Is Keenious GDPR compliant? What universities should check
Keenious is a research discovery tool from Tromsø that recommends literature based on the text you are writing or the question you ask, with add-ins for Word and Google Docs. Many Nordic universities license it through their libraries. This page sets out what Keenious publicly documents about data protection and what a university should confirm.
Short answer
Keenious is run by Keenious AS in Tromsø, Norway, which is in the European Economic Area, so the GDPR applies to it directly. It says prompts, files and AI responses are hosted in the EU (Ireland, Belgium and Germany), that user inputs and outputs are not used to train its models or its providers' models, and that raw prompts and outputs are deleted after 24 hours by default. Its subprocessor list gives EU or EEA processing locations for every entry, and its trust centre lists ISO 27001. A DPA is part of the Institutional plan but is not published. For a university, the main checks are the DPA itself, how the AI provider (Google Gemini) is contracted, and how much document text the Word and Google Docs add-ins send.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI research assistance with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Keenious documents publicly
All sources were read on 7 October 2026. Keenious's trust centre was read in a browser; the subprocessor list is a PDF linked from the privacy policy. "Not found publicly" means we did not find it in the sources listed; it does not mean the safeguard does not exist.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Keenious AS, Sykehusvegen 23, 9019 Tromsø, Norway, is controller for individual users under its privacy policy (last updated January 2026). The terms of use (last updated September 2026) are governed by Norwegian law. Norway is one of the EEA EFTA states. Privacy contact: privacy@keenious.com. Not found publicly A named data protection officer. | [1], [2], [9] |
| Where data is stored and processed | Documented Keenious "processes and hosts prompts, messages, files, and AI responses within the European Union (specifically Ireland, Belgium, and Germany)". | [1] |
| Data processing agreement | Plan-dependent The pricing page lists a "Data Processing Agreement" as part of the Institutional plan. For institutional accounts, the privacy policy says Keenious "acts as a processor" and the organisation "is the controller". Not found publicly The DPA text, and a DPA for the Team plan. | [4], [1] |
| Subprocessors | Documented An "Approved Subprocessors" PDF lists Microsoft Azure, Amazon Web Services and Google Cloud Platform (Irish entities, data centre services) and PostHog (application performance monitoring, Frankfurt address), all with "European Union / European Economic Area" as processing location. The privacy policy names Google Gemini as an LLM provider. Not found publicly A notice period or objection right for new subprocessors. | [5], [1] |
| International transfers | Partly documented All listed subprocessors process data in the EU or EEA. The privacy policy does not describe transfers outside the EEA or name a transfer mechanism. | [5], [1] |
| AI model training on customer content | Documented "Keenious does not use user prompts, inputs, or outputs to train its models or the models of its providers." The terms of use repeat that user inputs and conversations are not used for training. | [1], [2] |
| Retention and deletion | Partly documented "The default retention period for raw prompts and outputs is 24 hours, after which it will be deleted." Other personal data is kept as long as needed for the stated purposes or as required by law, without fixed periods. The universities page says: "We do not store any content submitted by our users". | [1], [6] |
| Security certifications | Documented The trust centre (updated 21 August 2026) lists an ISO 27001 certificate dated December 2025, a HECVAT (version 4.1.1, September 2025) and a VPAT for WCAG 2.2 AA, all on request, and 70 security controls. The certificate's scope is not public. | [3] |
| Institution and enterprise controls | Plan-dependent Free and Plus for individuals are personal plans (Plus starts at $10 per month billed annually, with a 30% annual discount for students). The Team plan (from $20 per user per month billed annually) adds an admin console, centralised billing and two-factor authentication. The Institutional plan adds access for all students and staff, SSO with SAML, IP-based access, library integration and the DPA. The universities page mentions login with institutional email domains, Microsoft and Google. | [4], [6] |
What this means for a university
Validemic's analysis
A short, mostly EEA-only data path. Keenious is established in the EEA, hosts AI traffic in Ireland, Belgium and Germany, and lists only EU or EEA processing locations for its subprocessors [1], [5]. Together with a clear no-training statement and a 24-hour default for raw prompts and outputs, this is a strong starting point. Fewer transfer questions arise than with most AI research tools.
Check how Gemini is contracted. The privacy policy names Google Gemini as an LLM provider, while the subprocessor list names Google Cloud Platform with an EU location [1], [5]. Ask Keenious to confirm that Gemini is used through Google Cloud in the EU under its processor terms, with no retention by Google beyond what Keenious describes, and that no other model provider receives prompts.
The add-ins send document text. The Word and Google Docs add-ins work by analysing what the user is writing [1]. A thesis draft or grant application can contain personal data about research participants or colleagues. The 24-hour retention limits the exposure, but guidance for staff and students should still say what kind of text is suitable.
