Privacy Policy
Last updated August 28, 2025
This Privacy Policy explains how GradeGuru (“GradeGuru”, “we”, “us”, “our”) collects, uses, discloses, retains, and protects personal data when you visit gradeguru.nl and use our services, including downloadable summaries (PDFs), practice exams, DeepDive AI lessons, and live or recorded exam trainings (collectively, the “Services”).
Entire agreement. This Privacy Policy, together with our Terms and Conditions and Refund Policy, collectively constitute the entire agreement between you and GradeGuru for your use of the Services. If any provision conflicts, the Terms and Conditions control, except where applicable privacy law requires otherwise.
How to read this policy. Longer sections include a brief “In Short” summary to help you scan; the full text that follows is legally operative. Short sections (for example, the controller details) do not include an “In Short.”
Who this applies to. This policy applies to visitors and registered users of gradeguru.nl. Our Services are intended for adults (18+) only.
Questions. For anything related to privacy, contact [email protected].
TABLE OF CONTENTS
1. WHO WE ARE (CONTROLLER)
Controller: GradeGuru, Pleinweg 214A, 3083 EW Rotterdam, Netherlands.
Privacy contact: [email protected].
We are responsible for deciding how and why your personal data is processed when you use gradeguru.nl and our Services. We have not appointed a Data Protection Officer. If you have questions or requests about this policy or your data, email us at the address above.
2. SCOPE & ELIGIBILITY
In Short: This policy covers how we handle personal data when you browse gradeguru.nl or use our Services; it applies only to adults (18+) and does not cover third-party sites or services we link to or embed.
This Privacy Policy applies to visitors and registered users of gradeguru.nl and to all features we operate, including, but not limited to, account creation and authentication (email/password or Google sign-in), purchases, access to downloadable summaries (PDFs), practice exams, DeepDive AI lessons, and live or recorded exam trainings, whether bought individually or through a subscription. It covers information collected online through our website and related pages, and information generated by your use of the Services (for example, usage logs and security signals).
Our Services are intended for adults (18+) only. We do not knowingly permit or process data from users under 18, and we do not accept parental-consent registrations for 16–17-year-olds. If we become aware that a user under 18 has created an account or provided personal data, we will take steps to delete the account and associated data.
This policy does not apply to third-party websites, services, or content that we link to or embed (for example, when you play an embedded YouTube video). Those services have their own privacy practices, which govern your interactions with them.
3. WHAT DATA WE COLLECT
In Short: We collect what you give us (account, purchases, support), what’s generated automatically (device/logs, usage, security), limited data from Google for sign-in, payment confirmations from Stripe, and technical data from security and media providers like reCAPTCHA, Cloudflare, YouTube, and analytics. We don’t intentionally collect special-category data.
Account and contact data you provide. Email address and password (stored using strong hashing); optional name/display name; any preferences you set in your profile.
Purchase and billing data. When you buy via Stripe, we receive billing name and address, transaction identifiers, payment status, and limited card metadata (brand and last four digits). We do not store full card numbers or CVC codes.
Content, learning, and interaction data. Materials you view/download; course or exam selections; progress indicators (e.g., completion markers, quiz outcomes where available); notes or feedback you submit; customer support requests and our correspondence.
Automatically collected technical data. IP address and approximate location derived from it; device and browser/OS details; pages viewed, time spent, and timestamps; referring/exit URLs; identifiers set by cookies or similar technologies; session integrity and telemetry needed to keep the service reliable.
Data from third parties and integrations.
• Google sign-in (OAuth): basic profile information (e.g., name if provided) and email address to create or log into your account. We do not receive your Google password.
• Stripe: payment confirmations and billing metadata necessary to complete your purchase and meet accounting obligations.
• Security providers: Google reCAPTCHA (bot detection signals) and Cloudflare (security and delivery logs) to protect the platform.
• Embedded media: YouTube may set/read identifiers when you play an embedded video, in line with its own policies.
