Privacy Policy
Last updated: September 27, 2026
Syntrixo ("we"), the operator identified in the legal notice, is the data controller for personal data processed through IQScores (iqscores.org). Contact: [email protected]. This policy explains what we collect, why, who we share it with and what you can do about it.
1. Data we collect
- Account data: email address, name if you give one (used on your certificate), and a password hash if you set a password.
- Test and training data: your answers, scores, timings, assessment results, puzzle and game activity.
- Billing data: subscription status, trial and renewal dates, payment history (amount, date, last four digits and brand of the card, as reported by Stripe). Full card numbers never reach our servers.
- Technical data: IP address, browser and device type, pages requested, and the cookies described below. Web-server logs are kept for 30 days.
- Support data: the content of emails you send us.
2. Why we use it, and the legal basis
- To provide the Service (score your test, show your report, issue your certificate, run your membership): performance of our contract with you.
- To take payment and send receipts, renewal notices and cancellation confirmations: performance of the contract and our legal obligations.
- To send login links and security notices: performance of the contract and our legitimate interest in keeping accounts secure.
- To prevent fraud, abuse and payment disputes: our legitimate interests.
- To improve the Service using aggregated statistics that do not identify you: our legitimate interests.
- To comply with tax, accounting and consumer-protection law: legal obligation.
We do not send marketing emails, and we do not sell or rent personal data.
3. Who we share data with
We share personal data only with processors that act on our instructions to run the Service:
- Stripe Payments Europe Ltd / Stripe Inc.: Payment processing and subscription billing (Ireland, United States).
- Resend (Plus Five Five Inc.) via Amazon Web Services: Transactional email delivery (United States, EU (eu-west-1)).
- Cloudflare Inc.: DNS, TLS termination, DDoS protection and CDN (United States, global edge).
- Hosting provider: Application and database hosting (European Union).
We may also disclose data when required by law, to enforce our Terms, or to a successor if the business is sold. Stripe acts as an independent controller for the payment data it holds; see Stripe's privacy policy.
4. International transfers
Some processors are in the United States. Transfers from the UK and EEA rely on the processors' certification under the EU-US Data Privacy Framework and its UK extension or on standard contractual clauses, together with the safeguards those processors publish.
5. Cookies
We use only strictly necessary cookies, so no consent banner is shown:
- a session cookie that keeps you logged in (deleted when the session expires or you log out);
- a pending-result cookie that links the test you just took to the account you create next (short-lived).
We set no advertising, analytics or third-party tracking cookies.
6. How long we keep data
- Account, test and training data: for as long as your account exists, then deleted within 30 days of a deletion request.
- Billing records: 7 years after the transaction, as required by accounting law, in a form limited to what the law requires.
- Server logs: 30 days.
- Support emails: 2 years.
7. Your rights
Under the EU GDPR (and the UK GDPR if you live in the UK) you can ask us to access, correct, delete or export your data, to restrict or object to processing, and to withdraw consent where processing is based on consent. Residents of California and some other US states have comparable rights, including the right to know and to delete. To exercise any right, email [email protected] from the address on your account. We respond within one month.
You can also complain to a supervisory authority: the Spanish Data Protection Agency (AEPD, aepd.es), or the authority of the country where you live.
8. Security
Data is transmitted over TLS, passwords are stored as salted hashes, login links expire, and access to production systems is restricted. No system is perfectly secure; if a breach affects you we will notify you and the relevant authority as the law requires.
9. Children
The Service is not directed at children. Memberships may only be purchased by adults. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes
We may update this policy. The date at the top shows the current version; material changes are announced by email or on the site. See also our Terms and Conditions.