Privacy Policy

Last updated: October 2, 2026

This policy explains how testimea collects, uses, stores, and shares personal data when you visit our website, create an account, buy a practice exam, send site feedback, or contact us. testimea sells a digital service worldwide. Because we are established in the Slovak Republic (European Union), the EU General Data Protection Regulation (GDPR) and Slovak Act No. 18/2018 Coll. on Personal Data Protection are our primary legal framework. Where other countries give you additional rights, we honour those rights as required by applicable law.

Related documents: Terms of Service and Refund Policy.

1. Who we are (data controller)

The data controller is the operator of testimea.com (“testimea”, “we”, “us”), established in the Slovak Republic, European Union:

Marián Ondrejka – Wtrade
Mikuláša Dohnányho 817/1A
010 04 Žilina
Slovak Republic

Company ID (IČO): 34933336
Tax ID (DIČ): 1026340513
VAT ID (IČ DPH): SK1026340513

Bank: mBank, a.s.
IBAN: SK65 8360 5207 0042 0198 4390

Privacy requests: privacy@testimea.com
Customer support: support@testimea.com

We have not appointed a Data Protection Officer because this is not required for our current processing. You can still contact us at the privacy email above. Our lead supervisory authority is the Office for Personal Data Protection of the Slovak Republic (see section 11).

2. Who this policy covers

This policy applies to visitors, account holders, and customers anywhere in the world, including the European Economic Area (EEA), the United Kingdom, Switzerland, the United States, and other countries from which our site is accessible.

testimea provides online IT certification practice exams (digital content / digital service). We do not ship physical goods. Checkout typically needs an email address and name so we can create your account, confirm payment, and deliver access to the exam.

3. Personal data we collect

We collect only what we need to run the service:

  • Account data — name, email address, password (stored in hashed form), and account identifiers.
  • Order and billing data — purchased exam, order number, amount, currency, date, payment status, billing name/email, and country or other billing fields shown at checkout.
  • Payment data — handled by the payment provider shown at checkout. We do not store full card numbers. We may keep a transaction ID, last four digits, card brand, and payment status for your order record.
  • Exam use data — exam or practice started, answers, notes, flagged questions, question issue reports, time remaining, score, pass/fail result, and timestamps needed to run an attempt.
  • Support data — messages and question issue reports you send us, including the reason, comment, relevant exam/question identifiers, and your account email or the email you enter as a guest.
  • Site feedback — if you use the Feedback button, the “Rate your experience” prompt, or the prompt shown when you leave a page: a star rating (optional), free-text comment (optional), which of those prompts you used, the page URL and exam context where you opened the form, your access tier if relevant (for example visitor, free sample, trial, or full access), and — only if you choose to enter it or you are logged in — an email address so we can reply. A hashed form of your IP address may be stored temporarily to limit spam. You can send feedback without buying anything and without an email address. If you send feedback from the leaving prompt, we also create a single-use 50% discount code for full-access exams, valid for 14 days, and store the code and a browser-verification key in cookies so checkout can apply it only in that browser.
  • Technical data — IP address, browser and device type, pages requested, referral URL, and security logs. This is collected automatically when you use the site.
  • Cookies and similar storage — see section 8. We use cookies to keep you logged in, remember a cart or checkout session, keep a guest quiz attempt attached to this browser while you take it, and (after purchase) remember access in that browser where needed.

The address entered on a free-sample result is used only to send that one message.

We do not intentionally collect special-category data (such as health, biometric, or political data) or government ID numbers. Please do not send those in support emails or in site-feedback comments.

Providing account and checkout data is required to buy and use a paid exam. If you do not provide them, we cannot complete the purchase or deliver access. Browsing public pages without an account is possible, but some features will not work.

