Privacy Policy
Last updated: 2026-07-29
1. Who we are
testmypersonality.com ("we," "us," "our") is operated by:
MARTIN IVERSEN KOMMUNIKASJON Enkeltpersonforetak, registered in Norway Foretaksnummer (org. no.): 929297857 Registered address: Morellveien 41, 1387 Asker Contact for privacy matters: our contact email
We are the "data controller" for the personal data described in this policy. As a sole proprietorship we are not required to appoint a formal Data Protection Officer, but the contact above handles all privacy requests personally.
2. Scope
This policy applies to testmypersonality.com and covers visitors, registered users, and purchasers worldwide. It is written to meet the EU/EEA General Data Protection Regulation (GDPR), and we apply the same standard globally rather than offering a lower level of protection to visitors outside the EU/EEA/UK. Where a specific right or mechanism (e.g. California's CCPA/CPRA) applies only to certain users, that is noted separately in Section 9.
3. What data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password (hashed) | You, at signup |
| Assessment data | Your answers to personality questionnaire items, computed trait/facet scores, archetype results | You, via the assessment |
| Purchase data | Product purchased, price, transaction ID, purchase date | Generated at checkout; card details are handled entirely by Stripe (see Section 6) — we never see or store your card number |
| Communications | Support emails, messages you send us | You |
| Technical data | IP address, browser/device type, pages visited, referring site | Automatically, via server logs and (if enabled) analytics cookies — see our Cookie Policy |
| Relationship Report data (if used) | A second person's assessment answers, submitted with their consent | You and, where required, the second participant directly |
We do not knowingly collect any data beyond what is listed above, and we do not collect special categories of data (e.g. health, racial/ethnic origin, religious belief, sexual orientation) as a matter of design.
A note on the nature of assessment data: Some legal commentary treats certain psychometric outputs (particularly emotional-stability/Neuroticism-related scores) as potentially touching on health-adjacent inference. Our platform is a self-directed, self-report developmental tool — not a clinical, diagnostic, or employment-screening instrument, and results are not shared with or used by any third party to make decisions about you. We do not treat your data as a special category, but we handle it with materially higher care than ordinary account data: assessment answers and results are never sold, never used for third-party advertising, and are only used to generate your report and (with your explicit consent) improve our content.
4. Why we process your data, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and manage your account | Contract necessity |
| Generate your personality report(s) | Contract necessity |
| Process payment | Contract necessity / legal obligation (accounting) |
| Respond to support requests | Legitimate interest / contract |
| Send transactional emails (purchase confirmation, report delivery, account notices) | Contract necessity |
| Send optional marketing emails | Consent (opt-in; withdrawable anytime) |
| Analytics / product improvement (cookies) | Consent, where required — see Cookie Policy |
| Aggregate, de-identified research to improve report content and validate scoring thresholds | Legitimate interest (data is aggregated/anonymized before analysis) |
| Fraud prevention, security, legal compliance | Legal obligation / legitimate interest |
We do not use your data for any purpose beyond what's listed here without asking you first.
5. Automated processing
Your report is generated by an algorithm that scores your questionnaire answers against established psychometric models (Big Five / IPIP-NEO) and, where applicable, assigns an archetype. This is automated profiling, but it does not constitute "solely automated decision-making producing legal or similarly significant effects" under GDPR Article 22 — no decision is made about you by us or a third party; the report is delivered to you for your own use.
6. Who we share data with
We use the following processors to run the service. Except where noted, they operate within the EU/EEA:
- Supabase (database hosting) — EU region (Ireland)
- Stripe (payment processing) — processes and stores payment data under Stripe's infrastructure applicable to Norwegian accounts, which complies with EU/EEA data protection standards. Stripe is a global payments company and may process limited data outside the EEA for card-network and fraud-prevention purposes; where it does, Stripe relies on Standard Contractual Clauses or equivalent safeguards. See Stripe's own privacy policy for details.
- PostHog (product analytics, once enabled) — EU Cloud instance (hosted in the EU)
- Tidio (live-chat support) — provides the on-site chat widget and processes the messages you send through it. Tidio may process data outside the EEA; where it does, it relies on Standard Contractual Clauses or equivalent safeguards. See Tidio's privacy policy for details.
We do not sell your personal data. We do not share assessment data or report contents with advertisers, data brokers, or any third party for their own marketing purposes.
If we ever add a processor located outside the EU/EEA without an adequacy decision, we will rely on Standard Contractual Clauses and update this policy before doing so.
7. How long we keep your data
- Account and assessment data: kept while your account is active, plus a limited period after account deletion to fulfil legal obligations (see below).
- Purchase/transaction records: Norwegian bookkeeping law (bokføringsloven) requires us to retain accounting records for up to 5 years. When you delete your account, we anonymize your profile and assessment data (removing name, email, and other identifiers) but retain the anonymized transaction record for this legal minimum period, rather than deleting it outright.
- Support communications: typically retained for up to 2 years for quality and continuity purposes.
8. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten"), subject to Section 7 above
- Restrict or object to certain processing
- Data portability — receive your data in a machine-readable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with a supervisory authority — in Norway, this is Datatilsynet; EU/EEA residents may also complain to their local data protection authority
To exercise any of these rights, contact us at our contact email. We will respond within one month, as required by GDPR.
9. Region-specific notices
California (CCPA/CPRA): We currently fall below the revenue and data-volume thresholds that trigger full CCPA obligations. As a matter of practice, however, we do not sell or share your personal information, and California residents may still contact us to request access to or deletion of their data.
Other jurisdictions: If your local law grants you additional rights not listed above, contact us and we'll do our best to honor them.
10. Children
testmypersonality.com is not directed at, and is not intended for use by, anyone under 16 years old. We do not knowingly collect data from children under 16. Personality assessments of this kind are also not psychometrically validated for use with minors. If you believe a child has provided us data, contact us and we will delete it.
11. Security
We use industry-standard technical and organizational measures (encryption in transit, access controls, hashed passwords) to protect your data. No system is 100% secure; if a breach affecting your data occurs, we will notify affected users and, where required, the relevant supervisory authority within 72 hours, in line with GDPR Article 33.
12. International visitors
We are based in Norway (EEA) and process data primarily within the EU/EEA. If you access the service from outside the EEA, your data will be transferred to and processed in the EEA as described above.
13. Changes to this policy
We'll update this page when our practices change and update the "Last updated" date above. Material changes affecting your rights will be communicated via email or a notice on the site.
14. Contact
Questions or requests: our contact email, or via the live chat on our site.