Where your data lives, and for how long.
This page is designed to be printed and included in a file. It contains only verifiable facts: the actual location of the hosting infrastructure, how institutions are isolated from one another, the retention periods effectively enforced by a scheduled task, and our position with regard to the EU Artificial Intelligence Regulation.
European Union, and we say exactly where.
"European hosting" means nothing if you do not specify what, or where.
Data, in Ireland
The database and files — student submissions, instructions, solutions, course materials — are hosted within the European Union, in Ireland. Encryption in transit and at rest.
Page rendering, in Ireland
Application pages are rendered in the same region as the database. This is not solely a compliance matter: it is also what makes the application fast, since no request crosses the Atlantic.
Marking processing, in Germany
The service that orchestrates marking runs in Frankfurt. It reads the files, prepares the analysis request, and writes the result.
The analysis itself is entrusted to a specialist model provider, which is not hosted by us. Its processing terms, location, and non-retention commitment are set out in the contractual documentation we provide on request. No submission, marking scheme, or exercise is used to train any model whatsoever.
What is deleted, and when.
Four retention periods, applied automatically. All other data is kept for as long as the institution remains a client.
These three periods are not a policy written somewhere: they are enforced by a scheduled task that runs every night. A retention period that is announced but never executed is a promise no one keeps.
An exam adjustment — such as extra time — is recorded as a number of minutes, and nothing more. No reason, no medical document, no reference to a disability enters CORRAICT: these elements remain in your institution's records. The decision is yours; the product simply applies it and keeps a record.
What falls under high risk, and what does not.
Both distinctions matter for an institution: they do not carry the same obligations.
Marking, a high-risk system
- Assessing learning outcomes falls under Annex III of Regulation (EU) 2024/1689.
- We acknowledge this rather than circumvent it: mandatory human oversight, no grade published without a teacher's approval.
- Each proposed point is linked to a criterion in the marking scheme and accompanied by its justification — explainability is not an afterthought.
- The history of an assessment — proposal, amendment, approval, timestamp — is retained and exportable.
What is not an AI system
- The composition record: browser events timestamped server-side, counted. No model is involved, nothing is inferred.
- The individualisation of exam papers: a deterministic calculation based on the student's address and the bounds declared by the teacher.
- No monitoring of the student during the exam: no webcam access, no emotion recognition — which Article 5 prohibits in educational institutions.
- No tool for recognising generated text, neither integrated nor developed.
What we provide on request.
What falls within the contract is not published on a web page: it is exchanged, dated, and signed.
Data processing agreement, detailed list of sub-processors with their role and location, legal bases by processing activity, technical and organisational measures, data breach procedure, reversibility and export arrangements. Send your request to the data protection contact point; we respond within five working days.
The platform's legal notices and data policy complement this page.
Compliance with the European AI Regulation.
Our role, the schedule of obligations, our concrete commitments and what we do not do. This document had its own page until 27 August 2026.
Our commitment
OAVENTURE intègre des technologies d’intelligence artificielle dans son offre. Nous considérons l’encadrement de l’IA comme une responsabilité, au même titre que la protection des données personnelles. Cette page décrit notre démarche de mise en conformité avec le Regulation (EU) 2024/1689 (« IA Act »), en complément de notre politique de confidentialité / conformité RGPD et de nos mentions légales.
The framework applies progressively. We align our commitments with the regulatory timetable and keep this page updated as obligations come into effect.
Our role under the regulation
Under the AI Act, OAVENTURE acts as a deployer: we integrate and use AI models and services provided by third parties (for example, providers of general-purpose AI models) to deliver our features. We do not develop our own foundation models.
To this end, we select providers that are themselves committed to a compliance approach, and we use their systems in accordance with the instructions and conditions they set out.
Regulatory framework and timeline
The AI Act has been in force since 1 August 2024 and applies in stages:
- Since February 2025: prohibition of unacceptable-risk AI practices (social scoring, manipulation, certain biometric uses) and AI literacy obligation for teams.
