EP

ExamPal

Legal Document

Privacy Policy

Privacy Policy

Version: 1.1
Effective Date: 2026-02-20


1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Jean Isserstedt
trading as “CGIsserstedt”
Einzelunternehmen

Am Treptower Park 16
12435 Berlin
Germany

E-Mail: [email protected]


2. Overview of Data Processing

We process personal data only insofar as this is necessary to provide our online language examination simulation platform.

Personal data includes any information relating to an identified or identifiable natural person.

We process data in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
  • Applicable German data protection laws

3. Minimum Age

This platform is intended exclusively for individuals who are at least 18 years old.

We do not knowingly collect personal data from individuals under the age of 18.

If we become aware that personal data has been collected from a person under 18 without valid authorization, we will delete such data without undue delay.

If you believe that a minor has provided personal data to us, please contact us using the details provided above.


4. Categories of Data Processed

4.1 Account Data

  • Email address
  • Account credentials (securely hashed and encrypted)
  • Optional profile information (if provided)

Purpose: Account creation and access to the platform
Legal Basis: Art. 6(1)(b) GDPR (contract performance)


4.2 Audio Recordings

When using the exam simulation feature, your spoken responses are recorded and stored.

Audio recordings may contain personal data.

Purpose:

  • Providing automated evaluation and feedback
  • Operating the speaking simulation service
  • Supporting quality assurance and evaluation reliability

Legal Basis:

  • Art. 6(1)(b) GDPR (service provision)
  • Art. 6(1)(f) GDPR (legitimate interest in ensuring the accuracy and reliability of automated evaluations)

Audio recordings are not used for biometric identification.

Consent for improvement purposes can be withdrawn at any time via account settings or by contacting us. Withdrawal does not affect processing that has already occurred based on valid consent.


4.3 Human Review for Quality Assurance

In limited cases, audio recordings may be reviewed by qualified language professionals for quality assurance and evaluation improvement purposes.

The purpose of such review is to assess the accuracy of automated evaluation results and improve the reliability and fairness of the evaluation system.

Where human review is conducted:

  • recordings are pseudonymized before being made available to reviewers
  • reviewers do not have access to user account information
  • only the minimum information required for evaluation is provided

All reviewers are bound by strict confidentiality obligations and may only process the data for the purposes described above.

Legal Basis:

Art. 6(1)(f) GDPR (legitimate interest).

Our legitimate interest lies in ensuring the quality, fairness, and reliability of automated evaluation results provided by the platform.


4.4 Usage Data (Technical Data)

When accessing the platform, we process technical data such as:

  • IP address
  • Browser type
  • Device information
  • Access timestamps

Purpose: Ensuring system security, fraud prevention, and technical stability
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest)

Our legitimate interest lies in maintaining the secure and reliable operation of our platform.


4.5 Consent and Acknowledgement Records

When users provide consent (e.g., for system improvement) or acknowledge required audio processing, we store:

  • Type of consent or acknowledgement
  • Applicable document or consent version
  • Timestamp of acceptance
  • Technical metadata (such as IP address, where necessary)

Purpose: Legal documentation and compliance
Legal Basis:

  • Art. 6(1)(c) GDPR (legal obligation)
  • Art. 6(1)(f) GDPR (legitimate interest in legal defense)

5. Storage and Retention

We store personal data only for as long as necessary for the purposes described in this Privacy Policy.


5.1 Account Data

Account data is stored for the duration of the user account.

If an account remains inactive for 24 months, it may be deleted automatically.

Users may request deletion of their account at any time.


5.2 Audio Recordings

Audio recordings submitted during exam simulations are stored for a maximum period of 90 days.

Users may delete recordings earlier via their account or by contacting us.

A limited number of recordings may be temporarily reviewed by qualified language professionals for quality assurance purposes during this retention period.

Such review is performed using pseudonymized recordings and without access to user account information.

After 90 days, raw audio recordings are permanently deleted.


5.3 Technical Logs

Technical access logs, including IP addresses, are stored for a maximum of 14 days.

These logs are used exclusively for:

  • Ensuring system security
  • Preventing misuse
  • Detecting technical errors

After 14 days, logs are automatically deleted or anonymized.


5.4 Legal Retention Obligations

Where required for legal defense or compliance with statutory obligations, certain data (such as records of Terms acceptance or consent documentation) may be retained for up to 3 years following account deletion.

Such data is stored in a restricted manner and used solely for legal purposes.


