Our Top Courses

DigiAssess Privacy Policy

Introduction

DigiAssess respects your privacy. This policy explains how we collect, use, and safeguard your personal information in compliance with GDPR, SOC 2, and ISO standards.

Data We Collect

  • Personal data (name, email, phone) when requesting demos or support
  • Assessment data (exam responses, proctoring data, feedback)
  • Technical data (browser, device, IP address) for security and performance

How We Use Data

  • To provide and improve DigiAssess services
  • To ensure assessment integrity and compliance
  • For communication regarding product updates and support

Data Sharing

  • DigiAssess does not sell personal data
  • Data is shared only with trusted service providers under strict confidentiality agreements
  • Cross-border transfers comply with GDPR and relevant laws

Data Security

  • SOC 2, ISO-certified infrastructure
  • End-to-end encryption of data in transit and at rest
  • Role-based access control

User Rights

  • Right to access, correct, or delete personal data
  • Right to opt-out of communications
  • Right to file a complaint under GDPR

DigiAssess, a product of DigiVal IT Solutions, is committed to protecting the privacy, security, and integrity of all data processed through its platform. As a digital assessment management system built for higher education institutions, DigiAssess handles sensitive academic, personal, and assessment-related data. This Privacy Policy outlines how such data is collected, processed, stored, and protected across the platform.

1. Data Roles and Responsibilities

DigiAssess operates as a data processor, while the educational institution using the platform acts as the data controller. This means that institutions retain full ownership and control over their data, including how it is used, stored, and retained. DigiAssess processes data strictly based on institutional instructions and does not independently use or monetize institutional data. This structure ensures that academic data governance remains fully aligned with institutional policies and regulatory requirements. DigiAssess shall not be considered a data controller under any circumstances unless expressly agreed in writing.

2. Information We Collect

To enable secure and outcome-driven assessments, DigiAssess processes various types of data. This includes institutional data such as academic structures, programs, and assessment configurations; user data, including student, faculty, and administrator profiles; and assessment data such as exam responses, scores, and evaluation outputs. The platform also processes learning outcome data, including Course Learning Outcomes (CLO) and Program Learning Outcomes (PLO), enabling institutions to measure academic performance and identify learning gaps through structured analytics.

3. Purpose of Data Processing

All data processed within DigiAssess is used strictly for academic and operational purposes. This includes conducting secure assessments, verifying user identity, preventing impersonation, enabling AI-based proctoring, and generating performance analytics and reports. The platform is designed to simplify complex academic workflows and provide actionable insights that support continuous improvement and outcome-based education.

4. Biometric and Proctoring Data

To maintain exam integrity, DigiAssess may process biometric and proctoring-related data where enabled by the institution. This includes facial recognition data, image captures, video recordings, and behavioral indicators collected during exam sessions. Such data is treated as sensitive personal data and is used solely for identity verification, monitoring exam conditions, and preventing malpractice. Access to this data is strictly controlled, and it is stored securely in accordance with institutional policies.

5. Data Security Measures

DigiAssess implements enterprise-grade security controls to protect all data processed within the platform. These include encryption of data in transit and at rest, role-based access controls, multi-factor authentication, secure audit logs, and continuous monitoring. These measures ensure that data remains protected against unauthorized access, loss, or misuse while maintaining transparency and accountability across all system activities.

6. Data Hosting and Transfers

DigiAssess is hosted on a multi-region cloud infrastructure, such as AWS, which allows data to be stored and processed across multiple geographic locations. Appropriate safeguards are implemented to ensure secure cross-border data transfers, and the platform aligns with applicable data protection requirements in its primary operating regions, including the Middle East. DigiAssess shall not be liable for any cross-border data transfer restrictions imposed by local laws applicable to the institution.

7. Data Sharing and Disclosure

DigiAssess does not sell or commercially exploit user data. Data is shared only in controlled scenarios, such as with authorized institutional users, integrated systems like ERP, SIS, or LMS platforms, or trusted infrastructure providers required for service delivery. All data sharing is governed by strict access controls, security protocols, and institutional policies.

8. Data Retention

Data retention within DigiAssess is determined by the institution. Institutions can define how long data is stored based on academic, regulatory, or accreditation requirements. Data may be securely archived for reporting purposes and can be permanently deleted upon request or policy expiry.

9. User Rights and Institutional Control

Users may have rights to access, correct, or request deletion of their personal data, depending on applicable laws and institutional policies. Since institutions act as data controllers, such requests are typically managed directly by the institution. DigiAssess supports institutions in fulfilling these obligations by providing appropriate data access and control mechanisms. DigiAssess shall not be directly responsible for responding to individual data subject requests unless contractually required. 

10. Third-Party Integrations

DigiAssess integrates with institutional systems such as Student Information Systems (SIS), ERP platforms, and Learning Management Systems (LMS) to ensure seamless academic operations. These integrations are secured through controlled APIs and follow institutional data governance frameworks.

11. Cookies and Tracking Technologies

DigiAssess uses cookies and similar technologies to maintain session integrity, improve system performance, and analyze usage patterns. Users can manage cookie preferences through their browser settings.

12. Compliance and Governance

DigiAssess is designed to support academic governance, outcome-based education models, and accreditation requirements. The platform maintains detailed audit trails and structured reporting mechanisms to help institutions meet compliance standards and demonstrate academic quality and accountability.

13. Updates to This Policy

This Privacy Policy may be updated periodically to reflect changes in regulations, platform capabilities, or security practices. The most recent version will always be available on the DigiAssess website.

14. Contact Information

For any questions or concerns regarding this Privacy Policy or data protection practices, please contact:

DigiAssess – DigiVal IT Solutions
Email: info@digiassess.com
Website: www.digiassess.com

©2026. All rights reserved by DigiAssess.

[academy_login_form]