Skip to content
Exam hall in a large warehouse building

Your students and staff's work is not training data

Your assessment data should only be used to run your assessments, and nothing else. At UNIwise, no model trains on it, no other institution sees it, and you decide how long it's kept. 

How your data stays yours

What students submit, what markers write, and the grades that follow all belong to your institution. The material is used to run your assessments and for no other purpose. You decide which AI features can reach it, and how long any of it is kept.

YOUR WORK NEVER TRAINS A MODEL

Training an AI model means feeding it large amounts of text so that it learns patterns from that text and carries them into everything it produces afterwards. We do none of that with your material.

Student submissions, marking, feedback, grades and the criteria you assess against are used to run your assessments, and for nothing else. They do not improve a model, they do not inform a product for another institution, and they do not leave your tenancy for that purpose.

This is written into the agreement your institution signs with us, which means it is enforceable rather than promised. It binds every company we work with to deliver the platform, so the commitment holds wherever your data travels inside the service.

AI ARRIVES SWITCHED OFF

Every AI feature in WISEflow is enabled by your institution, on your decision, at the point you are ready for it. None of them appear because we shipped them.

You choose which features are available, which staff can reach them, and which assessments they apply to. That control sits at licence level, so it holds across your institution rather than depending on individual choices made under time pressure.

Running WISEflow with none of them switched on is a normal and fully supported way to use the platform.

PEOPLE DECIDE, AI ASSISTS

AI-assisted feedback runs only after grading is finished. The assessor's grade and marking annotations are inputs to it, so there is no point at which AI could shape a mark that has not already been decided. What it drafts is the justification and the written feedback, and the assessor edits, regenerates or discards that draft as they see fit.

Nothing reaches a student until the assessor has actively assembled the final text themselves. That step is deliberate friction, built so that approving AI output can never become a reflex.

 

We build the features this way from the start rather than adding an approval step afterwards, because the academic judgement in marking is the part worth protecting.

NOTHING HAPPENS INVISIBLY

Your institution always knows which AI features are active, and the assessor always knows when one has been used. Where AI has helped draft feedback or a grade justification, the student is told so in WISEflow, and what reaches them is the assessor's approved text rather than raw AI output. 

Every action taken during an assessment, whether by a person or by an AI-assisted feature, is recorded with a timestamp. Your institution can export that record at any point, which is what turns a claim about oversight into something you can actually evidence, to a student, to an appeals panel, or to a regulator.

ACCESS FOLLOWS ROLE

Inside your institution, people see what their role requires and no more. A marker sees what a marker should see, and the permissions follow the structure you set rather than a default we chose.

At UNIwise, a small named group can reach the live system when there is a specific operational reason, such as investigating a fault you have reported. That access is logged, formally reviewed every six months, and limited to staff who have been background checked and who complete security training every year.

Your data is never shared with another institution unless you choose it. With Originality, your institution sets the scope of the comparison base: keep your submissions out of any shared set, compare only against your own institution's work, or contribute to a cross-institutional set. That decision sits with you, not with a default we set. 

DELETION ON YOUR SCHEDULE

Exam data is deleted automatically after two years. That covers resits, appeals and audit, and it happens without anyone having to remember to do it.

Institutions that need to keep assessment records longer, whether for internal policy or regulatory reasons, can retain them for the life of their agreement.

Where proctoring or biometric checks are used, recordings are held for six months at most, and your institution can set them to delete sooner, including the moment an assessment ends.

Where your data lives, and how we look after it

Control is one half of it. The other half is what we do with the material once it is in our care, and that comes down to deliberate choices about where it sits and how it is protected. 

TOUCH
European by architecture
European by architecture Your data is held in Ireland and Germany, run by AWS, and stored in three separate locations within each region so a single failure cannot lose it. It stays inside the EU.
TOUCH
Protected in transit and at rest
Protected in transit and at rest Data is encrypted while it travels and while it sits, using keys held by UNIwise. Amazon cannot access them, and neither can anyone without them.
TOUCH
Recoverable
Recoverable Backups are encrypted and retained, recovery is tested every year, and our uptime commitment is 99.9% with live and historical performance published openly.
TOUCH
Independently checked
Independently checked Our security management is certified to ISO/IEC 27001 and audited annually by an external body. The platform itself is tested by external security specialists every year.
TOUCH
Exportable on exit
Exportable on exit If you leave, you have a window to export everything before deletion. We then return the data or delete it and confirm in writing.
TOUCH
72-hour breach notice
72-hour breach notice If your data is ever compromised, we tell you within 72 hours, sooner where risk to people is high, with a written account of what happened and what changed. 

Built for what comes next

Assessment is about to be regulated more closely than it has been, and institutions will carry obligations of their own when they deploy AI in high-stakes decisions. We would rather you inherited a platform that already assumes this than one that adapts to it later.

That means the things regulation asks for are built in rather than added on. Every action in an assessment, by a person or by an AI-assisted feature, is captured and exportable, which is what makes any claim about oversight provable rather than asserted. Where you need to document how an AI feature works, what it is for, where its limits sit and how a person stays in control of it, we supply that information rather than leaving you to reconstruct it. And when your institution carries out its own assessment of the impact on students' rights, we support it with what we know about how the technology behaves.

Our view on where this is heading, and what it means for assessment, is set out in our writing on the EU AI Act.

EVERYTHING HERE IS VERIFIABLE

Claims about data are easy to make and harder to evidence. Our Trust Centre holds the certification, the data processing agreement, a data protection impact assessment for every AI feature in the platform, the full list of companies involved in delivering the platform, our privacy and cookie policies and our service commitments. If your data protection team needs something that is not there, ask and we will provide it.