• Analytics: measurement providers may collect aggregated usage signals to help us understand performance and improve features.
Public content you choose to share. If you post a review or similar public content, the submitted text and your name/display name can be visible to others.
Special categories. We do not intentionally collect special-category data (e.g., health, ethnicity, religion). Please avoid including such data in free-text fields or uploads.
Children. Our Services are for adults (18+) only. We do not knowingly process children’s data.
4. HOW WE USE DATA & LEGAL BASES
In Short: We use data to operate and improve GradeGuru, fulfill purchases, provide support, secure the platform, deliver embedded media, measure performance, and, if you opt in, send marketing. Legal bases: contract, legitimate interests, legal obligations, and consent where required.
Provide and operate the Services (Contract). Create and maintain accounts; authenticate users (including Google sign-in); deliver purchased/subscribed materials; personalize dashboards (e.g., show relevant summaries/exams); record progress and maintain your library.
Payments and financial recordkeeping (Contract / Legal obligation). Process payments and issue invoices/receipts via Stripe; maintain records to comply with Dutch accounting and tax laws.
Customer support and service communications (Contract / Legitimate interests). Respond to questions; troubleshoot; send important service notices (e.g., material changes that affect your use).
Security, fraud prevention, and abuse detection (Legitimate interests). Protect accounts and content; detect bots/abuse via reCAPTCHA; defend availability and integrity with Cloudflare; keep security and server logs to investigate incidents.
Analytics and product improvement (Consent where required; otherwise Legitimate interests). Measure aggregate usage, performance, and feature adoption to improve content and user experience. Where analytics involves non-essential cookies or similar technologies, we rely on consent where required; otherwise we pursue our legitimate interests in a way that does not override your rights and freedoms.
Marketing communications (Consent). If you opt in, send newsletters and product updates. You can withdraw consent at any time using the unsubscribe link or by contacting us. Transactional emails (e.g., receipts, critical account notices) are not marketing and will be sent as needed.
Embedded media (Legitimate interests / Consent where required). Deliver and measure playback of YouTube videos you choose to interact with, in accordance with YouTube’s policies and applicable law.
Compliance, enforcement, and defense (Legal obligation / Legitimate interests). Comply with legal requests and regulatory duties; enforce our terms; prevent misuse; establish, exercise, or defend legal claims.
Business transfers (Legitimate interests). We may share or transfer personal data in connection with, or during negotiations of, any merger, sale of assets, financing, or acquisition of all or part of our business.
No automated decisions with legal or similarly significant effects. We do not use automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
Balancing test for legitimate interests. When we rely on legitimate interests, we assess and balance our interests against your rights and expectations and implement safeguards (e.g., minimization, pseudonymization, access controls) to reduce risk.
5. COOKIES & TRACKING (ANALYTICS, RECAPTCHA, CLOUDFLARE, YOUTUBE)
In Short: We use essential cookies and similar technologies for security and basic functionality, plus non-essential technologies for analytics and embedded media. You can manage these in your browser and, where available, via provider opt-outs. We do not present a separate cookie banner or host a standalone cookie policy.
What technologies we use.
• Essential (security & core functionality): session/authentication cookies; Google reCAPTCHA to detect bots and abuse; Cloudflare for DDoS protection, web application firewall (WAF), and content delivery. These help keep the Service reliable and secure.
• Non-essential analytics: tools that measure visits, page interactions, events, and performance so we can improve content and features. These may use first-party or third-party cookies, local storage, and similar identifiers.
• Embedded media: when you play an embedded YouTube video, YouTube may set/read identifiers to provide the player, measure performance, and personalize content under its own policies.
What data these technologies generate.
Device identifiers; IP address and approximate location derived from it; browser/OS details; pages viewed and timestamps; referrers and campaign/UTM parameters; interaction events (e.g., clicks, scrolls, video play/pause); session integrity and telemetry needed to protect the Service.
Your choices and controls.
