AugDapt · Legal
AugDapt Privacy Policy
Public privacy notice for the AugDapt platform and MarkingMates
| Organisation | AugDapt Pte. Ltd. |
| UEN | 202615269N |
| Version | v1.1-2026-07-29 |
| Effective date | 29 July 2026 |
| Data Protection Officer | Bill James, Founder and Director |
| Privacy contact | admin@augdapt.com |
| Website | augdapt.com/legal/privacy |
1. About this Privacy Policy
This Privacy Policy is issued by AugDapt Pte. Ltd., a company incorporated in Singapore under Unique Entity Number 202615269N. It explains how AugDapt collects, uses, discloses, stores, protects, transfers and deletes Personal Data in connection with the Services.
This Policy applies to Account Holders, Learners, parents and guardians, teachers, Customer Organisation personnel, website visitors, and other individuals whose Personal Data is processed through the Services.
This Policy is intended to support compliance with the Personal Data Protection Act 2012 of Singapore and, where applicable, other data-protection laws. It does not replace a Customer Organisation’s own privacy notices, policies or legal responsibilities.
2. Identity and Contact Details
| Organisation | AugDapt Pte. Ltd. |
| UEN | 202615269N |
| Country of incorporation | Singapore |
| Data Protection Officer | Bill James, Founder and Director |
| Public business contact | admin@augdapt.com |
All Personal Data enquiries, requests, withdrawals of consent, complaints and suspected Personal Data breach reports should be sent to admin@augdapt.com.
3. Definitions
“Account Holder” means a person who creates, administers or controls an account for the Services.
“Calibration Composition” means a composition selected for the Calibration Corpus under a valid, separate opt-in consent.
“Calibration Corpus” means the controlled collection of consented writing samples, expert annotations and related quality-assurance records used to test, evaluate and calibrate Writing Analytics.
“Customer Content” means compositions, images, scans, documents, rubrics, comments, reports, prompts, instructions and other materials submitted to, stored in or generated through the Services.
“Customer Organisation” means a school, tuition centre, education provider, company, charity or other organisation that subscribes to or uses the Services.
“Learner” means a student or other person whose work or Personal Data is processed through the Services.
“Personal Data” means data, whether true or not, about an individual who can be identified from that data or from that data together with other information to which an organisation has or is likely to have access, and includes any equivalent concept under applicable law.
“Services” means the AugDapt platform, MarkingMates and any associated websites, applications, analytics, integrations, reports and educational tools.
“Writing Analytics” means automated or human-reviewed analysis of writing features, performance, development, evidence, strengths, weaknesses, learning targets and intervention outcomes.
4. AugDapt’s Role in Processing Personal Data
4.1 Direct accounts and AugDapt operations
AugDapt determines the purposes and means of processing required to create and administer accounts, secure and operate the Services, manage subscriptions, provide support, prevent misuse, maintain legal records and comply with law. For those activities, AugDapt acts as the organisation responsible for the Personal Data and, where applicable, as a controller.
4.2 Services provided to a Customer Organisation
Where a Customer Organisation submits Learner information or Customer Content for marking, teaching, reporting or classroom administration, the Customer Organisation generally determines why the Personal Data is processed. AugDapt generally processes that Personal Data on the Customer Organisation’s documented instructions and may act as a data intermediary or processor.
The Customer Organisation is responsible for providing any required notice, obtaining any required consent or authorisation, and ensuring that its use of the Services is lawful.
4.3 Writing Analytics
AugDapt determines the technical design and methodology of Writing Analytics. The Account Holder or Customer Organisation determines whether and how analytics outputs are used for instruction, assessment, reporting or other educational purposes.
4.4 Calibration Corpus
AugDapt determines the calibration, validation, quality-assurance and fairness-testing purposes of the Calibration Corpus. A composition will not be included in the Calibration Corpus unless the required separate opt-in consent has been recorded.
5. Personal Data We Collect
5.1 Account and identity data
- name, display name and email address;
- profile image, account role, organisation and class affiliation;
- authentication identifiers, sign-in events and account settings;
- subscription, billing and transaction information where applicable;
- consent, withdrawal, policy-acceptance and audit records;
- communications with AugDapt, including support and privacy requests.
Where an external identity provider is used, AugDapt receives only the account information authorised through that provider. AugDapt does not receive the password for the external account.
