Privacy Policy:
1. Introduction
This Privacy Policy outlines how Exam Online(‘we’, ‘our’, or ‘us’) collects, uses, discloses, and protects your personal information when you use our services. We are committed to ensuring that your privacy is protected. If we ask you to provide certain information by which you can be identified when using this website, it will only be used in accordance with this Privacy Policy.
For any privacy-related queries, please contact us at [email protected].
2. Data We Collect
We may collect Personal Information directly from you in the following circumstances and the processing may be based on rules such as consent-based, Contractual Necessity, Legal Obligations, Legitimate Interest, Vital Interest or Public task.
- Contact Information such as name, photograph, business email, phone number, Student or employee ID number or address when you express an interest in obtaining additional information about our services; via our contact-us” or similar options on the website. We may also be getting the information from events we conduct and third-party sources.
- Prospects information, Personal information is processed as part of maintaining relationships or related to entering into an agreement with prospects.
- Exam Candidate or Customer information, Customer’s personal information is processed during the signing of execution of an agreement as part of a business opportunity, maintaining relationships, handling disputes etc. It also includes a screen recording of the examinee’s PC during the exam, a webcam recording of the examinee’s environment, a smartphone camera recording of the examinee’s environment (if applicable), Associated exam institute of the examinee, Information on the browser and operating system used by the user, IP address of the user, Geo-location of the candidate and tracking of candidate Behaviour Traits ( Movements of Lip, Face, Eyes and other body movements)
- Suppliers, supplier’s personal information is processed for the purpose of making payments, maintaining relationships, getting into an agreement, handling disputes etc.
- Employee or Applicant Information, if you apply for an employment opportunity with Exam Online, we collect your name, email, phone number, address, bank account details, age, gender, other address proofs and the information you provide in your application materials and during any interview process.
- Reviews and Feedback, if you voluntarily submit certain information to us, such as by filling out a survey about your user experience, providing feedback, or submitting a review of our services, we collect the information that you have provided.
- Legal obligations, there may be situations where the data we collect are processed to comply with any legal requirements.
- Cookies and Similar Technologies: We use common information-gathering tools, such as cookies and similar technologies, to automatically collect information as you navigate our website, our services, or interact with emails we have sent to you.
- Information we receive from third parties: We collect some Personal Information from third parties, such as publicly available databases or social media platforms; and vendors who compile information for our use, such as in recruiting or sales leads.
- Other Information – We collect the data you explicitly send us when you submit information via forms on our web page in form of Sign up for ExamOnline release notes, product roadmap, and webinars, Sign up for ExamOnline user conference; Sign up for ExamOnline Blog subscription; Enquire information and Order products or services.
3. Purpose of Processing the Personal Data
ExamOnline utilizes this data for specific purposes, such as:
- User Identification: To accurately identify you as a user during the exam process.
- Exam Integrity: To monitor your environment during the exam to maintain the integrity and fairness of the examination.
- Data Security: Ensuring that access to exam data is restricted only to authorized individuals with legitimate reasons and proper permissions.
- Ensuring Service Functionality: The data is used to enable the proper functioning of our services on your device.
- Troubleshooting: It aids in identifying and resolving any technical issues that may arise.
- User Behavior Analysis: We may analyze user behavior relevant to the correctness of the exam to ensure the integrity and fairness of the assessment process.
- Workflow Support and Control: User-related events on the system are logged to support and monitor the overall workflow. For example, events such as staff members viewing or modifying exam sets are recorded for auditing purposes
4. Legal Basis for Processing Data
We process your personal data based on the following legal grounds:
– Your consent
– Performance of a contract
– Compliance with a legal obligation
– Legitimate interests pursued by us or a third party
– Vital Interests or Public Task
5. How We Use Personal Data
ExamOnline utilizes this data for specific purposes, such as:
- User Identification: To accurately identify you as a user during the exam process.
- Exam Integrity: To monitor your environment during the exam to maintain the integrity and fairness of the examination.
- Data Security: Ensuring that access to exam data is restricted only to authorized individuals with legitimate reasons and proper permissions.
- Ensuring Service Functionality: The data is used to enable the proper functioning of our services on your device.
- Troubleshooting: It aids in identifying and resolving any technical issues that may arise.
- User Behavior Analysis: We may analyze user behavior relevant to the correctness of the exam to ensure the integrity and fairness of the assessment process.
- Workflow Support and Control: User-related events on the system are logged to support and monitor the overall workflow. For example, events such as staff members viewing or modifying exam sets are recorded for auditing purposes.
6. Sharing and Disclosure of Personal Data
We do not intend to transfer, share or disclose your Personal Information unless we have your consent in advance, to third parties who are not bound to act on our behalf unless such a transfer is legally required. With respect to projects, we may transfer the data internationally as per the Customer business. In case we transfer/disclose any information as legally required we will take reasonable steps to ensure that these third-party service providers are obligated to protect Personal Information on our behalf Similarly, it is against our policy to sell any Personal Information we collected.
7. Data Security Measures
Exam Online stores personal data related to stakeholders and Customers at a data center located in the Milan ,Italy. We ensure that all the appropriate controls are in place to safeguard the security of data stored by us. Wherever your Personal data is held by Exam Online or on its behalf, we will take reasonable and appropriate steps to protect it from unauthorized access or disclosure. We have appropriate Technical and Organizational measures in place like firewall, backup and periodic data restoration. We only collect the data needed to provide the service to our users and customers and we anonymize data before making secondary use of them in statistics. We never keep or sell personal information for any other purpose.
