You have visited a Tosa website or registration page. Isograd Inc. and its affiliates and subsidiaries are committed to protecting and respecting your privacy. This policy explains how we collect, use, and disclose information from or about you when you use our websites, services, applications, and other digital services that link to this policy.
This policy applies to all services we provide in the United States. The data controller of your information is the legal entity that registered you to use the services; Isograd Inc. is designated as the data processor in those circumstances. For our websites, and where users are registered directly by Isograd Inc., we act as the data controller.
When we provide services to a business or educational institution (a “Customer”) that has a customer agreement with us, Isograd Inc. is the data processor and the Customer is the data controller. We process end-user information strictly under the Customer’s instructions, as described in the applicable customer agreement or as otherwise required by law. If a Customer agreement conflicts with this policy, the customer agreement controls. If you are an end user of one of our Customers and have questions about how your data is handled, please contact the Customer organization directly.
For contact details, see our Contact Us page.
Data Privacy Certification
1EdTech TrustEd Apps™ Data Privacy Certified
Isograd Inc. holds the 1EdTech TrustEd Apps™ Data Privacy Certification for Tosa Certifications — an independent third-party certification that verifies our platform meets rigorous standards for student data privacy and security in educational technology.
Certification awarded: April 8, 2026 | Valid through: April 2027
Verification: site.imsglobal.org/certifications/isograd-inc/tosa-certifications
1EdTech is a nonprofit member organization that develops and maintains open technology standards for education. The TrustEd Apps™ Data Privacy Certification independently verifies that an educational technology product’s data practices meet the program’s requirements for privacy, security, and responsible data use — providing educators, students, and institutions with confidence in the tools they use.
Definitions
The following terms are used throughout this policy:
| Term | Meaning |
|---|---|
| Data Controller | The entity that determines the purposes and means of processing personal data. Typically the Customer who uses our services to manage its end users’ information. |
| Data Processor | The entity that processes data on behalf of the data controller. Isograd Inc. acts as data processor when processing Customer and end-user information under Customer instructions. |
| Services | The testing platform and related applications, software, and digital services provided by Isograd Inc. that link to this policy. |
| Customer | A business, educational institution, or other legal entity that has entered into an agreement with Isograd Inc. to provide services to its end users. Customers act as data controllers. |
| End User | An individual who uses our services as a candidate taking tests or assessments. |
| User / Administrator | An individual who manages and oversees use of the platform within an organization — managing accounts, organizing tests, and administering platform services. |
| Candidate | An individual who takes tests or assessments on the platform. |
| Visitor | Any individual who visits our websites or social media pages. |
| Personal Data | Any information relating to an identified or identifiable individual. |
| Consent | Freely given, specific, informed, and unambiguous permission by a data subject for the processing of their personal data. |
| Service Providers | Vendors and partners who perform tasks on behalf of Isograd Inc., such as hosting, email delivery, remote proctoring, technical support, and security. |
How We Collect and Use Your Personal Data
Our legal basis for collecting and using your personal data depends on the type of information we collect and the context in which we collect it. We may process your personal data because:
- we need to perform a contract with you;
- you have given us your consent;
- the processing is in our legitimate interests and is not overridden by your rights;
- it is necessary for payment processing; or
- we are required to do so by law.
We may also collect personal data you provide during communications with us, such as technical support interactions. We may use your personal data for audits and to comply with our legal obligations under applicable law.
What Data We Collect
Information You Provide Directly
When you visit our websites or use our services, we may ask you to provide personal data, including when you:
- register for an account or create a user profile;
- subscribe to our newsletter;
- place an order or make a purchase;
- join us on social media;
- attend a training or onboarding session; or
- contact us with questions or request support.
Categories of data we may collect directly from you include:
- Contact and account identifiers: name, address, phone number, email address, and login credentials.
- Financial information: payment method details and transaction history. Payment card data is collected by our PCI-DSS-certified payment processors on our behalf.
- Identification information: photo and photo ID document, used to verify your identity when taking an exam through our remote proctoring service. This data is collected and processed by our third-party proctoring provider, Integrity Advocate, in strict compliance with this policy.
