Effective February 24, 2021
Your Rights and Responsibilities
As the subject of the Personal Data collected, you have rights related to the Personal Data that we hold about you.
At any time, you have the right to:
- Access—The right to be provided with a copy of your Personal Data—subject to the approval of your test sponsor.
- Rectification—The right to correct any mistakes in your Personal Data—subject to the approval of your test sponsor.
- Deletion—The right to request deletion of your Personal Data—subject to the approval of your test sponsor.
- Restriction of Processing—The right to restrict the processing of your Personal Data—in certain circumstances, e.g., if you contest the accuracy of your personal data—subject to the approval of your test sponsor.
- Data Portability—The right to have your Personal Data transferred to a third party in a machine-readable format—subject to the approval of your test sponsor.
- To Object—The right to object to how your personal data is used—subject to the approval of your test sponsor.
Your California Privacy Rights
California grants certain rights to California residents. These include:
- Right to Access—Request a copy of the personal information Kryterion has collected about me.
- Right to Know—Disclose the categories of personal information collected about me, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting personal information, the categories of third parties with whom Kryterion shares personal information, and the specific pieces of personal information collected about me.
- Right to Deletion—Request deletion of the personal information Kryterion has collected from me.
Please visit our Privacy Notice for California Residents for additional information about our processing of personal information and your California privacy rights.
How to Exercise Your Rights
Kryterion provides testing services as a Data Processor under the instructions of and on behalf of our Test Sponsors (that act as an independent Data Controller). Test Sponsors have their own policies regarding the processing of personal data. Decisions regarding any request you make about your personal data occur with your Test Sponsor (your Academic Institution or Organization), as the Data Controller, for whom Kryterion is a Data Processor. As such, Test Sponsors are responsible for receiving and responding to requests from individuals to exercise any rights afforded to them under applicable data protection laws, including the GDPR and CCPA.
To exercise your privacy rights described above, please directly contact your Test Sponsor, academic institution or organization, who is the Data Controller. We may only access your Test Sponsor’s data upon their instructions.
If you cannot locate the contact information of your Test Sponsor, please contact our privacy office at email@example.com and include the name of your Test Sponsor with the subject line “Data Subject Request Support.” We will assist you with providing your Test Sponsor's contact information and will support them as needed in responding to your request within a reasonable timeframe.
Our Rights and Responsibilities
We rely on the following legal grounds to process your Personal Data:
Legitimate interests. We may use your Personal Data for our legitimate interests for the purposes of improving our products and services and improving the content of our Site(s); and for the legitimate interest of our test sponsors. Kryterion and its subcontractors will at all times protect your Personal Data with operational, administrative, technical, and physical security safeguards.
Description of Certification, Licensure and Academic Admission Test Services
We provide testing services as a service provider under the direction of and on behalf of our test sponsors (that act as an autonomous data controller). The test sponsor is the company or organization that offers certification, licensure, or academic admission testing and controls the test(s) that must be taken to secure such certification, credentialing, licensure, or academic admission. We collect or receive Personal Data from certification, licensure, and academic admission testing candidates and from the test sponsor. The information we may collect or receive includes, but is not limited to, your test registration, incident resolution (such as fraud prevention), collection of payment for testing services you've requested, and your test results of such testing. We use Personal Data in order to perform the testing services related to the administration and delivery of certification, licensure, and academic admission testing on behalf of the test sponsor. Upon completion of your exam, we may collect and score your test responses and then derive a test score and generate a report about your certification, credentialing, licensure, or academic admission test results. In most cases, as it is necessary to perform the services, such scoring will be completed through automated means based on the criteria provided by your test sponsor.
In the event that you submit a request for an accommodation for your certification, licensure or academic admission test, you may be asked to submit health information records in compliance with your test sponsor's requirements, including but not limited to, documentation from your physician evidencing your need for the accommodations. We will work with the test sponsor to evaluate your eligibility for an accommodation and if an accommodation is granted, we will implement an acceptable accommodation solution.
