Effective date: 3 October 2026.
Two sets of policies serve different purposes#
Nuits, the Finnish sole proprietorship operated by Bapusaheb Patil, operates Quire. These canonical operator policies describe our websites and business relationship. An institution using Quire is a separate school, employer or other organisation; its policies describe its learners, staff, courses, services and local duties. A footer link to Quire does not make us the institution, its seller or its educational controller.
On an institution's site, identify the institution from its own branding, privacy notice and contact information. The Quire/operator links lead to our separate canonical notices at quirelms.com. Policies you accept for enrolment or access can be institution policies, not a purchase or data-processing agreement with Nuits. The responsible organisation and policy version should be clear when a choice is requested.
Current public demo#
The public demo runs a fictional institution, including sample Harbourview Institute policies and records, in your browser. Those sample notices are not real contractual promises by Harbourview or Nuits and do not identify the Quire proprietor. They show the institution-facing policy system and must remain distinct from these operator documents.
The demo is for adults using non-confidential sample data. Its changes and uploads can persist in local browser storage. Reset demo data restores the working sample; complete removal may require clearing all site data. Read the Cookie and Device Storage Policy before using a shared device. Do not treat a local demo privacy request, policy acceptance or simulated payment as a request about our waitlist, a real school record or an actual purchase.
Hosted and self-hosted responsibilities#
For a future hosted deployment, the institution normally controls its learner and staff processing. It establishes lawful authority, purposes, access, required and optional fields, retention, educational assessment practices and disclosures. Nuits processes hosted institutional data on documented instructions under the signed Data Processing Agreement, while separately controlling our customer-contact and business-administration data described in the Privacy Policy.
An independently self-hosted institution operates its own service, security, backups, providers and rights procedures. Owning a Quire licence does not automatically give Nuits access to its learner database, and our supplier list does not cover its independently selected providers. Any separately agreed operator hosting or support access must be described in the applicable agreement and institutional notice.
The institution must not copy this operator notice and present it as its complete privacy policy without identifying its actual controller, uses and practices. Software defaults and sample policies cannot supply missing lawful authority or prove that operational controls are active.
What the institution must explain#
The institution is responsible for clear, applicable policies including:
- Its identity and contacts, controller role, lawful bases, data categories/sources, required and optional information, recipients, transfer arrangements, retention, rights and complaints.
- Enrolment and participation rules, staff/learner responsibilities, acceptable use, moderation and review procedures, and the consequences of an institutional breach.
- Course or product sales, pricing, payment, cancellation and refund terms where it is the seller. Its storefront refund rules are not Quire's operator subscription refund policy.
- Actual cookies/device storage, analytics, communications tracking and integrations, with usable choices where required. Educational analytics must be distinguished from optional page measurements.
- Accessibility of the deployment and its materials, accommodation contacts and alternatives for required tasks, and any applicable statutory complaint route.
- Age/guardian authority and approved child-data arrangements, and an accurate AI notice identifying enabled uses, providers, inputs, retention and meaningful human review.
Publishing a document is not enough by itself: the settings, contracts, onboarding, retention, worker operation and human handling must match it. Customers must keep their notices current as those practices change. Our canonical documents do not certify GDPR, COPPA, FERPA, WCAG or other universal compliance for a tenant.
Your route to a request or concern#
For a real course, grade, enrolment, message, institutional purchase, learner record or accommodation, contact that institution first using its published contact. Account → Privacy at /account/privacy on its application, when available, offers personal settings and export, portability, correction or erasure requests. Its Cookie Preferences page at /legal/cookie-preferences controls that host's supported categories. If you cannot identify the institution's contact, we can help locate the responsible party at legal@quirelms.com; do not send a full student record merely to identify the site.
If we receive an institutional rights request while acting as processor, we forward and assist the customer under the agreement rather than independently decide its retention or educational policy. External recipients and self-hosted systems may require requests to their responsible controller. A requested deletion can leave lawfully retained academic evidence or other participants' shared content, and does not necessarily remove all offline device copies.
For Quire's public waitlist, operator correspondence, licences or future operator-hosted commercial relationship, email legal@quirelms.com. The operator Terms, Refund Policy and Privacy Policy govern those matters as applicable, preserving mandatory rights. An institution's policy cannot waive your mandatory rights or those obligations of the operator that the law does not permit it to transfer.