Pensa Privacy Policy
Last updated: 2 September 2026
1. Who is responsible for your data
Your institution has installed Pensa inside its own Canvas. Under the GDPR your institution is the data controller and Pensa is the data processor, acting on your institution's documented instructions under a data processing agreement.
For every right described below, your institution is the party legally obliged to answer you, and its data protection officer is usually the fastest route. Pensa is contractually required to assist, and does.
Pensa is a pilot project under NTNU Discovery, is not a registered company, and publishes no telephone number or postal address. Contact: contact@pensa.no
2. What we process
- Identity. A pseudonymous subject identifier issued by your institution's Canvas, your institution, your course, your role in it, and internal pseudonymous identifiers derived from these. The identifier is pseudonymous, not anonymous: it is stable, specific to you, and your institution can link it back to you. We do not process your name, e-mail address, telephone number, postal address, student number, date of birth, profile picture, payment details, location data or advertising identifiers.
- Content you produce. Your questions and Pensa's answers, stored verbatim; the course excerpts cited in each answer; follow-up threads; conversation titles, which are the first 120 characters of your own first message; and Reflect sessions, including model-written summary cards. In Reflect voice mode, your audio goes from your browser directly to our speech provider and only the transcribed text is stored, together with the duration in seconds and playback progress.
- Feedback. Survey ratings and optional free-text comments, and ratings of individual answers with optional reason categories and free text.
- Usage. Which learning surface you opened, for which lecture, on which day, and your answer-style and language settings.
- Technical and operational data. Session and login-handshake records, a usage and cost ledger containing no question or answer text, browser error diagnostics carrying no user identifier, a security event register, an internal administration audit log, and an aggregate monthly spending figure held under a one-way hash.
- IP address, read solely to count requests for abuse protection. It is hashed, truncated, kept for 60 seconds, and never stored in the clear.
We also index course files a lecturer selects, and lecture recordings where enabled. That is course material, not personal data about you.
Important: Pensa applies no filter that removes sensitive personal data from what you write. Do not enter information about health, beliefs, sexuality, political views, or about other people.
3. Where the data comes from
Most of it comes from you directly, when you open Pensa from Canvas, accept the terms, ask a question, speak in Reflect voice, give feedback, change settings or load a page.
We also receive data from your institution's Canvas, which is the source of the signed launch token and the course files, and from your institution's Panopto tenant where lecture recordings are used.
4. How we use your data, and on what basis
Pensa processes your data on your institution's instructions in order to:
- Provide the Service: answer your questions from your course's own material with page citations, keep your conversations, and run the Prepare, Catch-up and Reflect study modes
- Apply your preferences: language and answer style
- Report to your lecturer: aggregated course statistics only — never individual conversations, never your identity
- Keep the Service running and secure: abuse protection, cost control, error diagnostics and security monitoring
Legal basis. The legal basis is your institution's, established in its agreement with Pensa, not your individual consent given to Pensa. This document is information, not a consent form. Your institution can tell you which Article 6 basis applies.
Your data is not used for advertising or marketing, not sold or shared with any partner company, not used to grade you or report your individual activity to your lecturer, and not used to train AI models. There is no automated decision-making producing legal or similarly significant effects, and no profiling, within the meaning of Article 22.
Providing this data is not a statutory or contractual requirement, but Pensa cannot operate without the launch identifiers and the text of your questions. If you decline the terms, no record about you is created and the tool is unavailable to you.
5. How we share data
We do not sell your personal data. It is disclosed only to sub-processors, which process it on our instructions under data processing agreements. Categories of provider:
- Cloud infrastructure, hosting and database providers
- AI providers for generation, search and ranking
- A speech recognition and synthesis provider, for Reflect voice
- A document parsing provider and a background job provider, for course material
- A caching provider, for abuse counters and search caching
The full sub-processor register, naming each provider and its processing region, is part of the agreement your institution holds, and is available from your institution or from contact@pensa.no.
6. International transfers
Pensa's application logic and storage run in the EEA. Some providers are US-registered companies operating in EU regions. Where any processing involves a transfer outside the EEA, it takes place under the safeguards recorded in the data processing agreement your institution holds; your institution can provide a copy of those terms.
7. Retention and deletion
- Conversations and everything attached to them are kept for 6 months from the last message in that conversation, then permanently deleted. This is a default: your institution, or an individual course, can be configured to a shorter or longer period.
- Survey answers, answer feedback, usage records, security events and audit logs are kept for 12 months.
- Browser error diagnostics are kept for 90 days; sessions for 8 hours; login handshake records for minutes; the hashed monthly spending figure for two to three months.
- The usage and cost ledger, which holds no question or answer text, has no scheduled deletion window. It is removed when you delete your data or when the course is deleted.
Deletions operate on the live database. Deleted data can persist in the database platform's backups and recovery snapshots for the platform's backup window before ageing out.
8. Your rights
Requests made to Pensa are answered within one month, at no fee. For access, objection and restriction, contact your institution's data protection officer.
- Access and portability. You may request a copy of your data. The in-app button files a request; the export is a JSON bundle produced by an operator and returned to you.
- Rectification. Inaccurate data corrected and incomplete data completed. There is no edit function in the app; contact your institution or contact@pensa.no.
- Erasure. Available to you directly and immediately: Profile → Data controls → Delete all my data, which permanently removes your profile and everything attached to it. There is no undo. Two limits: the hashed monthly spending figure survives by design and ages out after two to three months, and a no-content record naming no subject is kept as evidence that the erasure took place. Deletion does not clear preferences stored in your browser, and is not account closure — a fresh pseudonymous identity is created if you open Pensa again. You may also delete a single free-chat conversation from the history menu.
- Restriction. Implemented, but not self-service; contact your institution or contact@pensa.no. While a restriction is active it also blocks your own delete and export buttons.
- Objection. Decided by your institution as controller.
- Complaints. See section 10.
9. Cookies and browser storage
Pensa sets three cookies, all strictly necessary to deliver the service you requested by opening the tool: lti_session, your encrypted 8-hour session, holding your pseudonymous identifiers, institution, course, roles and interface language, and no free text; and lti_state and lti_nonce, two random values that protect the Canvas login handshake, valid for five minutes and deleted on successful launch. Blocking them prevents the Canvas launch from completing and Pensa will not work.
Pensa sets no analytics, advertising or functionality cookies and loads no third-party script.
Your preferences — answer-style sliders, language, theme, reading typeface, an onboarding flag, a dismissed-hint flag per course and the voice mute toggle — are stored in your browser's local storage. Your theme and typeface never leave your device; your sliders and language are sent with each request so answers can follow them. Clear the site's storage in your browser to remove them.
Canvas and the hosting platform may set their own cookies, covered by your institution's own privacy information.
10. Contact and complaints
E-mail: contact@pensa.no — Pensa v/ Theo (CTO), pilot project under NTNU Discovery.
You can also contact your institution's data protection officer, through the details your institution publishes.
You may lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet (datatilsynet.no, postkasse@datatilsynet.no, Postboks 458 Sentrum, 0105 Oslo). If you are based outside Norway, you may also contact the supervisory authority in your country of residence.
11. Changes to this policy
Updates are published at https://pensa.no/privacy-policy and the "Last updated" date above is changed. Material changes are communicated to your institution as controller, which decides how they are communicated to you.