0. Definitions
- Examiner: a person (teacher, trainer, member of an assessment centre, a training body or a professional certification body) who creates, configures, administers and/or marks Assessments; controller within the meaning of the GDPR.
- Participant: a person (student, learner, candidate) who sits an Assessment on the Platform.
- Assessment: any test, exam, multiple-choice questionnaire, exercise or certification available on the Platform.
- Imaging data: images and video from the webcam, where applicable the audio from the microphone, and the screenshots of the exam screen triggered by a technical event, used for remote proctoring purposes. Identity verification arrangements are dealt with in section 3 bis.
- Technical events: deterministic facts occurring on the Participant's device during the exam (leaving the exam window, opening another application, leaving full screen, a copy-and-paste event, the presence of a second screen, detection of a suspicious browser extension), time-stamped.
- Risk score: a value calculated from those technical events alone, intended to draw an examiner's attention. It constitutes neither a decision nor evidence.
1. Roles and responsibilities
Examiner = controller. The institution/organisation (or the individual Examiner) determines the purposes, the legal bases and the retention periods for exam data (submissions, answers, marks, metadata) and informs Participants.
Evalmee = processor, within the meaning of article 28 of the GDPR. We act solely on the Examiner's instructions, in accordance with the DPA, without determining purposes of our own or setting autonomous retention periods, except as expressly stated below for proctoring imaging data.
Evalmee never keeps or uses that data for any purpose other than providing the remote proctoring service.
For its own processing — the evalmee.com site, Examiners' accounts, billing, support and the security of the Platform — Evalmee is the controller. Section 12 is devoted to that processing and carries the information notices incumbent on Evalmee in that capacity.
Examiners use the platform either individually (direct contract) or within an organisation (Organisation plan, on a quote basis).
Evalmee enables no option on its own initiative, decides no setting in the Examiner's place, and makes no recommendation on monitoring arrangements: these are matters for the controller alone and for its data protection officer.
Examiners' privacy policies. Each Examiner, as controller, must provide its Participants with its own privacy policy, describing the processing it carries out through the Evalmee Platform (purposes, legal bases, retention periods, data subject rights).
It is for the Examiner, as controller, to inform Participants of the remote proctoring arrangements before the exam. To help it meet that information obligation, Evalmee provides a template privacy policy and a template privacy notice for candidates.
2. Legal bases
The legal basis for assessment and remote proctoring processing is determined by the Examiner, as controller. In practice, it is the public interest task (article 6.1.e of the GDPR) for a public institution, or the performance of the contract (article 6.1.b) for a private body, provided that the exam arrangements are settled and known to the Participant before registration.
The Participant's consent is not a valid basis for remote proctoring: what makes the arrangement enforceable is the prior information, not the acceptance. An exam cannot freely be refused, and an agreement that cannot be refused is not consent.
The bases below are recalled for descriptive purposes only; Evalmee chooses none of them.
- Contract: performance of the online assessment services between the Examiner and its Participants (e.g. account creation, sitting/marking).
- Legitimate interests: relied on by Evalmee only for the processing for which it is itself responsible (Examiners' accounts, billing, support, security of the Platform, technical communications), never for exam data or for remote proctoring data, which are not used for any purpose other than providing the service.
- Legal obligation: accounting and tax obligations, responses to legal requests, retention in the event of litigation.
- Public interest task: where a public Examiner expressly relies on it for its processing.
- Consent: only for the non-essential cookies on the marketing site.
Where proctoring (webcam, microphone) is enabled, it falls under the legal basis chosen and documented by the Examiner, who informs Participants of it beforehand. Evalmee acts solely as the technical executant.
3. Data processed (categories)
No automated decision-making. The technical events and the risk score are brought together in an integrity report accessible only to the Examiner's examiners. They are leads to be investigated, never standalone evidence: the score interrupts no exam and reports no one on its own. A human check always takes place before any decision or any change to a candidate's exam conditions: no decision producing legal effects is taken solely on the basis of automated processing (article 22 of the GDPR).
- Accounts & exams: the Participant's identity and identifiers, affiliations, answers, marks, exam metadata.
- Technical events on the device (according to the options enabled by the Examiner), time-stamped: leaving the exam window, opening another application, leaving full screen, a copy-and-paste event, the presence of a second screen, detection of a suspicious browser extension.
