Last Updated: May 25, 2025
Effective Date: May 25, 2025
Important: This Privacy Policy explains how Test Apps Limited collects, uses, discloses, and safeguards your personal information when you use our mobile applications and services. By using our applications, you consent to the practices described in this Privacy Policy.
1. Introduction
Test Apps Limited ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy applies to all our mobile applications and related services, including but not limited to:
Our Applications Include:
*This list includes our current applications but is not limited to these apps. Additional applications may be released and covered under this Privacy Policy.
1.1 Controller Information
Test Apps Limited is the data controller for the personal information collected through our applications. We are incorporated in New Zealand and operate under New Zealand privacy laws, while also complying with international privacy regulations including GDPR, CCPA, and other applicable privacy laws.
1.2 Scope of This Policy
This Privacy Policy covers:
- Information collection practices across all our applications
- How we use, process, and store your personal information
- Your rights regarding your personal information
- Our data security measures and retention policies
- Information sharing and disclosure practices
- Compliance with international privacy laws
2. Information We Collect
We collect various types of information to provide and improve our services. The information we collect falls into several categories:
2.1 Information You Provide Directly
Data Type | Description | Purpose | Legal Basis |
---|---|---|---|
Account Information | Email address, username, password, profile information | Account creation, authentication, service provision | Contract performance, legitimate interests |
Test Responses | Answers to assessment questions, quiz responses, test results | Providing personalized results and recommendations | Contract performance, consent |
Communication Data | Messages sent to customer support, feedback, inquiries | Customer support, service improvement | Legitimate interests |
Preference Settings | App settings, notification preferences, accessibility options | Personalizing your app experience | Legitimate interests |
2.2 Information Collected Automatically
Data Type | Description | Purpose | Legal Basis |
---|---|---|---|
Device Information | Device model, operating system, app version, device identifiers | App functionality, compatibility, technical support | Legitimate interests |
Usage Analytics | App usage patterns, feature interactions, session duration | Service improvement, analytics, user experience optimization | Legitimate interests |
Performance Data | Crash reports, error logs, performance metrics | Bug fixes, app stability, technical improvements | Legitimate interests |
Location Data | Approximate location based on IP address (country/region level) | Compliance with local laws, relevant content delivery | Legitimate interests |
2.3 Information from Third Parties
We may receive information from third-party services integrated with our applications:
- Apple App Store: Purchase information, subscription status (processed by Apple)
- Analytics Services: Aggregated usage statistics and performance metrics
- Advertising Partners: Limited advertising identifiers for personalized ads (with your consent)
- Social Media Platforms: If you choose to connect social accounts (with explicit permission)
Data Minimization Principle
We only collect information that is necessary for providing our services, improving user experience, or complying with legal obligations. We regularly review our data collection practices to ensure we maintain this principle.
3. How We Use Your Information
We use your personal information for the following purposes:
3.1 Primary Service Provision
- Assessment Delivery: Processing your test responses and generating personalized results
- Account Management: Creating and maintaining your user account
- Content Personalization: Customizing content and recommendations based on your preferences
- Progress Tracking: Storing your test history and progress over time
3.2 Service Improvement and Development
- Analytics: Understanding how users interact with our applications
- Feature Development: Developing new features based on user needs and usage patterns
- Quality Assurance: Testing and improving application performance
- Research: Conducting anonymized research to improve assessment methodologies
3.3 Communication and Support
- Customer Support: Responding to your inquiries and providing technical assistance
- Service Updates: Notifying you about important changes or new features
- Educational Content: Providing relevant health and wellness information (where applicable)
- Marketing Communications: Sending promotional content (only with your explicit consent)
3.4 Legal and Compliance
- Legal Obligations: Complying with applicable laws and regulations
- Safety and Security: Protecting against fraud, abuse, and security threats
- Dispute Resolution: Resolving conflicts and enforcing our terms of service
Purpose Limitation
We only use your personal information for the purposes described in this Privacy Policy or other purposes that are compatible with these purposes. We will not use your information for unrelated purposes without obtaining your explicit consent.
