Who we are
Integrevise Ltd provides AI-supported oral assessment technology to educational institutions.
Company: Integrevise Ltd
Company number: 16264734, registered in England & Wales
Registered office: Alacrity House, Kingsway, Newport, Wales, NP20 1HG, United Kingdom
General enquiries: info@integrevise.com
Data protection: privacy@integrevise.com
For any privacy question or request, contact our data protection team at privacy@integrevise.com.
Our role
Where you use Integrevise through your university or business school, that institution is the controller and Integrevise is the processor. The institution determines the purposes, lawful basis, participating users, configuration and use of results, and we act on its documented instructions under a written data processing agreement.
If you are a student, your institution is the first point of contact for any request relating to your assessment data, and we support the institution in responding.
Where you visit our website or contact us directly, Integrevise is the controller. We are also the controller for our own platform security and for pseudonymised technical and product telemetry relating to the operation of our platform.
| Data category | Integrevise role | Controller |
|---|---|---|
| User identity and profile | Processor | Your institution |
| Academic content | Processor | Your institution |
| Interaction data | Processor | Your institution |
| AI-generated data | Processor | Your institution |
| Proctoring and integrity events | Processor | Your institution |
| Performance and analytics data | Processor | Your institution |
| Technical logs and platform telemetry | Controller | Integrevise Ltd |
| Website visitors and enquiries | Controller | Integrevise Ltd |
1. User Identity & Profile Data
This covers names, institutional email addresses, user or student identifiers, roles and enrolment information. It is used to give users access, assign permissions and personalise the assessment experience. Users sign in with their institutional credentials; Integrevise does not use biometrics for login or authentication. The data is encrypted at rest and in transit, and role-based access controls ensure that only authorised individuals can see it.
2. Academic Content
Academic content includes student submissions, module materials, rubrics and tutor feedback. It is processed to configure the assessment, generate questions grounded in the supplied material and give authorised staff evidence for review. Access is restricted to authorised users, and rights in academic content remain with the institution and the student under their applicable terms.
3. Interaction Data
Interaction data includes audio captured during viva sessions, real-time transcripts and limited session metadata. Where a teacher enables recording for an assessment, it also includes recorded camera frames from the session. This data is processed solely to provide the Integrevise service, support tutor review, maintain session records, address technical or academic disputes and keep the platform secure. It is not used to train, fine-tune or improve internal or third-party AI models. The institution determines the lawful basis and configuration for any recording.
4. AI-Generated Data
AI-generated data includes question logs, follow-up prompts, analytical feedback, performance indicators, suggested grades and other system-generated content produced during viva sessions. It is processed solely to deliver the service, support tutor review and produce feedback reports for authorised staff. Integrevise does not use customer personal data or AI-generated data to train, fine-tune or improve third-party or internal AI models. Our AI providers do not use this data for model training and may keep it for up to 30 days solely to monitor for abuse and misuse.
5. Proctoring and Identity Verification
Proctoring is optional and is switched on or off by the institution, and for each assessment. Where it is enabled, the student's browser periodically compares the live camera image with a reference taken at the start of the session to confirm that the enrolled student is present. This comparison happens entirely on the student's device. The face data it uses is held in browser memory only and discarded when the session ends.
Integrevise does not store or receive biometric templates (hashed or otherwise), face descriptors or reference images. We receive only the outcome of each check (confirmed, inconclusive, mismatch or unavailable) and integrity event metadata covering browser focus, gaze direction, head pose, lighting and face presence. The platform does not perform emotion recognition.
Students are told before each session how the camera is used, whether recording is on and what is kept. A student can switch the camera off and still complete the assessment; identity checks are then recorded as unavailable. Because on-device identity comparison can still count as biometric processing under data protection law, the institution decides the lawful basis, notices and alternatives before enabling it.
6. Technical Logs
Technical logs record device and browser information, IP addresses, timestamps, error logs, API call details and security events. We process them, as controller, on the basis of our legitimate interests in debugging, monitoring security and keeping the service reliable. IP addresses are masked, identifiers are minimised or pseudonymised, and logs and telemetry are generally kept for no longer than three months.
7. Performance & Analytics Data
This category covers rubric scores, levels of understanding and aggregated performance trends used for institutional reporting, curriculum improvement and student support. Personally identifiable information is removed from aggregated analytics before they are shared with administrators, and access to analytics dashboards is restricted to authorised administrators.
8. Automated Decision-Making
Integrevise does not carry out automated decision-making that produces legal effects or similarly significant effects within the meaning of Article 22 of the UK and EU GDPR.
The platform produces analytical feedback, performance indicators and a suggested assessment of a student's responses. These outputs are advisory and are not released to a student until an authorised member of academic staff has reviewed them and chosen to release them. Staff may change or reject any output. Academic decisions, including grades, rest with the institution, and the human review step cannot be disabled.
Academic integrity signals follow the same model. Where an institution enables proctoring, the platform may record events for staff review. Such an event is a prompt for human review rather than a finding, does not interrupt the assessment, and has no bearing on the outcome by itself. Any academic misconduct process belongs to the institution and follows its own regulations.
9. Retention
Institution data, including assessment data, recordings and integrity event metadata, is kept for the period set in the institution's data processing agreement. At the end of that period it is returned or deleted, including from backups, unless the law requires us to keep it. Retention by our service providers is separate and does not extend this period.
10. Cross-Cutting Security Measures
Across all data categories, we collect only the data the service needs. Safeguards include encryption at rest and in transit, role-based access, multi-factor authentication for administrators, tenant isolation, audit logging of data access and changes, and vulnerability management. Integrevise holds Cyber Essentials Plus certification and commissions independent penetration testing every year. In a university-integrated environment, consent and notices are managed centrally by the institution. Regional compliance is ensured by storing data in servers that meet legal requirements (e.g., GDPR in the EU).
11. Your Rights and Complaints
You may have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. For assessment data, please contact your institution first, as it is the controller; we help it respond. For website enquiries, Integrevise telemetry or questions about this policy, contact privacy@integrevise.com.
You can also complain to a data protection supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk); in the EU, it is the authority in the country where you live or study.