: authentication, session management, security
- Functional cookies: remembering your preferences (e.g. language)
- Analytics cookies and storage (PostHog): PostHog collects pseudonymous usage analytics, evaluates feature flags, records session replay, and receives error events alongside Sentry. These are not strictly necessary. This policy describes them, and your consent is collected through the legal-documents acceptance screen presented when you create an account, and again whenever these documents are materially updated. You can withdraw consent at any time by writing to lectora@fjordbyte.no (Section 9).
- Error monitoring (Sentry): crash and error reports needed to keep the service secure and working. We treat this as strictly necessary for service operation; no advertising or cross-site tracking is involved.
Session replay runs only on sign-in and public pages, with all text and input fields masked, and never on grading or student-content pages.
We do not use advertising cookies. We do not allow third-party tracking for marketing purposes.
11. Transitioning from individual to institutional use
If you signed up for Lectora individually with a Personal Access Token and your institution later signs a Master Service Agreement, the following applies:
- We notify you in-app and by email that your institution has signed a Data Processing Agreement with Fjordbyte.
- From that point onward, your use of Lectora is governed by your institution's contract and DPA, not by your individual ToS. Your account is migrated under institutional governance.
- Any data you had processed under your individual usage continues to be held by Fjordbyte and is carried forward under the institution's DPA. We notify the institution of the transition and of the data that is now governed by its agreement.
- You are encouraged to re-authenticate via institutional SSO. Your Personal Access Token can be revoked and removed from Lectora at your request.
- We log the transition as an auditable event.
If you object to your data being placed under your institution's control after such a transition, you may request deletion of your account and data (Section 9).
12. Children
Lectora is designed for higher-education students and educators. We do not knowingly process personal data of children under 16. If you believe a child's data has been processed, contact us at lectora@fjordbyte.no and we will delete it.
13. Changes to this policy
We may update this policy from time to time. Material changes are notified to:
- Active institutional customers by direct email to the contact on file (GDPR Art. 13(2)(a) requirement for changes affecting processing)
- Individual users by in-app notification on next sign-in
Non-material changes (typos, formatting) may be made without notice. The "Last updated" date at the top of this policy always reflects the latest revision.
14. Contact
Data controller (for data we control): Fjordbyte AS Org. nr. 933 773 477 Address: Solheimsgaten 7 C, 5058 Bergen, Norway Email: lectora@fjordbyte.no
Privacy contact: Christian B. (cb@lectora.io). We have not formally appointed a Data Protection Officer; appointment is not required for Fjordbyte under GDPR Art. 37 at our current scale, and we will revisit this as the service grows.
EU representative: Not required — Fjordbyte AS is established in Norway, within the EEA (GDPR Art. 27 applies only to controllers and processors not established in the Union/EEA).
Supervisory authority: Datatilsynet (the Norwegian Data Protection Authority) Postboks 458 Sentrum, 0105 Oslo Phone: +47 22 39 69 00 Web: https://www.datatilsynet.no
You have the right to lodge a complaint with Datatilsynet, or with the supervisory authority in your country of residence, if you believe our processing of your personal data violates the GDPR.