Your data, your rules.

Full text of the personal data protection policy under GDPR. No marketing wording, no extra legal jargon — only what you need to know about how we handle your data.

01 / Data controller

The data controller within the meaning of Art. 4(7) of Regulation (EU) 2016/679 (GDPR) is DriverRank s.r.o. We are a company seated in Bratislava and we are responsible for how your personal data is handled.

We have not yet appointed a Data Protection Officer (DPO) — we are not a public authority and our core activity does not involve large-scale processing of special categories of data within the meaning of Art. 37 GDPR. If that changes, we will add the contact here.

02 / Data we collect

We work with the minimum we need to make the test work and to let you return to your result. No extra data "just in case".

Category Specific data When
Result identifier Anonymous token (UUID) generated when the test starts. Stored in your browser. When the test starts
Account (optional) E-mail address. Password is stored as a bcrypt hash, never in readable form. On registration
Test answers Your answers to the questionnaire, self-rating, reaction test result, optional lap-time entries. During the test
Score and tier Computed S-Score, P-Score, tier T1–T8, calibration signal Δ. Including a timestamp. After the test
Technical data IP address (truncated to /24 within 24 h), browser type, language, time zone. No device fingerprinting. On every request
Profile preferences Age, country, annual mileage, vehicle type — only if you fill them in your profile (optional). In settings
Notification preferences Consent to result e-mail, consent to re-test reminder (both opt-in, independently togglable). In settings

What we do not collect: name (or surname), phone, exact address, date of birth (only an age cohort), document numbers, health data, geolocation, device fingerprint, data about third parties.

03 / Processing purposes

Every piece of data we collect has a precisely defined purpose. If data does not correspond to any of these purposes, we do not collect it.

Purpose What we do Lawful basis
Test evaluation We process your answers, compute your score, and assign you to a tier T1–T8. Art. 6(1)(b)
Result delivery Showing the result in your browser and — if you enabled it — sending it by e-mail. Art. 6(1)(b)
Account and history Storing your results so you can return to them, compare re-tests, and see trends. Art. 6(1)(b)
Re-test reminder E-mail after 14 days proposing to repeat the test. Only if you opted in in settings. Art. 6(1)(a)
Population norms Your tier, calibration signal and demographic cell enter the population norm — only if you tick the consent before the test. No IP, no device, no individual answers. Art. 6(1)(a)
Security and anti-abuse Bot detection, rate limiting, abuse protection. IP truncated after 24 h. Art. 6(1)(f)
Compliance with legal obligations Accounting and tax records (where relevant), responses to data subject requests. Art. 6(1)(c)

None of these purposes involves profiling for a third party, automated decision-making with legal effect on you, or sale of data.

04 / Lawful basis

GDPR requires every processing operation to have one of six lawful bases in Art. 6. Our mix is:

  • Performance of a contract (Art. 6(1)(b)) — when you want to receive a result, we must process your answers and return your tier. This is the core of the service.
  • Consent (Art. 6(1)(a)) — for optional things: the population-norm contribution, the re-test reminder, marketing. Revocable at any time — by deleting your account or with a single click.
  • Legitimate interests (Art. 6(1)(f)) — for security and anti-abuse only. We have performed a balancing test and your rights do not override these interests.
  • Legal obligation (Art. 6(1)(c)) — for accounting and responses to authority requests if they arrive.

The evaluation is automated, but Art. 22 GDPR does not apply to it: the tier has no legal or similarly significant effect — it is feedback for you, not a decision about you. Open-ended answers do not enter the tier in Beta.

05 / Retention period

We do not keep data "forever just in case". For each category we have a specific period after which the data is automatically deleted or anonymised.

  • Account and results For the entire lifetime of the account. After account deletion everything is removed within 30 days; records in the population norm remain only if you consented — with no link to you.
  • Anonymous token Without registration — a cookie in your browser, 14 days from the last activity. Without the token you cannot return to your result.
  • Unfinished anonymous test 14 days from the last activity. Then the answers, lap times, e-mail, token and demographic data are irreversibly removed — only an anonymous record of the status, language, the section where the test stopped and whether the population-norm consent was given remains.
  • IP address Full IP for up to 24 hours. Then truncated to /24 and held for up to 90 days for anti-abuse. Then deleted completely.
  • Benchmark pool Anonymised answers with no link to an account — without a time limit. They cannot be re-attributed.
  • E-mail logs Records of notification e-mail dispatches — 12 months for deliverability and complaint handling.
  • Accounting records 10 years under Act No. 431/2002 Coll. — only if a billing transaction occurs.