- Since August 2025: obligations applicable to providers of general-purpose AI models.
- Upcoming deadlines: the obligations specific to high-risk AI systems, as well as enhanced transparency rules, come into application on a timeline extending to 2027–2028 depending on the nature of the systems.
Our approach anticipates these deadlines: we are already preparing the documentation, governance and controls required, without waiting for them to become binding.
Our concrete commitments
For features likely to fall under high-risk use cases, we implement the following measures:
Human oversight. Our processes provide for human involvement in significant decisions. Outputs produced by AI are designed as a decision-support aid, which a competent person can review and correct, and not as unsupervised automated decisions.
Transparency. We inform the individuals concerned when they interact with an AI system or when such a system is used in relation to them, and we explain, in understandable terms, the purpose of that use.
Compliant and controlled use. We use third-party AI systems in accordance with their intended purpose and their suppliers' instructions, and we monitor their operation within the scope of our activities.
Logging and traceability. We retain the information needed to trace the operation of the relevant systems, in compliance with applicable retention periods and purposes.
Data quality and relevance. We ensure the relevance of the input data we control and work to limit bias, in line with our data protection obligations.
Supplier selection. We give preference to AI suppliers committed to a documented compliance approach and offering the corresponding technical and contractual guarantees.
No prohibited practices. We do not use AI for purposes prohibited by the regulation (social scoring, exploitation of vulnerabilities, manipulation, unauthorised biometric surveillance, etc.).
Team competence. We train and raise awareness among our relevant staff on the controlled and responsible use of AI (AI literacy obligation).
What we do not do
No generated-text recognition tool. We do not integrate — and we do not develop — any system claiming to determine whether a submission was written by an artificial intelligence. Such tools do not deliver on their promise: OpenAI withdrew its own classifier in 2023 due to insufficient accuracy, and Stanford research (Liang et al., 2023) shows that they systematically flag texts by non-native writers as AI-generated. Such a verdict cannot be defended before a disciplinary panel, and it would expose the most vulnerable students. This is a design decision, not a step on our roadmap.
No monitoring of the student during the exam. No proctoring, no webcam access, no emotion recognition — which Article 5 of the regulation prohibits outright in educational institutions. Nothing is collected from the student's device: no IP address, no browser fingerprint, no inventory of open software. Tab changes are not observed.
Composition record: facts, never a judgement. When an institution enables it, CORRAICT provides the teacher with factual information about how an online submission was composed — number and length of pastes, typing pace, duration. The content of what is pasted is never recorded, no keystrokes are stored, and the list of collected items is fixed. No score, no risk indicator, no suggested action: reading and deciding are the teacher's responsibility. These items are timestamped browser events, produced without any model intervention. Our assessment is therefore that this mechanism does not constitute an AI system within the meaning of Article 3 of the regulation, and that it does not fall within the cases covered by Annex III regarding exams.
Processing decided by the institution. This collection is disabled by default. It is only enabled upon written request from the institution, which acts as data controller, and then activated exam by exam by the teacher. The student is informed on the opening screen, before they begin composing. The collected items are deleted one month after the submission is handed in.
Relationship with the GDPR
Where our AI processing involves personal data, it is carried out in compliance with the GDPR: legal basis, minimisation, information to data subjects, exercise of rights, and, where applicable, a Data Protection Impact Assessment (DPIA). AI Act compliance and GDPR compliance are pursued in a coordinated manner.
Governance and contact
AI compliance is monitored internally by our AI compliance officer. For any questions regarding our use of artificial intelligence, human oversight, or the exercise of your rights:
OAVENTURE — 13 bis avenue de la Motte-Picquet, 75007 Paris
Contact : contact@corraict.com
This document describes our commitments and our approach to compliance with Regulation (EU) 2024/1689. It does not constitute a declaration of conformity with obligations that are not yet fully applicable, and is subject to change in line with the regulatory framework and its implementing texts.
A compliance question before going further?
We are happy to spend time with your DPO or CTO, even before discussing the product.