Privacy Policy
How we collect, use, share, and protect your personal data when you use PluQuiz AI. Written to meet GDPR Articles 13–14 and Romanian Law 190/2018.
- Effective
- Effective
- Last updated
- Last updated
- Version
- v2.0
At a glance
What we collect
Account, content, usage, billing, and support data — no more than we need to run the service.
No AI training on your data
We don't train machine-learning models on your inputs, outputs, or personal content.
Your GDPR rights
Access, rectify, erase, port, restrict, object — all free, answered within one month.
EU-first hosting
Database and auth in the EU. International transfers covered by SCCs + the EU-US Data Privacy Framework.
Section 01
Who is the data controller
The data controller for personal data processed via PluQuiz AI is [COMPANY LEGAL NAME], CUI [CUI], registered office at [ADDRESS], Romania.
For any privacy question or to exercise your rights, contact our privacy team at privacy@pluquiz.ai. Where a Data Protection Officer is appointed, you can reach them at dpo@pluquiz.ai.
Section 02
Data we collect
We collect only what we need to run the service, bill you fairly, keep the platform safe, and improve it over time. Here's the full catalogue:
Account data
- Email address (required)
- Display name and username (required)
- Avatar image (optional)
- Authentication method and session tokens
- Multi-factor authentication factors, if you enable them
- Role and status flags (e.g. admin, active/deactivated)
Profile & preferences
- Bio, learning purpose, interests, preferred difficulty, daily goal
- Theme choice (galaxy / light / dark) and language preference
- Privacy settings (profile visibility, competitive-mode opt-in)
- Notification and email preferences
Content data (your creations)
- Quizzes, courses, study guides, flashcards, collections you create
- Quiz attempts, answers, scores, and time spent
- Progress data (completion, streaks, XP, badges)
- Discussion posts and study-group activity, where applicable
AI-generation data
- Prompts and source material you submit for generation
- AI-generated outputs returned to you
- Token counts, model used, and credit cost per request
Billing data
- Subscription tier, billing period, status, cancellation dates
- Credit balance and transaction history (audit log)
- Invoice history and VAT ID (for B2B customers)
- A customer identifier from our payment processor — card numbers are never stored by us
Usage & technical data
- IP address, user-agent, device type, approximate location from IP
- Pages visited, features used, session duration, timestamps
- Server-side logs (for debugging and security)
- Error reports (no sensitive content captured)
Support data
- Messages you send to support@, billing@, privacy@, legal@pluquiz.ai
- Feedback submitted via in-app forms
We do notprocess special-category data (health, biometric, political, religious) as part of our service. We do not knowingly collect the Romanian CNP (personal numerical code) or national ID numbers. If a quiz or uploaded document contains such data, it's your responsibility to remove it first.
Section 03
Purposes & legal bases (GDPR Art. 6)
Each processing activity has a specific purpose and legal basis:
Contract (Art. 6(1)(b))
Creating and managing your account, processing credit purchases and subscriptions, running AI generation you request, delivering courses and quizzes, providing support.
Consent (Art. 6(1)(a))
Optional marketing emails, non-essential cookies/analytics, optional integrations. You can withdraw consent at any time in your account settings — withdrawal doesn't affect prior lawful processing.
Legitimate interest (Art. 6(1)(f))
Fraud prevention, platform security, abuse detection, aggregated product analytics, direct-marketing to existing customers (with opt-out), legal-claims defence. Balanced against your rights in documented assessments.
Legal obligation (Art. 6(1)(c))
Invoicing and VAT records (Romanian Fiscal Code Law 227/2015, RO e-Factura), accounting records (Romanian accounting law), responses to lawful orders from authorities.
Where legitimate interest is the basis, you have the right to object. For direct marketing, the objection is absolute.
Section 04
Who we share data with
We share data with trusted sub-processors who help us operate the service. Each is bound by a GDPR-compliant data-processing agreement and may only process data on our instructions. We disclose the categories of recipients below, as permitted by GDPR Article 13(1)(e).
| Category | Purpose | Region |
|---|---|---|
| Hosting & database provider | Storing your account, content, and application data. | EU |
| Application hosting & edge network | Serving the website, handling requests, writing server logs. | EU + US |
| Payment processor | Processing payments, invoicing, fraud prevention. | EU + US |
| AI service providers | Generating quizzes, study guides, explanations, audio, and images on your request. | EU + US (and, for optional features you enable, other regions) |
| Email delivery provider | Sending transactional email (receipts, password resets, notifications). | US |
A detailed list of specific sub-processors, together with the applicable safeguards, is available on request by emailing privacy@pluquiz.ai. We do not sell your personal data, and we do not share it with third parties for their own marketing.
Section 05
AI training policy
We do not train machine-learning models on your personal data. Your prompts, inputs, AI outputs, quizzes, courses, and account data are not used to train PluQuiz models or third-party foundation models.
Our AI service providers operate on API-tier terms under which customer API traffic is not used to train their models. We minimise personal data in prompts and rely on contractual non-training commitments plus appropriate international-transfer safeguards.
Anonymised, aggregated statistics may be used internally to improve the service. These statistics cannot be linked back to you.
Section 06
International transfers
Your primary data stays in the EU. Some sub-processors are based outside the EEA — most commonly the United States, and, for optional features you enable, other jurisdictions.