5.2 Teaching and learner content
- compositions, answers, assignments and revision drafts;
- photographs, scans, images, PDFs and other uploaded files;
- text extracted through optical character recognition;
- rubrics, assessment criteria, instructions and source materials;
- marks, corrections, annotations, teacher comments and moderation decisions;
- generated feedback, reports, practice activities and model rewrites;
- Learner names or identifiers, class names and programme information entered by users;
- information submitted through classroom, parent-facing or reporting functions.
Users should not include Personal Data that is unnecessary for the educational purpose and should redact unnecessary direct identifiers where reasonably practicable.
5.3 Writing Analytics and learner-profile data
- rubric, criterion and skill observations;
- evidence-linked strengths and development areas;
- recurring writing, language and task-performance patterns;
- confidence, uncertainty and not-observed indicators;
- developmental descriptors and curriculum mappings;
- recommended learning targets and instructional actions;
- intervention history, revision uptake and outcome information;
- teacher confirmations, corrections, comments and overrides;
- support conditions, task conditions and degree of independence;
- longitudinal progress history across authorised submissions.
Writing Analytics are educational support tools. They are not medical, psychological, cognitive, intelligence or disability assessments.
5.4 Integration data
If an Account Holder connects Google Drive, Google Slides or another integration, AugDapt may store the access tokens, integration identifiers, permission scopes and file metadata required to perform the actions requested by the Account Holder. Integrations may be disconnected through the provider or through available account settings.
5.5 Technical, cookie and security data
- IP address, browser type, device type and operating system;
- request paths, timestamps, session identifiers and authentication cookies;
- application events, feature usage and performance information;
- error logs, security alerts and abuse-prevention signals;
- information needed to diagnose faults and protect the Services.
AugDapt uses cookies and similar local storage that are reasonably necessary for authentication, security, preferences and operation of the Services. Additional analytics or optional cookies, if introduced, will be described through an appropriate notice or consent mechanism.
5.6 Sensitive information
Customer Content may contain sensitive or highly personal information, including information relating to health, family circumstances, religion, race, nationality, disability, behaviour or safeguarding matters. Users should not submit sensitive Personal Data unless it is necessary for an authorised educational purpose.
AugDapt may restrict, redact, quarantine or remove content where reasonably necessary to protect a Learner, address a safety concern, comply with law, or prevent inappropriate inclusion in the Calibration Corpus.
6. How We Obtain Personal Data
AugDapt may obtain Personal Data directly from an Account Holder, Learner, teacher, parent, guardian or Customer Organisation; from authorised integrations; from Customer Content; automatically through use of the Services; or from service providers acting on AugDapt’s behalf.
A person who submits Personal Data relating to another individual must have the authority to do so and must provide any notification or obtain any consent required by applicable law, contract or institutional policy.
7. Purposes for Which We Process Personal Data
AugDapt may collect, use or disclose Personal Data for purposes that a reasonable person would consider appropriate in the circumstances, including:
- creating, authenticating and administering accounts;
- providing, operating, maintaining and securing the Services;
- receiving, storing, displaying and exporting Customer Content;
- performing optical character recognition;
- applying rubrics and analysing written work;
- generating corrections, feedback, reports, practice tasks and rewrites;
- creating and maintaining authorised learner histories and Writing Analytics;
- identifying patterns, strengths, development areas and suggested learning targets;
- supporting teachers, Learners, parents and Customer Organisations;
- monitoring revision, intervention and transfer outcomes;
- processing subscriptions, invoices, credits and payments;
- providing technical and customer support;
- detecting, preventing and investigating fraud, misuse, security incidents and service faults;
- maintaining operational, accounting, consent and audit records;
- complying with law, regulatory requirements and lawful requests;
- establishing, exercising or defending legal claims;
- calibrating and testing Writing Analytics where separate opt-in consent has been provided.
AugDapt will not use Personal Data for a materially different purpose without providing further notice and, where required, obtaining additional consent.
8. Consent and Other Grounds for Processing
AugDapt will obtain consent where required by applicable law. Consent will relate to identified purposes and will not be obtained through false, misleading or unnecessarily broad wording.
Where permitted by applicable law, AugDapt may also process Personal Data to perform a contract, comply with a legal obligation, protect legitimate interests, respond to an emergency, prevent misuse, act on a Customer Organisation’s documented instructions, or rely on another applicable exception or basis.
Where the GDPR applies, the relevant legal basis may include consent, contractual necessity, legitimate interests, compliance with legal obligations or processing on behalf of a Customer Organisation. A Customer Organisation remains responsible for identifying its own lawful basis for the Personal Data it submits.
