Skip to content
Quire
WebsiteDocs
  • Product
  • Pricing
  • Compare
    • Moodle
    • Canvas
    • Blackboard
    • Google Classroom
    • Docebo and TalentLMS
    • All comparisons
  • Try the live demo
  • Join the waitlist

Quire / Operator documents / English

Privacy Policy

How Nuits handles Quire website, waitlist and business-contact data, and how customer learning data is handled in hosted and self-hosted deployments.

Effective 3 October 2026 · Contact legal@quirelms.com

On this page

  1. Who is responsible
  2. What is available now, and what changes with deployment
  3. Data we collect and where it comes from
  4. Purposes and legal bases
  5. Learning data in customer deployments
  6. Analytics, communications and automated assistance
  7. Recipients and service providers
  8. International processing
  9. Retention and deletion
  10. Your choices and rights
  11. Complaints, security and changes

Effective date: 3 October 2026.

Who is responsible#

Quire is operated by Nuits, a Finnish sole proprietorship operated by Bapusaheb Patil, VAT ID FI35848458. In this policy, “we” means that operator. Contact legal@quirelms.com for privacy questions, rights requests and security concerns. Our business address is available on request through that mailbox. See the Imprint for identity and disclosure information.

We are the controller of personal data used to run our public websites, manage the Quire waitlist, answer enquiries and administer our own business relationships. This notice covers quirelms.com, www.quirelms.com, docs.quirelms.com and demo.quirelms.com and our operator-side communications. It does not replace an institution's privacy notice.

What is available now, and what changes with deployment#

The current public offering is a pre-release waitlist and a browser-local demonstration. There are no current paid sales described by this notice. The demo uses fictional institutional records and stores its working database and changes in your browser. Those local learning records are not a hosted customer database that we receive. Requests for static assets still reach our delivery infrastructure; emailing us or joining the waitlist sends the information in that communication to us. Do not put real student records, passwords or confidential information into the demo.

For a future hosted customer deployment, the school, employer or other customer normally determines the purposes and lawful basis for its learner and staff data and is the controller. We process that data on its documented instructions under a signed Data Processing Agreement. We remain a separate controller for our customer contacts, contractual administration, our own billing and legal obligations. Access to an institution's data does not make us its educational controller.

In an independently self-hosted deployment, the customer operates its infrastructure and chooses its providers. Licensing the software does not by itself send its database, files or learner records to us. We receive only data involved in an actual interaction with us, such as licensing administration or information the customer deliberately supplies in a support case. Separately purchased operator access or hosting must be covered by the applicable agreement. The Tenant Site Policies explain which notice to consult.

Data we collect and where it comes from#

For the current public service, the relevant categories and sources are:

  • Website requests: network address, requested URL, request time, browser or user-agent information, response and security information may be processed by our delivery infrastructure when your browser requests a page or asset. Device preferences are described in the Cookie and Device Storage Policy.
  • Waitlist signup: you provide an email address and hosted, self-hosted or unsure intent. Organisation-size band is optional. The form also supplies its language and source path, and the request supplies a client address. We keep confirmation and unsubscribe timestamps, a digest of the confirmation token, and the versions and date of the terms/privacy acknowledgement. Acceptance records may include client address and user-agent information, with the user-agent limited to 500 characters.
  • Enquiries and support: you supply contact details, correspondence and any attachments you choose to send. A customer or colleague may give us a business contact's name, role and contact information. Avoid sending learner records or unnecessary sensitive information; use a separately agreed secure channel where needed.
  • Future business administration: customers supply order, licence, billing-contact and payment-reference information. Identity, access, incident and contract records arise from administering that relationship. Any collection additional to the current waitlist will be explained when the service is offered.

Reading the public static sites does not require an account or a waitlist signup. To join the waitlist, an email address, an intent selection and the form's terms/privacy acknowledgement are required; confirmation of the email is required to activate the subscription. Without them we cannot subscribe you. The optional organisation-size answer can be omitted without losing access. Technical request information is necessary to deliver and protect the service. If you contact us, enough information to answer or verify a request may be necessary, but you need not send unrelated personal information.

The signup acknowledgement is not blanket consent to every processing purpose in this policy. The confirmation process establishes your request for waitlist communications; we limit operator promotional mail to the launch and offer messages you have validly consented to receive. We do not acquire learner records from data brokers or use the public demo to build learner advertising profiles.

Purposes and legal bases#

Where the GDPR applies, we use the following bases for data for which we are controller:

  • Waitlist confirmation and the launch or offer information you have consented to receive: consent. You can withdraw by the unsubscribe link or by emailing us, without affecting the lawfulness of processing before withdrawal.
  • Answering a purchase or licensing enquiry made by you: steps at your request before a contract, and performance of a contract if one is entered into. Managing a representative's business contact details, ordinary enquiries and support administration: our legitimate interests in responding and conducting the business relationship.
  • Delivering public pages, preventing abusive signups, securing systems, diagnosing service faults and recording necessary evidence: our legitimate interests in reliable services, protection against abuse and establishing or defending claims. We consider your interests and use information proportionate to those purposes. You may object to processing based on legitimate interests.
  • Accounting, tax records, legally binding disclosures and other mandatory records: compliance with applicable legal obligations. We do not treat optional marketing as a legal obligation.
  • Optional device storage, analytics or communications tracking where offered: consent where required, with the specific controls explained at the point of use. Storage strictly necessary for a requested function or recording your choice is distinguished from optional measurement.

