ENG ACADEMi
ENG ACADEMi

Privacy Policy

Version 2.0.0

Eng Academi Privacy Policy
 
_Version 2.0.0 — Effective 26 August 2026_
 
Eng Academi Inc. (**“Eng Academi,” “we,” “us,” or “our”**) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use Eng Academi websites, applications, APIs, engineering-learning tools, interview-preparation features, assessments, employer-facing services, and other products or services that link to this Privacy Policy (collectively, the **“Services”**).
 
This Policy is designed primarily around Eng Academi’s operations in Canada, including obligations that may apply under the **Personal Information Protection and Electronic Documents Act (PIPEDA)** and other applicable federal or provincial laws. Additional privacy rights may apply depending on where you live or the particular Service you use.
 
This Policy covers both current consumer-facing learning features and additional B2C or B2B features when they are offered. Where a future feature collects materially different information, we may provide a feature-specific notice in addition to this Policy.
 
If you do not agree with this Policy, do not provide personal information through the Services. If you have questions, contact us using Section 25 below.
 
---
 
1. Scope
 
This Privacy Policy applies to personal information that Eng Academi collects or controls in connection with the Services, including information associated with:
 
- account registration and authentication;
- engineering practice, question attempts, long-answer evaluation, hints, feedback, bookmarks, collections, timers, and learning history;
- search, taxonomy, tagging, question similarity, recommendations, and knowledge-map features;
- user-submitted questions or other contributions;
- job-description analysis and role-specific practice;
- legal-policy acceptance and account-security records;
- communications with Eng Academi;
- paid subscriptions or purchases, if and when offered;
- employer, recruiter, school, team, or organization accounts, if and when offered; and
- candidate invitations, assessments, technical-screening workflows, reports, or talent-related services, if and when offered.
 
This Policy does not govern third-party websites or services that Eng Academi does not control, even if they are linked from the Services.
 
---
 
2. Our Privacy Role
 
For most individual Eng Academi accounts, Eng Academi determines why and how personal information is processed for account administration, learning features, service operation, security, product improvement, legal compliance, and related purposes.
 
For certain B2B Services, an employer, recruiter, school, or other organization may provide candidate or participant information to Eng Academi and instruct us to process that information for an assessment, invitation, reporting, or similar organizational purpose. In those circumstances:
 
- the organization may be responsible for deciding the purpose of the processing and for providing required notices or obtaining required authority from the individual;
- Eng Academi may process that organization-controlled information on the organization’s instructions and under a commercial agreement; and
- Eng Academi may still independently control certain information needed for security, fraud prevention, legal compliance, billing, and operation of our own platform.
 
If you participate in an employer- or organization-sponsored assessment, you should also review the organization’s privacy notice because that organization’s use of your results is outside Eng Academi’s exclusive control.
 
---
 
3. Personal Information We Collect
 
The information we collect depends on the features you use. The categories below describe the information that may be collected through current or future Services.
 
3.1 Account and profile information
 
When you create or maintain an account, we may collect:
 
- username;
- email address;
- password credential in protected, hashed form;
- engineering stream or discipline;
- account role;
- account status;
- account creation date; and
- other profile fields you choose or are asked to provide as the Services evolve.
 
We do not need your plain-text password after it has been transformed into the protected credential used for authentication.
 
3.2 Third-party identity information
 
If you sign in with or link a third-party identity provider such as Google, we may receive and store information needed to authenticate or link the account, such as:
 
- the provider name;
- the provider’s stable account identifier;
- the email address reported by the provider;
- whether the provider reports the email as verified;
- the date the identity was linked or updated; and
- last-login information.
 
The third-party provider may separately collect information about your use of its sign-in service under its own privacy policy.
 
