Privacy
What we hold, and who can see it
Your institution operates this platform and is the controller of your assessment data. This page describes what is collected, what it is used for, and the specific controls in place.
What is collected
- · Your identity and enrolment details, provided by your institution: name, roll number, email, department, programme, batch and expected graduation year.
- · Your responses to assessments, the time taken on each question, and whether each was correct.
- · Derived measures computed from those responses: concept mastery, competency scores, readiness and role readiness.
- · Where an assessment enables activity monitoring, in-browser events during that attempt: window focus changes, fullscreen exits, copy and paste. No camera or microphone access is requested, and no recording of your screen is made.
- · Your interactions with the coach and the plans generated for you.
What it is used for
- · Producing your own results, profile and preparation plan.
- · Letting staff at your institution with a legitimate role see cohort-level readiness and identify where support is needed.
- · Improving the assessment instrument itself: item statistics are computed across responses to find questions that are not measuring well.
It is not used to train models. Your responses and your profile are not sent to a model provider for training, and generated text is produced from a summary of your computed figures rather than from your raw responses.
Who can see your data
- · You can see everything the platform holds about you, including the evidence behind each score.
- · Staff see only the students their role covers. A head of department sees their department; a placement officer sees the institution. This is enforced in the data layer rather than by hiding parts of a page.
- · Recruiters see nothing unless you have explicitly consented to share your profile, and that consent is recorded and revocable.
- · Other students never see your results. There is no public leaderboard in the default configuration.
Consent
Consent is recorded separately for each purpose: processing your assessment data, personalising AI features, biometric proctoring where an institution enables it, sharing your profile with recruiters, and anonymised cross-institution benchmarking. Each can be granted or withdrawn independently, and withdrawal takes effect immediately for future processing.
Cross-institution benchmarking
Where an institution opts in, aggregate statistics may be contributed to anonymised benchmarks. Individual records are never shared. Aggregates are only published where at least 50 results exist in a cell, so no figure can be traced back to a person. Institutions that have not opted in contribute nothing, and this is off by default.
Retention
Assessment records are retained for the period your institution configures, with a default of five years — long enough to support a transcript request after graduation. Session records expire after seven days. Audit entries are retained for the full retention period, with contact details and credentials redacted rather than stored.
Automated decisions
No decision affecting you is made automatically. Readiness scores and predictive signals are shown to staff to direct support, never to filter opportunities. Integrity signals produce evidence for a human reviewer and nothing else — no attempt is invalidated and no score is altered without a person deciding.
If a figure about you looks wrong, you can see exactly how it was derived from the evidence ledger on your passport, and you can raise it with your placement office.
Security
- · Passwords are hashed with scrypt; they are never stored or logged in readable form.
- · Sessions are server-side records that can be revoked, not stateless tokens that must expire.
- · Every institution’s data is scoped at the data layer, not by filtering in the interface.
- · Staff actions on student data are written to an audit log with contact details redacted.
Your institution is the controller of this data. Requests to access, correct or delete it should go to your placement office or data protection contact, who can action them within the platform.