Data controller
Ziad Yassine og Mikkel Ryborg Blom I/S. We are the data controller together, as one partnership. We use Stripe for payments. Questions about your data: privacy@docta.dk.
Docta is a browser extension, a website and a server that together make your itslearning course material searchable by your own AI. Docta is not affiliated with itslearning AS or your educational institution.
What we process, why, and for how long
| Data | Purpose | Legal basis | Kept |
|---|---|---|---|
| Email and sign-up date | Your account and email-link login | Contract (GDPR art. 6(1)(b)) | While you have an account |
| That you confirmed you're 18 or over, and the date of the terms you accepted, stored when the account was created | To be able to show the account was created by an adult who accepted the terms | Contract (b) | While you have an account |
| Your language (Danish or English) | To write to you and show pages in your language | Contract (b) | While you have an account |
| Your library: the text of your course material, title, course, folder, itslearning link, file type, language, status and a sha256 hash of each file | So your AI can search your material and show the source | Contract (b) | While you have access, and 90 days after access stops. We email you before deleting. When you delete your account, it is deleted right away. Copies in our encrypted backups disappear automatically within 4 weeks and are never restored |
| Your school on itslearning (e.g. "sdu"), stored as plain text; an HMAC fingerprint of your itslearning person id; when the binding was made | So one account belongs to one itslearning user. The school is stored as it is and shown under My account. The person id is never stored: the extension sends it, and the server keeps only the fingerprint, which is made with a secret key and used only to check that it's the same user | Contract (b) | While you have an account |
| Sync reports: times, counts and error codes. Never file names or content | To show you status and find faults | Contract (b) | While you have an account |
| Personal AI tokens: name, created, last used. The token itself is stored only as a hash | So your AI can sign in | Contract (b) | Until you revoke it or delete the account |
| Connected apps (the extension and AI apps you approved): the app's name as it gave it, when it was connected and last used. The access tokens are stored only as hashes | So the extension and your AI can sign in, and you can see and remove them under My account | Contract (b) | Until you remove the app or delete the account. Access that goes unused for 90 days expires |
| Payment: customer id at Stripe, subscription status and plan, invoices. We never see card details | Payment and bookkeeping | Contract (b) and legal obligation (c, Danish Bookkeeping Act) | Records for 5 years from the end of the financial year |
| Messages to support | To reply to you | Legitimate interest (f) | Until we've dealt with them; we don't delete them automatically yet. They're deleted when you delete your account (messages from the account's email), and you can always ask us to delete them |
| Server logs: time, account, method, address called (without course and file ids) and status code. Never text, tokens, itslearning ids or IP addresses | Operations, security and troubleshooting | Legitimate interest (f) | 30 days |
The same file in the same course. If another student in the same course has already synced a file with exactly the same sha256 hash, we copy the existing text into your library instead of your browser processing the file again. Each library is still your own; nobody can see who else has the file.
Links from teachers. If a teacher linked to a web page, the extension sends the link and title to us, and our server fetches the public page as text. The site sees our server's address, not yours. Pages behind a login, video sites and linked PDF files are kept as title and link only.
Your itslearning sign-in in the browser. The extension syncs using your own itslearning sign-in in the browser it's installed in. To fetch your material it goes through itslearning's normal sign-in links with that browser's own itslearning cookies. So a sync signs the browser in to itslearning or keeps it signed in, even if you had signed out yourself. Cookies from itslearning are set by itslearning, stay in your browser and are never sent to us. If you don't want that, turn on Keep itslearning signed out after a sync in the extension's settings: the extension then asks for cookie access and, after each sync, removes the itslearning cookies the sync set. You can also turn automatic sync off or remove the extension.
Chrome Web Store. The use of information received through the browser extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use it only for your library, don't sell it and don't use it for advertising.
What we never process
- Your original files. They're turned into text in your browser and aren't sent to us.
- Your itslearning password, and the extension's itslearning sign-in key. The key is kept in the extension's storage in the browser and is sent only to itslearning.
- Video and audio files, such as lecture recordings. The extension doesn't download them.
- Your questions to your AI and its answers.
- Analytics, tracking or advertising. The website has no third-party scripts.
Who we share with (processors)
| Who | What | Where |
|---|---|---|
| Netcup GmbH | The server where accounts and libraries live | Germany |
| Stripe | Payment and subscription | EU (Ireland); may transfer to the US under the EU Standard Contractual Clauses or the EU-US Data Privacy Framework |
| Brevo | Sending login links, receipts and important notices | EU (France) |
| [backup provider to be confirmed] | Storing the weekly backup. It is encrypted on our server before it's stored there, so the provider can't read it | EU |
We never sell your data and don't share it with itslearning, your school or anyone else.
Your AI
When you connect an AI such as Claude or ChatGPT, the notes it looks up are sent to that provider (for example Anthropic or OpenAI). That happens under your own agreement with them; they are independent controllers for it. We run no AI ourselves and don't use your data to train models.
Deletion and retention
- Delete your account: under My account. When you delete your account, it is deleted right away along with your library and AI tokens (GDPR art. 17), and you get a confirmation by email. Copies in our encrypted backups disappear automatically within 4 weeks and are never restored. Payment records are kept as long as bookkeeping law requires.
- Backups: we back up weekly. Each backup is encrypted with age as it's written, and the key that opens it isn't on the server; the two of us keep it offline. A backup is deleted after 28 days. A deleted account is never restored: we keep a list of deleted accounts (the account's internal id and the time, not your email), and every restore deletes those accounts again. So copies of your data in backups disappear automatically within 4 weeks after you delete your account; after that nothing is left except payment records. Data deleted any other way, such as notes mirrored away from itslearning, leaves the backups the same way.
- When access stops (cancelled or unpaid): the library is kept for 90 days so you can come back. We email you before it's deleted.
- Mirroring: if a file or course is deleted on itslearning, it's deleted from your library at the next sync.
Security
All traffic is encrypted (HTTPS). You log in with a one-time link valid for 15 minutes; your account has no password. The text in libraries isn't encrypted on the server, so it can be searched. Our admin tool shows only counts, sizes and error codes, never the content of a library, and requires two-factor login. Read more under security and data.
Your rights
You have the right of access, rectification, erasure, restriction, data portability and to object. Under My account, signed in on the website, you can download all your data yourself (art. 15 and 20) and delete your account (art. 17). Otherwise write to privacy@docta.dk. You can complain to the Danish Data Protection Agency, datatilsynet.dk.
Docta is only for people aged 18 or over.
Changes
If we change what we process, we update this page and email you before the change applies. Cookies are described on the cookie page.