Exam Online ensures that the person who handles personal data is trained in Privacy and Information Security to manage data with utmost confidentiality. Data Privacy Impact Assessments are performed to evaluate the impact on Privacy Data and adequate security measures taken.
Our data protection practices adhere to the principles of ‘Privacy by Design and by Default.
8. Data Protection by Default
As per GDPR, “the controller shall implement technical and organizational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed”. That obligation applies to
- the amount of personal data collected,
- the extent of their processing,
- the period of their storage and
- their accessibility.
9. Data Privacy by Design
We follow below principles
- minimizing the processing of personal data,
- pseudonymizing personal data as soon as possible,
- transparency with regard to the functions and processing of personal data,
- enabling the data subject to monitor the data processing,
- enabling the controller to create and improve security features.
- staff training,
10. International Data Transfers
Your personal data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country. With respect to projects, we may transfer the data internationally as per the Customer’s business.
11. Data Subject Rights
Your personal information Rights
In accordance with data privacy requirements ExamOnline recognizes that data subjects have specific rights that must be protected and observed.
Right to Know
You have the right to know certain information about our data practices in the preceding 12 months. You have the right to request the following from us:
- Personal Information we have collected about you.
- Sources from which the Personal Information was collected
- Personal Information about you that we have disclosed
- Third parties to whom Personal Information was disclosed
- Purpose for collecting the Personal Information
All data subject requests and data erasure request related information are tracked and managed internally.
Right to get consent
Data Subjects may be asked to provide their clear and unequivocal consent for the collection, processing and transfer of their Personal Data.
Right to access
ExamOnline may provide data subjects with access or can request for the personal data that we manage as a data controller.
Right to Modify
ExamOnline recognizes the right of individuals to have inaccurate or incomplete data modified. Data subjects for whom data needs to be modified can go to the contact details as available below.
Right to Erasure
If any information is inaccurate or incomplete, the Data Subject may request that the data to be erased. If the data being processed is no longer legal or appropriate, the data to be deleted/erased, unless required by applicable laws.
Personal data is not retained for longer than is necessary for the purpose for which the data was originally collected. However, some personal data may be required to be retained to adhere with legal or regulatory obligations.
Withdrawing consent
Data subjects have the right to ask us not to process your personal data for any purposes which are not legal. We will usually inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such by different means we use to collect your data.
It is completely up to you whether you want to access or not and use this website and provide the information requested, if applicable (generally termed as, “Subscribe”). Exam Online uses the contact information you provide to us via contact forms to contact you about our services. Each time you receive electronic marketing information from us, you have the option to decline to receive further marketing information from us.
You may unsubscribe from these communications at any time by clicking the (“Unsubscribe”) link at the bottom of any email that we send to you.
Right to restriction of processing
Individuals have the right to limit the processing of their personal data under certain circumstances, such as when the accuracy of the data is contested, or the processing is unlawful.
Right to Data Portability
Individuals can request their personal data to be provided to them in a structured, commonly used, and machine-readable format, allowing them to transfer it to another data controller.
Right to Object
Exam Online recognizes the right of individuals to object to the processing of their personal data, where such objections are allowable under data protection legislation.
Rights related to automated decision-making
Individuals have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning them or similarly significantly affect them.
Right to Nominate
Individuals have the right to nominate a person who can execute all the rights on behalf of the data subject.
Right for No Retaliation
Business shall not discriminate against an individual because they exercised any of the personal information rights.
12. Information Retention
We retain your personal information for as long as the information is reasonably needed for the purposes described in this Privacy Notice. We store data in our database servers situated at Milan, Italy. Our application servers are situated in Mumbai, India. We also may retain your personal information to comply with our legal or professional obligations, enforce our agreements, or resolve disputes. Videos and Screen records are stored with retention of 45 days by default and data retention could be more than 45 days based on contract requirements. Access of personal information to a Proctor is only between exam start time to exam end time
13. Cookies and Similar Technologies
We use common information-gathering tools, such as cookies and similar technologies, to automatically collect information as you navigate our website, our services, or interact with emails we have sent to you.
14. Children’s Privacy
Our website and services do not knowingly collect personal information from users under the age of 13. If you are under the age of 13, you are not permitted to use the website and Services or to disclose Personal Information. If we learn we have collected or received Personal Information from a child under 13, we will delete that information or take parental consent.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
16. Data Breach Policy
Data breach means the loss of unauthorized access to, or unauthorized disclosure of personal information resulting from a security breach. All privacy data related breaches can be reported to our Privacy Officer and please refer to the contact details section below for reporting details. In case of any data breaches occurring, it shall be informed to the impacted data subjects within 72 hours of discovering the breach.
Contact Information
Postal Address:
Diversified Business Solutions Pvt. Ltd
118-B Wing, Ansa Industrial Estate, Saki Vihar Road,
Andheri East, Mumbai – 400072
Phone No. : +91 89290 13490
Email: [email protected] and [email protected]
If you have any questions or concerns about this Privacy Policy, please contact us at [email protected]