4. Why we use your data and the legal bases

Under GDPR Article 6 we process personal data for these purposes:

  • To provide the service and fulfil a purchase (contract, Art. 6(1)(b)) — create your account, take payment, grant access to the exam you bought, run Exam and Practice attempts, show results, and send order/account emails.
  • To meet legal duties (legal obligation, Art. 6(1)(c)) — keep invoices and accounting records under Slovak accounting and tax law (in particular Act No. 431/2002 Coll. on Accounting and related tax rules), handle consumer complaints, and respond to lawful requests from authorities.
  • To keep the service secure and improve it (legitimate interests, Art. 6(1)(f)) — prevent fraud and abuse, debug errors, measure basic site reliability, review voluntary site feedback (ratings and comments) so we can improve the exams and the website, and defend legal claims. Our legitimate interest is operating a secure, useful exam platform. You may object (see section 10). We do not use this basis for optional advertising cookies. If you leave an email with feedback, we use it only to reply about that feedback.
  • With your consent (consent, Art. 6(1)(a)) — only where required, for example optional analytics or marketing cookies or newsletters if we add them. You can withdraw consent at any time without affecting processing that already happened.

We do not use your exam answers to profile you for advertising. We do not make solely automated decisions that produce legal or similarly significant effects about you (GDPR Art. 22). Scoring a practice exam is the service you asked for, not a credit, hiring, or eligibility decision.

5. Payments

Card and other online payments are processed by the provider displayed at checkout (for example Stripe Payments Europe Ltd or another enabled processor). That provider acts as an independent controller or as our processor, depending on the payment method. Their own privacy notice applies to cardholder data.

We receive confirmation that a payment succeeded or failed so we can unlock the exam. Refunds, if approved under our Refund Policy, are returned to the original payment method.

6. Who we share data with

We do not sell personal data and we do not share it for cross-context behavioural advertising.

We share data only with parties who help us operate the service, under contracts where GDPR requires them (Art. 28 processors), or where the law requires disclosure:

  • Hosting and infrastructure — website, database, and backups.
  • E-commerce platform — WooCommerce / WordPress components used to run the shop, accounts, and orders.
  • Payment providers — to take payment and process refunds.
  • Email delivery — transactional messages such as order confirmation, account, and password emails.
  • Professional advisers and authorities — accountants, lawyers, banks, tax offices, or courts when reasonably necessary or legally required.

A provider may use subprocessors (for example cloud or CDN services). We select providers we consider appropriate for a worldwide digital shop and require them to protect personal data.

7. International transfers

We are established in the EU. Some providers (or their subprocessors) may process data in the United States or other countries outside the EEA/UK.

When we transfer personal data outside the EEA, we rely on a mechanism recognised by GDPR Chapter V, typically:

  • an adequacy decision of the European Commission (including, where the recipient is certified, the EU–US Data Privacy Framework), or
  • the European Commission Standard Contractual Clauses (SCCs), with extra safeguards where needed after a transfer assessment.

UK transfers follow the UK GDPR equivalent (UK adequacy regulations or UK International Data Transfer Agreement / Addendum). You may ask us for more detail about the safeguards used for a specific transfer.

8. Cookies

We use cookies and similar technologies as follows.

Strictly necessary (no consent required under ePrivacy rules, because they are needed to provide the service you request):

  • login and account session;
  • shopping cart and checkout;
  • security (for example CSRF and fraud checks);
  • keeping a guest quiz attempt attached to this browser while you take it;
  • remembering paid access in the browser after checkout, where that is how access is delivered;
  • storing your cookie choice, if a banner is shown;
  • browser local storage that remembers you already sent site feedback, so we do not keep showing the Feedback button on every page for a limited time; session storage that notes a paid-ad landing (for example a Google or Meta click id) and whether we already showed an exit-feedback prompt this visit;
  • cookies that remember a one-time exit-feedback discount code and verify its browser for 14 days so checkout can apply it there.

Optional analytics or marketing cookies are not required for the exams. If we add them, we will ask for consent first and let you refuse or withdraw it. Essential cookies cannot be switched off if you want to buy or take an exam, because the site cannot function without them.

