PRINTEXAM PRIVACY POLICY
Version: [1.0] Effective date: 03 August 2026 Last updated: 03 August 2026
1. Who We Are
PrintExam is a service for creating, managing, storing, synchronizing, sharing, exporting and printing tests, examinations, exercises and other educational materials.
For the purposes of applicable data protection law, the data controller is:
Danilo Clemenzi Privacy contact: support@printexam.com General contact: support@printexam.com
In this Privacy Policy, the controller is referred to as “PrintExam,” “we,” “us” or “our.”
A Data Protection Officer has not been appointed unless otherwise stated in this Privacy Policy.
2. Scope of This Privacy Policy
This Privacy Policy explains how personal data is collected and processed when individuals:
- visit the PrintExam website;
- use the PrintExam application;
- create or manage an Account;
- create, store, synchronize or share examinations;
- subscribe to a paid plan;
- use PrintExam through a school or organization;
- contact customer support;
- interact with analytics, advertising or consent-management technologies.
This Privacy Policy applies to:
- individual users;
- teachers and education professionals;
- representatives and members of schools or organizations;
- website visitors;
- persons whose personal data may be included in User Content.
This Privacy Policy does not govern third-party websites or services that are independently operated by other organizations.
3. Our Role Under Data Protection Law
3.1 PrintExam as Data Controller
PrintExam generally acts as data controller when it determines the purposes and means of processing personal data, including for:
- Account administration;
- authentication configuration;
- subscription management;
- billing and accounting;
- customer support;
- website and infrastructure security;
- prevention of fraud and abuse;
- service communications;
- compliance with legal obligations;
- optional analytics and advertising activities.
3.2 PrintExam as Data Processor
Where a school, company or other organization uses PrintExam to process personal data under its own authority and determines why such data is processed, the organization will generally act as the data controller and PrintExam will act as its data processor.
This may apply, for example, where an organization stores:
- student names or identifiers;
- examination results;
- assessments;
- accommodations or accessibility information;
- internal educational materials;
- employee or teacher information.
In such circumstances, the organization is responsible for providing the appropriate privacy information to affected individuals and establishing a valid legal basis for processing.
Where required, the relationship between PrintExam and the organization must be governed by a separate Data Processing Agreement.
Even when acting as a processor for User Content, PrintExam may remain an independent controller for limited processing concerning Account management, billing, security, fraud prevention and compliance with legal obligations.
4. Personal Data We Collect
The personal data collected depends on how the Service is used and which features are enabled.
4.1 Account and Authentication Data
When an Account is created or accessed, we may process:
- name;
- email address;
- username;
- profile image;
- internal User identifier;
- organization membership;
- authentication provider;
- sign-in and sign-out timestamps;
- authentication events;
- multi-factor authentication status;
- recovery and security information;
- IP address;
- browser and device information.
Authentication and user-management functions are currently provided through Clerk.
Depending on the authentication method selected, additional information may be received from an external identity provider, such as Google, Microsoft or another supported provider.
PrintExam does not receive the User’s password in readable form.
4.2 Profile and Organization Data
We may process:
- display name;
- profile preferences;
- selected language;
- organization name;
- role within an organization;
- organization membership and permissions;
- subscription status;
- plan type;
- account settings.
4.3 User Content and Examination Data
When using PrintExam, Users may create, upload, store or share:
- examination titles;
- questions and answers;
- exercises;
- answer options;
- grading criteria;
- scores and point values;
- text and rich-text content;
- formulas and mathematical expressions;
- images and attachments;
- templates;
- folder and file names;
- document metadata;
- sharing settings;
- identifiers of collaborators or recipients;
- revision and synchronization information.
User Content may contain personal data concerning students, teachers, colleagues or other individuals.
Users should avoid including personal data unless it is genuinely necessary for the intended educational purpose.
PrintExam is not intended for the routine storage of special-category data, health information, biometric data, criminal-offence data or other highly sensitive information.
4.4 Local Browser Data
Some PrintExam features may save data locally within the User’s browser or device.
This may include:
- locally stored examinations;
- editor state;
- interface preferences;
- draft content;
- temporary files;
- technical identifiers;
- authentication session information;
- consent preferences.
Data stored exclusively in the browser may not be transmitted to PrintExam unless the User enables Cloud Services, synchronization, sharing or another online feature.
4.5 Technical, Network and Security Data
When the Service is accessed, we may automatically process:
- IP address;
- date and time of requests;
- requested pages or resources;
- HTTP headers;
- browser type and version;
- operating system;
- device type;
- referring page;
- approximate geographic area derived from the IP address;
- network and connection information;
- error logs;
- crash information;
- authentication and security events;
- indicators of automated, malicious or abusive traffic.
