PRIVACY POLICY Effective Date: December 1st, 2025 This Privacy Policy explains how Maximilian Kuechen ("Maximilian," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with our online exam and assessment platform, related websites, applications, and services (collectively, the "Service"). By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, you must not use the Service. SCOPE AND ROLE 1.1 Scope This Privacy Policy applies to personal information we collect from: (a) students, test-takers, and other end users; (b) instructors, proctors, administrators, and institutional clients; and (c) visitors to any website or application we operate for the Service. 1.2 Role of Institutions In many cases, we process personal information on behalf of educational institutions or other organizations that use the Service ("Institutions"). In those situations, the Institution is typically the "controller" of your personal information, and we act as their "processor" or "service provider." To the maximum extent permitted by law, we are not responsible for the privacy practices, decisions, or policies of any Institution or third party, nor for any academic, employment, or disciplinary decisions made using data from the Service. INFORMATION WE COLLECT We may collect the following categories of information: 2.1 Account and Profile Information • Name, email address, username, institutional ID, course or section, and role (e.g., student, instructor). • Authentication details (e.g., institutional login or single sign-on identifiers). 2.2 Exam and Course Information • Exam registrations, exam IDs, exam configurations, and schedules. • Exam responses, code submissions, uploads, and other content you create or submit. • Grading data, scores, feedback, and instructor comments. 2.3 Proctoring and Monitoring Data Depending on how the Institution configures the Service and subject to applicable law, we may collect: • Screen activity, including screen sharing, screenshots, or screen recordings. • Browser activity (e.g., tab switches, window focus changes, navigation events). • Device and technical information (e.g., IP address, device type, operating system, browser type and version, approximate location inferred from IP, performance logs). • Logs of actions taken during an exam (e.g., time started, time ended, question navigation, file uploads/downloads). • Other proctoring signals if enabled (for example, webcam or microphone streams, environmental audio, room scans), to the extent permitted by applicable law and institutional policy. 2.4 Usage and Technical Information • Log files, error logs, performance metrics, and diagnostic data. • Information about how you interact with the Service (e.g., pages viewed, clicks, feature usage). • Cookies and similar technologies to maintain sessions, remember preferences, and support security. 2.5 Communications • Messages and support requests you send to us (e.g., via email or support tools). • Communications with instructors or Institutions via the Service, where applicable. 2.6 Information from Institutions and Third Parties • Information received from Institutions (e.g., rosters, email addresses, course assignments, exam registrations). • Information from third-party integrations, such as learning management systems, identity providers, grading tools, or cloud providers, as authorized by the Institution. HOW WE USE INFORMATION We may use personal information for the following purposes: 3.1 Provide and Operate the Service • Creating and managing user accounts. • Scheduling, delivering, proctoring, and grading exams. • Providing coding environments or other exam tools. • Identifying and addressing suspicious or prohibited behavior during exams as configured by the Institution. 3.2 Secure and Maintain the Service • Monitoring for and preventing fraud, misuse, cheating, security incidents, and other prohibited conduct. • Debugging, troubleshooting, and resolving technical issues. • Maintaining system integrity, reliability, and performance. 3.3 Improve and Develop the Service • Analyzing aggregated or de-identified usage data to improve user experience, security controls, and performance. • Developing and testing new features and services. 3.4 Communicate with You • Sending service-related notices (e.g., exam reminders, changes to scheduled exams, important system updates). • Responding to your inquiries and support requests. 3.5 Legal, Compliance, and Protection • Complying with applicable laws, regulations, legal processes, and lawful requests. • Enforcing our agreements and protecting our rights, property, and safety, and those of our users and third parties. LEGAL BASES FOR PROCESSING (EEA/UK USERS) If you are located in the European Economic Area or the United Kingdom, our legal bases for processing your personal information may include: • Performance of a contract (e.g., providing the Service to you or your Institution). • Legitimate interests (e.g., securing the Service, preventing misuse, improving functionality), provided those interests are not overridden by your rights and interests. • Compliance with a legal obligation. • Consent, where required and obtained (either by us or your Institution). HOW WE SHARE INFORMATION We may share personal information as follows: 5.1 With Institutions and Instructors • Exam responses, monitoring and proctoring data, logs, and related information may be shared with the Institution, instructors, administrators, and authorized staff for grading, academic integrity investigations, and administrative decisions. • The Institution decides how such information is used, including whether to initiate disciplinary or academic actions. 