TestPrep — Worldwide Online Tutoring
Legal

Privacy Notice

This notice describes what personal data apcourses.net collects, the lawful basis we rely on for each purpose, which companies process it on our behalf, where in the world it travels, and how you exercise your rights. It is written from what the site actually does. It does not describe things we do not do.

Last updated:

Three things on this page are still outstanding

The processing described below is complete and accurate. But the following are not yet settled, and we would rather show you the gap than fill it with something plausible:

  • our EU and UK Article 27 representatives

None of this blocks a request. Write to info@testprepeurope.com and we will answer within one month, as the GDPR requires.

1. Who is responsible for your data

The controller — the company that decides why and how your personal data is processed — is the entity below. It trades as TestPrep and operates apcourses.net.

Legal entity
TestPrep LLC.
Registered office
777 NW 72nd Ave STE 1075, Miami, FL 33126, United States
Türkiye office
Acıbadem, Acıbadem Cd. No: 188 D:1, 34660 Üsküdar/İstanbul
Email
info@testprepeurope.com
Phone
+44 7862 610215

We are established outside the UK and the EEA

This is the most consequential fact on the page, so it comes first rather than last. TestPrep LLC. is a limited liability company registered in Florida, in the United States. It has an office in İstanbul, but no establishment in the United Kingdom or the European Economic Area.

Two things follow. Almost everything described below is an international transfer, covered in section 5. And because we offer services to people in the UK and the EEA from outside them, Article 27 of each regime asks us to designate a written representative there.

We have not designated one yet. We are not going to claim otherwise on a page whose entire purpose is to tell you the truth about your data. Until that changes, contact the controller directly at info@testprepeurope.com; a request loses none of its force for being sent to us rather than to a representative, and the one-month deadline applies either way. Current status: EU and UK Art. 27 representatives — TO BE COMPLETED.

2. What we collect, and how

Four things, and nothing else. We do not buy data, we do not enrich it from third-party sources, and we do not build advertising profiles.

a. When you ask us to contact you

The enquiry form collects your name, email address, phone number, the subject you are asking about and your message. It also records which page you submitted from, so we can answer in context. You type all of it yourself; none of it is inferred.

b. When you buy lessons

Payment is taken by Stripe. Stripe's checkout runs inside our page rather than redirecting you away, but your card details go to Stripe, never to us — we never see or store a card number. What reaches us is the outcome: which package, the amount charged in Euro, and Stripe's reference for the payment.

c. When you leave a comment

The name and comment you submit, held for moderation before anything appears publicly.

d. While you browse

Google Analytics 4 records the pages you visit and the broad technical characteristics of your visit — but only if you have said yes to it. See section 6. Separately, our server keeps a short-lived count of requests per IP address to stop the enquiry form being abused. That count is a number against an address; it is not a profile and it is not used to identify you.

3. Why we process it, and on what lawful basis

The GDPR requires a specific lawful basis for each purpose, not one blanket justification. Ours are below. Where we rely on legitimate interests we say what that interest is, so you can weigh it.

PurposeDataLawful basis (Art. 6)
Answering your enquiry and arranging lessonsName, email, phone, messageArt. 6(1)(b) — steps taken at your request before entering a contract
Delivering and administering tuition you have boughtContact details, purchase recordArt. 6(1)(b) — performance of the contract
Taking payment and keeping the payment recordPurchase details via StripeArt. 6(1)(b), and Art. 6(1)(c) for the retention that accounting law requires
Publishing a comment you submittedName, comment textArt. 6(1)(a) — consent, given by submitting it
Preventing abuse of the enquiry formIP address, as a short-lived counterArt. 6(1)(f) — our legitimate interest in a form that is not flooded with automated submissions, which also protects you from being impersonated
Measuring how the site is usedAnalytics cookies and the events they carryArt. 6(1)(a) — consent, and only after you give it

You can object to anything resting on legitimate interests, and withdraw consent for anything resting on consent, at any time — section 8 explains how. Withdrawing consent does not affect processing already carried out.

4. Who else handles your data

These companies process data on our instructions. They are not free to use it for their own purposes.

ProcessorWhat forWhat it receives
StripeTaking payment, and fraud checks on itCard details, purchase amount and reference
SupabaseThe database holding enquiries and commentsEverything you submit through a form
ResendDelivering your enquiry to us by emailThe contents of the enquiry
VercelHosting and serving the siteRequest data, including IP address, as any web server receives
UpstashThe abuse-prevention counterIP address, briefly (Primary: London, United Kingdom (eu-west-2) · Read replica: Frankfurt, Germany (eu-central-1))
GoogleAnalytics — only with your consentPage views and interaction events

We do not sell personal data, we do not share it with data brokers, and no advertising network runs on this site.