3.3 Learning, practice, and assessment activity
 
When you use question and practice features, we may collect:
 
- question identifiers;
- selected multiple-choice answers;
- whether an answer was correct;
- timestamps and attempt history;
- long-answer text you submit;
- hashes or other fingerprints used to detect duplicate long-answer submissions or support caching;
- scores, pass/fail indicators, and solution-reveal status;
- generated or stored feedback;
- hints requested or displayed;
- practice modes and session information;
- bookmarks, collections, saved items, and preferences;
- progress, readiness, ranking, streak, completion, or other learning metrics where offered; and
- timing information where a practice or assessment feature includes timers.
 
This information allows the Services to provide feedback, maintain progress, enforce attempt or usage limits, personalize practice, and show historical results.
 
3.4 AI-assisted feature inputs and outputs
 
If you use an AI-assisted feature, information processed may include:
 
- the question or other platform content relevant to the request;
- your submitted answer or other input;
- expected solution, rubric, tags, or contextual information needed to evaluate the response;
- generated feedback, score, hint, explanation, tags, or other output;
- model or provider identifier;
- prompt or feature version;
- token or usage counts;
- estimated service cost or similar operational metadata; and
- error or fallback information if a model call fails.
 
We seek to avoid including direct account identifiers in AI prompts when those identifiers are not needed for the feature.
 
3.5 Search, taxonomy, recommendations, and knowledge-map activity
 
When you use search or discovery features, we may process search terms, filters, selected engineering streams, question interactions, tags, taxonomy information, relationships between concepts, and other signals needed to return or improve relevant content.
 
Some taxonomy, tagging, similarity, or content-enrichment processes may operate on question content rather than on personal information. Where user-specific activity is used to personalize or improve results, it is treated as account activity under this Policy.
 
3.6 User submissions and community contributions
 
If you submit a question or other contribution for review, we may collect:
 
- submitted question text;
- answer options;
- proposed correct answer;
- tags;
- review or moderation status;
- comments or feedback associated with the submission; and
- the account identifier needed to administer the submission.
 
If an approved submission is published in the shared question bank, we may remove or avoid displaying account attribution. De-identified or non-personal versions of published question content may remain after account deletion where permitted by law.
 
3.7 Job descriptions and role-related content
 
If you submit a job description or similar role text, we may collect the raw text and derived tags or other analysis needed to provide role-relevant practice or assessment features.
 
Job descriptions can sometimes contain names, contact details, confidential business information, or other personal information. You should remove information that is not necessary for the feature and provide only information you are authorized to share.
 
3.8 Behaviour and content-protection events
 
To protect platform content, assessment integrity, and the Services from abuse, we may record limited authenticated interaction events related to content protection or suspicious use. Depending on the event, this may include:
 
- a pseudonymous or internal event identifier;
- account identifier;
- session identifier;
- event category and event name;
- application route;
- related question identifier;
- practice mode;
- protected interface or content surface;
- whether a restricted action was blocked;
- event time; and
- limited event metadata needed to understand the security or content-protection event.
 
These records are not intended to store the text you copied or typed merely because a content-protection event occurred, and they should not contain redundant profile information.
 
3.9 Authentication, fraud-prevention, and security information
 
We collect information needed to protect accounts and the Services. Depending on the security function, this may include:
 
- login success or failure information;
- account or username security hashes;
- IP-address security hashes;
- password-reset request hashes derived from email addresses and IP addresses;
- password-reset token records in protected form;
- rate-limit and abuse-control state;
- timestamps and security event history; and
- information reasonably necessary to investigate suspected unauthorized access or misuse.
 
For certain application-level login, password-reset, and legal-acceptance records, Eng Academi stores keyed cryptographic hashes of identifiers such as IP address, username, email address, or user-agent data rather than storing the raw value in those specific records.
 
However, ordinary network requests necessarily expose information such as IP address to internet, cloud, hosting, security, and network providers that transmit or host the request. Those providers may maintain their own infrastructure logs for security, reliability, and legal purposes.
 
3.10 Legal acceptance records
 
When you accept our Terms of Service or acknowledge this Privacy Policy, we may retain an audit record that includes:
 
- your account identifier;
- the specific Terms version and Privacy Policy version presented;
- the time of acceptance;
- the acceptance source, such as registration or re-acceptance;
- a snapshot of the acceptance checkbox language; and
- privacy-preserving hashes derived from request metadata, such as IP address or user-agent information, where used.
 
