Exercise feedback

Report a problem

Reporting
0/500

Terms of Use FDA Application

These Terms of Use apply to the learning and examination environment for the Utrecht University course Financial Data Analytics (USEMFDA), hereafter the FDA app. By using the FDA app, you must comply with these terms and the Utrecht University regulations relating to the use of ICT facilities.

What is the FDA app for?

You may use the FDA app only for authorised teaching, practice, assessment and administration connected with the Utrecht University course Financial Data Analytics. This includes completing exercises, mock examinations and formal examinations, reviewing feedback and managing the course where you have been given an administrator role.

You may not use the app, its accounts, interfaces, data or computing capacity for unrelated personal, commercial, teaching, research or technical purposes without prior written permission from the course coordinator.

Accuracy of exercises

We aim to keep the exercises, instructions, automated checks, feedback and example solutions accurate and up to date. However, we cannot guarantee that these materials are complete or free from mistakes. If you believe that an exercise contains an error or behaves unexpectedly, please report it to the course instructor or coordinator.

What is not allowed?

You must not:

  • share your account, password or active session, use another person’s account, or allow another person to submit work in your name;
  • access, copy, change or delete another user’s work or data without authorisation;
  • manipulate or falsely report progress, points, scores, submissions, time limits or other records;
  • attempt to reveal protected answers, assessment content or administrator functions, or bypass authentication, access restrictions or other security measures;
  • scan, probe, scrape, automate, reverse engineer, load test or test vulnerabilities in the app or its infrastructure without prior written authorisation;
  • introduce malicious code, disrupt the app, place an unreasonable load on it, interfere with other users or attempt to solve a network problem by changing or attacking systems;
  • enter confidential information, special-category personal data or another person’s personal data unless the course explicitly requires and authorises it;
  • use the app for unlawful, threatening, offensive, discriminatory, copyright-infringing or private commercial activities; or
  • use the app in breach of course assessment rules or Utrecht University’s rules on academic integrity.

How do I use the app safely?

  1. Sign in only with your own Utrecht University account.
  2. Keep login details private. Use an up-to-date device and browser, and keep your device protected with its available security updates.
  3. Check that your answers and code have been saved or submitted, especially before leaving an examination.
  4. Log out when you finish, particularly on a shared device. Do not leave an authenticated session unattended.
  5. If the app or network behaves unexpectedly, stop the affected action, keep any relevant error message, and report the problem. Do not repeatedly retry actions that could overload the service.
  6. If you discover a possible vulnerability or obtain unexpected access, do not exploit it, retain data, or share details with others. Report it promptly.

Reporting problems and security incidents

Report ordinary course or application problems to the course instructor or coordinator. Report an information-security incident, suspected unauthorised use or exposed data promptly to cert@uu.nl. If you discover a possible vulnerability, follow the UU Responsible Disclosure guidelines and email responsible.disclosure@uu.nl. Include only the information needed to investigate the report and do not send passwords or unnecessary personal data.

Monitoring

Use of the FDA app is recorded and may be reviewed to operate and secure the service, support teaching and assessment, investigate problems, and monitor compliance with these terms. Depending on the activity, records may include your institutional identifier, progress, answers, code, scores, timestamps, requested functions, IP address, browser or device information, and examination security events. Monitoring is carried out in accordance with applicable Utrecht University policy and privacy law. See the FDA app Privacy Statement for further information.

What happens if these terms are not followed?

Access to the FDA app or other relevant ICT services may be suspended while a risk or suspected violation is investigated and addressed. Depending on the seriousness, duration, frequency and consequences, Utrecht University may take proportionate technical, academic, disciplinary or legal measures. Illegitimately obtained progress, points, scores or submissions may be corrected or invalidated under the applicable course and university procedures.

Applicable regulations

These app-specific terms supplement the Utrecht University Regulations relating to the use of ICT facilities. If these terms conflict with binding Utrecht University rules or applicable law, those higher rules prevail.

Version

Version 2026-09-16.2. These terms take effect on 16 September 2026. You will be asked to acknowledge the current version before using the FDA app and again after a material change.

Privacy Statement FDA Application

In this privacy statement, we explain what happens to your personal data when it is processed for the learning and examination environment for the course Financial Data Analytics (USEMFDA), hereafter FDA app.

Who is responsible for data processing?

Utrecht University is responsible for the data processing described in this privacy statement.

For what purposes are my personal data processed?

