1. Controller vs. Processor Roles
Under global data privacy frameworks, educational data roles are strictly defined when using ProfDesk:
- Educator-controlled class records: Instructors control the courses, rosters, assessment content, and live class records they create. Instructors are responsible for ensuring they have appropriate institutional or legal authority to upload and process student materials.
- Federated student workspaces: A student may create a full ProfDesk account and connect one or more instructor-created class accounts. The student's personal workspace and any detached read-only academic records described below are associated with that federated account.
- ProfDesk as service provider: ProfDesk hosts and processes these records to provide course, storage, grading, account-linking, and optional AI functionality. The precise legal classification of each party may depend on the law and institutional arrangement that applies to you.
2. Information We Collect
When you register for and utilize ProfDesk, we collect specific categories of data necessary to deliver our academic management features:
- Account Information: Name, email address, username, password hash, connected Google identity information where selected, workspace preference, and subscription status.
- Academic & Course Data: Course modules, Course Learning Outcomes (CLOs), assessment question papers, and interactive grading rubrics created by instructors.
- Student Rosters & Submissions: Student names, institutional roll numbers, email addresses, and uploaded PDF assessment files processed through our grading workflow.
- Optional Course Activity Insights: When a course instructor has enabled the paid Student Activity Insights add-on, ProfDesk records privacy-limited course events such as opening course items, completing requirements, submitting work, and an estimate of time while the course page is visible, focused, and recently active. The instructor can see course and student summaries, completion coverage, content reach, and a safe event timeline. Students can view their own summary and the measurement methodology from the course workspace.
- Billing Details: Subscription ordering and global payment processing are conducted externally by our authorized reseller and Merchant of Record (a third-party payment provider). We do not directly capture or store sensitive credit card numbers on our servers.
3. Connected Class and Federated Accounts
An instructor may create a teacher-managed class account for a student. The student can later create or use a federated ProfDesk account and connect that class account after proving control of it. Connecting is reversible:
- While connected, the federated account can access the live class record and student-specific class files count against the federated account's storage allowance. AI features, where available, use the federated account's Free or Pro allowance.
- The instructor may disconnect the class record for account recovery. Live access and storage responsibility then return to the instructor-managed class account, without changing the student's independent federated workspace.
- If the federated account is deleted, connected live class records remain with their instructors and their student-specific storage responsibility returns to those instructors.
- A teacher-managed class account that has not been connected to a federated account has no independent AI allowance.
4. How We Store & Secure Data
We employ a robust, multi-tiered architecture to secure educational assets:
- Structured Data Storage: Course setups, CLO/PLO matrices, student rosters, and calculated grades are stored securely in access-controlled databases protected by strict access controls and firewall barriers.
- Encrypted Cloud Object Storage: All uploaded assessment answer booklets, scanned PDFs, and solution files are encrypted and stored with a reputable cloud object-storage provider, accessed only through secure, temporary pre-signed URLs.
- Transport Security: All communications between your browser, our servers, and storage are encrypted in transit via industry-standard HTTPS/TLS protocols.
- Similarity-Analysis Text: When you run the optional similarity/plagiarism check, the text of student submissions is extracted (from the document's text layer or via AI transcription) and stored in our database to perform the comparison and to avoid re-processing on later runs. This extracted text is removed when the submission, course, or account is deleted.
5. Third-Party Sub-Processors
To provide our specialized service, ProfDesk shares necessary data subsets with vetted third-party infrastructure partners under strict confidentiality obligations:
- Payment Provider (Merchant of Record): Our authorized reseller acts as global Merchant of Record for payment processing, invoicing, subscription management, and tax compliance.
- Cloud Storage Provider: Provides encrypted object storage for uploaded student documents and assessment files.
- Third-Party AI Providers: Process API requests for automated rubric creation and submission matching. As detailed in the Fair Use of AI section of our Terms, data submitted through the Service's AI features may be processed and used by our AI provider(s) to operate and improve their models and services, including for training purposes.
6. Student Privacy & Educational Compliance
We recognize the sensitivity of educational records under regulations such as FERPA (US), the GDPR, and other international and regional educational data-protection standards, and this policy is drafted to align with those principles. ProfDesk processes student records strictly as an authorized educational tool; student submissions, roll numbers, and grades are never monetized, sold, or shared with third-party advertisers. Because data-protection requirements vary by institution and country, you remain responsible for verifying compliance with your specific university or national data-protection rules before processing confidential student records through the Service.
Student Activity Insights does not collect keystrokes, typed answers or message bodies, screen recordings, webcam or microphone data, IP addresses, user-agent strings, geolocation, or activity in other browser tabs, applications, or websites. Active time is an estimate and may differ from actual study time. These signals are designed for instructional coaching and course improvement; they are not proof of attendance, identity, academic effort, or academic misconduct and must not be treated as the sole basis for a disciplinary or grading decision.
7. Data Retention, Read-Only Academic Records & Erasure
Deletion depends on which account or record is removed:
- Instructor removes a connected roster entry, course, or instructor account: instructor-owned content is deleted, including modules, lecture materials, assessment questions and context, solution keys, and unrelated instructor files. The connected federated account retains a read-only academic record containing only the student's own submitted files or attempts, marks, feedback, annotations, the rubric snapshot applied to that work, and minimal identifying information such as the course and assessment title. The student cannot submit or modify work through that detached record.
- Instructor removes an unconnected class record: its associated student records and files are deleted because there is no federated account to receive them.
- Federated user deletes their account: their personal workspace and detached read-only academic records are deleted. Any still-live class records they connected are disconnected rather than deleted; access control and storage responsibility return to the instructor.
- Disconnect before deletion: if an instructor disconnects a class record before deleting it, it is treated as an unconnected instructor-managed record and no detached academic record is created.
- Student Activity Insights: raw privacy-safe timeline events are retained for up to 180 days, and daily course/resource aggregates for up to 13 months while the add-on remains active. If the add-on ends, tracking and instructor access stop immediately; retained activity data is deleted after a 90-day re-subscription grace period. Permanently deleting the relevant course or student record deletes its activity data immediately.
Read-only academic records are active account data, not recovery backups. They exist only while the receiving federated account exists. Account and record deletion is irreversible, subject to limited operational logging and any retention required by law or our payment provider.
8. Contact Us
If you have questions or concerns regarding our privacy practices, data processing agreements, or erasure requests, please email our team at [email protected].