Privacy Policy

Last updated: September 27, 2026. Version 2026-09.2

1. Entity and Roles

BentoBits Inc. provides the Rowseta software service (the "Service"). For account, billing, security, and support data, BentoBits Inc. determines the purposes of processing and acts as controller. For personal data that a Customer connects from its learning management system, BentoBits Inc. acts as processor on the Customer's documented instructions.

Privacy Officer: BentoBits Inc., support@rowseta.com.

2. Personal Data

  • Account and contact data: names, work email addresses, Organization name, subdomain, region, roles, and permissions, collected from Customers and their users.
  • Billing data: plan, invoices, transaction status, billing contacts, LMS Account counts, dated snapshot identifiers, and count-check records. Stripe collects payment-card details directly.
  • Customer-controlled LMS data: the datasets selected by the Customer, which may contain learner, staff, enrollment, course-activity, and grade data, and the Brightspace Course Access and Course Access Log extracts used to measure LMS Accounts. Derived measurement records contain user and course identifiers, UTC course-access days, per-user access counts, and last-access days.
  • Service and security data: sign-ins, sync history, audit records, IP address, user agent, timestamps, and support communications.

3. Purposes and Legal Bases

BentoBits Inc. uses personal data to create and administer accounts, provide Customer-requested analytics, control access, measure LMS Accounts for billing, process billing, monitor count accuracy and connection failures, send transactional notices, secure and support the Service, comply with law, and respond to rights requests.

Rowseta uses the Organization's stored Brightspace connection to check its LMS Account count daily without a Customer-initiated sync. These checks cover Evaluation Organizations with a completed sync and active paid Organizations from 21 days before their subscription period ends, including those with cancellation scheduled. Locked, dormant, and purged Organizations are excluded. Rowseta downloads the latest full Course Access and Course Access Log extracts and subsequent updates as needed for the count. This processing does not use Evaluation sync credits or refresh the Customer's analytical datasets.

Where applicable, the legal bases are performance of the contract, compliance with legal obligations, and legitimate interests in operating and securing the Service. Consent is used only where an applicable law requires it and may be withdrawn for future processing. Account identity, Organization, subdomain, region, and legal-acceptance information are required to create an account; optional fields are identified in the Service.

4. Disclosures

Personal data is disclosed to infrastructure, storage, backup, payment, and transactional-email providers only as needed for the purposes above; to the Customer and users it authorizes; and to authorities or other recipients where required by law. For a purchase, Stripe receives the Organization's LMS Account count, Organization identifier, snapshot identifier, and as-of date. Daily count summaries and alerts containing Organization names, counts, dates, and check status are emailed to BentoBits Inc.'s billing operations address. BentoBits Inc. does not sell personal data or share it for cross-context behavioral advertising. Customer-controlled LMS data is not used to train machine-learning models.

5. Retention

Account and Customer-controlled data is generally retained while the account is active, subject to the billing measurement cleanup described below. Locked account data is retained for 90 days and then deleted. Never-paid Evaluation accounts may be deleted after six months without an administrator sign-in plus a 90-day warning period. Platform-metadata backups are configured to age out after 30 days. Security, billing, deletion, and legal records are retained only for the period needed for their purpose or required by law.

Raw billing extracts are deleted after successful processing. After a newer count snapshot is published, cleanup removes superseded compact course-access files and per-user snapshots that are no longer needed for processing or the current billing and report snapshots. Failed cleanup is retried during later successful runs. Billing snapshot records are retained until account purge. Deleting analytical datasets does not delete billing measurement files. Remaining billing measurement files and snapshot records are removed through account purge.

6. Security

BentoBits Inc. uses technical and organizational measures appropriate to the risk, including access controls, encrypted transport, credential protection, tenant-scoped application controls, logging, backup, and deletion procedures.

7. Locations and Transfers

The Customer selects an available storage jurisdiction for its analytical data and billing measurement files. Platform metadata, query processing, and billing measurement processing are configured in Canada, and service providers may process personal data in other countries. Where applicable law requires a transfer mechanism, BentoBits Inc. and the Customer must put the required mechanism in place. No customer-specific Standard Contractual Clauses are completed by this policy.

8. Rights and Requests

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or information about processing; object to or opt out of certain processing; and complain to a privacy authority without discrimination for exercising a right. Requests concerning account data may be sent to the Privacy Officer. BentoBits Inc. verifies requests and responds within the period required by applicable law.

Requests concerning Customer-controlled LMS data should be sent to the Customer that controls that data. BentoBits Inc. assists the Customer as required by the Data Processing Agreement.

9. Student and Children's Data

Customer-controlled LMS data may concern students, including minors. The Customer determines whether that data is connected to the Service and is responsible for the notices, authority, and consents required for its use. BentoBits Inc. does not offer the Service directly to children.

10. Cookies and Automated Decisions

The Service uses cookies necessary for authentication and security and does not use advertising cookies. BentoBits Inc. does not make solely automated decisions about individuals that produce legal or similarly significant effects. Automated account rules enforce plan and security conditions.

11. Changes

Material changes are identified by a new version, and notice is provided before the changes apply. Acknowledgement records notice and does not create consent where a different legal basis applies.