Skip to main content
Platform Review
PricingSign in
← Educato assessment

Educato procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Educato
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown“ As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 18 and 21 of the GDPR: Right to Object : You have the right, on grounds arising from your particular situation, to object at any time to the processing of your personal data based on Article 6(1) (e) or (f) GDPR, including profiling based on those provisions. Where personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. Right of Withdrawal for Consents : You have the right to revoke consents at any time. Right of Access : You have the right to request confirmation as to whether the data in question will be processed and to be informed of this data and to receive further information and a copy of the data in accordance with the provisions of the law. Right to Rectification : You have the right, in accordance with the law, to request the completion of the data concerning you or the rectification of the incorrect data concerning you. Right to Erasure and Right to Restriction of Processing : You have the right to demand immediate erasure of your data or to demand restriction of the processing of your data, which includes data related to our policy of automatic account deletion due to inactivity, in accordance with the statutory provisions. ”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ If we process data in a third country (i.e. outside the European Union (EU), the European Economic Area (EEA)) or the processing takes place in the context of the use of third party services or disclosure or transfer of data to other persons, bodies or companies, this will only take place in accordance with the legal requirements. Subject to express consent or transfer required by contract or law, we process or have processed the data only in third countries with a recognised level of data protection, which includes US processors certified under the "Privacy Shield" or on the basis of special guarantees, such as a contractual obligation through so-called standard protection clauses of the EU Commission, the existence of certifications or binding internal data protection regulations (Article 44 to 49 GDPR, information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en). ”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ Right to Data Portability : You have the right to receive data concerning you which you have provided to us in a structured, common and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller. Complaint to the Supervisory Authority : You also have the right, under the conditions laid down by law, to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR. If you wish to exercise any of these rights, please send us an email at privacy@educato.com . Supervisory authority competent for us :”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ The data processed by us will be erased in accordance with the statutory provisions as soon as their processing is revoked or other permissions no longer apply (e.g. if the purpose of processing this data no longer applies or they are not required for the purpose). This includes the automatic deletion of personal data from user accounts that have been inactive for a period of one year. Inactivity is defined as the lack of user-initiated activity, such as logging in or interacting with our services. Users will be notified in advance of the impending deletion of their data due to inactivity, providing them an opportunity to interact with our services and prevent such deletion. If the data is not deleted because they are required for other and legally permissible purposes, their processing is limited to these purposes. This means that the data will be restricted and not processed for other purposes. This applies, for example, to data that must be stored for commercial or tax reasons or for which storage is necessary to assert, exercise or defend legal claims or to protect the rights of another natural or legal person. Further information on the erasure of personal data can also be found in the individual data protection notices of this privacy policy. Additionally, we offer users the option to independently delete their accounts and associated data. Detailed instructions for this can be found on our dedicated account deletion guide . ”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersmedium“Accounts that do not exhibit any activity for a continuous period of one year will be considered inactive and are subject to automatic deletion. This measure is part of our commitment to enhancing service performance and managing user data responsibly. Users approaching this inactivity threshold will receive notifications within the app, and those with registered email addresses will be alerted via email. Devices And Software : Access to our Online Services requires certain devices, software, and data connections, which are not provided by us. By using our Online Services, you agree to download and install updates to our service, either manually or automatically, as they become available. Furthermore, you consent to receiving essential service notifications from our Online Services as necessary to continue providing our services to you. Fees And Taxes : You bear the responsibility for any carrier data plans, Internet service fees, and other charges incurred from using our services, along with any applicable taxes. It's important to be aware of your local data and connectivity costs that apply when accessing our Online Services. Permission to Use Essays, Answers and Other Materials : By submitting essays, answers, or other materials on Educato , you automatically grant us and our Partners, and our and their respective successors, assigns, and legal representatives, (1) all rights, title, and interest in the intellectual property rights, including all common law rights, in and to the submitted materials, and (2) an irrevocable, perpetual, royalty-free, transferable, and worldwide right and license to use, copy, modify, adapt, publish, translate, create derivative works from, and sell and distribute any submitted materials or incorporate such materials into any form,”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ Legitimate Interests (Article 6 (1) (f) GDPR) : Processing is necessary for the purposes of legitimate interests pursued by us or a third party, provided that these interests are not overridden by your interests or fundamental rights and freedoms. This includes processing for data management, service optimization, and enhancing user privacy, such as the automatic deletion of inactive accounts. Accounts inactive for over one year may be automatically deleted to manage our user base efficiently and maintain the security of our services. National Data Protection Regulations in Romania: Complementing the GDPR, Romanian data protection is governed by Law 190/2018, which implements GDPR measures and provides specific national provisions on personal data processing. Additionally, the EU e-Privacy Directive has been incorporated into Romanian law via Law 506/2004, focusing on personal data processing in the electronic communications sector. For e-commerce