Who we are and when this policy applies
This Privacy Policy (the “Policy”) sets out how personal data is handled in IVY TEST, operated by 株式会社CS&E (“CS&E,” “we,” “us,” or “our”), including the IVY Academy OS teacher service, student testing and study services, websites, applications, APIs, and related services (collectively, the “Services”).
Representative Director & CEO: Yeon June Jeong
Lark Hill, 4-7 Kawadacho, Shinjuku-ku, Tokyo 162-0054, Japan
developer@csne.co.jp
- Google Cloud Platform supports application infrastructure and the primary production data location is configured in Japan; Supabase provides hosted PostgreSQL data services.
- We do not sell personal data for money or share it for cross-context behavioral advertising.
- Managed exams may record operational events, but IVY TEST does not activate the webcam or record continuous screen video. Speaking may record microphone audio after the required notice and consent.
- AI may assist with transcription, preliminary grading, feedback, and analysis; materially consequential automated results may be submitted for human review.
- Minors may use the Services only under the authorization and guardian-consent rules that apply to their location.
- Stripe or another disclosed provider may process payments. We do not store full payment card numbers.
- Public product walkthroughs use fixed, non-personal illustrative records or reconstructions, not live student records.
This Policy applies when you use the Services directly, receive access through a school, academy, teacher, employer, or other organization (“Institution”), communicate with us, or visit our public websites. It does not govern a third party’s independent services.
Our role and the Institution’s role
For individual accounts purchased or created directly with us, CS&E generally determines why and how personal data is processed and acts as the controller or equivalent business under applicable law.
For Institution-managed accounts, the Institution generally decides the educational purpose, roster, assignments, retention instructions, and people who may access records. CS&E processes those records for the Institution under its instructions and contract, except for security, billing, fraud prevention, legal compliance, and product administration activities for which CS&E may act independently.
Questions about an Institution’s educational decisions or access to Institution-controlled records should first be directed to that Institution. We will assist the Institution with valid requests.
Personal data we collect
- Account and identity data: name, login ID, email, role, organization, class, school, grade, preferred language, guardian relationship, authentication and account-recovery data.
- Educational records: enrollment, attendance, homework, counseling and intervention records, answers, drafts, scores, rubrics, feedback, reports, teacher decisions, retakes, accommodations, and changes to those records.
- Exam content and activity: assigned tests, question position, module route, answer changes, response time, remaining time, pause and resume events, submission receipts, grading history, and report publication history.
- Speaking audio: microphone audio recorded throughout the Speaking section, individual task recordings, audio duration, upload and recovery status, transcripts, pronunciation and scoring signals, and teacher feedback.
- Exam operations telemetry: online or offline state, last synchronization time, browser visibility or focus changes, full-screen status where used, device and browser type, operating system, network latency, recording state, and error events.
- Communications: messages among students, guardians, teachers, and support staff; delivery status; templates; support requests; and consent or notice records.
- Technical and security data: IP address, session and cookie identifiers, timestamps, audit logs, access-control events, diagnostics, crash reports, and suspected abuse or security events.
- Transaction data: plan, order, subscription, payment status, invoice, refund, and tax-related records. Full payment card numbers are handled by the payment provider and are not stored by us.
- Derived data: progress trends, skill estimates, difficulty-response patterns, cohort comparisons, risk or intervention indicators, and preliminary AI-generated scores or feedback.
Where data comes from
We receive data from you; a parent or guardian; an Institution and its authorized educators or administrators; your browser or device when you use the Services; payment and identity providers; and service providers acting for us. We may also create analytics and operational records from your use of the Services.
An Institution must have authority to provide roster, guardian, and educational data to us and must give required notices or obtain required consent before assigning an account.
Why we process data
| Purpose | Examples | Typical legal basis |
|---|---|---|
| Deliver the Services | Accounts, classes, exams, saving answers, grading, reports, messages, subscriptions | Contract; steps requested before contract; Institution instructions |
| Run fair and reliable exams | Timers, synchronization, focus events, submission receipts, recovery, incident review | Contract; legitimate interests; consent where required |
| Personalize learning | Progress analytics, content recommendations, skill and difficulty models | Contract; legitimate interests; consent where required |
| Protect users and the Services | Authentication, access control, fraud and abuse prevention, diagnostics, audit trails | Legitimate interests; legal obligations |
| Operate the business | Billing, support, service notices, compliance, dispute handling | Contract; legal obligations; legitimate interests |
| Improve the product | Aggregated quality analysis, reliability and accessibility testing | Legitimate interests; consent where required |
Where consent is the legal basis, you may withdraw it for future processing. Withdrawal does not affect processing that was lawful before withdrawal. Certain data is necessary to provide an exam or maintain an authoritative educational record; if it is not provided, the relevant feature may be unavailable.
