Your Data Matters

Privacy Policy

Your privacy is important to us. This policy explains how TestCEFR collects, uses, and protects your personal information.

Last updated: March 4, 2026

Data Collection

Information We Collect

We only collect information that is necessary to provide our assessment services and improve your experience.

Personal Information

When you register, we collect your name and email address. This information is used to create and manage your account, issue certificates, and communicate with you about your assessments.

Assessment Data

We collect your test responses, scores, and performance analytics across all six CEFR skills. This data powers your results and generates your personalized proficiency certificate.

Payment Information

All payments are processed securely by PayPal. We never store your credit card details or payment information on our servers. PayPal handles all financial data in compliance with PCI-DSS standards.

Usage Data

We automatically collect page views, browser type, device information, and general interaction patterns. This helps us understand how users navigate our platform so we can improve the experience.

Purpose & Use

How We Use Your Information

To provide and maintain our AI-powered CEFR assessment services, including test delivery, scoring, and certificate generation.

To issue personalized CEFR proficiency certificates with unique QR verification codes that employers and institutions can validate.

To improve our platform, develop new features, and enhance the accuracy of our AI assessment algorithms.

To communicate with you about your account, test results, certificate status, and important platform updates.

Security Measures

Data Security

We implement industry-standard security measures to protect your personal data from unauthorized access, disclosure, or destruction.

Encryption

All data transmitted between your browser and our servers is encrypted using TLS 1.3. Sensitive data at rest is encrypted using AES-256 encryption standards.

Secure Servers

Our infrastructure is hosted on enterprise-grade cloud servers with firewalls, intrusion detection systems, and regular security patching to prevent vulnerabilities.

Regular Audits

We conduct periodic security audits and penetration testing to identify and address potential vulnerabilities before they can be exploited.

GDPR Compliance

We are fully compliant with the General Data Protection Regulation. Users from the European Economic Area have enhanced rights over their personal data.

Cookie Policy

Cookies & Tracking

Essential Cookies

These cookies are required for the platform to function properly. They handle authentication, session management, and security features like CSRF protection. You cannot opt out of essential cookies as the service would not work without them.

Analytics Cookies

These cookies help us understand how visitors interact with our platform by collecting information about pages visited, time spent, and navigation patterns. All data is aggregated and anonymized — we never track you individually.

Managing Cookies

You can control and manage cookies through your browser settings. Most browsers allow you to block or delete cookies, set preferences for certain sites, and opt out of tracking. Note that disabling cookies may affect the functionality of our platform.

External Partners

Third-Party Services

We work with trusted third-party providers to deliver our services. Each partner adheres to strict data protection standards.

P

PayPal

Payment Processing

Handles all financial transactions securely. Your card details never touch our servers.

G

Google AI

Assessment Engine

Powers our CEFR evaluation using advanced natural language processing and speech recognition.

A

Analytics

Usage Insights

Provides anonymized, aggregated data about how our platform is used to guide improvements.

Your Rights

Your Data Rights

You have full control over your personal data. Here are the rights you can exercise at any time.

Access Your Data

You have the right to request a copy of all personal data we hold about you. We will provide this within 30 days of receiving your request.

Request Deletion

You can request that we delete your personal data at any time. Upon verification, we will remove your data from our active systems within 14 business days.

Data Portability

You can request your data in a structured, machine-readable format (JSON or CSV) so you can transfer it to another service provider if you choose.

Object to Processing

You have the right to object to the processing of your personal data for specific purposes, including direct marketing and profiling activities.

Privacy Questions?

If you have any questions or concerns about this Privacy Policy or how we handle your data, please don't hesitate to contact our privacy team.

privacy@testcefr.com