We protect those transfers using:
- EU-US Data Privacy Framework (adequacy decision of 10 July 2023) for US recipients certified under the Framework.
- Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914) for recipients not covered by an adequacy decision.
- Transfer Impact Assessments and supplementary measures (encryption in transit, access controls, data minimisation) where the recipient country lacks essentially equivalent data-protection law.
A copy of the relevant SCCs is available by emailing privacy@pluquiz.ai. Transfers under Article 49 derogations (for example to enforce legal claims) are used only where appropriate and are always documented.
Section 07
How long we keep data
We don't keep personal data longer than we need it. Retention periods by category:
| Category | Retention |
|---|---|
| Account & profile data | Until account deletion, then 30-day recovery grace, then erased. |
| Content you create | While the account is active. On deletion, erased together with the account. |
| AI-generation logs | 90 days for troubleshooting and safety; then aggregated. |
| Billing & tax records | 10 years — Romanian accounting and fiscal law (Law 82/1991, Fiscal Code). |
| Server-side security logs | 90 days by default. |
| Support emails & tickets | 2 years after resolution, or as required for legal claims. |
| Marketing preferences | Until you withdraw consent or the account is deleted. |
| Backups | Short rolling window; deletions are propagated to backups on the next cycle. |
Section 08
Your rights (GDPR Art. 15–22)
You have extensive rights over your personal data. All requests are free (unless manifestly unfounded or excessive) and answered within one month — extendable by two further months for complex requests, with notice.
Access (Art. 15)
Ask for a copy of the personal data we hold about you and how we process it.
Rectification (Art. 16)
Correct inaccurate or incomplete data. You can do this in your account settings for most fields.
Erasure (Art. 17)
Delete your account and associated personal data. Some data is kept where law requires (e.g. invoices).
Restriction (Art. 18)
Tell us to pause processing while a dispute over accuracy or legitimate interests is resolved.
Portability (Art. 20)
Receive your personal data in a structured, machine-readable format, or have it sent to another provider.
Objection (Art. 21)
Object to processing based on legitimate interest. For direct marketing the objection is absolute.
Automated decisions (Art. 22)
Not be subject to solely automated decisions with legal or similarly significant effects. We don't make such decisions.
Withdraw consent
Where we rely on consent (e.g. marketing, non-essential cookies), you can withdraw it at any time.
To exercise any right, email privacy@pluquiz.ai from the address on your account (or provide another verification). You can also delete your account directly from your account settings.
You have the right to lodge a complaint with a supervisory authority, in particular in the EU country of your habitual residence, place of work, or place of the alleged infringement. In Romania:
ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
B-dul G-ral Gheorghe Magheru 28–30, Sector 1, 010336 București · Tel: +40 318 059 211 · dataprotection.ro
Section 09
Security
We protect your data with the technical and organisational measures expected of a modern SaaS:
- Encryption in transit (TLS 1.2+) and at rest.
- Row-level access controls, so one user's data cannot be accessed by another.
- Optional multi-factor authentication (TOTP authenticator apps) for your account.
- Principle-of-least-privilege access for our staff, with logging and audit.
- Card numbers are handled by a PCI-DSS-compliant payment processor and never stored by us.
- Regular security reviews, dependency scanning, and incident-response procedures.
No system is perfectly secure. If you discover a vulnerability, please report it to security@pluquiz.ai — we operate a good-faith disclosure policy.
Section 10
Children
PluQuiz AI is not intended for children under 16. Romanian Law 190/2018 does not derogate from the GDPR Article 8 default, so the age of digital consent in Romania is 16. We do not knowingly collect personal data from children under 16.
If you believe a child under 16 has created an account, please contact privacy@pluquiz.ai and we will delete the account.
Section 11
Automated decisions & profiling
PluQuiz AI uses automated processing to generate quizzes, grade quiz attempts, recommend content, and calculate credit costs. These decisions are not solely automated decisions with legal or similarly significant effects under GDPR Article 22 — their purpose is to produce study materials for your review, and a human can always override them.
We do not engage in any AI practice prohibited by the EU AI Act (Regulation (EU) 2024/1689), including emotion recognition in educational contexts, social scoring, manipulative exploitation, or biometric categorisation.
Section 12
Data breaches
If a personal data breach occurs and is likely to pose a risk to your rights and freedoms, we will notify the Romanian DPA (ANSPDCP) without undue delay and, where feasible, within 72 hours of becoming aware, as required by GDPR Article 33.
Where the breach is likely to result in a high risk to you, we will notify you directly without undue delay and in plain language explaining what happened, what data was affected, what we're doing about it, and what you can do (Art. 34).
Section 13
Changes to this policy
We may update this Privacy Policy to reflect changes in the service, law, or our processing. If a change has a material impact on your rights, we will give you at least 30 days' notice by email and in-app. Previous versions are archived — email privacy@pluquiz.ai to request one.
Section 14
Contact & complaints
Privacy team
privacy@pluquiz.ai
DPO (if appointed)
dpo@pluquiz.ai
General support
support@pluquiz.ai
Security disclosures
security@pluquiz.ai
For postal correspondence: [COMPANY LEGAL NAME], Privacy Team, [ADDRESS], Romania.
Privacy question or request?
Email our privacy team directly — we respond within 30 days for statutory requests and usually much faster.
Email privacy@pluquiz.ai