5. Data Security
We implement comprehensive security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
5.1 Technical Safeguards
- Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
- Access Controls: Multi-factor authentication and role-based access controls for our systems
- Network Security: Firewalls, intrusion detection systems, and regular security monitoring
- Secure Development: Security-by-design principles in our application development process
- Regular Updates: Timely security patches and system updates
5.2 Organizational Safeguards
- Staff Training: Regular privacy and security training for all employees
- Access Limitation: Information access limited to employees who need it for their job functions
- Confidentiality Agreements: All staff and contractors sign confidentiality agreements
- Incident Response: Documented procedures for responding to potential security incidents
- Regular Audits: Periodic security assessments and vulnerability testing
5.3 Data Breach Response
In the unlikely event of a data breach, we will:
- Investigate and contain the breach immediately
- Assess the scope and impact of the incident
- Notify affected users within 72 hours where required by law
- Report to relevant supervisory authorities as required
- Implement additional measures to prevent future incidents
- Provide support and guidance to affected users
Your Role in Security
While we implement strong security measures, you also play a role in protecting your information. Please use strong, unique passwords, keep your device secure, and contact us immediately if you suspect unauthorized access to your account.
6. Data Retention
We retain your personal information only as long as necessary to fulfill the purposes for which it was collected or as required by law.
6.1 Retention Periods
Data Type | Retention Period | Reason |
---|---|---|
Account Information | Duration of account + 2 years after deletion | Service provision, legal compliance |
Test Results | Duration of account + 1 year after deletion | User access to historical data |
Usage Analytics | 26 months from collection | Service improvement, analytics |
Support Communications | 3 years from last contact | Customer service quality, legal protection |
Marketing Consents | Until withdrawn + 1 year | Compliance demonstration |
Legal/Compliance Records | 7 years or as required by law | Legal and regulatory compliance |
6.2 Secure Deletion
When we delete your personal information:
- Data is permanently removed from our active systems
- Backup copies are systematically purged according to our retention schedule
- Physical media containing your data is securely destroyed
- We maintain logs of deletion activities for compliance purposes
6.3 Account Deletion
You can request account deletion at any time by contacting us. Upon account deletion:
- Your account becomes immediately inaccessible
- Personal information is deleted according to our retention schedule
- Some information may be retained for legal compliance or legitimate business purposes
- Anonymized or aggregated data may be retained for analytical purposes
7. Your Privacy Rights
You have various rights regarding your personal information, depending on your location and applicable privacy laws.
7.1 Universal Rights
Regardless of your location, you have the following rights:
- Right to Information: Clear information about how we process your data
- Right of Access: Request a copy of the personal information we hold about you
- Right to Rectification: Correct inaccurate or incomplete information
- Right to Deletion: Request deletion of your personal information
- Right to Withdraw Consent: Withdraw consent for processing based on consent
- Right to Opt-out: Unsubscribe from marketing communications
7.2 How to Exercise Your Rights
To exercise any of these rights:
- Contact Us: Email us at hello@testapps.com with your request
- Verification: We may need to verify your identity to protect your privacy
- Processing Time: We will respond within 30 days (or as required by applicable law)
- No Fee: Exercising your rights is generally free of charge
7.3 Limitations
Some rights may be limited in certain circumstances:
- Legal obligations may require us to retain certain information
- Legitimate interests may justify continued processing
- Technical limitations may affect how quickly we can process requests
- Rights of others may limit what information we can provide or delete
Right to Lodge a Complaint
If you believe we have not handled your personal information properly, you have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can address your concerns directly.
8. International Data Transfers
As a global service, we may transfer your personal information to countries outside of your residence. We ensure all transfers are protected by appropriate safeguards.
8.1 Transfer Locations
Your personal information may be transferred to and processed in:
- New Zealand: Our primary operations base
- United States: Cloud hosting and analytics services
- European Union: Data processing and support services
- Other Countries: As necessary for service provision with appropriate safeguards
8.2 Transfer Safeguards
We implement the following safeguards for international transfers:
- Adequacy Decisions: Transfers to countries recognized as providing adequate protection
- Standard Contractual Clauses: EU-approved contractual protections for data transfers
- Binding Corporate Rules: Internal policies ensuring consistent protection
- Certification Schemes: Third-party certifications demonstrating privacy compliance
- Codes of Conduct: Industry standards for privacy protection
8.3 Your Rights Regarding Transfers
You have the right to:
- Obtain information about the countries where your data is processed
- Request copies of the safeguards protecting your data during transfers
- Object to transfers in certain circumstances
- Lodge complaints with supervisory authorities about international transfers
10. Third-Party Services and Integrations
Our applications integrate with various third-party services to provide enhanced functionality.