These records help Eng Academi demonstrate which legal terms were presented and accepted.
 
3.11 Communications and support information
 
If you contact us, submit feedback, report content, request support, respond to research, or communicate with us through email or another channel, we may collect:
 
- your contact information;
- the content of the communication;
- attachments you provide;
- related account or issue information; and
- the history needed to resolve or document the request.
 
3.12 Payment and subscription information
 
If Eng Academi offers paid Services, a third-party payment processor may collect payment-card, bank, billing, or similar payment information directly from you.
 
Eng Academi may receive limited payment and transaction information needed to administer the purchase, such as:
 
- customer or transaction identifier;
- subscription plan;
- billing status;
- amount and currency;
- billing period;
- payment success or failure;
- limited payment-method descriptor; and
- tax or invoice information.
 
We will describe any material change in payment-data handling before collecting payment information directly ourselves.
 
3.13 B2B account and business-contact information
 
If you act for an employer, recruiter, school, vendor, partner, or other organization, we may collect:
 
- name;
- work email address;
- job title or role;
- organization name;
- business contact information;
- account permissions or administrator status;
- billing and contract information;
- support communications; and
- activity within the organization’s Eng Academi workspace.
 
3.14 Candidate and participant information for B2B Services
 
If Eng Academi offers candidate or participant assessment Services, we or the sponsoring organization may collect or provide information such as:
 
- name and email address;
- organization or role associated with the invitation;
- assessment identifier and invitation status;
- answers and response history;
- scores and topic-level performance;
- completion status and timestamps;
- permitted hint or solution usage;
- timing information;
- generated feedback or evaluation outputs; and
- reports shared with the sponsoring organization.
 
We do not intend to require sensitive personal characteristics such as race, ethnicity, religion, disability, health information, sexual orientation, political affiliation, or similar protected information for ordinary technical assessment features. If a future feature requires sensitive information for a legitimate purpose, such as an accommodation process, we will provide additional notice and apply safeguards appropriate to the sensitivity and applicable law.
 
3.15 Device, browser, and technical information
 
The Services and our infrastructure providers may process technical information necessary to deliver, secure, and troubleshoot the Services, such as:
 
- IP address;
- browser or device type;
- operating system;
- referring or requested page;
- request timestamps;
- diagnostic information;
- approximate location derived from IP address where used by infrastructure providers; and
- identifiers stored in cookies, browser storage, or similar technologies where used.
 
We do not need precise GPS location for ordinary Eng Academi learning features unless a future feature clearly requests it.
 
---
 
4. How We Collect Personal Information
 
We may collect personal information:
 
1. **Directly from you**, such as when you register, answer a question, submit a long answer, create a collection, contact support, or enter a job description.
2. **Automatically through your use of the Services**, such as authentication, security, practice history, content-protection events, or technical request information.
3. **From a third-party identity provider**, when you choose third-party sign-in or account linking.
4. **From an employer, recruiter, school, or other organization**, if the organization invites you to an assessment or administers a B2B workspace.
5. **From service providers**, such as payment status, email-delivery status, hosting diagnostics, or other information returned in the course of providing services to us.
6. **From public or licensed sources**, where permitted and appropriate for developing non-personal educational content, market research, or business contact purposes.
 
We seek to collect only information reasonably necessary for identified purposes.
 
---
 
5. How We Use Personal Information
 
We use personal information for purposes that include the following.
 
5.1 Provide and personalize the Services
 
We use information to:
 
- create and administer accounts;
- authenticate users;
- provide questions, practice sessions, bookmarks, collections, and history;
- record answers and results;
- provide long-answer evaluation, feedback, hints, and solution-reveal features;
- remember preferences;
- provide search, taxonomy, similarity, recommendation, and knowledge-map features;
- tailor content to engineering discipline, selected filters, or prior activity; and
- provide organization-sponsored assessments or reports where applicable.
 
