Legal

Privacy Policy

Version 2.3, effective from 1 September 2026

1. Introduction

This Privacy Policy explains how Fjordbyte AS (org. nr. 933 773 477) ("Fjordbyte", "we", "us") processes personal data when you or your institution use the Lectora platform — an AI-assisted grading and feedback tool for higher education that integrates with the Canvas learning management system (LMS).

We have written this policy to comply with the EU General Data Protection Regulation (GDPR), the Norwegian Personal Data Act (Personopplysningsloven), and the guidance issued by the Norwegian Data Protection Authority (Datatilsynet) for the education sector.

This policy describes:

  • What personal data we collect, and from whom
  • Why we process it and on what legal basis
  • Who we share it with, and where it is processed geographically
  • How long we keep it
  • The rights you have, and how to exercise them
  • How to contact us, our privacy contact, and the supervisory authority

If anything in this policy is unclear, write to lectora@fjordbyte.no.

2. Who is the data controller?

Lectora is used in three distinct ways. The controller and processor roles differ in each. Find the scenario that matches you:

2.1 You are an individual educator using Lectora with a personal Canvas access token

You signed up for Lectora yourself, generated a Personal Access Token in your Canvas account, and pasted it into Lectora. Your institution has not signed a Master Service Agreement with us.

  • For your own personal data (your name, email, login activity): Fjordbyte AS is the controller.
  • For the student work you upload, the rubrics, the grades you generate: you, as the educator, are operating as the data controller (or as a representative of your institution's controllership, depending on your institution's policies). Fjordbyte is the processor, processing this data on your instructions.

You confirm in our Terms of Service that you have authority from your institution to use Lectora to process student work. If you are uncertain whether you have this authority, do not upload student work and contact your institution's data protection officer first.

2.2 Your institution has signed a Master Service Agreement with Fjordbyte

Your institution installed Lectora as an LTI 1.3 application in Canvas. You access it through institutional single sign-on.

  • For all student and educator data flowing through Lectora: your institution is the data controller. Fjordbyte is the processor, governed by the Data Processing Agreement (DPA) signed between Fjordbyte and your institution.
  • For data Fjordbyte collects independently to operate the service (account metadata, billing contacts, security logs): Fjordbyte AS is the controller.

2.3 You started in scenario 2.1, and your institution later signed a Master Service Agreement

This is a controller transition. See Section 11.

3. What personal data we collect

The categories of data we collect depend on which mode you use.

3.1 Account & authentication data

DataPurposeSource
NameIdentification, addressing in emailsYou at signup, or your institution via LTI/SSO
Email addressAuthentication, notificationsYou at signup, or via SSO
Profile image (optional)UI personalisationCanvas (if available)
Password hash (PAT mode only)AuthenticationYou at signup, hashed before storage
Canvas user IDLinking your Lectora account to your Canvas identityCanvas
Canvas access token (PAT or OAuth)Authorised API access to Canvas on your behalfYou (PAT) or Canvas OAuth flow (LTI)

Canvas access tokens are encrypted at rest using AES-256-GCM with key rotation support.

3.2 Course and assignment data

DataPurposeSource
Course title, code, semesterOrganising work within LectoraCanvas
Assignment text, rubric, point valuesGrading context for the AICanvas
Solution manuals, reference files (uploaded by you)Grading context for the AIYou

3.3 Student submission data

DataPurposeSource
Submission text (body), URLs, attachmentsGrading and feedback generationCanvas
Extracted text from PDF/DOCX submissionsAI processingLectora extracts on your behalf
Submission metadata (attempt number, timestamps, file types)Audit and grading workflowCanvas
Student name and emailLinking grades back to Canvas usersCanvas

Important: In the grading flow, Lectora replaces direct student identifiers — name, email address and student ID — with internal identifiers before content is sent to an AI provider. AI outputs are linked back to students within Lectora's own systems. An institution may instruct us otherwise in writing; absent such an instruction, direct identifiers are not sent.

Course material that an educator or institution uploads to a knowledge base may itself contain personal data. Such material is processed by our OCR and knowledge-base providers as listed in Section 5.