Information Collected When Creating a Customer Account
When an organization registers as a Customer, we collect the following information:
- Institution or business name
- Address
- Email address
- Phone number
- Main account user’s first and last name
- Primary language
Information Collected When Creating a User or Candidate Account
When a user (administrator) or end-user (candidate) account is created, we collect:
- First name
- Last name
- Email address
- Primary language
Information We Collect Automatically When You Take a Test
When you take a test on our platform, we automatically collect certain technical and performance data. We may use this data to provide or improve the services, for security and analytics purposes, and for any other lawful purpose permitted by applicable law.
| Category | Data Collected |
|---|---|
| Application Technology Metadata | IP address, browser type and version, internet bandwidth, cookie data |
| Application Usage Statistics | Metadata on how you interact with the application |
| Assessment Data | Standardized test scores, observation data, incidents and test policy or proctoring breaches |
| User Identifiers | Application-assigned user ID, encrypted SSO passwords |
| In-App Performance Data | Program-specific performance metrics (e.g., typing speed, ability to input a formula in Excel) |
| Survey Responses | Your responses to surveys or questionnaires |
| User Work | User-generated content, including writing, images, and test item responses |
Data We Collect Through Third-Party Services
We use third-party tools to operate and analyze our websites for analytics and advertising purposes. These tools use cookies and other tracking technologies, and are activated only with your consent, recorded when you click “Accept” in our Privacy Center (Trust Badge). You can manage your preferences at any time by clicking the Privacy button at the bottom left of any page on this Site, or by visiting the Privacy Center directly.
We work with service providers including Google Ads, Google Analytics, and LinkedIn. All such providers are contractually required to keep your personal data secure and confidential, and to use it only for the purposes described in this policy. We take all steps necessary to ensure that your data is treated securely in accordance with this policy, and that no transfer of your personal data to a third-party organization or country takes place unless adequate controls are in place for the security of your information.
Cookies
Cookies and the Do Not Sell or Share Right (CCPA)
Isograd Inc. does not sell the personal data of end users (candidates and administrators) for commercial purposes. However, our website uses advertising and analytics cookies from third-party providers (Google Ads, LinkedIn, YouTube, Facebook, Pardot) that may constitute “sharing” of personal data under the California Consumer Privacy Act (CCPA/CPRA).
If you are a California resident, you have the right to opt out of this sharing. You can exercise this right at any time by clicking the “Do Not Sell or Share My Personal Information” button available on this Site, or by adjusting your cookie preferences in our Privacy Center (Trust Badge).
This right applies to website visitor data only. It does not affect the processing of test or assessment data, which is handled separately and never sold or shared for advertising purposes.
We use three categories of cookies on this Site: Essential (required for the site to function), Analytics (with your consent), and Advertising (with your consent). For the full list of cookies we use, what they do, how to manage or disable them, and your consent choices, see our Cookie Policy.
Service Providers
We share personal data with our Service Providers only to the extent necessary for them to deliver services on our behalf. Service Providers are not permitted to use your data for their own purposes and must comply with confidentiality, security, and legal obligations consistent with this policy.
Our current Service Providers are:
| Provider | Location | Purpose |
|---|---|---|
| Amazon Web Services (AWS) | United States | Platform and data hosting |
| Integrity Advocate | Canada | Remote exam proctoring (where applicable) |
| Google Analytics | United States | Website analytics (with consent) |
| Google Ads | United States | Advertising (with consent) |
| United States | Social and advertising (with consent) | |
| YouTube | United States | Social and advertising (with consent) |
| United States | Social and advertising (with consent) | |
| Salesforce | United States | Marketing automation tracking |
| Hotjar | United States | Website analytics |
Questions about our Service Providers? Email us at support@isograd.com.
We Do Not Sell End-User Data
Isograd Inc. does not sell the personal data of end users (candidates or administrators).
We do not use end users’ personally identifiable information for commercial purposes or for advertising by Isograd Inc. or any third party. End-user data is shared only with: (1) the Customer that registered the end user (the data controller), and (2) Isograd Inc. (the data processor). We treat all personal data in the end-user database as strictly confidential, and we prohibit its dissemination or sale to third parties, during and after the term of any customer agreement.
Note: website visitor data collected through advertising and analytics cookies is governed separately. See the Cookies section above and our Cookie Policy for details.
Data Retention and Deletion
We retain personal data for 5 years by default. Customers may adjust the retention period from their account settings. When Isograd Inc. acts as the data controller (for candidates registered directly by us), the retention period is 4 years.
We will delete your data upon written request within 60 days of receiving the request, or according to a schedule agreed with the Customer where applicable. Deletion is complete and applies to all categories of personal data collected.
Your Privacy Rights
The data collected and generated through our websites and services belongs to our visitors, customer users (administrators), and their end users (candidates). As the owner of the personal information we collect, you have the following data protection rights:
| Right | What It Means |
|---|---|
| Right to Know | Know what personal data we have collected about you, where it came from, and why. |
| Right to Access | Request a copy of the personal data we hold about you. |
| Right to Correction | Ask us to correct inaccurate or incomplete data. |
| Right to Deletion | Ask us to delete your personal data (subject to legal retention obligations). |
| Right to Restrict Processing | Ask us to limit how we use your data in certain circumstances. |
| Right to Data Portability | Receive your data in a structured, machine-readable format. |
| Right to Object | Object to processing based on our legitimate interests. |
| Right to Withdraw Consent | Withdraw your consent at any time where processing is based on consent. |
| Right to Non-Discrimination | Not be penalized for exercising any of your privacy rights. |
| Right to Opt Out of Sale or Sharing | Opt out of the sale or sharing of your personal data for advertising purposes (see Cookies section above). |
If you are a California resident, you also have the right to know: the categories of personal data we collect and their sources; the business or commercial purpose for collecting it; the categories of third parties with whom we share it; and the specific pieces of data we hold about you.
