KevraPublic beta

Legal

Privacy Policy

Last updated

Scope and data controller

This policy explains how personal information is handled when you use Kevra LMS. Diego Henao, the independent operator of Kevra in Colombia, is the data controller. It applies to Kevra accounts, courses, learning activities, support, and related communications. Questions and data-rights requests can be sent to support@kevra-lms.com or submitted through the Contact page.

Information Kevra processes

Kevra may process:

  • account and profile information, including your Google identifier, name, email address, profile photo, optional birthday, biography, time zone, and profile links;
  • course information, including enrollments, per-course roles, participation, and course settings;
  • learning records, including submissions, uploaded files, quiz answers and attempts, forum participation, grades, feedback, comments, and completion activity;
  • preferences and communications, including notification settings and messages generated by course activity; and
  • security and technical records, including sign-in events, audit history, request timestamps, and information needed to diagnose errors or prevent misuse.

Why information is used

Kevra uses personal information to authenticate accounts, operate courses, deliver learning materials, receive and assess work, calculate and display grades, provide feedback, send requested course notifications, support users, maintain academic records, enforce course permissions, protect the service, investigate incidents, and meet legal obligations. It is not sold or used for unrelated advertising or profiling.

Authorization and legal framework

Processing is based on the authorization you provide when you accept this policy and, where applicable, on the need to provide the educational service, protect legitimate academic and security interests, or comply with legal obligations. Kevra follows Colombia's personal-data protection framework, including Ley 1581 de 2012 and the applicable provisions compiled in Decreto 1074 de 2015.

Who can access information

Teachers and authorized teaching staff can access the information reasonably needed to manage their courses, teach, review participation, grade work, and resolve academic issues. Students may see information shared within collaborative course features, such as names, profile photos, and forum posts. Access is limited by each person's role and course membership.

Kevra also relies on service providers for functions such as Google sign-in, hosting, data storage, and email delivery. They may process information only to provide those services under their own security and privacy obligations. Information may also be disclosed when required by law, to protect rights and safety, or as part of an authorized institutional process.

Cookies and browser storage

Kevra uses an essential, secure session cookie to keep you signed in. The service also uses local or session browser storage for functional preferences, draft recovery, and quiz continuity. These technologies are used to provide requested features, not for cross-site advertising. Clearing cookies or browser storage may sign you out, reset preferences, or remove an unsent local draft.

Children and adolescents

Kevra may be used in educational settings by children or adolescents. Their information must be processed in a way that respects their best interests and fundamental rights, with the authorization and involvement of a parent, guardian, or educational institution when required. A parent or legal representative may exercise the applicable data rights on their behalf.

Security

Kevra uses role-based access controls, protected sessions, server-side validation, restricted file access, encrypted transport in production, audit records, and operational safeguards designed to prevent unauthorized access, alteration, loss, or disclosure. No online system can guarantee absolute security. If a material incident affects your information, Kevra will respond and provide notice when required by law.

Retention and account deletion

Kevra keeps information only for as long as reasonably needed for the purposes described in this policy. When you request account deletion, active access ends and direct profile details are deleted or anonymized. Academic records, including enrollments, submissions, attempts, grades, feedback, and audit history, may be retained for up to five years after the relevant academic period when needed for academic integrity, grade disputes, certification, institutional reporting, or legal and contractual obligations. After the applicable period, records are deleted or anonymized unless a longer period is legally required.

Your rights

Subject to applicable law, you may ask to know, access, update, correct, or delete your personal information; request evidence of your authorization; learn how your information has been used; revoke authorization when legally available; and submit a complaint to Colombia's Superintendencia de Industria y Comercio after completing the required direct process. You may update profile information, export your account data, or request account deletion from Kevra's settings.

How to make a request

Submit a privacy request at support@kevra-lms.com or through the Contact page and include your name, the email associated with your Kevra account, the right you wish to exercise, and enough detail to understand the request. Kevra may ask for information needed to verify your identity or authority to act for another person. Requests will be handled within the periods required by Colombian law. A request to delete information may be limited where retention is required for the reasons described above.

Changes to this policy

Kevra may update this policy as the service or legal requirements change. The current version and effective date are shown above. Material changes will be communicated when practical, and renewed acceptance may be requested where required. The related service rules are available in the Terms of Use.