Regional data protection policy

Effective date: July 22, 2025

This Regional data protection policy ("Policy") supplements our Terms of service and Privacy notice, providing additional protections and rights for individuals in specific jurisdictions. ProctorEdu, Inc. dba OctoProctor ("we," "us," or "our"), is committed to complying with all applicable data protection laws based on your location.

1. Scope and application

This Policy applies when we process personal data of individuals located in jurisdictions with specific data protection requirements, including but not limited to:

2. Our role in data processing

2.1 Data processing relationships

2.2 Lawful basis for processing

We process personal data based on:

3. Data we process

3.1 Categories of personal data

During proctoring sessions, we may process:

3.2 Special category data

In jurisdictions where biometric data is considered a special category or sensitive personal data, we implement additional safeguards and obtain explicit consent where required.

6. Regional rights and protections

6.1 European Union, UK, and Switzerland

Individuals have the right to:

6.2 Brazil (LGPD)

Brazilian residents have similar rights to EU residents, plus:

6.3 United States state laws

Residents of California, Virginia, Colorado, and other states with privacy laws have the right to:

California specific:

6.4 Canada

Canadian residents have rights under PIPEDA and provincial laws to:

6.5 Australia and New Zealand

Residents have the right to:

7. Children's data protection

7.1 Age restrictions

7.2 Special protections

For individuals under 18:

8. Security measures

We implement comprehensive security measures including:

9. Data breach notification

9.1 Notification timeline

9.2 Notification content

Breach notifications include:

10. Third-party sub-processors

10.1 Current sub-processors

10.2 Changes to sub-processors

11. Exercising your rights

11.1 How to submit requests

11.2 Identity verification

We may request information to verify your identity before processing requests.

11.3 Response timeline

11.4 Fees

Rights requests are generally free, but we may charge a reasonable fee for excessive or repetitive requests.

12. Data protection contacts

12.1 Data protection officer

For data protection inquiries:

12.2 EU/UK representative

[To be appointed if required based on business operations]

13. Updates to this policy

We have collected the following categories of personal information in the past twelve (12) months:

14. Relationship with other policies

This Policy supplements and should be read in conjunction with:

15. Contact information

For questions about this Policy or your privacy rights: