This Privacy Policy explains how Viva Proof, Inc. ("Viva," "we," "us") collects, uses, and protects personal data when you use the Viva oral-assessment platform at vivaproof.com.
1. Who We Are
Viva Proof, Inc. is a Delaware-incorporated company that operates the Viva AI oral-assessment platform, serving educational institutions globally.
Contact us: privacy@vivaproof.com
Boston, MA, USA
UK/EU Representative: to be appointed (for enquiries, contact privacy@vivaproof.com)
2. Our Role: Controller vs. Processor
Viva acts as a data processor for student data. The school or university is the data controller for all student-related personal data. Viva processes student data only on the school’s instructions, under a Data Processing Agreement.
Viva acts as a data controller for its own business data (accounts, billing, analytics).
3. Data We Collect and Why
A. Student Data (Viva as Processor, on behalf of your school)
| Type of Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Name, school email, class details | Account creation; assessments | School instruction | Per school contract |
| Submitted work (assignments, essays) | Generating interview questions; grading | School instruction | Per school contract |
| Voice recording (oral interview) | Transcription; teacher review; identity check | School instruction; explicit consent for biometric use | Deleted within 30 days of session |
| Interview transcript | AI grading; teacher review; student feedback | School instruction | Contract term + 1 year |
| AI-suggested grade and teacher grade | Academic record; feedback | School instruction | Contract term + 1 year |
| Session metadata (timestamps, duration) | Operational monitoring | School instruction | Contract term + 1 year |
| Voiceprint (optional, consent-required) | Identity verification only | Explicit consent obtained by school | Earlier of: purpose satisfied; 90 days after account closure or contract end; or 3 years after last interaction |
| Video-integrity signals and flagged still images (optional, consent-required) | Deriving attention and presence signals to flag possible integrity concerns to the teacher. Not used for identification or grading. See Section 9B. | Explicit consent obtained by school, to the extent the signals or images constitute biometric/sensitive data | Same schedule as the associated interview record; or earlier on the school's request |
B. Teacher / Administrator Data (Viva as Controller)
| Type of Data | Purpose | Retention |
|---|---|---|
| Name, email, role, login credentials | Account management; service delivery | Account lifetime; deleted within 90 days of account closure |
C. Website Visitor Data (Viva as Controller)
| Type of Data | Purpose | Retention |
|---|---|---|
| IP address, browser type, pages visited | Website security; analytics | Per analytics provider settings (see Cookie Policy) |
D. Billing Data (Viva as Controller)
| Type of Data | Purpose | Retention |
|---|---|---|
| Institution billing contact; usage metrics | Invoicing; account management | Per applicable tax/accounting requirements |
Viva does not store payment card data. Card processing is handled by Stripe.
4. How We Use Your Data
We use personal data to:
- Provide and operate the Viva platform
- Generate personalised interview questions and AI-suggested grades
- Support teacher review, feedback delivery, and classroom management
- Detect and flag potential academic integrity issues (advisory only — a teacher always reviews)
- Maintain platform security
- Send transactional service emails (assessment reminders, account notifications)
- Improve the platform (only with explicit permission from your school)
- Comply with legal obligations
We do not use personal data for advertising, sell data to third parties, or train AI models without an explicit grant from your school. We do not infer emotions from biometric data in an educational setting — a practice prohibited under Article 5 of the EU AI Act.
5. Who We Share Data With
Your school. Teachers and authorised administrators can see student data, including the audio recording of a student's oral interview (accessible within the platform for up to 30 days, for assessment purposes only).
Subprocessors. We engage trusted third-party service providers to operate the Platform. Subprocessors are primarily based in the United States; Supabase and PostHog each offer EU/UK data residency options. Each subprocessor is bound by a written data processing agreement. Our current subprocessors are:
| Provider | Role | Location | SOC 2 |
|---|---|---|---|
| Anthropic (Claude) | AI interviewing, question generation, and grading (inputs and outputs deleted within 30 days; not used for model training) | US | Type II ✓ |
| AWS (Amazon Web Services) | Secondary AI evaluation and quality-assurance cross-checks (tie-breaker model) | US | Type II ✓ |
| Cartesia | Korean voice synthesis for live interviews | US | Type II ✓ |
| Daily.co | Real-time audio transport (WebRTC) for live interviews | US | Type II ✓ |
| Deepgram | Speech-to-text and English voice synthesis for live interviews | US | Type II ✓ |
| Fal.ai | AI image generation for anti-cheat visual questions (prompts may be derived from student work) | US | Type II ✓ |
| Secondary AI evaluation and quality-assurance cross-checks; image generation for anti-cheat visual questions | US | Type II ✓ | |
| Microsoft | Office document viewer (fallback previews for legacy Office formats) | US | Type II ✓ |
| OpenAI | Secondary AI evaluation and quality-assurance cross-checks | US | Type II ✓ |
| PostHog | Product analytics (consent-gated) | US / EU | Type II ✓ |
| Render | Speaker-verification (voiceprint), document text extraction, OCR, and document-to-PDF conversion microservice | US | Type II ✓ |
| Resend | Transactional email | US | Type II ✓ |
| Sentry | Error monitoring (PII scrubbed before write) | US | Type II ✓ |
| Stripe | Billing (Viva does not store card data) | US | Type II ✓ |
| Supabase | Database, authentication, file storage | US / EU-UK available | Type II ✓ |
| Vercel | Application hosting | US | Type II ✓ |
Slack. Viva uses Slack for internal operational alerting (system health, usage metrics, and de-identified product-feedback summaries). No Student Data or other personal data is transmitted to Slack, so Slack is not acting as a subprocessor of personal data under this Privacy Policy.
The optional video-integrity feature performs face and gaze analysis locally in the student's browser; the live video is not transmitted to Viva or to any subprocessor. The only subprocessor that receives voiceprint data is Render.
Legal authorities. We may disclose data if required by law, court order, or regulatory authority.
We do not sell or commercially exploit personal data.
6. International Transfers
Viva is based in the United States. When student data is transferred to Viva or its subprocessors from outside the US, we ensure such transfers comply with applicable law in your jurisdiction.
For institutions in the EEA and UK, transfers are protected by EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum (IDTA), with supplementary measures (encryption, access controls, data minimisation).
For institutions in jurisdictions with specific cross-border data transfer requirements, including (but not limited to) the Republic of Korea under PIPA Article 28-8, the EEA under EU GDPR Article 46, and others, Viva works with the institution to put appropriate transfer mechanisms in place. Where required, a jurisdiction-specific addendum to the Data Processing Agreement is executed alongside the Master Service Agreement.
For a copy of the transfer documentation applicable to your jurisdiction, or to request in-region data residency where available, contact privacy@vivaproof.com.
7. Your Rights
Depending on where you live, you may have the right to:
- Access — request a copy of the data we hold about you
- Correction — request correction of inaccurate data
- Deletion ("Right to be Forgotten") — request deletion of your data, subject to your school's legal record-keeping requirements
- Restriction — ask us to limit how we process your data
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- No automated decision-making — Viva does not make final grading decisions automatically; a teacher always reviews
For students: please contact your school first. They are the data controller and will liaise with Viva on your behalf.
For parents/guardians: if your child is below the age requiring additional consent where you live (see Section 8), contact your child's school.
To exercise rights directly: privacy@vivaproof.com
You may also have the right to complain to your local data protection supervisory authority, for example:
- EEA: your national Data Protection Authority (edpb.europa.eu for a list)
- UK: Information Commissioner’s Office (ico.org.uk)
- US: Federal Trade Commission (ftc.gov)
- Korea: Personal Information Protection Commission (pipc.go.kr)
- Other jurisdictions: contact your national data protection authority
8. Children’s Privacy
The platform is designed for students aged 14 and older.
Schools are responsible for obtaining any additional consent required under applicable law for younger students. Requirements vary by jurisdiction, for example:
- Under 13 (US COPPA / UK GDPR): Schools are responsible for obtaining verifiable parental consent before enrolling students under 13.
- Under 14 (Korea PIPA): Where a school enrols students under 14, the school is responsible for obtaining legal guardian consent before their data is processed.
- Under 16 (some EU member states): School-specific consent rules may apply.
- Under 18 — biometric features (UK schools and colleges): Where a school or college in England or Wales enables the optional voiceprint or video-integrity feature, the Protection of Freedoms Act 2012 requires it to notify every parent and obtain the written consent of at least one parent before biometric data is processed for a student under 18. A student may refuse regardless of parental consent, and the school must provide a reasonable alternative without detriment.
If you believe a child's data has been collected in error, contact privacy@vivaproof.com immediately.