- Screenshots of the exam screen triggered only by one of those events: there is no continuous video stream of the screen.
- Risk score: a value calculated from those events alone. Evalmee carries out no automatic analysis of behaviour — no gaze direction, no emotions, no typing rhythm — and that analysis does not exist in the product in any form, not even as an option.
- Optional remote proctoring (enabled by the Examiner): imaging data from the webcam and audio data from the microphone, recorded during the exam. When these options are enabled, elements of the Participant's surroundings or people present with them may be captured incidentally; the Examiner informs Participants of this.
- Identity verification: photographs of the identity document and of the face — see section 3 bis.
- Support & service quality: ticket metadata, exchanges relating to support.
- Marketing site: cookies and trackers as described in section 13.
Enabling proctoring (webcam/microphone) is visible to the Participant and is the subject of prior information from the Examiner. Evalmee never enables these options on its own initiative.
3 bis. Verification of the Participant's identity
Standard, all plans — document-based check. Where the Examiner enables this option, the Participant photographs their identity document (national identity card, passport or student card) and their face before the exam. An examiner of the customer organisation visually compares the two images: this is a document-based check carried out by an invigilator, the first of the arrangements cited by the CNIL, France's data protection authority. No biometric template is computed or stored: these photographs do not constitute biometric data within the meaning of article 9 of the GDPR, and no specific consent therefore has to be obtained on that basis. Evalmee hosts these photographs on the Examiner's behalf, does not validate them and does not access them other than out of strict technical necessity.
Option, Organisation plan on a quote basis — automated verification. The Examiner may ask for an automated identity verification, operated by a specialist provider, to be enabled. This option processes biometric data within the meaning of article 9 of the GDPR. It is disabled by default, is available only on the Organisation plan and is enabled only at the Examiner's express request. The CNIL makes its use subject to cumulative conditions (§ 45) that the Examiner must verify under its own responsibility: a single verification at the start of the exam, a very large number of candidates, a human alternative always available to the candidate who asks for it, and prior information. It rests on a basis of its own under article 9 of the GDPR, determined and documented by the Examiner. No database of biometric templates is built (§ 46). This measure is never used to monitor the Participant during the exam.
The choice between the two arrangements is for the controller and its data protection officer; Evalmee configures one or the other without recommending it or advising against it.
4. Access to proctoring recordings
Where proctoring is enabled by the Examiner, the recordings are accessible to the customer's Examiner users:
- Individual account: the sole Examiner user.
- Organisation account: the authorised Examiner users of the customer organisation, and them alone.
The recordings are reserved for internal use by the Examiner for assessment and fraud prevention purposes. Any download, distribution or external re-use is prohibited save under a legal obligation or a judicial request. Access to the recordings and their consultation are logged, under the conditions of the CNIL recommendation on logging (délibération n° 2021-122 du 14 octobre 2021); the access logs are kept for six months to one year.
Evalmee never accesses the recordings, save out of strict technical necessity (maintenance, support) and under confidentiality controls.
5. Retention and deletion
Principle. The Examiner defines the retention periods for exam data (submissions, answers, marks, metadata) and carries out the exports and deletions in accordance with its policies. Evalmee operates no autonomous retention of that data.
Exception (remote proctoring). The imaging and audio data produced by the remote proctoring features is deleted after 3 months on all plans, a period matching the handling of any challenges.
On the Organisation plan, the period is set by the customer organisation, as controller, before implementation (§ 48), provided that it remains proportionate and is communicated to Participants by their Examiner.
Where fraud is suspected, retention does not exceed the time limits of the disciplinary or legal proceedings — in principle two months. At the Examiner's request, the data in the file concerned is kept until the proceedings brought have ended and is, while they last, neither altered nor deleted. It is for the Examiner to make that request before the deletion date.
6. Data subject rights
Everyone has, over the data concerning them, a right of access, a right to rectification, a right to erasure, a right to restriction of processing, a right to portability and a right to object. Where processing rests on consent, that consent may be withdrawn at any time, without calling into question what was done beforehand.
For exam and remote proctoring data, these requests must be addressed first to the Examiner (the controller). Evalmee assists the Examiner in handling them: dpo@evalmee.com and support@evalmee.com.
If a Participant contacts Evalmee directly, their request is passed on without delay to the Examiner concerned, who alone remains competent to answer it.
