Detailed insight into how IMP3RIAL EDU protects, isolates, and processes your institutional data securely.
Last updated: 9/29/2026
We only collect data that is strictly necessary for the operation of the educational platform. This includes:
Because IMP3RIAL EDU is an educational tool, it is used by minors. In legal terms, the School acts as the Data Controller, and IMP3RIAL EDU acts as the Data Processor.
It is the responsibility of the School to obtain verifiable parental consent before creating accounts for students under the age of 18 (or the applicable age of digital consent in your jurisdiction). We do not use student data for targeted advertising, we do not sell student profiles to third parties, and we do not track students outside of the platform.
IMP3RIAL EDU operates on a strict multi-tenant architecture powered by Supabase and PostgreSQL. Every single database table containing sensitive information utilizes Row-Level Security (RLS). This means that data isolation is enforced at the database engine level.
Your school's unique school_id binds all your records. It is cryptographically impossible for users from one school to query, view, or mutate the data of another school. All server-side actions utilize a verifyTenantOwnership protocol to prevent Insecure Direct Object Reference (IDOR) attacks.
To ensure academic integrity during Computer-Based Testing (CBT), our testing lobbies monitor specific client-side behaviors. During an active exam, we track:
IMP3RIAL EDU integrates LLMs via the Groq API to provide AI-Powered Educational Intelligence (e.g., Auto-Generated Teacher Comments).
When triggered, we securely transmit scores and prompts to Groq strictly for generation. We have zero-data-retention agreements in place: Groq does not use your school's academic data or student names to train their foundational models. We do not sell or share data with any other unauthorized third parties.
We believe administrators should have total sovereignty over their data. In the event your institution wishes to leave the platform, Super Admins have access to the Danger Zone.
Initiating a school deletion triggers custom cascading PostgreSQL functions. This executes an irreversible database wipe that instantly destroys all associated attendance logs, LMS assignments, CBT records, fee histories, and purges all user identities. We leave no orphaned data behind.
For any privacy-related inquiries, requests to delete personal data, or questions regarding this policy, please contact our Data Protection Officer at: contact@imp3rial.dev.