Privacy policy

Privacy policy

This policy explains how your personal data is processed when you use the notasis website and app.

Last updated: [DATE]

1. Data controller

[COMPANY NAME], [ADDRESS], MERSİS: [MERSİS NO] (“notasis”, “we”). You can reach us at [email protected].

We process exam and student data on behalf of educators and institutions, following their instructions. [DATA CONTROLLER / PROCESSOR ROLES: TO BE CONFIRMED WITH LEGAL ADVICE]

2. Data we process

Educator accounts

  • First name, last name and institutional email address
  • Institution and account approval status
  • Activity in the app: exams and rubrics created, grades given and grade changes

Student and exam data

  • Roster: first name, last name, student number and email address (by CSV, manual entry or a course entrance code)
  • Scanned exam papers and images of answer regions
  • Grades, rubric items applied, feedback, regrade requests and grade history

Technical data

  • Server logs for security and debugging: IP address, browser details and access time

This website

The notasis.app website uses no cookies and contains no analytics or advertising tools.

3. Purposes and legal grounds

  • Providing the service: exam setup, uploading papers, mapping, grading and publishing grades
  • Verifying and approving educator accounts
  • Keeping the service secure and fixing errors
  • Meeting legal obligations

We process data on the legal grounds listed in Article 5 of KVKK. [LEGAL GROUND PER PURPOSE]

4. AI processing

Images of answer regions and the related rubric items are sent to the OpenAI API to produce mapping suggestions. The AI doesn’t grade and doesn’t create new rubric items; no grade is saved until the educator confirms the suggestions.

[OPENAI DATA RETENTION AND MODEL-TRAINING TERMS]

5. Transfers

We don’t sell data or share it for advertising. We work with the following service providers to run the service:

  • OpenAI: AI mapping suggestions
  • Cloudflare: website hosting
  • [APP HOSTING AND OTHER SERVICE PROVIDERS]

Some of these providers process data outside Türkiye. [LEGAL BASIS FOR TRANSFERS ABROAD UNDER KVKK ARTICLE 9]

6. Retention

[RETENTION PERIODS AND WHAT HAPPENS TO DATA WHEN AN ACCOUNT IS DELETED]

7. Security

Data is encrypted in transit (HTTPS). Only a course’s instructors and TAs can access its exam data; students see only their own results. [ADDITIONAL TECHNICAL AND ORGANISATIONAL MEASURES]

8. Your rights

Under Article 11 of KVKK, you have the right to:

  • Learn whether your personal data is processed and, if so, request information about it
  • Learn the purpose of processing and whether data is used accordingly
  • Know the third parties your data is transferred to
  • Ask for incomplete or inaccurate data to be corrected
  • Ask for your data to be deleted or destroyed
  • Ask for corrections and deletions to be notified to third parties your data was transferred to
  • Object to an outcome against you that results from analysis by automated systems
  • Claim compensation for damage caused by unlawful processing

You can send requests to [email protected]. [APPLICATION METHOD AND RESPONSE TIME] If you are a student, you can also send your request to your course instructor or your institution.

9. Changes

When we update this policy, we publish the new version on this page and change the “Last updated” date.