Providing your Personal Data is voluntary but may be necessary if you wish to receive certification, licensure, or academic admission testing services. We will retain your Personal Data for as long as needed to provide our services and for such period of time as instructed by the test sponsor. To the extent that you request Kryterion to delete your Personal Data, it will affect our ability to allow you to register, schedule, and take a test administered and delivered by us on behalf of the test sponsor; or to provide to you any other products or services offered, and such deletion may affect your certification, licensure or academic admission status, dependent on the policy of your test sponsor.
In addition to the Personal Data that we may collect or receive in registering a candidate ("you") for certification, licensure, or academic admission testing the test sponsor may also provide to us or instruct us to collect the following additional Personal Data, as necessary or appropriate, including, but not limited to: language, sponsor identification number, employment information, previous examination history, education information, and source of financing for the test. For candidate verification and identification purposes, we may be instructed to collect all or part of a government-issued identification number.
At the test center, depending upon the test sponsor and/or test security requirements, you may be required to provide a copy of your photo identification (for the purposes of identity verification and to protect the security and integrity of the test) and you may be audio- and video-recorded while you are taking the test.
How We Use the Personal Data We Collect
We use Personal Data to provide services and information, to administer testing programs on behalf of your test sponsor, and for legitimate purposes in operating our business. Examples of our use or disclosure of your Personal Data include, but is not limited to:
- We will use your Personal Data to provide test delivery services to you, including test scheduling and administration, maintaining the integrity of the testing process, and score reporting as directed by your test sponsor.
- Personal Data is also used for our legitimate business purposes as needed to manage day to day business needs including, but not limited to, payment processing and financial account management, business planning and forecasting, security and fraud prevention, and compliance with legal and regulatory obligations.
- To request to limit the use and disclosure of your personal information, please submit a Data Subject Request Form. In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Independent Testing Centers
Any such third-party data processors are and/or will be subject to contractual agreements to ensure that they only process personal data provided by Kryterion in a manner consistent with the GDPR requirements as more fully described and made accessible to you below. Kryterion remains liable under such Principles if its agent processes your personal data in a manner inconsistent with the Principles, unless we can prove that we are not responsible for the event giving rise to any damage.
Online Proctoring Test Services
Description of Online Proctoring Test Services
If a test sponsor offers their test outside of a Kryterion authorized testing center through Online proctoring and if you choose to take the test through Kryterion's Online proctoring platform, in addition to the requirements of Description of Certification, Licensure, and Academic Admission Test Services, you will be monitored over the Internet through your computer via your webcam and microphone. Online proctoring means that you will log on to a test platform through the internet to take your test and you will be monitored during your entire testing session in real-time so that your face, voice, desk and workspace will be captured and a recording will be made of these images for the purposes of test security and the integrity of the testing process. It is your responsibility to monitor your Online proctored testing environment. You must make sure that only you will be recorded during your testing session and that no one else will be physically in the room where you are testing and that no one speaks to you during your testing session. If at any time during an Online proctored testing session a third party enters the workspace or if any third party's voice is detected on the audio recording your testing session may be immediately terminated and the test stopped. If this event occurs, you will not receive a test refund or be credited for any portion of the test fee.
Personal Data Collected for Online Proctoring Test Services
All of the same Personal Data that we collect or receive as described above applies to you when you register to take a test sponsor's Online proctored test. Prior to the start of your Online proctored test you may be required to take a picture of yourself and/or provide your keystroke pattern for the purpose of identity verification. The collection of such data is optional, but necessary if you choose to use the Online proctoring function. You understand that the audio- and video-tapes of your testing session, as well as photos, will be supplied to the relevant test sponsor and any of their appointed agents to assist with their management of your test.
Description of eCommerce Services
Kryterion's eCommerce Sites provide you with the opportunity to purchase certification, credentialing, licensure, and academic admission test related products and services. Kryterion also provides eCommerce services on behalf of our test sponsors.
Personal Data Collected for eCommerce Services
We clearly identify what information must be provided by you in order for us to deliver the various products, services, and information that you may have requested. Depending on your choices, we will require different types of information for these various products, services, and information. You may also choose to provide additional or optional information to enhance the services we may provide to you. The Personal Data that we may collect includes:
- Contact information, as well as purchase history, and payment information.