5.2 Operate AI-assisted features
 
We may process relevant questions, answers, solutions, rubrics, tags, or contextual information through AI or machine-learning systems to provide feedback, hints, evaluation, tagging, search, recommendations, or content-enrichment features.
 
We do not intend to use direct identifiers in model prompts when they are unnecessary for the requested feature.
 
5.3 Maintain assessment and learning integrity
 
We may use attempt history, timing, solution visibility, hint usage, content-protection events, rate limits, and related information to enforce feature rules, protect question content, reduce cheating, and preserve the usefulness of practice or assessment results.
 
5.4 Secure accounts and prevent abuse
 
We use security information to:
 
- detect repeated failed logins;
- rate-limit abusive login or password-reset activity;
- detect suspicious account or scraping behaviour;
- investigate security incidents;
- prevent unauthorized access, fraud, credential abuse, or content theft;
- maintain platform availability; and
- enforce our Terms of Service.
 
5.5 Improve and develop Eng Academi
 
We may analyze account activity, feature usage, question performance, search behaviour, error data, aggregated results, and user feedback to:
 
- identify confusing or inaccurate questions;
- improve hints and explanations;
- improve search and taxonomy quality;
- understand feature adoption;
- diagnose performance problems;
- test new features;
- conduct product and educational research; and
- develop future B2C or B2B Services.
 
Where practical, we use aggregated or de-identified information for research and product-development activities that do not require identity.
 
5.6 Administer subscriptions and commercial relationships
 
If paid Services are offered, we may use account, billing, subscription, and transaction information to process purchases, administer plans, issue invoices, manage renewals or cancellations, detect payment fraud, and maintain financial records.
 
For B2B relationships, we may use business-contact information to administer contracts, accounts, support, billing, security, and customer success.
 
5.7 Communicate with you
 
We may send:
 
- account and authentication messages;
- password-reset emails;
- security notices;
- legal-policy notices;
- billing or subscription notices;
- assessment invitations or completion messages;
- support responses;
- service updates; and
- marketing communications where permitted by law.
 
5.8 Comply with law and protect rights
 
We may use information to comply with legal obligations, respond to lawful requests, establish or defend legal claims, investigate misconduct, protect Eng Academi or others, enforce agreements, and maintain records required by law.
 
---
 
6. Consent and Other Legal Authority
 
Eng Academi seeks to collect, use, and disclose personal information only with valid legal authority.
 
In Canada, consent may be express or implied depending on the sensitivity of the information, reasonable expectations, and the circumstances. We seek express consent when required by law or when the sensitivity or use makes express consent appropriate.
 
You may withdraw consent to a collection, use, or disclosure that depends on consent, subject to legal or contractual restrictions and reasonable notice. Withdrawal may prevent us from providing a feature that requires the information.
 
Some processing may be permitted without consent where applicable law provides an exception, such as certain fraud-prevention, legal, investigation, or emergency circumstances.
 
Where another organization provides your information to Eng Academi for a B2B Service, that organization is responsible for having the authority required for its collection and disclosure to us, while Eng Academi remains responsible for our own legal obligations.
 
---
 
7. Artificial Intelligence, Automated Evaluation, and Profiling
 
Eng Academi uses or may use automated systems to support educational and assessment features. We believe transparency is particularly important when automated outputs could influence how a person understands their skills or when an organization may consider an assessment result.
 
7.1 Current educational uses
 
Automated systems may help evaluate a long answer, generate feedback, provide progressive hints, generate or review question-related content, tag questions, build semantic relationships, improve search, or recommend relevant questions.
 
These outputs can be inaccurate or incomplete. They should be treated as educational assistance rather than infallible judgments.
 
7.2 Candidate or B2B uses
 
If Eng Academi offers AI-assisted candidate evaluation, we will seek to make clear that automation is being used and the role it plays. Where a result may materially affect a candidate, Eng Academi’s Services are intended to support rather than replace appropriate human decision-making.
 