3.4 Grading and feedback data

DataPurposeSource
AI-drafted scoresEducator review and approvalLectora generates
AI-drafted written feedback (strengths, suggestions, corrections)Educator review and approvalLectora generates
Educator edits, approvals, and publication actionsWorkflow stateYou
Reviewer identity, review timestampsAudit trailLectora records on each review/publish action

3.5 Chat and assistant data

DataPurposeSource
Your messages to the Lectora teacher assistant (retained while your account is active; deleted or irreversibly anonymised within 30 days of account closure, and automatically once a session has been inactive for 12 months)AI response generation, conversation historyYou
Per-student daily feedback-chat usage countersRate limiting (deleted after 30 days)Lectora records

3.6 Technical and operational data

DataPurposeSource
IP addressSecurity, rate limiting, abuse preventionNetwork
Browser type / user-agentCompatibility, debuggingNetwork
Session cookies, authentication tokensKeeping you signed inLectora
Application logs, error reportsDiagnosing and fixing issuesLectora
Anonymised usage events (feature interactions)Product improvement (aggregate only)Lectora

3.7 Billing data (institutions only)

DataPurposeSource
Institution name, billing contactInvoicingYour institution
Subscription details, invoice historyAccount managementLectora and Stripe

Lectora does not store payment card data. Card details are processed exclusively by Stripe (PCI DSS Level 1 certified).

3.8 Prospect data (sales outreach)

This category applies if you are receiving outreach emails from Lectora before you have signed up — typically because you are a course leader, department head, or member of academic staff at a higher-education institution we believe Lectora is relevant to.

DataPurposeSource
Name and work emailInitial professional contactPublicly available professional listings (university web pages, LinkedIn, conference programmes)
Job title, institution, departmentTargeting relevanceSame as above
Engagement metadata (email opens, link clicks, replies)Adjusting outreach cadence; suppressing further contact when there is no interestLectora's outreach tooling (HubSpot Sales Hub)

We do not buy, scrape at scale, or build behavioural profiles of prospects. The data is collected in the public professional context, processed under legitimate interest (see Section 4), and you can opt out at any time using the unsubscribe link in any email we send you or by writing to lectora@fjordbyte.no. On opt-out we suppress further contact and delete the prospect record within 30 days unless we have another lawful basis to retain it (e.g. an active sales conversation you initiated).

3.9 Marketing-website enquiry data

This category applies if you asked us for something through a form on our marketing website lectora.io — for example the validation study — rather than signing up for Lectora itself.

DataPurposeSource
Work email addressSending you the document you asked for, and material corrections to itYou, in the form on lectora.io
Preferred languageSending the document in the language you were readingDerived from the page you submitted from
Engagement metadata (whether that email was opened, whether its links were clicked)Understanding whether the document is actually read. Collected only if you separately tick the box for it — it is not required to receive the document, and is never pre-tickedOur email tooling (HubSpot)

This is a distinct subscription from the newsletter in Section 3.8 and from Pipeline A: it carries the one document you asked for and material corrections to it, nothing else. You can unsubscribe from any email we send you, or by writing to lectora@fjordbyte.no.

Note that this measurement happens in your email client rather than on lectora.io, so it is not covered by the website's cookie banner — which is why it is disclosed here and consented to at the point of submission.

4. Legal bases for processing

Under GDPR Art. 6, each processing activity has a legal basis:

ActivityLegal basis
Operating your Lectora accountContract performance (Art. 6(1)(b)) — our agreement with you or your institution
Processing student work for gradingIn institutional mode: our Data Processing Agreement on behalf of the institution. In PAT mode: your instructions as the operating controller, with your warranty of authority
Security monitoring, fraud prevention, abuse detectionLegitimate interest (Art. 6(1)(f)) — operating a secure service
Transactional emails (account, security, billing)Contract performance (Art. 6(1)(b))
Aggregated, anonymised product analyticsLegitimate interest (Art. 6(1)(f)) — improving the service
Retaining irreversibly anonymised data — after customer content is returned, or when the retention periods in Section 7 expire — to improve LectoraOutside the scope of the GDPR — anonymised data is not personal data (Art. 4(1), Recital 26). For institutional customers this is additionally agreed in the DPA and the institutional agreement. Customer content is never used to train or fine-tune AI models
Marketing emails to opted-in subscribers (Pipeline A — newsletter, product updates, case studies)Consent (Art. 6(1)(a)) + Markedsføringsloven §15
Sending a document a visitor asked for on lectora.io (Pipeline C — e.g. the validation study), and keeping them informed of material corrections to that one documentConsent (Art. 6(1)(a)) + Markedsføringsloven §15. A separate, narrowly scoped subscription — not the newsletter. Every send carries an unsubscribe link
Measuring whether such a requested document email is opened, or its links clickedConsent (Art. 6(1)(a)), asked for separately from the send itself. This measurement is not necessary to deliver the document, so making delivery conditional on it would undermine the consent (Art. 7(4)). Declining it does not withhold the document, and it is never pre-ticked
Sales outreach to prospects in their professional capacity (Pipeline B — 1:1 emails from a Lectora team member to a professionally-relevant contact)Legitimate interest (Art. 6(1)(f)) — balanced against the prospect's professional context. A written Legitimate Interest Assessment (LIA) is kept on file. Every outreach email contains a one-click unsubscribe link and a link to this policy.
Compliance with legal obligations (e.g. accounting records)Legal obligation (Art. 6(1)(c))

