Working draft — requires legal review before publication This document is grounded in what the platform actually does, but it is not legal advice. It must be reviewed by counsel specialising in data protection in the Kingdom, and the bracketed fields must be completed before publication.

Who controls the data?

The distinction is not a formality: it determines who an access or deletion request should be addressed to.

Role

Platform data: the institution is the controller

When a university or institute subscribes to EvaliX, the institution remains the controller of its students' and staff data, and we act as a processor on its behalf and under its instructions. It decides what is collected, which proctoring layers are enabled, and the retention period within the ceilings we provide.

Role

This website: we are the controller

Data you send through the demo request form or the newsletter signup is controlled by us, and used only to reply to you and arrange the session.

What is collected

Nothing outside this table is collected. What the institution does not enable is not collected at all.

CategoryWhat it includes Retention
Account dataName, institutional email, role, and academic identifier where applicable.For the duration of the subscription, then per institutional policy
Assessment responsesAnswers, scores, response times and navigation history within the assessment.Academic record — set by the institution
Proctoring materialTimestamped snapshots, short clips at flagged events, device fingerprint and network address. Collected only when the institution enables the proctoring layer on a specific assessment.A configurable ceiling ending in automatic deletion
Biometric dataThe facial matching template derived from the reference image, when the facial verification path is used.Deleted with proctoring material when the ceiling expires
Usage dataSign-in logs, content operations, and the audit trail for every change to a grade or approved item.Required for academic integrity and not deleted early

Biometric data: four controls

This is the most sensitive category in the platform and we treat it accordingly. It is not collected by default, it always has an alternative, and access to it is logged.

Collected only on explicit activation

The facial proctoring layer is disabled by default. Enabling it is a decision the institution makes per assessment, not a global setting that applies to everything.

A documented alternative path

For a candidate to whom facial verification does not apply, or who does not consent to it, the platform provides alternative paths: supervised in-person verification, or reuse of a documented prior verification. The path used is recorded against the attempt.

Disclosed to the candidate in advance

Before the session starts, the candidate is shown exactly what is recorded, for how long, and who can view it.

An access log

Every view of a candidate's proctoring material is logged with viewer and timestamp, and is exportable on request.

Where the data is stored

Your rights

If you are a student or member of an institution using EvaliX, your request goes to your institution as the controller, and we support it in fulfilling the request. If it concerns data you sent through this website, address it to us directly.

Access

Knowing what is held about you and obtaining a copy.

Correction

Correcting inaccurate or incomplete data.

Deletion

Requesting deletion within the limits of academic record retention.

Objection

Objecting to a specific processing activity, including facial verification.

Security, cookies and changes

A privacy question, or a request about your data?

Write to evalix.ai@gmail.com and we reply within one business day. Subscribing institutions may request the data processing addendum and the full sub-processor list.