Right of access
You have the right to know whether and what data we process about you. On request we will send you an export of your data in a machine-readable format.
Full text of the personal data protection policy under GDPR. No marketing wording, no extra legal jargon — only what you need to know about how we handle your data.
The data controller within the meaning of Art. 4(7) of Regulation (EU) 2016/679 (GDPR) is DriverRank s.r.o. We are a company seated in Bratislava and we are responsible for how your personal data is handled.
We have not yet appointed a Data Protection Officer (DPO) — we are not a public authority and our core activity does not involve large-scale processing of special categories of data within the meaning of Art. 37 GDPR. If that changes, we will add the contact here.
We work with the minimum we need to make the test work and to let you return to your result. No extra data "just in case".
| Category | Specific data | When |
|---|---|---|
| Result identifier | Anonymous token (UUID) generated when the test starts. Stored in your browser. | When the test starts |
| Account (optional) | E-mail address. Password is stored as a bcrypt hash, never in readable form. | On registration |
| Test answers | Your answers to the questionnaire, self-rating, reaction test result, optional lap-time entries. | During the test |
| Score and tier | Computed S-Score, P-Score, tier T1–T8, calibration signal Δ. Including a timestamp. | After the test |
| Technical data | IP address (truncated to /24 within 24 h), browser type, language, time zone. No device fingerprinting. | On every request |
| Profile preferences | Age, country, annual mileage, vehicle type — only if you fill them in your profile (optional). | In settings |
| Notification preferences | Consent to result e-mail, consent to re-test reminder (both opt-in, independently togglable). | In settings |
What we do not collect: name (or surname), phone, exact address, date of birth (only an age cohort), document numbers, health data, geolocation, device fingerprint, data about third parties.
Every piece of data we collect has a precisely defined purpose. If data does not correspond to any of these purposes, we do not collect it.
| Purpose | What we do | Lawful basis |
|---|---|---|
| Test evaluation | We process your answers, compute your score, and assign you to a tier T1–T8. | Art. 6(1)(b) |
| Result delivery | Showing the result in your browser and — if you enabled it — sending it by e-mail. | Art. 6(1)(b) |
| Account and history | Storing your results so you can return to them, compare re-tests, and see trends. | Art. 6(1)(b) |
| Re-test reminder | E-mail after 14 days proposing to repeat the test. Only if you opted in in settings. | Art. 6(1)(a) |
| Population norms | Your tier, calibration signal and demographic cell enter the population norm — only if you tick the consent before the test. No IP, no device, no individual answers. | Art. 6(1)(a) |
| Security and anti-abuse | Bot detection, rate limiting, abuse protection. IP truncated after 24 h. | Art. 6(1)(f) |
| Compliance with legal obligations | Accounting and tax records (where relevant), responses to data subject requests. | Art. 6(1)(c) |
None of these purposes involves profiling for a third party, automated decision-making with legal effect on you, or sale of data.
GDPR requires every processing operation to have one of six lawful bases in Art. 6. Our mix is:
The evaluation is automated, but Art. 22 GDPR does not apply to it: the tier has no legal or similarly significant effect — it is feedback for you, not a decision about you. Open-ended answers do not enter the tier in Beta.
We do not keep data "forever just in case". For each category we have a specific period after which the data is automatically deleted or anonymised.
After the period expires, we do not merely stop using the data — we physically delete or irreversibly anonymise it.
We do not share your data with third parties for their own purposes. The only ones who may access it are technical suppliers (processors within the meaning of Art. 28 GDPR) with whom we have concluded data processing agreements.
| Processor | Purpose | Location |
|---|---|---|
| Laravel Cloud (Laravel LLC) | Application and database hosting — managed infrastructure on AWS (Amazon Web Services EMEA SARL) as sub-processor. The data processing agreement (DPA) is part of the provider's terms of service. | Frankfurt, Germany (AWS eu-central-1, EU) |
| Anthropic PBC | Scoring of open-ended scenario answers against expert-written rubrics — only when that feature is enabled (off in Beta). We send the answer text only, never your e-mail or an identifier. Data processing agreement (DPA) per the provider's terms. | USA — SCC / DPF (counsel to verify) |
| Resend, Inc. | Delivery of transactional e-mails (result, re-test reminder). | USA — SCC + supplementary measures |
| Cloudflare, Inc. | CDN, DDoS protection, DNS. Processes request metadata, not the test content. | EU edge servers |
Transfers outside the EU/EEA only to Resend and — when the feature is enabled — to Anthropic, in both cases under the Standard Contractual Clauses (SCC, Commission Decision 2021/914); Resend is certified under the EU-U.S. Data Privacy Framework. Laravel LLC is a US company, but the data lives exclusively in Frankfurt.
No transfer of data to insurers, employers, marketing aggregators, or state authorities (unless required by law).
GDPR grants you eight specific rights against us. All are exercisable by e-mail — we will respond within 30 days, in exceptional cases within 90 days with an explanation of why.
You have the right to know whether and what data we process about you. On request we will send you an export of your data in a machine-readable format.
If something is incorrect (e.g. e-mail), you can correct it directly in your account or write to us.
There is a "Delete account" button in your account. Everything is removed within 30 days. If you consented to the population norm, your tier and cohort stay in it — with no link to you.
If you object to processing, you can request its temporary restriction — until the dispute is resolved.
We will send your answers and score in JSON format. Usable for transfer to another service or for your own archive.
You can object to processing based on legitimate interests (anti-abuse). We will review and either stop or justify it.
You can switch off re-test e-mails and marketing at any time in settings — no explanation, no follow-up questions.
If you feel we do not respect your rights, you can lodge a complaint with the Slovak Data Protection Authority (ÚOOÚ SR). Contact details are below.
How to exercise: write to privacy@mydriverrank.com. The request does not need a form or a notarised signature — we just need to be able to identify you (account e-mail or result token). Handling is free of charge unless the request is manifestly unfounded or excessive.
Security is a technical discipline, not marketing. These are the specific measures we currently have in place:
If you find a security vulnerability, write to security@mydriverrank.com. Responsible disclosure welcome; a formal bug bounty is not yet established.
We update this policy occasionally — laws change, technical providers change, sometimes we improve how we do things. Rules for changes:
Historical versions of the policy can be found in the commit history — no silent rewriting.
Questions, requests, complaints — the fastest path is e-mail.
Hraničná 12, 820 07 Bratislava 27
Tel.: +421 2 3231 3214
You can lodge a complaint with the DPA directly — you do not have to contact us first. We do however recommend trying that, as most issues are resolved faster directly.