- Information regarding your use of the Site (i.e., pages visited, files downloaded).
How We Use the Personal Data We Collect
We use the Personal Data you provide to Kryterion to provide services and information you request, to process transactions, fulfill product delivery and for legitimate purposes in operating our business. Additionally, we use information collected about your use of our site for legitimate business interests to understand the habits of our Site users and to improve the products, services, and content we offer.
Protection of Credit Card Information
Individuals who make online purchases will be asked to provide credit/debit card information, which may include payment instrument number (e.g., credit card), name and billing address, the security code associated with the credit/debit card information, organizational tax ID, and other financial data ("Payment Data"). We use Payment Data to complete transactions, as well as to detect and prevent fraud. We will retain your Payment Data for as long as reasonably necessary to complete the transaction, to comply with our legal and reporting requirements, and to detect and prevent credit/debit card fraud. We provide a secured transmission method for the electronic transmission of credit/debit card information.
Information Received from Internet Service Providers Through this Site
This Site receives information that is automatically generated by a user's Internet service provider (ISP), browser or mobile device. This information may include the IP address, the associated URLs, domain names, the browser type, the approximate location of the ISP's servers, the pages of our Site that the user views, and any search terms entered on this Site. This information may be collected for unicorn's system administration purposes, to gather broad demographic information and to monitor the level of activity on the Site. We reserve the right to link this information to your Personal Data in order to protect the integrity of our system and for security purposes.
How Long We Store Your Information
We keep your information for no longer than necessary for the purposes for which it is processed. The length of time for which we retain information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws.
Disclosure and Transfer of Information
We will comply with the privacy and data collection laws of the jurisdiction of the individual from whom the information is being collected. Personal Data and information of exam candidates located outside of the United States will be transferred to Kryterion, test sponsors and data processors in the United States and elsewhere in the world only to facilitate the purpose for which it was collected. Our computer operations are currently based in the United States. The Internet is a global environment. By using this Site and sending information and Personal Data to us electronically, you consent to trans-border and international transmission of any data that you may choose to supply us to any country in the world, including countries without an adequate level of data protection. Information and Personal Data transmissions to this Site and emails sent to us may not be secure. Given the inherent operation and nature of the Internet, all Internet transmissions are done at the user's own risk.
Transfer of Information to Test Sponsors (if applicable)
For purposes of validating test and user integrity and security, we may supply audio- and video-tapes of test candidates in a testing center at a particular time to any test sponsor whose test was being administered at that time in such test center. Where you have chosen to take your test through our online proctoring platform, the photos, audio- and video-tapes of your testing session will be supplied to the relevant test sponsor and any of their appointed agents to assist with their management of your test.
Other Disclosures and Transfer of Information
We may disclose Personal Data in the following situations: (a) in response to a subpoena, court order or legal process, to the extent permitted and required by law; (b) to protect your security, or the security of other persons, consistent with applicable law; (c) to address actual or suspected fraud or other illegal activities; (d) in connection with a sale, joint venture or other transfer of some or all of the assets of Kryterion; (e) where you explicitly agree to allow Kryterion to disclose your Personal Data to select third parties; and (f) to our subcontractors and/or agents (such as, those third parties hosting one or more of our websites; processing credit card transactions and payments; fulfilling and processing orders; assisting us with marketing and promotions; collecting web analytics data, etc.), including independent testing centers solely for the purpose of enabling them to perform services on our behalf (collectively "third party" or "third parties").
Kryterion will have agreements in place with these third-party subcontractors and/or agents prior to the transfer of any Personal Data requiring that such subcontractors and/or agents protect the Personal Data in a manner that is consistent with EU GDPR. All subcontractors and/or agents will be instructed that they may only use the Personal Data for the purposes identified by Kryterion. In cases of onward transfer to third parties of Personal Data of EU individuals received, we are not responsible for the processing of Personal Data by any third party, other than those third parties acting as our subcontractors to process data on our behalf.
