Your data security is our top priority at SmartGradeAI POLIMAS
SmartGradeAI implements enterprise-grade security measures to protect all user data and ensure the integrity of the educational assessment process at POLIMAS.
All data transmitted between your device and our servers is encrypted using industry-standard TLS 1.3 protocol with 256-bit AES encryption.
Multi-layer authentication system with password hashing using bcrypt algorithm, session management, and optional two-factor authentication (2FA).
Automated daily backups with redundant storage across multiple secure locations. Recovery Time Objective (RTO) of less than 4 hours.
Role-based access control (RBAC) ensuring users only access data relevant to their role. All access attempts are logged and monitored.
| Data Type | Purpose | Retention Period |
|---|---|---|
| Personal Information Name, Email, Student/Staff ID |
Account creation and identification | Duration of enrollment/employment + 1 year |
| Academic Data Quiz responses, Grades, Submissions |
Educational assessment and grading | Academic year + 5 years (archive) |
| Usage Data Login times, IP addresses, Device info |
Security monitoring and system optimization | 90 days |
| Communication Support tickets, Feedback |
User support and system improvement | 2 years |
Fully compliant with Personal Data Protection Act 2010
Information Security Management Standards
Malaysian Qualifications Agency compliance
Aligned with international privacy standards
Automated monitoring systems detect potential security incidents within minutes
Security team evaluates the severity and scope of the incident
Immediate action to prevent further damage or data exposure
Fix vulnerabilities and restore normal operations
Affected users notified within 72 hours as per PDPA requirements
security@polimas.edu.my
Response within 24 hours04-979 8000 ext 1234
24/7 for critical issuesReport vulnerabilities
Rewards up to RM1000Last Updated: January 15, 2025
This security and privacy policy is reviewed quarterly and updated as needed to reflect changes in technology, regulations, and best practices. Users will be notified of any significant changes via email and system notifications.