Privacy Policy

Last updated: July 8, 2025  ·  Version 1.0

🇦🇷 Law 25.326 Argentina 🇪🇺 GDPR Europe 🇺🇸 CCPA California 🌎 LATAM

This Privacy Policy ("Policy") describes how Federico Osella, operator of TestVocacional.app (the "Controller"), collects, uses, stores and protects the personal data of users ("User") when accessing or using the TestVocacional.app web and mobile platform (the "Platform").

This Policy is an integral part of the Terms and Conditions. By using the Platform, the User accepts the practices described herein. If you disagree, you must stop using the Platform.

✅ What we DO

  • Store your email, name and avatar to identify your account
  • Store your test answers to generate your results
  • Record timestamps of your legal consents
  • Infer your country from your device locale
  • Use analytics cookies to improve the experience

❌ What we DON'T do

  • We do not sell your personal data to anyone
  • We do not store card or payment data (Apple/Google do)
  • We do not commercially profile your test answers
  • We do not make automated decisions with legal effects on you
  • We do not intentionally collect data from under-14s

1 Data Controller

Field Details
Controller Federico Osella
Platform TestVocacional.app
Address José A. Nanini 3154, Colonia Caroya, Córdoba, Argentina
Privacy email [email protected]
General response time Up to 30 business days
Urgent privacy requests Up to 15 business days

2 What data we collect

2.1 Data the User provides directly at registration

When creating an account in the app (LegalGate registration screen), the system collects:

Data Type Required How it is collected
Name Free text ✅ Yes Entered by the User
Email Email address ✅ Yes Entered by the User. Write-once: cannot be changed once saved.
Avatar Image identifier ✅ Yes Selected from predefined gallery
Main vocational goal Category code (e.g. GM-EC, GM-PT) ✅ Yes Selected from predefined options
Age confirmation (+16) Boolean (checkbox) ✅ Yes User self-declaration
Push notification preference Code "1" (yes) / "0" (no) ❌ No User selection. Default: NO (opt-out).

2.2 Automatically inferred data — not requested from the User

Data How obtained Purpose
Country Inferred from device locale (e.g. AR, ES, MX). No GPS geolocation is used or requested from the User. Adapt regional content and comply with local regulations
Academic level Retained if the User indicated it in prior interactions. Not requested at initial registration. Personalisation of recommendations

2.3 Usage and device data

Data Description
IP address Recorded on server connections for security and aggregate analysis
Device type and OS iOS or Android, OS version
App version For technical support and compatibility
Web browsing data Through analytics cookies (see Section 9)
Activity timestamps Date and time of relevant actions: registration, consents, purchases

2.4 Third-party sign-in (Google / Facebook)

If the User registers or signs in via Google or Facebook, we receive only the basic data those platforms share according to the User's privacy settings (typically: name, email and profile picture). We do not receive passwords or additional data beyond what the User has authorised on that platform.

2.5 Vocational test answers

The answers the User provides when completing tests are stored linked to their account in order to: (a) generate personalised result reports, (b) allow the User to consult their test history, and (c) improve algorithms in an exclusively aggregated and anonymised form. See Section 6 for the special safeguards that apply to this data.

3 How and why we use your data

Purpose Data used Legal basis
Create and manage the User's account Name, email, avatar, goal Contract performance
Generate test results and reports Test answers, vocational goal Contract performance / Consent
Personalise experience and content Goal, country, academic level, history Legitimate interest / Consent
Manage Premium subscriptions Email, subscription status (via Apple/Google) Contract performance
Send push notifications Device notification token Explicit consent (opt-in)
Send service communications Email Legitimate interest / Contractual obligation
Comply with legal obligations Registration data, consent timestamps Legal obligation
Security, fraud and abuse prevention IP, session data, email Legitimate interest
Improve the Platform (aggregate analysis) Anonymised usage and result data Legitimate interest
Respond to support requests Email, account data Contract performance

4 Legal basis for processing

Personal data processing is carried out on the following legal bases in accordance with GDPR (Art. 6) and equivalent regulations in each jurisdiction:

Legal basis When it applies
Contract performance (Art. 6.1.b GDPR) Processing necessary to provide the contracted services: account, tests, results, subscription.
Consent (Art. 6.1.a GDPR) Push notifications, processing of answers as personality data, optional direct marketing.
Legitimate interest (Art. 6.1.f GDPR) Platform security, fraud prevention, aggregate analysis for service improvement, service communications.
Legal obligation (Art. 6.1.c GDPR) Retention of consent records, compliance with requests from competent authorities.

For Users in Argentina, equivalent bases are found in Law 25.326 and the regulatory resolutions of the AAIP.

5 Payment data — what we do NOT collect

🔒 TestVocacional.app does NOT store any payment data

All Premium subscription payments are processed entirely by Apple (App Store) or Google (Google Play), depending on the User's device. The Controller never receives, stores or processes credit card, debit card, bank account or any other payment instrument data.