10.1 Apple Services Integration
As iOS applications, we integrate with various Apple services:
- App Store: App distribution and in-app purchases
- Apple ID: Authentication and account management (optional)
- HealthKit: Health data integration (with explicit permission)
- CloudKit: Data synchronization across devices (optional)
- Push Notifications: App notifications and updates
10.2 Analytics and Performance Services
- Firebase Analytics: Usage analytics and crash reporting
- App Store Analytics: App performance and user acquisition metrics
- Custom Analytics: Internal analytics for service improvement
10.3 Advertising and Marketing Services
With your consent, we may use:
- Apple Search Ads: Advertising attribution and measurement
- Third-party Ad Networks: Personalized advertising delivery
- Marketing Platforms: Email marketing and user engagement
10.4 Third-Party Privacy Policies
Third-party services have their own privacy policies:
- Apple Privacy Policy
- Google Privacy Policy (Firebase)
- Other third-party services as integrated and disclosed within our applications
Third-Party Responsibility
We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies before using integrated features that involve third-party data processing.
11. Children's Privacy
We are committed to protecting the privacy of children and comply with applicable children's privacy laws.
11.1 Age Restrictions
- Minimum Age: Our applications are intended for users 17 years and older
- Parental Consent: Users under 18 must have parental permission
- No Children Under 13: We do not knowingly collect information from children under 13
11.2 If We Learn of Child Data Collection
If we discover we have collected information from a child under 13:
- We will delete the information immediately
- We will terminate any associated accounts
- We will notify parents if we have their contact information
- We will implement additional measures to prevent future collection
11.3 Parental Rights
Parents have the right to:
- Review any personal information we have collected about their child
- Request deletion of their child's personal information
- Refuse to allow further collection or use of their child's information
- Contact us with questions about our children's privacy practices
Report Child Privacy Concerns
If you believe we have collected information from a child under 13, please contact us immediately at hello@testapps.com so we can address the situation promptly.
12. Health Data and Sensitive Information
Some of our applications collect health-related information. We handle this sensitive data with extra care and protection.
12.1 Types of Health Data
Our health-related applications may collect:
- Assessment Responses: Answers to mental health screening questions
- Symptom Information: Self-reported symptoms and experiences
- Progress Data: Changes in assessment results over time
- Wellness Goals: Personal health and wellness objectives
12.2 Special Protections for Health Data
- Enhanced Encryption: Additional encryption layers for health information
- Limited Access: Strict access controls for health-related data
- Explicit Consent: Clear consent for health data collection and use
- Professional Standards: Adherence to healthcare privacy standards
12.3 Health Data Usage
We use health data only for:
- Providing assessment results and recommendations
- Tracking your progress over time (with your consent)
- Improving our assessment tools (using anonymized data)
- Complying with applicable health privacy laws
Not Medical Advice
Our applications provide educational information and self-assessment tools. They are not intended to diagnose, treat, or provide medical advice. Always consult qualified healthcare professionals for medical concerns.
12.4 HealthKit Integration (iOS)
If you choose to integrate with Apple HealthKit:
- You control what data is shared
- Data remains encrypted and secure
- You can revoke access at any time
- We follow Apple's HealthKit privacy requirements
13. California Privacy Rights (CCPA/CPRA)
California residents have additional privacy rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
13.1 Categories of Personal Information
Category | Examples | Collected | Sold/Shared |
---|---|---|---|
Identifiers | Email, device ID, IP address | Yes | No |
Personal Information | Contact details, account information | Yes | No |
Commercial Information | Purchase history, subscription data | Yes | No |
Internet Activity | App usage, browsing behavior | Yes | Limited* |
Geolocation Data | Approximate location | Limited | No |
Sensory Information | Health assessment responses | Yes | No |
Inferences | Preferences, characteristics | Yes | No |
*Limited sharing for advertising purposes with your consent
13.2 Your California Rights
- Right to Know: Request information about personal information collection and use
- Right to Delete: Request deletion of personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: Opt-out of sale or sharing for advertising
- Right to Limit: Limit use of sensitive personal information
- Right to Non-Discrimination: Equal treatment regardless of exercising rights
13.3 Exercising California Rights
California residents can exercise their rights by:
- Emailing us at hello@testapps.com
- Using our online request form (if available)
- Contacting us through our applications
13.4 Verification Process
We may need to verify your identity by requesting:
- Email verification
- Account credentials
- Additional identifying information
California "Shine the Light" Law
California residents may also request information about our disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
14. European Privacy Rights (GDPR)
Individuals in the European Economic Area (EEA), UK, and Switzerland have additional rights under the General Data Protection Regulation (GDPR).