Cloudflare is used for network delivery, content distribution, security, DNS and protection against abusive or malicious traffic.
4.6 Usage and Product Data
Where operational measurements or optional analytics are enabled, we may process:
- features accessed;
- buttons or interface elements used;
- page views;
- session duration;
- navigation paths;
- creation, export or synchronization events;
- general performance measurements;
- error and diagnostic events;
- pseudonymous identifiers;
- browser and device characteristics.
We will not intentionally send the contents of examinations, questions, answers or other sensitive User Content to analytics providers unless this is strictly necessary, transparently disclosed and appropriately protected.
4.7 Payment and Subscription Data
When a paid plan is purchased, we may process:
- billing name;
- billing address;
- country;
- tax identification or VAT information;
- email address;
- purchased plan;
- subscription status;
- billing period;
- amount paid;
- currency;
- payment status;
- transaction identifier;
- invoice and receipt information;
- cancellation and refund information;
- limited information about the payment method.
Payments are processed through Stripe.
Where the payment provider hosts the payment form, PrintExam does not directly receive or store the complete payment card number, card security code or equivalent payment credentials.
The payment provider may independently process personal data in accordance with its own privacy notice and applicable contractual arrangements.
4.8 Support and Communications Data
When a User contacts us, we may process:
- name;
- email address;
- Account identifier;
- message content;
- attachments;
- technical details supplied with the request;
- correspondence history;
- support actions;
- information necessary to investigate a problem.
Users should not send passwords, complete payment credentials, unnecessary student information or other sensitive information through support communications.
4.9 Consent and Preference Data
Where consent is requested, we may retain:
- the consent choice;
- the purposes accepted or rejected;
- the date and time of the choice;
- the version of the notice shown;
- the consent-management identifier;
- subsequent changes or withdrawal of consent.
5. How We Obtain Personal Data
We obtain personal data:
- directly from the User;
- automatically from the User’s browser or device;
- from authentication providers;
- from the school or organization managing the User’s Account;
- from collaborators who share content with the User;
- from payment providers;
- from infrastructure and security providers;
- from support and communication providers;
- from analytics or advertising providers, where enabled and lawfully permitted.
6. Purposes and Legal Bases
We process personal data only where there is an appropriate legal basis.
6.1 Providing the Account and Service
Purposes:
- creating and maintaining Accounts;
- authenticating Users;
- providing the editor;
- storing and synchronizing examinations;
- enabling sharing and collaboration;
- exporting and printing materials;
- providing Free and Premium Plans;
- maintaining User preferences.
Legal basis:
- performance of a contract;
- taking steps requested before entering into a contract.
6.2 Managing Subscriptions and Payments
Purposes:
- processing purchases;
- managing subscriptions and renewals;
- issuing invoices or receipts;
- handling cancellations and refunds;
- detecting failed or fraudulent payments;
- maintaining accounting records.
Legal basis:
- performance of a contract;
- compliance with legal obligations;
- legitimate interests in preventing fraud and defending legal claims.
6.3 Customer Support
Purposes:
- answering questions;
- resolving technical problems;
- investigating reported errors;
- responding to complaints;
- communicating about an Account or subscription.
Legal basis:
- performance of a contract;
- legitimate interests in operating and improving customer support.
6.4 Security and Abuse Prevention
Purposes:
- securing Accounts and infrastructure;
- detecting unauthorized access;
- preventing spam, fraud and misuse;
- rate limiting;
- protecting the availability of the Service;
- investigating security incidents;
- enforcing the Terms and Conditions.
Legal basis:
- legitimate interests in protecting the Service, Users and third parties;
- compliance with legal obligations;
- establishment, exercise or defence of legal claims.
6.5 Service Operation and Improvement
Purposes:
- identifying technical failures;
- measuring reliability and performance;
- understanding general feature usage;
- improving accessibility and usability;
- planning capacity and infrastructure;
- developing new features.
Legal basis:
- legitimate interests, where processing is necessary, proportionate and does not require access to non-essential tracking technologies;
- consent, where non-essential analytics cookies, local storage or equivalent tracking technologies are used.
6.6 Service Communications
Purposes:
- sending security alerts;
- sending authentication messages;
- notifying Users of material contractual or privacy changes;
- communicating subscription and payment information;
- providing operational notices;
- notifying Users about changes affecting stored data.
Legal basis:
- performance of a contract;
- compliance with legal obligations;
- legitimate interests in administering the Service.
Users cannot opt out of communications that are strictly necessary to operate an Account or fulfil legal obligations.
