For school owners: privacy, security and procurement
Last updated 06.10.2026. This page collects what school owners, IT leads and data protection officers usually ask before a pilot. The details are in the privacy policy, the data processing agreement and the DPIA material.
1. Who provides the service
Graidable is run by Lukas Thrane (sole proprietorship), Norwegian org. no. 936 043 925, Vegamot 1N, 7049 Trondheim, Norway. Contact for privacy, security and agreements: [email protected].
Graidable is run by one person today, so you talk to the person who built it. If the service closes, you can export your results, and we confirm in writing that all data is deleted.
2. Who uses the app
Teachers only. Students do not sign in or use Graidable. The teacher uploads the exam, the marking guide and the answers. The AI suggests points and feedback, and the teacher reviews, changes and approves every grade. The teacher sets the grade.
3. Status of each item
| Item | Status |
|---|---|
| Data processing agreement | Ready as a template. We are happy to sign your own template instead. |
| DPIA material | Ready |
| Sub-processors and transfers | Ready (see section 4 and the DPA) |
| Description of the AI service (models, data flow, no training) | Ready, sent on request |
| Feide login (Norway) | Application sent to Sikt on 06.10.2026. Teacher login is in development. |
| Automatic deletion | Not yet. Deletion at the end of the pilot or the school year is agreed with you. |
| School account with an administrator | Not yet. Each teacher has their own account today. |
| Accessibility statement (WCAG 2.1) | In progress |
4. Where data is processed
- Upload: files are stored with AWS in Ireland, the database with Railway in Amsterdam.
- Reading: scanned pages are read by LandingAI in the EU.
- Sorting (US): TypeSafe (the model Jev) suggests which student each page belongs to. It receives the page text and the class list with names, student numbers and candidate numbers. No page images.
- Questions and criteria (EU): drafted from the teacher's own files, with no student work.
- Grading (EU): one student at a time, with Microsoft Azure or Google Vertex AI on EU endpoints. Lines with the student's name are removed from the text.
- Review: the teacher approves. Feedback to the student is made only from approved results.
Every AI call is routed through OpenRouter (US). The transfers to the US are covered by the EU standard contractual clauses (SCCs). Every AI call requires zero data retention and no data collection by the provider. Neither Graidable nor the AI providers train on student work.
If you use candidate numbers instead of names on the class list and the answers, the sorting sees no names.
5. Rules
- The teacher sets the grade. The AI only drafts, and nothing reaches the student before the teacher has approved it.
- EU AI Act: AI that evaluates learning outcomes is high-risk. Human oversight is built in, and the school is the deployer.
6. Price and procurement
You pay per student graded with AI. Setting up, reading the answers and reviewing are free. For schools and school owners, price and invoicing are agreed directly.
7. Pilot
A pilot is free and covers, for example, one exam, one class or one term. It includes setting up the exam with the teachers, a data processing agreement before we receive student data, and deletion when the pilot ends. Contact [email protected] or use the contact page.