Legal

Privacy Policy

Last updated: July 2026

This is a draft policy pending legal review.

1. Who we are

Neuroxa.ai (“Neuroxa”, “we”, “us”) provides an AI-powered remote proctoring platform used by employers and educational organizations (our “Customers”) to monitor assessments, interviews, and meetings. When you take a proctored session, Neuroxa generally processes your data on behalf of the Customer who invited you, acting as a data processor; the Customer is the data controller. This policy explains what we collect and how we handle it.

2. Data we collect

Depending on how a session is configured, we may collect:

  • Video and audio recordings of your session, captured via your webcam and microphone
  • Screen recordings and browser activity signals (tab switches, copy/paste events, window focus)
  • Identity documents (e.g., a government-issued ID) when the Customer enables ID verification
  • Biometric face templates used to match your live image to your ID document and to detect the presence of additional persons
  • Account and contact information such as name and email address
  • Technical data such as IP address, device and browser type, and session logs

3. How we use it

We use session data solely to deliver the proctoring service: to verify identity, monitor sessions for integrity violations, generate trust reports and flagged-event timelines for the Customer, and improve the reliability of our detection systems. We do not sell personal data, and we do not use candidate session recordings for advertising.

4. Biometric data

Face templates are mathematical representations derived from images; they are used only for identity matching and presence detection within your session. They are encrypted, are not shared with third parties for their own purposes, and are deleted at the end of the applicable retention period or earlier upon a valid deletion request from the Customer.

5. Retention

By default, session recordings and analysis artifacts are retained for the period set by the Customer’s plan and configuration, after which they are permanently deleted. Enterprise Customers can configure custom retention windows and execute a Data Processing Agreement (DPA) with us. Account data is retained for as long as the account is active.

6. Subprocessors

We use a small set of vetted subprocessors to run the service, including cloud hosting and storage providers, speech-to-text transcription providers, AI model providers used for session analysis, meeting-bot infrastructure that enables the AI Meeting Proctor to join Zoom, Teams, and Meet calls, and email delivery services. Each is bound by contractual obligations at least as protective as this policy. A current list is available on request.

7. Your rights

Depending on your jurisdiction (including under the GDPR and similar laws), you may have the right to access, correct, delete, or receive a copy of your personal data, and to object to or restrict certain processing. Because we usually act as a processor, we may direct your request to the Customer who administered your session, and we will assist them in fulfilling it. Contact us at privacy@neuroxa.ai.

8. Education and FERPA

When our platform is used by educational institutions, we handle student records in accordance with the Family Educational Rights and Privacy Act (FERPA) as a “school official” under the institution’s direct control, using education records only to provide the contracted service.

9. Security

All data is encrypted in transit (TLS) and at rest. Access to session recordings is restricted to authorized Customer users and a limited set of Neuroxa personnel under least-privilege access controls, with audit logging. We maintain incident response procedures and will notify affected Customers of any personal data breach without undue delay.

10. Changes and contact

We may update this policy from time to time; material changes will be announced on this page with an updated date. Questions or requests: privacy@neuroxa.ai.