You can block or delete cookies and site data in your browser settings; use tracking protection or private browsing modes; and (where offered) use provider-level opt-outs for analytics/ads. Blocking certain technologies may affect functionality (e.g., staying logged in, media playback, or site performance). We do not respond to Do-Not-Track signals; see 16. DO-NOT-TRACK below for more detail.
Legal bases.
For essential and security technologies we rely on legitimate interests to operate and protect the Service. For analytics and embedded media, we rely on consent where required by law or on legitimate interests where appropriate and where your rights and freedoms are not overridden. We respect your browser/device-level choices and provider opt-outs and do not present a separate cookie banner.
6. PAYMENTS (STRIPE)
In Short: Payments are processed by Stripe. We never store full card numbers or CVC codes. We receive limited payment metadata to complete your order and comply with accounting laws. PSD2/Strong Customer Authentication (SCA) may apply to EEA transactions.
How payment processing works.
When you check out, your card details are transmitted directly to Stripe, our payment service provider. Stripe uses that information to authorize and charge your payment method, perform fraud screening, and meet its own regulatory obligations. GradeGuru does not see or store full card numbers or CVC codes.
What we receive from Stripe.
To fulfill your order, prevent fraud, and keep accurate records, we receive: transaction status, payment method brand and last four digits, expiration month/year, billing name and address, country of issuance (where applicable), and Stripe identifiers (e.g., charge or payment IDs). We use this information to deliver content you purchased, issue invoices/receipts, handle refunds/chargebacks, and provide support.
Roles and responsibility.
Stripe may act as an independent controller for certain activities (e.g., fraud monitoring, regulatory compliance) and as our processor for others (e.g., charging your card on our instructions). Your use of Stripe at checkout is also governed by Stripe’s own terms and privacy notices.
Security and authentication.
Stripe is certified to industry security standards for handling payment data. For EEA cards, PSD2/SCA may require you to complete additional authentication (for example, a bank app approval or one-time code) before a payment can be completed.
Accounting and records.
We retain invoices and related payment records for 7 years to comply with Dutch accounting and tax laws (see 10. DATA RETENTION). Refunds, disputes, and chargebacks generate additional records that we keep for compliance and fraud prevention.
International transfers.
While our hosting and backups are in the EU, Stripe and other payment networks may process limited personal data across borders (for example, to the United States). We rely on appropriate safeguards such as Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework (see 9. INTERNATIONAL TRANSFERS).
7. HOSTING & INFRASTRUCTURE
In Short: We host our application and database with Hostinger in the European Union, keep backups in the EU, and use Cloudflare to protect and deliver the site. These providers process technical data (like IP addresses and request metadata) to operate, secure, and optimize the Service under contracts that restrict use to our instructions.
We operate gradeguru.nl on infrastructure provided by Hostinger located in the European Union. Hostinger supplies compute, storage, databases, and backup facilities. We remain the data controller; Hostinger acts as our processor and processes personal data only to provide infrastructure services to us. Where supported by our providers, data at rest is encrypted; data in transit is protected with TLS. Administrative access is limited to authorized personnel under role-based access controls and least-privilege principles. Backups of relevant data are stored within the EU and regularly cycled to support disaster recovery and business continuity; we periodically test restore procedures.
To protect and deliver our site globally, we use Cloudflare for web application firewall (WAF), DDoS mitigation, TLS termination/optimization, bot management, and content delivery (CDN). In performing these functions, Cloudflare processes technical data such as source IP address, request headers and URLs, timestamps, TLS handshake details, performance telemetry, and security signals (e.g., bot scores). These signals help us detect abuse, prevent fraud, and ensure availability. We retain our own server and security logs according to 10. DATA RETENTION below; Cloudflare and Hostinger may retain limited logs per their own legal obligations and service operations.
We also run internal monitoring and administrative tools needed to manage the platform. Each service provider we engage is subject to confidentiality obligations and a data processing agreement (or equivalent terms) that require appropriate security, limit use to our documented instructions, and assist us in meeting GDPR duties.
