Skip to content
Q Quizment
Features Demo Insights Pricing
Legal information

Privacy Policy

Information about the processing of personal data when using Quizment.

Last updated: 6 August 2026

1. Controller

The controller responsible for operating the Quizment platform, user accounts, contractual and billing relationships, support, and the operator's own assessments is:

Andre Sieger
c/o IP-Management #7773
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany
Email: admin@quizment.com

2. Scope and allocation of controller roles

This Privacy Policy applies to website visitors, registered users, organization members, customers, support contacts, and participants in public or invitation-only assessments.

Where a user or organization creates an assessment for its own purposes, that party determines, in particular, the topic, questions, group of participants, evaluation, and subsequent use of the responses. It is therefore generally the controller for this substantive processing within the meaning of Article 4(7) GDPR. Where Quizment processes such data exclusively on documented instructions and on the basis of a valid agreement under Article 28 GDPR, Quizment acts as a processor; otherwise, its specific role must be determined separately in light of the actual circumstances. The assessment creator must provide participants with its own privacy notice and state the legal basis on which it relies.

Where Andre Sieger creates an assessment of his own and determines its purposes and means, he is also the controller for the participant data processed in that assessment. Questions concerning an assessment created by another party should primarily be directed to that assessment's creator; Quizment assists in routing and handling data protection requests.

3. Categories and sources of personal data

Depending on how Quizment is used, it processes the following categories of personal data:

  • Connection and log data: IP address, time, requested address, HTTP method and status, amount of data transferred, referrer, and browser or device details;
  • Account and profile data: email address, display name, role, language, profile image or avatar, account and verification status, and login and security events;
  • Assessment and organization data: titles, descriptions, questions, response logic, versions, images, sharing permissions, memberships, roles, and comments;
  • Participation data: invitation address, invitation and opening status, responses, result, completion time, submission time, and a pseudonymous participant or device identifier;
  • Contract and billing data: plan, subscription status, contract periods, provider, customer, and subscription identifiers, and billing-related metadata;
  • Communication and support data: the content and status of requests, replies, internal processing notes, error messages, and attachments;
  • AI usage data: inputs, relevant assessment content, conversation context, generated results, web-search setting, and a pseudonymous security identifier.

The data generally originates from the data subject. Invitation addresses, organization roles, and shared assessment content may also be provided by an assessment creator, organization administrator, or another authorized user. The relevant creator must provide the information required under Article 13 or 14 GDPR in due time, either in the configurable invitation text or by another directly accessible means.

4. Website access, hosting, and logs

When the website is accessed, the server processes connection and log data to deliver the requested page, diagnose errors, prevent attacks, and ensure stable and secure operation. The legal basis is Article 6(1)(b) GDPR where access is necessary to use a service provided under a contract; in all other cases, the legal basis is Article 6(1)(f) GDPR. The legitimate interests pursued are availability, integrity, prevention of misuse, and IT security.

The quizment.com domain currently points to infrastructure operated by netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. Where netcup processes personal data on instructions, it is engaged as a processor. Server logs are required for operation, troubleshooting, and security purposes. In the event of a security incident, relevant entries may be retained until the incident has been investigated and legal claims have been established, exercised, or defended.

netcup Privacy Notice

5. Registration, account, and security

For registration, sign-in, and account management, Quizment processes in particular the email address, display name, language, role and status details, and a password stored only as a secure hash. Time-limited tokens, dispatch times, and rate-limiting information are processed for verification and for password or email-address changes. The registration security check runs entirely on Quizment infrastructure; no request is sent to an external CAPTCHA service. To limit abuse, the connection address is immediately transformed into an identifier using a secret key; the full address is not stored for this purpose. Consumed checks and these identifiers are stored only temporarily. Previous email addresses are retained as a change history until the account is deleted so that invitations and responses associated with the account can be reliably located and anonymized upon deletion. Profile images and avatar settings are optional.

The processing is necessary to take steps prior to entering into and to perform the user agreement pursuant to Article 6(1)(b) GDPR. Failed login attempts are logged for a limited period together with the user identifier and IP address, and the account may be locked for one hour after five failed attempts. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is to protect accounts and the platform against unauthorized access and misuse.