The institution, not this operator policy, identifies the legal basis for its education, employment and assessment processing. It must have authority for any special-category data and children's data it instructs us to process. Highly sensitive health or biometric data is excluded from our standard offering unless separately agreed with appropriate safeguards. The Age and Children's Data Policy sets the prerequisites for child deployments.

Learning data in customer deployments#

Depending on the customer's enabled modules, its records can include profiles and identifiers; locale, timezone and accessibility settings; age or country information where collected; enrolments, progress and attendance; assignments, assessment attempts, grades and teacher feedback; forum, chat and wiki content; uploaded files; credentials; orders and payment references; notifications; consent and audit records; and AI messages, prompts and results. Identity sessions can include network address and user-agent information. Data can come from learners, authorised staff, guardians, an identity provider, institutional imports and integrations, and activity within the learning service. Not every deployment collects every category.

Authorised teachers, administrators and other recipients identified by the institution can see relevant records under its access rules. Published posts and collaborative content may be visible to other participants. The institution must explain its directory, sharing, assessment, retention and integration choices and the consequences of required or optional fields. Do not assume that a course tutor conversation is private from the teacher.

Analytics, communications and automated assistance#

Our current static public sites do not include configured advertising pixels or behavioural advertising profiles. There is no marketing-cookie category to enable on those sites. This is not a claim that all technical requests or security logs are anonymous.

The customer application supports first-party page timing and route statistics when the deployment and applicable choices allow them. Some modes use a daily pseudonymous user bucket, device class and country information. These are not necessarily irreversibly anonymous. Educational progress and learner-risk analytics are different from optional page statistics and remain subject to the institution's lawful basis and notice.

Application email delivery can support open pixels and tracked links with per-message events. For our operator messages, open and click tracking may be used only after separate valid consent; joining the waitlist or accepting the terms/privacy notice does not grant that tracking consent. You can refuse or withdraw tracking consent at legal@quirelms.com without losing the launch messages you separately requested. Customer institutional email configuration and personal choices are a separate matter, and not all application regions have identical defaults. Use the unsubscribe link for waitlist mail and the institution's Account → Privacy settings for its available communications choices.

AI features are deployment-dependent and can forward messages, submitted work, rubrics, accessible course context or authored text to a selected provider. We do not use the public waitlist to make solely automated decisions with legal or similarly significant effects. Our service policy is that consequential educational decisions, including final grading and action based on learner-risk indicators, require meaningful review by an authorised person; AI suggestions are not a substitute for that review. You can ask the responsible institution for human review, present your view and contest an outcome. See the AI Use Disclosure.

Recipients and service providers#

Our public sites are delivered through Cloudflare. Delivery necessarily involves its handling of network requests and may involve security and operational metadata. Mail-delivery and mailbox infrastructure providers process the information needed to deliver and store our correspondence. We do not represent an available email, payment, AI or hosting adapter as a currently appointed supplier. You can request recipient and location information at legal@quirelms.com.

Access to operator-held information is limited to people authorised for the relevant business purpose and the providers needed to deliver that purpose. Professional advisers and authorities may receive necessary information for accounting, legal advice, a binding legal requirement or the protection of rights. We do not sell personal data or share it for cross-context behavioural advertising. A business transfer, if one occurs, must protect data under applicable law and be explained to affected people as required.

Future hosted processing needs a deployment-specific supplier and location schedule before customer data is entrusted to that service. Customer-selected identity, communications, payment, learning-record, meeting, AI or other integrations have their own recipients and terms; they are not all currently active. Consult the Subprocessor Information and the institution's notice for the applicable deployment, rather than treating software capabilities as a supplier register.

International processing#

Nuits is established in Finland, but internet delivery, mailbox services and customer-selected providers can involve processing outside Finland and outside the EEA. A Finnish operator or a selectable EU setting is not a guarantee that every request stays in the EU. This policy does not certify a processing country or contractual transfer arrangement without the actual recipient-specific information.

Where a restricted transfer requires a legal mechanism, that mechanism must be established for the actual recipient and route before the transfer: for example an applicable adequacy decision, or appropriate contractual safeguards such as the European Commission's Standard Contractual Clauses together with the required assessment and supplementary measures. Merely linking to those clauses does not execute them. You may ask legal@quirelms.com about the recipients, countries and safeguards applicable to your data and request a copy or explanation, with protected commercial or security information redacted where necessary. Future hosted regional commitments are defined in the signed deployment schedule; independently self-hosted customers determine their own transfers.

