Skip to main content

Security & compliance

What happens to a script once you upload it.

You’re uploading real student work. Here’s exactly where it goes, how long we keep it, and who’s responsible for it, in plain terms.

Your data stays in the EU

Assessment files, marks, and account data are stored on infrastructure in the EU/EEA. Nothing is routed through servers outside the UK/EU for storage.

Encrypted

Traffic to and from GradeDrive runs over TLS. Uploaded PDFs and results sit in storage that's encrypted at rest and blocked from public access by default, not left open and relying on an unguessable URL.

Your content trains nothing

Mark schemes and student submissions are processed to produce your marks and nothing else. We don't use them to train our models or feed them back into the underlying AI providers' training data.

Data doesn't linger

Student data is kept for 18 months from upload and then removed, or sooner if you delete it yourself. Deleting your account removes stored files and results and anonymises what's left of the account record.

Your school is the controller. We’re the processor.

Under UK GDPR and EU GDPR, your school or you as a teacher decide why student data is uploaded and what happens to the results, that makes you the Data Controller. GradeDrive only processes that data to produce marks and feedback on your instructions, that makes us the Data Processor, governed by the Data Processing Addendum in our Terms of Service.

In practice that means: a subject access or erasure request about a student’s marked work should go to the school or teacher who uploaded it, and we’ll assist manually once it’s verified. Requests about your own account go straight to us through Contact. Either way, you can lodge a complaint with the ICO if you’re not satisfied with how a request was handled.

Still have a security & compliance question?