privacy matters, Law 365/2002, transposing the EU E-commerce Directive, applies. These regulations, alongside guidelines from the National Supervisory Authority for Personal Data Processing (ANSPDCP), establish a comprehensive data protection framework in Romania, addressing aspects such as DPIAs, certification bodies, complaint management, and breach notifications. ”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“in principle after expiry of 4 years, unless the data is stored in a customer account or must be kept for legal reasons of archiving (e.g., as a rule 10 years for tax purposes). In the case of data disclosed to us by the contractual partner within the context of an assignment, we delete the data in accordance with the specifications of the assignment, in general after the end of the assignment. If we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms shall apply in the relationship between the users and the providers. Customer Account : Contractual partners can create a customer or user account. If the registration of a customer account is required, contractual partners will be informed of this as well as of the details required for registration. The customer accounts are not public and cannot be indexed by search engines. In the course of registration and subsequent registration and use of the customer account, we may store the IP addresses of the contractual partners along with the access times, in order to be able to prove the registration and prevent any misuse of the customer account. If customers have terminated their customer account, their data will be deleted with regard to the customer account, subject to their retention is required for legal reasons. It is the responsibility of the customer to secure their data upon termination of the customer account. ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ PostHog : Web analytics, reach measurement, and session replay – collects information about user interactions, features used, session duration, and visual recordings of user sessions for product improvement. Service provider: PostHog Inc. , hosted on PostHog 's own servers in the EU (not under our direct control). Consent handling: By default, tracking is in memory only and no cookies are set until you provide consent via our cookie banner; if you decline, tracking is disabled. Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR) and Consent (Article 6 (1) (a) GDPR) where required. Website: https://posthog.com ; Privacy Policy: https://posthog.com/privacy . Amplitude : Web analytics, experimentation, and session replay – collects information about user interactions, feature usage, session duration, and visual recordings of user sessions for product improvement. Service provider: Amplitude Inc. , 201 Third Street, Suite 200, San Francisco, CA 94103, USA; data stored in the EU ( AWS Frankfurt ). Consent handling: By default, tracking uses in-memory storage only and no persistent cookies are set until you provide consent via our cookie banner; if you decline, tracking is disabled. Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR) and Consent (Article 6 (1) (a) GDPR) where required. Website: https://amplitude.com ; Privacy Policy: https://amplitude.com/privacy . Sentry : Monitoring of system stability and identification of code errors, details of the device or time of error will be collected pseudonymously and deleted subsequently; Service provider: Functional Software Inc., Sentry , 132 Hawthorne Street, San Francisco, California 94107, USA; Website: https://sentry.io ; Privacy Policy: https://sentry.io/privacy . ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ In order to provide our Online Services securely and efficiently, we use the services of one or more web hosting providers from whose servers (or servers they manage) the Online Services can be accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space and database services, as well as security and technical maintenance services. The data processed within the framework of the provision of the hosting services may include all information relating to the users of our Online Services that is collected in the course of use and communication. This regularly includes the IP address, which is necessary to be able to deliver the contents of Online Services to browsers, and all entries made within our Online Services or from websites. E-Mail Sending and Hosting : The web hosting services we use also include sending, receiving and storing e-mails. For these purposes, the addresses of the recipients and senders, as well as other information relating to the sending of e-mails (e.g. the providers involved) and the contents of the respective e-mails are processed. The above data may also be processed for SPAM detection purposes. Please note that e-mails on the Internet are generally not sent in encrypted form. As a rule, e-mails are encrypted during transport, but not on the servers from which they are sent and received (unless a so-called end-to-end encryption method is used). ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ The purchase of our apps is done via special online platforms operated by other service providers (so-called "app stores"). In this context, the data protection notices of the respective app stores apply in addition to our data protection notices. This applies in particular to the methods used on the platforms for webanalytics and for interest-related marketing as well as possible costs. Processed Data Types : Inventory data (e.g. names, addresses), Payment Data (e.g. bank details, invoices, payment history), Contact data (e.g. e-mail, telephone numbers), Contract data (e.g. contract object, duration, customer category), Usage data (e.g. websites visited, interest in content, access times), Meta/communication data (e.g. device information, IP addresses). Data subjects : Customers. Purposes of Processing : Contractual services and support. Legal Basis : Performance of a contract and prior requests (Article 6 (1) (b) GDPR), Legitimate Interests (Article 6 (1) (f) GDPR). Services and service providers being used: Apple App Store :App and software distribution platform; Service provider: Apple Inc. , Infinite Loop, Cupertino, CA 95014, USA; Website: https://www.apple.com/ios/app-store/ ; Privacy Policy: https://www.apple.com/privacy/privacy-policy/ . Google Play :App and software distribution platform; Service provider: Google Ireland Limited , Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC , 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://play.google.com/store/apps?hl=en ; Privacy Policy: https://policies.google.com/privacy . ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Facebook Single-Sign-On : Authentication service; Service provider: https://www.facebook.com , Facebook Ireland Ltd. , 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland, Mutterunternehmen: Facebook , 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com ; Privacy Policy: https://www.facebook.com/about/privacy ; Privacy Shield (Safeguarding the level of data protection when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active ; Opt-Out: https://www.facebook.com/settings?tab=ads . Google Single-Sign-On : Authentication service; Service provider: Google Ireland Limited , Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC , 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.google.com ; Privacy Policy: https://policies.google.com/privacy ; Privacy Shield (Safeguarding the level of data protection when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active ; Opt-Out: Settings for the Display of Advertisements: https://adssettings.google.com/authenticated . ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ AppsFlyer : Mobile app attribution and analytics — measures which advertising campaigns lead to app installs and in-app events. On iOS , the app requests your permission via the App Tracking Transparency prompt before accessing the advertising identifier ( IDFA ). On Android , the Google Advertising ID ( GAID ) is used for campaign measurement. See the Advertising Identifiers section below for details. Service provider: AppsFlyer Ltd. , 14 Maskit Street, Herzliya, Israel; Website: https://www.appsflyer.com ; Privacy Policy: https://www.appsflyer.com/privacy-policy/ . Other Tracking Technologies : We may use additional tracking technologies, such as pixels from social media platforms and advertising networks (e.g., Reddit), to enhance our marketing efforts and provide more relevant content. These technologies are subject to the user's consent and can be managed through our cookie consent dialog. ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“website visitors, users of Online Services). Purposes of Processing : Provision of our Online Services and usability, Content Delivery Network (CDN). Legal Basis : Legitimate Interests (Article 6 (1) (f) GDPR). Services and service providers being used: Vercel : Hosting and services for web applications and websites; Service provider: Vercel, Inc , 340 S Lemon Ave #4133, Walnut, California 91789, USA; Website: https://vercel.com ; Privacy Policy: https://vercel.com/legal/privacy-policy . Supabase : Backend and database services; Service provider: Supabase Inc , 2345 Yale Street, 1st Floor, Palo Alto, CA 94306, USA; Website: https://supabase.com ; Privacy Policy: https://supabase.com/privacy . ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ Within the framework of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and use other service providers for this purpose in addition to banks and credit institutions (collectively referred to as "payment service providers"). The data processed by the payment service providers includes inventory data, such as the name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as the contract, total and recipient-related information. The information is required to carry out the transactions. However, the data entered is only processed by the payment service providers and stored with them. I.e. we do not receive any account or credit card related information, but only information with confirmation or negative information of the payment. Under certain circumstances, the data may be transmitted by the payment service providers to credit agencies. The purpose of this transmission is to check identity and creditworthiness. Please refer to the terms and conditions and data protection information of the payment service providers. The terms and conditions and data protection information of the respective payment service providers apply to the payment transactions and can be accessed within the respective websites or transaction applications. ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ In the context of our processing of personal data, it may happen that the data is transferred to other places, companies or persons or that it is disclosed to them. Recipients of this data may include, for example, payment institutions within the context of payment transactions, service providers commissioned with IT tasks or providers of services and content that are embedded in a website. In such a case, the legal requirements will be respected and in particular corresponding contracts or agreements, which serve the protection of your data, will be concluded with the recipients of your data. ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ RevenueCat : Subscription and in-app purchase management platform used to manage and verify subscription status across app stores; Service provider: RevenueCat, Inc. , 633 Tarava St, Ste 101, San Francisco, CA 94116, USA; Legal Basis: Performance of a contract and prior requests (Article 6(1)(1)(b) GDPR); Website: https://www.revenuecat.com ; Privacy Policy: https://www.revenuecat.com/privacy . ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Ways To Improve Our Services: We continually assess user interaction with our Online Services to enhance all facets of the services we offer. To achieve this, we not only leverage the information within our ecosystem but also collaborate with partners and service providers, including analytics tools (e.g., PostHog ) and error tracking services (e.g., Sentry ), to refine and evolve our offerings. Safety And Security: Ensuring the safety and security of our Services and its users is paramount. We are dedicated to managing and mitigating abusive behavior and activities that breach our Terms. Misuse of our services, harmful conduct towards others, and any violations of our Terms and policies are strictly prohibited. We are committed to taking decisive action against such violations, which may include removal of content, suspension of accounts, or engagement with law enforcement agencies where necessary. Enabling Global Access To Our Services : To provide our Services effectively worldwide, we utilize data centers and systems across the globe, potentially outside your country of residence. These facilities ensure that our content and information are readily available wherever our users are, and may be managed by our service partners or affiliated entities. Automatic Deletion of Inactive Accounts : We aim to maintain a dynamic and engaged user base to optimize the relevance and efficiency of our services. An account is deemed active based on interactions such as signing in and using the app while connected to the internet. ”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ To measure the effectiveness of our advertising campaigns and understand how users discover Educato , we use advertising identifiers provided by your device's operating system. This data is shared with our attribution partner, AppsFlyer , solely for the purpose of campaign measurement and optimization. ”Captured 2026-09-25Open source →Finding permalink →
Tier differencesAll applicable tiersmedium“ Until You Pass Option : For certain products, we offer an "until you pass" guarantee. If you purchase a product with this option and don't pass your exam, you can contact us via email to receive a free extension of your study access. To qualify for the extension, you may need to provide proof that you did not pass the exam. This option is only available for specific exam preparation packages that are clearly marked with "until you pass" or similar wording during purchase. We reserve the right to make all final decisions regarding eligibility for extensions under this guarantee at our sole discretion. ”Captured 2026-09-25Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.