We do not authorize customers to use Eng Academi to make unlawful discriminatory decisions or to infer sensitive protected characteristics for unrelated hiring purposes.
 
Where appropriate and legally required, candidates may request information about or human review of Eng Academi-controlled automated processing. A sponsoring employer or organization may separately be responsible for reviewing its own employment decision.
 
7.3 Model training and secondary use
 
Eng Academi does not use identifiable private practice answers to train a general-purpose AI model for unrelated purposes unless we provide appropriate notice and obtain any consent required by law.
 
We may use de-identified, aggregated, synthetic, or appropriately authorized information to evaluate or improve prompts, scoring methods, search, classification, feedback quality, or other Eng Academi features.
 
Third-party AI providers may process prompts and outputs on our behalf under the service configuration and contractual terms we select. Provider retention, abuse-monitoring, or model-improvement practices can vary by provider and product. We seek to configure and contract for business use in a manner appropriate to the information processed and will update this Policy if our practices materially change.
 
---
 
8. When We Disclose Personal Information
 
We do not sell your personal information.
 
We may disclose personal information in the following circumstances.
 
8.1 Service providers
 
We may use service providers that support:
 
- cloud hosting and databases;
- network delivery and security;
- authentication;
- email delivery;
- AI or model inference;
- payment processing;
- analytics or diagnostics;
- customer support;
- logging, monitoring, or error reporting;
- backup and disaster recovery; and
- other technical or business operations.
 
Service providers receive only the information reasonably necessary for their role and are expected to process it under appropriate contractual, confidentiality, security, and privacy requirements.
 
8.2 Employers, recruiters, schools, and other organizations
 
If an organization sponsors an assessment, workspace, or B2B Service, we may share information relevant to that organizational relationship, such as:
 
- invitation and completion status;
- assessment answers or results;
- scores and topic-level performance;
- timing or attempt information;
- generated assessment feedback;
- reports; and
- organization-workspace activity reasonably needed for administration.
 
We will not treat ordinary private learning history as automatically available to an employer merely because the user also has an Eng Academi account. Organization access will be based on the relevant Service design, notice, agreement, and legal authority.
 
8.3 At your direction
 
We may disclose information when you direct us to do so, such as when you choose to share a report or connect a third-party service.
 
8.4 Legal and safety disclosures
 
We may disclose information where we reasonably believe disclosure is required or permitted by law, including to:
 
- comply with a subpoena, warrant, court order, or lawful governmental demand;
- respond to an emergency involving safety;
- investigate fraud, cyber abuse, intellectual-property infringement, or unlawful activity;
- protect the rights, property, systems, or safety of Eng Academi, users, or others; or
- establish, exercise, or defend legal claims.
 
Where legally permitted and appropriate, we may seek to narrow overly broad requests or notify affected users.
 
8.5 Business transactions
 
Personal information may be transferred as part of a proposed or completed financing, merger, acquisition, restructuring, sale of assets, insolvency process, or similar corporate transaction, subject to applicable legal protections and restrictions on use.
 
8.6 De-identified and aggregated information
 
We may use or disclose information that has been aggregated or de-identified so that it is not reasonably capable of identifying an individual, subject to applicable law. We do not intend to attempt to re-identify properly de-identified information except for legitimate security, validation, or legal purposes where permitted.
 
---
 
9. Cross-Border Processing
 
Eng Academi is based in Canada, but our service providers may process or store personal information in Canada, the United States, or other jurisdictions.
 
When personal information is transferred to a service provider for processing, Eng Academi remains accountable for information under our control as required by applicable law. We seek to use contractual, technical, organizational, and vendor-management measures appropriate to the sensitivity and risk of the information.
 
Information processed in another jurisdiction may be subject to that jurisdiction’s laws and may be accessible to courts, law-enforcement agencies, national-security authorities, or regulators in accordance with local law.
 
You may contact us if you have questions about the use of service providers outside Canada.
 