The personal data are processed to operate and secure the FDA app and to support teaching and assessment. Specifically, the data are used to:

  • verify that you are authorised to access the application;
  • save your exercises, answers, progress, scores, badges and practice activity;
  • provide feedback and allow you to continue your work on another visit;
  • give instructors insight into participation, progress and questions that students find difficult;
  • administer timed examinations, save submissions, support approved extra time and calculate or record scores;
  • investigate technical problems and unusual device or IP-address changes during examinations;
  • record that you acknowledged the current Terms of Use;
  • maintain the application’s security, reliability, audit records and backups.

Aggregated statistics may be used to improve the course and its exercises. Your data are not used for advertising or commercial profiling.

What personal data is processed?

Users

  • Institutional student or employee number and a pseudonymous SURFconext account link.
  • An optional self-chosen nickname for private leagues.
  • FDA administrator status, where applicable.
  • The version of the Terms of Use you acknowledged and the date and time of acknowledgement.
  • Exercise and quiz progress: attempts, completion status, points, selected variants, saved code and answers.
  • Practice activity: practice dates, daily points, approximate active time, badges, streaks and game scores.
  • Mock-exam attempts: assigned questions, answers, scores, feedback, start and submission times, elapsed time and submission reason.
  • Formal examination data: assigned questions, answers and submitted code, scores, marker comments, approved extra time and examination audit events.

General

  • IP address;
  • Date and time of access;
  • Requested page or endpoint;
  • Browser and device information;
  • Failed-login and security-throttling information.

In addition, the app uses a functional cookie to keep users logged in for the duration of 1 hour.

How long is this personal data kept?

Personal data in the online practice environment are retained until the annual reset in August following the course. The course runs from September to November, but retaining the environment until August allows students, including students who may need to repeat the course, to continue accessing their exercises and progress after the teaching period. This includes:

  • student accounts and identifiers;
  • Terms of Use acknowledgement records;
  • exercise progress, saved code, points and activity data;
  • mock-exam attempts and results;
  • online examination answers, scores and results;
  • authentication and security data;
  • server backups containing these data.

After an examination, the answers and results are exported to a restricted institutional storage. These examination records are retained for two years from the examination date and are then deleted from OneDrive and any synchronised local copies. The corresponding online examination records are deleted during the next annual August reset.

Functional session cookies and authentication tokens may expire or be deleted earlier, for example after logout or when their validity period ends (1h). Data connected with a security or fraud incident may be retained until the incident has been investigated and resolved. Aggregated statistics may be retained longer only if they have been fully anonymised and can no longer be linked to an individual student.

Will my data be shared with third parties?

No.

Will my data be transferred to third countries?

No, data will not be transferred to third countries outside the European Economic Area.

What is the legal basis for this data processing?

Utrecht University is allowed to process personal data on the basis of the performance of a task carried out in the public interest (Article 6(1)(e) GDPR). Where the processing involves special categories of personal data — such as information relating to approved examination accommodations — this processing takes place on the basis of Article 9(2)(g) GDPR in conjunction with Article 30 of the Dutch GDPR Implementation Act (Uitvoeringswet AVG, UAVG).

What rights do I have under the GDPR and how can I exercise them?

The GDPR gives you a number of rights with regard to your personal data. You have the right to access your data and to have it corrected or deleted. In this processing, you also have the right to temporarily freeze (‘restrict’) the processing of your data, the right to object to the processing and the right to have your dataset transferred to another organisation.

How can I exercise these rights?

If you want to exercise one or more of the above rights, you can submit a request using the privacy request form. We will then have one month to respond to your request. For very complex requests (or if a lot of requests come in at the same time), we sometimes need more time (up to two months extra). We will let you know within that first month.

Questions? Complaints?

Do you have any specific questions regarding the above information or do you have any comments regarding this privacy statement? Feel free to contact us. You can send a message to privacy@uu.nl. The UU has appointed a Data Protection Officer (DPO). This is an internal advisor and supervisor who may also be important to you, namely if you want information about our processing of personal data or if you want to file a complaint about it. You can contact our DPO via fg@uu.nl. We would like to point out that you also have the right to file a complaint with the supervisory authority, the Dutch Data Protection Authority.

Contact details

Utrecht University
Heidelberglaan 8
3584 CS Utrecht
Tel. (030) 253 35 50

Privacy Statement: Version and Policy Document

This Privacy Statement was last modified on 16 September 2026. From time to time, we will make changes to this Privacy Statement.