Privacy Policy

Last updated: March 29, 2026

1. Who we are

EU·Now ("we", "us", "our") is an online platform for EPSO exam preparation, operated by SanJeMi S.L. For data protection inquiries, contact our Data Protection Officer at dpo@eu-now.com.

2. What data we collect

We collect the following categories of personal data:

2.1 Account data

  • Email address — for authentication (magic link login), communication, and account recovery
  • Display name — optional, for personalization
  • Language preference — to serve content in your language
  • Timezone — to schedule study reminders

2.2 Preparation data

  • Question attempts — your answers, correctness, and time spent per question
  • Essay submissions — full text of essays you write for EUFTE practice
  • Tutor conversations — messages exchanged with our AI tutor EUgenio
  • Study preferences — competition type, exam language, target date, study intensity
  • Progress scores — readiness scores, domain scores, streaks

2.3 Payment data

  • Subscription status and tier — stored by us
  • Payment details — handled entirely by Stripe; we never see your card number

2.4 Technical data

  • IP address — for rate limiting only; not stored persistently
  • Cookies — see our Cookie Policy

2.5 Newsletter subscribers

  • Email address — to send weekly EPSO preparation digests
  • Language preference — to send content in your language

3. Legal basis for processing

Processing activityLegal basis (GDPR Art. 6)
Account creation and authenticationContract performance (Art. 6(1)(b))
Serving questions and tracking progressContract performance (Art. 6(1)(b))
AI essay evaluation and tutorConsent (Art. 6(1)(a)) — you explicitly opt in
Payment processing via StripeContract performance (Art. 6(1)(b))
Newsletter emailsConsent (Art. 6(1)(a)) — double opt-in
Rate limiting (IP address)Legitimate interest (Art. 6(1)(f)) — preventing abuse
Security loggingLegitimate interest (Art. 6(1)(f))

4. AI data processing

Important: When you use the Essay Evaluation or AI Tutor features, your text is sent to Anthropic (Claude API) for processing. Specifically:

  • Essay text you submit is sent to Anthropic to generate evaluation scores and feedback
  • Tutor messages are sent to Anthropic to generate responses
  • Anthropic processes this data under their Privacy Policy and does NOT use your data for training
  • You can opt out by not using the Essay or Tutor features

We require explicit consent before processing your data with AI services. You can withdraw consent at any time by stopping use of these features and requesting deletion of your data.

5. Data processors (third parties)

ProcessorPurposeLocationSafeguards
SupabaseDatabase, authenticationEU (Frankfurt)GDPR-compliant, DPA
AnthropicAI essay evaluation, tutorUSASCCs, zero-retention API
StripePayment processingUSA/EUSCCs, PCI DSS Level 1
ResendTransactional and newsletter emailsUSASCCs, DPA
VercelWebsite hosting, CDNGlobal (EU edge)SCCs, DPA

6. Your rights

Under GDPR, you have the following rights:

  • Access — Download all your data from Settings → Export Data
  • Rectification — Edit your profile in Settings
  • Deletion — Delete your account in Settings → Delete Account
  • Portability — Export your data in JSON format from Settings
  • Object — Opt out of newsletter via unsubscribe link; opt out of AI processing by not using those features
  • Withdraw consent — At any time, for any consent-based processing

To exercise any right, email dpo@eu-now.com or use the self-service options in Settings.

7. Data retention

  • Account data — retained while your account is active; deleted within 30 days of account deletion
  • Question attempts — retained while your account is active
  • Essay submissions — retained while your account is active
  • Tutor conversations — retained while your account is active; you can delete individual conversations
  • Newsletter subscribers — retained until you unsubscribe
  • Payment records — retained for 7 years (legal obligation)

8. International data transfers

Your data is primarily stored in the EU (Supabase Frankfurt). When data is transferred to processors in the USA (Anthropic, Stripe, Resend), we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission to ensure adequate data protection.

9. Children

EU·Now is designed for adults preparing for EU institutional careers (typically 18+). We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact dpo@eu-now.com.

10. Data breach notification

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and affected individuals without undue delay if the breach poses a high risk to their rights and freedoms (GDPR Art. 34).

11. Changes to this policy

We may update this policy from time to time. We will notify registered users by email of any material changes. The date at the top of this page indicates the last revision.

12. Contact

Data Protection Officer: dpo@eu-now.com
General inquiries: hello@eu-now.com
Supervisory authority: You have the right to lodge a complaint with your local data protection authority.