This policy explains which personal data is processed when you use FRM Mock Tests, why, for how long, and what your rights are, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
1. Data controller
[To be completed: name of the data controller], [To be completed: address]. For any question about your data: [To be completed: personal data contact email].
2. Data processed
- Account: name, email address, password (stored in hashed form by our authentication provider, never readable by us), creation date and email verification status.
- Purchases: amount, VAT, date, order reference, invoice, consent to immediate performance and waiver of the right of withdrawal (text and timestamp). The billing address and, where applicable, the company name and VAT number are collected by Stripe. Card details are processed by Stripe only.
- Exams: answers, questions flagged for review, time, scores and results of each attempt.
- Invitations: email address of the invited person, dates of sending, acceptance or revocation.
- Technical data: connection and usage logs for the service’s functions, IP address, and security signals used to block automated access (see “Local storage and security”).
3. Purposes and legal bases
- Creating and managing your account, providing the mock exams, saving your attempts and showing your results: performance of the contract.
- Processing payment, issuing the invoice, keeping proof of the waiver of the right of withdrawal and accounting records: performance of the contract and legal obligations.
- Sending service emails (address verification, password reset, purchase confirmation, invitation): performance of the contract, or legitimate interest for sending an invitation.
- Securing the service and preventing fraud and abuse (limit on the number of attempts, blocking automated access, logging of administrative actions): legitimate interest.
No data is used for advertising, sold or used for profiling.
4. Recipients and processors
Your data is accessible only to the publisher’s authorised staff and to the following processors, for the purposes of the service:
- Google (Firebase, Google Cloud): website hosting, authentication, database, server functions, protection against automated access (reCAPTCHA Enterprise);
- Stripe: payment, VAT calculation and invoicing;
- Brevo (Sendinblue): sending confirmation and invitation emails;
- [To be completed: any other provider (accountant, support…)].
5. Transfers outside the European Union
Data is hosted in the European Union ([To be completed: Firestore database region, e.g. europe-west1 – Belgium]). Some providers (Google, Stripe) may access it from the United States; these transfers are governed by the EU–US Data Privacy Framework and the European Commission’s standard contractual clauses.
6. Retention periods
- Account, attempts and results: as long as the account exists, then deleted within [To be completed: period] after its deletion or after [To be completed: inactivity period] without signing in.
- Orders, invoices and proof of the waiver of the right of withdrawal: 10 years from the order (accounting obligations, article L123-22 of the French Commercial Code).
- Invitations: [To be completed: invitation retention period].
- Technical logs: [To be completed: log retention period, e.g. 12 months].
7. Local storage and security
The website uses no advertising cookies and no audience measurement tools. It stores in your browser only what it needs to work:
- your sign-in session (Firebase Authentication);
- the language you chose;
- technical elements protecting against automated access (Firebase App Check and Google reCAPTCHA Enterprise).
These elements are strictly necessary for the service you request and do not require consent.
8. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, as well as the right to set instructions regarding your data after your death. You can delete your account at any time from the “My account” page: your attempts, results and access are erased immediately, and your orders are kept for the period stated above. To exercise your other rights, write to [To be completed: personal data contact email]. You will receive a reply within one month.
You may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr — or with the authority of your country of residence.
9. Security
Exchanges with the website are encrypted (HTTPS). Access to data is restricted by strict security rules: each user can only view their own data, and sensitive operations are performed by the server only.
10. Changes to this policy
This policy may be updated. The date of the last update is shown at the top of the page; in the event of a significant change, you will be informed by email.