8. SHARING YOUR DATA (PROCESSORS, BUSINESS TRANSFERS & RECIPIENTS)
In Short: We do not sell personal data. We share it with trusted service providers who help us run GradeGuru (hosting, payments, security, authentication, email, analytics, media). We may disclose data to comply with law or protect rights, and we may transfer data in connection with a merger or acquisition. Some third parties (like Stripe, Google, YouTube) also act as independent controllers for parts of their processing.
Categories of recipients we use to operate the Service
Payments: Stripe processes your card data and provides us with payment confirmations, billing details, and limited card metadata so we can fulfill orders, handle refunds/chargebacks, and meet accounting obligations. For certain activities (e.g., fraud monitoring and regulatory compliance), Stripe acts as an independent controller.
Hosting & storage: Hostinger (EU) provides the infrastructure and storage that run our application and databases; Hostinger acts as our processor.
Security & delivery: Cloudflare protects availability and integrity (WAF, DDoS mitigation, CDN) and processes request metadata and security signals as our processor. Google reCAPTCHA evaluates bot risk when you interact with protected forms; Google may act as an independent controller for some of that processing.
Authentication: Google (OAuth) shares basic profile information and email so you can log in; Google is an independent controller of data in your Google account.
Email & communications: email service provider(s) for transactional messages and, if you opt in, marketing emails.
Analytics: measurement provider(s) that help us understand aggregate usage and performance.
Media embeds: YouTube collects data when you play embedded videos according to its own policies (independent controller).
Each processor is bound by a data processing agreement (or equivalent terms) requiring confidentiality, appropriate security, and use limited to our documented instructions. We conduct vendor diligence proportionate to risk.
Disclosures for legal and safety reasons
We may disclose personal data to competent authorities, courts, regulators, or third parties where required by law or where we reasonably believe disclosure is necessary to: comply with legal obligations or lawful requests; enforce our Terms and Conditions; protect the rights, property, or safety of GradeGuru, our users, or the public; or detect, prevent, and address fraud, abuse, or security incidents. Where legally permitted and feasible, we will notify you of such requests.
Business transfers
We may share or transfer personal data in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company. The successor entity will honor the commitments in this Privacy Policy unless and until it is replaced by an updated policy you are notified about.
Public content and social proof
If you choose to post reviews or similar public content on GradeGuru, the information you submit (e.g., text, name/display name) may be visible to others. Avoid including personal or sensitive information in public fields.
No sale or targeted advertising sharing
We do not sell personal data. We also do not share personal data with third parties for their own behavioral advertising purposes. If this changes in the future, we will update this Privacy Policy and, where required, seek your consent.
Aggregated and de-identified information
We may use and share aggregated or de-identified information (which cannot reasonably be used to identify you) for purposes such as analyzing usage trends, improving the Service, or publishing statistics. We take steps to prevent re-identification and will not attempt to re-identify such data.
International transfers
Some recipients listed above may process data outside the EEA/UK. For details on safeguards (e.g., Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework), see 9. INTERNATIONAL TRANSFERS.
9. INTERNATIONAL TRANSFERS
In Short: Our primary hosting and backups are in the EU, but certain providers (e.g., Stripe, Google services such as OAuth/reCAPTCHA/YouTube, Cloudflare, and any chosen email/analytics vendors) may process limited personal data outside the EEA/UK. When that happens, we use lawful safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework (DPF), plus technical and organizational measures like encryption in transit and data minimization.
We design our platform with EU data residency in mind: application hosting and databases run on Hostinger in the European Union, and our backups are retained in the EU. However, some processing is global by nature. For example, payment execution and fraud screening by Stripe; identity, bot detection, and media services from Google (Google OAuth, reCAPTCHA, YouTube); edge security and content delivery via Cloudflare; and any future marketing-email or analytics providers may involve access to or processing of personal data from locations outside the EEA/UK.
