Privacy Policy
What personal information Quademia collects, why we collect it, who else handles it, and what you can ask us to do about it.
Draft — not yet in force. This document has been prepared but has not yet been reviewed by a qualified professional, and the company registration it depends on is not complete. It is published here so it can be read and checked. Please do not rely on it as a statement of your rights until this notice is removed.
Passages shown [like this] are values still to be settled.
Who we are
Quademia builds exam-preparation and licensure products for nurses, teachers and schools. When we say we, us or Quademia in this policy, we mean the organisation responsible for those products — the data controller, in the language of data-protection law. That means we decide what personal information is collected and what happens to it, and we are the ones you can hold to account for it.
Our registered details are: [registered company name] [company registration number] [registered address].
Note for review — not for publication. These blanks are not an oversight. The company is in the process of being registered, and a privacy policy has to name a real, existing legal person as the controller. This document must not go live until the registration exists and these three fields are filled in.
You can reach us about anything in this policy at hello@quademia.com.
What this policy covers
This is one policy for the whole of Quademia. It covers this website and every product we run:
- MyNclex — NCLEX-RN preparation: a question bank you can study from on your own, and tutor-led programmes.
- MyNMCLicensure — preparation for Ghana’s Nursing and Midwifery Council licensure examination.
- MyTeacher — class-based assessment for teachers and their students.
- Our schools product — running formal examinations across a whole school.
We deliberately keep this as a single document rather than one per product. Four copies would be four documents to keep in step, and the copy that missed an update would be the one that caused harm. Where a particular product does something different, that product is named in the clause.
Some of our products still carry our older QAcademy branding while they move across to Quademia. It is the same organisation and this same policy applies to them.
This policy does not cover other companies’ websites we link to, or the video-meeting tools your tutor may use to run a live class — see section 7.
The information we collect
Information you give us
- When you create an account: your first name, last name and email address, and a password. Your password is stored only in a scrambled (hashed) form — nobody at Quademia can read it, and we cannot tell you what it is.
- Optionally, on your profile: a phone number and a profile picture.
- If you are a tutor: the public profile you choose to publish — your headline, speciality, years of experience, biography, and any business branding you add. Everything in that profile is intended to be seen publicly, which is why we ask you not to put private details in it.
- When you contact us or a tutor: what you write in an enquiry form, a support message or an email, and anything you attach.
- Anything you upload: files, images and documents you add — for example, materials a tutor adds to a programme.
Information created as you use the products
- Your study record: the questions you attempt, the answers you choose, how long you take, your scores and marks, which questions you flag or bookmark, and your results on practice tests and readiness packs.
- Your progress: what you have completed in a programme, and whether your tutor marked you present, absent or excused for a live session.
- Your access: what you have bought, when it started and when it ends, which programme and cohort you are enrolled in, and any credits you hold.
Payment information
We never see, receive or store your card number, its security code or your PIN. When you pay, our payment provider, Paystack, collects those details directly from you on its own secure systems.
What we do keep is the record of the transaction:
- the email address the payment was made with;
- the amount, the currency (Ghana cedis or US dollars) and what it was for;
- the payment reference, whether it succeeded, failed or was refunded, and the dates;
- the confirmation record Paystack sends back to us.
Where a tutor collects a payment outside the platform — cash or a bank transfer — and records it against your enrolment, we keep that record and which tutor entered it.
Technical and security information
- Sign-in events: each time an account is signed into, a password reset is asked for, or a sign-in attempt fails or is blocked, we record the email address used, the time, the outcome and the reason.
- Your IP address and a description of your device (for example, Android · Chrome) against those events.
- Cookies that keep you signed in — see section 5.
We keep this because accounts get attacked. It is how we notice somebody trying passwords against your account, and how we can tell you what happened if you ask.
What we do not collect
We do not buy personal information about you from anyone. We do not run advertising or cross-site tracking, and we do not ask you for information about your own health, race, religion, politics or anything else the law treats as a special category. Our questions describe fictional patients; nothing in them is about you.
