Privacy Policy
This policy explains how ClearGrade processes personal data for online assessments. It is designed to align with GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Applicable legal frameworks
ClearGrade is intended to support compliance with multiple legal regimes, including: the Zambia Data Protection Act, 2021, GDPR (where applicable), and relevant United States privacy rules and state laws where institutions operate in those jurisdictions.
For US-based institutions, this may include education and consumer privacy obligations such as FERPA and state-level privacy frameworks (for example CCPA/CPRA where applicable). Institutions are responsible for mapping platform use to their exact legal duties.
Who controls your data
Your lecturer and institution are the primary data controllers for course assessment records. ClearGrade acts as a service platform and processes data to deliver account, assessment, and proctoring features.
Lawful basis for processing
Data is processed to deliver educational assessment services, protect academic integrity, and maintain auditability of submissions. Depending on institution policy, this is usually based on public task, legitimate interests, or contractual necessity.
Automated checks and human review
Proctoring checks are used to raise incidents for review, not to automatically impose penalties. Incident evidence is reviewed by a human marker or invigilator.
Your rights
You may request access, correction, objection, restriction, or deletion according to your institution's legal obligations. Contact your lecturer or institution first, as they control course-level records.
Security and transfers
Passwords are hashed, session tokens are signed, and sensitive connection credentials are encrypted at rest. Email and hosting providers may process limited data in transit to deliver service functions.
Cookies and similar technologies
ClearGrade uses essential session cookies to keep users signed in and to secure course-scoped access. These cookies are necessary for the platform to function and are not used for advertising profiling. For details, see the Data Collection Policy.
Related policies
See Data Collection Policy and Data Retention Policy for detailed records and retention periods.
Contact for privacy requests
For access, correction, restriction, deletion, or objection requests, contact your lecturer first or the institution data-protection contact below:
- Email: [email protected]
- Office: Data Protection Officer / Registrar
Last updated: 23 August 2026
This policy is an operational template, not legal advice. Review and approve it with your institution's legal or compliance team before production use.