6.7 Marketing Communications
Where enabled, we may send product announcements, offers or newsletters only where an appropriate legal basis exists.
Legal basis:
- consent, where required;
- legitimate interests only where applicable law permits such processing and the User can reasonably expect it.
Marketing consent may be withdrawn at any time.
6.8 Advertising
Where advertising is enabled, personal data may be processed to:
- display advertisements;
- limit how often an advertisement is shown;
- measure advertisement delivery and performance;
- prevent advertising fraud;
- display personalized advertising, only where specifically permitted and consented to.
Legal basis:
- consent for non-essential advertising cookies, identifiers, personalization and measurement;
- legitimate interests may apply only to limited advertising operations that do not require consent under applicable law.
Advertising technologies will not be activated before any legally required consent has been obtained.
6.9 Legal Compliance and Claims
Purposes:
- responding to lawful requests from authorities;
- complying with tax, accounting and consumer-protection obligations;
- handling data-protection requests;
- investigating unlawful activity;
- establishing, exercising or defending legal claims.
Legal basis:
- compliance with legal obligations;
- legitimate interests in protecting legal rights;
- performance of tasks required by applicable law.
7. Whether Providing Data Is Mandatory
Certain information is necessary to create an Account, provide Cloud Services, complete a purchase or respond to a request.
Failure to provide required information may prevent us from:
- creating the Account;
- authenticating the User;
- storing or synchronizing content;
- processing a payment;
- providing a paid plan;
- responding to a support request;
- complying with legal obligations.
Data used exclusively for optional analytics, marketing or personalized advertising is not required to use the core Service.
8. Cookies and Similar Technologies
PrintExam may use cookies, local storage and similar technologies.
8.1 Strictly Necessary Technologies
Strictly necessary technologies may be used for:
- authentication;
- maintaining a User session;
- Account security;
- fraud and abuse prevention;
- load balancing;
- network delivery;
- saving privacy choices;
- providing features explicitly requested by the User.
Where these technologies are strictly necessary to provide the requested Service, they may be used without consent, as permitted by applicable law.
They will nevertheless be described in the relevant cookie information.
8.2 Analytics Technologies
Non-essential analytics technologies will be used only after obtaining consent where required.
Analytics consent may be refused or withdrawn without preventing access to the essential functions of PrintExam.
8.3 Advertising Technologies
Advertising cookies and similar identifiers may be used only where advertising has been enabled and any legally required consent has been obtained.
Users must be able to:
- accept or reject non-essential technologies;
- make choices by purpose;
- withdraw consent as easily as it was provided;
- access the Service without being forced to accept unnecessary tracking, except where lawfully justified.
A separate Cookie Policy or cookie-management interface should provide updated information about the specific technologies in use, their duration, providers and purposes.
9. Analytics Services
9.1 Current Operational Analytics
Cloudflare may provide limited traffic, performance and security information as part of the delivery and protection of the Service.
Such data is used primarily to operate, secure and maintain PrintExam.
9.2 Future Use of PostHog
This section applies only after PostHog has been enabled.
PrintExam may use PostHog to understand product usage, diagnose problems and improve the Service.
Depending on the final configuration, PostHog may process:
- pseudonymous User identifiers;
- page views;
- feature interactions;
- browser and device information;
- timestamps;
- session information;
- error events;
- approximate location derived from network information.
Before PostHog is enabled, PrintExam must:
- select the appropriate hosting region;
- enter into an applicable Data Processing Agreement;
- configure data minimization;
- prevent unnecessary capture of examination content;
- disable sensitive-field capture;
- define an appropriate retention period;
- implement consent controls where required.
PostHog must not be described as an active provider until it is actually integrated.
10. Advertising Services
10.1 Future Use of Google Advertising Services
This section applies only after Google advertising services have been enabled.
PrintExam may use Google advertising services to display or measure advertisements within the Free Plan.
Depending on the final implementation and User choices, Google may process:
- cookie or device identifiers;
- IP address;
- browser and device information;
- advertisement impressions;
- advertisement interactions;
- approximate location;
- consent signals;
- information used to prevent fraud;
- information used for advertising measurement or personalization.
Before Google advertising services are enabled, PrintExam must:
- implement a compliant consent-management platform where required;
- prevent advertising tags from operating before consent where required;
- identify relevant advertising partners;
- provide a method to withdraw consent;
- record the User’s consent choices;
- determine whether advertisements will be contextual or personalized;
- implement protections appropriate for minors.
PrintExam will not knowingly use personal data of minors for personalized advertising.
Google advertising services must not be described as active until they are actually integrated.
