Legal

Privacy Policy

Questions about this policy? Contact us at privacy@incluxa.com. See also our Terms of Service and Cookie Policy.

1. Who We Are

Angstroma, Inc. operates the INCLUXA accessibility service ("INCLUXA," "we," "us," or "our") from the United States.

2. Scope of This Policy

This Privacy Policy applies to portal users (incluxa.com accounts), website visitors, end users of our accessibility widget on customer websites, and users of the INCLUXA Chrome Extension.

If you are a visitor to a website using the INCLUXA widget: The website operator is the data controller for your personal data. INCLUXA acts as a data processor on their behalf. Please refer to that website's own privacy policy.

If you are a Chrome Extension user: All accessibility adjustments (contrast, fonts, reading aids, etc.) run locally on your device. We do not collect your browsing history, nor any data about the websites you visit. We do not track which pages you open or how long you spend on them. See Section 3 for the full list of what an extension install does send to our servers.

3. Data We Collect

Portal users

We do not sell your data. Widget end user data is never used for advertising or cross-site tracking.

Chrome Extension users

The extension is designed to minimize data collection. Most of what you configure stays on your device and is never transmitted to our servers.

What we explicitly do NOT collect from Chrome Extension users: your browsing history, the URLs or content of pages you visit, which sites you spend time on, your tab list, passwords, form data, bookmarks, or any advertising identifiers. The extension applies visual adjustments locally on the page in front of you and nothing else.

If you are in the EEA, UK, or Switzerland, we process your data under these legal bases:

5. How We Use Your Data

  • Provide, operate, and maintain the INCLUXA service
  • Process transactions and send billing-related notices
  • Send account notifications and security alerts
  • Respond to support requests
  • Detect and prevent fraud, abuse, and security incidents
  • Generate aggregated, anonymized analytics to improve the product
  • Comply with applicable laws and enforce our Terms of Service

6. Data Sharing and Disclosure

We do not sell your personal data. We share data only with service providers (sub-processors) required to deliver our service, and when required by law.

All sub-processors are bound by Data Processing Agreements. Contact privacy@incluxa.com to request a copy.

7. International Data Transfers

Our infrastructure is primarily hosted in the United States. Transfers from the EEA, UK, or Switzerland are made under Standard Contractual Clauses (SCCs) or UK IDTAs. Contact us to request a copy of the relevant safeguards.

8. Data Retention

9. Your Rights

All users may access, correct, delete, and export their data, and opt out of marketing at any time.

EEA / UK users (GDPR) may additionally restrict processing, object to legitimate-interest processing, and withdraw consent at any time. You may lodge a complaint with your national data protection authority.

California residents (CCPA / CPRA) have the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell data.

To exercise your rights: privacy@incluxa.com. Response within 30 days (GDPR) or 45 days (CCPA).

10. Cookies

We use strictly necessary, functional, and analytics cookies. For a complete list see our Cookie Policy. Manage preferences via the Privacy Choices link in our footer.

11. Security

We use Argon2id password hashing, RS256 JWT, AES-256 encrypted session cookies, TLS 1.2+ in transit, and immutable audit logs. For full details see our Security page.

No system is completely secure. In the event of a breach, we will notify affected customers within 24 hours of confirming it, and supervisory authorities within 72 hours where the law requires.

12. Children's Privacy & Student Data (COPPA · FERPA)

Schools tier customers: This section governs all student data processing. The district agreement (SDPC National Data Privacy Agreement v2.0 plus the applicable state exhibit) must be signed in the portal under Settings → Schools before IEP automation, the teacher dashboard or LMS connections can be used. The district selects the student-data retention period (1–120 months).

12.1 Platform Not Directed to Children

The INCLUXA portal, API, and scanner are B2B services directed to businesses and educational institutions — not to individual children. Portal accounts are for adults acting for a business or school (our Terms of Service require account holders to be at least 18). We do not knowingly solicit or collect personal information directly from children under 13, except as a school's service provider under a signed district agreement. If you believe a child under 13 has provided us personal data without appropriate consent, contact privacy@incluxa.com and we will delete it within 5 business days.

