Insightquiz

Privacy Policy

Transparency and data protection are important to us. In this privacy policy, we inform you in accordance with Art. 13 and 14 GDPR about how we process and protect personal data and what rights you have.

Last updated: December 2025

1. Controller

Responsible for data processing in connection with InsightQuiz is:

Chris Requardt
Nansenstraße 13
86179 Augsburg
Deutschland
[email protected]

2. Types of Data Processed

We distinguish between trainers (registered users) and participants (not registered).

2.1 Trainers (Registered Users)

During registration and use of the service, we process the following data:

  • Email address
  • Password (stored encrypted, never in plain text)
  • Display name
  • Subscription and payment data (via Stripe)
  • Created quizzes, sessions, reports
  • Uploaded content for the AI generator
  • Feedback messages (optional)
  • Log and usage data (e.g., login times, technical logs)

2.2 Participants (Not Registered)

For participation in quiz sessions, we process:

  • Self-chosen display name
  • Answers, scores, response times
  • Session ID / technical metadata for connection
  • (Optional) Device and browser information

We do not collect real names, email addresses, or IDs unless explicitly requested by the trainer.

3. Automatic Data Deletion (Data Minimization)

InsightQuiz follows the principle of data minimization (Art. 5(1)(c) GDPR).

FREE
  • Participant data: automatic deletion 24 hours after session end
  • Temporary AI data: deletion within max. 24 hours
  • Reports: not available
PRO
  • Trainers can set retention period in the dashboard (1–30 days)
  • AI input data: temporary processing, deletion after max. 24 hours

General Deletion Rules

  • Quiz definitions remain until actively deleted
  • Trainer accounts are removed upon request or self-deletion
  • Legal retention obligations (e.g., payment data) remain unaffected

4. Purposes of Data Processing

We process personal data for the following purposes:

  • Operation and provision of the InsightQuiz service
  • Real-time synchronization between trainers and participants
  • Creation of learning progress statistics and reports
  • Authentication and account management
  • Contract and payment processing (PRO plan)
  • Provision of the AI generator for creating quiz questions
  • Abuse detection and system security
  • Product improvement (customer feedback, anonymized usage analytics)

Legal Basis (Art. 6 GDPR):

  • Art. 6(1)(b) (contract performance)
  • Art. 6(1)(a) (consent, e.g., cookies / analytics)
  • Art. 6(1)(f) (legitimate interest)
  • Art. 6(1)(c) (legal obligations)

5. Disclosure to External Service Providers

We use various service providers with whom data processing agreements ("DPA") exist.

5.1 Hosting & Database – Supabase

  • Location: EU / Germany (depending on region settings)
  • Purpose: Hosting, authentication, databases, edge functions
  • Legal basis: Art. 6(1)(b) GDPR
  • DPA in place

5.2 Payment Processing – Stripe

  • Purpose: Processing subscriptions in the PRO plan
  • Stripe is PCI DSS certified
  • Only data necessary for payments is transmitted to Stripe
  • Legal basis: Art. 6(1)(b) GDPR

5.3 Analytics – Google Analytics

  • We only use Google Analytics with consent (opt-in)
  • Collected data: usage statistics, interactions, browser information
  • IP addresses are anonymized
  • Legal basis: Art. 6(1)(a) GDPR
  • You can revoke your consent at any time

5.4 AI Service – Mistral AI (Model: Mistral Large)

  • Purpose: Creation of quiz questions from provided texts
  • PDF Processing: Performed entirely locally in your browser using pdfjs-dist – the document never leaves your device
  • Only the extracted text is sent encrypted to the AI
  • No transmission or storage of original documents on our servers
  • No storage of personal data
  • Provider: Mistral AI SAS, Paris (France) – processing on EU infrastructure, no US data transfer
  • Legal basis: Art. 6(1)(b) GDPR

5.5 Other Sub-processors – IONOS

  • Email service (IONOS)
  • Logging / Monitoring
  • Error tracking

Current sub-processors can be viewed in the Terms of Service / DPA at any time.

6. Cookies

We use cookies for basic functions and optional analytics.

6.1 Necessary Cookies (Essential)

These are required for:

  • Login / Session
  • Security
  • Language settings
  • Technical functions

They cannot be disabled.

6.2 Statistics Cookies (Optional)

With your consent, we use Google Analytics. These cookies serve to create anonymized statistics to improve our website.

You can change or revoke your cookie settings at any time:

Marketing attribution (how you found us)

If you reach our website through an ad link, a search engine or a referring page, we store technically necessary information about how you got here. This data is stored only alongside your account if you register — it is never passed on to third parties.

Fields collected:

  • UTM parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) from the URL
  • Google click ID (gclid), where present
  • Referring URL (HTTP referrer) and the first page you opened

Storage before registration: locally in your browser (localStorage) for a maximum of 60 days. Deleted automatically if you do not register.

Storage after registration: linked to your profile for as long as your account exists.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in evaluating our marketing activity).

Objection / deletion: You can object to this processing at any time, or request deletion, via [email protected].

7. Duration of Storage

The storage duration depends on:

  • Legal requirements (e.g., payment data: 10 years)
  • Retention settings of the trainer (1–30 days)
  • Technical requirements (e.g., server logs: max. 14–30 days)

8. Security Measures

We protect your data through:

  • Encrypted data transmission (TLS 1.2+)
  • Encrypted password hashing (bcrypt)
  • Access restrictions and role-based permissions
  • Firewall and anti-DDoS protection
  • Regular backups and monitoring
  • Verified sub-processors exclusively according to ISO 27001 or comparable standards

9. Your Rights under GDPR

You have the right at any time to:

Access to stored data
Correction of inaccurate data
Deletion ("right to be forgotten")
Restriction of processing
Data portability
Objection to processing
Withdrawal of given consents

To exercise your rights, an email is sufficient to: [email protected]

You also have the right to lodge a complaint with a data protection supervisory authority.

10. Changes to this Privacy Policy

We reserve the right to adapt this privacy policy to accommodate new legal requirements or technical changes. The current version is always available on our website.

11. Privacy Contact

For questions about data protection, you can contact us at any time: [email protected]