Privacy Policy

Last updated: 17 September 2026

Privacy Policy

This Privacy Policy explains which personal data we process when you use IQhippo, for what purposes and on what legal basis, how long we keep the data and what rights you have. It applies to our website, the member area and our email communication with you.

1. Controller

The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

[Firmenname GmbH]
[Straße Hausnummer]
[PLZ Ort]
Germany
Represented by: [Vor- und Nachname, Geschäftsführer/in]
Email: help@iqhippo.com
Phone: [+49 000 0000000]

2. Our principles in brief

3. Legal bases

We process personal data only where there is a legal basis for doing so. The relevant bases are:

For each processing activity described below we state the applicable legal basis.

4. Hosting and server log files

Our website is hosted by [Hosting-Anbieter, Anschrift]. The servers are located in [Serverstandort, z. B. Deutschland]. We have concluded a data processing agreement with the provider.

Each time you access our website, the following data is automatically stored in server log files: IP address, date and time of access, page or file requested, amount of data transferred, status code, the previously visited page (referrer), browser type and version, and operating system.

Purposes: delivery of the website, ensuring stability and security (in particular detecting and preventing attacks and misuse), error analysis.
Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is the secure and trouble-free operation of the website.
Retention: log files are deleted after 14 days. They are kept longer only if a specific security incident needs to be investigated.

5. User account, test and evaluation

5.1 Which data we process

5.2 Purposes: creating and managing your user account, conducting and evaluating the test, producing the report and certificate, providing the results history and the member area, managing the subscription (trial, renewal, cancellation, withdrawal) and responding to your enquiries.

5.3 Legal bases: Art. 6(1)(b) GDPR for all data we need to conduct the test and perform the contract; taking the test before a subscription is concluded constitutes steps taken at your request prior to entering into a contract. For the optional information (age, education, name for the certificate) the legal basis is your consent under Art. 6(1)(a) GDPR, which you give by entering the information. You can withdraw this consent at any time by emailing us; we then delete the information. The use of test data in anonymised and aggregated form to calibrate our tasks and improve the service is based on Art. 6(1)(f) GDPR; our legitimate interest is the quality and further development of the test. The anonymised data cannot be traced back to you.

5.4 Automated evaluation: your result is calculated automatically according to fixed rules (in particular the number of correct answers and the response time). The evaluation is for your information only. It has no legal effect on you and is not an automated decision within the meaning of Art. 22 GDPR. We do not build profiles from your data for advertising purposes.

5.5 Test attempt without a subscription: if you take the test but do not take out a subscription, we store the data of the test attempt and any email address you provided for a maximum of 30 days so that you can still complete your attempt during that time. After that we delete them. We do not send marketing emails or reminders about an incomplete purchase without your consent.

5.6 Retention: we keep account and test data for as long as your user account exists. If you delete your account, we delete this data within 30 days unless statutory retention obligations prevent this; in that case we restrict processing and delete the data once the retention periods have expired. Accounts without an active subscription that have not been used for 24 months are deleted after prior notice by email.

6. Payment processing (Stripe)

We process payments through Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland ("Stripe"), a company of the Stripe group whose parent company is Stripe, Inc. in the USA.

You enter your payment details (for example cardholder name, card number, expiry date, security code or the details of other payment methods offered, and a billing address where requested) directly on the payment page provided by Stripe. Stripe also receives your email address, the amount, the payment reference and technical data such as IP address and device information, which Stripe processes for fraud prevention. In this respect Stripe is an independent controller; details can be found in Stripe's privacy policy at https://stripe.com/privacy.

From Stripe we receive and store only: a customer identifier, the status of the subscription and payments, the amount and date of payments, the payment method, for cards the card brand and the last four digits, and the country of the payment method. We do not receive full card details.

Purposes: processing the payment, collecting the recurring amounts, issuing receipts, handling refunds, fraud prevention, accounting.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract); for the retention of accounting records Art. 6(1)(c) GDPR in conjunction with section 147 of the German Fiscal Code (AO) and section 257 of the German Commercial Code (HGB); for fraud prevention measures Art. 6(1)(f) GDPR.
Transfer to third countries: Stripe may transfer data to Stripe, Inc. in the USA. Stripe is certified under the EU-U.S. Data Privacy Framework; in addition, the European Commission's standard contractual clauses apply (Art. 46(2)(c) GDPR).
Retention: we keep payment and invoice data for ten years from the end of the calendar year of the payment (section 147 AO).

7. Email communication

7.1 Transactional emails: to perform the contract we send emails to the address of your account, in particular login codes or access details, the order and contract confirmation including the Terms and the withdrawal instructions, the reminder before the end of the trial and the first regular charge, payment receipts, notices of failed payments, confirmations of cancellations and withdrawals, notices of changes to the services or terms, and security notices about your account. These emails are part of the contract and cannot be unsubscribed from while the contractual relationship exists.
Legal basis: Art. 6(1)(b) GDPR; for confirmations required by law (sections 312f, 312k BGB) Art. 6(1)(c) GDPR; for security notices Art. 6(1)(f) GDPR.

