Legal information

Privacy policy

Your privacy matters to us. This policy explains which personal data we process at SifG22 and its associated services —including the SifG Area platform, managed by SifG Edu—, for what purpose, for how long, with whom we do (not) share it and the rights you have over it. It is written in accordance with the GDPR, the Spanish LOPDGDD and the AEPD's guidelines.

Last updated: May 4, 2026 · Version 2026.05

1. Data controller

The controller of your personal data is SifG22, owner of the domain sifg.net and its associated subdomains and services, including the SifG Area exam platform, operated by SifG Edu.

  • Controller: SifG22
  • Services included: sifg.net, area.sifg.net (SifG Area), edu.sifg.net (SifG Edu) and other SifG22 subdomains and applications.
  • Privacy contact: support@sifg.net
  • Help center: help.sifg.net

If a Data Protection Officer (DPO) is formally appointed in the future, their contact details will be published in this section.

2. Scope and services covered

This policy applies to all services provided by SifG22, in particular:

  • sifg.net and institutional subdomains (blog, help, status).
  • SifG Area (area.sifg.net): online exam platform managed by SifG Edu. It allows tests to be taken, managed and marked, as well as tracking the user's progress.
  • SifG Edu (edu.sifg.net): the ecosystem's educational services.
  • SifG22 for Windows, distributed through the Microsoft Store.
  • All other products and services identified with the SifG22 brand.

Some services may have specific policies that complete or detail this policy. In case of discrepancy, the specific policy of that service will prevail.

3. Personal data we process

Below we list the categories of data we process. We only collect the data needed to provide the service and always respect the principles of data minimisation, purpose limitation and accuracy under article 5 of the GDPR.

3.1 Account data (sign-up with email and password)

  • Identifiers: name or username, email address.
  • Password: never stored in plain text. Only its hash is stored, generated with modern algorithms resistant to brute force (Argon2id or bcrypt with a high cost factor and a unique salt per user).
  • Optional data: profile photo, bio, app preferences.

3.2 Sign-in with external providers (Google and GitHub)

When you choose to sign in with Google or GitHub via OAuth 2.0 / OpenID Connect, we receive from the provider only the data strictly necessary to create or link your account:

  • Google: unique Google identifier, email address, name and public profile photo (when you authorise them).
  • GitHub: unique GitHub identifier, username, email address (if you've made it public or authorise access to it) and avatar.

We don't access contacts, private repositories, files, messages or any other information in your Google or GitHub account. Authentication takes place directly with the provider: we never know your Google or GitHub password.

3.3 Data generated by using SifG Area

  • Exams and tests: exams you sign up for, dates, time spent, answers and scores obtained.
  • Academic progress: statistics and progress metrics within the platform.
  • Account settings: school, subject, year or team, if you enter them.

3.4 Technical and security data

  • IP address and approximate geolocation (country/city level) derived from the IP.
  • Device and browser information (User Agent, operating system, language).
  • Access dates and times, security events (failed attempts, password changes).
  • Data stored in cookies and similar technologies, as detailed in the Cookie policy.

3.5 Communications

If you contact us (by email, form or help center), we process the content of the message and the identifying data you provide in order to handle your request.

4. What we use your data for

  • Create and manage your account (identification, authentication, linking with Google or GitHub if you choose to).
  • Provide the service: access to SifG Area, taking exams, storing results, progress, settings and preferences.
  • Communicate with you about incidents, essential updates, password recovery or relevant changes to the policy.
  • Handle requests and questions through the help center and support email.
  • Ensure the security of the service: fraud prevention, abuse detection, incident monitoring and response to unauthorised access.
  • Comply with legal obligations: accounting, tax, data protection or requests from competent authorities.
  • Improve the service: aggregated and anonymised statistical analysis of usage, without individual profiling.

We don't use your data for advertising purposes, sell it, or share it with advertisers or data brokers. We don't carry out profiling with legal effects or significant automated decision-making (see section 11).

6. Retention periods

We only keep your data for as long as necessary for the purposes described:

  • Account and SifG Area data: while the account is active.
  • After the account is deleted: your data is anonymised or erased, except for data we must keep blocked due to legal obligations or for the establishment, exercise or defence of legal claims, for the legally established periods.
  • Security and access logs: up to 12 months, unless incidents are identified that justify keeping them longer.
  • Support communications: the time needed to handle the request and, afterwards, up to 24 months for quality and traceability purposes.
  • Cookie decision: up to 12 months, in line with AEPD recommendations.

If your account remains inactive for an extended period, we may contact you and, failing a response, delete it automatically to minimise data.

