Privacy Policy
Last updated: 15 May 2026. We comply with UK GDPR and the Data Protection Act 2018. This policy explains what we collect, why, and your rights.
1. Who we are
The passmed.uk website is operated by Passmed Pte. Ltd. ("Passmed", "we", "us"), a company registered in Singapore. We are the data controller for the personal information you provide on this site. For all data protection matters, contact us at support@passmed.com.
2. What we collect
When you create an account: your name, email address, and password (stored hashed - we never see your actual password).
When you use the service: your question attempts, scores, time spent, flagged questions, and progress data. This is necessary for the service to work - without it we can't show you analytics or save your progress.
When you subscribe: your billing details are collected and processed by Stripe (our payment processor). We store your subscription status, plan, and billing email - never your full card number.
Automatically: your IP address, browser type, device type, and pages visited. We use this for service security, fraud prevention, and to understand which features are used.
3. Why we use it
To provide the service: serving questions, saving your progress, showing analytics, processing payments.
To improve the service: anonymised, aggregated usage statistics to understand what's working and what isn't.
To communicate with you: transactional emails (account, subscription, trial ending) and, if you have subscribed to a paid plan, occasional product update emails about features and content similar to what you've purchased. You can unsubscribe from product update emails at any time using the link in any email or from your account settings.
For institutional users: cohort-level reporting to your faculty as part of your institutional licence (see section 5 on joint controllership).
4. Legal basis (UK GDPR)
We process your data under the following lawful bases:
Contract - to provide the service you've signed up for, process your payment, and deliver the question banks and analytics features.
Legitimate interests - for service security, fraud prevention, product improvement, and (for paid subscribers) sending product update emails about similar features under the "soft opt-in" basis permitted by the Privacy and Electronic Communications Regulations (PECR). You can object to this at any time.
Legal obligation - for retention of payment and tax records.
5. Who we share with
We share your data only with service providers necessary to operate Passmed: Stripe (payments), Brevo (transactional email), Google Cloud (hosting), and Cloudflare (DDoS protection and CDN). Each is bound by a data processing agreement and processes your data on our instructions only.
Institutional users - joint controllership. If you access Passmed through an institutional licence (for example, your medical school, deanery, or NHS trust), Passmed and your institution act as joint controllers for cohort reporting and account management. Under Article 26 UK GDPR, the essence of our arrangement is that your institution determines who accesses Passmed under its licence and reviews cohort performance reports; Passmed determines the technical and editorial nature of the service. Both parties may view and manage your account in connection with the institutional licence. Your statutory rights under sections 7 and 8 below can be exercised against either party. Contact support@passmed.com for the joint-controller arrangement in full.
We never sell your data to third parties.
6. International transfers
Passmed is operated from Singapore. Some of our service providers are based outside the UK. Where data is transferred outside the UK, we use the UK International Data Transfer Agreement (or the EU Standard Contractual Clauses with the UK Addendum) to ensure your data is protected to UK GDPR standards.
7. How long we keep it
Account data: while your account is active, plus 12 months after closure (for legal and accounting purposes). Question attempt data: while your account is active, plus 6 months. Anonymised aggregate data: indefinitely. Payment records: 7 years (for tax compliance).
8. Your rights
Under UK GDPR you have the right to: access the data we hold on you; correct inaccurate data; delete your data (subject to our legal retention requirements); restrict or object to processing; and data portability (receive your data in a machine-readable format).
To exercise any of these rights, email support@passmed.com. We'll respond within 30 days.
You also have the right to complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk if you're not satisfied with our handling of your data.
9. Personal data breaches
In the unlikely event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, and notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms, as required by Articles 33 and 34 UK GDPR.
10. Cookies
We use cookies for: keeping you logged in (essential), remembering your preferences (functional), and understanding aggregate site usage (analytics, via Google Analytics with IP anonymisation). Non-essential cookies are only set after you give consent via our cookie banner. You can manage your consent at any time via the cookie settings link in the footer; disabling essential cookies will mean you can't log in.
11. Children
Our service is not directed at and we do not knowingly process personal data of anyone under 18. By creating an account, you confirm you are 18 or older. If you believe we have collected data from someone under 18, please contact support@passmed.com immediately and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to all account holders at least 30 days before they take effect.
13. Contact
Questions about your data, or to exercise any of your rights? Email our privacy team at support@passmed.com.