12.2 Schools Tier — COPPA (16 C.F.R. Part 312)

The Schools tier enables K–12 institutions to deploy accessibility features for students, including those under 13. Schools may consent on parents' behalf for educational use, consistent with long-standing FTC COPPA guidance, where the operator processes student data solely for the use and benefit of the school and for no other commercial purpose. The amended COPPA Rule's compliance date was April 22, 2026.

By activating the Schools tier and uploading student data, the subscribing institution:

  • Represents it is providing parental consent on behalf of enrolled students for the limited purpose of delivering accessibility services
  • Warrants it has complied with all applicable COPPA requirements, including providing direct notice to parents where required
  • Agrees that INCLUXA processes student data solely as a data processor on the school's instructions

We never use student data for advertising, marketing, profiling, or any commercial purpose beyond the accessibility services contracted by the school. Student data is never sold.

12.3 FERPA (20 U.S.C. § 1232g; 34 C.F.R. Part 99)

For educational institutions subject to FERPA:

  • School Official Designation. Schools that sign the district agreement designate INCLUXA as a "school official" with a "legitimate educational interest" as defined under 34 C.F.R. § 99.31(a)(1). INCLUXA uses education records only to provide contracted accessibility services.
  • No Re-Disclosure. INCLUXA will not re-disclose education records to any third party except as explicitly authorized by the district agreement or required by law.
  • Breach Notification. We will notify the school within 24 hours of discovering any unauthorized access to or disclosure of education records.

12.4 IEP Document Processing & AI Safeguards

Critical disclosure: IEP documents are processed using Claude AI (Anthropic, PBC, United States) to extract accessibility accommodation types. Automated redaction is applied before any content leaves our systems.

When a school uploads an IEP document, the following sequence is enforced:

  1. PII Redaction. Before any content is transmitted externally, an automated redaction engine replaces student names, dates of birth, parent/guardian names, contact information, Social Security Numbers, and other direct identifiers with anonymized placeholders (e.g., [STUDENT], [DATE], [GUARDIAN]).
  2. AI Extraction. Only the redacted text is transmitted to Anthropic's Claude API. Redaction is automated and may not catch every identifier, so schools should upload only the IEP content needed for accommodation mapping.
  3. File Deletion. The IEP file itself is deleted after parsing.
  4. Accommodation Storage. We store an opaque student ID, accommodation types, a short description and a supporting quote from the redacted IEP (encrypted at rest), plus the uploaded file name.

INCLUXA maintains a Data Processing Agreement with Anthropic, PBC governing AI processing. Anthropic processes only the redacted content described above and does not retain it for model training without explicit consent.

12.5 What Student Data We Collect

We do not ask for: student names, dates of birth, Social Security Numbers, medical diagnoses, grades, disciplinary records, or any data beyond what is strictly necessary for accessibility service delivery. Uploaded file names are stored as provided, so schools should not put student names in IEP file names.

12.6 Parent, Guardian & Student Rights

Parents of students under 18, and eligible students (18+), may exercise the following rights through their school administrator:

  • Review accessibility profiles and accommodation records on file
  • Request correction of inaccurate data
  • Request deletion of all data associated with a specific student
  • Receive a copy of student data in a machine-readable format (data portability)

Schools submit requests on behalf of parents or students by emailing privacy@incluxa.com with the subject line "Student Data Request — [School Name]". We respond and act within 30 days. Deletion requests are confirmed in writing.

13. Changes to This Policy

We will provide at least 30 days' notice of material changes via email and a notice on our website. Continued use after the effective date constitutes acceptance.

14. Contact Us

For privacy questions, data subject requests, or to execute a DPA:

Email: privacy@incluxa.com
Postal address: Angstroma, Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, United States (Delaware registered agent address — accepts executed DPAs and legal service of process).