Exam.ify

Privacy Policy

Last updated: January 2026

This Privacy Policy explains what personal data Exam.ify ("we", "us") collects when you visit this website, create an account, or purchase a practice test, why we collect it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Dutch GDPR Implementation Act (Uitvoeringswet AVG).

1. Data controller

Exam.ify is the data controller responsible for the personal data described in this policy. Contact details for data-protection requests are provided in Section 12 below.

2. What personal data we collect

  • Account data: your name (if provided), email address, residence country (if provided at registration), and a securely hashed and salted password. We never store your password in plain text.
  • Order and payment data: the products you purchase, the price paid, and any promotional code used. Card and payment-method details are collected and processed directly by our payment provider, Mollie B.V. — we do not receive or store your full card number, CVC, or online banking credentials.
  • Exam activity data: your answers, submission timestamps, and score for each practice test you take, stored against your account so you can review your results.
  • Technical data: standard web-server logs (IP address, browser type, device type, pages visited, timestamps), collected automatically by our hosting provider for security, abuse-prevention, and reliability purposes.
  • Communications: any information you send us directly, for example by email, including the content of your message and your contact details.

We do not knowingly collect any special category of personal data (Art. 9 GDPR, e.g. health, religion, or biometric data) and ask that you do not send us any such data.

3. Why we process your data, and our legal basis

  • To create and manage your account, and deliver purchased practice tests — necessary for the performance of a contract with you (Art. 6(1)(b) GDPR).
  • To process payment, via Mollie B.V. — necessary for the performance of a contract with you (Art. 6(1)(b) GDPR).
  • To keep financial and administrative records as required by Dutch tax law — necessary to comply with a legal obligation (Art. 6(1)(c) GDPR).
  • To secure our website, prevent fraud and abuse, and maintain service logs — necessary for our legitimate interest in operating a safe and reliable service (Art. 6(1)(f) GDPR), balanced against your rights and freedoms.
  • To respond to a message you send us — necessary for our legitimate interest in responding to inquiries (Art. 6(1)(f) GDPR), or to take pre-contractual steps at your request (Art. 6(1)(b) GDPR).

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22 GDPR), and we do not sell your personal data to third parties.

4. Payment processing — Mollie

Payments are processed by Mollie B.V., a licensed Dutch payment institution regulated by De Nederlandsche Bank. When you pay, Mollie processes your payment details as an independent controller in accordance with its own privacy policy, and shares with us only the information necessary to confirm your payment (such as the transaction status, amount, and a payment reference). We recommend reviewing Mollie's privacy policy for details of its own processing.

5. Other recipients and processors of your data

We use a limited number of third-party service providers ("processors") who process personal data on our behalf and under our instructions, bound by data-processing agreements consistent with Art. 28 GDPR, including:

  • our cloud hosting and infrastructure provider, to run this website and store account, order, and exam-attempt data;
  • Mollie B.V., to process payments, as described in Section 4; and
  • our email-delivery provider, where used to send account or order-related messages.

We do not permit any processor to use your personal data for its own marketing purposes. We do not share your personal data with third parties for their own independent purposes, except where required by law, to enforce our Legal Notice, or with your explicit consent.

6. International data transfers

Where any of our processors store or process personal data outside the European Economic Area, we ensure an adequate level of protection is in place, such as the European Commission's Standard Contractual Clauses (Art. 46 GDPR) or an applicable adequacy decision, before any such transfer occurs.

7. How long we keep your data

  • Account and exam-activity data is kept for as long as your account is active, and deleted or anonymized within a reasonable period after you request account deletion, subject to Section 7's exception below.
  • Order and invoice data is kept for seven (7) years after the end of the relevant financial year, as required by Dutch tax law (Art. 52 Algemene wet inzake rijksbelastingen), even if you delete your account.
  • Technical server logs are retained for a limited period (typically no longer than 12 months) for security and troubleshooting purposes, then deleted or anonymized.

8. Security measures

We apply appropriate technical and organizational measures under Art. 32 GDPR to protect your personal data, including: encrypted transport (HTTPS/TLS) across the website; passwords stored only as salted cryptographic hashes, never in plain text; session cookies marked httpOnly and restricted to same-site use to reduce the risk of theft or misuse; and access to account and order data limited to what is necessary to operate the service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we take reasonable steps consistent with industry practice to protect your data.

9. Your rights under the GDPR

Subject to the conditions and exceptions set out in the GDPR, you have the right to:

  • request access to the personal data we hold about you (Art. 15);
  • request correction of inaccurate or incomplete data (Art. 16);
  • request erasure of your data ("right to be forgotten") (Art. 17);
  • request restriction of processing in certain circumstances (Art. 18);
  • receive your data in a structured, portable format, or have it transferred to another provider (Art. 20);
  • object to processing based on our legitimate interest (Art. 21); and
  • lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

To exercise any of these rights, contact us using the details in Section 12. We will respond within the timeframe required by the GDPR (in principle, one month).

10. Cookies and similar technologies

Our use of cookies and browser local storage is described separately in our Cookie Policy.

11. Children's privacy

This website and our products are intended for prospective and current university students and are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without the consent of a parent or legal guardian, as required under Art. 8 GDPR. If you believe a child has provided us with personal data without appropriate consent, please contact us so we can delete it.

12. Contact and data-protection requests

For any question about this Privacy Policy or to exercise your rights under Section 9, please contact us using the support contact listed on our Legal Notice page or at checkout. We will handle your request in accordance with applicable data protection law.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. Material changes will be reflected by an updated "Last updated" date above. We encourage you to review this page periodically.