Privacy Policy

1. Who We Are

Poseidon is a grading and assessment platform for educational institutions. We are built and operated by Emzini weCode (hereinafter "Poseidon", "we", "us", or "our"). For any privacy-related queries, contact us at privacy@emziniwecode.com.

2. Information We Collect

Account information

When you register or are invited to Poseidon, we collect your name, email address, institution affiliation, role (student, teaching assistant, instructor, or administrator), and — where your institution provides it — your student identifier. Passwords are stored as one-way cryptographic hashes — we cannot retrieve them. If you sign in with Google, we receive your Google account identifier and email address; we never receive your Google password.

Submission content

When students submit assignments, we store the submitted files — code, PDFs, essays, documents, or any other format permitted by the assignment. This content is associated with the submitting student's account and the relevant course.

Scanned exam material

Where your institution runs paper exams through Poseidon, we store the scanned images of answer sheets and exam papers, the marks read from them (including any student-identifier digits bubbled on the sheet), and the resulting scores. Scans are retained so that a disputed reading can be checked against the original paper.

Grades and feedback

We store grades, rubric scores, inline annotations, comments, regrade request history, and a record of which staff member applied which grading action and when. Where an assignment is completed in groups, we store group membership and any per-member grade adjustment.

Academic integrity records

Where staff raise an academic-integrity concern, we store that record: the reason codes selected, a severity, any written description or notes, the resulting status and outcome, and copies of integrity-related correspondence sent to the student through the platform. This is sensitive information and is treated as such — see section 5.

Administrative and billing data

For institutional administrators we additionally hold contact details, billing addresses, tax identifiers, purchase-order and payment references, and correspondence relating to your institution's licence.

Usage data

We collect standard technical data: pages visited, features used, browser type, device type, and timestamps. We also maintain an append-only event log of significant platform actions (such as a submission being made or a grade being published). This log deliberately holds identifiers only, never personal content, so that it can be kept for long-term trend analysis without accumulating personal information.

Cookies

Poseidon uses essential cookies to maintain authentication sessions. We do not use advertising or third-party tracking cookies, and we do not embed third-party analytics scripts — the charts you see in the platform are drawn from your institution's own data, in your browser. You may disable cookies in your browser, but doing so will prevent you from signing in.

3. How We Use Your Information

4. Automated Analysis and At-Risk Flagging

Poseidon includes features that analyse course activity automatically and surface the results to your instructors. The most significant is at-risk flagging: once a week the platform looks for signals such as no recent activity, a missed assignment, or repeated failing runs followed by silence, and presents a ranked list to the instructor with the reasons for each entry.

We want to be precise about what this is and is not:

Similarly, our item analysis (question difficulty, discrimination, and KR-20 reliability) is classical psychometrics applied to assessment quality — it evaluates your questions, not your students.

5. Academic Integrity Records

Academic-integrity records are the most sensitive data Poseidon holds, and they are handled under stricter rules than ordinary grading data:

Students have the same rights of access and correction over these records as over any other personal data we hold (see section 11), subject to your institution's own disciplinary procedures.

6. Research and Platform Improvement

As part of our mission to build better assessment tools, we may analyse grading data, assessment outcomes, and submission patterns to improve the platform's analytics features. This analysis is conducted by Poseidon staff and may include:

Where possible, this analysis is conducted on de-identified or aggregated data. Individual student work is not shared publicly or sold to third parties under any circumstances.

Should we ever wish to publish research findings derived from institutional data, we will seek your institution's agreement and appropriate ethical approval first, and publish only aggregate results from which individuals cannot be identified.

7. Who We Share Data With

We do not sell your personal data. Within Poseidon, data is shared only as necessary for the platform to function:

Service providers

We engage a small number of providers who process data on our behalf under confidentiality obligations, and we keep the list short deliberately:

We will update this list as it changes. We do not share personal data with any third party for their own marketing or commercial purposes, and we do not use student data to train any machine-learning model, ours or anyone else's.

8. Where Your Data Is Hosted

Poseidon runs on servers located in Germany, operated by Emzini weCode from Zimbabwe. Encrypted backups are stored with a separate provider in a different location, so that a failure of one does not take the other with it. If you are subject to a data-protection regime with specific cross-border transfer requirements, contact us and we will confirm the current arrangement in writing.

9. Data Retention

We retain your data for as long as your institution's account is active. Upon account closure or subscription expiry, data is retained for a further 12 months to allow for recovery or dispute resolution, after which it is permanently deleted. You may request earlier deletion at any time (see Your Rights below).

Deleted data may persist in encrypted backups for a limited period after removal from the live platform, until those backups age out of their retention window. Backups are never used to repopulate deleted records except during recovery from a genuine data-loss incident.

10. Security

We implement industry-standard security measures including encrypted data transmission (HTTPS/TLS), hashed password storage, and access controls that restrict data visibility to authorised users only. Each institution's data is logically isolated from every other institution's. Administrative and monitoring interfaces are not publicly reachable. Backups are encrypted before leaving our infrastructure, stored with a separate provider, and periodically test-restored — an untested backup is not a backup.

No system is perfectly secure; we will notify affected users promptly in the event of a data breach that poses significant risk.

11. Your Rights

Depending on your location, you may have the right to:

To exercise any of these rights, contact us at privacy@emziniwecode.com. We will respond within 30 days.

Institutional administrators can file a data deletion or export request directly from the Trust section of their admin portal. Requests raised there are recorded and tracked through to resolution rather than disappearing into a mailbox. To be plain about what this is: filing a request opens a tracked case that we action — it is not instantaneous self-service erasure, because deletions affecting an institution's academic records deserve a human check first.

If you are a student, your first point of contact is normally your institution, which controls its own academic records and retention obligations. You may always contact us directly, and we will work with your institution to answer you.

12. Children's Privacy

Poseidon is designed for use in formal educational settings. Students under 13 must only use the platform through their institution, which is responsible for obtaining appropriate parental or guardian consent where required by applicable law.

13. Changes to This Policy

We may update this policy from time to time. We will notify registered users of material changes by email at least 14 days before they take effect. Continued use of Poseidon after the effective date constitutes acceptance of the updated policy.

14. Contact

For privacy questions, data requests, or concerns, contact:
Emzini weCode — Poseidon Privacy
privacy@emziniwecode.com
Bulawayo, Zimbabwe