Skip to document
MarkBook®Back to homepage

MarkBook® Services Privacy Policy

Effective date: September 30, 2026

1. About this policy

MarkBook® is provided by Asylum Software Inc., operating as The Acadiem Group (“MarkBook®,” “we,” “us,” or “our”). This policy covers MarkBook® Online and MarkBook® CONNECT, including their account administration and support (the “MarkBook® Services” or “Services”). It does not cover our public website, store or MarkBook® for Windows.

“Personal information” means information about an identifiable individual, including information that can reasonably be linked to that individual. This policy explains our handling of information about educators, students, guardians and other authorized users. Please also consult your school or school board's privacy notices for its own information practices.

2. Our role and your educational organization

MarkBook® provides classroom assessment, grade management, attendance, reporting and related communication tools. Teachers may obtain their own accounts and create classes, or schools and school boards may arrange and manage access. Students and guardians create CONNECT credentials after access is enabled through the applicable teacher or educational organization.

Educational organizations determine the educational purposes and authority for handling student records. MarkBook® processes those records to deliver and support the service and remains responsible for its own privacy obligations. Paying for an individual subscription does not, by itself, determine who controls school records. If instructions about access, transfer or deletion conflict, we verify authority with the relevant parties before acting.

3. Categories of personal information

The information handled depends on the features used and the records supplied by authorized users and educational organizations. It includes the following categories; not every field is collected for every person.

Account and access information: names, email addresses, usernames, authentication information, roles, school or organization associations, student–guardian account links, invitations, account status, subscription entitlements and records of required confirmations. If you use an external sign-in provider, section 12 describes that information.

Student and classroom information: student names and identifiers; school, class, course and enrolment details; assessments, grades, attendance, comments and other classroom records; reports and imported or exported records. Depending on what is entered, these records may also include contact details, dates of birth, gender, photographs, program information and notes. Some information can be sensitive, particularly information included in free-text notes or attachments.

Communications and support information: report recipients and delivery information, service communications, support enquiries, correspondence and any records or attachments supplied for troubleshooting.

Technical and usage information: sign-in and activity timestamps, feature usage, browser and device information, network information such as IP addresses, and diagnostic, error and security records generated when the Services are used.

Many classroom fields are optional. Users should provide only information needed for their authorized educational purposes and avoid unrelated sensitive information in notes, reports and support requests.

4. Where information comes from

We receive information from users and their educational organizations, including through account setup, classroom entry, imports, reports and support. Students and guardians provide information when establishing or using authorized CONNECT access. Information is also generated through use of the Services or received from a selected sign-in provider. Account administration may receive subscription status or transaction references from the separate purchasing process; this policy does not describe payment processing in our store.

5. How we use information

Providing the educational service: we use account and classroom information to establish authorized access, manage classes and assessments, calculate and present results, generate reports and provide selected CONNECT and communication features. Educational decisions remain with educators and their organizations.

Administration and communication: we use account, entitlement and contact information to administer subscriptions and permissions, deliver requested reports and transactional messages, and communicate service, security and policy information.

Support, security and reliability: we use relevant account, classroom, support and technical information to investigate enquiries, troubleshoot faults, maintain and recover the Services, prevent misuse and protect accounts and records.

Product improvement: we use usage and diagnostic information to understand feature use and improve MarkBook®. We minimize the information used and use aggregated or de-identified results where practicable. Student information remains limited to the authorized educational service and its support, security and improvement, not an unrelated commercial purpose.

Legal and contractual responsibilities: we use information as necessary to respond to authorized requests, comply with applicable law and agreements, and establish, exercise or defend legal rights, subject to the restrictions applicable to educational records.

We do not sell information from the Services or use it for research, advertising, data brokerage, AI features or AI training. Teachers receive marketing messages only if they separately opt in; using MarkBook® or accepting its terms does not subscribe them to marketing. They may unsubscribe from marketing without losing service access. A materially different use requires appropriate notice and any required authorization or consent before it begins.

