← Back to Home

Legal

Privacy Policy

Last updated: September 2026

PreMedEU is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, how we use it, and what rights you have under the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information.

1. Data Controller

The data controller responsible for your personal data is:

PreMedEU

[Company legal name and registration number — to be confirmed]

[Registered address — to be confirmed]

Email: [email protected]

If you have any questions about how we handle your data, or wish to exercise your rights, please contact us at the email address above.

2. Personal Data We Collect

We collect the following categories of personal data:

  • Account data: your name, email address, and hashed password, collected when you register. Optionally: target country, current academic status, and target entry year (collected during post-signup onboarding).
  • Learning activity data: your answers to Q-Bank questions (selected option, correctness, time spent), study session state, question bookmarks, and Codex annotations.
  • Mock exam data: your responses and scores for timed mock examinations.
  • Payment metadata: when you subscribe to a paid plan, Stripe processes your payment card details. We store only non-sensitive billing metadata (Stripe customer ID, subscription ID, plan, and current period end). We never store full card numbers.
  • Technical and device data: your IP address, browser/device type, and access timestamps, collected automatically by our hosting infrastructure (Vercel) for security and performance.
  • Communications: any messages you send us via email or support channels.

3. Legal Bases for Processing

We process your personal data only where we have a valid legal basis under Article 6 GDPR:

  • Performance of a contract (Art. 6(1)(b)): providing your account, delivering Q-Bank access, processing subscription payments, and maintaining your learning progress.
  • Legitimate interests (Art. 6(1)(f)): fraud prevention, rate-limiting abuse, platform security, and aggregate analytics to improve our service. These interests are balanced against your rights and do not override them.
  • Consent (Art. 6(1)(a)): sending you marketing communications (study tips, product news, offers). You may withdraw this consent at any time by emailing us or using the unsubscribe link in any marketing email.
  • Compliance with legal obligations (Art. 6(1)(c)): retaining financial records as required by applicable tax and accounting law.

4. How We Use Your Data

  • Creating and maintaining your account and subscription.
  • Delivering personalised learning features (performance tracking, spaced-repetition recommendations, adaptive Q-Bank filters).
  • Processing payments and issuing receipts.
  • Sending transactional emails (account confirmation, password reset).
  • Sending marketing emails where you have given consent, including study tips and product updates.
  • Detecting and preventing fraud, abuse, and unauthorised access.
  • Aggregated, anonymised analytics to understand how the platform is used and to improve it.
  • Complying with applicable law.

5. Data Processors and Sub-processors

We share your data with the following sub-processors, each bound by data processing agreements (DPAs) and appropriate safeguards:

Supabase (Supabase Inc.)

Authentication and PostgreSQL database hosting. Your account data and learning records are stored on Supabase infrastructure. Data may be hosted in EU regions; refer to Supabase's DPA for transfer safeguards.

Stripe (Stripe Payments Europe, Ltd.)

Payment processing. Stripe acts as an independent data controller for payment card data under PCI DSS. We share only the minimum billing metadata necessary. Stripe is certified under EU Standard Contractual Clauses.

Vercel (Vercel Inc.)

Application hosting, CDN, and edge infrastructure. Vercel processes request logs including IP addresses. Covered by Vercel's DPA and EU Standard Contractual Clauses.

Upstash (Upstash Inc.)

Serverless Redis used for API rate-limiting. Only request-rate counters keyed on anonymised identifiers are stored; no personal data is persisted beyond the TTL window.

OpenAI (OpenAI, L.L.C.)

AI-assisted question generation and content improvement (admin-side pipeline only). Prompts contain no student personal data. Covered by OpenAI's data processing addendum.

We do not sell your personal data to any third party, and we do not share it with advertisers.

6. Data Retention

  • Account data: retained for the duration of your account and deleted within 30 days of a verified deletion request.
  • Learning activity data: retained for the duration of your account to power performance tracking; deleted on account deletion.
  • Payment records: retained for 8 years to comply with Hungarian and EU financial record-keeping obligations (Act C of 2000 on Accounting), even after account deletion.
  • Server logs: retained for up to 90 days by Vercel for security and debugging purposes.
  • Marketing consent records: retained until you withdraw consent, plus a further period sufficient to demonstrate compliance.

7. International Data Transfers

Some of our sub-processors are based outside the European Economic Area (EEA), primarily in the United States. Where such transfers occur, we rely on European Commission Standard Contractual Clauses (SCCs, Commission Decision 2021/914) and, where available, adequacy decisions to ensure an equivalent level of data protection. You may request a copy of the relevant safeguards by contacting [email protected].

8. Your Rights Under GDPR

Under GDPR Articles 15–22, you have the following rights regarding your personal data:

  • Right of access (Art. 15): request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to restriction of processing (Art. 18): request that we restrict processing of your data in certain circumstances.
  • Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21): object to processing based on legitimate interests, including profiling and direct marketing.
  • Right to withdraw consent (Art. 7(3)): where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right not to be subject to automated decisions (Art. 22): we do not make solely automated decisions that produce legal or similarly significant effects.

To exercise any of these rights, email [email protected]. We will respond within 30 days. We may ask you to verify your identity before acting on the request.

9. Cookies and Local Storage

We use strictly necessary cookies for authentication (managed by Supabase) and local storage for user preferences such as theme selection and cookie consent state. We may use anonymised analytics (Vercel Analytics). For full details, please read our Cookie Policy.

10. Children's Privacy

PreMedEU is intended for users who are 16 years of age or older. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by a prominent notice on the platform at least 14 days before the changes take effect. Continued use of PreMedEU after the effective date constitutes acceptance of the updated policy.

12. Right to Lodge a Complaint

If you believe we have processed your personal data in breach of the GDPR, you have the right to lodge a complaint with a supervisory authority. In Hungary, the competent supervisory authority is:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

National Authority for Data Protection and Freedom of Information

Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary

Website: naih.hu

Email: [email protected]

Phone: +36 (1) 391-1400

You may also lodge a complaint with the supervisory authority of your EU member state of habitual residence or place of work.