Where personal data is transferred to a country that has not received an adequacy decision from the European Commission, we rely on SCCs with the relevant recipient and implement additional measures where appropriate (e.g., TLS in transit, strict access controls, data minimization/pseudonymization, and vendor contractual commitments). Where a U.S. recipient participates in the EU–US DPF, we may rely on that participation for transfers, in combination with provider-specific security controls. Copies or a meaningful summary of relevant transfer safeguards can be requested at [email protected] (we may redact commercially sensitive terms).
We periodically review our vendors and transfer mechanisms and will update this section if our cross-border processing materially changes.
10. DATA RETENTION
In Short: We keep personal data only as long as needed for the purposes described in this policy. Typical periods: account data while active (deleted or anonymized within 90 days after account closure or confirmed deletion request), invoices 7 years, support 2 years and security/server logs 12 months. Backups rotate on a schedule and are purged automatically.
Principles we follow. We apply data-minimization and storage-limitation principles: we retain personal data only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and protect our users and platform. When data is no longer needed, we delete it or irreversibly anonymize it.
Standard retention periods.
Account data (profile, authentication, service configuration): kept while your account is active. If you delete your account or ask us to delete your data, we delete or irreversibly anonymize within 90 days, except where a longer period is required by law or needed to establish, exercise, or defend legal claims.
Purchase records & invoices: retained for 7 years to satisfy Dutch accounting and tax obligations. Some transactional records may be anonymized and kept longer for financial integrity and fraud analytics.
Customer support & correspondence (including rights requests): retained for 2 years after the ticket/request is resolved. Minimal records demonstrating that we fulfilled a statutory request may be kept longer where necessary to demonstrate compliance.
Security, audit, and server logs: retained for up to 12 months for security monitoring, troubleshooting, abuse prevention, and incident response. Logs linked to ongoing investigations or legal matters may be kept longer until the matter is closed.
Marketing email preferences: if you unsubscribe, we keep a minimal suppression record to ensure we do not email you marketing again.
Backups and disaster recovery. Backups are stored within the EU and rotate on a rolling schedule. When you delete data, it is removed from active systems and will be overwritten in backups as those cycles complete. If we must restore from a backup, we will re-apply deletions as soon as practicable.
Aggregated and de-identified data. We may retain aggregated or de-identified data (which cannot reasonably be used to identify you) without a specific end date, and we will not attempt to re-identify it.
If you have questions about a specific category of data or need a tailored retention confirmation for compliance purposes, contact [email protected].
11. SECURITY
In Short: We apply technical and organizational measures proportionate to risk, including, but not limited to TLS encryption in transit, strong password hashing, access controls with least-privilege, EU-based backups, Cloudflare WAF/DDoS protection, vulnerability management and monitoring, vendor due diligence, and GDPR-aligned incident response.
Governance and access controls. We operate on a least-privilege basis with role-based access controls for administrative tools and production systems. Administrative access is limited to authorized personnel and protected by strong authentication; we apply additional authentication controls (such as multi-factor authentication) for sensitive operations. Access rights are granted and reviewed according to job role and revoked upon change or departure.
Data security. Transport is protected with HTTPS/TLS. Passwords are stored using modern, adaptive hashing (e.g., bcrypt/argon2) with unique salts. Where supported by our providers, data at rest is encrypted. We minimize the personal data we collect and retain, and we segregate operational data from backups.
Application & infrastructure protection. We use Cloudflare for web application firewall (WAF), DDoS mitigation, bot management, and secure content delivery. reCAPTCHA helps detect automated abuse. We follow a patching cadence for operating systems, runtimes, and dependencies; changes are deployed through controlled processes. Rate-limiting and other controls help reduce brute-force and scraping risks.
Monitoring, logging, and integrity. We maintain security and server logs to monitor service health, detect anomalies, and support incident response. Logs are retained per 10. DATA RETENTION and are accessible only to authorized personnel.
