We are the controller
Exam Espresso is responsible for processing your personal data on this website. You reach us through the feedback form.
We have not appointed a data protection officer because the law does not require one for us.
We collect only what the service needs
We process the following data:
- Access requests: your email address and the country, industry and position you pick from our lists, the version of the terms you accepted and the time of the request. We keep a request until we decide on it. If we open your account, the request becomes your account; if we decline it, we delete it, email address included.
- Account data: your email address, your customer number, your country, industry and position, your account role and status, the date and version of the terms you accepted, and, if a colleague invited you, their customer number. We keep no name.
- Sign in data: the time of each sign-in and, if you sign in by email, a six digit code we send to your address. It is valid for 10 minutes and stored only in hashed form.
- Session data: a hashed session identifier, your IP address and your browser's user agent, for as long as the session is valid.
- Learning data: your test attempts, your answers, your results, and a record of which questions were delivered to your account and when.
- Feedback: your rating of a question or a test, the category you choose and the comment you write, with the question and the sitting it belongs to.
- Feedback form messages: what the message is about, the exam and page it concerns, how much it affects you and your message, with your browser, operating system and screen size. Your email address only if you are not signed in and choose to give it. Before 30 September 2026 the contact form also kept your name and email address.
- Plans waiting list: your email address and, if you choose to give them, your exam, the month of your exam and the price you would expect to pay.
- Emails we send you: which email, when, and whether it was delivered.
- Use of the service: which tests you start and finish, when a daily limit was reached, invitations and feedback, recorded by our own server with your account. Where you first came from: a campaign tag in the link you followed and the website that sent you, kept in your browser until you ask for access and then stored with your request and account. No third party receives any of this.
- Invitations: whose link brought you (a customer number), whether you started practising, and a scrambled form of your connection address that only tells us whether you asked from the same connection as the person who invited you. It cannot be turned back into the address.
- Security log: security relevant actions such as signing in, changing access or deleting an account, recorded with the acting email address, the IP address and the action.
We do not use analytics, tracking, advertising, third party fonts or third party scripts.
Why we process your data and on what legal basis
- To handle your access request, create and run your account, sign you in, deliver tests, grade them, show your results and study suggestions: Art. 6 (1) (b) GDPR (performance of the contract with you).
- To answer feedback and contact messages and to check and correct questions on the basis of your feedback: Art. 6 (1) (b) GDPR where it concerns your account, otherwise Art. 6 (1) (f) GDPR. Our legitimate interest is answering enquiries and keeping our questions correct.
- To keep the service secure, detect misuse, and protect our questions from copying and scraping, including session records, the security log and the record of delivered questions: Art. 6 (1) (f) GDPR. Our legitimate interest is a secure service and the protection of our content.
- To write to you once plans open, if you joined the plans waiting list: Art. 6 (1) (a) GDPR (your consent). You can withdraw it at any time through the feedback form.
You need to give your email address, country, industry and position to request access, and your email address to sign in. Without them we cannot provide the service.
Who receives your data
We use these service providers, who process data on our behalf (Art. 28 GDPR):
- Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, hosts our server and database. Your data is stored on servers in the European Union.
- Sendinblue SAS (Brevo), 106 boulevard Haussmann, 75008 Paris, France, sends our emails, such as sign in codes and invitations. For this it processes your email address and the content of the message within the European Union.
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, keeps the spreadsheets in which we record contact messages sent before 30 September 2026 (with your name, email address and message) and feedback (with your account number only, never your name or email address).
- Anthropic, PBC, 548 Market Street, San Francisco, CA 94104, USA, provides the AI model that helps us review feedback each night. It receives the text of the feedback and the question concerned, never your name, email address or account number.
We do not sell your data and do not share it with anyone else, unless the law obliges us to, for example towards authorities.
Where your data is processed
Our server, database and mail provider are in the European Union. Google may process the spreadsheets, and Anthropic processes the feedback text it reviews, in the United States. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR). For Anthropic, the transfer is based on the European Commission's standard contractual clauses (Art. 46 GDPR).
How long we keep your data
- Sign in codes: 10 minutes. Expired codes are deleted every hour.
- Sessions: until the session expires, at the latest after 14 days without use or 30 days in total. Expired sessions are deleted every hour.
- Account data, learning data and feedback: until your account is deleted. Feedback in our spreadsheet carries only your account number, which no longer points to anyone once the account is deleted.
- Customer number: the number itself is kept after your account is deleted, marked closed and linked to nothing, so it is never given to anyone else. On its own it does not identify you.
- Free exam offers and invitations: a claimed offer or an invitation reward is a line in your credit history and is deleted with your account. An inviter sees only how many colleagues are waiting and how many joined, never who.
- Feedback and contact messages: until your request is settled, at the latest 24 months after the message.
- Plans waiting list: until we have written to you that plans are open, at the latest 24 months after you joined.
- Record of emails sent: 12 months, then it is deleted.
- Use of the service: 25 months, then it is deleted; with your account at the latest.
- Security log entries: 12 months, then they are deleted.
- Database backups: they roll over within 14 days, so deleted data disappears from backups within that time.
You can delete your account yourself at any time on the Account page. This immediately deletes your account, your sessions, your attempts, your answers and your feedback in our database. Security log entries remain for up to 12 months and are then deleted.
We use one strictly necessary cookie
When you sign in, we set a single session cookie named __Host-trainer.sid. It keeps you signed in, cannot be read by scripts, and expires after 14 days without use or 30 days in total. This cookie is strictly necessary to provide the service you asked for, so it does not need your consent under Art. 5 (3) of the ePrivacy Directive (2002/58/EC).
We set no other cookies and use no tracking of any kind.
We make no automated decisions about you
We do not use automated decision making or profiling within the meaning of Art. 22 GDPR. The recommended next step shown after a test is a study suggestion calculated from your results. It has no legal effect and does not affect your access. An AI model helps us decide whether feedback on a question is right; it decides about the question, not about you.
Your rights
You have the right to:
- access the personal data we hold about you (Art. 15 GDPR),
- have incorrect data corrected (Art. 16 GDPR),
- have your data erased (Art. 17 GDPR),
- have processing restricted (Art. 18 GDPR),
- receive your data in a structured, machine readable format (Art. 20 GDPR),
- object to processing (Art. 21 GDPR), as described below,
- withdraw any consent you have given, with effect for the future (Art. 7 (3) GDPR). We currently do not rely on consent for any processing.
To exercise these rights, write to us through the feedback form and quote your customer number. You can delete your account yourself on the Account page.
You can object to processing based on legitimate interest
Where we process your data under Art. 6 (1) (f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will then stop the processing unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
You can complain to a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state where you live, where you work or where the alleged infringement took place (Art. 77 GDPR).
Version of this policy
This privacy policy is version 2026-10-01. We update it when our processing changes and publish the new version on this page.