Privacy Policy
Last updated: May 10, 2026
1. Who We Are
DrSmartIQ ("we", "us", "our") operates the website drsmartiq.com and provides online cognitive assessment services. We are the data controller responsible for your personal information collected through this website.
Contact: support@drsmartiq.com
2. What Data We Collect
We collect the following categories of personal data:
- Account data: your name and email address when you register an account.
- Test data: your answers to test questions and your computed IQ score.
- Payment data: payment is processed entirely by Stripe. We do not store your card number, CVV, or other sensitive payment details on our servers. We receive only a Stripe session ID and payment status.
- Usage data: anonymised event data (e.g. which question you reached, whether you completed the test) tied to a random session identifier. This data does not identify you by default.
- Technical data: IP address, browser type, device type, and pages visited, collected automatically via server logs and analytics tools.
3. How We Use Your Data
- To generate and deliver your personalised IQ report.
- To create and manage your account and save your results.
- To process payments through Stripe.
- To respond to support enquiries.
- To improve our services using aggregated, anonymised analytics.
- To comply with legal obligations.
We do not sell, rent, or trade your personal data to third parties. We do not use your data for automated individual decision-making or profiling beyond generating your test report.
4. Legal Basis for Processing (GDPR)
- Contract performance: processing your order and delivering your report.
- Legitimate interests: improving our services, fraud prevention, and internal analytics.
- Legal obligation: retaining transaction records as required by applicable law.
- Consent: optional analytics and marketing communications (where applicable).
5. Data Retention
- Account and result data is retained for as long as your account is active, or until you request deletion.
- Transaction records are retained for 7 years to comply with financial regulations.
- Anonymous usage events are retained for up to 2 years for analytics purposes.
6. Third-Party Services
- Stripe: payment processing. Stripe's privacy policy applies to all payment data: stripe.com/privacy.
- Google Analytics: anonymised website analytics. You can opt out via your browser's cookie settings or the Google Analytics opt-out browser add-on.
- Google OAuth: optional sign-in. If you choose to sign in with Google, we receive your name and email address from Google.
7. Cookies
We use strictly necessary session cookies to keep you signed in. We may also use analytics cookies (Google Analytics) to understand how our site is used. Analytics cookies are only set after interaction. You can disable cookies in your browser settings at any time.
8. Your Rights
Under applicable data protection law, you have the right to:
- Access a copy of the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your personal data ("right to be forgotten"), subject to legal retention requirements.
- Restrict or object to processing in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email us at support@drsmartiq.com. We will respond within 30 days.
9. Data Security
We implement appropriate technical and organisational measures to protect your data, including encrypted data transmission (HTTPS/TLS), hashed password storage (bcrypt), and access controls limiting data access to authorised personnel only.
10. Children's Privacy
Our service is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of our service after changes constitutes acceptance of the updated policy.