Exam monitoring and Speaking recordings
During a managed exam, authorized educators may see a near-real-time reconstruction of exam status, including the current section or question position, answers saved, progress, time remaining, synchronization health, device type, focus or visibility events, and recording status. This is a semantic status view, not a live video feed of the student’s screen.
When a Speaking section begins, IVY TEST may record microphone audio continuously until the Speaking section is completed or exited. Continuous capture helps recover an answer if a task recording is interrupted and helps investigate clipping, silence, upload failure, or grading failure. Audio may be replayed by authorized educators and processed to create a transcript, preliminary score, feedback, and quality evidence.
We do not use exam telemetry or Speaking audio for advertising. Institutions must notify students and guardians before a monitored exam. Where local law requires consent, the exam cannot begin until valid consent is recorded or an approved alternative is arranged.
In Japan, we display a consent confirmation screen before the exam begins and obtain explicit consent. Consent may be withdrawn prospectively, but doing so may prevent the learner from taking an exam that includes a Speaking section.
AI-assisted grading and analytics
We use Google Gemini and other Google Cloud services to assist with transcription, preliminary grading, feedback, content quality checks, and educational analytics. We may also use Google Gemini, OpenAI services, and Anthropic Claude services for content development and quality review, including candidate question work. The provider used depends on the task and configuration; we do not send every record to every provider. AI output may be incomplete or incorrect. It is not an official SAT®, TOEFL®, school, admissions, or government score.
For Institution-managed assessments, a teacher or authorized reviewer can inspect evidence, retry failed processing, change or confirm a score, and control publication. A student or guardian may ask the Institution or CS&E for human review of a materially consequential automated result. We retain model, rubric, revision, and reviewer information where needed to explain the result.
We do not permit third-party providers to use student personal data for targeted advertising. Whether submitted content is retained or used to improve a provider model depends on the contracted provider, service, and configuration; CS&E selects business-grade settings and limits submitted data to what is needed for the feature.
Children and student accounts
Our Services are designed for learners, including minors. We apply the age threshold and authorization rules of the learner’s location.
- Institution-managed accounts: the Institution represents that it has authority to create or assign the account and has delivered notices and obtained guardian consent where required. The data may be used only for the authorized educational purpose.
- Direct consumer accounts: users below the applicable digital-consent age may register only through a verified parent or guardian flow. In the United States this generally includes children under 13 under COPPA; in Korea, legal guardian consent is required for children under 14.
- Parents and guardians may request access, correction, deletion, or an end to further collection, subject to school record obligations and applicable law.
- We do not show behavioral advertising, sell children’s data, or require more child data than reasonably necessary for the relevant educational activity.
When we disclose data
We may disclose personal data in the following circumstances:
- With the individual’s consent. Within the scope agreed in advance, we may provide educational records, exam activity, grading information, and related records to authorized students, guardians, educators, administrators, graders, and support staff according to role and Institution settings. Consent is obtained through the applicable service-start or Institution consent screen and may be withdrawn prospectively.
- To processors and service providers. Without separate consent where permitted, we provide only the data necessary to contracted providers that are subject to confidentiality and security obligations, as described in Section 10.
- Where required by law. Without consent where permitted, we provide the information required in response to a lawful request from a competent authority.
- For a business transfer. Without consent where permitted, we may provide information necessary for business continuity to a successor in a merger, company split, or other reorganization.
Method of disclosure: electronically, including API integration and encrypted transmission, or in writing.
You may withdraw consent or request that future disclosure stop where disclosure is based on item 1. We do not sell personal data for money and do not share personal data for cross-context behavioral advertising.
Key service providers
| Provider | Purpose | Relevant data |
|---|---|---|
| Supabase | Hosted PostgreSQL database and related data services | Accounts, organizations, educational records, operational data |
| Google Cloud Platform | Application hosting, storage, secrets, speech recognition, text-to-speech, authentication and infrastructure | Service records, files, audio, technical and authentication data |
| Google Gemini API | AI-assisted grading, feedback, transcription support, analysis and content quality | Responses, audio or transcripts, rubrics, limited learning context |
| OpenAI | Content development, review and quality assurance | Content-development prompts, drafts, rubrics and limited reference material |
| Anthropic (Claude) | Content development, review and quality assurance | Content-development prompts, drafts, rubrics and limited reference material |
| Sentry, when enabled | Error and reliability diagnostics | Error context, device and technical data; we configure diagnostic collection to minimize personal data |
| Stripe, when used | B2C payment and subscription processing | Customer, transaction, fraud and payment data |
Our current subprocessor list and material changes will be made available through this Policy or a linked service notice. Institution contracts may include additional notice commitments.
