Introduction
Privacy at a glance
Ratelsoft uses personal information to provide and secure examina.io—not to sell it or build advertising profiles. An organization such as a school or employer usually controls examinee data, while Ratelsoft processes that data to deliver the Service. Features involving live video or facial identity checks require additional notice and controls.
Section 1
Scope and who is responsible
This Privacy Policy explains how Ratelsoft Inc. (“Ratelsoft,” “we,” “us,” or “our”) handles personal information through examina.io websites, applications, APIs, embedded exam clients, and related support and business interactions (the “Service”).
When Ratelsoft decides how information is used
Ratelsoft is responsible as a controller or organization for information used to operate our business, such as account registration, billing, website contacts, security, and service administration.
When a customer decides how information is used
Schools, employers, certifying bodies, and other customers decide what examinee information, exam content, scoring, and proctoring settings to use. For that information, the customer is normally the controller and Ratelsoft acts as its processor or service provider. The customer’s own privacy notice also applies.
If you are an examinee: contact the organization that invited you first if you want to access, correct, or delete assessment data. We will help that organization respond where required.
Section 2
Information we collect and where it comes from
We collect information directly from you, from the customer that provides your access, from enabled integrations, from payment and identity providers, and automatically when you use the Service.
- Account and organization information: name, email address, password hash, title, organization name, role, permissions, profile image, email-verification and password-reset records, and authorized domains.
- Sales, billing, and contact information: contact details, quote requirements, billing country and address, tax information, plan and currency choices, invoices, transaction status, provider references, and support messages. Payment providers—not Ratelsoft—collect full payment-card or bank credentials submitted on their hosted interfaces.
- Integration information: connected Google account email, approved OAuth scopes and credentials, Classroom or Drive data requested by an authorized user, and information exchanged with a customer-configured API, webhook, or other integration.
- Support and communications: the content of messages, issue details, attachments, and records of our response.
- Technical and usage information: IP address, device and browser characteristics, session identifiers, timestamps, referring page, country inferred from IP for localization, security events, connection state, feature usage, error and performance data, and audit events.
Section 3
Assessment and Customer-provided data
A customer may submit or create:
- examinee name, code, passcode, email, phone number, date of birth, gender, photograph, groups, and connected Google account;
- exam questions, answer choices, files, images, audio, instructions, schedules, accommodations, and access rules;
- responses, drafts and backups, scores, result reports, start and completion times, connection status, approvals, and activity history; and
- administrator and proctor notes, review decisions, communications, and audit records.
The customer determines which fields are appropriate for its assessment. Customers should avoid collecting information that is unnecessary for the stated purpose.
LMS integrations
Customer-directed learning management system exchange
When an authorized organization connects examina.io to a learning management system (“LMS”), the organization directs the exchange. Depending on the services it enables, we may receive course and context identifiers, resource-link and assessment-placement identifiers, user roles, and a platform-specific user identifier. If the organization enables Names and Roles Provisioning Services (NRPS), we may also receive the limited roster and role information needed for the requested course workflow.
When Assignment and Grade Services (AGS) is enabled, examina.io may return an assessment score, scoring scale, activity status, and related line-item reference to the LMS gradebook. We use LMS information to authenticate launches, connect the learner and assessment to the correct course placement, provide the hosted assessment, prevent replay or misuse, and perform the enabled roster or grade-return operation.
The school or other organization is responsible for choosing the LMS data and services it enables, providing notices to instructors and learners, and maintaining the authoritative gradebook and education records. Its privacy notice and LMS provider's terms also apply. Disconnecting an integration stops future exchanges after the disconnection takes effect; it does not remove information already transferred to the LMS or information the organization must retain. Learners should contact their institution about LMS records or grades.
AI authoring
Source-backed AI question authoring
When an authorized user uses AI authoring, we process the selected passages or uploaded source files, extracted and indexed text, embedded or directly uploaded images, image metadata and fingerprints, generation instructions and blueprint choices, generated candidates and visuals, accessibility descriptions, evidence references, validation results, and limited operational data such as token counts, status, errors, and billable-question units.
We use this information to retrieve relevant source sections and images, ask our configured AI provider to draft questions and—only when selected—create a new visual based on the same concept, validate the output, check for duplicates within the open paper, present candidates for human review, meter valid candidates, prevent abuse, and diagnose failures. Google Gemini currently provides the generative models. Cloud and storage providers may process source material as described under “How we disclose personal information.” We configure paid provider services for business use and do not authorize providers to use Customer Content to train general-purpose models.
Saved source resources, extracted images, and optimized representations remain in the organization’s private library until an authorized user deletes them or applicable plan, account, and retention rules require deletion. Temporary generation jobs and passage sources are normally removed within 24 hours, subject to backups, security records, and legal requirements. Generated candidates and visuals remain drafts unless a user chooses to insert them.
Do not supply material unless your organization has the right and lawful authority to process it. Authors should inspect source evidence and verify accuracy, appropriateness, and intellectual-property compliance before using a candidate.
