Privacy Notice
Last updated: 17 April 2026
1. Who we are
DataMentor AB ("DataMentor", "we", "us", "our"), registered in Sweden with its registered office at Sländstigen 12, 191 38 Sollentuna, Sweden, is the data controller for personal data processed in connection with Kursixa (the "Service").
For any privacy-related questions, contact us at support@kursixa.se.
2. Personal data we collect
We process the following categories of personal data:
- Account data — name, email address, password (hashed), workspace membership, and role.
- Profile data — optional avatar and display name.
- Content data — initiatives, scoring inputs, comments, and other content you create within the Service.
- Communications — messages you send to our support team.
- Usage and telemetry — basic logs about how you interact with the Service (pages visited, features used, errors), device identifiers, and IP address.
3. Why we use your data and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and manage your account | Performance of contract |
| Provide and operate the Service | Performance of contract |
| Customer support | Performance of contract / legitimate interests |
| Security, fraud prevention, and abuse detection | Legitimate interests |
| Improve and develop the Service | Legitimate interests |
| Service-related notifications (transactional emails) | Performance of contract |
| Comply with legal obligations (e.g. accounting) | Legal obligation |
4. Who we share data with
We share personal data only with the following categories of recipients, under appropriate data-processing agreements:
Subprocessors that help us operate the Service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage, transactional email delivery (account verification, password reset, invitations), and serverless backend functions. | EU (Frankfurt) with US fallback |
| Cloudflare, Inc. | Application hosting (Cloudflare Workers), CDN, and DDoS protection for the Kursixa web application. | Global edge network |
| Paddle.com Market Limited | Merchant of Record for payment processing, subscription management, tax compliance, and invoicing. Paddle acts as an independent controller for data it collects at checkout. | UK / EU / US |
| Functional Software, Inc. (Sentry) | Application error monitoring and crash reporting. Receives error messages, stack traces, browser/OS metadata, and the URL where an error occurred. We do not send form inputs or initiative content to Sentry. | US (with EU data residency option) |
We may also share personal data with professional advisers (legal, accounting) where reasonably necessary, and with public authorities where required by law or to protect our rights.
We will update this list whenever we add a new subprocessor and notify users of material changes.
5. International transfers
Some of our subprocessors are located outside the EU/EEA. Where this is the case, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) or adequacy decisions.
6. Data retention
We retain your personal data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we are required to retain it longer to comply with legal obligations (e.g. tax records) or to resolve disputes.
7. Your rights under GDPR
If you are in the EU/EEA, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- request erasure of your data;
- request restriction of processing;
- data portability (receive your data in a structured, machine-readable format);
- object to processing based on legitimate interests;
- withdraw consent at any time, where processing is based on consent;
- lodge a complaint with a supervisory authority — in Sweden, this is the Integritetsskyddsmyndigheten (IMY).
To exercise any of these rights, email support@kursixa.se. We will respond within one month.
8. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), encryption at rest, role-based access controls, and regular backups. No system can be guaranteed 100% secure, but we work continuously to maintain a high standard of protection.
9. Cookies
Kursixa uses only strictly necessary cookies required to keep you signed in and to operate the Service. We do not currently use analytics or marketing cookies. If we add such cookies in future, we will update this notice and provide a cookie banner to manage your preferences.
10. Changes to this notice
We may update this Privacy Notice from time to time. We will notify you of material changes by email or through the Service.
11. Contact
DataMentor AB
Sländstigen 12
191 38 Sollentuna, Sweden
Email: support@kursixa.se