Retention and deletion#

We apply the following operator commitments. Some require manual action and are not a claim that every deadline is already enforced by an automated job:

  • Waitlist records are removed within 24 months of your last engagement. Unsubscribing stops waitlist mail but does not immediately erase the stored signup row. Minimal suppression or dispute evidence may be retained separately where necessary to respect your opt-out or a legal obligation; we limit it to that purpose and explain a continued retention on request.
  • Confirmation links expire after 48 hours. The application has pruning for unconfirmed entries 30 days after token expiry, triggered by later signups; it is not a continuously running deletion guarantee. You can request removal without waiting for that process.
  • Routine operator service and security logs are retained for up to 90 days. Material needed for a specific incident, legal obligation or claim may be isolated and kept for the necessary period rather than used as routine telemetry.
  • Enquiries and support information are kept while needed to answer and resolve the matter, and afterwards only as necessary for the relationship, applicable limitation periods, legal duties or claims. Accounting and contractual evidence follows the applicable statutory requirements rather than a promise of immediate deletion. We review continued need and restrict retained records to those purposes.
  • Future hosted customers have a 30-day data-export period after termination. Subject to lawful customer instructions, required preservation and law, we commit to deleting live hosted customer data within 60 days after termination and backup copies within 90 days. Necessary preserved records remain restricted until the preservation ground ends.

During an active institutional service, the institution defines its lawful retention schedule. Product defaults, which the institution can configure within supported limits, include five years for progress and assessment evidence, three years for communications, 365 days for closed-account identity, 30 days for recycle-bin items and privacy export packages, and seven years for consent and billing records; credentials can be retained indefinitely where justified. These defaults are not this operator's universal retention rule or a declaration that each period is lawful for every institution. Files generally follow their owning records and holds can prevent deletion.

Erasure may remove or pseudonymise direct identifiers without removing required academic evidence, shared authorship or personal information embedded in surviving free text. AI prompt and response records and recipients' copies require their own assessment; removing an actor's name is not complete erasure of all content. An identity used in another institutional membership may remain for that membership. Local demo and offline copies on your device are not cleared by an email unsubscribe, server-side erasure or necessarily by logging out. See the Device Storage Policy for device removal instructions.

Your choices and rights#

Depending on applicable law and the circumstances, you may request access and a copy, correction, erasure, restriction, and portability of data processed by automated means on consent or contract. You may object to processing based on legitimate interests and to direct marketing at any time, withdraw consent, and seek human review of a consequential automated outcome. These rights are not all absolute; statutory retention, other people's rights and legitimate grounds can affect a request. Withdrawal does not invalidate earlier lawful processing.

For our waitlist, correspondence and business-contact data, email legal@quirelms.com, stating the address or relationship concerned and the right you wish to exercise. Requests are handled by the operator; there is no requirement to have a customer account or pay to submit one. We may ask for proportionate information to verify identity or an authorised representative. Please do not send identity-document copies unless specifically needed and an appropriate channel has been agreed.

For institutional records, contact the institution's privacy contact or use Account → Privacy on its application when available. That screen supports personal choices and export, portability, correction or erasure requests. Restriction and objection can also be raised with its privacy officer. If a request reaches us as processor, we will assist and forward it to the customer rather than decide its educational records policy ourselves. Device-local demo requests affect fictional/local records, not our controller-held waitlist data.

Under the GDPR we respond without undue delay and ordinarily within one month of receipt. If complexity or number of requests permits an extension of up to two further months, we explain it within the first month. If we refuse or charge for a manifestly unfounded or excessive request where the law permits, we explain the grounds and remedies. Other laws may prescribe different deadlines or appeal rights; identify your jurisdiction if it is relevant, or ask us to explain them. You will not be discriminated against for exercising an applicable privacy right.

Complaints, security and changes#

You may complain to the Finnish Office of the Data Protection Ombudsman or your competent supervisory authority, including the authority where you habitually reside, work or consider an infringement occurred. You do not lose that right by contacting us first, and applicable judicial remedies remain available. We use legal@quirelms.com as the privacy contact; it is not a representation that a statutory Data Protection Officer has been appointed.

Report suspected exposure or an access problem to legal@quirelms.com, giving enough context to investigate without unnecessarily reproducing sensitive records. Security and backup measures depend on the real deployment and agreement. We do not promise breach-proof systems, universal encryption of all stored data, or a security certification through this notice.

This version takes effect on the date above. Material changes to purposes or data handling will be published and, where required, communicated directly or subject to a fresh choice before the changed processing. The institution is responsible for changes to its own notice.

Back to top

Everything you need to run learning.

Pre-release. Not yet open for sign-up. Things on this site may change.

WebsiteDocs

Contact legal@quirelms.com

LanguageEnglish
  • English
  • العربية
  • Deutsch
  • Español
  • فارسی
  • Suomi
  • Français
  • עברית
  • हिन्दी
  • Bahasa Indonesia
  • Italiano
  • 日本語
  • 한국어
  • Nederlands
  • Polski
  • Português (Brasil)
  • Русский
  • Svenska
  • Türkçe
  • اردو
  • 简体中文

Operator legal documents are in English.

Policies

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Cookie preferences
  • Refunds and Cancellation
  • Age and Children
  • Institution Policies

Compliance

  • Data Processing Agreement
  • Subprocessors
  • Accessibility
  • Accessibility conformance report
  • Do Not Sell or Share
  • AI Disclosure

Company

  • Imprint
  • Acceptable Use

Quire