Privacy Policy
Data Minimization, Telemetry Security, and Information Handling Framework
ExamsWave is committed to maintaining strict data minimization standards. We collect and process only the minimal telemetry necessary to secure our platform, deliver diagnostic testing, and enforce API authorization scopes.
1. Information Categories Collected
We process the following explicit categories of user and system data:
- Identity & Account Telemetry: Account name, validated email address, cryptographically hashed access tokens, and assigned role scopes (e.g., Student, Agent, Partner, Admin).
- Performance Metrics & Usage Activity: Assessment attempts, item completion speed, aggregate mastery scores, IP addresses, user agent strings, and REST API invocation logs.
- Financial Transactions: Payments are processed via PCI-DSS Compliant payment processing gateways. ExamsWave does not store full credit card numbers or account credentials on internal database servers.
2. Purpose of Processing
Collected data serves strictly to render practice items, compute performance analytics, enforce API rate limits, prevent brute-force attacks, and maintain platform infrastructure stability.
3. API Authorization & Credential Integrity
API Secret Keys issued by ExamsWave represent unique security credentials tied directly to your organization. All database interactions utilize PDO prepared parameters, strict CORS security policies, and encrypted storage. You are solely responsible for preventing API key exposure.
4. Privacy Rights & Erasure Protocols
ExamsWave never sells, monetizes, or rents personal data to third parties. Subject to applicable data protection regulations (GDPR/CCPA), you may submit an account record inspection or complete erasure request by contacting our Compliance Officer at privacy@examswave.com.