6. Hosting and Processors

We use carefully selected technical service providers (processors) to operate the platform in accordance with Art. 28 GDPR.

We have concluded Data Processing Agreements (DPAs) with all relevant service providers.


6.1 Hosting Infrastructure

Our application servers and databases are hosted by Hetzner Online GmbH within the European Union (Germany).


6.2 Speech-to-Text Processing

We use OpenAI, L.L.C. to perform automated speech-to-text transcription of audio recordings submitted by users.

Audio recordings may be transmitted to OpenAI's API infrastructure for the sole purpose of generating text transcripts.

OpenAI processes the data as a processor on our behalf.

OpenAI states that API data is not used to train their models and is retained only for limited abuse monitoring purposes.

Where data transfers outside the European Union occur, they are safeguarded using appropriate mechanisms such as Standard Contractual Clauses.


6.3 Cloud Storage and Network Security

We use Cloudflare, Inc. as a processor for secure network delivery and object storage.

Audio recordings are stored using Cloudflare R2 object storage, which provides an S3-compatible storage interface.

Cloudflare, Inc. is headquartered in the United States.

Where personal data is transferred outside the European Union, such transfers are based on:

  • Certification under the EU–US Data Privacy Framework, or
  • Standard Contractual Clauses pursuant to Art. 46 GDPR.

7. Cookies and Similar Technologies

7.1 General Information

We use cookies and similar technologies to operate and secure our platform.

Cookies are small text files stored on a user’s device that enable certain functionalities and improve user experience.

We distinguish between:

  • Technically necessary cookies
  • Analytics cookies

The use of cookies is governed by §25 of the German Telecommunications-Telemedia Data Protection Act (TTDSG) and, where personal data is processed, by the GDPR.


7.2 Technically Necessary Cookies

Technically necessary cookies are required to:

  • Enable secure authentication
  • Maintain user sessions
  • Ensure platform stability and security

These cookies are essential for the operation of the platform and do not require user consent.

Legal Basis:

  • §25(2) No. 2 TTDSG
  • Art. 6(1)(f) GDPR (legitimate interest)

Our legitimate interest lies in providing a secure and functional online service.


7.3 Analytics (PostHog)

We use PostHog for product analytics and usage measurement.

Provider:
PostHog Ltd.

Purpose:

  • Measuring feature usage
  • Analyzing user interaction patterns
  • Improving platform functionality and performance

Data processed may include:

  • IP address
  • Browser and device information
  • Visited pages
  • Interaction events
  • Referrer information
  • Timestamps

Analytics data is processed on servers located within the European Union.

Analytics cookies and tracking technologies are activated only after explicit user consent via our consent banner.

No analytics data is collected before consent is granted.

Legal Basis:

  • §25(1) TTDSG
  • Art. 6(1)(a) GDPR (consent)

7.4 Storage Duration

Technically necessary cookies are stored only for the duration required to maintain session integrity or platform functionality.

Analytics cookies are stored for a maximum period of 12 months, unless deleted earlier by the user.

Consent preferences are stored locally within the user’s browser. If consent settings are changed or the consent version is updated, renewed consent may be requested.

Users may delete cookies at any time via their browser settings.


7.5 Withdrawal and Cookie Settings

Users may withdraw or modify their consent for analytics at any time with future effect.

A permanent “Cookie Settings” link is available in the website footer, allowing users to review or change their preferences.

Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.


8. Data Subject Rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

If processing is based on consent, you may withdraw consent at any time with future effect.

To exercise your rights, please contact us at the email address listed above.

You also have the right to lodge a complaint with a supervisory authority.

Competent supervisory authority in Germany:

Berlin Commissioner for Data Protection and Freedom of Information


9. Automated Decision-Making

The platform provides automated evaluations based on submitted audio responses.

These evaluations are intended solely for training purposes and do not produce legal effects or similarly significant effects within the meaning of Art. 22 GDPR.

No automated decision-making within the meaning of Art. 22 GDPR takes place.


10. Security Vulnerability Reporting

If you believe you have identified a security vulnerability affecting the platform, please report it responsibly to:

[email protected]

Please include sufficient detail to allow us to investigate and reproduce the issue.


11. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encrypted data transmission (TLS)
  • Encrypted storage where applicable
  • Role-based access restrictions
  • Regular system updates and security monitoring

12. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy.

Material changes will be communicated appropriately and, where required, renewed consent will be requested.

If you have any questions about this document, please contact us at [email protected]