Privacy Policy

Last updated: January 11, 2026Effective date: January 11, 2026

Privacy at a Glance

  • We collect only what's needed to provide the learning service (email, name, learning progress).
  • We never sell your data or share it with advertisers.
  • Your data stays in the EU (Frankfurt/Ireland data centers).
  • You control your data - access, export, or delete it anytime.
  • Payments are secure - handled by Stripe; we never see your card details.

1. Introduction

Einbürgerung Easy ("we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our German citizenship test preparation platform.

We comply with the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) and the German Federal Data Protection Act (BDSG). Your privacy rights are important to us, and we are committed to transparent data practices.

This policy applies when you:

  • Visit our website at einburgerung-easy.com
  • Create an account and use our learning platform
  • Subscribe to our premium service
  • Contact us via email or other channels

2. Data Controller

The data controller responsible for your personal data is:

Azinge Digital
Gutenstetten, Bavaria, Germany

Email: einburgerungeasy@gmail.com

As a small business, we are not required to appoint a Data Protection Officer (DPO) under GDPR Article 37. However, you can contact us directly for any privacy-related inquiries at the email address above.

3. Data We Collect

a) Account Data (provided by you)

  • Email address - for account identification and communication
  • Name - for personalization
  • Password - securely hashed using bcrypt; we never store plain text passwords
  • Selected Bundesland - for state-specific practice questions
  • Preferred language - for displaying translations (English, French, Turkish, or Arabic)

b) Learning Data (generated through your use)

  • Question responses and timestamps
  • Progress and mastery levels per question
  • Practice exam results and scores
  • XP points and achievements
  • Daily streak data
  • Spaced repetition scheduling data

c) Technical Data (collected automatically)

  • IP address
  • Browser type and version
  • Device type and operating system
  • Pages visited and features used
  • Usage analytics via Vercel Analytics

d) Payment Data (if you subscribe to premium)

Payments are processed securely by Stripe. We store only:

  • Subscription status (active/inactive)
  • Plan type and billing period
  • Stripe customer ID

We do NOT store your credit card number, CVV, or full payment details. This information is handled entirely by Stripe under their Privacy Policy.

5. How We Use Your Data

We use your personal data to:

  • Provide the learning service - display questions, track your progress, calculate mastery
  • Personalize your experience - show content in your preferred language and for your selected state
  • Implement spaced repetition - schedule question reviews based on your learning patterns
  • Process payments - manage subscriptions and billing through Stripe
  • Send service emails - account verification, password resets, subscription updates
  • Improve our platform - analyze usage patterns to enhance features
  • Ensure security - detect and prevent fraud, abuse, and unauthorized access
  • Provide support - respond to your questions and requests

6. Data Sharing

We share your data only with trusted service providers necessary to operate our platform:

Stripe (Payment Processing)

Stripe processes all payments and stores payment method details. They are PCI-DSS Level 1 certified.
Stripe Privacy Policy

Vercel (Hosting & Analytics)

Our website is hosted on Vercel. They provide hosting infrastructure and optional analytics.
Vercel Privacy Policy

MongoDB Atlas (Database)

Your data is stored in MongoDB Atlas, hosted in the EU region (Frankfurt/Ireland).
MongoDB Privacy Policy

We do NOT sell your personal data.
We do NOT share your data with advertisers.
We do NOT use your data for third-party marketing.

7. International Transfers

We prioritize keeping your data within the European Union. Your primary data is stored in:

  • MongoDB Atlas - EU region (Frankfurt, Germany or Dublin, Ireland)

Some of our service providers (Stripe, Vercel) are US-based companies. They comply with GDPR through:

  • EU-US Data Privacy Framework certification
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs)

These safeguards ensure your data receives equivalent protection when processed outside the EU.

8. Data Retention

We retain your data only as long as necessary:

Data TypeRetention Period
Account dataUntil account deletion + 30 days (recovery period)
Learning dataUntil account deletion
Payment records10 years (German tax law requirement)
Analytics data26 months (anonymized/aggregated)
Support correspondence3 years after resolution

After retention periods expire, data is securely deleted or anonymized so it can no longer identify you.

9. Your Rights

Under GDPR (Articles 15-22), you have the following rights:

Right of Access (Article 15)

Request a copy of your personal data and information about how we process it.

Right to Rectification (Article 16)

Request correction of inaccurate personal data or completion of incomplete data.

Right to Erasure (Article 17)

Request deletion of your personal data ("right to be forgotten") when it's no longer necessary or you withdraw consent.

Right to Restriction (Article 18)

Request that we limit how we process your data in certain circumstances.

Right to Data Portability (Article 20)

Receive your data in a structured, machine-readable format and transfer it to another service.

Right to Object (Article 21)

Object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent (Article 7)

Withdraw consent at any time for processing based on consent (e.g., marketing emails).

How to Exercise Your Rights

  • Email us: einburgerungeasy@gmail.com
  • Use in-app settings: Delete account, export data, update preferences
  • Response time: We will respond within 30 days
  • Verification: We may need to verify your identity before processing requests

10. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit: All data transmitted via HTTPS/TLS
  • Encryption at rest: Database encryption for stored data
  • Password security: Passwords hashed using bcrypt with salt
  • Access controls: Strict access limitations to personal data
  • Regular updates: Security patches and dependency updates
  • Secure infrastructure: Hosted on Vercel and MongoDB Atlas with enterprise-grade security

While we take security seriously, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please contact us immediately.

11. Cookies

We use cookies and similar technologies on our platform:

Essential Cookies

Required for the platform to function. Cannot be disabled.

  • Session cookies - maintain your login state
  • Authentication tokens - secure your account access
  • CSRF protection - prevent cross-site request forgery

Analytics Cookies

Help us understand how you use the platform. Can be disabled.

  • Vercel Analytics - privacy-focused, no personal data collected

No Advertising Cookies

We do not use any advertising or tracking cookies from third parties.

You can manage cookie preferences through our cookie consent banner or your browser settings.

12. Children's Privacy

Our service is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16.

The age of 16 aligns with German data protection law regarding the age at which minors can consent to data processing.

If you believe a child under 16 has provided us with personal data, please contact us immediately at einburgerungeasy@gmail.com. We will promptly delete such information.

13. Changes to Policy

We may update this Privacy Policy from time to time. When we make changes:

  • Material changes: We will notify you via email at least 30 days before they take effect
  • Minor changes: We will update the "Last updated" date at the top
  • Previous versions: Available upon request

We encourage you to review this policy periodically. Continued use of the service after changes constitutes acceptance of the updated policy.

14. Complaints

If you have concerns about how we handle your personal data, please contact us first. We will do our best to resolve any issues.

You also have the right to lodge a complaint with a supervisory authority. For Bavaria, Germany, this is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach, Germany

Website: www.lda.bayern.de
Email: poststelle@lda.bayern.de

15. Contact

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Azinge Digital
Gutenstetten, Bavaria, Germany

Email: einburgerungeasy@gmail.com

Privacy inquiries are typically answered within 5 business days.