Privacy Policy

Last updated: 2026-07-29

1. Who we are

testmypersonality.com ("we," "us," "our") is operated by:

MARTIN IVERSEN KOMMUNIKASJON Enkeltpersonforetak, registered in Norway Foretaksnummer (org. no.): 929297857 Registered address: Morellveien 41, 1387 Asker Contact for privacy matters: our contact email

We are the "data controller" for the personal data described in this policy. As a sole proprietorship we are not required to appoint a formal Data Protection Officer, but the contact above handles all privacy requests personally.

2. Scope

This policy applies to testmypersonality.com and covers visitors, registered users, and purchasers worldwide. It is written to meet the EU/EEA General Data Protection Regulation (GDPR), and we apply the same standard globally rather than offering a lower level of protection to visitors outside the EU/EEA/UK. Where a specific right or mechanism (e.g. California's CCPA/CPRA) applies only to certain users, that is noted separately in Section 9.

3. What data we collect

CategoryExamplesSource
Account dataName, email address, password (hashed)You, at signup
Assessment dataYour answers to personality questionnaire items, computed trait/facet scores, archetype resultsYou, via the assessment
Purchase dataProduct purchased, price, transaction ID, purchase dateGenerated at checkout; card details are handled entirely by Stripe (see Section 6) — we never see or store your card number
CommunicationsSupport emails, messages you send usYou
Technical dataIP address, browser/device type, pages visited, referring siteAutomatically, via server logs and (if enabled) analytics cookies — see our Cookie Policy
Relationship Report data (if used)A second person's assessment answers, submitted with their consentYou and, where required, the second participant directly

We do not knowingly collect any data beyond what is listed above, and we do not collect special categories of data (e.g. health, racial/ethnic origin, religious belief, sexual orientation) as a matter of design.

A note on the nature of assessment data: Some legal commentary treats certain psychometric outputs (particularly emotional-stability/Neuroticism-related scores) as potentially touching on health-adjacent inference. Our platform is a self-directed, self-report developmental tool — not a clinical, diagnostic, or employment-screening instrument, and results are not shared with or used by any third party to make decisions about you. We do not treat your data as a special category, but we handle it with materially higher care than ordinary account data: assessment answers and results are never sold, never used for third-party advertising, and are only used to generate your report and (with your explicit consent) improve our content.

4. Why we process your data, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Create and manage your accountContract necessity
Generate your personality report(s)Contract necessity
Process paymentContract necessity / legal obligation (accounting)
Respond to support requestsLegitimate interest / contract
Send transactional emails (purchase confirmation, report delivery, account notices)Contract necessity
Send optional marketing emailsConsent (opt-in; withdrawable anytime)
Analytics / product improvement (cookies)Consent, where required — see Cookie Policy
Aggregate, de-identified research to improve report content and validate scoring thresholdsLegitimate interest (data is aggregated/anonymized before analysis)
Fraud prevention, security, legal complianceLegal obligation / legitimate interest

We do not use your data for any purpose beyond what's listed here without asking you first.

5. Automated processing

Your report is generated by an algorithm that scores your questionnaire answers against established psychometric models (Big Five / IPIP-NEO) and, where applicable, assigns an archetype. This is automated profiling, but it does not constitute "solely automated decision-making producing legal or similarly significant effects" under GDPR Article 22 — no decision is made about you by us or a third party; the report is delivered to you for your own use.

6. Who we share data with

We use the following processors to run the service. Except where noted, they operate within the EU/EEA:

  • Supabase (database hosting) — EU region (Ireland)
  • Stripe (payment processing) — processes and stores payment data under Stripe's infrastructure applicable to Norwegian accounts, which complies with EU/EEA data protection standards. Stripe is a global payments company and may process limited data outside the EEA for card-network and fraud-prevention purposes; where it does, Stripe relies on Standard Contractual Clauses or equivalent safeguards. See Stripe's own privacy policy for details.
  • PostHog (product analytics, once enabled) — EU Cloud instance (hosted in the EU)
  • Tidio (live-chat support) — provides the on-site chat widget and processes the messages you send through it. Tidio may process data outside the EEA; where it does, it relies on Standard Contractual Clauses or equivalent safeguards. See Tidio's privacy policy for details.

We do not sell your personal data. We do not share assessment data or report contents with advertisers, data brokers, or any third party for their own marketing purposes.

If we ever add a processor located outside the EU/EEA without an adequacy decision, we will rely on Standard Contractual Clauses and update this policy before doing so.

7. How long we keep your data

  • Account and assessment data: kept while your account is active, plus a limited period after account deletion to fulfil legal obligations (see below).
  • Purchase/transaction records: Norwegian bookkeeping law (bokføringsloven) requires us to retain accounting records for up to 5 years. When you delete your account, we anonymize your profile and assessment data (removing name, email, and other identifiers) but retain the anonymized transaction record for this legal minimum period, rather than deleting it outright.
  • Support communications: typically retained for up to 2 years for quality and continuity purposes.

8. Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten"), subject to Section 7 above
  • Restrict or object to certain processing
  • Data portability — receive your data in a machine-readable format
  • Withdraw consent at any time, where processing is based on consent
  • Lodge a complaint with a supervisory authority — in Norway, this is Datatilsynet; EU/EEA residents may also complain to their local data protection authority

To exercise any of these rights, contact us at our contact email. We will respond within one month, as required by GDPR.

9. Region-specific notices

California (CCPA/CPRA): We currently fall below the revenue and data-volume thresholds that trigger full CCPA obligations. As a matter of practice, however, we do not sell or share your personal information, and California residents may still contact us to request access to or deletion of their data.

Other jurisdictions: If your local law grants you additional rights not listed above, contact us and we'll do our best to honor them.

10. Children

testmypersonality.com is not directed at, and is not intended for use by, anyone under 16 years old. We do not knowingly collect data from children under 16. Personality assessments of this kind are also not psychometrically validated for use with minors. If you believe a child has provided us data, contact us and we will delete it.

11. Security

We use industry-standard technical and organizational measures (encryption in transit, access controls, hashed passwords) to protect your data. No system is 100% secure; if a breach affecting your data occurs, we will notify affected users and, where required, the relevant supervisory authority within 72 hours, in line with GDPR Article 33.

12. International visitors

We are based in Norway (EEA) and process data primarily within the EU/EEA. If you access the service from outside the EEA, your data will be transferred to and processed in the EEA as described above.

13. Changes to this policy

We'll update this page when our practices change and update the "Last updated" date above. Material changes affecting your rights will be communicated via email or a notice on the site.

14. Contact

Questions or requests: our contact email, or via the live chat on our site.