Consent may be withdrawn by emailing admin@augdapt.com or using an available account control. Withdrawal does not affect processing that was lawful before the withdrawal took effect and may not require deletion of information that AugDapt is legally required or otherwise permitted to retain.
9. Children, Minors and Student Data
AugDapt recognises that children’s and minors’ Personal Data requires heightened care. Notices and consent materials intended for Learners should be clear, prominent and appropriate to their likely level of understanding.
Where a Learner cannot provide legally effective consent, or where law, school policy or contract requires adult or institutional authorisation, the relevant consent or authority must be provided by a parent, legal guardian, authorised Customer Organisation or another person with lawful authority.
For Calibration Corpus participation, AugDapt’s default product rule requires parent or legal guardian consent for a Learner under 18, unless AugDapt has accepted another lawful institutional arrangement in writing. Where a Learner is under 21 or otherwise lacks legal capacity, additional protections or authorisation may apply depending on the circumstances.
- Learners should receive an age-appropriate explanation of optional uses;
- a Learner’s reasonable objection to Calibration Corpus participation will be respected;
- children’s Personal Data will not be used for behavioural advertising;
- access will be limited according to role and need;
- unnecessary Personal Data should not be collected;
- safety and sensitivity screening may be applied.
10. Writing Analytics and Automated Processing
AugDapt may use automated systems, rule-based extractors, classifiers, language models and human review to extract text, identify writing features, apply rubrics, suggest corrections, generate feedback, estimate skill development and recommend learning targets or instructional actions.
Automated results may be incomplete, uncertain or incorrect. AugDapt does not warrant that an automated result is equivalent to the judgement of a qualified teacher, examiner, language specialist or disciplinary expert.
Where supported by the Services, teachers and authorised reviewers may review evidence, correct task context, identify whether assistance was provided, accept or reject suggested targets, override unsuitable feedback and request reassessment.
AugDapt does not independently use Writing Analytics to make decisions that produce legal or similarly significant effects concerning admission, employment, immigration, healthcare, credit or access to essential services. Customer Organisations remain responsible for educational and assessment decisions made using AugDapt outputs.
11. Optional Calibration Corpus for Writing Analytics
11.1 Separate and optional consent
A composition may be included in the Calibration Corpus only where AugDapt has recorded a separate, explicit opt-in consent covering that use. Calibration consent is not bundled with acceptance of the Terms of Service or with consent necessary to provide ordinary marking functions.
Refusing or withdrawing Calibration Corpus consent will not prevent an Account Holder, Learner or Customer Organisation from using the ordinary marking, feedback, reporting and learning functions of MarkingMates.
11.2 Calibration purposes
- obtaining expert assessments of writing samples;
- testing automated extractors, classifiers and qualitative analytics;
- comparing automated results with expert judgement;
- establishing and revising accuracy thresholds;
- measuring false strengths, false weaknesses and inappropriate recommendations;
- testing multilingual, language-profile and cross-context fairness;
- investigating disagreement between automated and human analysis;
- improving the reliability, interpretability and instructional usefulness of Writing Analytics.
11.3 Pseudonymisation before expert review
Before a Calibration Composition is made available to an expert rater, AugDapt will take reasonable steps to remove or conceal direct identifiers that are not required for the calibration task. This may include removing names, contact details, school or class identifiers and account references, and replacing them with a corpus-specific internal identifier.
Information capable of reconnecting a corpus identifier to an account will be stored separately and access will be restricted. Pseudonymised information remains Personal Data where AugDapt retains the ability to reconnect it to an identifiable Learner.
11.4 Access controls
Access to the Calibration Corpus is limited to authorised AugDapt personnel, contracted expert raters and approved service providers whose involvement is reasonably necessary. Access is subject to role-based permissions, need-to-know restrictions, authentication, confidentiality obligations, restrictions on copying and onward disclosure, termination of access when a role ends, and activity or audit logging where technically available.
Expert raters will not receive account passwords, contact details or other unnecessary direct identifiers.
11.5 Overseas expert raters and processors
Some expert raters or technical service providers may be located outside Singapore. AugDapt will limit their access to what is reasonably necessary and will use contractual, security and organisational measures intended to provide protection comparable to that required under the PDPA.