Kryterion stores information about visitors to our Website and users on servers located in the United States. By using our services, you consent to the storage of your information inside the United States. If you are using the services from outside the United States and the European Union, please know the information you submit will be transferred to and stored in servers in the United States or other countries. The data protection and other laws of the United States and/or other countries might not be as comprehensive as those in your country. By submitting your data and/or using our services, you acknowledge the transfer, storing, and processing of your information in and to the United States.
As described above, Kryterion also may subcontract the processing of your data to, or otherwise share your data with, service providers and others in countries other than your country of residence, including the United States, in accordance with applicable law. Such third parties may be engaged in, among other things, the provision of services to you, the processing of transactions and/or the provision of support services. By providing us with your information, you acknowledge any such transfer, storage or use.
In compliance with the Privacy Shield Principles, Kryterion commits to resolve complaints about our collection or use of your personal information. EU individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Kryterion at: firstname.lastname@example.org.
Kryterion has further committed to cooperate with the panel established by the EU data protection authorities (DPAs) with regard to unresolved Privacy Shield complaints concerning data transferred from the EU.
If applicable, you may make a complaint to the data protection supervisory authority in the country where you are based. Alternatively, you may seek a remedy through local courts if you believe your rights have been breached.
If you still believe that your complaint or dispute has not been resolved, you can invoke binding arbitration as a last resort (if permitted with respect to your complaint), by providing notice to us in the manner indicated in Annex I to the EU – U.S. Privacy Shield Principles, available online, and following the procedures set forth in such Annex. The location of the arbitration will be in the United States.
Please note that, despite the Court of Justice of the European Union’s invalidation of the EU-US Privacy Shield Framework as a mechanism for transfers of personal data between the EU and the U.S. in Case C-311/18, Kryterion intends to maintain its self-certification under the EU-US Privacy Shield Framework and remains committed to complying with the Privacy Shield Principles. Kryterion will no longer rely on Privacy Shield as a mechanism to transfer personal data from the European Economic Area to the United States. For more information on the U.S. Department of Commerce’s continued administration of the Privacy Shield program, please visit https://www.privacyshield.gov/article?id=EU-U-S-Privacy-Shield-Program-Update.
By using our Site(s), you agree to the use of the cookies as described above for the collection of information in order to provide the products or services you have requested and for improvements, as we deem appropriate for our legitimate purposes, related to our products and services.
Cookies.Cookies are small text files that a web server places on your computer. Cookies contain information that can later be read by the web server that originally placed the cookie on your computer.
Below are the main types of cookies we use and what we use them for:
Strictly Necessary Cookies. These cookies are essential in order to enable you to move around the Site(s) and use its features, such as accessing secure areas of the Site(s). Without these cookies, services you have asked for, like shopping carts or e-billing, cannot be provided.
Performance Cookies. These cookies collect information about how visitors use a website, for instance which pages visitors go to most often, and if they get error messages from web pages. Some of the performance cookies are analytics cookies using third party web analytics software, which allow us to understand more about how our Site is used. Performance cookies are not used to collect information that identifies a visitor. All information these performance cookies collect is aggregated and therefore anonymous. The aggregated data is only used by us to improve how our Site works. We might also use performance cookies to highlight our products or services which we think will be of interest to you based on your use of our Site. By using this Site, you agree we may place these types of cookies on your device
How to Manage Cookies
If you block cookies or cookies are not enabled on your computer, it will mean that your browsing or purchase experience on our Site(s) will be limited. Some active content, movies and online shopping baskets, for example, may not work correctly.
Resolution of Concerns
Kryterion endeavors to respond to your inquiry within 30 days. If you believe you have not received a timely acknowledgement of your inquiry or concern, or if you believe your inquiry or concern was not satisfactorily addressed by Kryterion you should contact (at no charge) your state or national data protection authority. A list of National Data Protection Authorities can be found on the National Data Protection Authorities website. Kryterion has committed to cooperate with the Data Protection Authorities and will comply with the information and advice provided to it by the panel of DPAs in relation to such unresolved complaints.
7776 South Pointe Pkwy W, Suite 200
Phoenix, AZ 85044
+1 (602) 659-4660
429-433 Pinner Road
Middlesex HA1 4HN
2021 © Kryterion, Inc. All Rights Reserved.