7.2 Marketing emails: we send newsletters or other marketing emails only if you have expressly consented (Art. 6(1)(a) GDPR, double opt-in). You can withdraw your consent at any time, for example via the unsubscribe link in every email. We do not use tracking pixels or similar techniques in our emails to track opens.

7.3 Delivery service provider: we use [E-Mail-Versanddienstleister, Anschrift] to send emails, under a data processing agreement. The provider processes your email address, the content of the message and delivery information exclusively on our behalf. [If the provider processes data outside the EU: state the safeguard, e.g. standard contractual clauses or certification under the EU-U.S. Data Privacy Framework.]

8. Cancellation page (cancellation button)

Via the button "Cancel contracts here" you can cancel your subscription without logging in. In doing so we process the email address of your account, the date and time of your statement, the requested end date and, if you provide it voluntarily, the reason for cancellation. We send you a confirmation email stating the content, the time of receipt and the end date.
Legal basis: Art. 6(1)(b) and (c) GDPR (section 312k BGB).
Retention: three years after the end of the contract as proof of cancellation (standard limitation period).

9. Contact and support

If you contact us by email or phone, we process your contact details, the content of your enquiry and, where available, the data of your user account in order to handle your request.
Legal basis: Art. 6(1)(b) GDPR if the enquiry relates to a contract, otherwise Art. 6(1)(f) GDPR; our legitimate interest is answering your enquiry.
Retention: three years after the matter is closed, unless longer statutory retention periods apply (for example for commercial correspondence, section 257 HGB).

10. Cookies

We use strictly necessary cookies only, which we set ourselves (first-party cookies): iq_session (login session, 30 days), iq_attempt (assignment of your test attempt, 7 days), iq_lang (selected language, 1 year) and iq_auth (display flag indicating whether you are logged in, 30 days). These cookies contain no advertising or analytics identifiers and are not transmitted to third parties.

Legal basis: storing and reading these cookies is permitted without consent under section 25(2) no. 2 TDDDG because they are strictly necessary to provide the service you have expressly requested. The associated processing of personal data is based on Art. 6(1)(b) GDPR (login, test attempt) and Art. 6(1)(f) GDPR (language setting, display flag). As we do not use any cookies requiring consent, we do not display a cookie banner.

On the payment page operated by Stripe, Stripe sets its own cookies for fraud prevention and session management; Stripe's privacy policy applies to these. Details on all cookies can be found in our Cookie Policy.

11. Recipients and transfers to third countries

We share personal data only with the following categories of recipients:

We do not sell personal data and do not share data with advertising networks, data brokers or social networks.

Transfers to countries outside the EU and the European Economic Area take place only as described in this Privacy Policy (in particular to Stripe, Inc. in the USA) and only on the basis of an adequacy decision of the European Commission (such as the EU-U.S. Data Privacy Framework) or appropriate safeguards such as the standard contractual clauses (Art. 46(2)(c) GDPR). We provide a copy of the safeguards on request.

12. Retention periods at a glance

DataRetention period
Server log files14 days
Test attempt without a subscriptionmaximum 30 days
Account and test datauntil the account is deleted; inactive accounts without a subscription after 24 months (with prior notice)
Contract documents (order confirmation, consent to early performance, cancellations, withdrawals)three years after the end of the contract; where they are accounting records or commercial correspondence: six or ten years respectively (section 257 HGB, section 147 AO)
Payment and invoice dataten years (section 147 AO)
Support communicationthree years after the matter is closed
Cookiessee section 10 and the Cookie Policy

13. Your rights

You have the following rights vis-à-vis us with regard to your personal data:

Right to object (Art. 21 GDPR): you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(f) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Where your data is processed for direct marketing, you may object at any time without giving reasons.

Right to lodge a complaint (Art. 77 GDPR): you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The supervisory authority responsible for us is: [zuständige Landesbeauftragte/r für den Datenschutz, Anschrift, Website].

To exercise your rights, an email to help@iqhippo.com is sufficient. To make sure the request comes from you, we may ask you to send it from the email address of your account. We respond within one month. You can also delete your account yourself at any time in the account settings.

14. Obligation to provide data

To conclude and perform the subscription we need your email address and, at Stripe, your payment details. Without this information we cannot conclude the contract. All other information, in particular age, level of education and the name for the certificate, is optional. Without a name we cannot create a personalised certificate.

15. Data security

We take technical and organisational measures in accordance with Art. 32 GDPR to protect your data against loss, misuse and unauthorised access. These include in particular encrypted transmission of all data (TLS), storage of passwords exclusively as a hash, time-limited login codes, access restrictions based on the principle of least privilege, regular backups and careful selection of our service providers. We continuously adapt these measures to the state of the art. Should a personal data breach occur despite these measures, we notify the competent supervisory authority and, where there is a high risk to you, also you without undue delay (Art. 33 and 34 GDPR).

16. Minors

Our service is intended for persons aged 18 and over. We do not knowingly process data of minors. If you become aware that a minor has created an account without the consent of a parent or guardian, please let us know; we will then delete the data.

17. Changes to this Privacy Policy

We update this Privacy Policy when our services, the service providers we use or the legal situation change. The current version is always available on our website. We inform you by email of material changes that affect your user account.

Last updated: 17 September 2026