---
 
10. Cookies, Browser Storage, and Similar Technologies
 
Eng Academi may use cookies, local storage, session storage, authentication tokens, or similar browser technologies where needed to:
 
- keep you signed in or maintain session state;
- remember preferences;
- provide security protections;
- operate application functionality;
- measure or diagnose performance; and
- understand feature usage where analytics are used.
 
Essential technologies may be necessary for the Services to function. If we introduce non-essential advertising, cross-site tracking, or similar technologies that require consent under applicable law, we will provide appropriate notice and consent controls before relying on them.
 
Your browser may allow you to delete or block cookies or browser storage. Doing so can cause authentication, preferences, or other Services to stop working correctly.
 
---
 
11. Communications and Canada’s Anti-Spam Requirements
 
We may send non-promotional communications required to provide, administer, or secure the Services, such as password-reset, account, legal, billing, or assessment messages.
 
For commercial electronic messages subject to Canada’s Anti-Spam Legislation or similar laws, we will rely on a lawful form of consent or another permitted basis, identify the sender as required, and provide an unsubscribe mechanism where required.
 
You can unsubscribe from marketing communications through the unsubscribe method provided in the message or by contacting us. We may retain limited suppression information needed to respect your unsubscribe request.
 
Unsubscribing from marketing does not opt you out of essential transactional or security communications.
 
---
 
12. Data Minimization and Sensitive Information
 
We aim to limit collection to information reasonably necessary for identified purposes.
 
You should avoid submitting unnecessary sensitive information through free-text answer fields, job-description fields, feedback forms, or AI-assisted features. In particular, do not submit another person’s health information, government identifiers, financial account credentials, private passwords, protected characteristics, or confidential records unless an Eng Academi feature specifically requires that information and you are legally authorized to provide it.
 
If we develop features that intentionally collect sensitive information, we will evaluate the necessity of that collection and apply safeguards and consent appropriate to the circumstances.
 
---
 
13. Accuracy and Correction
 
We take reasonable steps to maintain personal information as accurate, complete, and current as necessary for the purposes for which it is used.
 
You are responsible for keeping your account information accurate. Depending on the feature, you may be able to update information directly through your account.
 
If you believe personal information Eng Academi controls is inaccurate, you may request correction using the contact information in Section 25. We may need to verify your identity before making a correction.
 
We may decline to alter information where the request concerns an opinion, a security record, an immutable legal audit record, or another record that must remain unchanged for legal or integrity reasons. Where appropriate, we may instead record a correction, annotation, dispute, or updated record.
 
---
 
14. Retention
 
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, subject to legal, contractual, security, dispute-resolution, and operational requirements.
 
Retention depends on the category and context. For example:
 
- **Account information** may be retained while your account is active and for a reasonable period afterward where needed for legal, security, or recovery purposes.
- **Practice and learning history** may remain associated with your account so that you can review progress and results.
- **Long-answer attempts and generated feedback** may be retained to provide history, apply usage rules, support duplicate-response caching, analyze question quality, investigate errors, and improve the feature.
- **Security and abuse-prevention records** may be kept for a period appropriate to detecting repeated abuse, investigating incidents, and defending the Services.
- **Legal acceptance records** may be retained as needed to evidence the Terms and Privacy Policy versions presented and accepted.
- **Payment and financial records** may be retained as required for accounting, tax, chargeback, fraud-prevention, and legal obligations.
- **B2B assessment records** may be retained according to the organization’s agreement, candidate notice, applicable law, and Eng Academi’s own legitimate legal or security needs.
- **Support communications** may be retained while an issue is open and for a reasonable period afterward.
- **Backups** may retain deleted information temporarily until backup cycles expire or are overwritten, subject to security and restoration controls.
 
When information is no longer required, we may delete, destroy, anonymize, or de-identify it as appropriate.
 
We may retain de-identified or aggregated information for research, analytics, security, or product improvement where it no longer constitutes personal information under applicable law.
 
