Skip to main content
PrivacyLiving document

Privacy Policy

How DevAcademia collects, uses, shares, and protects personal data - for institutions, educators, and learners.

Reference: FERPA · GDPR · UK GDPREffective: Reviewed annually

Status: living document. Reviewed at least annually.

This Privacy Policy explains how DevAcademia collects, uses, shares, and protects personal data. It applies to the DevAcademia platform and website. For students and educators, most personal data is handled on behalf of your school or institution under that institution's own privacy policies — see "Our role" below.

About this document. DevAcademia is committed to protecting
the privacy and security of the data entrusted to us. This
policy transparently describes what personal data we collect,
how we preserve it, and what we do with it, so institutions and
users can evaluate our practices with complete information. It is
a living document, reviewed periodically and updated as our
services and applicable law evolve. The binding terms that
govern how DevAcademia processes an institution's data are set
out in the agreement — including a Data Processing Agreement —
entered into with each institution.

#Our role

DevAcademia provides learning and assessment software to schools, districts, and other institutions.

  • When we act for an institution (processing student and

educator data to deliver the service), the institution is the controller and DevAcademia acts as a processor or "school official." We process that data only on the institution's documented instructions, under a Data Processing Agreement established at engagement. If you are a student or educator, the institution's own privacy policy governs, and rights requests are directed through the institution.

  • When we act for ourselves (for example, handling inquiries

from our public website, or managing our billing relationship with an institution), DevAcademia is the controller for that limited data.

This policy describes both. The FERPA compliance and GDPR compliance pages give the detail for institutional (school-official / processor) processing.


#What data we collect

Account and profile data. Name, email address, institution membership, and role. Provided by the institution or during sign-up.

Learning data. Coursework, submissions, attempts, grades, and progress — the education records the institution asks us to process.

Communications data. In-app notifications, feedback, and support messages.

Technical and usage data. Sign-in events, device and browser information, IP address, and usage patterns needed to operate and secure the service. Minimised by design.

We do not collect special-category data (health, biometric, racial or ethnic origin, political, religious, or sexual- orientation data). We do not run advertising or third-party tracking, and we do not build advertising profiles.


#How we use data

We use personal data to:

  • Provide, maintain, and secure the platform.
  • Deliver coursework, assessment, grading, and progress features.
  • Send service communications (sign-in codes, notifications,

billing).

  • Prevent abuse and protect the security of the service.
  • Meet legal and compliance obligations.

We do not sell personal data, we do not use student data for advertising, and we do not use student data to train external AI models.

Lawful basis (GDPR). For institutional processing, the basis is the institution's contract with us (Article 6(1)(b)) and its instructions to us as processor (Article 28). For our own limited controller processing, the basis is our legitimate interest in running and securing our business, or your consent where required.


#How we share data

We share personal data only with:

  • The institution that controls the data.
  • Sub-processors — a small number of vetted service providers

that help us run the platform, each bound by a written data- protection agreement. They are named in our public sub-processor list.

  • Integrations the institution configures (for example a Slack

channel or webhook endpoint the institution chooses).

  • Legal and safety recipients where required by law or to

protect rights and safety.

We do not share personal data with advertising networks, data brokers, or analytics providers operating on student data.


#International transfers

Some of our sub-processors are located in the United States and some in the EU. Transfers of personal data out of the EU/EEA/UK rely on the EU-US Data Privacy Framework and Standard Contractual Clauses, and EU-region processing is available on request for institutions that require it. See the sub-processor list for the mechanism per provider.


#Data retention

We keep personal data only as long as needed to provide the service and meet legal obligations. Retention windows for each category of data are published in our data retention schedule. Institutions can direct deletion of their data, and all education records are deleted on contract termination on the timeline in that schedule.


#Your rights

Depending on where you are and your relationship with DevAcademia, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability.

  • Students and educators: signed-in users can download a

copy of their own data and file correction or amendment requests directly from their dashboard. Because your institution is the controller of your records, some requests are routed to the institution for a decision.

for the full list of Article 15–22 rights and how to exercise them.

To make a request or ask a question, contact compliance@devacademia.com. You also have the right to lodge a complaint with your local data- protection authority.


#Security

We protect personal data with encryption in transit (TLS) and at rest (provider-managed, block-level encryption on our hosted database and backups), role- and institution-based access controls, an append-only audit trail of administrative actions, and regular review of our security practices. More detail is in the GDPR compliance page (Article 32).


#Children's privacy

DevAcademia is used by schools with students who may be minors. We do not knowingly collect personal data from children except on behalf of, and under the instruction of, the school as controller. Institutions are responsible, as controllers, for obtaining any parental consent required under FERPA, COPPA, and the applicable GDPR Article 8 digital-consent age, and they attest to that consent in the product.


#Cookies

DevAcademia uses only strictly-necessary cookies — to sign you in and keep you signed in. We set no advertising, analytics, or tracking cookies, so no cookie-consent banner is required. Our sign-in and sign-up pages run a Cloudflare Turnstile bot-detection challenge, which may set a strictly-necessary security cookie from Cloudflare and receives your IP address and a browser signal for that purpose only — it performs no advertising or cross-site tracking. See our sub-processor list for details, and the GDPR compliance page for the e-Privacy position.


#Changes to this policy

We may update this policy from time to time. Material changes affecting institutional (education-record) processing are notified to institutions at least 30 days in advance. The effective date and change history are shown on this page.


#Contact

Privacy and compliance: compliance@devacademia.com. Security matters: security@devacademia.com.

For our own limited processing, the data controller is DevAcademia. Our registered details are available on request via the contact above.


#Change history

DateChange
2026-07-12Initial version.