L4Privacy policy

Your data, in good hands.

What data we collect, what for, who we share it with, how long we keep it, and how you stay in control.

Version in force · May 2026

This is a translation provided for convenience. In the event of any discrepancy, the French version prevails.

Contents
  1. 01Our commitment
  2. 02Data controller
  3. 03Data we collect
  4. 04Why we process your data
  5. 05Data made public
  6. 06Who we share with
  7. 07How long we keep it
  8. 08Security
  9. 09Cookies & trackers
  10. 10Your rights
  11. 11Minors
  12. 12Complaint to the CNIL
  13. 13Changes to this policy
  14. 14Contact us

01

Our commitment

A certificate is only worth something if the body issuing it can be trusted. The same is true of the way your data is handled. We hold to three simple principles:

  • Minimisation. We only collect what is necessary to issue the certificate or what is required by law.
  • Transparency. You know at all times what is public, what is private, and who we share it with.
  • Control. You can exercise your GDPR rights with a simple email — we respond within one month.

02

Data controller

Controller
BRAINEE, SAS
SIREN
849 355 383
Address
7 avenue de Ségur, 75007 Paris, France

03

Data we collect

We only collect the data necessary for the service:

  • Identity. First name, last name, date of birth, and — when sitting the exam — proof of identity.
  • Contact. Email address, possibly a phone number.
  • Professional profile. Role, level of experience, organisation, entered in the application file.
  • Exam data. Answers provided, overall score, per-skill scores, level attained, session timestamps.
  • Certificate photo. Optional: uploaded by the candidate to appear on the public verification page.
  • Payment data. Processed exclusively by Stripe; we never store your bank card details.
  • Technical data. Connection logs, IP address, browser type — used for security and proper operation.

04

Why we process your data

  • To perform the contract — account management, application file, payment, sitting the exam, issuance and verification of the certificate.
  • To comply with our legal obligations — retention of accounting and tax records, declarations made necessary by the RS7554 registration.
  • To preserve the integrity of the exam — fraud prevention, detection of abnormal behaviour (legitimate interest).
  • To improve the service — pseudonymised audience measurement, bug fixes (legitimate interest).
  • To communicate with you — transactional notifications (performance of the contract) and newsletters or marketing messages only after your consent.

05

Data made public

The public certificate verification page (“Verify a certification”) exists to allow any third party — employer, client, platform — to check that a certificate is authentic.

What is public

The following are publicly accessible once a valid certificate code has been entered: the holder's first and last name, the level and score obtained, the date of issuance and — if you have uploaded one — your photo. No data other than that listed here is exposed publicly.

By sitting the certification and completing the issuance of the certificate, you consent to this publication, which is the very purpose of the certification. You may request the removal of the certificate from the public page by writing to us; its invalidation may then be recorded.

06

Who we share with

Your data is never sold. It is accessible to authorised BRAINEE teams and to a limited number of technical processors acting on our behalf and on our instructions:

  • Vercel Inc. (United States / EU) — website hosting, execution of server functions.
  • Supabase Inc. (Singapore / EU) — database and authentication.
  • Stripe Payments Europe Ltd (Ireland) — payment processing.
  • Transactional email provider — sending notifications related to the account and the order.
  • France Compétences and accredited bodies — for the declarations made necessary by the RS7554 registration.

Where transfers outside the European Union are necessary, they rely on a transfer mechanism recognised by the European Commission (standard contractual clauses, adequacy decision, etc.).

07

How long we keep it

  • Candidate account. For the duration of active use, then archived for up to 3 years after the last interaction.
  • Exam data and certificate. Kept for as long as the certificate is in force and beyond, to allow public verification over time.
  • Accounting records and invoices. 10 years, in accordance with accounting obligations.
  • Technical logs. 12 months maximum.
  • Identity documents presented in order to sit the exam. For the time strictly necessary for verification, then deleted — unless a legal obligation requires otherwise.

08

Security

We implement reasonable technical and organisational measures to protect your data: encryption in transit (HTTPS), encryption at rest on the database, role-based access control, strict separation between client code and server keys, logging of sensitive actions. No solution is perfect: we notify the data subjects concerned and the CNIL without undue delay in the event of a breach likely to give rise to a risk to their rights and freedoms.

09

Cookies & trackers

We use a limited number of cookies, in two categories:

  • Essential cookies — Supabase authentication session, security tokens, load balancing. They are placed without prior consent, as they are indispensable to the operation of the service.
  • Audience measurement and personalisation cookies — placed only after your consent, which you may withdraw at any time from your browser or from the management panel offered on the website.

10

Your rights

In accordance with the GDPR and the French Data Protection Act (loi Informatique et Libertés), you have the rights:

  • of access to your data and to obtain a copy of it;
  • of rectification of inaccurate or incomplete data;
  • of erasure (the “right to be forgotten”), subject to our legal obligations;
  • of restriction of and objection to processing, in the cases provided for by law;
  • of portability of your data in a structured format;
  • to set out directives on the fate of your data after your death.

To exercise these rights: write to certification@iq-certification.ai, clearly stating your request. Proof of identity may be requested in the event of reasonable doubt. We undertake to respond within one month, which may be extended to three months for complex requests.

11

Minors

The service is primarily intended for an adult audience. Where a candidate who is a minor wishes to sit the certification, the authorisation of their legal representative is required. We do not knowingly collect data from children under the age of 15; should that occur, such data will be deleted on request.

12

Complaint to the CNIL

If you consider that the processing of your data does not comply with the regulations, you may lodge a complaint with the CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.

13

Changes to this policy

This policy may change to reflect technical, legal or service developments. The version in force is the one published on this page. In the event of a substantial change affecting active users, prior information is provided by email or by notification.

14

Contact us

A question, a request, a doubt about how your data is used? Write to us at certification@iq-certification.ai or by post: BRAINEE — 7 avenue de Ségur, 75007 Paris, France.