7. Recipients and disclosures

SifG22 does not sell, rent or share your personal data with third parties for commercial purposes. Nor do we share it with advertisers, ad networks or marketing platforms.

Your data may be disclosed to:

  • Data processors that provide services to SifG22 (hosting, transactional email, security monitoring, third-party authentication). They act on behalf of SifG22 under a data processing agreement in accordance with article 28 of the GDPR. See section 8.
  • Competent authorities: judges, courts, law enforcement or public administrations, when there is a legal obligation, a court order or a valid request.
  • Federated identity providers (Google and GitHub): if you choose to sign in with one of them, a minimal exchange of data takes place to authenticate you. This exchange is also governed by the privacy policies of Google and GitHub.

8. Data processors

SifG22 relies on trusted technology providers to deliver the service. They only process your data on behalf of SifG22, following its instructions, with appropriate security measures and the confidentiality commitments required by the GDPR.

Usual categories of processors: cloud hosting, databases, transactional email, authentication, monitoring and observability. The up-to-date list of providers and the countries they operate from can be requested at support@sifg.net.

9. International transfers

Some providers we work with (for example, Google or GitHub for federated sign-in) may process data in countries outside the European Economic Area. When this happens, we ensure a level of protection equivalent to Europe's through:

  • European Commission adequacy decisions (for example, the EU-US Data Privacy Framework).
  • Standard Contractual Clauses approved by the European Commission.
  • Other appropriate safeguards provided for in articles 46 and 49 of the GDPR.

10. Data security

SifG22 applies appropriate technical and organisational measures to ensure the confidentiality, integrity and availability of data, in accordance with article 32 of the GDPR, including:

  • Communications encrypted with HTTPS/TLS.
  • Passwords stored only as a hash (Argon2id / bcrypt) with a random salt per user.
  • Role-based access control and the principle of least privilege.
  • Logging and monitoring of critical events.
  • Regular security updates and dependency reviews.
  • Encrypted backups and retention policies.
  • Incident response procedures and notification to the AEPD and affected users, where applicable, within a maximum of 72 hours, in accordance with articles 33 and 34 of the GDPR.

Despite these measures, no system is completely infallible: we ask you to use strong passwords and not to share them with anyone.

11. Automated decisions

Some exams in SifG Area are marked automatically (multiple-choice questions, answers with an objective key, etc.). This automatic marking produces no legal effects and does not significantly affect you within the meaning of article 22 of the GDPR, as you can always request a human review of the results from the teacher, school or person responsible for the exam.

We don't carry out profiling for advertising purposes or classifications that limit access to services or rights.

12. Your rights

As a data subject, you have the right to:

  • Access the personal data we process about you.
  • Rectify inaccurate or incomplete data.
  • Erase data when it's no longer necessary or when you withdraw your consent.
  • Restrict processing in certain cases.
  • Object to processing based on legitimate interest.
  • Port your data to another controller, in a structured, commonly used and machine-readable format.
  • Withdraw consent at any time, without retroactive effect.
  • Not be subject to automated decisions with legal effects.

You can exercise these rights by writing to support@sifg.net or through the help center. We'll respond to your request within one month at most, which may be extended to two months in particularly complex cases.

If you believe your rights have not been properly respected, you can lodge a complaint with the Spanish Data Protection Agency (AEPD), the supervisory authority in Spain.

13. Cookies and similar technologies

The use of cookies on our sites and apps is governed by the Cookie policy, which details which cookies we use, for what purpose and how you can manage them or withdraw your consent at any time.

14. Minors

Since SifG Edu and SifG Area are aimed at education, some students may be minors. Under article 7 of the Spanish LOPDGDD, in Spain processing the personal data of a child under 14 requires the consent of the holders of parental authority or guardianship.

Schools that use SifG Area with students under 14 are responsible for obtaining that consent and for informing them about the processing beforehand. In these cases, SifG22 will act as the school's data processor, under the corresponding agreement.

If you become aware that a child under 14 has provided data without the consent of their parents or guardians, let us know at support@sifg.net and we'll erase it.

15. Changes to the policy

SifG22 may update this Privacy policy to reflect regulatory, case-law or service changes. When the changes are substantial, we'll notify you prominently (banner, email or in-app notice) with reasonable advance notice. The date of the last update appears at the top of this page.

16. Contact and complaints

For any privacy question, to exercise your rights or to make a complaint, you can contact us through:

You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) if you believe your right to data protection has been infringed.

Want to review the terms of service too?

Go to the Terms of use