11. Service Providers and Recipients
We may disclose personal data to service providers only where necessary for the purposes described in this Privacy Policy.
Current or expected categories of recipients include:
| Provider or category | Purpose | Status | | --------------------------- | ------------------------------------------------------------- | ------------------------------ | | Clerk | Authentication and user management | Active | | Neon | Database infrastructure and Cloud storage | Active | | Cloudflare | DNS, network delivery, security and infrastructure protection | Active | | Stripe | Payments, subscriptions and billing | Active | | Proton Mail | Transactional and service emails | Active | | PostHog | Product analytics | Future; inactive until enabled | | Google advertising services | Advertising and advertising measurement | Future; inactive until enabled | | Professional advisers | Legal, tax and accounting assistance | As necessary | | Public authorities | Compliance with lawful obligations | Where legally required |
Service providers acting as processors may process personal data only under contractual instructions and for the agreed purposes.
Some providers may also process limited information as independent controllers, for example for billing, legal compliance, fraud prevention or their direct contractual relationship with the User. Their own privacy notices will apply to those independent activities.
We may also disclose personal data:
- where required by law or a valid legal order;
- to protect the rights, safety or security of Users, PrintExam or third parties;
- in connection with a merger, acquisition, reorganization or transfer of the Service;
- with the User’s instructions or consent.
We do not sell User-created examination content.
12. International Data Transfers
Some service providers or their subprocessors may process personal data outside Italy or the European Economic Area.
Where personal data is transferred to a country that has not been recognized as providing an adequate level of protection, we will use an appropriate transfer mechanism, such as:
- European Commission Standard Contractual Clauses;
- an applicable adequacy decision;
- the EU–US Data Privacy Framework, where valid and applicable;
- supplementary technical, contractual or organizational safeguards.
The availability and legal status of a transfer mechanism may change. We will periodically review the safeguards used by our providers.
Users may contact us to request additional information about the safeguards applicable to relevant international transfers.
13. Data Retention
Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected, including legal, accounting, security and dispute-resolution requirements.
The following retention periods must be verified against the actual technical configuration before publication:
| Data category | Intended retention period | | -------------------------------- | -------------------------------------------------------------------------------------- | | Account and profile data | For the duration of the Account and up to [30 DAYS] following deletion | | Cloud examination content | Until deleted by the User or the Account is terminated | | Deleted Cloud content | Removed from active systems within [30 DAYS] | | Backup copies | Automatically overwritten or deleted within [90 DAYS] | | Authentication and security logs | [12 MONTHS], unless a longer period is required to investigate an incident | | Support requests | [24 MONTHS] after closure of the request | | Payment and transaction records | For the period required by applicable tax and accounting law | | Contract and consent records | For the period necessary to demonstrate compliance and manage legal claims | | Non-essential analytics data | [12 MONTHS] or the shorter period configured with the analytics provider | | Advertising data | According to the consent choices and retention settings disclosed in the Cookie Policy |
Data may be retained for a longer period where:
- required by law;
- necessary for an ongoing dispute or investigation;
- necessary to prevent fraud or abuse;
- necessary to establish, exercise or defend legal claims.
Where data cannot immediately be removed from backups, it will remain protected and will not be restored for ordinary operational use.
14. Schools, Organizations and Student Data
Organizations using PrintExam are responsible for determining whether personal data may lawfully be entered into the Service.
Schools and organizations should:
- minimize the use of identifiable student data;
- use internal identifiers where possible;
- avoid including unnecessary information in examination documents;
- define access permissions;
- establish retention periods;
- inform students, parents, employees or other affected individuals;
- ensure that only authorized personnel access stored examinations;
- enter into a Data Processing Agreement with PrintExam where required.
PrintExam should not be used to store special-category student data unless:
- such processing is strictly necessary;
- the organization has identified a valid legal basis;
- appropriate safeguards have been implemented;
- the arrangement has been separately reviewed.
Requests relating to personal data controlled by a school or organization should generally be directed to that organization.
Where we receive such a request directly, we may forward it to the relevant organization or assist it in responding.
15. Children and Minors
PrintExam is primarily intended for teachers, education professionals and persons capable of entering into the relevant contractual relationship.
Children under the applicable age for independent digital consent must not create an Account or provide consent-based personal data without the authorization required under applicable law.
For Users located in Italy, the age threshold for independently consenting to consent-based information-society services is generally fourteen years.
This privacy threshold does not necessarily mean that a minor has the legal capacity to purchase a subscription or enter into a binding paid contract.
Paid plans must be purchased by a person having the required legal capacity.