---
 
15. Account Deletion
 
Where account-deletion functionality is available, you may request deletion through account controls or by contacting us.
 
Deletion generally removes or disconnects account-linked personal records that are no longer required, but deletion may not immediately remove:
 
- information required to comply with law;
- records necessary to establish, exercise, or defend legal claims;
- security or fraud records reasonably needed to protect the Services;
- billing or transaction records required by law;
- B2B records another organization is legally entitled or required to retain;
- information in backups awaiting normal overwrite or expiry; or
- question content or other contributions that have been de-identified and incorporated into shared platform content.
 
We may need to verify your identity before completing a deletion request.
 
Deleting an Eng Academi account does not necessarily delete information already received and independently controlled by an employer, recruiter, school, or other organization.
 
---
 
16. Your Privacy Rights
 
Depending on applicable law and the context, you may have rights to:
 
- ask whether Eng Academi holds personal information about you;
- request access to personal information under our control;
- ask for an explanation of how personal information has been used or disclosed;
- request correction of inaccurate or incomplete information;
- withdraw consent where processing depends on consent, subject to legal or contractual limitations;
- request deletion where available or required by law;
- object to or restrict certain processing where applicable law provides that right;
- request information about automated processing where required by law;
- request human review of certain significant automated decisions where applicable; and
- challenge Eng Academi’s compliance with applicable privacy law.
 
To exercise a right, contact `admin@engacademi.org` and identify the request as a privacy request.
 
We may ask for information sufficient to verify your identity and authority before providing access or making changes. We will not ask for information that is disproportionate to the verification need.
 
Access rights are subject to legal exceptions, including information that would reveal another person’s personal information, confidential commercial information, privileged information, or information that cannot lawfully be disclosed.
 
If an employer or other organization controls the information you are asking about, we may direct you to that organization or coordinate with it as appropriate.
 
---
 
17. Security Safeguards
 
Eng Academi uses administrative, technical, and organizational safeguards intended to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification.
 
Depending on the system and sensitivity, safeguards may include:
 
- password hashing;
- access controls and account roles;
- authentication tokens and expiry controls;
- rate limiting and progressive abuse controls;
- cryptographic hashing of selected security identifiers;
- separation of certain security or feature data into purpose-specific tables;
- transport encryption provided through HTTPS/TLS in deployed environments;
- environment-based secret management;
- restricted administrative functionality;
- database backup and recovery processes;
- logging and incident investigation; and
- code, dependency, configuration, and security testing appropriate to the stage of the product.
 
No internet service, database, or security control can guarantee absolute security. You are responsible for using a strong, unique password and protecting access to your account and email address.
 
If you believe your account or personal information has been compromised, contact us promptly.
 
---
 
18. Privacy and Security Incidents
 
We maintain processes intended to identify, contain, assess, investigate, and remediate privacy or security incidents.
 
If a breach of security safeguards involving personal information creates a legal obligation to notify affected individuals, a privacy regulator, or another authority, we will provide notification in accordance with applicable law.
 
We may preserve incident records and related evidence as required for investigation, remediation, legal compliance, or the prevention of similar incidents.
 
---
 
19. Children and Young Users
 
The Services are designed primarily for post-secondary students, graduates, early-career professionals, educators, and organizations. They are not directed to children under 13, and we do not knowingly seek to collect personal information from children under 13 without legally valid parental or guardian authorization where required.
 
Users who are under the age of majority where they live should use the Services with parent or guardian involvement where required by law.
 
If you believe a child has provided personal information in circumstances where valid authorization was required but not obtained, contact us so that we can review the situation.
 
---
 
20. B2B Customers and Candidate Privacy
 
This section applies when an employer, recruiter, school, or other organization uses Eng Academi to invite, assess, screen, train, or evaluate an individual.
 
20.1 Information provided by the organization
 
The organization may provide information such as a candidate’s name, email address, intended role, assessment configuration, or other information reasonably necessary to administer the Service. The organization is responsible for ensuring it has lawful authority to provide that information.
 
