Privacy Policy

Last updated: March 2026

1. Data controller

The data controller is Soltea, based in Italy. For any privacy-related requests, please write to privacy@edukite.it..

2. Data collected

EduKite collects the following data:

  • Google authentication data: name, email address and profile picture, obtained via Google OAuth 2.0 at login. nome, indirizzo email e immagine del profilo, ottenuti tramite Google OAuth 2.0 al momento dell'accesso.
  • Billing data: name, surname, company name, VAT number, tax code, address, SDI/PEC code, entered voluntarily by the user for electronic invoicing. nome, cognome, ragione sociale, partita IVA, codice fiscale, indirizzo, codice SDI/PEC, inseriti volontariamente dall'utente per la fatturazione elettronica.
  • Usage data: logs of operations performed (OCR, audio generation, map generation, image generation) with related costs, for credit tracking purposes. log delle operazioni effettuate (OCR, generazione audio, generazione mappe, generazione immagini) con i relativi costi, ai fini del tracciamento del credito.
  • Uploaded content: images with text, PDF and DOCX documents uploaded by the user for processing. This content is used exclusively to provide the service. immagini con testo, documenti PDF e DOCX caricati dall'utente per l'elaborazione. Questi contenuti vengono utilizzati esclusivamente per fornire il servizio.

3. Purpose of processing

Personal data is processed for the following purposes:

  • User authentication and identification.
  • Service delivery: processing uploaded content to generate summaries, audio and concept maps.
  • Credit and billing management.
  • Service improvement and anonymized aggregate analytics.

4. Data retention

Content uploaded by the user (images, documents) is not permanently stored. It is processed to generate learning materials and can be deleted by the user at any time.. Vengono elaborati per generare i materiali didattici e possono essere eliminati dall'utente in qualsiasi momento.

Account data and generated lessons are retained until the user deletes their account or for a maximum period of 24 months from the last login.

5. Third-party services

EduKite uses the following third-party services to deliver the service:

  • Google OAuth 2.0: for user authentication. per l'autenticazione degli utenti.
  • OpenAI API: for text processing, audio generation (text-to-speech) and image generation. Content sent to OpenAI is subject to OpenAI's privacy policy. per l'elaborazione dei testi, la generazione di audio (text-to-speech) e la generazione di immagini. I contenuti inviati a OpenAI sono soggetti alla privacy policy di OpenAI.
  • Stripe: for payment processing. Payment data is managed directly by Stripe and is not stored on our servers. per l'elaborazione dei pagamenti. I dati di pagamento sono gestiti direttamente da Stripe e non vengono memorizzati sui nostri server.

6. User rights

In accordance with the GDPR (EU Regulation 2016/679), the user has the right to:

  • Access their personal data.
  • Request rectification or deletion of data.
  • Object to processing or request its restriction.
  • Request data portability.
  • Withdraw consent at any time.

To exercise these rights, write to privacy@edukite.it..

7. Cookies

EduKite uses only technical cookies necessary for the application to function (authentication tokens, language preference). No profiling or third-party cookies are used for advertising purposes.

8. Security

We adopt adequate technical and organizational security measures to protect personal data from unauthorized access, loss or destruction. Communications use the HTTPS protocol. Authentication data is managed via JWT tokens.