GeneralSurgeryBoardsQA

Last updated: 28 August 2026

Privacy policy

What is collected, why, who processes it and how to make it stop. Written to be read, not to be survived.

1. Data controller

Pablo Lozano Lominchar, NIF 50900723K, Madrid, Spain. For any request about your data, write to lozanon57@gmail.com.

The same controller operates SurgicalBoardsQA. The two sites keep separate databases and separate accounts: registering here creates no account there, and data is not combined between them.

2. What is collected, and on what legal basis

DataWhyLegal basis (GDPR Art. 6)
Email addressTo create your account and send sign-in linksContract — 6(1)(b)
Country of your payment cardTo apply the correct price tierContract — 6(1)(b)
Answers, scores and topics practisedTo show your progress and identify weak areasContract — 6(1)(b)
Payment record (not card numbers)To prove what you bought and issue receiptsLegal obligation — 6(1)(c)
Aggregate page trafficTo know which pages are usedLegitimate interest — 6(1)(f)

No card details ever reach this site. Payment is handled entirely inside Stripe; the operator sees only the last four digits and the card country.

No special-category data under Article 9 is collected. You are never asked for clinical information about yourself or about any patient. Do not enter patient-identifiable information anywhere on this site — there is no field intended to receive it.

3. Who else processes it

ProcessorPurposeLocationSafeguard
Supabase Inc.Database, authentication and question storageEuropean Union (eu-west-1, Ireland)Data held in the EU; no transfer
Vercel Inc.Application hosting and deliveryUnited StatesEU Standard Contractual Clauses
Stripe Inc.Payment processing (card data never reaches us)United States / IrelandEU Standard Contractual Clauses; PCI-DSS Level 1
Resend Inc.Transactional email (sign-in links, receipts)United StatesEU Standard Contractual Clauses

The database itself is hosted in the European Union. Your data is never sold, rented or shared for advertising, and there is no advertising on this site.

4. How long it is kept

Account and progress data: for as long as the account exists, and for 30 days after you delete it, so the deletion can be reversed if it was a mistake. After that it is erased.

Payment and invoicing records: six years, because Spanish commercial and tax law requires it (Código de Comercio Art. 30). This is the one category that cannot be deleted on request while the retention period runs.

5. Your rights

Under Articles 15 to 22 of the GDPR you may request access to your data, correction, erasure, restriction of processing, portability in a machine-readable format, and you may object to processing based on legitimate interest. Write to lozanon57@gmail.com. The response is due within one month.

If you are not satisfied, you may complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos, or to the supervisory authority of your own country of residence.

6. Security

Traffic is encrypted in transit (TLS). Authentication is handled by Supabase; the operator never sees your password. Database access is restricted by row-level security so one account cannot read another’s progress. Server-side credentials are held in encrypted environment variables and rotated when there is any reason to believe one has been exposed.

7. Changes

Any change is published on this page with a new date at the top. A change that materially affects your rights will also be sent by email to registered users before it takes effect.