Student submission text may incidentally contain special-category personal data (GDPR Art. 9) — for example a health-related case study, or content revealing a student's beliefs. Lectora processes such content only as an incidental consequence of the educational task and never deliberately solicits it. The legal basis is Art. 9(2)(j) (archiving for scientific or educational purposes) combined with the safeguards in Section 8 of this policy.

5. Who we share your data with (subprocessors)

We use the third-party providers listed below to operate Lectora. Each is bound by a written Data Processing Agreement and contractual data-protection safeguards. The full operational details and contact information for each provider are in our DPA's Bilag B (annex of subprocessors); a public-facing summary lives at /subprocessors.

ProviderRoleData processedRegion
Vercel Inc.Application hosting (Next.js, serverless compute, edge), Vercel Analytics, Speed Insights and firewallAll application traffic in transitEU (Frankfurt, fra1) — access from the USA for operations and support, under EU SCCs
Vercel AI Gateway (operated by Vercel Inc.)Routing layer for part of the AI functionalityPrompt, context and model response; usage metadataEU/USA under EU SCCs — forwards to the model provider's region listed below
Supabase Pte. Ltd. / Supabase, Inc.PostgreSQL database and object storageAll application data, course files, submissions, knowledge-base material, accounts and sessionsEU (Frankfurt, AWS eu-central-1) — support access from the USA and Singapore, under EU SCCs
OpenAI Ireland Ltd.AI inference (grading, feedback, assistant)Pseudonymised text, submission content (no direct student identifiers). Files uploaded for grading and question extraction are transient and deleted after processing; knowledge-base search runs on Fjordbyte's own vector index in Supabase (EU), not at OpenAIEU (Europe region) — no training on customer data. Global endpoint under EU SCCs for development and for features not yet in the EU region
Google Cloud EMEA Ltd. (Gemini)AI inference (alternate models, via Vercel AI Gateway)Pseudonymised text (no direct student identifiers)EU/EEA — no training on customer data
Anthropic Ireland, Ltd. (Claude)AI inference — approved and planned; not enabled in productionPseudonymised text (no direct student identifiers)EU/EEA — no training on customer data; API inputs and outputs deleted within 30 days
Mistral AI SASOCR and image understanding for knowledge-base documentsUploaded course material, which may contain personal data if the institution includes itEU (France) — no third-country transfer; zero data retention on the production account
Inngest, Inc.Background job orchestrationInternal job identifiers and job metadata only — never submissions or grading materialUSA — see the transfer note in Section 6
Plus Five Five, Inc. (Resend)Transactional email deliveryRecipient address, message metadataUSA — covered by SCCs
Functional Software, Inc. (Sentry)Error monitoring and performance tracingError messages, stack traces, URLs, browser and device data, pseudonymous user IDEU (Frankfurt, Germany) — region locked in code
PostHog, Inc. / PostHog GmbHProduct analytics, feature flags, experimentation, session replay and error trackingEvent data, page views, pseudonymous user IDEU (Germany, AWS) — region locked in code
Stripe Payments Europe Ltd.Billing (institutions only)Billing contacts, invoice dataEU/global — covered by Stripe DPA + SCCs

The detailed Subprocessors page contains DPA links, sub-processor lists for each provider, and update notifications.