For the processing for which Evalmee is itself responsible (section 12), the point of contact is Evalmee directly.
No solely automated decision producing legal effects is taken: any final decision is a matter for the Examiner.
The Participant's access to the data collected about them in connection with remote proctoring is guaranteed in all circumstances: Evalmee provides the Examiner with the technical means to return it to them.
7. Complaint to a supervisory authority
If you consider that your data is not being processed as it should be, you may lodge a complaint with a data protection authority — in particular that of the country of your habitual residence, that of your place of work, or that of the place where the alleged infringement was committed (article 77 of the GDPR).
In France, that authority is the Commission nationale de l'informatique et des libertés (CNIL): cnil.fr/fr/plaintes. The list of the authorities of the other countries of the European Economic Area is published by the European Data Protection Board.
As Evalmee is established in France, the CNIL is its lead supervisory authority within the meaning of article 56 of the GDPR. That takes nothing away from the above: your national authority remains your point of contact, wherever you live.
No prior step with us is required. We would nevertheless rather settle ourselves what can be settled: write to dpo@evalmee.com.
8. Minors
Where Participants are minors, the Examiner adapts the information provided to their age and informs the holders of parental authority of the assessment and remote proctoring arrangements, before registration. It assesses, under its own responsibility, the proportionality of the options enabled in the light of the candidates' age and obtains, where applicable and only where the applicable law requires it, the parental authorisation required.
Evalmee plays no part in that process.
9. Security and incidents
Evalmee implements technical and organisational measures appropriate to the nature of the processing: encryption in transit (TLS 1.2/1.3) and at rest (AES-256); hashed passwords; encrypted backups; a partitioned private network and a firewall; DDoS protection; key-based server access; monitoring of published vulnerabilities.
Evalmee holds no certification in its own name: neither SOC 2, nor ISO 27001, nor HDS, nor SecNumCloud — the ISO 27001 certification sometimes cited is that of its host Scaleway.
In the event of a security incident affecting personal data, Evalmee notifies the Examiner without undue delay and provides it with the information it needs for its own regulatory obligations.
Evalmee does not inform Participants directly, unless the applicable regulations require it.
The Examiner then informs the Participants concerned, in accordance with the regulations.
10. Sub-processors and transfers
Evalmee may use sub-processors for hosting, transactional emailing, support, product analytics, monitoring and content delivery.
Exam and remote proctoring data is hosted in France (Scaleway; AWS eu-west-3 region, Paris), with no replication outside Europe, backups included. It is subject to no transfer outside the European Union.
Three peripheral tools — Cloudflare (network protection), Sentry (error reports), Stripe (payment) — are established in the EU but belong to US groups and do not access exam data; where a transfer is involved, it is governed by the European Commission's Standard Contractual Clauses.
The List of Evalmee's sub-processors is kept up to date.
11. AI and assisted marking
Evalmee may use AI services (e.g. OpenAI/ChatGPT) to assist the Examiner with marking and with providing educational feedback. That processing pursues the following purposes exclusively, in the Participant's interest:
- More accurate and fairer marking, by helping to make the assessment objective and to make the criteria consistent;
- More detailed and more usable feedback, including an explanation of mistakes and suggestions for improvement to support the Participant's progress;
- Help for the Examiner, who retains control of marking and of educational decisions in all circumstances.
Data used. The content sent to the AI services is non-nominative: it contains no name, no identifier and no contact details of the Participant or of the Examiner. AI plays no part at any point in remote proctoring and no mark is awarded automatically to a written answer.
No model training. The data sent is never used to train the AI providers' models.
No automated decision-making. AI issues no decision producing legal effects: any final decision (marking, validation, sanction) is a matter for the Examiner.
Legal basis. This processing is carried out by Evalmee as a processor, on the legal basis determined by the Examiner, as controller, and documented by it.
12. The processing for which Evalmee is itself responsible
For the evalmee.com site, Examiners' accounts, billing, support and the security of the Platform, Evalmee follows no one's instructions: it is the controller. The notices that follow are therefore its own. The controller is FD EDU, whose full contact details are given in section 14.
Purposes and legal bases.
- Creating and managing an Examiner account, and providing the Platform — performance of the contract (article 6.1.b of the GDPR).
- Invoicing, keeping the accounts and retaining the mandatory records — legal obligation.
- Answering support, contact or demonstration requests — performance of the contract, or a legitimate interest in answering those who write to us.