11.6 Sensitive content
AugDapt may exclude, redact, quarantine or remove a composition from the Calibration Corpus notwithstanding valid consent where the composition contains sensitive, distressing, unsafe or unnecessarily identifying material, presents a safeguarding concern, or is unsuitable for the stated purpose. Consent does not guarantee inclusion.
11.7 Withdrawal and removal
Calibration consent may be withdrawn through an available account setting or by emailing admin@augdapt.com. Following a valid withdrawal, AugDapt will stop selecting the composition for new calibration activity and will schedule the linkable composition and associated corpus record for removal within 30 days.
Withdrawal does not affect processing lawfully completed before it took effect. AugDapt may retain consent and withdrawal records, de-identified aggregate statistics, completed validation findings that no longer identify the Learner, calibration parameters that do not contain or permit reconstruction of the composition, and records required for legal, security or audit purposes.
12. Service Providers and Disclosures
AugDapt uses service providers to operate and support the Services. The principal current providers and purposes are listed below. Actual data processed depends on the function used.
| Provider or category | Principal purpose |
|---|---|
| Supabase | Database, authentication and related backend services. |
| Cloudflare, including R2 | Object storage, content delivery, network security and related infrastructure. |
| Vercel | Application hosting, deployment and operational logging. |
| Google Cloud and Google APIs | Optical character recognition and user-authorised Drive or Slides functions. |
| OpenAI | Selected AI-assisted analysis, correction, feedback, reporting and practice generation. |
| Anthropic | Selected AI-assisted reasoning, analysis, grading support, feedback and rewriting. |
| Payment, communications and professional advisers | Billing, transactional communications, support, legal, accounting and compliance functions where applicable. |
AugDapt may also disclose Personal Data on the documented instructions of a Customer Organisation, where required by law or lawful process, to protect the rights or safety of a person, to investigate misuse, or in connection with a corporate restructuring subject to appropriate confidentiality and data-protection arrangements.
AugDapt does not sell Personal Data, use student compositions for third-party behavioural advertising, or disclose Customer Content to advertisers.
13. Overseas Processing and Transfers
Service providers, contractors and expert raters may process Personal Data outside Singapore, including in the United States and other jurisdictions in which they operate infrastructure or personnel.
Before permitting an overseas recipient to process Personal Data, AugDapt will take reasonable steps to ensure that the transferred Personal Data receives a standard of protection comparable to the protection required under the PDPA, unless an applicable exception applies.
- written data-processing and confidentiality terms;
- purpose and disclosure restrictions;
- security and access-control requirements;
- subprocessor obligations;
- transfer clauses or other lawful transfer mechanisms where required;
- deletion, return and incident-notification requirements;
- risk reviews and compliance information where appropriate.
Where the GDPR applies, AugDapt will use an available lawful transfer mechanism where required. Customer Organisations requiring a specific data-residency arrangement must obtain written confirmation from AugDapt before submitting Personal Data.
14. AI Provider Data Use and Model Training
AugDapt uses commercial or API-based AI services rather than consumer chat accounts for operational processing of Customer Content. AugDapt configures and contracts for those services so that Customer Content is not used to train the provider’s general-purpose models by default, where those controls are available.
AugDapt will not voluntarily opt identifiable Customer Content into a provider’s model-training, development-partner or data-sharing programme without an appropriate legal basis, any required notice and any required additional consent.
AugDapt personnel must not submit identifiable Customer Content through consumer AI accounts for operational marking or Writing Analytics. Provider feedback tools should not be used where submitting feedback would cause identifiable or confidential Customer Content to be retained or used for model improvement, unless separately authorised.
Provider terms, retention periods and technical practices may change. AugDapt will review material changes and update this Policy or its service-provider disclosures where reasonably necessary.
15. Security
AugDapt will implement reasonable administrative, technical and organisational safeguards appropriate to the nature of the Personal Data and the risk of unauthorised access, collection, use, disclosure, copying, modification, loss or disposal.
- encrypted network connections and infrastructure-provided encryption at rest;
- authentication, session and credential controls;
- role-based and least-privilege access;
- separation of operational and administrative access;
- secure storage of OAuth tokens, API keys and application secrets;
- logging, monitoring and alerts for suspicious access where available;
- restrictions on unnecessary downloads and bulk access;
- pseudonymisation and data minimisation;
- confidentiality obligations for personnel and contractors;
- backup, recovery, vulnerability management and incident-response procedures.
No internet-based service can guarantee absolute security. Users are responsible for protecting their credentials and devices and should notify AugDapt promptly if unauthorised access is suspected.
