Effective date: August 7, 2026
This Regional data protection policy ("Policy") supplements our Terms of service and Privacy notice, providing additional protections and rights for individuals in specific jurisdictions. ProctorEdu, Inc. dba OctoProctor ("we," "us," or "our"), is committed to complying with all applicable data protection laws based on your location.
1. Scope and application
This Policy applies when we process personal data of individuals located in jurisdictions with specific data protection requirements, including but not limited to:
- European Union (EU GDPR)
- United Kingdom (UK GDPR)
- Switzerland (Swiss FADP)
- Brazil (LGPD)
- United States state privacy laws (California CCPA/CPRA, Virginia VCDPA, Colorado CPA, and others)
- Canada (PIPEDA and provincial laws)
- Australia and New Zealand
4. Data location and transfers
4.1 Primary data location
Personal data is hosted on Amazon Web Services (AWS) infrastructure. The hosting region depends on the Testing Institution's location at the time of onboarding:
- Testing Institutions in the European Economic Area, the United Kingdom, or Switzerland: data is hosted in the AWS Ireland region (eu-west-1) and remains within the EEA.
- Testing Institutions in the United States: data is hosted in AWS United States (us-west-1) infrastructure.
- Testing Institutions in any other country: data is hosted in AWS infrastructure in a region selected by OctoProctor on a case-by-case basis at onboarding, taking into account operational factors including proximity to the Testing Institution's primary user base, infrastructure availability, regional data-protection considerations, and load-balancing across AWS regions and availability zones. Testing Institutions in this category can confirm their current hosting region on request.
- Enhanced data residency: A Testing Institution may select a specific data-residency configuration as part of its plan or order form, so that its data is hosted in a designated region rather than the default region for its location. Where selected, our technical and network controls are configured to keep that data within the designated region, subject to the support-access and international-transfer provisions in Section 4.2.
4.2 International data transfers
International data transfers may arise in two situations:
- where a Testing Institution's data is hosted in AWS infrastructure outside the EEA — whether because the Testing Institution is located in a non-EEA jurisdiction whose default hosting region is outside the EEA (such as the United States), or because an onboarding-time placement decision allocated a Testing Institution's data to a non-EEA AWS region — and personal data of EEA, UK, or Swiss data subjects collected through the Services is accordingly transferred to that jurisdiction; and
- where OctoProctor support, engineering, or security personnel located outside the Testing Institution's designated region access personal data in connection with providing, maintaining, or securing the Services.
For each such transfer:
- For transfers to the United States, where our infrastructure provider is certified under the EU-US Data Privacy Framework (and its UK Extension and the Swiss-US Data Privacy Framework), we rely on that Framework; where it is not available, we rely on the mechanisms below.
- We use Standard Contractual Clauses (SCCs) approved by the European Commission
- For UK transfers, we implement the UK International Data Transfer Agreement (IDTA)
- For Swiss transfers, we apply the Swiss Federal Data Protection and Information Commissioner-approved mechanisms
- We conduct Transfer Impact Assessments where required
- We apply technical and organizational safeguards proportionate to the transfer risk, including access controls, encryption in transit and at rest, and logging of cross-region support-access events
- On-premise deployments: Where the Services are deployed on the Testing Institution's own infrastructure (on-premise), the Testing Institution hosts and controls the personal data within its own environment. In that case the AWS hosting, regional-placement, and retention arrangements described in Sections 4.1, 4.2, and 5 do not apply to that data, and the Testing Institution is responsible for its storage location, retention, and deletion.
