1. Controller
AYRES S.R.L., Corso Re Umberto 63, 10128 Torino (TO), Italy, VAT IT12280250015 is the controller for the processing described here. Privacy enquiries: support@neuronprep.com. No Data Protection Officer has been appointed, as none is required under Article 37 GDPR for processing of this nature and scale.
2. Data we process
- Account: email, optional name, authentication identifiers, confirmation status and security logs. Passwords are handled by Supabase and are not stored by us in readable form.
- Legal records: versions and timestamps of Terms/Privacy acceptance.
- Marketing preference and delivery evidence: request, confirmation token hash, double-opt-in status and timestamps, campaign/send status, discount code, provider message reference, and a one-way hash of any one-click unsubscribe token; no marketing is sent before confirmation.
- Purchases: product entitlement, checkout email, Stripe session/payment references, status, refund/dispute status. Stripe processes card data separately.
- Study activity: answers, results, topics, timing and completed sessions.
- Technical/security: IP address, browser/device and server logs from hosting/authentication providers.
- Analytics, only after consent: Google Analytics 4 may receive page and device interaction data through cookies or similar identifiers. We configure analytics without advertising features and do not load Google Analytics before analytics consent.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Create and secure the account, deliver purchased content, save progress | Contract; legitimate interests for security |
| Process payments, refunds and accounting records | Contract and legal obligation |
| Send service/confirmation/security messages | Contract and legitimate interests; not marketing |
| Send optional study updates and offers, including a one-time follow-up after confirmed subscription when no purchase is recorded | Consent, confirmed by separate double opt-in; withdrawable at any time |
| Optional Google Analytics measurement | Consent; denied by default |
| Prevent fraud, abuse and protect systems | Legitimate interests and legal obligations where applicable |
4. Account confirmation and marketing double opt-in
Account email confirmation proves control of the registration address and is required before first sign-in. The optional marketing checkbox does not subscribe you immediately. A separate bilingual email asks you to confirm. Ignoring it leaves the account fully usable and no marketing consent is recorded as confirmed. A confirmed subscriber who has no recorded purchase may receive one promotional follow-up approximately 24 hours after confirmation. A database send ledger prevents that follow-up from being sent twice, and eligibility is checked again immediately before sending.
5. AI study suggestions
When enabled, aggregated performance statistics are sent to Anthropic through a protected server function. The function requires an authenticated paid account. We do not intentionally send your name or email in the study-plan payload. Anthropic acts as a processor under a data processing agreement, does not use the content of these requests to train its models, and retains it only as long as needed to return a response and meet its own trust and safety obligations. The feature is optional and can be left unused without affecting your access to the materials.
6. Recipients and processors
- Supabase: authentication and EU-hosted database.
- Netlify: hosting, delivery and serverless functions.
- Stripe: payment processing/tax and its own legal obligations.
- Resend: transactional, double-opt-in and consented marketing email delivery.
- CookieYes: consent-management platform and consent logs.
- Google Analytics 4: optional analytics after consent.
- Anthropic: optional AI phrasing as described above.
7. International transfers
Our infrastructure providers are Supabase (database and authentication), Netlify (hosting and server functions), Stripe (payments), Resend (transactional email) and Anthropic (optional study suggestions). Where any of them processes personal data outside the European Economic Area, the transfer is covered either by an adequacy decision of the European Commission or by the Commission Standard Contractual Clauses together with the supplementary measures set out in that provider data processing agreement. Copies of the relevant agreements are available on request.
8. Retention
Account and progress data are kept while the account is active and for 30 days thereafter, after which they are permanently deleted. Accounting/payment records are kept for the statutory period. Security logs: 12 months. Pending marketing confirmation tokens expire or are replaced. Confirmed consent and campaign-send evidence are kept while needed to demonstrate consent, honour suppression and meet legal obligations; raw unsubscribe tokens are not stored.
9. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may withdraw marketing or analytics consent at any time without affecting earlier lawful processing. Use Email Preferences or Cookie Settings, or contact support@neuronprep.com. You may also complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or to the supervisory authority of your own country of residence.
10. Cookies, consent and analytics
Strictly necessary authentication and security storage operates where required to provide the requested service. CookieYes is used to present and remember the user's categories and may keep a consent identifier/log. Google Analytics 4 (Measurement ID G-4RRDTCRNF4) is denied by default and is not requested by Neuron Prep until the user accepts analytics. The implementation disables advertising storage, Google Signals and ad-personalisation signals. A persistent Cookie settings control allows withdrawal. The current inventory, providers and typical durations are listed in the Cookie Policy and are reviewed when the site’s services or consent configuration change.
11. Security
We use database row-level security, encrypted transport, signed payment webhooks, verified email, least-privilege browser credentials, protected server secrets, refund/dispute revocation, and MFA for administrator accounts. No system is risk-free. We will handle incidents and notifications as required by law.
12. Children and changes
The service is for university-entry preparation and is not directed to children below 16. Material changes will be communicated when required.