After the period expires, we do not merely stop using the data — we physically delete or irreversibly anonymise it.

06 / Data recipients

We do not share your data with third parties for their own purposes. The only ones who may access it are technical suppliers (processors within the meaning of Art. 28 GDPR) with whom we have concluded data processing agreements.

Processor Purpose Location
Laravel Cloud (Laravel LLC) Application and database hosting — managed infrastructure on AWS (Amazon Web Services EMEA SARL) as sub-processor. The data processing agreement (DPA) is part of the provider's terms of service. Frankfurt, Germany (AWS eu-central-1, EU)
Anthropic PBC Scoring of open-ended scenario answers against expert-written rubrics — only when that feature is enabled (off in Beta). We send the answer text only, never your e-mail or an identifier. Data processing agreement (DPA) per the provider's terms. USA — SCC / DPF (counsel to verify)
Resend, Inc. Delivery of transactional e-mails (result, re-test reminder). USA — SCC + supplementary measures
Cloudflare, Inc. CDN, DDoS protection, DNS. Processes request metadata, not the test content. EU edge servers

Transfers outside the EU/EEA only to Resend and — when the feature is enabled — to Anthropic, in both cases under the Standard Contractual Clauses (SCC, Commission Decision 2021/914); Resend is certified under the EU-U.S. Data Privacy Framework. Laravel LLC is a US company, but the data lives exclusively in Frankfurt.

No transfer of data to insurers, employers, marketing aggregators, or state authorities (unless required by law).

07 / Your rights

GDPR grants you eight specific rights against us. All are exercisable by e-mail — we will respond within 30 days, in exceptional cases within 90 days with an explanation of why.

How to exercise: write to privacy@mydriverrank.com. The request does not need a form or a notarised signature — we just need to be able to identify you (account e-mail or result token). Handling is free of charge unless the request is manifestly unfounded or excessive.

08 / Cookies and tracking

We use cookies minimally. No advertising, no third-party tracking. The full breakdown is in our separate Cookie policy — here is the summary.

  • Strictly necessary cookies — session, anonymous result token, CSRF protection. Without them the application does not work. No consent required, because the lawful basis is performance of a contract.
  • No third-party analytics cookies — no Google Analytics, no Facebook pixel, no Hotjar. If we introduce privacy-friendly analytics in the future (e.g. Plausible / self-hosted), we will add a cookie banner and opt-in.
  • No marketing cookies — we do not build retargeting audiences.

Browser local storage is used to remember your language choice and test context (in-progress answers). These are not cookies and do not fall under §55(5) of Act No. 452/2021 Coll. — they are necessary for functionality.

09 / Data security

Security is a technical discipline, not marketing. These are the specific measures we currently have in place:

  • Encryption in transit — TLS 1.3, HSTS preload, no HTTP fallback.
  • Encryption at rest — database encrypted at the storage layer managed by the provider (AWS).
  • Passwords — bcrypt with cost factor 12. Never plain-text logs.
  • Tokens — an anonymous result is bound to a random token (UUID) in your browser; public result sharing is not offered yet.
  • Access — production database has no public endpoint; access only through the provider's console.
  • Backups — daily backups kept for 7 days + a manual snapshot before every deployment that changes the database structure.
  • Audit — every change to the scoring rules is versioned and traceable; logging of personal-data access in the admin panel will be added before the public launch.
  • Incident response — in case of a breach we notify the Slovak DPA within 72 hours under Art. 33 GDPR and you directly without undue delay.

If you find a security vulnerability, write to security@mydriverrank.com. Responsible disclosure welcome; a formal bug bounty is not yet established.

10 / Policy updates

We update this policy occasionally — laws change, technical providers change, sometimes we improve how we do things. Rules for changes:

  • Minor edits (typos, clarifications) — we do a silent update; the date below changes.
  • Substantive changes (new processor, new processing purpose, new categories of data) — we will notify you by e-mail at least 30 days before they take effect, if you have an account.
  • Change of lawful basis — will require your new consent where relevant.

Historical versions of the policy can be found in the commit history — no silent rewriting.

11 / Contact and DPA

Questions, requests, complaints — the fastest path is e-mail.

You can lodge a complaint with the DPA directly — you do not have to contact us first. We do however recommend trying that, as most issues are resolved faster directly.

Version 1.0 Effective from 2026-05-14 Jurisdiction SR Form full GDPR text (P1)