Section 4
Live proctoring, recording, and identity verification
Live proctoring
When a customer enables live proctoring, the Service may transmit the examinee’s live camera and microphone feed, connection and session status, and proctor approvals to that customer’s authorized proctors. The live-proctoring feature does not currently record the audio or video stream.
Proctoring recording is currently unavailable for general use. If a recording feature is introduced or separately enabled, the organization must provide notice and the Service will identify that recording is active and state the applicable retention period before collection.
Facial identity verification
Biometric identity verification is optional and must be activated by the organization before it is enabled for an exam. It may process an enrolled reference photograph, liveness-session images or video, facial comparison results, confidence scores, provider session identifiers, and consent or review records. Ratelsoft does not use this information to identify people outside the relevant exam attempt, for advertising, or to train a general facial-recognition model.
Before biometric processing, the Service will present a separate notice identifying the purpose, provider, processing region, retention periods, and a non-biometric review alternative, and will ask for express consent where required. Withdrawing consent ends the biometric path for that active attempt and directs the examinee to the available alternative, subject to the organization’s assessment rules.
Identity results can be inaccurate. They are used to support an authorized organization’s review and should not be the sole basis for a high-impact decision without human review.
Section 5
Cookies and technical information
We use cookies and similar storage that are necessary to operate the Service. These are a secure session cookie for authentication, a security token used to protect form submissions, a preference cookie recording the language you selected, a preference cookie for the selected public-pricing currency, and a cookie recording your answer to the cookie notice itself. They keep you signed in, maintain security, remember choices you made, and route requests. We cannot remember a refusal without storing that refusal, which is why the last of these is necessary.
Google reCAPTCHA protects our public registration, contact, and quote-request forms from automated abuse. When you submit one of those forms, your browser contacts Google and Google sets cookies in it, and our server sends Google the reCAPTCHA token together with your IP address so that Google can return a score indicating whether the submission appears automated. We use that score to accept or reject the submission; we do not store the score or the token, and we do not use either for any other purpose. Google’s handling of that information is governed by Google’s Privacy Policy and Terms of Service. We treat this as strictly necessary because these forms are open to anyone on the internet and the check is what makes them safe to offer; it runs on those forms and nowhere else.
We do not currently use analytics, cross-site advertising cookies, or any similar measurement technology. We do not sell personal information or use it for targeted advertising. Our cookie notice offers categories for analytics and advertising so that a choice already exists if we ever adopt either; today both are empty, and nothing in either category is loaded whatever you choose.
Where a cookie is not necessary, we ask before setting it, and nothing optional is set until you answer. You can change or withdraw your answer at any time using the Cookie choices link in the footer of any page, and refusing is as easy as accepting. You can also control cookies through your browser. Blocking necessary cookies may prevent login, assessment access, or other core functions.
Section 6
How we use personal information
We use personal information to:
- create and administer accounts, organizations, exams, examinees, results, and reports;
- authenticate users, maintain sessions, manage permissions, and prevent fraud or abuse;
- deliver live proctoring, enabled integrations, optional identity workflows, and customer-configured communications;
- process orders, payments, subscriptions, prepaid balances, refunds, taxes, and billing support;
- send service, activation, security, exam, billing, and support messages;
- provide support, diagnose errors, monitor reliability and capacity, and improve usability;
- enforce agreements, protect people and the Service, investigate incidents, and establish or defend legal claims; and
- comply with law and respond to valid legal process.
We may create aggregated or de-identified statistics that do not reasonably identify a person and use them to operate, understand, and improve the Service.
Section 7
Legal bases for processing
Where a law requires us to identify a legal basis, we rely on one or more of:
- contract: processing needed to provide the Service or take steps requested before a contract;
- legitimate interests: securing, supporting, and improving the Service; communicating with customers; preventing abuse; and protecting legal rights, balanced against individual rights;
- consent: where requested for a specific optional use, including sensitive processing where required;
- legal obligation: recordkeeping, tax, compliance, safety, and valid legal requests; and
- instructions from a customer: when we process examinee or assessment information as that customer’s processor.
Where Canadian law applies, we obtain meaningful consent or rely on another basis permitted by law. You may withdraw consent for future processing, but this does not affect earlier lawful processing and may prevent an optional feature from working.
Section 8
How we disclose personal information
We disclose information only as needed for the purposes described above:
- Customers and authorized users: administrators, examiners, proctors, and other people authorized by the organization can access information according to their roles.
- Service providers: cloud hosting and storage, databases, email delivery, monitoring and error diagnostics, security, customer support, and infrastructure providers process information for us under contractual restrictions.
- Named feature providers: Google supports reCAPTCHA, which receives your IP address when you submit a public form, and user-enabled Workspace integrations; Stripe and Paystack may process payments; and Amazon Web Services may provide storage, content delivery, or separately enabled identity-verification infrastructure. A feature is shared only when configured or used.