This list reflects DPA Bilag B as of 24 August 2026. If the subprocessor roster changes, both the DPA and this policy are updated, and institutions are notified per the DPA's notification clause (Bilag B punkt B.1).

6. International data transfers

Customer content — submissions, grades, feedback, chat and knowledge-base material — is processed within the EU/EEA:

  • Application hosting: EU (Frankfurt)
  • Database: EU (Frankfurt)
  • File storage: EU (Frankfurt)
  • AI inference: EU (Europe region for OpenAI; EU/EEA for Google, Anthropic and Mistral)
  • Error monitoring and product analytics: EU (Frankfurt for Sentry; Germany for PostHog) — region-locked in code

A small number of operational services are hosted outside the EEA:

  • Email (Resend): USA, under EU SCCs
  • Background-job orchestration (Inngest): USA — receives only internal identifiers and job metadata, never submissions or grading material

Where a transfer outside the EU/EEA occurs, it is governed by the EU Commission's Standard Contractual Clauses (Decision 2021/914) and, where the provider is certified, the EU–US Data Privacy Framework. Supplementary measures are in place: encryption in transit (TLS 1.2+), encryption at rest (AES-256), and contractual data-use restrictions.

For Inngest specifically, our current basis is Inngest's standard data-processing terms combined with strict data minimisation — Inngest receives internal identifiers and job metadata only, never personal data or content — and end-to-end encryption of event payloads. A signed DPA incorporating the EU Standard Contractual Clauses will be put in place, and this section will be updated when it is.

7. How long we keep your data

Data categoryRetention
Account data (name, email, profile)While your account is active; deleted within 30 days of account closure
Canvas OAuth tokensRefreshed proactively before expiry; revoked + purged 7 days after they go stale (institutional mode)
Canvas Personal Access TokensUntil you replace or delete the token, or close your account
Course and assignment dataWhile the course exists in Lectora; deletable on request
Student submissions, AI-generated grades and feedback — institutional customersInstitutional customers: retained for the term of the agreement. On termination all personal data is returned in a structured, machine-readable format, and then deleted within 30 calendar days — including at subprocessors. This mirrors Annex C, section C.6 of the DPA.
Student submissions, AI-generated grades and feedback — individual (PAT) usersRetained while the course exists in Lectora. 90 days after you delete or archive the course — and in any event within 30 days of account closure — submissions, grades and feedback are irreversibly anonymised: every identifier linking the data to a person is removed, and content that cannot be reliably de-identified is deleted. The anonymised remainder is retained in aggregate form to improve Lectora (Section 4). You can request full deletion instead at any time (Section 9).
Per-student feedback-chat usage counters30 days (automatic deletion)
Application logs and security telemetryUp to 90 days: platform runtime logs at Vercel are short-lived (plan-dependent, days up to 30); errors and traces at Sentry EU are retained 90 days; session recordings, where enabled, 30–90 days at PostHog EU per plan
Billing recordsAs required by Norwegian accounting law (5 years)
Audit-trail records (security events, governance transitions)5 years (aligned with the Norwegian Bookkeeping Act)

You can request deletion of data Fjordbyte holds about you at any time (Section 9). Where Fjordbyte is processor and the institution is controller, deletion requests should be addressed to your institution first; Fjordbyte will act on the institution's instructions per the DPA.

8. Security

We protect your data with industry-standard technical and organisational measures, including:

  • Encryption in transit: TLS 1.2+ for all connections to Lectora and to upstream providers
  • Encryption at rest: AES-256 for database storage; AES-256-GCM with key rotation for stored Canvas tokens
  • Access control: role-based access within Lectora; principle of least privilege for engineering access; multi-factor authentication required for administrative accounts
  • Network security: Vercel Firewall (WAF) and rate limiting protect against abuse
  • Subprocessor controls: every subprocessor is reviewed for security posture; SOC 2 / ISO 27001 certifications preferred
  • Audit logging: security-relevant actions are logged with timestamps and actor identity
  • AI provider isolation: customer content sent to AI providers contains no direct personal identifiers; outputs are linked back internally
  • Backups: automated daily database backups at Supabase, retained for 7 days, with access control. Note that database backups do not include files in object storage; a separate protection measure for stored files is tracked in the engineering backlog

Full technical and organisational measures (TOMs) are documented in the DPA's security annex for institutional customers.

