Privacy
Privacy Policy
One policy for every service OWCOL operates: what gets collected, why, who can see it, how long it is kept, and how to have it deleted.
The short version
OWCOL collects what the services need to work, plus the logs needed to keep them secure. Nothing else. No advertising, no analytics platform, no tracking pixels, and your data is never sold or shared for marketing. The administrator is technically able to reach your content, but only does so to operate the service, investigate abuse, or comply with the law. You can ask for a copy of your data, or its deletion, at any time. This box is a summary; the numbered sections are the policy.
01Scope
This policy applies to all services operated by OWCOL — Canvas by OWCOL, OWCOL SSO, OWCOL Office, OWCOL Mail, OWCOL SIS, and this documentation site — and to anyone who uses them.
It does not apply to third-party sites or services you reach from an OWCOL service, or to mail providers that handle messages once they leave OWCOL Mail. Those have their own policies.
02Who is responsible
OWCOL, contactable through the OWCOL Administrator at admin@owcol.com, is the data controller for most of the data described here.
Exception: where OWCOL hosts records on behalf of a school or institution — principally in OWCOL SIS and OWCOL Canvas — that institution is the controller and OWCOL acts as its processor, handling data on the institution's instructions. Requests about those records should go to the institution first; see section 14.
03What is collected
Information you provide
- Account information — name, username, email address, and any role, group, or institutional affiliation attached to your account. Accounts are provisioned by an administrator, so this typically comes from OWCOL or your institution rather than from you directly.
- Credentials — your password, stored only as a salted cryptographic hash, plus any second factor you enroll and the recovery codes generated for you.
- Content — whatever you put into a service: files, email, coursework, calendar entries, contacts, documents, discussion posts, and records you enter.
- Correspondence — messages you send to admin@owcol.com and any information in them.
Information collected automatically
- Server and access logs — IP address, timestamp, requested URL, HTTP status, referrer, and user agent.
- Authentication logs — sign-in attempts and outcomes, session creation, second-factor events, and password changes.
- Application activity — actions recorded by the service itself, such as file operations in OWCOL Office, page views in Canvas, or record access in OWCOL SIS.
- Mail transport logs — envelope sender and recipient, timestamps, message size, connecting IP, spam score, and delivery result. Message bodies are not written to logs.
- Security telemetry — blocked requests, rate-limit trips, and firewall or intrusion-prevention events.
What is not collected
No advertising identifiers, no third-party analytics or tracking scripts, no tracking pixels, no cross-site profiling, no device fingerprinting, and no sale of data to anyone. This documentation site loads no external resources and runs no JavaScript at all.
04Service by service
| Service | Address | Personal data held |
|---|---|---|
| Canvas | canvas.inactiveimmortal.com | Enrollments, submissions, quiz responses, discussion posts, grades and instructor feedback, course files, page-view and access logs. |
| OWCOL SSO | sso.owcol.com | Username, email, display name, group memberships, password hash, enrolled second factors, session and authentication logs (time, IP, user agent), consented application grants. |
| OWCOL Office | office.owcol.com | Files and folders you upload, file metadata and versions, share links and their recipients, calendars, contacts, tasks, collaborative document content, sync-client activity logs. |
| OWCOL Mail | mail.owcol.com | Message contents, attachments, folders, filters and aliases, address book entries, and mail transport logs (sender, recipient, timestamp, size, connecting IP, delivery result). |
| OWCOL SIS | sis.inactiveimmortal.com | Student identifiers and demographics, guardian and contact details, enrollment and schedules, attendance, discipline entries, grades and transcripts, staff notes, and record-access logs. |
Every service also produces the server, authentication, and security logs described above.
05Why it is processed
Personal data is processed only to:
- Provide the service you are using, and store and deliver your content.
- Authenticate you, maintain your session, and enforce the permissions attached to your role.
- Keep the platform secure — detect and investigate abuse, intrusion attempts, spam, and malware.
- Operate, maintain, back up, troubleshoot, and capacity-plan the systems.
- Communicate with you about your account, outages, maintenance, and changes to these policies.
- Comply with legal obligations and respond to valid legal process.
Your content is not used to build advertising profiles, is not sold, is not shared for marketing, and is not used to train machine-learning models.
Administrator access to content is limited to what operating the service requires: diagnosing a fault, restoring data at your request, investigating a specific abuse report, or complying with a legal obligation.
06Legal bases
Where the GDPR or a comparable law applies, OWCOL relies on:
- Performance of a contract — providing the services you have an account for, under the Terms of Service.
- Legitimate interests — securing the platform, preventing abuse, and keeping the systems running, balanced against your rights.
- Legal obligation — retention and disclosure required by law.
- Consent — for anything optional, which you may withdraw at any time.
07Cookies and local storage
OWCOL services set cookies only for functional purposes: your session, your sign-in state, CSRF protection, and interface preferences such as language or theme. Services may also use browser local storage to cache interface state and, in OWCOL Office, offline file data.
There are no advertising or analytics cookies on any OWCOL service. This documentation site sets no cookies at all.
Blocking functional cookies will prevent sign-in from working.
08Sharing and third parties
Your data is not sold, rented, or traded. It is shared only in these situations:
- Infrastructure providers — the hosting, network, and domain providers that OWCOL servers depend on. They may process data incidentally as part of operating that infrastructure and are bound by their own contractual obligations.
- Recipients you choose — people you email, share a file or link with, or collaborate with. What happens to that data afterwards is between you and them.