5. Data retention
5.1 Standard retention period
Client service retention: We keep your personal data no longer than necessary for the proctoring purpose. The exact retention period is set by your Testing Institution through the plan it selects and may be shorter or longer than the standard period. Under the standard plan, personal data is retained for your Testing Institution's access for 6 months from the date of collection; some plans provide a shorter period (for example, 1 month), and longer retention is available as a paid option. In every case the period remains subject to the exceptions in Section 5.2
Service improvement retention: When you provide explicit consent for us to use your data for service improvement purposes:
- Your Testing Institution continues to have access for the retention period set out above
- We may retain an anonymized copy of your data indefinitely for research, analytics, and service improvement
- This anonymized data cannot be linked back to you as an individual
5.2 Retention exceptions
- Legal requirements: Data may be retained longer if required by law
- Active disputes: Data related to disputes or investigations may be retained until resolution
- Agreed variations: Where the License agreement, invoice, or order form specifies a different retention period, that period applies
7. Children's data protection
7.1 Age restrictions
- Direct services: Not intended for individuals under 18 years of age
- Ages 13-17 (through Testing Institutions): May use the Services only through Testing Institutions that have assumed responsibility for obtaining parental consent or authorization where required by applicable law (including GDPR Article 8 and equivalent national legislation)
- Under 13 (through Testing Institutions): May use the Services only where the Testing Institution acts as the COPPA operator with verifiable parental consent. The school authorization exception (addressed in FTC COPPA FAQ Section M) is available only to educational institutions; see Terms of Service for details
7.2 Special protections
For individuals under 18:
- Testing Institutions must obtain verifiable guardian consent where required by applicable law, including under the Children's Online Privacy Protection Act ("COPPA") for individuals under 13 and Article 8 of the GDPR (or UK GDPR or Swiss FADP equivalent) in the EEA, UK, and Switzerland
- We implement age-appropriate privacy safeguards
- Enhanced data minimization principles apply, including a written data-retention policy under which personal information of individuals under 13 is retained only as long as reasonably necessary to fulfill the purpose for which it was collected (consistent with 16 CFR § 312.10, as amended in 2025)
- Disclosure of a child's personal information to a third party that is not reasonably necessary to provide the Services requires separate verifiable parental consent (consistent with 16 CFR § 312.5, as amended in 2025)
- We maintain a written information security program with reasonable administrative, technical, and physical safeguards for children's personal information (consistent with 16 CFR § 312.8, as amended in 2025)
- Marketing and profiling activities are prohibited for individuals under 18
- Where we become aware that a minor is using the Services without the consents required by applicable law (including COPPA for individuals under 13 and GDPR Article 8 for individuals below the applicable age of digital consent), we will promptly suspend the minor's access, notify the Testing Institution, and request evidence of the required consent. If adequate consent is not provided within 30 days of our request (or a shorter period where required by applicable law), we will delete the minor's personal data in accordance with applicable law. Further operational detail is set out in Section 7 of our Health and Safety Policy.
11. Exercising your rights
11.1 How to submit requests
- Email: legal@octoproctor.com
- Portal: Through your Testing Institution's administrator
- Mail: ProctorEdu Inc., 111 Pier Ave STE 100, Hermosa Beach, CA 90254, United States
11.2 Identity verification
We may request information to verify your identity before processing requests.
11.3 Response timeline
- Acknowledgment: Within 5 business days
- Response: Within 30 days (may be extended by 60 days for complex requests)
11.4 Fees
Rights requests are generally free, but we may charge a reasonable fee for excessive or repetitive requests.
12. Data protection contacts
12.1 Data protection officer
For data protection inquiries:
12.2 EU/UK/Swiss representative
Pursuant to Article 27 of the EU GDPR and the UK GDPR, and Article 14 of the Swiss FADP, we have appointed DataRep (Data Protection Representative Limited, trading as DataRep) as our data protection representative for the EEA, the UK, and Switzerland. Individuals and supervisory authorities may contact DataRep on our behalf:
13. Updates to this policy
We may update this Policy to reflect changes in law or our practices. We will notify you of material changes through:
- Email notification to Testing Institution administrators
- Prominent notice on our website
- In-app notifications where applicable
14. Relationship with other policies
This Policy supplements, and should be read together with, the other documents that govern your use of the OctoProctor service:
- Terms of Service - the master terms governing use of the service;
- Privacy Notice - how we collect, use, and disclose personal data, including cookies and similar technologies;
- any pilot, demo, or order-specific terms that apply to your engagement (for example, the Terms & Conditions for an OctoProctor Pilot or Demo)
Where this Policy refers to internal operational practices (for example, data retention and secure deletion), those are implemented through our internal information security and data-handling policies, summaries of which are available to Testing Institutions on request.
In case of conflict, the provision offering the greater protection to data subjects shall prevail.
15. Contact information
For questions about this Policy or your privacy rights:
- Email: legal@octoproctor.com
- Phone: +1 (310) 303-8236
- Mail: ProctorEdu Inc., 111 Pier Ave STE 100, Hermosa Beach, CA 90254, United States