6. Assessments, organizations, and collaboration

To create and manage assessments, Quizment processes the content entered, versions, images, publication and invitation settings, and their assignment to authors and organizations. Team features involve processing the organization name, memberships, roles, invitations, sharing permissions, and comments. Depending on their role, authorized members of the relevant organization may access this data. For guest quizzes, only the creation time rounded to the minute is retained permanently for internal usage statistics; this statistical record contains no quiz content, IP addresses, session tokens, or account data. Uploaded assessment and support images may contain metadata from the original file; this metadata should be removed before uploading if it is not intended to be disclosed.

The legal basis for platform features requested by the account holder is Article 6(1)(b) GDPR. Where Quizment is to process content as a processor for a company or another organization, this requires an agreement under Article 28 GDPR and documented instructions from the relevant controller.

The content-free guest quiz creation statistics are processed on the basis of Article 6(1)(f) GDPR. The legitimate interest lies in privacy-conscious usage measurement, capacity planning and the further development of the guest offering.

Quizment is not intended to collect special categories of personal data under Article 9 GDPR or highly sensitive confidential information without a prior legal and organizational review. Assessment creators are responsible for collecting only the data that is necessary and, where applicable, for defining a specific legal basis, safeguards, and deletion periods.

7. Invitations, participation, and results

For personal invitations, Quizment processes the email address provided by the creator, a random invitation token, dispatch, delivery-error, opening, and completion times, and a pseudonymous participant identifier. For identified invitations, the email address is linked to the response; in the mode in which responses are not linked to email addresses, the invitation and its opening and completion status remain stored separately.

For public participation without an email association, Quizment does not store an email address or use an IP address as the participant identifier in the response. Connection data may nevertheless be recorded independently in server logs. If one-time participation is enabled, a random signed browser identifier is set; only an assessment-specific hash of that identifier is stored in the database. These pseudonymous identifiers make repeated participation in the same browser more difficult but do not enable reliable identification across devices.

Where Quizment processes responses for an external assessment creator, that creator must disclose the purpose, legal basis, recipients, and retention period before the data is collected, for example in the configurable invitation text or in its own directly linked privacy notice. For a complete evaluation, the questions reached in the selected flow must be answered; without this information, participation cannot be completed.

8. AI features and optional web search

When an authorized user actively invokes AI generation or the AI assistant, Quizment transmits the input and, where necessary for the task, the title, summary, questions, logic, and previous conversation context of the relevant assessment to the OpenAI API. A pseudonymous security identifier derived from the internal user ID is also transmitted. The user decides whether the optional web search is disabled, used automatically, or required; search queries and accessed sources may be processed as part of this feature.

The service provider is OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. The API request is configured with store=false. Under the data controls applicable to the API, inputs and outputs are not used for model training by default; limited abuse-monitoring logs may generally be retained for up to 30 days unless a legal obligation or security exception requires longer retention.

The legal basis is Article 6(1)(b) GDPR for the feature requested by the user and Article 6(1)(f) GDPR for misuse-prevention and security checks. The legitimate interest is the secure and traceable operation of the AI features. Users must not include unnecessary personal data, special categories of personal data, or confidential third-party information in AI inputs.

OpenAI Privacy Policy · OpenAI Data Processing Agreement

9. Subscriptions and Stripe

If paid billing is enabled and a plan is purchased, Quizment redirects the user to the checkout and customer portal provided by Stripe. In particular, the email address, internal user identifier, selected plan, billing period, and, for Business, the purchased seat quantity are transmitted. Stripe additionally collects the required billing address, tax details, and payment data. Full card or bank-account details are not stored on Quizment's servers.

For customers in the European Economic Area, the service is provided by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Depending on the activity, Stripe processes data as a processor and, for its own purposes prescribed by law, in particular payment processing, fraud prevention, anti-money-laundering and sanctions screening, as an independent controller.

Quizment relies on Article 6(1)(b) GDPR for the contract and payment, Article 6(1)(c) GDPR for obligations under commercial and tax law, and Article 6(1)(f) GDPR for fraud prevention and the mitigation of payment and legal risks. The legitimate interest is secure and verifiable payment processing. Stripe's Privacy Policy also applies.

Stripe Privacy Policy · Stripe Data Processing Agreement

10. Email, support, and files

When a person contacts Quizment or submits a support request, Quizment processes contact details, messages, ticket status, replies, internal processing notes, and attachments uploaded voluntarily in order to handle the matter. The legal basis is Article 6(1)(b) GDPR for contractual matters and otherwise Article 6(1)(f) GDPR. The legitimate interest is efficient communication, troubleshooting, and documentation. Communications required by law are additionally processed pursuant to Article 6(1)(c) GDPR.

An SMTP email service may be used for verification, account recovery, invitations, and organization and support messages. It receives the recipient address, subject, message body, and technical delivery information. The category of recipient is the configured email transport service; no external SMTP provider is currently configured in the production setup. Before a provider is enabled, its data protection terms and conditions for third-country transfers will be reviewed and this documentation updated.

11. Cookies and browser storage

Quizment does not use analytics, advertising, or social-media cookies. Session, security, one-time-participation, and AI-transfer storage is used only where strictly necessary for the service expressly requested (Section 25(2), no. 2 TDDDG). The language, theme, and billing interval are stored only following an explicit selection and are subsequently read solely to retain that requested setting. Where the information constitutes personal data, its subsequent processing is based on Article 6(1)(b) or (f) GDPR as described below. If storage requiring consent is added in the future, it will be activated only after consent has been obtained in accordance with Section 25(1) TDDDG.

Name Type and purpose Duration
sessionid HTTP-only cookie for login and session management; performance of the contract and account security up to 14 days; expires earlier upon logout or account deletion
csrftoken Protection against forged form submissions; legitimate interest in application security up to 1 year
django_language Stores the selected interface language until the end of the browser session
quizment_device Random signed HTTP-only identifier to limit repeated pseudonymous participation without an email association; only for assessments configured accordingly up to 2 years
quizment-theme Local storage for the selected light or dark theme until deleted in the browser
quizment-billing-cycle Session storage for selecting monthly or annual billing until the end of the browser session
quizment.ai.generationResult Session storage for a temporarily generated AI result when switching to the editor until applied or until the end of the browser session

All cookies and stored content listed above are set by Quizment as the first party; no third-party trackers are embedded in the browser.

Browsers can delete or block cookies and local-storage content. This may restrict login, language and theme selection, applying AI results, or the limitation of repeated participation.

12. Recipients and authorized users

Data is disclosed only to parties that require it for the purposes described. These include the operator and authorized administrators, the relevant assessment creator and authorized organization members, hosting and IT infrastructure providers, any configured email transport service, and, only when actively used, OpenAI and Stripe. Authorities, courts, legal counsel, or tax advisers receive data only where required by law or where necessary for the establishment, exercise, or defense of legal claims.

Where a recipient processes data on instructions, an agreement under Article 28 GDPR is required before that recipient is engaged. Where a service provider processes data for its own statutory or security-related purposes, it acts as an independent controller to the stated extent.

13. Transfers outside the EU and EEA

When OpenAI or Stripe is actively used, data may be transferred to recipients and subprocessors outside the EU and EEA. Quizment reviews the recipients, safeguards, and data-processing terms applicable to the specific service before productive use and again following material changes.

OpenAI's Data Processing Agreement provides for the European Commission's Standard Contractual Clauses for transfers to recipients without an adequate level of data protection; for a U.S. recipient certified under the EU-U.S. Data Privacy Framework, the adequacy decision pursuant to Article 45 GDPR may apply. Stripe likewise governs international transfers in its Data Processing Agreement and Data Transfers Addendum, depending on the recipient, through the EU-U.S. Data Privacy Framework or Standard Contractual Clauses. A copy of, or further information about, the safeguards specifically used upon activation may be requested at admin@quizment.com.

14. Retention and deletion

Quizment retains personal data only for as long as required by the relevant purpose, the contract, the instructions of a controller responsible for an assessment, statutory retention obligations, or the protection of legal claims.

  • Account data, including previous email addresses, is retained while the account is active. A deletion request is subject to a seven-day period in which it can be cancelled; the data is then removed when the deletion routine is run, unless a legal obligation or pending billing transaction prevents deletion.
  • Personal assessments belonging to the deleted account are deleted. Organization or company assessments may be transferred to another authorized member in order to preserve shared work. Invitations sent to the account's email address are deleted, and corresponding email references stored with responses are anonymized.
  • Assessment responses, versions, and invitations are retained until the relevant assessment is deleted or until an earlier instruction is given by its controller. Merely ending publication or allowing a participation period to expire does not delete existing responses.
  • Guest quiz content is automatically deleted after the three-day guest period expires unless the quiz was previously transferred to an account. The separate, content-free creation time rounded to the minute is retained for internal usage statistics.
  • Sessions are generally valid for up to 14 days and are terminated upon logout or account deletion. Verification, change, and recovery links generally expire after 24 hours; associated records may remain until they are replaced or confirmed or until the account is deleted.
  • Login, security, and error logs are maintained separately from the user account and are therefore not necessarily deleted together with it. They are retained for as long as necessary to prevent misuse, investigate incidents, or address legal claims; in the event of an incident, necessary extracts may be retained until the matter has been resolved.
  • Support and communication data is retained until the matter is closed and thereafter only for as long as required for follow-up questions, warranty matters, legal defense, or statutory obligations.
  • Deleted team comments are initially hidden only. Their content may be retained until the associated organization or assessment is deleted in order to preserve a traceable record of collaborative work, unless a valid right to erasure requires earlier removal.
  • Documents subject to retention requirements under commercial and tax law are generally retained for six, eight, or ten years, depending on the type of document. This applies only to documents subject to a retention obligation, not to all account or content data as a whole.
  • Where backups are created, they are retained exclusively for recovery and security purposes. Data already marked for deletion is deleted again after a restore and is not used for any other purpose. The applicable backup cycle depends on the production infrastructure in use.

15. Data subject rights

Subject to the statutory requirements, data subjects have the right of access and to obtain a copy of their data (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), notification of recipients (Article 19), and data portability (Article 20). Consent may be withdrawn at any time with effect for the future; the lawfulness of processing carried out before withdrawal remains unaffected.

Right to object: Where processing is based on Article 6(1)(e) or (f) GDPR, the data subject may object at any time on grounds relating to their particular situation. An objection to direct marketing does not require specific grounds. Quizment does not currently engage in direct marketing based on user profiles.

Requests may be sent to admin@quizment.com. Additional information necessary to confirm identity may be requested only where there are reasonable doubts concerning the requester's identity. If the request concerns responses or content in an assessment created by another party, the responsible creator will be involved or the request forwarded to that creator. Requests are generally answered within one month; in complex cases, this period may be extended in accordance with Article 12 GDPR.

16. Right to lodge a complaint

Data subjects may lodge a complaint with a data protection supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place of the alleged infringement. The authority generally competent for the operator established in Hamburg is:

The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22
20459 Hamburg
Telephone: +49 40 42854-4040
Email: mailbox@datenschutz.hamburg.de

Submit a complaint or report to the Hamburg supervisory authority

17. Requirement to provide data

Connection data is technically necessary to provide the website. An email address, display name, and password are required for a user account; without them, an account cannot be created or used. Contract and payment data is required for a paid plan. A profile image, avatar, and information not marked as required are optional.

For assessments, the relevant creator defines the sequence of questions. The questions displayed in the flow reached must be answered so that the assessment can be fully submitted and evaluated. Participation itself is voluntary unless a separate legal or contractual relationship with the assessment creator provides otherwise.

Quizment is not directed exclusively at children and does not currently perform technical age verification. If an assessment is intended specifically for use by minors, the relevant controller must ensure that age-appropriate information and a valid legal basis are provided and, where applicable, that the consent of the holders of parental responsibility required under Article 8 GDPR is obtained.

18. Automated evaluation and profiling

Quizment may automatically evaluate responses using the scoring, branching, and result rules defined by the assessment creator. The operator does not use these results to make solely automated decisions concerning user accounts or contracts that produce legal or similarly significant effects. If an assessment creator uses results for decisions with such effects, that creator must independently assess the requirements of Article 22 GDPR and inform participants about the logic used and the significance and envisaged consequences.

AI outputs are drafts and are not published autonomously or used as legally significant decisions about individuals. Quizment does not create advertising profiles or use solely automated decisions concerning the conclusion or continuation of a user agreement.

19. Security and changes

Quizment uses technical and organizational measures appropriate to the risk. These include encrypted transmission via HTTPS, hashed passwords, restricted session and role permissions, protection against forged requests, rate limits, and the logging of security-relevant errors. When Stripe billing is enabled, webhooks are processed only after successful signature verification. No procedure provides absolute security; measures are therefore reviewed and developed further in line with the risk and the state of the art.

This Privacy Policy will be updated if features, service providers, processing purposes, or legal requirements change materially. Registered users will be informed appropriately of significant changes. The version published on this page applies.

© 2026 Quizment
Insights Privacy Policy Imprint