- Ensuring the security of the Platform: technical logs, prevention of abuse, detection and handling of incidents — a legitimate interest in protecting the service and its users.
- Informing our customers of changes to the service and sending them the necessary technical communications — performance of the contract.
- Prospecting organisations and measuring the site's audience — legitimate interests, and consent for the trackers that require it (section 13).
Origin of the data. It comes to us from the person themselves, or from the organisation that opened an account for one of its staff. Participants' data, for its part, comes to us from the Examiner: we never collect it on our own initiative.
Mandatory nature. The information requested when an account is opened is necessary for providing the service: without it, the contract cannot be performed. The other information is optional, and its absence has no other consequence.
Recipients. Our teams, within the limits of what their duties require, and the sub-processors mentioned in section 10. No data is sold, rented or transferred to third parties, for advertising or any other purpose.
Retention periods.
- Account and billing: for the term of the contract, then for as long as is needed to handle complaints and disputes; the accounting records are kept for ten years, as the law requires.
- Support: for as long as it takes to handle the request, and to draw service-quality lessons from it.
- Prospecting, contact and demonstration requests: at most three years from the last contact, and erased without delay if the person objects.
- Technical security logs: from six months to one year.
No automated decision-making. No decision producing legal effects or significantly affecting you is taken on that data by solely automated processing, and there is no profiling for that purpose.
Your rights. For that processing, your point of contact is Evalmee directly, at dpo@evalmee.com: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where the processing rests on it. The route of a complaint to a supervisory authority remains open in any event (section 7).
13. Cookies and trackers
A cookie is a small file that a site places on your device and reads again on your subsequent visits. The rule applicable in France is article 82 of the loi Informatique et Libertés: the trackers strictly necessary for providing the service you request are placed without consent; the others require your prior agreement.
On the evalmee.com site. We measure the site's audience with Staminads, served from our own infrastructure (staminads.evalmee.io). It counts page views, reading depth and a few deliberate actions — a click on "free trial", a change of language, the use of a free tool. The statistics produced serve to tell us which pages are useful, never to recognise a person from one site to another. We load no advertising network and no social media pixel.
Three pages of the site, and three only, embed a third-party module that may place its own trackers when you use it: demonstration booking (HubSpot), the webinars page (Contrast) and the product updates page (Featurebase). These modules are loaded only on those pages.
On the app.evalmee.com application.
- Strictly necessary — session and authentication (
remember_user_token,_evalmee_session,ahoy*), Crisp online support (crisp*). - Usage measurement — PostHog (
ph_*), to understand which features are useful. - Technical diagnostics — Sentry (
gsID,sentry-sc,AMP_*), to receive error reports. - Advertising — none.
The measurement and diagnostic trackers are strictly limited to technical analysis and to the improvement of the service. They are never used for advertising purposes, nor to profile an individual Participant, nor to follow anyone across other sites.
13.1 How to refuse cookies
Every browser allows you, in its privacy settings, to block cookies or to erase those already placed; most also allow you to accept only those of the site visited. If you block the strictly necessary trackers, the application can no longer work: you will not stay logged in from one page to the next.
To have us stop all audience measurement concerning you, simply write to us at dpo@evalmee.com.
14. Who we are, and how to reach us
Controller — FD EDU, a société par actions simplifiée with share capital of €1,000, registered office: 3 Rue Joliot Curie, 91190 Gif-sur-Yvette, France. RCS Évry 884 027 079, VAT FR78884027079. Evalmee is the brand under which it operates the Platform.
- Data Protection Officer (DPO): dpo@evalmee.com
- Support: support@evalmee.com
- General contact: contact@evalmee.com
15. Updates to this Policy
We may update this Policy. In the event of a material change, we inform Examiners by email at the known administrator addresses.
Examiners are responsible for passing that information on to Participants.
The Last updated notice is refreshed. The version history is available on request at dpo@evalmee.com.
16. Our reading of the CNIL recommendation
On 8 June 2023 the CNIL adopted its délibération n° 2023-058, a recommendation on the arrangements for implementing remote proctoring systems for online exams. It is the reference text in France, where Evalmee is established, and our design choices align with it.
Our detailed reading of that recommendation is published on our security page, point by point. It is our own and does not bind the CNIL: as controller, it is for the Examiner to carry out its own analysis, with its data protection officer.