Privacy Policy
Effective date: 22 July 2026 · Last updated: 22 July 2026
Poseidon is operated by Emzini weCode, based in Bulawayo, Zimbabwe. This policy explains what data we collect, how we use it, and what rights you have over it.
Two things worth stating up front: Poseidon is a hosted service we run for your institution — you don't install or operate it — and no artificial intelligence or machine learning is applied to student work anywhere in the platform. Autograding runs the tests your instructors write; scanned exam sheets are read by deterministic image processing; our analytics are ordinary statistics.
1. Who We Are
Poseidon is a grading and assessment platform for educational institutions. We are built and operated by Emzini weCode (hereinafter "Poseidon", "we", "us", or "our"). For any privacy-related queries, contact us at privacy@emziniwecode.com.
2. Information We Collect
Account information
When you register or are invited to Poseidon, we collect your name, email address, institution affiliation, role (student, teaching assistant, instructor, or administrator), and — where your institution provides it — your student identifier. Passwords are stored as one-way cryptographic hashes — we cannot retrieve them. If you sign in with Google, we receive your Google account identifier and email address; we never receive your Google password.
Submission content
When students submit assignments, we store the submitted files — code, PDFs, essays, documents, or any other format permitted by the assignment. This content is associated with the submitting student's account and the relevant course.
Scanned exam material
Where your institution runs paper exams through Poseidon, we store the scanned images of answer sheets and exam papers, the marks read from them (including any student-identifier digits bubbled on the sheet), and the resulting scores. Scans are retained so that a disputed reading can be checked against the original paper.
Grades and feedback
We store grades, rubric scores, inline annotations, comments, regrade request history, and a record of which staff member applied which grading action and when. Where an assignment is completed in groups, we store group membership and any per-member grade adjustment.
Academic integrity records
Where staff raise an academic-integrity concern, we store that record: the reason codes selected, a severity, any written description or notes, the resulting status and outcome, and copies of integrity-related correspondence sent to the student through the platform. This is sensitive information and is treated as such — see section 5.
Administrative and billing data
For institutional administrators we additionally hold contact details, billing addresses, tax identifiers, purchase-order and payment references, and correspondence relating to your institution's licence.
Usage data
We collect standard technical data: pages visited, features used, browser type, device type, and timestamps. We also maintain an append-only event log of significant platform actions (such as a submission being made or a grade being published). This log deliberately holds identifiers only, never personal content, so that it can be kept for long-term trend analysis without accumulating personal information.
Cookies
Poseidon uses essential cookies to maintain authentication sessions. We do not use advertising or third-party tracking cookies, and we do not embed third-party analytics scripts — the charts you see in the platform are drawn from your institution's own data, in your browser. You may disable cookies in your browser, but doing so will prevent you from signing in.
3. How We Use Your Information
- Providing the service: storing and displaying submissions, grades, and feedback to authorised users within your institution.
- Communications: sending grade notifications, group and course announcements, weekly instructor summaries, password reset emails, and essential platform alerts.
- Platform improvement: analysing usage patterns, grading data, and assessment outcomes to improve the platform's features. This may include aggregated or de-identified analysis of submission content and grade distributions.
- Billing and account administration: measuring licensed usage, issuing invoices, and managing your institution's contract.
- Security and compliance: detecting abuse, fraud, or misuse of the platform.
4. Automated Analysis and At-Risk Flagging
Poseidon includes features that analyse course activity automatically and surface the results to your instructors. The most significant is at-risk flagging: once a week the platform looks for signals such as no recent activity, a missed assignment, or repeated failing runs followed by silence, and presents a ranked list to the instructor with the reasons for each entry.
We want to be precise about what this is and is not:
- It uses transparent, rule-based logic — not machine learning, and not a predictive score. Every flag shows the reason that produced it.
- It produces a prompt for a human, never a decision. Nothing is graded, penalised, reported, or actioned automatically. An instructor decides whether to reach out, and outreach messages can be edited before they are sent.
- It is visible to course staff only. Institutional administrators see aggregate counts, not named students.
Similarly, our item analysis (question difficulty, discrimination, and KR-20 reliability) is classical psychometrics applied to assessment quality — it evaluates your questions, not your students.
5. Academic Integrity Records
Academic-integrity records are the most sensitive data Poseidon holds, and they are handled under stricter rules than ordinary grading data:
- Poseidon does not detect or accuse. There is no AI-generated-text detector and no automated plagiarism verdict. A record exists only because a member of your institution's staff created it.
- Visibility is limited to course staff at the institution concerned. Records are never visible to other students, and institutional administrators see only aggregate counts.