Why we use it, and our legal basis
Data-protection law requires us to have a specific reason — a legal basis — for every use of your information. Ours are:
| What we do | Information used | Our basis |
|---|---|---|
| Create and run your account | Name, email, password, roles | Performing our contract with you |
| Give you what you bought | Purchases, subscriptions, enrolments, credits | Performing our contract with you |
| Run your studying and show your results | Attempts, answers, scores, progress, attendance | Performing our contract with you |
| Take payment and confirm it | Email, amount, currency, reference, status | Performing our contract with you |
| Send service emails — receipts, invitations, password resets, reminders about your programme | Name, email, what you are enrolled in | Performing our contract with you |
| Answer your support questions | What you tell us, plus your account record | Performing our contract, and our legitimate interests |
| Keep accounts secure — block automated sign-in attempts, investigate abuse and fraud | Sign-in events, IP address, device description | Our legitimate interests in protecting you and us |
| Improve the products — for example, spotting a question that almost everybody gets wrong | Study records, usually combined and not identifying you | Our legitimate interests in improving what we sell |
| Send you marketing about our products | Name, email | Your consent — you can withdraw it at any time |
| Keep accounting and tax records | Payment records | Complying with our legal obligations |
Where our basis is legitimate interests, we have weighed what we want to do against your privacy, and we will not do it where your interests come first. You can object to any of those uses — see section 11.
Where our basis is consent — which today means marketing email only — you can say no in the first place, and withdraw later without losing anything you paid for. Service emails about something you bought are not marketing, and you cannot unsubscribe from a password reset.
Cookies
We use cookies only where the product will not work without them:
- Signing you in. A cookie holds your session so you do not have to type your password on every page. Without it there is no way to stay signed in.
- Security. Cloudflare Turnstile, which checks that a sign-in or sign-up is coming from a person and not an automated script, sets its own cookie for that check.
We do not use advertising cookies, and we do not have any third-party analytics or tracking on our sites. Nobody is following you from our pages to anyone else’s. If that ever changes we will update this policy and ask for your consent first — we will not slip it in.
Who else handles your information
We do not sell your personal information to anyone. We do not share it for anyone else’s advertising.
We do use specialist companies to run parts of the service. They handle your information on our instructions only, under a contract, and may not use it for their own purposes:
| Company | What they do for us | Where |
|---|---|---|
| Supabase | Hosts the database, the account and sign-in system, and uploaded files | [region] |
| Cloudflare | Hosts and serves our websites and applications; provides the Turnstile bot check on our sign-in forms | Worldwide network |
| Paystack | Takes card and mobile-money payments, and issues refunds. Your card details go to Paystack, not to us | Nigeria / Ghana |
| Resend | Delivers our emails — receipts, invitations, password resets and reminders | [region] |
| Provides “Sign in with Google” where we offer it, and hosts our own company email | Worldwide network | |
| Microsoft | Provides “Sign in with Microsoft” on our schools product | Worldwide network |
Beyond those, we will share your information:
- With your tutor, your teacher or your school — explained in full in section 7, because it is the sharing most people will care about.
- Where the law requires it — for example a valid court order or a lawful request from an authority. We will tell you if we are allowed to.
- With our professional advisers — accountants and lawyers, bound by confidentiality.
- If the business is sold or reorganised — to the buyer, who would have to keep to a policy no weaker than this one.
Signing in with Google or Microsoft. Where we offer it, this is only a second door into an account that already exists — it never creates one. We receive your name, email address and profile picture from them. We never receive your password, and we get no access to your mail, files, contacts or anything else in your account there.
Tutors, teachers and schools — who can see your work
If you study on your own — the question bank by itself — nobody else sees your results. If you join a tutored programme or a class, other people necessarily do, and you should know exactly who and what before you enrol.
What your tutor or teacher can see
- your name and the email address on your account;
- that you are enrolled, and in which cohort or class;
- payments recorded against your enrolment — including whether an instalment is outstanding;
- your progress through their programme, your results on the work they set, and your attendance at their live sessions.
They do not see your card details, your password, or your work in other tutors’ programmes.
Other students
Other members of your cohort or class may see your name where the product shows a group — for example, a class list. They do not see your results, your payments or your contact details.
Live sessions and recordings
Tutors run live classes on outside platforms — Zoom, Google Meet or Microsoft Teams — using their own accounts. When you join one, that platform’s own privacy policy applies to you, not ours, and we have no control over what it collects.
Where a session is recorded, the recording can capture your name, your voice, your camera picture and anything you type in the chat. The recording is then shared with your cohort. Your tutor should tell you before recording; if you do not want to appear, you can keep your camera and microphone off.
Tutors are independent
Tutors run their own programmes on our platform. For the personal information they collect and hold themselves — outside our products, such as their own WhatsApp group or their own notes — they are responsible, not us. For the records held inside our products, we are.
Schools
On our schools product, the school decides which students are enrolled, what examinations they sit and who can see the results. In that arrangement the school is the data controller for its students’ records and we act on the school’s instructions. If you are a student or a parent asking about that data, ask the school first; we will help the school answer.
