Privacy Policy
Last updated: August 27, 2026
1. Who we are
CertOnyx ("we," "us," "our") operates certonyx.com. This Privacy Policy explains how we collect, use, and protect your personal data.
Data controller: BEE FOR SERVICES, société à responsabilité limitée à associé unique (SARL AU), registered in Morocco under RC N° 127247 (Tribunal de première instance de Témara), ICE N° 002201222000070. Registered office: N14, Lot 24 HEC, Secteur 06, Garage N2 RDC, Témara, Morocco.
Contact: support@certonyx.com
2. What data we collect
- Account data: email address, hashed password (via Supabase Auth).
- Usage data: your practice question attempts, correct/incorrect answers, mock exam scores, spaced-repetition progress.
- Preference data: language preference, timezone, notification settings.
- Billing data: handled entirely by Paddle (our Merchant of Record) — we do not store your payment card details ourselves.
- Technical data: IP address, browser type, and similar data collected automatically for security and analytics purposes.
- Google Sign-In data: If you choose to sign in with Google, we receive basic information from your Google account, such as your email address, name, profile picture (if available), and Google account identifier, as necessary to authenticate you and create or access your CertOnyx account. We do not access your Gmail, Google Drive, contacts, or other Google services.
3. Why we collect this data (legal basis under GDPR)
- Contract performance: account data and usage data are necessary to provide the service you've signed up for.
- Consent: marketing emails and study reminder notifications are sent only with your explicit opt-in, which you can withdraw at any time.
- Legitimate interest: basic technical/analytics data helps us maintain and improve the service.
4. How we use your data
- To provide and personalize your practice sessions and progress tracking.
- To process your subscription and billing (via Paddle).
- To send service-related emails (account confirmation, password reset).
- To send study reminders and marketing emails, only if you've opted in.
- To improve our content and identify commonly-missed questions in aggregate (anonymized/aggregated, not tied to your individual identity in reporting).
5. Who we share data with
- Supabase (database and authentication hosting).
- Paddle (billing, tax compliance, payment processing) — acts as Merchant of Record and has its own privacy obligations for payment data.
- Vercel (application hosting).
- Google: used as an optional authentication provider when you choose ‘Continue with Google.’
We do not sell your personal data to third parties.
6. Data storage and international transfers
Your data is stored on Supabase infrastructure (EU region, Europe/Frankfurt or similar). If any data is transferred outside the EU/EEA (e.g. via Paddle or Vercel's infrastructure), such transfers rely on appropriate safeguards as required under GDPR (e.g. Standard Contractual Clauses).
7. Your rights (GDPR)
If you are located in the EU/EEA (or another jurisdiction with similar protections), you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data (“right to be forgotten”) — available via account deletion in settings, or by contacting us.
- Restrict or object to certain processing.
- Data portability — receive your data in a portable format.
- Withdraw consent at any time for marketing/notification emails.
To exercise these rights, contact support@certonyx.com or use the relevant controls in your account settings.
8. Data retention
We retain your account and usage data for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required for legal or billing compliance (e.g. transaction records).
9. Cookies
CertOnyx uses essential cookies necessary for authentication and service functionality. This section will be expanded if any non-essential tracking or analytics cookies are introduced for EU visitors, along with the cookie consent banner that would require.
10. Children's privacy
CertOnyx is not directed at children under 16. We do not knowingly collect data from children under this age.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the platform.
12. Contact
Questions or requests regarding this Privacy Policy: support@certonyx.com
You also have the right to lodge a complaint with your local data protection authority (e.g. the CNIL in France) if you believe your data protection rights have been violated.