Privacy policy
Privacy policy
This policy explains how your personal data is processed when you use the notasis website and app.
1. Data controller
[COMPANY NAME], [ADDRESS], MERSİS: [MERSİS NO] (“notasis”, “we”). You can reach us at [email protected].
We process exam and student data on behalf of educators and institutions, following their instructions. [DATA CONTROLLER / PROCESSOR ROLES: TO BE CONFIRMED WITH LEGAL ADVICE]
2. Data we process
Educator accounts
- First name, last name and institutional email address
- Institution and account approval status
- Activity in the app: exams and rubrics created, grades given and grade changes
Student and exam data
- Roster: first name, last name, student number and email address (by CSV, manual entry or a course entrance code)
- Scanned exam papers and images of answer regions
- Grades, rubric items applied, feedback, regrade requests and grade history
Technical data
- Server logs for security and debugging: IP address, browser details and access time
This website
The notasis.app website uses no cookies and contains no analytics or advertising tools.
3. Purposes and legal grounds
- Providing the service: exam setup, uploading papers, mapping, grading and publishing grades
- Verifying and approving educator accounts
- Keeping the service secure and fixing errors
- Meeting legal obligations
We process data on the legal grounds listed in Article 5 of KVKK. [LEGAL GROUND PER PURPOSE]
4. AI processing
Images of answer regions and the related rubric items are sent to the OpenAI API to produce mapping suggestions. The AI doesn’t grade and doesn’t create new rubric items; no grade is saved until the educator confirms the suggestions.
[OPENAI DATA RETENTION AND MODEL-TRAINING TERMS]
5. Transfers
We don’t sell data or share it for advertising. We work with the following service providers to run the service:
- OpenAI: AI mapping suggestions
- Cloudflare: website hosting
- [APP HOSTING AND OTHER SERVICE PROVIDERS]
Some of these providers process data outside Türkiye. [LEGAL BASIS FOR TRANSFERS ABROAD UNDER KVKK ARTICLE 9]
6. Retention
[RETENTION PERIODS AND WHAT HAPPENS TO DATA WHEN AN ACCOUNT IS DELETED]
7. Security
Data is encrypted in transit (HTTPS). Only a course’s instructors and TAs can access its exam data; students see only their own results. [ADDITIONAL TECHNICAL AND ORGANISATIONAL MEASURES]
8. Your rights
Under Article 11 of KVKK, you have the right to:
- Learn whether your personal data is processed and, if so, request information about it
- Learn the purpose of processing and whether data is used accordingly
- Know the third parties your data is transferred to
- Ask for incomplete or inaccurate data to be corrected
- Ask for your data to be deleted or destroyed
- Ask for corrections and deletions to be notified to third parties your data was transferred to
- Object to an outcome against you that results from analysis by automated systems
- Claim compensation for damage caused by unlawful processing
You can send requests to [email protected]. [APPLICATION METHOD AND RESPONSE TIME] If you are a student, you can also send your request to your course instructor or your institution.
9. Changes
When we update this policy, we publish the new version on this page and change the “Last updated” date.