9. How long we keep data

We keep personal data only as long as needed for the purpose, then delete or anonymise it, unless a longer legal retention applies:

  • Account — for as long as the account is active. You may ask us to close it. We may keep a minimal record if needed for security or legal claims.
  • Orders, invoices, and tax records — generally 10 years after the accounting year they relate to, as required by Slovak accounting and tax law. We cannot erase that financial record while the legal duty lasts, but we can remove other account or exam data that is not required for bookkeeping.
  • Exam attempts and results — while your account needs them to review a result, and for a reasonable period afterwards for support and abuse prevention (typically up to 24 months after the last attempt, unless a longer legal hold applies).
  • Question issue reports — typically up to 24 months, or while a reported content problem remains open and needs investigation.
  • Site feedback — we keep the rating, comment, and page/exam context while they remain useful for improving the service. Identifiers that can point to you (optional email and hashed IP) are removed or anonymised after 12 months, unless a dispute remains open. Aggregated or anonymised ratings may be kept longer because they are no longer personal data.
  • Support emails — typically up to 3 years after the last message, or longer if a dispute is open.
  • Security logs — typically up to 12 months, unless we need them for an incident or claim.
  • Cookies and similar storage — session cookies expire when you close the browser or after a short period; exam-access cookies last long enough to complete the exam you bought; the feedback “already sent” local-storage flag is cleared after about 30 days or when you clear site data; the exit-feedback session flags expire when you close the tab; the exit-feedback discount and browser-verification cookies expire after 14 days.

10. Your rights (GDPR and similar laws)

If GDPR applies to you (including EEA residents, and in many cases when we process your data from Slovakia), you may:

  • access your personal data and get a copy;
  • correct inaccurate data;
  • erase data (“right to be forgotten”), subject to legal retention of invoices;
  • restrict or object to processing, including processing based on legitimate interests;
  • receive data you provided to us in a structured, commonly used format and transmit it to another controller (portability), where processing is based on contract or consent and is carried out by automated means;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a supervisory authority (section 11).

To exercise these rights, email privacy@testimea.com. We may need to verify your identity (for example by requesting that you write from the email on the account). We respond within one month, or we will tell you if we need more time as allowed by GDPR.

UK users have equivalent rights under the UK GDPR. You may also complain to the UK Information Commissioner (ICO).

11. Complaints and supervisory authority

Please contact us first so we can try to resolve the issue. You also have the right to lodge a complaint with a data protection authority.

Because we are established in Slovakia, our lead authority is:

Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky)
Hraničná 12, 820 07 Bratislava, Slovak Republic
Website: https://dataprotection.gov.sk

If you live in another EEA country, you may instead complain to your local authority. A list is published by the European Data Protection Board. If you live outside the EEA, you may complain to your local privacy regulator where that body accepts complaints about a foreign online service.

12. People outside the EEA (including the United States)

If you buy from outside the EEA, we still process your data in the EU under this policy. Additional local laws may apply.

United States. We do not sell personal information and we do not share it for cross-context behavioural advertising as those terms are used in California (CCPA/CPRA) and similar US state laws. If such a law applies to us (for example because we later meet a revenue or volume threshold), you may also have rights to know, delete, correct, and opt out of sale/sharing. You can send those requests to privacy@testimea.com. We will not discriminate against you for exercising privacy rights. We do not currently use sensitive personal information to infer characteristics about you.

Other countries (for example Canada, Brazil, Australia). Where a local privacy law gives you access, correction, deletion, or complaint rights in relation to our service, you may use the same privacy email. We will handle the request in line with that law and with GDPR.

13. Children

testimea is aimed at adult learners preparing for professional IT certifications. We do not knowingly collect personal data from children under 16 (the GDPR age of digital consent in Slovakia). If you believe a child has created an account, contact us and we will delete it, except for any invoice we must keep by law.

14. Security

We use appropriate technical and organisational measures for a small digital shop: HTTPS, hashed passwords, access limited to people who need it, and backups. No online service is completely secure. Please use a unique password and keep your login details confidential.

15. Changes to this policy

We may update this policy when the service, our providers, or the law changes. The “Last updated” date at the top will change. If a change is material, we will provide a more prominent notice (for example a notice on the site or by email to account holders) where required.

16. Contact

Questions about this policy or your personal data:

Marián Ondrejka – Wtrade
Mikuláša Dohnányho 817/1A
010 04 Žilina
Slovak Republic

Company ID (IČO): 34933336
Tax ID (DIČ): 1026340513
VAT ID (IČ DPH): SK1026340513

Bank: mBank, a.s.
IBAN: SK65 8360 5207 0042 0198 4390

privacy@testimea.com
support@testimea.com
Contact page