General Data Protection Regulation (GDPR) Compliance
Last Updated: July 29, 2025
Introduction
Merxtechnology is committed to protecting the privacy and security of personal data. This GDPR Compliance Statement explains how we collect, use, store, and protect your personal information in accordance with the General Data Protection Regulation.
Data Controller
Merxtechnology operates as the data controller for personal information collected through our platform. You can contact us at:
- Email: help@merxtechnology.com
- Phone: +3725022920
- Address: Vaksali 17, 50410 Tartu, Estonia
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
- Legal Obligation: Processing is necessary for us to comply with the law
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests
Personal Data We Collect
We may collect and process the following categories of personal data:
Account Information
- Full name
- Email address
- Username and password
- Profile information
Learning Activity Data
- Quiz responses and test results
- Course progress and completion status
- Time spent on learning activities
- Performance metrics and scores
Technical Data
- IP address
- Browser type and version
- Device information
- Operating system
- Usage data and analytics
Communication Data
- Messages sent through our platform
- Feedback and survey responses
- Support requests and correspondence
How We Use Your Personal Data
We use your personal data for the following purposes:
- Providing access to educational content and interactive learning features
- Tracking your learning progress and quiz performance
- Personalizing your learning experience
- Communicating with you about your account and our services
- Improving our platform and developing new features
- Ensuring security and preventing fraud
- Complying with legal obligations
- Analyzing usage patterns to enhance user experience
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Active Accounts: Data is retained while your account remains active
- Closed Accounts: Data may be retained for up to 90 days after account closure, except where longer retention is required by law
- Legal Requirements: Some data may be retained longer to comply with legal, accounting, or reporting obligations
- Legitimate Interests: Certain data may be retained to resolve disputes, enforce agreements, or for other legitimate business purposes
Your Rights Under GDPR
You have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw your consent at any time.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
Exercising Your Rights
To exercise any of your rights, please contact us at help@merxtechnology.com. We will respond to your request within 30 days. We may need to verify your identity before processing your request.
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Regular security assessments and audits
- Access controls and authentication mechanisms
- Employee training on data protection
- Incident response procedures
Data Transfers
Your personal data may be transferred to and processed in countries outside your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Other legally approved transfer mechanisms
Third-Party Processing
We may share your personal data with third-party service providers who process data on our behalf. These processors are contractually obligated to:
- Process data only according to our instructions
- Implement appropriate security measures
- Maintain confidentiality
- Assist with fulfilling your data subject rights
- Delete or return data when the processing relationship ends
Automated Decision-Making
We may use automated processing to personalize your learning experience and provide adaptive content recommendations. You have the right to:
- Request human intervention in automated decisions
- Express your point of view regarding automated decisions
- Contest decisions made solely by automated means
Children's Privacy
Our platform is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our platform. You can control cookie preferences through your browser settings. For detailed information, please refer to our Cookie Policy.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
- Inform affected individuals without undue delay if the breach poses a high risk
- Provide information about the nature of the breach and measures taken to address it
Changes to This Statement
We may update this GDPR Compliance Statement from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by posting a notice on our platform or sending you an email. The date at the top of this statement indicates when it was last updated.
Contact Information
If you have questions about this GDPR Compliance Statement or our data processing practices, please contact us:
- Email: help@merxtechnology.com
- Phone: +3725022920
- Address: Vaksali 17, 50410 Tartu, Estonia
Supervisory Authority
If you are not satisfied with our response to your concerns, you have the right to contact your local data protection supervisory authority.