Privacy Policy for INSIGHTEACH Canvas

Effective Date: 17 September 2025

1. Introduction

Welcome to INSIGHTEACH Canvas, a service provided by Insightune Technologies Sdn. Bhd. ("we," "us," or "our"). We are a company registered in Malaysia and are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share information about our users.

This policy covers the INSIGHTEACH Canvas application and our related services (collectively, the "Service"). By using our Service, you agree to the collection and use of information in accordance with this policy.

Note on student data: Your school or the individual teacher is the "Data Controller." We act as the "Data Processor," meaning we only process that data on your behalf and in accordance with your instructions.

2. Our Role as a Data Processor (Student Data)

When a teacher or school uses our Service to process student data (such as names, IDs, attendance, and scores), Insightune Technologies Sdn. Bhd. acts as a Data Processor. The teacher or their educational institution is the Data Controller.

This means:

  • The teacher or school is responsible for ensuring they have a lawful basis (e.g., parental consent) to collect and process student data using our Service.
  • We only process student data to provide the Service, as instructed by the teacher or school. We do not use student data for our own purposes, such as advertising or marketing.

3. Information We Collect

We collect information in a few different ways to provide and improve our Service.

a) Information You Provide to Us

  • Teacher Account Information: When you register for an account, you provide your name and email address.
  • Payment Information: When you subscribe to a paid plan, our third-party payment processors (Stripe or Paddle) collect your payment information. We do not store full credit card details on our servers.
  • Student Information: Teachers may add student names and IDs to class rosters to use features like attendance, scoring, and group creation.

b) Information Generated Through Your Use of Our Service

  • Session Data: Contents of your saved canvas sessions, including widgets, drawings, and other content you create.
  • Activity Data: Attendance records, quiz scores, team assignments, poll results, and activity timeline logs.
  • AI Chat Logs: Interactions with our AI Chat Assistant for service delivery and troubleshooting.

c) Information We Collect Automatically

  • Log and Usage Data: IP address, browser type, device information, pages visited, and timestamps.
  • Cookies: Essential cookies to keep you logged in and for core functionality; analytics cookies (e.g., Google Analytics) to understand usage and improve the product.
  • Local Storage: Data such as canvas session state may be stored in your browser to support offline tolerance.

4. How and Why We Use Your Information

We use your information only for specific, lawful purposes as required by regulations like GDPR.

PurposeData UsedLegal Basis (GDPR)
Provide and maintain the ServiceAccount info, student info, session/activity data, logsPerformance of a contract
Manage your account and paymentsAccount info, payment info (via processor)Performance of a contract
Communicate with youAccount info (email)Performance of a contract
Improve our Service and UXUsage data, analytics cookies (e.g., FullStory/Google)Legitimate interest
Ensure security and prevent fraudLog data, account infoLegitimate interest
Send marketing/newslettersAccount info (email)Consent

You can withdraw consent for marketing communications at any time via account settings or the "unsubscribe" link in our emails.

5. How We Share Your Information

We do not sell your personal data. We share it only with trusted third-party service providers who help us operate our business ("sub-processors").

  • Hosting and Database Providers: AWS, Supabase, and GCP to host the application and store data.
  • Payment Processors: Stripe and Paddle to handle payments securely.
  • Analytics and UX Providers: Google Analytics and FullStory to understand usage and improve the Service.
  • Communication Providers: Mailchimp for newsletters (with your consent) and Gmail for transactional emails (e.g., password resets).

6. International Data Transfers

We are a global service. Our servers and third-party services are primarily located in the United States. If you access our Service from other regions (such as the EEA or the UK), your information will be transferred to, stored, and processed in the United States.

We ensure such transfers are lawful by relying on mechanisms such as Standard Contractual Clauses (SCCs), which are included in Data Processing Addendums with our service providers.

7. Data Security

We take data security seriously. We use a combination of technical and organizational measures to protect your information, including reputable cloud providers, encryption in transit (SSL/TLS), and restricted internal access. While no system is 100% secure, we strive to follow industry-standard best practices.

8. Data Retention

We retain your personal data for as long as your account is active. If you delete your account, we will permanently delete your personal information within a reasonable timeframe (typically 90 days), except where we are legally required to retain it for longer (e.g., tax and accounting records).

9. Your Data Protection Rights

Depending on your location, you may have certain rights regarding your personal data:

  • Right of access: Request a copy of your personal data.
  • Right to rectification: Ask us to correct inaccurate information.
  • Right to erasure: Ask us to delete your personal data.
  • Right to object to processing: Object to certain processing (e.g., marketing).

You can access and update basic information (such as your name and email) from your account settings. For other requests, contact us at contact@insightune.ai.

10. Children's Privacy

We do not knowingly collect personal information directly from children under the age of 16 (or the relevant age in your jurisdiction). Our Service is intended for use by teachers and educational institutions. As stated in Section 2, the teacher or school is responsible for obtaining any necessary parental consent before adding student data to the platform.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and, if the changes are substantial, by sending you an email notification.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Insightune Technologies Sdn. Bhd. (1534817-K)

Email: contact@insightune.ai