16. Retention and Deletion
AugDapt retains Personal Data only for as long as it is reasonably required for the purpose for which it was collected, for an authorised learner history, for contractual, security, accounting or legal purposes, or for separately consented calibration activity.
16.1 Ordinary content deletion
Content deleted through the Services may first be placed in a recoverable, soft-deleted state. Soft-deleted records and associated stored files are scheduled for permanent deletion after 30 days, unless retention is required or permitted by law or a binding Customer Organisation instruction.
16.2 Account termination and deletion
Following account deletion or an approved deletion request, active account information and Customer Content will enter the deletion process, integration credentials will be revoked or deleted, and associated learner-profile information will be deleted or de-identified as appropriate. Calibration Corpus information is handled under Section 11.
16.3 Backups, logs and legal records
Residual copies may remain temporarily in backups, security records, processor logs or disaster-recovery systems until overwritten or deleted under the applicable retention cycle. Limited records may be retained where reasonably required for security, fraud prevention, accounting, dispute resolution, proof of consent or legal compliance.
17. Access, Correction and Other Rights
Subject to applicable law, identity verification, legal exceptions and AugDapt’s role in relation to the relevant data, an individual may request:
- access to Personal Data held about them and information about how it has been used or disclosed;
- correction of inaccurate or incomplete Personal Data;
- deletion or de-identification where applicable;
- withdrawal of consent;
- withdrawal from the Calibration Corpus;
- a copy or export of relevant information where available;
- restriction of or objection to certain processing where applicable;
- human review of an automated Writing Analytics result.
Requests should be sent to admin@augdapt.com. AugDapt may require reasonable verification, request information needed to locate the relevant record, redact information relating to another person, or refer the request to a Customer Organisation where AugDapt processes the relevant data on that organisation’s behalf.
AugDapt aims to acknowledge requests promptly and respond within 30 days where reasonably practicable. Where additional time is permitted or required, AugDapt will inform the requester of the expected response period.
18. Personal Data Breaches
AugDapt will investigate suspected Personal Data breaches and take reasonable steps to contain the incident, prevent further unauthorised access or disclosure, assess the affected data and individuals, preserve relevant evidence, remediate identified weaknesses and determine whether notification is required.
Where required by applicable law, AugDapt will notify the relevant authority and affected individuals as soon as practicable. Where AugDapt processes Personal Data for a Customer Organisation, AugDapt will notify that organisation in accordance with the applicable agreement so that it can meet its own obligations.
19. Corporate Transactions
Personal Data may be disclosed or transferred in connection with a proposed or completed incorporation change, financing, merger, acquisition, restructuring, sale of assets or transfer of the AugDapt business, provided that appropriate confidentiality and data-protection arrangements are applied and the recipient is informed of the purposes for which the Personal Data was collected.
20. Third-Party Services and Links
The Services may contain links to or integrations with third-party services. A third party’s own privacy policy and terms apply to its independent processing. AugDapt is not responsible for a third party’s independent practices, but will remain responsible for its own selection and use of service providers to the extent required by applicable law and contract.
21. Changes to this Policy
AugDapt may amend this Policy to reflect changes to the Services, service providers, processing locations, retention practices, legal requirements or Writing Analytics.
AugDapt will update the version and effective date, maintain a summary of material changes, provide additional notice where appropriate, and obtain fresh consent where a materially different optional purpose cannot reasonably be covered by an existing consent.
Continued use of the Services does not by itself constitute consent to a materially different optional use where separate consent is legally required.
22. Contact and Data Protection Officer
Questions, requests, complaints and notices relating to Personal Data should be directed to:
| Name | Bill James |
| Position | Founder, Director and Data Protection Officer |
| Organisation | AugDapt Pte. Ltd. |
| UEN | 202615269N |
| admin@augdapt.com |
AugDapt may require reasonable verification of the requester’s identity or authority before disclosing, changing or deleting Personal Data.
23. Changelog
| Version | Effective date | Material changes |
|---|---|---|
| v1.1-2026-07-29 | 29 July 2026 | Added company and DPO details, Writing Analytics and learner profiles, optional Calibration Corpus controls, children’s data, overseas transfers, AI-provider practices, security, retention, rights and breach procedures. |
| v1-2026-07-28 | 28 July 2026 | Initial operational privacy notice. |
See also the applicable Terms of Service or Master Services Agreement.