Last updated: June 5, 2026
Excellent processes student exam papers, so protecting that data is the whole job. This page explains, in plain language, how we handle it under U.S. FERPA and the EU GDPR. It is a description of our practices, not legal advice — schools remain the data controllers for their students' records, and Excellent acts as their processor.
Who we are
Processor: Excellent Notenspiegel, Oppenhoffallee 143, Aachen, Germany.
Controller: the school, district, or independent teacher operating the workspace that uploads the student work.
Contact for privacy: privacy@excellent.app
Excellent acts as a “school official” service provider under FERPA: we process student education records only to deliver grading to the teacher and school that uploaded them, and for no other purpose.
We do not disclose student records to third parties except the infrastructure providers required to run the service (database, file storage, and the AI grading model), each bound by their own data-protection terms.
For users in the EU/EEA and UK, Excellent acts as a data processor under GDPR Article 28. The school or teacher uploading the work is the data controller; we process personal data only on documented instructions to deliver grading.
Our lawful bases are performance of a contract with the school (Art. 6(1)(b)) and legitimate interests in operating and securing the service (Art. 6(1)(f)). We sign a Data Processing Agreement with Standard Contractual Clauses on request to cover any transfers outside the EEA.
We apply data minimisation: we collect only what is needed to grade — student name or ID, exam scans, answers, and scores — and we do not use student work for profiling or automated decisions with legal effects.
Data subjects (or the school acting on their behalf) can request access, rectification, erasure, restriction, portability, and objection for any personal data we process. We respond within 30 days.
You also have the right to lodge a complaint with your national supervisory authority (e.g. CNIL in France, BfDI in Germany, AEPD in Spain, ICO in the UK).
Every scan, answer, and report belongs to a single workspace and is protected by row-level security so it is visible only to members of that workspace.
Files are uploaded to private storage buckets — not public URLs — and access is granted through short-lived signed links. Data is encrypted in transit (TLS) and at rest. We maintain appropriate technical and organisational measures as required by GDPR Art. 32, and will notify the controller without undue delay in case of a personal data breach (Art. 33).
Student answers are sent to the grading model solely to produce scores and feedback for that submission. They are not used to train or fine-tune any AI model, and they are not sold or shared for advertising.
The teacher always reviews and can override the AI before any score is final — the AI suggests, you decide. This keeps grading outside the scope of GDPR Art. 22 (solely automated decisions).
You can delete a scan, a student, an exam, or your entire workspace at any time, which removes the associated records and files from storage. Retention follows the controller's instructions; by default we keep submissions only as long as the workspace exists.
On request we will help a school export or delete student data to support its own retention, records, and GDPR erasure obligations.
We use a small number of vetted infrastructure providers — categorised generically below — each bound by their own data-protection terms. A current, named list is available on request as part of a Data Processing Agreement.
| Role | Purpose | Location |
|---|---|---|
| Database & file storage provider | Stores workspace records, exam scans, answers, and reports under row-level isolation. | EU / US regions |
| AI grading model provider | Receives exam questions and answers solely to return scores and feedback for that submission. | US |
| Hosting & CDN provider | Serves the application and static assets globally over TLS. | Global edge network |
| Transactional email provider (paid plan only) | Delivers report emails and teammate invitations on workspaces using paid features. | EU / US regions |
Some of our sub-processors operate outside the EEA, primarily in the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses (Module 3, processor-to-sub-processor), supplemented by the technical and organisational measures described under Security.
A signed DPA including SCCs is available to schools on request via privacy@excellent.app.
Controllers can instruct us to apply different retention via the DPA.
Excellent is built for school use. Student records uploaded to a workspace are processed under the school's authority — the school is the controller and obtains any consents required from parents or legal guardians.
Under FERPA, we act as a “school official” service provider. Under GDPR Art. 8, the age of digital consent varies by Member State (13–16); the school's consent framework, not direct child consent, is the lawful basis for our processing.
We use only essential cookies and local storage — to keep you signed in and to remember your cookie-notice preference. No analytics, no advertising, no third-party tracking. This privacy notice is the current source of truth for browser storage.