20.2 Information generated through the assessment
 
Eng Academi may generate or record answers, scores, completion data, topic performance, timing, attempt history, feedback, and related assessment information. The sponsoring organization may receive this information where disclosed as part of the assessment or organization Service.
 
20.3 Limits on employer access
 
Participation in an organization-sponsored assessment does not by itself give the organization unrestricted access to all information in a candidate’s independent Eng Academi learning account. We aim to separate organization-relevant data from unrelated private learning activity unless the user directs otherwise or the Service clearly provides a different arrangement.
 
20.4 Decisions remain with the organization
 
An employer or other customer decides how it uses assessment results in its hiring, admissions, training, or other processes. Eng Academi may provide technical scores or decision-support information, but the organization is responsible for its own decision and for complying with employment, human-rights, privacy, accessibility, and other applicable law.
 
20.5 Candidate questions or challenges
 
If your request concerns Eng Academi-controlled information or the operation of an Eng Academi assessment feature, you may contact us. If your request concerns why an employer made a hiring decision, the employer may be the appropriate organization to answer that question.
 
---
 
21. Public Content and User Contributions
 
Most account activity and private answers are not intended to be publicly displayed.
 
However, if you submit content for community review, publication, inclusion in the Eng Academi question bank, or another public-facing feature, that content may be reviewed, edited, moderated, de-identified, and published according to the Terms of Service.
 
Do not include personal information in a question submission or other contribution unless you intend and are authorized for that information to be reviewed for the stated purpose.
 
If content is published after account attribution is removed, the remaining question or educational material may no longer be personal information and may remain in the Services after account deletion.
 
---
 
22. Research, Analytics, and Product Improvement
 
Eng Academi may use service data to understand how questions and features perform and to improve learning quality.
 
Examples include analyzing:
 
- which questions have unusually high or low correctness rates;
- whether users repeatedly request hints on a particular concept;
- whether feedback appears to help subsequent attempts;
- search relevance;
- taxonomy coverage;
- feature reliability and error frequency;
- aggregate practice patterns; and
- aggregate assessment performance.
 
Where research or improvement does not require identity, we seek to use aggregated or de-identified information.
 
If we conduct research that requires identifiable or sensitive information outside the reasonable expectations described in this Policy, we will provide additional notice and obtain consent where required.
 
---
 
23. Changes to This Privacy Policy
 
We may update this Privacy Policy to reflect changes in law, security practices, service providers, technology, AI features, subscriptions, B2B Services, data practices, or the Services.
 
When a change is material, we will provide notice appropriate to the circumstances. Notice may include:
 
- posting the updated Policy;
- changing the version and effective date;
- displaying an in-product notice;
- sending an email; or
- requiring you to acknowledge the new version before continuing to use authenticated Services.
 
Where a new purpose requires fresh consent under applicable law, we will seek that consent rather than relying only on a policy update.
 
Previous acceptance records may be retained so that we can determine which version applied at a particular time.
 
---
 
24. Questions, Complaints, and Privacy Governance
 
Eng Academi is responsible for personal information under its control and designates responsibility for privacy compliance within the organization.
 
If you have a question, complaint, access request, correction request, deletion request, or concern about how Eng Academi handles personal information, contact us using Section 25.
 
We will review privacy complaints and respond within a reasonable period appropriate to the request and applicable law. If you are not satisfied with our response, you may have the right to make a complaint to the **Office of the Privacy Commissioner of Canada** or another privacy regulator with jurisdiction.
 
Nothing in this Policy limits your right to contact a regulator or exercise a non-waivable legal right.
 
---
 
25. Contact Us
 
Privacy questions and requests may be sent to:
 
**Privacy Lead**
**Eng Academi Inc.**
Ontario, Canada
Email: `admin@engacademi.org`
 
When contacting us about a privacy request, please provide enough information for us to understand the request. Do not send passwords, full payment-card numbers, government identification numbers, or other unnecessary sensitive information by email.
 
© 2026 EngAcademi. All Rights Reserved.About