14.1 Legal Basis for Processing
Processing Purpose | Legal Basis | Description |
---|---|---|
Service Provision | Contract Performance | Necessary to provide our applications and services |
Analytics & Improvement | Legitimate Interests | Improving our services and user experience |
Marketing Communications | Consent | Sending promotional content with your permission |
Legal Compliance | Legal Obligation | Complying with applicable laws and regulations |
Health Data Processing | Explicit Consent | Processing health-related information with clear consent |
14.2 Your GDPR Rights
- Right of Access: Obtain confirmation and details about processing
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion ("right to be forgotten")
- Right to Restrict Processing: Limit how we process your data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for consent-based processing
14.3 Data Protection Officer
You can contact our Data Protection Officer at:
- Email: hello@testapps.com
- Subject Line: "GDPR / Data Protection Inquiry"
14.4 Supervisory Authority
You have the right to lodge a complaint with your local supervisory authority if you believe we have not handled your personal data properly. Contact details for EU supervisory authorities are available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
Response Time
We will respond to GDPR requests within one month. In complex cases, we may extend this by two additional months and will explain the reasons for any delay.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
15.1 Notification of Changes
When we make changes, we will:
- Update the Date: Change the "Last Updated" date at the top of this policy
- In-App Notification: Notify users through our applications for significant changes
- Email Notification: Send email notifications for material changes (if we have your email)
- Website Notice: Post notices on our website
15.2 Types of Changes
- Minor Changes: Clarifications, formatting, or non-substantive updates
- Material Changes: Significant changes to data practices or your rights
- Legal Updates: Changes required by new laws or regulations
15.3 Your Options
When we make material changes:
- You can continue using our services under the new terms
- You can contact us with questions or concerns
- You can exercise your rights to access, correct, or delete your data
- You can stop using our services if you disagree with the changes
Continued Use Means Acceptance
Your continued use of our applications after privacy policy changes become effective means you accept the updated terms. If you don't agree with changes, please stop using our services and contact us about data deletion.
16. Contact Information
We're here to help with any privacy questions or concerns you may have.
Primary Contact
Test Apps Limited
Email: hello@testapps.com
Website: testapps.com
16.1 When to Contact Us
Please contact us for:
- Questions about this Privacy Policy or our privacy practices
- Requests to exercise your privacy rights
- Concerns about how your personal information is handled
- Reports of potential privacy or security issues
- Questions about data sharing or third-party integrations
- Requests for additional information about our data practices
16.2 Response Times
- General Inquiries: We aim to respond within 2-3 business days
- Privacy Rights Requests: Within 30 days (or as required by law)
- Security Issues: Within 24 hours for urgent matters
- GDPR Requests: Within 1 month (may be extended to 3 months for complex requests)
16.3 What to Include in Your Request
To help us process your request efficiently, please include:
- Your full name and email address associated with your account
- Specific details about your request or concern
- Which applications you use
- Any relevant dates or timeframes
- Proof of identity (for privacy rights requests)
16.4 Emergency Contacts
For urgent privacy or security matters:
- Email: hello@testapps.com with "URGENT" in the subject line
- Data Breach Reports: hello@testapps.com with "SECURITY INCIDENT" in the subject line
Medical Emergencies
If you are experiencing a medical or mental health emergency, do not contact us through these channels. Instead, contact your local emergency services, visit your nearest emergency department, or call a crisis helpline in your area.
16.5 Language Support
We primarily provide support in English. If you need assistance in another language, please let us know and we will do our best to accommodate your request or direct you to appropriate resources.
16.6 Representative Contacts
For residents of certain jurisdictions, we have appointed local representatives:
- EU/EEA/UK Representative: Contact details available upon request
- California Agent: Service through our primary contact above
Final Notes
This Privacy Policy represents our commitment to protecting your privacy and maintaining transparency about our data practices. We regularly review and update our privacy practices to ensure they meet the highest standards and comply with applicable laws.
Your trust is important to us, and we work hard to earn and maintain it through responsible data handling, clear communication, and respect for your privacy rights.
Thank you for using Test Apps.
Last Updated: May 25, 2025
This Privacy Policy is effective immediately and applies to all information collected on or after this date.