Assessmate

1. Who we are

Assessmate (“Assessmate”, “we”, “us”, or “our”) provides assessment and learning infrastructure for training organisations — including our marketing website at assess-mate.com, our assessment platform and related products, APIs, mobile or web applications, and professional services (together, the “Services”).

For privacy enquiries, contact:

Where a customer organisation (for example a training centre or corporate trainer practice) uses the Services to process learner, applicant, or candidate data, that organisation is typically the data controller (or equivalent) for that content, and Assessmate acts as a processor (or service provider) on their documented instructions — except where we determine purposes and means ourselves (for example, our own marketing site analytics or account administration), in which case we act as a controller.

2. Scope of this policy

This Privacy Policy explains how we handle personal data when you:

  • Visit or interact with our websites (including assess-mate.com and related pages)
  • Create or use an Assessmate account
  • Use our platform, Assessment Engine, analytics, APIs, exam-prep, or other products
  • Engage us for custom services, licenses, partnerships, demos, or consultations
  • Communicate with us by email, form, phone, or scheduling tools (such as Calendly)
  • Apply for a role with us or otherwise interact with our business

It does not replace any data processing agreement (DPA), order form, or other written contract between Assessmate and a customer. If there is a conflict for customer-controlled assessment data, the DPA or customer agreement controls for that processing.

3. Personal data we collect

We collect personal data in the following categories, depending on how you use the Services.

3.1 Information you provide

  • Identity and contact data — name, email address, phone number, organisation name, role/title, billing or postal address
  • Account data — login credentials (or tokens via SSO/OAuth), profile preferences, authentication events
  • Commercial enquiry data — messages submitted via contact forms, sales or partnership enquiries, demo booking details, call notes you share with us
  • Customer content — materials you or your organisation upload or generate in the Services (for example course packs, SOPs, item banks, assessments, submissions, scores, competency reports, and related metadata). This may include personal data about learners, applicants, candidates, facilitators, or employees if your organisation includes it
  • Support data — tickets, attachments, and correspondence related to support requests
  • Recruitment data — CVs and application materials if you apply to work with us

3.2 Information collected automatically

  • Usage and device data — IP address, browser type, device identifiers, operating system, referring URLs, pages viewed, feature usage, timestamps, approximate location derived from IP
  • Log and diagnostic data — server logs, error reports, performance metrics, security event logs
  • Cookies and similar technologies — see Section 10

3.3 Information from third parties

  • Identity providers — if you sign in with a third-party OAuth/SSO provider, we receive identifiers and profile fields authorised by that provider and by you
  • Payment or billing partners — limited billing metadata needed to process invoices or subscriptions (we do not store full payment card numbers on Assessmate systems when cards are processed by a PCI-compliant processor)
  • Public or commercial sources — business contact details from publicly available sources or partners, where permitted, for B2B outreach relevant to our Services

We do not require special-category data (such as health, biometric, or precise religious data) to operate the core Services. If customer content includes such data, the customer must ensure it has a lawful basis and any required notices or consents before uploading it.

4. How we use personal data

We use personal data to:

  • Provide and operate the Services — create accounts, authenticate users, deliver assessments, generate reports, and provide APIs and product features
  • Fulfil contracts — deliver custom services, licenses, partnerships, onboarding, and support under our agreements with you or your organisation
  • Communicate — respond to enquiries, send service notices, security alerts, and administrative messages
  • Improve and secure — monitor performance, debug, prevent fraud/abuse, maintain integrity of assessments where applicable, and develop product improvements
  • Market our business (B2B) — send relevant information about Assessmate products and services where permitted by law; you may opt out of marketing at any time
  • Comply with law — meet legal, regulatory, tax, and accounting obligations, and respond to lawful requests
  • Protect rights — establish, exercise, or defend legal claims

We do not sell personal data. We do not use customer assessment content to train public foundation models for unrelated third parties. Where we use aggregated or de-identified insights to improve the Services, we take steps designed so individuals are not reasonably re-identifiable.

If you are in the UK, EEA, Switzerland, or another jurisdiction that requires a “legal basis”, we rely on one or more of the following:

  • Contract — processing necessary to provide the Services you request or to take steps prior to entering a contract
  • Legitimate interests — operating, securing, and improving our business and B2B communications in ways that do not override your fundamental rights
  • Consent — where required (for example certain cookies or optional marketing); you may withdraw consent at any time
  • Legal obligation — where processing is required by applicable law

For processor activities on behalf of a customer, the customer is responsible for ensuring it has a lawful basis to collect and instruct Assessmate to process the relevant personal data.

