GDPR Support Overview
How GradeLogic™ supports compliance with the EU General Data Protection Regulation (GDPR) and similar laws (e.g. UK GDPR).
Roles
For account and billing data, GradeLogic™ is the data controller. For student assessment data processed on your instruction, the institution or instructor is the controller and GradeLogic™ acts as a processor under a Data Processing Agreement. Because GradeLogic™ is local-first, most student data is never transmitted to us at all.
Lawful basis
We process account data to perform our contract with you and to meet legal obligations (e.g. billing records). Student assessment data is processed only on the controller's documented instructions.
Data subject rights
You may exercise the following rights, subject to applicable law:
- Access
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Objection
You can export or delete your account data from within the app; deleting your account soft-deletes the billing record and clears your session. Locally-stored exam data is removed by clearing site data on your device. To make a request, email privacy@gradelogic.ai.
International transfers
Where data is processed outside your region, we rely on appropriate safeguards (such as Standard Contractual Clauses) provided by our subprocessors. Transport is encrypted in transit.
Subprocessors
Our current subprocessors are listed on the Subprocessor List.
Contact
Data protection enquiries: privacy@gradelogic.ai.