Legal
Privacy Policy
Last updated: 24 September 2026
This policy explains what personal data Practice Sitting (practicesitting.com) collects, why, and what rights you have. In short: we collect what is needed to run your account and your study, we do not sell data, we do not advertise, and we do not send your data to AI providers.
1. Who is responsible
The data controller is Leading srl STP, Via Lazzaretto 1, 20060 Gessate (MI), Italy, VAT IT11516580963. Contact: [email protected].
2. What we collect
- Account data. Your email address and, if you sign up with a password, the password in hashed form (PBKDF2), which we cannot read. Your plan (free or Pro) and when you created the account.
- Google or LinkedIn sign-in. If you choose it, we receive the identifier the provider assigns you and your verified email address. We ask only for the basic sign-in permissions (openid email profile) and do not store your name or photo, your contacts or anything from your profile.
- Study data. Your attempts, the answers you give, time spent per question, flagged questions, scores, the questions scheduled for review, drill sessions, and your exam date if you enter one. This is what the service exists to process: it builds your progress and your weak areas.
- Question reports. If you report a problem with a question, we store your message and link it to your account and the question.
- Security data. To slow down password-guessing, we briefly record failed sign-in attempts for an email address.
- Purchase data. When you buy Pro, Stripe processes the payment. We receive confirmation of the purchase and the details needed for the invoice or receipt, never your card number.
We do not collect special categories of data. We do not use tracking, advertising or profiling cookies, and we load no analytics scripts.
3. Why, and on what legal basis
- To provide the service you signed up for: your account, simulations, explanations, study features and Pro access (contract, Art. 6(1)(b) GDPR).
- To keep the service secure and prevent abuse, such as password guessing or multiple accounts used to obtain free content (legitimate interest, Art. 6(1)(f)).
- To improve the questions: we look at how questions perform in aggregate (for example, which ones nearly everyone gets wrong) to find and fix weak items (legitimate interest, Art. 6(1)(f)).
- To invoice and keep tax records (legal obligation, Art. 6(1)(c)).
- To send you service emails, such as address verification, password reset, receipts and notice of material changes to the Terms (contract). We do not send marketing email without your consent.
Your score is a readiness indicator for your own use. We make no automated decision about you that has legal or similarly significant effects (Art. 22 GDPR).
4. Who processes data for us
- Cloudflare, Inc. hosts the application and its database.
- Stripe, Inc. processes payments.
- Google LLC and LinkedIn Corporation handle sign-in, only if you choose to sign in with them. Their own privacy policies apply to your account with them.
- Google Fonts serves the typefaces used by the pages. Your browser requests them directly from Google, which therefore receives your IP address.
- Resend (Plus Five Five, Inc.) sends our service emails: it receives your email address and the content of the message.
- TeamSystem S.p.A. (Fatture in Cloud) prepares and stores our invoices: it receives your name, billing address and email and, for customers in Italy, the tax code or VAT number you enter at checkout.
Where these providers process data outside the EU/EEA, transfers rely on the European Commission's Standard Contractual Clauses or on the EU–US Data Privacy Framework, as applicable.
AI. The questions are written with the help of AI models before publication. The service does not send your account, your answers or your study data to any AI provider.
5. How long we keep data
- Account and study data: for as long as your account exists. When you ask us to delete your account, we delete it together with your attempts, answers, study data and question reports.
- Failed sign-in records: deleted after a successful sign-in, and otherwise kept only while the protection window lasts.
- Purchase and invoicing records: 10 years, as required by Italian tax law.
6. What we store in your browser
The app keeps your session token, your chosen language and some display preferences in your browser's local storage. During Google or LinkedIn sign-in it sets one short-lived cookie that protects the sign-in against forgery. All of these are strictly necessary for the service to work, so no consent banner is required. None of them is used to track you.
7. Your rights
Under the GDPR you can ask to access your data, correct it, delete it, receive it in a portable format, restrict its processing, or object to processing based on legitimate interest. Write to [email protected] from the address on your account. We reply within one month. You can also complain to the Italian data protection authority, the Garante per la protezione dei dati personali, or to the authority in your country.
8. Security
All traffic is encrypted with HTTPS. Passwords are stored only as salted hashes. Sessions use signed tokens. Only the application itself can reach the database. Sign-in codes from Google and LinkedIn are single-use, expire within minutes and are stored only as hashes.
9. Age
The service is for adults preparing for a professional credential. It is not directed at anyone under 18, and we do not knowingly collect their data.
10. Changes
If we change this policy in a material way, we will email registered users and update the date above.