- Every material action is logged — who raised the concern, who changed its status, who resolved it, and what correspondence was sent — so that a student subject to a process can be shown how it was conducted.
- Adjudication belongs to your institution. Poseidon records and structures the process; it does not determine guilt, penalty, or outcome.
Students have the same rights of access and correction over these records as over any other personal data we hold (see section 11), subject to your institution's own disciplinary procedures.
6. Research and Platform Improvement
As part of our mission to build better assessment tools, we may analyse grading data, assessment outcomes, and submission patterns to improve the platform's analytics features. This analysis is conducted by Poseidon staff and may include:
- Aggregated grade distributions and cohort performance metrics
- Rubric item quality and discrimination analysis
- Patterns in student submissions to improve autograding accuracy
Where possible, this analysis is conducted on de-identified or aggregated data. Individual student work is not shared publicly or sold to third parties under any circumstances.
Should we ever wish to publish research findings derived from institutional data, we will seek your institution's agreement and appropriate ethical approval first, and publish only aggregate results from which individuals cannot be identified.
7. Who We Share Data With
We do not sell your personal data. Within Poseidon, data is shared only as necessary for the platform to function:
- Instructors and TAs can see submissions, grades, and feedback for their courses. Teaching assistants may be restricted to rubric grading only.
- Students can see their own submissions, grades, and class-level statistics — and, on group assignments, the work and membership of their own group.
- Institutional administrators see aggregate course, member, usage, and billing information for their institution. They do not have access to student submissions, individual grades, or integrity records.
Service providers
We engage a small number of providers who process data on our behalf under confidentiality obligations, and we keep the list short deliberately:
- Hetzner Online GmbH — server infrastructure hosting the platform.
- Backblaze Inc. — storage of encrypted off-site backups. Backups are encrypted by us before they leave our infrastructure; the storage provider cannot read them.
- An email delivery provider — transmission of platform notifications and account emails.
We will update this list as it changes. We do not share personal data with any third party for their own marketing or commercial purposes, and we do not use student data to train any machine-learning model, ours or anyone else's.
8. Where Your Data Is Hosted
Poseidon runs on servers located in Germany, operated by Emzini weCode from Zimbabwe. Encrypted backups are stored with a separate provider in a different location, so that a failure of one does not take the other with it. If you are subject to a data-protection regime with specific cross-border transfer requirements, contact us and we will confirm the current arrangement in writing.
9. Data Retention
We retain your data for as long as your institution's account is active. Upon account closure or subscription expiry, data is retained for a further 12 months to allow for recovery or dispute resolution, after which it is permanently deleted. You may request earlier deletion at any time (see Your Rights below).
Deleted data may persist in encrypted backups for a limited period after removal from the live platform, until those backups age out of their retention window. Backups are never used to repopulate deleted records except during recovery from a genuine data-loss incident.
10. Security
We implement industry-standard security measures including encrypted data transmission (HTTPS/TLS), hashed password storage, and access controls that restrict data visibility to authorised users only. Each institution's data is logically isolated from every other institution's. Administrative and monitoring interfaces are not publicly reachable. Backups are encrypted before leaving our infrastructure, stored with a separate provider, and periodically test-restored — an untested backup is not a backup.
No system is perfectly secure; we will notify affected users promptly in the event of a data breach that poses significant risk.
11. Your Rights
Depending on your location, you may have the right to:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate information.
- Deletion: request deletion of your account and associated data (subject to institutional retention obligations).
- Objection: object to certain processing activities, including analytics.
- Portability: request your data in a machine-readable format.
To exercise any of these rights, contact us at privacy@emziniwecode.com. We will respond within 30 days.
Institutional administrators can file a data deletion or export request directly from the Trust section of their admin portal. Requests raised there are recorded and tracked through to resolution rather than disappearing into a mailbox. To be plain about what this is: filing a request opens a tracked case that we action — it is not instantaneous self-service erasure, because deletions affecting an institution's academic records deserve a human check first.
If you are a student, your first point of contact is normally your institution, which controls its own academic records and retention obligations. You may always contact us directly, and we will work with your institution to answer you.
12. Children's Privacy
Poseidon is designed for use in formal educational settings. Students under 13 must only use the platform through their institution, which is responsible for obtaining appropriate parental or guardian consent where required by applicable law.
13. Changes to This Policy
We may update this policy from time to time. We will notify registered users of material changes by email at least 14 days before they take effect. Continued use of Poseidon after the effective date constitutes acceptance of the updated policy.
14. Contact
For privacy questions, data requests, or concerns, contact:
Emzini weCode — Poseidon Privacy
privacy@emziniwecode.com
Bulawayo, Zimbabwe