Wonder Security & Trust
Data Protection & Privacy
Data Protection & Privacy
Encryption
Imagine protects data in transit and at rest using a combination of transport encryption, managed cloud encryption, and application-level encryption for selected sensitive identifiers.
| Control | Configuration |
|---|---|
| Public application traffic | HTTPS with TLS 1.2 / TLS 1.3 to the AWS Application Load Balancer |
| HSTS | Enabled, including includeSubDomains |
| Backend transport | TLS terminates at the AWS Application Load Balancer before traffic is forwarded to the application service |
| Redis / Valkey in transit | Encrypted using TLS (rediss) |
| AWS S3 at rest | Server-side AES-256 encryption |
| MongoDB Atlas at rest | Encrypted storage enabled |
| Sensitive institutional identifiers | Additional application-level encryption before database storage |
| Redis / Valkey at rest | Encrypted at rest using AWS-managed encryption |
Data We Process
Depending on the features used by the institution, Imagine may process the following data types:
| Category | Examples |
|---|---|
| User & Identity | Name, email address, role and permissions, organizational affiliation, encrypted personal/student identifier, authentication and account-security data |
| Academic | Courses and syllabi, course enrollments, attendance, groups and academic structure |
| Submissions & Assessments | Assignments and exams, submissions, grades, feedback |
| Learning Content | Documents, presentations, PDFs, videos, transcripts and other learning materials |
| Meetings & Recordings | Online meeting information, class recordings, transcripts and attendance data |
| User-Generated Content | Assignment responses, code, forum content, messages and AI chatbot interactions |
| Support & Communications | Support requests, ticket attachments, in-app communications and transactional email |
| Usage & Learning Analytics | Login and activity information, resource views, submissions, forum activity, attendance, media activity, AI tool interactions and IP addresses in security logs |
File & Content Protection
Imagine stores institutional files in private AWS S3 storage, with institution-scoped organization, controlled content delivery, encryption, versioning, and malware protection.
| Control | Configuration |
|---|---|
| File storage | Private AWS S3 storage |
| Institution separation | Institution-scoped object namespaces |
| Encryption at rest | Server-side AES-256 encryption |
| Versioning | S3 Versioning enabled |
| Public access protection | S3 Block Public Access enabled for private storage |
| Private content delivery | AWS CloudFront signed URLs |
| Malware protection | AWS GuardDuty Malware Protection for S3 |
Data Retention & Deletion
Imagine's retention model is designed to follow each institution's academic, legal, and operational retention requirements.
| Data / Process | Retention & Deletion |
|---|---|
| Academic records | Retained according to the institution's retention requirements. |
| User deactivation | Deactivation prevents account access while allowing required academic records to be retained. |
| AI chat history | Retained until deletion is requested by the institution. |
| Usage & learning analytics | Retention is determined by the institution. |
| Individual deletion requests | Personal data can be deleted or anonymized at the institution's request, subject to applicable academic and legal retention requirements. |
| Institutional offboarding | Institutional data is retained for up to 90 days following termination to support data export and transition, after which it is deleted from Imagine systems. |
Sensitive Data & Analytics
Imagine processes academic and learning activity data to provide students and authorized academic staff with learning and course analytics.
| Topic | Handling |
|---|---|
| Personal identifiers | Institutional personal/student identifiers are encrypted at the application level |
| Accessibility preferences | Accessibility display preferences are stored locally in the user's browser and are not maintained as a health or disability profile |
| Student analytics | Individual and aggregate analytics may include grades, submissions, attendance and learning activity |
| Analytics access | Individual and course analytics are available to authorized course staff; students can access their own academic information |
| Automated decisions | Learning analytics do not automatically change enrollment, access or student status |
| Dropout prediction | Under development; the current implementation prepares academic and engagement features but does not generate student risk scores or take automated actions |