The only thing we receive from the stores is a confirmation that the subscription is active or inactive, with no financial data of any kind. For any billing or refund enquiries, please contact directly:

6 Test answers — special treatment

Answers to vocational tests may reveal aspects of the User's personality, cognitive preferences and interests. Although they are not health data, in some jurisdictions (especially under GDPR) they may be considered special category data in certain contexts. The Controller applies the following additional safeguards:

Specific commitments regarding test answers

  • Strict confidentiality: individual answers are not accessible to any third party without the User's explicit consent.
  • No sale or commercialisation: we do not sell, rent or transfer individual test answers to any third party, under any circumstances.
  • No commercial profiling: we do not use answers to build commercial profiles or for personality-based targeted advertising.
  • No harmful automated decisions: results are not used to make decisions with legal effects on the User (e.g. recruitment, credit, insurance).
  • Aggregated and anonymised use: we may use answer data in a fully anonymised form to improve algorithms. The individual User cannot be identified in any case.
  • Right to deletion: the User may request deletion of their answers and results at any time (see Section 13).

7 Consent records

When completing the registration form (LegalGate screen in the app), the system automatically records the User's consent as follows:

Consent How it is recorded What is stored in the database
Acceptance of Terms and Conditions Mandatory checkbox at registration Unix timestamp (seconds) in the terms_accepted field
Acceptance of Privacy Policy Mandatory checkbox at registration Unix timestamp (seconds) in the privacy_policy_accepted field
Age confirmation (+16) Mandatory checkbox at registration Timestamp and boolean in the User's account
Push notifications Voluntary selection (default: NO) Code 1 (yes) or 0 (no) in the notifications_accepted field

These records constitute evidence of informed consent and are retained for as long as the account is active and during the legally required period after its deletion.

⚠️ Right to withdraw consent

The User may withdraw their consent at any time without affecting the lawfulness of processing carried out before the withdrawal. Withdrawing certain consents may mean that some features become unavailable. To withdraw consent: [email protected].

8 Minors

Age Applicable treatment
Under 14 We do not intentionally collect data from children under 14. If we detect that an account belongs to an under-14, we delete the account and all associated data immediately.
14 to 15 Only with verifiable parental consent. The responsible adult accepts this Policy on behalf of the minor and holds the minor's privacy rights against us.
16 to 17 Permitted with age self-declaration (checkbox at registration). In jurisdictions where GDPR requires parental consent for under-16s, the User declares under their responsibility that they meet the required age or hold their guardian's consent.

If a parent or legal guardian believes their child under 14 has created an account on TestVocacional.app, they can contact us at [email protected] to request immediate deletion of the account and all associated data.

9 Cookies and tracking technologies

9.1 Types of cookies we use

Type Purpose Required? Third parties
Essential / Technical Basic platform operation, session management ✅ Yes None
Analytics Usage analysis, pages visited, aggregate behaviour ❌ Opt-in Google Analytics
Preference Language, visual theme, User settings ❌ Opt-in None
Marketing Relevant ads on the free plan ❌ Opt-in Google, Meta (Facebook)

9.2 Google Analytics

We use Google Analytics to understand how Users use the web Platform. Data is anonymised and aggregated. To opt out: Google Analytics Opt-out Browser Add-on. More information: Google Privacy Policy.

9.3 Cookie management and GPC signal

The User can manage cookies from their browser or device settings. For more information: allaboutcookies.org · Full Cookies Policy.

The Platform recognises and respects the Global Privacy Control (GPC) signal where it can technically be verified. We do not currently respond to standard DNT signals due to lack of uniform implementation. To enable GPC: globalprivacycontrol.org.

10 Who we share data with

🚫 We do not sell personal data

TestVocacional.app does not sell, rent or trade personal data of its Users to any third party, under any circumstances.

We share data only in the following limited circumstances:

Recipient What data Why Safeguards
Apple / Google User identifier (to validate subscription) In-App purchase management Their own privacy policies
Google Analytics Anonymised usage data Platform analysis Data processing agreement with Google
Hosting / backend provider Account data and answers (encrypted) Necessary technical infrastructure Data processing agreement
Competent authorities As required by law Legal obligations or court orders Minimum indispensable data only
New owners (merger/acquisition) Account data Business transfer Prior notice to User; same privacy conditions

11 International data transfers

Since TestVocacional.app operates globally, User data may be transferred, stored and processed in countries other than the User's country of residence, including Argentina, the United States and other countries where our infrastructure providers operate.

For Users in the European Union / EEA GDPR

Transfers outside the EEA are carried out via: (a) Standard Contractual Clauses (SCCs) of the European Commission with providers in third countries, (b) Adequacy decisions where applicable, or (c) Explicit User consent.

For Users in Argentina Law 25.326

Argentina is recognised by the European Commission as a country with an adequate level of data protection. Transfers from Argentina abroad are carried out in accordance with Law 25.326 and the resolutions of the AAIP.