Backups and disaster recovery. Backups are stored within the EU on a rolling schedule. We periodically test restoration to verify recoverability. If we restore from backup, we re-apply account deletions as soon as practicable.
Vendor and processor management. We perform proportional due diligence on service providers (e.g., Hostinger, Cloudflare, Stripe, Google services), enter into data-processing agreements, and require appropriate security and confidentiality commitments. For cross-border processing, we implement transfer safeguards described in 9. INTERNATIONAL TRANSFERS.
Incident and breach response. We maintain procedures to investigate, contain, and remediate security incidents. Where a personal-data breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware, and, where required, notify affected users without undue delay, including information and guidance to mitigate potential harm.
Your responsibilities. Keep your account credentials confidential, use a unique and strong password, enable available security features, and sign out of shared devices. Contact [email protected] immediately if you suspect unauthorized access to your account.
12. YOUR RIGHTS
In Short: Under the GDPR you can review (access) your data, request deletion, and exercise other rights. We do not offer a self-service dashboard for data access or deletion. To review or delete your data, you must email us at [email protected]. You can also use email to exercise correction, restriction, portability, objection, and consent withdrawal.
Review (Access). You can request confirmation whether we process your personal data and obtain a copy of it by emailing [email protected].
Deletion (Erasure). You can request deletion of your personal data by emailing [email protected]. If the GDPR grounds apply (for example, the data is no longer necessary or you withdraw consent), we will delete it in line with our 10. DATA RETENTION section (typically within 90 days, except where we must retain certain records for legal or fraud-prevention reasons).
Correction (Rectification). If your personal data is inaccurate or incomplete, email [email protected] with the corrections you need and any supporting details.
Restriction. You may request that we restrict processing in certain circumstances (for example, while we verify accuracy or handle an objection) by emailing [email protected].
Portability. For data you provided to us, where processing is based on consent or contract and carried out by automated means, you may request a structured, commonly used, machine-readable copy and/or transmission to another controller by emailing [email protected].
Objection. You can object at any time to processing based on our legitimate interests (including related profiling). We will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is for legal claims. Email [email protected] to object.
Marketing opt-out and consent withdrawal. You can object to direct marketing at any time. If you receive marketing emails, use the unsubscribe link in those emails or email [email protected]. You can withdraw any consent you have given (e.g., for marketing or non-essential analytics) without affecting prior lawful processing.
How to exercise your rights. Email [email protected] from your registered address describing your request. For security, we may ask you to verify identity and confirm control of the account/email. We respond within one month of receipt; for complex or numerous requests, we may extend by up to two additional months and will inform you of the reason. We generally fulfill requests free of charge, but we may charge a reasonable fee or refuse manifestly unfounded or excessive requests as permitted by law.
Complaints. You may lodge a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority). We encourage you to contact us first so we can try to resolve your concern promptly.
13. ACCOUNTS & GOOGLE SIGN-IN
In Short: You can create an account with email + password or sign in with Google. If you use Google, we receive your basic profile info and email from Google to identify you; we never receive your Google password. For any account issues or to close your account, email [email protected].
Account creation and eligibility. Accounts are available only to adults (18+). By creating an account, you confirm you are at least 18 and agree to our Terms and Conditions and Refund Policy (together with this Privacy Policy, the entire agreement).
Email + password. If you register with email and password, your password is stored using strong, modern hashing. Please keep your credentials confidential and unique to GradeGuru.
Google sign-in (OAuth). If you choose Google sign-in, Google shares your basic profile information (for example, name if provided) and email address with us so we can create or log you into your GradeGuru account. We do not receive your Google password or access your Google content. Google remains an independent controller of data in your Google account; your use of Google sign-in is also governed by Google’s terms and privacy policy.
Managing connections. You can manage third-party app connections in your Google Account settings. If you need help with access, name or email changes, or to close your GradeGuru account, contact [email protected] and we’ll verify your identity and assist.