5. Where your data goes

We are established in the United States and our processors are spread across several countries, so if you are in the UK or the EEA your data leaves it. That is not incidental to how the service works; it is how the service works, and you should know it before you decide to use us.

Transfers to the United States and to other countries outside the UK/EEA rely on the safeguards in Chapter V of the GDPR — in practice the standard contractual clauses that our processors incorporate into their terms, and, for those certified under it, the EU–US Data Privacy Framework. You may ask us which mechanism applies to a particular processor and we will tell you.

6. Cookies and measurement

One thing on this site is behind a consent gate, and three things deliberately are not. We would rather explain the distinction than present a wall of toggles that governs nothing.

Behind the gate

Google Analytics 4 is the only thing here that writes a measurement cookie. It does not run until you accept it. Before you decide — and permanently if you decline — Google Consent Mode holds every storage signal at denied, so analytics receives at most a cookieless ping that cannot be tied back to you.

Outside the gate, and why

Your consent choice itself is stored in a cookie that lasts 180 days. Remembering that you said no is the only way to avoid asking again on every page, and a cookie whose sole purpose is to record a refusal does not itself require consent.

Stripe's cookies are set only on the checkout page, only because you went there to pay, and only to detect fraud. Stripe will not process a card without them. They are never set anywhere else on the site.

Vercel Web Analytics stores nothing on your device at all. It counts a visit using a hash derived from the incoming request, and discards it after 24 hours. The consent rules bite on storing or reading information on your device; there is nothing here to store or read.

The fonts are served from our own domain, so your browser never contacts Google Fonts. There is no advertising category on this site because there is no advertising on this site.

You can change your mind whenever you like: open cookie preferences.

7. How long we keep it

RecordKept for
Enquiry submitted through the form24 months from last contact, then deleted automatically
Payment and invoice recordsAs long as accounting and tax law requires, then deleted
Published commentUntil you ask us to remove it
Analytics events14 months, then deleted automatically by Google
Your consent choice180 days, then we ask again
Abuse-prevention counterOne hour

The first row is honest rather than tidy: nothing in our system currently deletes an old enquiry on a schedule. Setting that period is a decision we owe you, and it is one of the outstanding items flagged at the top of this page. In the meantime, ask us to delete yours and we will.

8. Students under 18

Most of our students are school age, and we expect a parent or guardian to make the arrangements. If you are under 18, please have a parent or guardian contact us rather than submitting the form yourself. If we learn that we hold data about a child without that involvement, we delete it.

9. Security

The site is served over HTTPS. Enquiries and comments sit in an access-controlled database, card details never touch our systems, and the number of people who can read an enquiry is small and limited to those who need to answer it. No system is beyond compromise; if one that affects your data occurs, we will tell you and the relevant supervisory authority as the GDPR requires.

10. Your rights

Under the UK and EU GDPR you can ask us to do all of the following. You do not need a reason, and exercising a right costs nothing.

RightWhat it means here
Access (Art. 15)A copy of what we hold about you
Rectification (Art. 16)Correction of anything wrong or incomplete
Erasure (Art. 17)Deletion — except where tax or accounting law requires us to keep a payment record
Restriction (Art. 18)We hold it but stop using it while a dispute is open
Portability (Art. 20)Your data in a machine-readable form, or sent to another provider
Objection (Art. 21)An objection to anything we base on legitimate interests
Withdraw consent (Art. 7)Turn analytics off again, or ask us to unpublish a comment

We answer within one month. There is no automated decision-making or profiling on this site, so Art. 22 does not arise.

11. How to ask, and how to complain

Email is the fastest route and the one we monitor. Tell us what you want and enough detail to find your record.

If you are not satisfied with our answer

You can complain to a data protection supervisory authority. In the United Kingdom that is the Information Commissioner's Office. In the EEA it is the authority for the country where you live, where you work, or where the problem happened — your choice. Complaining to them does not stop you also raising it with us, and we would rather you did both.

12. Changes to this notice

When the facts change — a new processor, a different retention period, an Article 27 representative appointed — we change this page and move the date at the top. We do not backdate it. If a change materially affects how we use data you have already given us, we will tell you rather than relying on you to re-read this page.

The Turkish site apozelders.org publishes its own notice under Türkiye's KVKK, which asks different questions of us. Neither page overrides the other; each covers the site it is published on.

WhatsAppGet info