6. How we share personal data

We may share personal data with:

  • Service providers / processors — hosting, infrastructure, email delivery, analytics, customer support tooling, scheduling, error monitoring, and similar vendors under contractual confidentiality and data-protection obligations
  • Customer organisations — when you use the Services under an organisation’s workspace, administrators and authorised users of that organisation may access content and activity consistent with their roles and settings
  • Professional advisers — lawyers, auditors, or insurers where reasonably necessary
  • Authorities — regulators, courts, or law enforcement when required by law or to protect rights, safety, and security
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality safeguards

We require processors to process personal data only on our documented instructions (or the customer’s, where we are a processor) and to implement appropriate security measures.

7. International transfers

We may process and store personal data in countries other than where you or your organisation are located. Where we transfer personal data from the UK/EEA/Switzerland to a country not recognised as providing adequate protection, we use appropriate safeguards such as standard contractual clauses (or successor mechanisms) and supplementary measures where required.

8. Retention

We retain personal data only as long as needed for the purposes described in this policy, including:

  • Account and workspace data — for the life of the account/subscription and a reasonable wind-down period afterward
  • Customer content — according to the customer’s settings and agreement; upon termination or verified deletion request, we delete or return data as described in the contract and our deletion process where applicable
  • Marketing contacts — until you opt out or the relationship is no longer relevant
  • Security and server logs — typically for shorter operational periods (often up to 12 months, unless needed longer for investigations)
  • Legal / accounting records — as required by applicable law

Backups may retain residual copies for a limited period (commonly up to 90 days) until rotated out of the backup cycle after deletion is processed.

9. Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration. These may include encryption in transit, access controls, least-privilege practices, monitoring, and vendor due diligence.

No method of transmission or storage is perfectly secure. You are responsible for safeguarding credentials and for configuring organisational access appropriately. Notify us promptly at support@assess-mate.com if you suspect unauthorised access to your account.

10. Cookies, analytics, and similar technologies

We use cookies and similar technologies to:

  • Enable core site and product functionality (necessary cookies)
  • Remember preferences
  • Understand traffic and feature usage (analytics)
  • Support security and fraud prevention

Where required by law, we request consent for non-essential cookies. You can control cookies through your browser settings; disabling some cookies may affect functionality.

Our marketing site and product may use analytics tools (for example privacy-respecting product analytics). Event data is used to improve the Services and measure business outcomes such as qualified conversations — not to sell personal profiles.

11. Your rights

Depending on your location and role (individual user vs. data subject of a customer organisation), you may have rights to:

  • Access personal data we hold about you
  • Correct inaccurate data
  • Delete data (subject to legal exceptions)
  • Restrict or object to certain processing
  • Data portability
  • Withdraw consent where processing is consent-based
  • Lodge a complaint with a supervisory authority

How to exercise rights

If your data was uploaded by a customer organisation (for example your school, employer, or training centre), please contact that organisation first. We may redirect your request to the customer as controller, or require their authorisation before acting on processor-held content.

We may need to verify your identity before fulfilling a request. We aim to respond within timelines required by applicable law (and typically acknowledge within five business days).

12. Children’s privacy

The Services are directed to organisations and adults. We do not knowingly collect personal data from children under 16 (or the higher age required in your jurisdiction) for our own marketing purposes. Where a customer uses Assessmate with learners who may be minors, the customer is responsible for obtaining any required parental/guardian consents and providing appropriate notices.

If you believe we have collected a child’s data inappropriately, contact hello@assess-mate.com and we will take appropriate steps.

13. Third-party sites and services

Our websites and Services may link to third-party sites (for example scheduling, documentation, or app stores). We are not responsible for their privacy practices. Review their policies before providing personal data.

14. Automated decision-making

Assessmate provides tools that score, analyse, or report on assessment performance based on rules, models, and configurations set by customers or product features. We do not make solely automated decisions that produce legal or similarly significant effects about individuals for our own purposes without meaningful human involvement, except where disclosed and permitted. Customers remain responsible for how they use assessment outputs in high-stakes decisions.

15. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be notified via the website, product notice, or email where appropriate. Continued use of the Services after an update constitutes acceptance of the revised policy to the extent permitted by law.

16. Contact

For privacy questions, requests, or complaints:

Assessmate
Email: hello@assess-mate.com
Support: support@assess-mate.com
Web: assess-mate.com/contact

If we cannot resolve your concern, you may have the right to contact your local data-protection authority.

Questions about this document? Contact us or email hello@assess-mate.com .