GDPR Support Overview
How GradeLogic™ supports compliance with the EU General Data Protection Regulation (GDPR) and similar laws (e.g. UK GDPR).
Roles
For account and billing data, GradeLogic™ is the data controller. For student assessment data processed on your instruction, the institution or instructor is the controller and GradeLogic™ acts as a processor under a Data Processing Agreement. Because GradeLogic™ is local-first, most student data is never transmitted to us at all.
Lawful basis
We process account data to perform our contract with you and to meet legal obligations (e.g. billing records). Student assessment data is processed only on the controller's documented instructions.
Data subject rights
You may exercise the following rights, subject to applicable law:
- Access
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Objection
- Withdrawal of consent, where processing is based on consent
- Complaint to the competent supervisory authority
Two of these you can exercise yourself. Access and portability: Settings › Your data produces a machine-readable download of everything we hold, from both our servers and your browser. Erasure: Settings › Danger Zone cancels the subscription, ends every session, and erases the account identity — name, email address, profile picture and the identifier your Google sign-in used. Exam data in your browser is not touched by that action; clear it separately from the same page before you close the account. To exercise any other right, email privacy@gradelogic.ai. We answer within one month (Art. 12(3) GDPR).
Erasure is subject to the limited exceptions in applicable law (Art. 17(3)(b) GDPR). We retain the accounting ledger for ten years (§ 147 Abs. 1 AO, § 257 Abs. 1 HGB) and payment records for eight (§ 14b UStG, § 147 Abs. 3 AO), and we keep the evidence of how a contract was concluded, and of the redaction review before an upload, for the four years in which an ordinary civil claim can still be brought (§§ 195, 199 BGB). Those records are kept without the personal details they do not need, are excluded from ordinary use (Art. 18 GDPR, § 35 BDSG), and are deleted when their period ends. We do not treat every credit-ledger, usage, or attestation row as automatically subject to a financial-record retention duty: each category is classified individually, and the classification is published in the Privacy Policy's retention table.
International transfers
Where assessment content may be processed is an account setting (Settings › AI Configuration), and the default for every account is the strict combination: EEA-restricted, no provider retention. An account may widen it only where we can positively place it outside the EEA. An account contracted or billed in an EEA country, an account whose country we cannot establish at all, and an account we have placed on a managed configuration are each held to the setting we determine. Note also that the restriction governs the model provider: every request still passes through our US-based AI gateway, so no option prevents the transfer itself. Each option is served by a separate processing credential whose limits are configured with our AI gateway, and that credential fails closed: if it is unavailable the request errors rather than falling back to one with weaker limits. Every provider we use is named on our Subprocessor List. Transport is encrypted in transit.
Subprocessors
Our current subprocessors are listed on the Subprocessor List.
Contact
Data protection enquiries: privacy@gradelogic.ai.