Privacy policy
Updated 11 September 2026
Who is responsible
The controller of your data is EPSOmetro (epsometro.com), a company being incorporated in Belgium, enterprise number (CBE) pending. For anything about your data: contact@epsometro.com.
We have not appointed a data protection officer: given what we process and at what scale, the GDPR does not require one.
What data we process
Only what is needed to sell you an exam, let you sit it and send you your report:
- Your email address. You give it when you pay or ask for a sign-in link, and it is your identifier: there are no passwords.
- The purchase: which pack, when, and the payment session ID. Payment details (card, cardholder, billing country) are collected by Stripe; of those we keep only your email.
- The record of your acceptance of the terms: which version, when, in which language and for which purchase.
- Your exams: answers, timings, score, section breakdown, exam languages and which questions you have seen, so you never get them again.
- Environment events during the exam: how many times the window loses focus, you leave full screen, you try to copy or you open the context menu. Only the count. We do not access your camera, microphone or screen.
- Sign-in link requests: email and IP address, to limit how many are sent.
- Technical server logs (IP address, date, page requested), produced by the website host.
We do not ask for your name, address, phone number or identity document.
Why we use it and on what basis
- Providing the service —creating your account, giving you the exam, scoring it and sending you access and your result—: performance of the contract you enter into when you buy (Art. 6(1)(b) GDPR).
- Taking payment and keeping accounts: legal obligation (Art. 6(1)(c)).
- Keeping proof that you accepted the terms and waived withdrawal: legal obligation and legitimate interest in being able to show it if there is a claim (Art. 6(1)(c) and 6(1)(f)).
- Limiting sign-in link requests, so nobody can use the form to flood someone else’s inbox: legitimate interest (Art. 6(1)(f)).
- Recording environment events and showing them in your report, so you know how you would arrive at a supervised remote exam: part of the service (Art. 6(1)(b)).
We do not use your data for advertising, we do not build marketing profiles and we do not send newsletters: only service emails.
Automated decisions
Scoring is automatic: each answer is compared with the key. It produces no legal effects and does not similarly significantly affect you (Art. 22 GDPR). If you think an answer was scored wrongly, write to us and a person will review it.
Who else processes it
Providers working on our behalf and only to deliver the service:
- Supabase: database and accounts. Servers in Ireland.
- Vercel: website hosting. The functions that process your data run in Paris.
- Stripe: payments, through Stripe Payments Europe, Ltd. (Ireland). Stripe also processes some data as an independent controller —fraud prevention, legal obligations— under its own privacy policy.
- Resend: sending service emails.
We do not sell or pass your data to anyone else. We would hand it to an authority only if a law required us to.
Outside the EU
The database and the website are in the EU. Some providers are US companies and may process data there —email delivery, technical support—. When that happens, it is with the safeguards of the GDPR: the adequacy decision for the EU-US Data Privacy Framework for certified companies, or standard contractual clauses approved by the European Commission (Arts. 45 and 46).
How long we keep it
- Account, exams and reports: for as long as you keep the account. If you ask us to delete it, we do so within one month.
- Purchase and acceptance record: for the period required by Belgian accounting and tax rules and the limitation period for claims, even if you delete your account. Only for that.
- Sign-in link requests: deleted automatically after two days.
- Hosting technical logs: a short period, according to the provider’s settings.
Your rights
You can ask us at any time to access your data, correct it, erase it, restrict its use, take it with you in a standard format, or object to processing based on legitimate interest (Arts. 15 to 21 GDPR).
Write to contact@epsometro.com from your account’s email address, so we know it is you. We answer within one month at the latest.
You can also complain, without contacting us first, to the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels · contact@apd-gba.be · dataprotectionauthority.be) or to the data protection authority of your country of residence.
How we protect it
- Everything travels encrypted (HTTPS).
- There are no passwords to steal: you sign in with a single-use link that expires in one hour.
- The database enforces row-level access control: with your session, only your own attempts, results and credits can be read.
Minors
EPSOmetro is designed for candidates in European Union competitions, who are adults. It is not directed at minors and we do not knowingly process their data.
Changes to this policy
If we change anything that affects how we use your data, we will tell you by email before applying it. The date at the top shows the version in force.