- Your institution — where OWCOL hosts Canvas or SIS records on a school's behalf, that school's authorized staff can access them.
- Mail in transit — email necessarily passes through the sending or receiving party's mail servers, which OWCOL does not control.
- Legal requirements — in response to a valid subpoena, court order, or other lawful demand, or where disclosure is necessary to protect the rights, safety, or property of OWCOL, its users, or the public. Where lawful and practical, you will be notified before disclosure.
- Transfer of operations — if a service is transferred to another operator, data may transfer with it, subject to advance notice and to this policy continuing to apply.
09Where data lives
OWCOL services run on infrastructure controlled by OWCOL. Data, including backups, is stored on those systems and on storage located in the jurisdictions where that infrastructure operates.
If you are in the European Economic Area or the United Kingdom, be aware that data may be stored or processed outside your region. Where such a transfer occurs, OWCOL relies on appropriate safeguards such as standard contractual clauses. Email admin@owcol.com for current details of hosting locations.
10How long it is kept
Data is kept only as long as there is a reason to keep it.
| Category | Retention |
|---|---|
| Account records and your content | For as long as the account is active. |
| Content after account closure | Deleted within 30 days, unless a legal obligation or open investigation requires otherwise. |
| Deleted files (trash and versions) | Kept for the service's configured window, then purged. Typically up to 30 days. |
| Server and access logs | Typically 30–90 days. |
| Authentication and security logs | Typically up to 12 months, longer where needed for an active investigation. |
| Mail transport logs | Typically 30–90 days. |
| System backups | Rolling window, typically up to 90 days. Deleted data may persist in backups until that window passes. |
| Education records (Canvas, SIS) | As required by the institution's retention obligations and applicable law, which may substantially exceed the periods above. |
| Correspondence with the administrator | Typically up to 24 months. |
Deletion from live systems is immediate on request; removal from backups happens as those backups age out of rotation.
11Security
OWCOL protects data with measures appropriate to a self-hosted deployment of this size:
- TLS encryption for all connections to OWCOL services, and opportunistic TLS for mail in transit.
- Encryption at rest at the storage layer.
- Centralized authentication through OWCOL SSO, with multi-factor authentication available and required for administrative accounts.
- Role-based access control, with administrative access limited to the OWCOL Administrator.
- Regular software updates, firewalling, rate limiting, and intrusion-prevention measures.
- Routine, monitored backups.
Limits
No system is perfectly secure. Content in OWCOL Office and OWCOL Mail is not end-to-end encrypted, which means the administrator is technically capable of reading it. If you hold data that needs cryptographic guarantees against the operator, encrypt it yourself before uploading. If a breach affects your personal data you will be notified without undue delay, and within 72 hours of discovery where that is required.
12Your rights
Regardless of where you live, you may ask OWCOL to:
- Access — get a copy of the personal data held about you.
- Correct — fix data that is inaccurate or incomplete.
- Delete — erase your account and content, subject to legal and institutional retention obligations.
- Export — receive your data in a portable format. Most services also provide self-service export.
- Restrict or object — limit or object to certain processing.
- Withdraw consent — where processing rests on consent.
- Complain — lodge a complaint with your local data protection authority. In the EEA and UK you may do so without contacting OWCOL first, though we would prefer the chance to fix it.
California residents have the rights described above under the CCPA/CPRA, including the right not to be discriminated against for exercising them. OWCOL does not sell or share personal information as those terms are defined under California law.
Making a request
Email admin@owcol.com with “Privacy request” in the subject line. Requests are answered within 30 days. Your identity will be verified first — normally by requiring the request to come from, or be confirmed through, the account in question. There is no charge unless a request is repetitive or excessive.
13Children
OWCOL services are not directed to children under 13 for general-purpose use, and general accounts are not knowingly created for them.
Accounts for users under 13 exist only on Canvas by OWCOL and OWCOL SIS, where they are created at the request of a school or a parent/guardian who has provided the required consent, and only for educational purposes. Data about these users is limited to what education requires, is never used for advertising or marketing, and is never sold.
A parent or guardian may review, correct, or request deletion of their child's data by contacting the institution or emailing admin@owcol.com. If personal data of a child under 13 has been collected without proper consent, it will be deleted on discovery.
14Education records
Records in OWCOL SIS and, in many cases, Canvas by OWCOL are education records. Where OWCOL hosts them on behalf of a school or institution:
- The institution is the controller; OWCOL is a processor acting under its direction, and functions as a “school official” with a legitimate educational interest where FERPA applies.
- OWCOL does not use education records for any purpose other than providing the service — not for advertising, not for profiling, not for model training.
- OWCOL does not disclose education records to third parties except as directed by the institution or as required by law.
- Access to records within the system is limited by role and is logged.
- Requests from students or guardians to inspect, correct, or amend a record should go to the institution, which directs OWCOL to act. OWCOL will supply a copy of stored data on a verified request.
- Records are retained for as long as the institution requires, and are deleted or returned at the end of the hosting arrangement at the institution's direction.
15Changes
This policy may be updated as the services change. The current version always lives at docs.owcol.com/privacy/, with the effective date at the top.
Material changes — anything that meaningfully expands what is collected or how it is used — will be announced by email or by notice within the service at least 14 days before taking effect. Continued use after that date means you accept the revised policy.
16Contact
Questions, concerns, and privacy requests all go to the same place:
OWCOL Administrator
Email: admin@owcol.com
Policy: docs.owcol.com/privacy/