9. Your rights

Under GDPR Art. 13–22, you have the following rights:

  • Right of access (Art. 15) — get a copy of the personal data we hold about you
  • Right to rectification (Art. 16) — correct inaccurate data
  • Right to erasure (Art. 17) — request deletion ("right to be forgotten")
  • Right to restriction (Art. 18) — limit how we process your data
  • Right to data portability (Art. 20) — receive your data in a machine-readable format
  • Right to object (Art. 21) — object to processing based on legitimate interest
  • Right to withdraw consent (Art. 7(3)) — for any processing based on consent
  • Right to lodge a complaint with the supervisory authority (Section 14)

If your institution is the data controller (LTI mode), you should direct rights requests to your institution first. Fjordbyte will support the institution in fulfilling such requests per the DPA.

To exercise these rights with Fjordbyte, write to lectora@fjordbyte.no. We respond within 30 days (extendable by 60 days for complex requests, with notice).

10. Cookies and tracking

Lectora uses the minimum cookies necessary to operate the service:

  • Strictly necessary cookies: authentication, session management, security
  • Functional cookies: remembering your preferences (e.g. language)
  • Analytics cookies and storage (PostHog): PostHog collects pseudonymous usage analytics, evaluates feature flags, records session replay, and receives error events alongside Sentry. These are not strictly necessary. This policy describes them, and your consent is collected through the legal-documents acceptance screen presented when you create an account, and again whenever these documents are materially updated. You can withdraw consent at any time by writing to lectora@fjordbyte.no (Section 9).
  • Error monitoring (Sentry): crash and error reports needed to keep the service secure and working. We treat this as strictly necessary for service operation; no advertising or cross-site tracking is involved.

Session replay runs only on sign-in and public pages, with all text and input fields masked, and never on grading or student-content pages.

We do not use advertising cookies. We do not allow third-party tracking for marketing purposes.

11. Transitioning from individual to institutional use

If you signed up for Lectora individually with a Personal Access Token and your institution later signs a Master Service Agreement, the following applies:

  1. We notify you in-app and by email that your institution has signed a Data Processing Agreement with Fjordbyte.
  2. From that point onward, your use of Lectora is governed by your institution's contract and DPA, not by your individual ToS. Your account is migrated under institutional governance.
  3. Any data you had processed under your individual usage continues to be held by Fjordbyte and is carried forward under the institution's DPA. We notify the institution of the transition and of the data that is now governed by its agreement.
  4. You are encouraged to re-authenticate via institutional SSO. Your Personal Access Token can be revoked and removed from Lectora at your request.
  5. We log the transition as an auditable event.

If you object to your data being placed under your institution's control after such a transition, you may request deletion of your account and data (Section 9).

12. Children

Lectora is designed for higher-education students and educators. We do not knowingly process personal data of children under 16. If you believe a child's data has been processed, contact us at lectora@fjordbyte.no and we will delete it.

13. Changes to this policy

We may update this policy from time to time. Material changes are notified to:

  • Active institutional customers by direct email to the contact on file (GDPR Art. 13(2)(a) requirement for changes affecting processing)
  • Individual users by in-app notification on next sign-in

Non-material changes (typos, formatting) may be made without notice. The "Last updated" date at the top of this policy always reflects the latest revision.

14. Contact

Data controller (for data we control): Fjordbyte AS Org. nr. 933 773 477 Address: Solheimsgaten 7 C, 5058 Bergen, Norway Email: lectora@fjordbyte.no

Privacy contact: Christian B. (cb@lectora.io). We have not formally appointed a Data Protection Officer; appointment is not required for Fjordbyte under GDPR Art. 37 at our current scale, and we will revisit this as the service grows.

EU representative: Not required — Fjordbyte AS is established in Norway, within the EEA (GDPR Art. 27 applies only to controllers and processors not established in the Union/EEA).

Supervisory authority: Datatilsynet (the Norwegian Data Protection Authority) Postboks 458 Sentrum, 0105 Oslo Phone: +47 22 39 69 00 Web: https://www.datatilsynet.no

You have the right to lodge a complaint with Datatilsynet, or with the supervisory authority in your country of residence, if you believe our processing of your personal data violates the GDPR.