Security and misuse. We use measures like reCAPTCHA and Cloudflare to protect accounts and the platform from automated abuse and fraud. We may suspend or disable accounts involved in security incidents, legal violations, or abuse, consistent with our Terms and Conditions.
Account closure and data. To request account closure and deletion of your personal data, email [email protected]. We will process the request in line with 10. DATA RETENTION and 12. YOUR RIGHTS.
14. PUBLIC CONTENT (REVIEWS)
In Short: Reviews are optional but public. What you post (and your name or display name) may be visible to others and indexed by search engines. Don’t include personal or sensitive information.
Visibility and responsibility. If you submit a review, rating, testimonial, or similar content on GradeGuru, the text and the name/display name you provide may be publicly visible on our site and can be captured by search engines or third-party archives. You are responsible for what you publish, avoid sharing personal data (such as addresses, phone numbers, IDs) or any content you would not want to be public.
Moderation. We may review, publish, decline, edit for clarity/length (without changing meaning), or remove user-submitted content that violates laws, intellectual property rights, or our Terms and Conditions, or that poses safety, security, or spam risks.
Use of reviews. We may display your review on relevant pages to help other users evaluate our Services. We may also use aggregated, de-identified insights from reviews to improve our content and features.
Removal requests. If you want a review you posted to be removed or anonymized, email [email protected] from the address associated with your account and include a link or enough detail to locate the content. We’ll handle your request consistent with 12. YOUR RIGHTS and 10. DATA RETENTION; note that we cannot control copies stored by third parties (e.g., search engine caches), though we can assist with standard takedown requests where appropriate.
15. CHILDREN
Our Services are intended for adults (18+) only. We do not knowingly solicit, register, or process personal data from individuals under 18. If we learn that a user under 18 has created an account or provided personal data, we will take reasonable steps to delete the account and associated data as soon as practicable. Parents or legal guardians who believe a minor has provided us personal data should contact [email protected] so we can investigate and remove the information. We may request limited information as necessary to verify the requester’s status as a parent or legal guardian.
16. DO-NOT-TRACK
Some browsers include a “Do-Not-Track” (DNT) setting. There is currently no uniform industry or legal standard governing how websites should respond to these signals. Accordingly, our site does not respond to DNT signals at this time. You can still manage cookies and similar technologies using your browser or device settings and, where available, provider-level opt-outs. If a binding standard emerges or the law changes to require a specific response to DNT, we will update this section.
17. THIRD-PARTY WEBSITES & EMBEDS
Our website may include links to, or embedded features from, third-party services that operate under their own terms and privacy policies. Examples include YouTube video players you choose to interact with, Google services involved in authentication or bot detection, and pages or widgets hosted by other providers. When you click a third-party link or use an embedded feature, that provider may collect information such as your IP address, device/browser details, interaction events, and identifiers (e.g., cookies or local storage) in accordance with its own policies. We are not responsible for the privacy practices of third parties, and your use of those services is governed by their terms and privacy notices. For details about the technologies those providers use on our pages, see 5. COOKIES & TRACKING. If you wish to exercise privacy rights with a third-party provider acting as an independent controller, please contact that provider directly.
18. CHANGES TO THIS POLICY
We may update this Privacy Policy to reflect changes in our Services, our processing activities, or applicable law. When we make changes, we will post the revised policy here and update the Last updated date at the top of the page. For material changes that meaningfully affect your rights or how we process personal data, we might provide an additional notice (for example, by email to registered users and/or a prominent notice on our site). Continued use of the Services after a revised policy takes effect signifies your acceptance of the updated terms. Prior versions are available on request.
19. CONTACT
GradeGuru
Pleinweg 214A, 3083 EW Rotterdam, Netherlands
Privacy contact: [email protected]
For any questions about this Privacy Policy or to make a privacy request (including review or deletion of your data), email us at [email protected] from the address associated with your account.