Legal · Privacy
Privacy policy
Introduction
Quizava (“we”, “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our websites, applications, and services (the “Services”). By using the Services, you agree to this Privacy Policy alongside our Terms and Conditions.
Who this applies to
This policy applies to visitors, registered users, and organization administrators. If you participate in an assessment hosted on Quizava, your organization may also impose its own notices; combine those with this policy when both apply.
Information we collect
Account and profile data
Name, email, username, authentication identifiers, preferences, billing contact details when you subscribe, and similar account information you provide.
Usage and technical data
Log data such as IP address, approximate location, browser type, device identifiers, timestamps, referring URLs, and diagnostics used to operate and secure the Services.
Content you submit
Quizzes, questions, uploads, learner responses and scores, prompts or media you attach to assessments, communications with support, and similar content processed to deliver features you request.
Proctoring and integrity signals
Where enabled for an assessment, we may collect data described at collection time—for example webcam images or video snippets, keystroke timings, clipboard events, tabs or focus indicators, microphone activity, identity checks, device posture, network metadata, or related signals—solely as configured by the administering organization and communicated to participants.
Cookies
We use cookies and similar technologies for authentication, preferences, analytics, fraud prevention, and product improvement. Manage browser controls to limit cookies; some features require essential cookies.
How we use information
- Provide, operate, and improve the Services, including personalization and telemetry for reliability.
- Authenticate users, process payments (via payment processors), and manage subscriptions.
- Communicate about security, outages, contractual matters, billing, and—with your consent—product updates.
- Detect abuse, enforce our Terms, and comply with legal obligations.
- Train or evaluate internal models only where permitted by contract and using appropriate safeguards.
Legal bases (EEA / UK visitors)
Where GDPR applies, we rely on contractual necessity (to deliver the Services you request), legitimate interests (for example securing our platform), consent where required, and legal obligations. You may object to processing based on legitimate interests or withdraw consent where processing is consent-based.
Sharing and subprocessors
We share information with:
- Service providers who assist with hosting, email, analytics, security, billing, AI inference, transcription, communications, monitoring, backup, identity verification (where used), storage, CDN, incident response, anti-fraud, and similar functions under contracts that require confidentiality and appropriate protection.
- Organizations on whose workspace or assessments you enroll (for example quiz owners see responses and moderation data attributable to assessments they control).
- Authorities where required by law or to protect vital interests.
- Corporate transactions such as a merger or acquisition subject to safeguards.
We do not sell your personal information as commonly defined where “sell” requires consideration in exchange.
Retention
We retain information while your account or organization workspace is active and for a commercially reasonable period afterward for backups, legal compliance, audits, disputes, enforcement, analytics in aggregate form, and genuine business needs documented in lifecycle rules.
Your rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information, or to lodge a complaint with a regulator.
Contact us to exercise applicable rights—we may verify your request consistent with applicable law.
Children
The Services are not directed at children under 13 (or applicable age thresholds). Administrators who involve minors bear responsibility under school or guardian consent regimes and applicable law (for example COPPA or FERPA where relevant).
International transfers
We operate globally and may process information where we maintain facilities or partners. Where required by law, such as EU SCCs or supplementary measures, contractual protections apply before transfers occur.
Security
We maintain administrative, technical, and organizational measures designed to protect information. No transmission or storage method is guaranteed secure; notify us promptly of suspected compromises.
Changes to this policy
We update this Privacy Policy when our practices evolve. Revised versions are posted here with an updated effective date. Material changes affecting rights may require additional disclosure or consent where law demands.
Contact
Privacy inquiries: [email protected].