5.2 Service Providers and Vendors • With third-party service providers that perform services on our behalf (such as hosting, storage, analytics, logging, and security). • These providers are contractually obligated to use personal information only as necessary to provide services to us and to protect it appropriately. 5.3 Legal Compliance and Protection • To courts, law enforcement, regulators, or other third parties when we believe disclosure is required by law or reasonably necessary to: – comply with legal obligations or lawful requests; – protect the rights, property, or safety of Maximilian, our users, or the public; – detect, prevent, or address fraud, security, or technical issues; – enforce our agreements and policies. 5.4 Business Transfers • In connection with any actual or proposed merger, acquisition, financing, sale of assets, reorganization, or similar transaction, personal information may be transferred to another entity as part of that transaction. We will take reasonable steps to require the recipient to honor this Privacy Policy or a successor policy. 5.5 Aggregated or De-Identified Data • We may share aggregated or de-identified information that does not identify you personally for research, analytics, or other business purposes. DATA RETENTION We retain personal information for as long as reasonably necessary to: • provide the Service; • fulfill the purposes described in this Privacy Policy; • comply with legal and contractual obligations; and • resolve disputes and enforce our agreements. Retention periods may be influenced by the Institution’s requirements. Institutions may instruct us to retain or delete exam data according to their policies. To the maximum extent permitted by law, we are not responsible for an Institution’s decisions regarding how long it retains information exported or received from the Service. DATA SECURITY We use reasonable administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized access, or disclosure. However, no method of transmission or storage is completely secure. To the maximum extent permitted by law, we do not guarantee and are not liable for absolute security of your information or any unauthorized access, disclosure, or loss that is beyond our reasonable control. YOUR RIGHTS AND CHOICES Depending on your location and applicable law, you may have certain rights with respect to your personal information, which can include: • The right to access the personal information we hold about you; • The right to correct inaccurate information; • The right to request deletion of your information; • The right to object to or restrict certain processing; • The right to data portability; • The right to withdraw consent where processing is based on consent. In many cases, because we process data on behalf of your Institution, you should first contact your Institution to exercise these rights. Where required by law or our contracts, we will reasonably assist the Institution in responding to such requests. You may also contact us directly using the information in Section 11. We will respond as required by applicable law and may refer you to your Institution where appropriate. CHILDREN’S PRIVACY The Service is intended for use by Institutions and their students, which may include minors, under the direction and responsibility of the Institution. We do not knowingly collect personal information directly from children under the age at which parental consent is required by applicable law without appropriate authorization from the Institution or a parent/guardian. If you believe we have collected personal information directly from a child in violation of applicable law, please contact us, and we will take appropriate steps to address the issue. INTERNATIONAL DATA TRANSFERS We may store and process personal information in the United States and other countries that may have different data protection laws than your country of residence. Where required by law, we will implement appropriate safeguards (such as standard contractual clauses) to protect personal information in connection with international transfers. CONTACT INFORMATION If you have questions or concerns about this Privacy Policy or our privacy practices, please contact: Maximilian Kuechen Email: [INSERT CONTACT EMAIL] Address: [INSERT POSTAL ADDRESS] CHANGES TO THIS PRIVACY POLICY We may update this Privacy Policy from time to time. If we make material changes, we may provide notice (for example, by updating the "Effective Date" and, where appropriate, by additional notice through the Service). Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the updated policy. If you do not agree with the updated policy, you must stop using the Service.