Legal & Institutional Governance

ExamsWave Platform Policies

Effective & Last Revised: July 22, 2026

Privacy Policy

Data Minimization, Telemetry Security, and Information Handling Framework

ExamsWave is committed to maintaining strict data minimization standards. We collect and process only the minimal telemetry necessary to secure our platform, deliver diagnostic testing, and enforce API authorization scopes.

1. Information Categories Collected

We process the following explicit categories of user and system data:

  • Identity & Account Telemetry: Account name, validated email address, cryptographically hashed access tokens, and assigned role scopes (e.g., Student, Agent, Partner, Admin).
  • Performance Metrics & Usage Activity: Assessment attempts, item completion speed, aggregate mastery scores, IP addresses, user agent strings, and REST API invocation logs.
  • Financial Transactions: Payments are processed via PCI-DSS Compliant payment processing gateways. ExamsWave does not store full credit card numbers or account credentials on internal database servers.

2. Purpose of Processing

Collected data serves strictly to render practice items, compute performance analytics, enforce API rate limits, prevent brute-force attacks, and maintain platform infrastructure stability.

3. API Authorization & Credential Integrity

API Secret Keys issued by ExamsWave represent unique security credentials tied directly to your organization. All database interactions utilize PDO prepared parameters, strict CORS security policies, and encrypted storage. You are solely responsible for preventing API key exposure.

4. Privacy Rights & Erasure Protocols

ExamsWave never sells, monetizes, or rents personal data to third parties. Subject to applicable data protection regulations (GDPR/CCPA), you may submit an account record inspection or complete erasure request by contacting our Compliance Officer at privacy@examswave.com.