12 Data retention

Data type Retention period Reason
Account data (name, email, avatar) While account is active + 2 years Service provision and claims period
Test answers and results While account is active + 1 year User history
Consent timestamps 5 years from consent date Legal obligation to demonstrate consent
Subscription records 5 years from last transaction Tax and accounting obligations
Security logs 12 months Security and incident investigation
Inactive accounts (no active subscription) 12 months inactivity → automatic deletion Data minimisation
Data after account deletion 30 days in backup → permanent deletion Recovery from accidental errors

After the above periods, data is securely deleted or irreversibly anonymised.

13 Your privacy rights

Right Description Jurisdiction
Access Obtain a copy of all your personal data we hold All
Rectification Correct inaccurate or incomplete data All
Erasure Request deletion of your data, subject to legal exceptions All
Portability Receive your data in a structured format to transfer to another service GDPR
Objection Object to processing based on legitimate interest GDPR · AR
Restriction of processing Request that we restrict processing in certain circumstances GDPR
Withdrawal of consent Withdraw any prior consent without affecting prior processing All
Non-discrimination Not be discriminated against for exercising your privacy rights CCPA
Opt-out of data sale Object to the sale of data (note: we do not sell data) CCPA

How to exercise your rights

Send an email to [email protected] stating: your full name and email registered in the app, the right you wish to exercise and, if applicable, which specific data it concerns. We respond within a maximum of 30 business days (15 days for urgent requests). We may request identity verification before processing.

Right to lodge a complaint with supervisory authorities

14 Data security

We implement reasonable technical and organisational measures to protect Users' personal data:

  • Encryption in transit: all communications between the app and our servers use HTTPS/TLS.
  • Encryption at rest: sensitive data stored in the database is encrypted.
  • Access control: only the minimum necessary technical personnel have access to User data.
  • Backups: periodic encrypted backups to prevent data loss.
  • Security monitoring: active monitoring of access and unusual activity.

⚠️ Important note on security

No system is 100% secure. In the event of a security breach affecting personal data, we will notify those affected and the competent authorities within the timeframes required by law (72 hours under GDPR; without undue delay under Law 25.326).

15 Push notifications

Push notifications on TestVocacional.app work as follows:

  • Disabled by default (opt-out). They are only enabled if the User explicitly chooses so during registration or in the app settings.
  • Used to inform about new content, vocational reminders and service updates.
  • The User can disable them at any time:
    • iOS: Settings → Notifications → TestVocacional
    • Android: Settings → Apps → TestVocacional → Notifications
  • Disabling notifications does not affect access to or any functionality of the app.

16 Automated decisions and profiling

TestVocacional.app uses algorithms to generate test results and personalised vocational reports. In this regard:

  • Results are generated automatically based on the User's answers and reference psychometric models.
  • This automation does not produce legal effects on the User or significant decisions outside the Platform (it is not used for recruitment, credit, insurance or any similar process).
  • The User has the right recognised in Art. 22 GDPR not to be subject to decisions based solely on automated processing with legal or significant effects.
  • We do not carry out commercial profiling based on test answers or usage behaviour for advertising purposes.

17 Changes to this Policy

The Controller may update this Policy when necessary to reflect changes in data processing practices, legal requirements or Platform features. When changes are significant, we will notify the User by:

  • Prominent notice on the Platform or app
  • Email to the registered address
  • Updating the "Last updated" date at the top of this document

Continued use of the Platform after changes take effect implies acceptance of the new Policy. If changes require new consent, we will request it explicitly.

18 Additional information by region

18.1 Argentina residents Law 25.326

In accordance with Law No. 25.326 on Personal Data Protection, the User has the right to access, rectify, update and, where applicable, delete or make confidential their personal data. The Agency for Access to Public Information (AAIP), as the supervisory authority, is empowered to handle complaints and claims for non-compliance. Contact: [email protected].

18.2 European Union residents GDPR

EU/EEA residents have all rights recognised under the GDPR, including the right to lodge a complaint with the supervisory authority in their country of residence. Full list: edpb.europa.eu. In Spain: AEPD. The basis for data transfers to third countries is described in Section 11.

18.3 California residents CCPA / CPRA

Under the CCPA and CPRA, in addition to the general rights in this Policy, you have the right to: know what categories of personal data we collect and for what purposes; opt out of the sale or sharing of data (note: we do not sell or share data for commercial purposes); not be discriminated against for exercising your rights; and limit the use of sensitive personal information. Requests under CCPA/CPRA: [email protected]. We respond within 45 days (extendable by a further 45 days if necessary).

18.4 Colombia, Mexico and Peru residents LATAM

Users resident in Colombia (Law 1581/2012), Mexico (LFPDPPP) and Peru (Law 29733) have equivalent rights of access, rectification, cancellation and objection (ARCO rights). To exercise them: [email protected].

19 Contact and privacy requests

Privacy contact — TestVocacional.app

Name Federico Osella
Platform TestVocacional.app
Address José A. Nanini 3154, Colonia Caroya, Córdoba, Argentina
Email [email protected]
General response time Up to 30 business days
Urgent requests Up to 15 business days

Last updated: July 8, 2025 — Version 1.0
© 2025 Federico Osella — TestVocacional.app. All rights reserved.