Where PrintExam learns that personal data has been collected from a child in breach of applicable requirements, we may:
- restrict or close the Account;
- request verification of authorization;
- delete the relevant personal data;
- contact the parent, guardian or responsible organization where appropriate.
Parents, guardians or organizations may contact us at support@printexam.com regarding data associated with a minor.
16. Automated Decision-Making and Artificial Intelligence
PrintExam does not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning Users or students.
Where automated or artificial intelligence features are introduced, their outputs must be reviewed by a human before being used for grading, educational assessment or other significant decisions.
PrintExam will not use User Content to train a general-purpose artificial intelligence model unless:
- the practice is separately and clearly disclosed;
- an appropriate legal basis has been identified;
- any necessary consent has been obtained;
- Users have been provided with appropriate controls.
17. Security
We use technical and organizational measures intended to protect personal data against:
- unauthorized access;
- accidental or unlawful destruction;
- loss;
- alteration;
- disclosure;
- misuse.
Measures may include:
- encrypted communications;
- access controls;
- authenticated sessions;
- separation of environments;
- logging and monitoring;
- database access restrictions;
- infrastructure security protections;
- backups;
- dependency and vulnerability management;
- incident-response procedures.
No online service can guarantee absolute security.
Users are responsible for:
- protecting their login credentials;
- using secure devices;
- keeping their browser and operating system updated;
- reviewing sharing permissions;
- maintaining independent copies of important materials;
- promptly reporting suspected Account compromise.
Security concerns may be reported to support@printexam.com.
18. Personal Data Breaches
Where a personal data breach occurs, we will investigate the incident and take reasonable steps to contain and remediate it.
Where legally required, we will notify:
- the competent data protection authority;
- affected individuals;
- relevant schools or organizations acting as controllers.
Notifications will be made within the periods and under the conditions required by applicable law.
19. Data Protection Rights
Subject to the conditions and limitations established by applicable law, individuals may have the right to:
- obtain confirmation that their personal data is being processed;
- access their personal data;
- correct inaccurate or incomplete data;
- request deletion of personal data;
- restrict processing;
- object to processing based on legitimate interests;
- receive certain personal data in a structured, commonly used and machine-readable format;
- transmit portable data to another controller where technically feasible;
- withdraw consent at any time;
- object to direct marketing;
- obtain information about international-transfer safeguards;
- lodge a complaint with a supervisory authority;
- receive information about qualifying automated decision-making.
Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.
The right to deletion is not absolute. Certain information may be retained where necessary to:
- comply with legal obligations;
- exercise freedom of expression or information;
- establish, exercise or defend legal claims;
- prevent fraud or maintain security;
- comply with another lawful retention requirement.
20. Exercising Your Rights
Requests may be submitted to:
support@printexam.com
The request should include sufficient information to identify the relevant Account or processing activity.
We may request reasonable information to verify identity and prevent unauthorized access to personal data.
We will respond within the period required by applicable law. That period may be extended where permitted due to the complexity or number of requests.
Requests are normally handled without charge. A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive, as permitted by law.
Where PrintExam acts only as a processor for a school or organization, the request may need to be handled by that organization as controller.
21. Objection to Legitimate-Interest Processing
Where processing is based on legitimate interests, the User may object on grounds relating to their particular situation.
We will stop the relevant processing unless:
- there are compelling legitimate grounds overriding the User’s interests, rights and freedoms; or
- processing is necessary for the establishment, exercise or defence of legal claims.
Objections to direct marketing will be respected without requiring the User to provide particular reasons.
22. Withdrawing Consent
Consent for optional analytics, advertising or marketing may be withdrawn through:
- the cookie-management interface;
- the Account settings;
- the unsubscribe function in marketing communications;
- a request sent to support@printexam.com
Withdrawal must be as easy as giving consent and will not affect essential functions that do not depend on that consent.
23. Complaints
Individuals have the right to lodge a complaint with the competent supervisory authority.
For a controller established in Italy, the relevant authority is generally the:
Garante per la protezione dei dati personali
Individuals may also contact the supervisory authority of the European Union Member State in which they habitually reside, work or believe an infringement occurred.
We encourage Users to contact us first so that the matter may be investigated and, where appropriate, resolved.
24. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- changes to the Service;
- new providers or subprocessors;
- new analytics or advertising technologies;
- changes to legal requirements;
- changes to processing purposes;
- security or organizational developments.
The updated version will include a new “Last updated” date.
Where changes are material, we will provide an appropriate notice through the Service, by email or through another durable medium where required.
Where a new processing activity requires consent, it will not begin on the basis of an earlier unrelated consent.