Reconcile the two retention statements. The privacy policy keeps raw prompts and outputs for 24 hours by default [1]; the universities page says Keenious does not store submitted content [6]. Both can be true if "store" means long-term storage, but the DPA should state the actual periods, including backups and logs.
Plan choice. Students or staff on Free or individual Plus plans use Keenious under its privacy policy, with Keenious as controller. A licence under the Institutional plan brings the DPA, SSO and central control [4]. If the library promotes Keenious, an institutional licence is the arrangement that fits the GDPR roles.
Credit where due. EU hosting, a public subprocessor list, a firm no-training commitment, a short default retention period, ISO 27001, a HECVAT and an accessibility report that Keenious says was externally audited [6] answer most of the first questions a DPO or librarian would ask.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Keenious before approving it
- Can we see the Institutional DPA, including the subprocessor change procedure and objection period?
- Through which service and region is Google Gemini called, and what retention applies at the model provider?
- What exactly do the Word and Google Docs add-ins send: the whole document, a section, or selected text?
- How does the 24-hour retention of raw prompts and outputs fit with the statement that content is not stored? What is kept in logs and backups, and for how long?
- What is the scope of the ISO 27001 certificate: does it cover the AI features and the add-ins?
- Can saved searches and account data be exported and deleted in bulk when a user leaves the university?
- Is there a named DPO or privacy lead we can list in our records of processing?
The EU AI Act angle
Literature discovery and explanation are not among the high-risk uses in Annex III of the AI Act, Regulation (EU) 2024/1689 [7]. Point 3 of that annex covers AI used to decide admission, evaluate learning outcomes, assess the level of education a person will receive, or monitor students during tests. A university using Keenious for research support is a deployer with transparency and AI literacy duties rather than high-risk obligations.
Article 4 on AI literacy has applied since 2 February 2025. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, turned it into a duty to take measures to support AI literacy and moved the Annex III high-risk rules to 2 December 2027 [8]. Keenious is established in Norway, an EEA EFTA state [9], where EU acts apply once incorporated into the EEA Agreement; for a university in an EU member state, the AI Act applies to its own use as deployer regardless.
Sources
- Keenious, Privacy Policy (last updated January 2026), retrieved 7 October 2026
- Keenious, Terms of Use (last updated September 2026), retrieved 7 October 2026
- Keenious Trust Center (updated 21 August 2026), retrieved 7 October 2026
- Keenious, Pricing, retrieved 7 October 2026
- Keenious, "Approved Subprocessors For Keenious" (PDF linked from the privacy policy), retrieved 7 October 2026
- Keenious, For universities, retrieved 7 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 4 and 113 and Annex III, Official Journal text read via the Publications Office, retrieved 7 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal text read via the Publications Office, retrieved 7 October 2026
- EFTA, The EEA Agreement, retrieved 7 October 2026
About this page
We read Keenious's privacy policy, terms of use, trust centre, approved subprocessor list, pricing page and universities page, and the EU legal texts, on 7 October 2026. We did not test the product or review the Institutional DPA, which is not public. This page is not legal advice and not a verdict on whether Keenious or any university's use of it complies with the GDPR; that depends on your plan, your contract and your use.
If you work at Keenious and something here is out of date or incomplete, please contact us and we will review it promptly.
Frequently asked questions
Where is Keenious data stored?
Keenious's privacy policy says it processes and hosts prompts, messages, files and AI responses within the European Union, specifically Ireland, Belgium and Germany. Its approved subprocessor list gives EU or EEA processing locations for Microsoft Azure, Amazon Web Services, Google Cloud Platform and PostHog (checked 7 October 2026).
Does Keenious use my documents to train AI?
Keenious says no. Its privacy policy states that it does not use user prompts, inputs or outputs to train its models or the models of its providers, and its terms of use say it does not use user inputs or conversations to train its models.
Does Keenious sign a DPA with universities?
Keenious's pricing page lists a Data Processing Agreement as part of the Institutional plan. The DPA itself is not published. Its privacy policy says that for institutional accounts Keenious acts as processor and the organisation is the controller.
How long does Keenious keep what I search for?
The privacy policy says the default retention period for raw prompts and outputs is 24 hours, after which they are deleted. Account data is kept as long as needed for the stated purposes or as required by law. Keenious's universities page also says it does not store content submitted by users, so ask how the two statements fit together.
Is Keenious ISO 27001 certified?
Keenious's trust centre lists an ISO 27001 certificate dated December 2025, available on request, together with a HECVAT and an accessibility conformance report. The certificate's scope is not public.