6. Education privacy and children

In Canada, relevant privacy requirements include the federal Personal Information Protection and Electronic Documents Act (PIPEDA) for applicable commercial activities, and applicable provincial privacy laws. Ontario school boards are subject to the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA) and educational-record requirements under the Education Act. Other educational organizations may be governed by different provincial legislation. We handle records within our role as a service provider and work with customers to support their applicable requirements; a teacher's acceptance of this policy does not replace a board's approval or legal authority.

For U.S. educational organizations subject to the Family Educational Rights and Privacy Act (FERPA), the organization must establish a permitted basis for providing education records. Where MarkBook® acts under FERPA's school-official exception, our use and maintenance of those records are subject to the organization's direct control and the applicable agreement. We use them only for authorized purposes and do not redisclose them except as authorized and permitted by law. We assist the organization with applicable access and correction requests.

CONNECT gives students and guardians authorized access to educational information. Children may use it only with the authorization required for their age, location and educational setting.

The U.S. Children's Online Privacy Protection Act and its implementing Rule (COPPA) establish requirements for covered online collection from children under 13. Before a child under 13 uses CONNECT, the required parental consent or legally permitted school authorization must be in place. A school or school board may authorize use on a parent's behalf only where the law allows it and only for the authorized educational purpose. Where school authorization is not sufficient, the required verifiable parental consent must be obtained before the covered collection or use begins. A child's creation of login credentials does not replace that authorization.

Parental consent does not replace required school or board approval, override applicable school policies, or authorize an educator to disclose educational records without the necessary authority. These authorization requirements also apply to continued use by existing student accounts.

Children's information is used for the authorized educational service and its necessary support and security, not advertising, marketing or unrelated commercial profiling. We work with educational organizations and families on required notices and requests to review, correct or delete children's information or stop further collection. MarkBook® remains responsible for its own obligations under applicable law. Parents and guardians may contact privacy@markbook.com directly, including if they believe a child is using CONNECT without the required authorization.

7. Access and sharing

Access to application information is restricted to authorized employees and contractors with a work-related need. Those personnel access application information from within Canada. Troubleshooting may involve authorized access to a teacher's account or a limited report or support attachment, using the minimum information needed or information specifically authorized by the person entitled to direct its use. We do not use screen sharing for support.

Service providers perform functions such as hosting, authentication, email delivery and technical operations. We limit information supplied to them to their service purposes and require appropriate confidentiality, security and use restrictions. Using a provider does not remove MarkBook®'s own responsibilities.

Authorized users can share records through reports, exports, CONNECT and email. Emailed reports pass through delivery systems and recipients' email providers and may contain student information. Authorized school or board personnel may access information within their authority. We may also disclose information when lawfully instructed by the responsible customer, necessary to provide or protect the service, or required by law. We assess legal requests and limit disclosure to what is appropriate and required.

Any transfer of personal information connected with a merger, reorganization or transfer of the Services must comply with applicable law and contractual restrictions, preserve applicable privacy protections and include required notices or consent. Such a transaction does not authorize unrelated uses of student information.

8. Location and safeguards

The core application and primary application data are hosted using Microsoft Azure services in Canada. Supporting providers' processing, and processing by recipients' systems, may occur outside Canada and may be subject to the laws of those locations. Our Canada-only personnel-access statement does not mean that all third-party processing occurs in Canada.

We use safeguards appropriate to the sensitivity of the information, including access controls, encrypted communications and storage, backups, security testing, and incident-response and recovery practices. We review safeguards as the service and risks change. No service can eliminate all risk. When an incident requires notification, we notify affected customers, individuals or authorities as applicable and provide information needed for them to respond.

9. Retention and deletion

We keep information for as long as reasonably necessary for the purposes described here, applicable customer instructions or agreements, and legal requirements. Different records have different retention periods. We review continued need and do not retain information indefinitely simply because an account exists.

Expiry of a teacher's paid subscription ends ordinary teacher access but does not itself delete records or immediately end existing CONNECT access. Authorized customers may request an export or temporary access arranged through support. Continued CONNECT access remains subject to authorization, the educational purpose and the applicable retention schedule; it does not create a permanent archive entitlement.