How to Exercise Your Rights
Submit a Privacy Request
- Email: dpo@isograd.com
- Web: www.tosa.org
- Mail: Isograd Inc. – Privacy Team, 329 NE Couch St, Portland, OR 97232, USA
We may ask you to verify your identity before acting on your request. We will respond within 45 days. If we need more time, we will notify you within the first 45 days and may extend our response by up to an additional 45 days, with an explanation.
You also have the right to file a complaint with a data protection authority. For California residents: California Privacy Protection Agency or California Attorney General.
Students and Children’s Privacy
Isograd Inc. does not knowingly collect personally identifiable information directly from children under 13 without verifiable parental or guardian consent, in accordance with the Children’s Online Privacy Protection Act (COPPA). If you are a parent or guardian and believe your child has provided us with personal data without authorization, contact us at support@isograd.com immediately. We will investigate and delete any such data where required.
We provide services to educational institutions that may use our platform with students, including children under 13. In those cases, we act as a school official under FERPA and collect, use, process, and share student data only in accordance with COPPA, FERPA, and other applicable law. We rely on Customers to provide consent on behalf of parents or guardians as permitted by law. We do not use student data for any commercial purpose, targeted advertising, profiling, or onward disclosure.
How We Protect Your Data
Technical Infrastructure
Our testing platform, test items, and user data are hosted with Amazon Web Services (AWS). AWS infrastructure is designed and managed in accordance with security best practices and is certified under multiple standards, including:
- SOC 1/ISAE 3402, SOC 2, SOC 3
- FISMA, DIACAP, and FedRAMP
- PCI DSS Level 1
- ISO 9001, ISO 27001, ISO 27017, ISO 27018
The platform relies on the following components:
- Multiple front-end servers that deliver web pages
- Multiple in-application servers on which candidates take in-application questions
- Multiple Thinfinity servers that enable candidates’ browsers to connect to the in-application servers
- AWS CloudFront Content Delivery Network (CDN) for static assets and multimedia resources (images, videos, audio files)
- A redundant database hosted by AWS on the RDS service
The platform is accessible only over an encrypted HTTPS connection. The database is protected by a firewall that restricts access to authorized AWS security groups only. The database administration console is accessible only from a specific list of approved IP addresses. The front-end server is behind a firewall, and login is performed using an SSL public/private key system rather than passwords. The AWS administration console requires two-factor authentication with a hardware device. Daily encrypted database backups are retained for 2 years. System and test log files are transferred daily to redundant storage and retained for one year.
Data Anonymization
We maintain a formal process for anonymizing personal data:
- Automatic: after 5 years (or an earlier period set by the Customer), candidates’ names, first names, and emails are automatically replaced with anonymous identifiers in the database.
- Manual: administrators can anonymize a specific candidate’s data at any time from the candidate registration menu in their account.
Security Measures
Our security program includes the following safeguards:
- Access controls: multi-factor authentication (MFA) for all employee access; data access limited to employees performing relevant services.
- Security protocols: industry-standard protocols for all data transfers and transmissions. We do not copy, reproduce, or transmit data obtained through the services except as necessary to deliver them.
- Employee training: regular security and privacy training for all staff with access to personal data.
- Encryption: TLS/SSL or equivalent technology to protect data in transit; server authentication and data encryption in place across all environments.
- Data Protection Officer: our DPO is available at dpo@isograd.com.
- Vendor agreements: written contracts with all sub-processors requiring security and data protection commitments consistent with our standards.
- Periodic risk assessments: regular security and privacy assessments with timely remediation of identified vulnerabilities.
- Backups: encrypted backup copies maintained to protect against data loss.
The security of your account also depends on you. Please use a strong, unique password, keep your credentials confidential, and log out after using our services on a shared device.
Changes to This Policy
We may update this policy from time to time. If we make material changes — including adding new third parties with whom we share personal data — we will notify you on our website, by email, or by another method we determine is appropriate. Your continued use of the website or our services after the updated policy takes effect constitutes your acceptance of the new terms.
Isograd Inc. – Privacy Team
Email: dpo@isograd.com
Support: support@isograd.com
Mail: Isograd Inc., 329 NE Couch St, Portland, OR 97232, USA
Web: tosa.org/en/contact-us