Practice SittingPractice for the ICF credential exams

Legal

Privacy Policy

Last updated: 24 September 2026

This policy explains what personal data Practice Sitting (practicesitting.com) collects, why, and what rights you have. In short: we collect what is needed to run your account and your study, we do not sell data, we do not advertise, and we do not send your data to AI providers.

1. Who is responsible

The data controller is Leading srl STP, Via Lazzaretto 1, 20060 Gessate (MI), Italy, VAT IT11516580963. Contact: carlo@carloperfetto.com.

2. What we collect

We do not collect special categories of data. We do not use tracking, advertising or profiling cookies, and we load no analytics scripts.

3. Why, and on what legal basis

Your score is a readiness indicator for your own use. We make no automated decision about you that has legal or similarly significant effects (Art. 22 GDPR).

4. Who processes data for us

Where these providers process data outside the EU/EEA, transfers rely on the European Commission's Standard Contractual Clauses or on the EU–US Data Privacy Framework, as applicable.

AI. The questions are written with the help of AI models before publication. The service does not send your account, your answers or your study data to any AI provider.

5. How long we keep data

6. What we store in your browser

The app keeps your session token, your chosen language and some display preferences in your browser's local storage. During Google or LinkedIn sign-in it sets one short-lived cookie that protects the sign-in against forgery. All of these are strictly necessary for the service to work, so no consent banner is required. None of them is used to track you.

7. Your rights

Under the GDPR you can ask to access your data, correct it, delete it, receive it in a portable format, restrict its processing, or object to processing based on legitimate interest. Write to carlo@carloperfetto.com from the address on your account. We reply within one month. You can also complain to the Italian data protection authority, the Garante per la protezione dei dati personali, or to the authority in your country.

8. Security

All traffic is encrypted with HTTPS. Passwords are stored only as salted hashes. Sessions use signed tokens. Only the application itself can reach the database. Sign-in codes from Google and LinkedIn are single-use, expire within minutes and are stored only as hashes.

9. Age

The service is for adults preparing for a professional credential. It is not directed at anyone under 18, and we do not knowingly collect their data.

10. Changes

If we change this policy in a material way, we will email registered users and update the date above.