When information is no longer needed, we securely delete it or make it non-identifiable. Authorized requests can result in earlier deletion. Limited copies in protected backups expire through the applicable recovery cycle. We restrict their ordinary use and address previously approved deletions when restoring backups. Any required legal hold is limited to the information and period needed.

10. Requests, choices and complaints

Contact privacy@markbook.com to request access, correction or deletion, withdraw consent where it is the basis for processing, or raise a privacy concern. Students and guardians may also contact their school or board concerning school-controlled records. We coordinate with that organization as appropriate without preventing individuals from contacting us directly.

We verify identity and authority using information proportionate to the request. We explain any applicable legal or contractual limitation and respond within applicable legal deadlines. Withdrawal or deletion can affect features that require the information. Our support and privacy teams can explain those effects before a request is carried out.

Our Privacy Officer handles privacy enquiries and complaints. You may also contact the applicable privacy regulator, such as the Office of the Privacy Commissioner of Canada or a provincial privacy commissioner, depending on the organization and law involved. You do not have to complete our complaint process before exercising a legal right to contact a regulator.

11. Cookies and browser storage

The Services use cookies and similar browser technologies, including local storage and session storage, to support sign-in, maintain sessions, remember preferences and operate security features. A cookie is a small item stored by a website in your browser; local and session storage provide other ways to retain information on your device. Some storage lasts only for a session, while other items remain until they expire or are cleared.

Authentication providers may also use cookies or browser storage when you choose their sign-in services. Microsoft's authentication library stores account information and authentication tokens in the browser to support sign-in and token renewal. Provider information is described in section 12.

You can manage cookies and site storage through your browser settings. Blocking or clearing necessary items may sign you out, remove preferences or prevent features from working. We do not use the Services for advertising tracking. Where optional technologies require consent, we obtain it before using them; an informational cookie notice is not a substitute for required consent. Our separate public website and store may use different technologies and are outside this policy.

12. Signing in with Google or Microsoft

MarkBook® supports eligible personal and school/work Google and Microsoft accounts for individual subscriptions and school or board arrangements. Availability depends on the account and feature being used, and organization-managed access is subject to that organization's policies. Student and guardian sign-in options are introduced separately within CONNECT, subject to the authorization requirements in section 6.

When you choose either provider, we receive identity information such as your provider account identifier, name and email address or username, and organization/domain information where supplied. Google also supplies email verification status and may include a profile-image URL in its signed identity credential; we do not need that image for authentication. MarkBook® does not receive your Google or Microsoft password.

We use and store the necessary identity information and account links, including connection and verification timestamps where used, for authentication, profile and account administration, organizational access and security—not unrelated analytics or marketing. Its access, sharing, retention and deletion follow sections 7–10, including restricted support access and supporting service providers.

Google Sign-In does not request Gmail, Drive, Classroom, contact or calendar access, or Google access or refresh tokens for ongoing access to those services. Microsoft Sign-In does not use the connection to access Outlook messages, OneDrive files, Teams content, contacts or calendars. Browser storage for sign-in is described in section 11.

MarkBook®'s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We explain any future additional data request or new use and obtain the required consent before accessing the additional data or beginning that use.

You can manage connected-app permissions through your provider account and contact us about unlinking or deleting your MarkBook® account. Unlinking may affect sign-in and does not itself delete educational records. Signing out of MarkBook® does not necessarily sign you out of your provider. Google and Microsoft handle their authentication services under the Google Privacy Policy and Microsoft Privacy Statement.

13. Changes

We display the effective date of this policy and notify affected users or customers of material changes by email or an in-application notice. Where a change requires new consent, including a new use of Google information, we obtain it before starting the changed processing. An editorial update does not itself require a new consent request.

14. Contact

Privacy Officer, Asylum Software Inc., operating as The Acadiem Group
18 King Street East, Suite 1400
Toronto, Ontario M5C 1C4, Canada
Privacy requests: privacy@markbook.com
Service support: support@markbook.com
Formal legal notices: legal@markbook.com

Business telephone: 1-844-ACADIEM (1-844-222-3436)