9. Security
We protect your data with:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Per-school tenant isolation via row-level database security
- Least-privilege access controls and audit logging
- Automated vulnerability scanning
- Breach notification to affected schools within 72 hours of becoming aware
No system is perfectly secure. If you discover a security issue, please report it to privacy@vivaproof.com.
For how Viva handles biometric data specifically — the voiceprint and the optional video-integrity feature — see Sections 9A and 9B below.
9A. Biometric Data (Voiceprint)
Where a school enables the optional voice-identity verification feature, Viva creates a voiceprint — a mathematical template derived from a short voice sample. A voiceprint is treated as biometric data wherever it is collected: it is a biometric identifier under the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14) and the Texas CUBI Act; biometric data under UK/EU GDPR Article 9; and sensitive information under Korea PIPA Article 23. (Washington's RCW 19.375 names voiceprints but excludes data generated from an audio recording; Viva applies these protections regardless.)
Purpose. The voiceprint is used solely to verify that the student taking an assessment is the student who submitted the work, and to flag possible impersonation to the teacher. It is never used for grading, and never for any other purpose.
Consent. Voiceprint processing requires separate, explicit consent, obtained by the school before the feature is enabled. That consent covers both Viva's collection and storage of the voiceprint and its disclosure to Render, the provider that performs the speaker-verification computation on Viva's behalf. Where the student is a minor, a parent or guardian's consent is required. Consent may be withdrawn at any time, and a student may decline without penalty; the school then assesses them another way.
Illinois. For schools in Illinois, the voiceprint feature is disabled by default and may be enabled only under a BIPA Rider to the Master Service Agreement, after a written release satisfying 740 ILCS 14/15(b).
Retention and destruction. Viva permanently destroys voiceprint data on the first to occur of: (a) satisfaction of the purpose for which it was collected; (b) 90 days after the student's account closure or contract termination; or (c) three years after the student's last interaction with Viva. Destruction means permanent deletion from primary storage and all backups, irreversibly. Viva provides written confirmation on request.
Disclosure and profit. Viva does not sell, lease, trade, or profit from biometric identifiers. It does not disclose voiceprint data except: (i) to Render, with the consent described above, to perform speaker verification on Viva's behalf; (ii) where required by law or municipal ordinance; or (iii) under a valid warrant or subpoena.
9B. Video-Integrity Signals (Gaze and Presence)
Where a school enables the optional video-integrity feature, the platform uses the student's device camera during an interview to derive attention and presence signals — for example, whether a face is present and whether the student's gaze is directed at the screen.
How it works, and what it is not. Face and gaze analysis is performed locally in the student's browser. The live video is not transmitted to or stored by Viva. The feature does not create or store a facial-recognition template, faceprint, or scan of face geometry, and does not identify a student from their face; identity verification, where enabled, is performed solely by the voiceprint feature in Section 9A. Because no facial-identity template is created, the feature is designed not to collect a "biometric identifier" as BIPA defines it — BIPA expressly excludes photographs.
What Viva retains. Only (i) derived numeric signals (for example, the share of sampled frames containing a face, the share of gaze samples directed at the screen, and counts of focus loss) and (ii) a limited number of still images captured at flagged moments, kept as evidence for the reviewing teacher.
Purpose and limits. These signals are used solely to surface possible integrity concerns to the teacher. They are never used for identification, to infer a student's emotions or affective state, for automated adverse decisions, or for sale. Inferring emotions from biometric data in an educational setting is prohibited under Article 5 of the EU AI Act; Viva does not do it.
Consent, retention, storage. To the extent the signals or images constitute biometric or sensitive data under applicable law, processing requires separate, explicit consent obtained by the school before the feature is enabled (a parent or guardian's consent where the student is a minor); consent may be withdrawn, and a student may decline without penalty. The data is encrypted in transit and at rest, and is deleted on the same schedule as the associated interview record, or earlier on the school's request or on withdrawal. Viva does not sell or profit from it.
10. Cookies
We use cookies on our website. See our Cookie Policy for details. For EEA/UK visitors, non-essential cookies are placed only with your consent via the cookie banner.
11. Changes to This Policy
We may update this policy from time to time. We will notify institutions of material changes by email at least 30 days before they take effect and will update the "Last updated" date above.
12. Contact Us
privacy@vivaproof.com
Viva Proof, Inc., Boston, MA, USA
vivaproof.com
© 2026 Viva Proof, Inc. All rights reserved.
Also see our Terms of Service · Trust Center.