Storage in Japan and international transfers
We configure the primary production data location in Japan. Because our users and providers operate internationally, personal data may be accessed or processed outside your country for support, security, communications, payments, or specific cloud and AI functions. We review the personal-information protection systems of the relevant foreign countries and implement appropriate security safeguards in light of those systems.
We use the transfer mechanism required by applicable law, such as consent after providing required transfer information, adequacy decisions, contractual safeguards, processor agreements, or equivalent protection measures. For Korean users, required information about overseas recipients, countries, purposes, items, timing, method, and retention is provided in this Policy, an Institution notice, or a separate transfer notice. For EEA and UK transfers, we use an available adequacy mechanism or approved contractual safeguards where required.
How long we keep data
| Record | Default period |
|---|---|
| Speaking source audio | 180 days after the exam, unless an Institution selects a shorter period or a dispute, accommodation, safety, or legal hold requires longer |
| Answers, scores, grading evidence and reports | 3 years after the assessment or as instructed under an Institution contract |
| Score changes, publication receipts and authoritative audit records | 3 years, or longer when required to establish or defend legal claims |
| Exam focus, synchronization and technical telemetry | 12 months |
| Support and consent records | 2 years after account cancellation or closure of the relevant support matter, unless a longer period is necessary for a dispute or legal obligation |
| Payment, invoice and tax records | The period required by applicable accounting, tax and consumer law |
| Deleted account data | Removed from active systems within 30 days after a valid request; encrypted backups expire or are isolated within 90 days, unless retention is legally required |
An Institution may configure a shorter period or require a longer lawful period. We may de-identify data so it can no longer reasonably identify a person; de-identified data may be retained for quality, research, and statistical purposes.
Security and incident response
We maintain safeguards appropriate to the nature of the data:
- Organizational safeguards: appointment of a privacy officer, internal handling rules, responsibility allocation, access reviews, and incident-response procedures.
- People safeguards: training for personnel and confidentiality obligations.
- Physical safeguards: restrictions on access to areas, devices, media, and documents that may contain personal data, together with theft and loss prevention.
- Technical safeguards: role-based access control, tenant separation, encrypted transport, managed cloud encryption, secret management, logging, backups, recovery controls, and protection against unauthorized access.
No system is completely secure, and we cannot guarantee absolute security.
If a personal-data incident occurs, we will investigate, contain, preserve evidence, and notify affected Institutions, users, and regulators when required. Notification timing and content follow the law applicable to the affected person, including Korea’s reporting and notification requirements where applicable.
Your choices and regional rights
Depending on your location and our role, you may request access, a copy, correction, deletion, processing restriction, objection, data portability, withdrawal of consent, or review of an automated result. You may also lodge a complaint with your local privacy regulator.
- Japan: rights under the Act on the Protection of Personal Information (APPI), including disclosure, correction, suspension of use, deletion, and information about certain foreign transfers.
- Korea: rights under the Personal Information Protection Act (PIPA), including access, correction or deletion, suspension, withdrawal, and rights relating to automated decisions and overseas transfers where applicable.
- United States: parents may exercise COPPA rights for children under 13. Residents of states with comprehensive privacy laws may have access, deletion, correction, portability, opt-out, and appeal rights, subject to exemptions.
- EEA and United Kingdom: GDPR or UK GDPR rights and the right to complain to a supervisory authority. Where applicable, you may object to legitimate-interest processing or ask not to be subject to a solely automated decision producing legal or similarly significant effects.
Send a request to developer@csne.co.jp. We may verify identity and authority before acting. For Institution-controlled data, we may forward the request to the Institution. We will not discriminate against you for exercising a privacy right.
Cookies, advertising, and communications
Our web Services use strictly necessary cookies or similar local storage for sign-in, security, preferences, recovery, and exam continuity. We do not use third-party behavioral advertising trackers in student testing surfaces. If we later introduce non-essential analytics or marketing cookies in a region requiring consent, they will remain off until you choose them.
Operational and legal notices are part of the Services. Marketing communications, if offered, use a separate preference and can be stopped without affecting essential service messages.
Changes, questions, and complaints
We may update this Policy as the Services, providers, or laws change. We will post the new version and effective date and provide additional notice before a material change when required. We will seek new consent if a new purpose is incompatible with the notice or consent previously provided.
株式会社CS&E (CS&E INC.)
Privacy Officer: Representative Director & CEO Yeon June Jeong
Lark Hill, 4-7 Kawadacho, Shinjuku-ku, Tokyo 162-0054, Japan
developer@csne.co.jp