Last updated: 28 August 2026
Privacy policy
What is collected, why, who processes it and how to make it stop. Written to be read, not to be survived.
1. Data controller
Pablo Lozano Lominchar, NIF 50900723K, Madrid, Spain. For any request about your data, write to lozanon57@gmail.com.
The same controller operates SurgicalBoardsQA. The two sites keep separate databases and separate accounts: registering here creates no account there, and data is not combined between them.
2. What is collected, and on what legal basis
| Data | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address | To create your account and send sign-in links | Contract — 6(1)(b) |
| Country of your payment card | To apply the correct price tier | Contract — 6(1)(b) |
| Answers, scores and topics practised | To show your progress and identify weak areas | Contract — 6(1)(b) |
| Payment record (not card numbers) | To prove what you bought and issue receipts | Legal obligation — 6(1)(c) |
| Aggregate page traffic | To know which pages are used | Legitimate interest — 6(1)(f) |
No card details ever reach this site. Payment is handled entirely inside Stripe; the operator sees only the last four digits and the card country.
No special-category data under Article 9 is collected. You are never asked for clinical information about yourself or about any patient. Do not enter patient-identifiable information anywhere on this site — there is no field intended to receive it.
3. Who else processes it
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase Inc. | Database, authentication and question storage | European Union (eu-west-1, Ireland) | Data held in the EU; no transfer |
| Vercel Inc. | Application hosting and delivery | United States | EU Standard Contractual Clauses |
| Stripe Inc. | Payment processing (card data never reaches us) | United States / Ireland | EU Standard Contractual Clauses; PCI-DSS Level 1 |
| Resend Inc. | Transactional email (sign-in links, receipts) | United States | EU Standard Contractual Clauses |
The database itself is hosted in the European Union. Your data is never sold, rented or shared for advertising, and there is no advertising on this site.
4. How long it is kept
Account and progress data: for as long as the account exists, and for 30 days after you delete it, so the deletion can be reversed if it was a mistake. After that it is erased.
Payment and invoicing records: six years, because Spanish commercial and tax law requires it (Código de Comercio Art. 30). This is the one category that cannot be deleted on request while the retention period runs.
5. Your rights
Under Articles 15 to 22 of the GDPR you may request access to your data, correction, erasure, restriction of processing, portability in a machine-readable format, and you may object to processing based on legitimate interest. Write to lozanon57@gmail.com. The response is due within one month.
If you are not satisfied, you may complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos, or to the supervisory authority of your own country of residence.
6. Security
Traffic is encrypted in transit (TLS). Authentication is handled by Supabase; the operator never sees your password. Database access is restricted by row-level security so one account cannot read another’s progress. Server-side credentials are held in encrypted environment variables and rotated when there is any reason to believe one has been exposed.
7. Changes
Any change is published on this page with a new date at the top. A change that materially affects your rights will also be sent by email to registered users before it takes effect.