Us
A small number of Quademia staff can see account and payment records, and only where their role requires it — answering a support request, investigating a payment, or dealing with abuse. Access is limited by role rather than given to everyone.
Sending information between countries
We are based in Ghana, and our students are in Ghana, the United States, the United Kingdom, Canada and elsewhere. The companies in section 6 run their systems across several countries. That means your information will be stored and processed outside the country you live in.
Where information leaves the United Kingdom or the European Economic Area, we rely on the safeguards the law provides for that transfer — in practice, standard contractual clauses in our contracts with those companies, or a finding by the relevant authority that the receiving country protects data adequately.
You can ask us for details of the safeguards that apply to your information at hello@quademia.com.
How long we keep it
We keep information for as long as we need it for the purpose we collected it, and then delete it.
| What | How long | Why |
|---|---|---|
| Your account and study record | While your account is open, and [period after closure] after you close it | So you can come back to your history; so we can settle a dispute about what you were given |
| Sign-in and security events | 90 days, then deleted automatically | Long enough to investigate an attack, no longer |
| Payment and accounting records | [retention period] from the date of the transaction | Required by tax and company law |
| Support messages | [retention period] | To keep a history of an ongoing issue |
| Backups | Rolled off within [backup window] | Deleted information can persist briefly in a backup before it expires |
Where we no longer need to identify you but the underlying facts are still useful — how hard a question turned out to be, for instance — we may keep the information in a form that is no longer linked to you.
How we protect it
The main measures we take:
- Passwords are hashed, never stored readable. Nobody at Quademia can look up your password.
- Everything travels encrypted between your device and us.
- The database enforces who can read what. The rules about which rows belong to which user live in the database itself, not only in the app — so a mistake in one screen cannot expose another student’s records.
- Staff access is limited by role, and the keys that would bypass those rules exist only on our servers and never in your browser.
- Sign-in forms are protected against automated attacks and repeated failures are recorded and can be blocked.
No system is perfectly secure, and we will not pretend otherwise. Please use a password you do not use anywhere else, and tell us at hello@quademia.com straight away if you think somebody else has got into your account.
If a breach happens that is likely to put you at risk, we will tell you and the relevant authority as the law requires.
Your rights
Depending on where you live, you have the right to:
- See what we hold about you, and get a copy;
- Correct it if it is wrong or incomplete — you can change most of it yourself in your profile;
- Have it deleted, where we have no continuing reason or legal duty to keep it;
- Ask us to stop or limit a particular use while a complaint is looked into;
- Object to a use we base on our legitimate interests, and to marketing at any time;
- Take your information elsewhere in a machine-readable form;
- Withdraw consent you gave, without affecting what was done before you withdrew it.
To use any of these, email hello@quademia.com. It is free. We will reply within one month, and tell you if we need longer because the request is complicated. We may need to check who you are first — which protects you, not us.
If you are not happy with our answer, you can complain to a regulator. Please come to us first if you can, but you do not have to:
- Ghana — the Data Protection Commission.
- United Kingdom — the Information Commissioner’s Office.
- European Economic Area — the supervisory authority in your country.
- Canada — the Office of the Privacy Commissioner, or your provincial equivalent.
- United States — your state Attorney General, where your state gives you privacy rights.
Children
Our nursing and licensure products are sold to adults, and you must be 18 or over to create an account on them yourself. We do not knowingly collect information from children through those products. If you believe a child has created an account, tell us and we will remove it.
Our schools product is different, and honestly so: it is used by school pupils, some of whom will be children. Their accounts are created by their school, not by them, and the school is the controller of that information — it decides what is collected and who sees it, and it is responsible for the permissions needed. We handle it on the school’s instructions.
Automated decisions
Parts of our products are automatic: they mark your answers, work out your score, and choose which question to show you next based on how you are doing. That is the product doing its job, and you can see the result of every one of those decisions.
No automated system of ours makes a decision that has a legal effect on you or anything similarly significant. A readiness score is our opinion about your practice, not a prediction and not a verdict. Decisions that actually affect you — suspending an account, refusing a refund — are made by a person, and you can ask us to look again.
Changes to this policy
We will update this policy when what we do changes. The version number and date at the top always tell you which version you are reading.
If a change matters to you — a new purpose, a new company handling your information, a longer retention period — we will email account holders rather than quietly changing the page.
How to contact us
For anything about this policy, your information, or a request under section 11:
Our postal address will appear here once the company registration is complete: [registered address].
Our terms of service cover the rest of the agreement between us.