Regional data protection policy

Effective date: August 7, 2026

This Regional data protection policy ("Policy") supplements our Terms of service and Privacy notice, providing additional protections and rights for individuals in specific jurisdictions. ProctorEdu, Inc. dba OctoProctor ("we," "us," or "our"), is committed to complying with all applicable data protection laws based on your location.

1. Scope and application

This Policy applies when we process personal data of individuals located in jurisdictions with specific data protection requirements, including but not limited to:

2. Our role in data processing

2.1 Data processing relationships

2.2 Lawful basis for processing

We process personal data based on:

3. Data we process

3.1 Categories of personal data

During proctoring sessions, we may process:

3.2 Special category data

Biometric data — including facial recognition data used for identity verification, and audio/video recordings to the extent they are processed for the purpose of uniquely identifying a natural person — is classified as special category data or sensitive personal data under a range of laws, including

Where any of these classifications applies, we implement additional technical and organizational safeguards proportionate to the risk, including: processing biometric data solely for identity verification; not using biometric data for service improvement, analytics, profiling, or algorithm training; and retaining biometric data only for the period necessary to fulfill the identity verification purpose or as required by applicable law.

The Testing Institution, as controller, is responsible for providing the required notices and obtaining the explicit or opt-in consent of data subjects (or, for minors, of parents or guardians) - or satisfying any alternative legal basis required by applicable law - before enabling identity verification features. Detail on the operational allocation of responsibilities is set out in Section 3 of our Health and Safety Policy.

6. Regional rights and protections

6.1 European Union, UK, and Switzerland

Individuals have the right to:

6.2 Brazil (LGPD)

Brazilian residents have similar rights to EU residents, plus:

6.3 United States state laws

Residents of California, Virginia, Colorado, and other states with privacy laws have the right to:

California specific:

6.4 Canada

Canadian residents have rights under PIPEDA and provincial laws to:

6.5 Australia and New Zealand

Residents have the right to:

We comply with the requirements of the Australian Privacy Act 1988 (including the Australian Privacy Principles) and the New Zealand Privacy Act 2020.

This includes:

Supervisory authorities:

We acknowledge the importance of complying with applicable privacy and information management obligations under Australian law and confirm that our internal policies and controls are consistent with these principles.

7. Children's data protection

7.1 Age restrictions

7.2 Special protections

For individuals under 18:

8. Security measures

We implement comprehensive security measures including:

9. Data breach notification

9.1 Notification timeline

9.2 Notification content

Breach notifications include:

10. Third-party sub-processors

10.1 Current sub-processors

10.2 Changes to sub-processors

11. Exercising your rights

11.1 How to submit requests

11.2 Identity verification

We may request information to verify your identity before processing requests.

11.3 Response timeline

11.4 Fees

Rights requests are generally free, but we may charge a reasonable fee for excessive or repetitive requests.

12. Data protection contacts

12.1 Data protection officer

For data protection inquiries:

12.2 EU/UK/Swiss representative

Pursuant to Article 27 of the EU GDPR and the UK GDPR, and Article 14 of the Swiss FADP, we have appointed DataRep (Data Protection Representative Limited, trading as DataRep) as our data protection representative for the EEA, the UK, and Switzerland. Individuals and supervisory authorities may contact DataRep on our behalf:

13. Updates to this policy

We may update this Policy to reflect changes in law or our practices. We will notify you of material changes through:

14. Relationship with other policies

This Policy supplements, and should be read together with, the other documents that govern your use of the OctoProctor service:

Where this Policy refers to internal operational practices (for example, data retention and secure deletion), those are implemented through our internal information security and data-handling policies, summaries of which are available to Testing Institutions on request.

In case of conflict, the provision offering the greater protection to data subjects shall prevail.

15. Contact information

For questions about this Policy or your privacy rights: