Privacy Policy

Your privacy is important to us. This privacy policy describes what personal data we collect, how we use it, and what rights you have regarding your data when you use the TI Naturalizzo service (tinaturalizzo.ch).

Last updated: February 2026

Data Controller

The data controller for your personal data is TI Naturalizzo, reachable at support@tinaturalizzo.ch. We are responsible for determining the purposes and means of processing your personal data in accordance with the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

Data Collected

We collect the following categories of personal data: • Account data: email address, name (if provided via social login), profile picture (if provided via social login). • Authentication data: login provider used (email, Google, Apple, or Microsoft), session tokens. • Quiz usage data: answers given, scores, attempts, timestamps, subject selected. • Payment data: payments are processed by Stripe. We never store your credit card details. We retain the Stripe transaction ID, amount, date, and payment status. • Technical data: IP address, browser type, operating system, pages visited, and access timestamps (collected automatically via Vercel Analytics).

Purpose of Processing

We use your personal data for the following purposes: • Service delivery: creating and managing your account, authenticating your logins, delivering quizzes and practice sessions, saving your progress, and displaying results. • Payment processing: handling credit purchases via Stripe and crediting your account. • Content generation: using AI providers (OpenAI, Google Vertex AI) to generate exam questions and personalized explanations. • Communications: sending transactional emails (login links, payment confirmations, welcome emails) via Resend. • Analytics: understanding how our service is used to improve it (via Vercel Analytics, which is cookie-free and privacy-respecting). • Legal obligations: fulfilling tax, accounting, and other legal requirements.

Legal Basis for Processing

The processing of your data is based on the following legal grounds: • Performance of a contract: processing is necessary to provide you with the requested service (account management, quizzes, credits). • Consent: when you log in via a social provider (Google, Apple, Microsoft), you consent to sharing your profile data with us. • Legitimate interests: we use anonymous analytics data to improve our service. • Legal obligations: we retain transaction data as required by Swiss law.

Cookies

We use only strictly necessary technical cookies for the operation of the service: • Session cookies: to maintain your authentication state while browsing. • Language preference cookies: to remember your preferred language. We do not use tracking cookies, advertising cookies, or third-party profiling cookies. Vercel Analytics, which we use for traffic analysis, does not use cookies.

Third-Party Services

To deliver our service, we rely on the following third-party providers: • Stripe (stripe.com): payment processing. Stripe processes your payment data under its own privacy policy. • Google, Apple, Microsoft: social authentication providers. When you choose to log in via these services, they share your name, email, and profile picture with us. • OpenAI (openai.com): AI-powered question and explanation generation. Quiz data may be sent as context to generate responses. • Google Vertex AI: alternative AI provider for content generation. • Resend (resend.com): transactional email delivery service (login links, payment confirmations). • Vercel (vercel.com): application hosting and privacy-respecting aggregate traffic analytics. • Neon (neon.tech): PostgreSQL database hosting where your account data is stored. Each third-party provider operates under its own privacy policy. We encourage you to review them for further details.

Data Transfers

Your personal data may be transferred to and processed outside of Switzerland and the European Economic Area (EEA), particularly in the United States, where some of our service providers are based (Stripe, OpenAI, Vercel, Resend, Neon). Such transfers are made on the basis of standard contractual clauses or other transfer mechanisms compliant with the nFADP and, where applicable, the GDPR, to ensure an adequate level of protection for your personal data.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy: • Account data: retained as long as your account is active. You may request account deletion at any time. • Quiz data: retained as long as your account is active, so you can review your results and progress. • Transaction data: retained for 10 years from the transaction date, as required by Swiss tax and accounting regulations. • Session cookies: expire when you close your browser or after a period of inactivity. Upon account deletion, your personal data will be erased or anonymized within 30 days, except for data we are legally required to retain.

Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration. These include: • Encryption of data in transit via HTTPS/TLS. • Secure authentication using cryptographic tokens (no passwords stored). • Restricted and protected database access. • Hosting services that comply with industry security standards. Despite our efforts, no method of electronic transmission or storage is 100% secure. In the event of a data breach that may affect your rights, we will notify you promptly as required by law.

Children

TI Naturalizzo is not intended for individuals under the age of 16. We do not knowingly collect personal data from minors. If you become aware that a minor has provided us with personal data, please contact us so we can promptly delete it.

Your Rights

Under the nFADP and, where applicable, the GDPR, you have the following rights: • Right of access: you may request a copy of the personal data we hold about you. • Right to rectification: you may request the correction of inaccurate or incomplete data. • Right to erasure: you may request the deletion of your personal data, subject to legal retention obligations. • Right to data portability: you may request your data in a structured, machine-readable format. • Right to object: you may object to the processing of your data in certain circumstances. • Right to lodge a complaint: you have the right to file a complaint with the Federal Data Protection and Information Commissioner (FDPIC) or another competent supervisory authority. To exercise your rights, contact us at support@tinaturalizzo.ch. We will respond to your request within 30 days.

Changes to This Policy

We reserve the right to update this privacy policy at any time. Changes will be posted on this page with the date of last update. In case of material changes, we may notify you via email or through a prominent notice on our website. Continued use of the service after changes are published constitutes acceptance of the updated policy.

Contact

For any questions or requests regarding this privacy policy or the processing of your personal data, you can contact us at: Email: support@tinaturalizzo.ch Website: tinaturalizzo.ch