- Customer-directed integrations: we send information to an API, webhook, Google service, or other system when an authorized customer enables and directs that connection.
- Legal and safety recipients: we may disclose information when reasonably necessary to comply with law or valid process, protect rights and safety, investigate abuse, or respond to an emergency.
- Business transactions: information may transfer as part of a proposed or completed financing, merger, reorganization, or sale, subject to appropriate confidentiality and continued protection.
We do not sell or rent personal information. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Section 9
International processing
Ratelsoft is based in Canada and serves customers in multiple countries, including Nigeria. We and our providers may process information in Canada, Nigeria, the United States, or other countries where we or they operate. Those countries may have privacy laws different from the place where the information originated, and lawful authorities there may have access rights.
We use contractual, organizational, and technical measures appropriate to the transfer and applicable law. Where required, these may include data-processing agreements and approved contractual safeguards. Optional biometric processing remains disabled unless its processing region and cross-border requirements have been specifically approved and disclosed.
Section 10
How long we keep information
We keep personal information only as long as reasonably necessary for the purposes described in this Policy, a customer’s documented instructions, our agreements, and legal, security, backup, audit, and dispute-resolution requirements.
Assessment and account data
- On the Starter plan, exams and examinees inactive for one month are scheduled for deletion.
- On active paid monthly plans, assessment data remains while the subscription is active; after the subscription becomes inactive, it is scheduled for deletion after two months.
- On the Flexible plan, exams and examinees inactive for more than two months are scheduled for deletion.
Plan materials or an enterprise order may specify different periods. We may send reminders before scheduled plan-based deletion. Customers can also delete records through available controls or request account closure. Limited transaction, consent, audit, security, and legal records may remain when required for compliance or to establish or defend claims. Backups are overwritten on a controlled cycle.
Identity and proctoring data
Live proctoring is not currently recorded. If biometric identity verification is separately activated, the just-in-time consent notice controls: the current default policy schedules successful verification and related consent records for deletion after 30 days and failed, incomplete, or review-required records after 90 days. An enrolled reference image remains until it is replaced or the examinee is deleted, unless an earlier valid deletion request applies. Provider evidence may expire sooner.
When information is deleted or de-identified, we take reasonable steps to remove it from active systems; residual copies may remain temporarily in protected backups or where retention is legally required.
Section 11
How we protect information
We use administrative, technical, and physical safeguards designed for the nature and sensitivity of the information. These include encryption in transit, access controls, role-based permissions, password hashing, private storage controls for sensitive images, encrypted biometric storage where configured, audit records, monitoring, recovery controls, and deletion procedures.
No internet service is completely secure. Customers and users must protect credentials, limit permissions, maintain secure devices, and promptly report suspected compromise. If a breach creates a real risk of significant harm or otherwise triggers notice duties, we will investigate and notify affected customers, individuals, and regulators as required by law.
Section 12
Your privacy choices and rights
Depending on where you live and the context, you may have rights to:
- know whether and how your personal information is processed;
- access or receive a copy of it;
- correct inaccurate or incomplete information;
- delete information or restrict or object to processing;
- withdraw consent for future processing;
- receive certain information in a portable format;
- request human review of a qualifying automated decision; and
- complain to a privacy or data-protection regulator.
Account users can update some information in the Service. For other requests, contact us using Section 16. We may verify your identity, ask you to clarify the request, route an examinee request to the responsible customer, or retain information where an exception applies. You will not be discriminated against for exercising a privacy right.
Section 13
Children, students, and parental authorization
examina.io is sold to organizations and is not directed to children for independent account creation. Children and students may take an assessment assigned by a school or other authorized organization. That organization is responsible for choosing appropriate information, giving age-appropriate notices, and obtaining consent from a parent or guardian when the individual cannot provide meaningful consent or when law requires it.
If you believe a child’s information was submitted without proper authority, contact the responsible organization or Ratelsoft. We will work with the organization to investigate and delete or restrict the information when appropriate.
Section 14
Service and commercial communications
We send messages needed to operate the Service, such as email verification, password reset, exam invitations, security alerts, billing notices, retention reminders, and support replies. You cannot opt out of essential messages while the relevant account or assessment remains active.
If we send optional marketing, you can unsubscribe using the message link or by contacting us. An unsubscribe may not stop communications sent independently by a customer that controls the recipient list.
Section 15
Changes to this Policy
We may update this Policy to reflect changes in the Service, law, or our practices. We will post the revised date here and provide additional notice before a material change takes effect when required. If a change introduces a materially different use of sensitive information, we will seek new consent where required.
Section 16
Contact the Privacy Officer or make a complaint
Send questions, rights requests, or complaints to our Privacy Officer. Please do not email passwords, passcodes, facial images, or other unnecessary sensitive information.
We will acknowledge and investigate complaints and explain our decision. You may also contact the privacy regulator where you live, including the Office of the Privacy Commissioner of Canada or the Nigeria Data Protection Commission, as applicable.