Privacy
Last updated 19 August 2026
What we collect, why we collect it, how long we keep it, and how to get it back or get rid of it. Written to be read, not to be survived.
The short version
Right now this site is a set of pages and an email address. There are no accounts, no database of candidates and no payment processor, so the only personal information we hold is whatever you choose to put in an email to us. The rest of this notice describes what we will collect as the product ships, so that none of it arrives as a surprise.
Who is responsible
Medlinga is an independent project built by the Medlinga team, working remotely and internationally. We are not yet incorporated as a company; until we are, the team is responsible for the data described here, and the company name and registered address will be published on this page before accounts open.
For anything in this notice, write to support@medlinga.com. We reply within one working day.
Data protection law requires a designated Data Protection Officer and, for candidates in the EU and UK, a local representative once processing reaches a certain scale. We are nowhere near that scale — we process almost nothing — and both will be appointed and named on this page before accounts open.
What we collect
If you email us, we hold your email address and whatever you write, so that we can reply and so we know who asked to be told when the first mock opens.
When accounts ship, we will hold your email address, your profession and the country you are registering for, and your attempt data — the answers you gave, when you gave them, your scores, and the timing of each section. That last part is the material the diagnostic report is built from; without it there is no report.
Referral codes. If you arrive through a link carrying a ?ref= code, we store that code in a cookie on your device for 30 days so we can tell who recommended us. It contains no personal information, and no cookie is set if there is no code in the link.
When payments ship, card details will be handled entirely by our payment provider as merchant of record. We will never see or store them.
A note on the watermark
When exam content is on screen, we will render your email address across the page at low opacity. It is there so that if our questions appear somewhere they should not, we can tell where they came from. It means any screenshot you take of a test will carry your email address in it — worth knowing before you share one.
Why we are allowed to hold it
To deliver a test and show you your results, we rely on performing our contract with you. To keep the service secure and protect our content, we rely on our legitimate interests. For anything optional — marketing email in particular — we rely on your consent, and you can withdraw it at any time by replying to any message we send.
Your profession is not special-category data under GDPR. If we ever add a flow that accepts medical certificates for special testing arrangements, that would be health data, and we would revisit this notice before building it.
Where your data goes
Our hosting, email and infrastructure providers operate internationally, which means your data is processed outside the country you are in. We rely on the standard contractual protections those providers offer for international transfers, and each provider will be named on this page before accounts open.
We do not sell your data, and we do not share it with advertisers.
How long we keep it
If you start a test without an account and never come back, that anonymous record and its attempts are deleted after 30 days.
If you have an account, we keep your attempts for as long as the account exists, because the whole point of the report is to compare an attempt with the one before it. Delete your account and we delete them. Emails you send us are kept while they are useful for supporting you and then removed.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to how we use it, or ask us to send it somewhere else. Email support@medlinga.com and we will reply within one working day and act within the time the law allows. You can also complain to your local data protection regulator.
If something goes wrong
If your data is exposed in a breach, we notify the relevant regulator within 72 hours, and we notify you directly where the risk to you is high. We will say what happened rather than what sounds best.
Analytics
When the product opens we will measure how many people start a test, finish it, and come back — the numbers that tell us whether it works. We will not record your screen during a test, and we do not run advertising trackers. The tools we use will be named here before they are switched on.