Who operates TAIF Lab
TAIF service operator: TAIFLab
Operated by Stephen Coetzee and Astrid Schmulian in partnership
Country: South Africa
Business / legal address: To be confirmed
Privacy contact: info@taiflab.com
TAIF Learning Lab is operated in South Africa as a partnership by Stephen Coetzee and Astrid Schmulian. The confirmed business / legal address must be added before a production institutional rollout.
Responsible party and operator roles
Data-protection roles depend on how TAIF is deployed. Where an educational institution decides why and how learner assessment information is processed, that institution will ordinarily act as the responsible party and TAIF will ordinarily process the information as an operator on the institution's documented instructions. TAIF may act as a responsible party for educator-account, service-administration, security and support information where TAIF determines the purpose and means of that processing.
The institution and TAIF should confirm their exact roles, instructions, security duties, subprocessors, retention requirements, incident process and exit arrangements in writing before institutional adoption.
Information TAIF may process
TAIF collects information reasonably needed to provide and secure the service. Depending on how an instructor or institution uses TAIF, this currently includes:
- student and instructor names;
- institution-issued learner identifiers, and instructor email addresses and identity details;
- organisation, class and team membership;
- assessment questions, answer options, instructions and explanations;
- individual think responses, team answers, attempts, marks, scores and reflections;
- assessment status, progress, timing, connection checks and support incidents;
- login, invitation and authentication information for instructors; and
- technical, security and audit information reasonably required to operate and protect TAIF.
TAIF does not currently provide a separate employee-number field or a standalone student account. Students may enter an institution-issued learner identifier when forming or joining a team. TAIF normalises it, uses a keyed lookup value to find the relevant class record, and holds the identifier itself in a restricted encrypted mapping for roster reconciliation and authorised gradebook export. The identifier is not copied into ordinary attempt, team-session or analytics records.
Where Open participation is enabled, a participant who is not on the uploaded roster enters a name and institution-issued learner identifier. TAIF records these as self-reported and Unmatched until the relevant instructor or institution verifies them. TAIF otherwise receives roster information from authorised instructors or institutions, account and support information from the relevant user, and assessment, technical and audit information when people use the service.
Anonymous public demo activity
When a visitor meaningfully starts the simulated public demo, TAIF records one anonymous demo session with server timestamps, the number of committed answer attempts, completion status and, when deliberately included in the shared link, a short source tag. A temporary random session identifier is kept in the browser's session storage only to prevent refreshes and retries from duplicating that active session.
This public-demo measurement does not collect names, email addresses, student identifiers, real assessment data, IP addresses, advertising identifiers or device fingerprints, and it is not used for advertising or cross-site profiling.
Why TAIF processes information
TAIF may process this information to:
- create and manage instructor accounts and authorised access;
- create and administer classes, rosters and instructor roles;
- reconcile class rosters, place participants into teams and verify team membership using institution-issued learner identifiers;
- deliver assessments and synchronise collaborative activity across permitted devices;
- record answers, attempts, reflections and scores and provide immediate feedback;
- show results and reconnect marks to institution-issued learner identifiers during an explicit authorised gradebook export;
- support users and diagnose technical problems;
- maintain security, assessment integrity and audit records; and
- meet applicable legal requirements.
When information is required
An institution-issued learner identifier is required for roster matching, self-enrolment and personal-device team verification. In Open participation, a learner who is not found on the roster may still participate by supplying a name and identifier, but the record remains Unmatched and self-reported until reviewed. If the required information is not provided, TAIF cannot match the learner, reconnect the mark to a gradebook identifier or verify personal-device membership.
Who may see the information
- Students may see information relevant to their own participation and their team’s assessment activity. A learner identifier entered for matching is not shown to teammates.
- Authorised instructors may see class, roster, team, assessment, attempt, reflection and result information for classes they are permitted to access. Institutional identifiers are masked in ordinary screens and included in a gradebook file only through an explicit authorised export. Roles limit what each instructor can change.
- Authorised TAIF administrators may access information where reasonably necessary to operate, support, moderate or secure the service.
- Service providers may process limited information where required for hosting, databases, authentication, security or technical infrastructure.
Student information is not intended to be public.
Instructor-provided student information
Instructors or institutions may add learners to a class roster or otherwise provide learner information. They are responsible for ensuring that they are authorised to provide and use that information through TAIF and for following their institution’s rules and applicable law.
Assessment information
TAIF records assessment activity according to the assessment configuration chosen by an authorised instructor. This may include question order, scoring by attempt, team membership, access controls, individual think responses and immediate feedback.
TAIF supports the administration and recording of assessments, but the relevant instructor or educational institution remains responsible for determining official academic results and resolving academic disputes.
Service providers and international processing
TAIF uses third-party technical services where needed to run the platform. The production configuration currently identifies:
- Cloudflare — application hosting, technical infrastructure and the production database.
Depending on these providers’ infrastructure, some processing may occur outside South Africa. TAIF will use international processing only where permitted by applicable law and covered by appropriate contractual or other safeguards. The exact processing locations, subprocessors and safeguards should be confirmed in the relevant institutional arrangements before rollout. The provider list will be updated here when the production setup changes materially.
Retention and deletion
Active classes keep the information needed for normal teaching and assessment use. Archived classes remain stored, become review-only and are hidden from normal active use; an authorised Course Owner can restore them.
Deleting a class permanently removes the class and its class-specific rosters, teams, assessments, questions, attempts, answers, scores, reflections, session records and activity records through TAIF’s deletion process. Limited information may remain temporarily where reasonably required for secure backups, recovery, legal obligations or legitimate institutional record-keeping.
Instructor email sessions are designed to expire after 30 days, class-specific activation links after seven days, and colleague invitation links after 14 days. Those authentication periods do not determine how long class or assessment records are kept.
Your rights and privacy concerns
Subject to applicable law and legitimate institutional record-keeping requirements, a person may request access to personal information, correction of inaccurate information, deletion where appropriate, information about processing, or object to certain processing where legally applicable.
Send a request to: info@taiflab.com. A request to remove a student’s information does not automatically require an institution to erase legitimate academic or assessment records that it is entitled or required to retain.
Complaints
Please raise a privacy concern with TAIF first using the privacy contact above. You may also have the right to approach South Africa’s Information Regulator. The Regulator’s official contact and complaint information is maintained on its own website.
Security and changes to this notice
TAIF uses reasonable technical and organisational measures designed to protect information, including server-enforced instructor access, role-based class permissions, encrypted institution-issued learner identifiers, keyed lookup values and session controls. Student sessions, incidents, answers and routine analytics use random TAIF learner IDs rather than institutional identifiers. Full identifiers are restored only for an explicit authorised gradebook export. No online service can guarantee absolute security.
If TAIF has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, TAIF will investigate, preserve relevant records, notify the responsible institution where applicable, and support notification to affected people and the Information Regulator as required by applicable law and institutional agreements.
This notice may be updated as TAIF, its providers or applicable requirements evolve. The current version and effective date will remain displayed on this page.