Privacy Policy
This policy explains what personal data 41Q processes, why, for how long and what rights you have.
Updated 23 August 2026
1. Controller and contact
The controller is Raketforskning AB, Swedish organisation number 556908-7496, VAT number SE556908749601, 4:e Villagatan 10, 653 41 Karlstad, Sweden. The company is represented by managing director Robert Carlesten. Privacy requests: [email protected]. No data protection officer has been appointed.
2. Data processed
Personality-test answers are processed in your browser and while the result is calculated. 41Q does not store each individual answer in the results database. An unfinished test remains only in sessionStorage in the current browser tab and is removed when the tab is closed.
When you visit, technical records may include IP address, time, requested URL, referrer, device and browser details. If you rate a result, we store the language, internal profile identifier, rating, selected general reasons and questionnaire/profile versions, without your name or free text.
New result links use a random token that is associated on the server only with a result code. The link does not contain your name. Older numerical result links remain readable for compatibility and may have no fixed technical expiry.
3. Purposes and legal bases
We process the data needed to provide the test and result you request, normally under Article 6(1)(b) GDPR. Security records, abuse prevention and quality analysis rely on our legitimate interest in protecting and improving the service, Article 6(1)(f). Contact messages are processed to respond and, depending on the request, for contractual steps or legitimate interests.
Where consent is legally required for non-essential analytics, advertising or social-media technology, the intended basis is Article 6(1)(a). Current technical limitation: some non-essential tags may load when a page opens, before a valid consent choice has been made. This is a known compliance exception and is also disclosed in the Cookie Policy; we do not claim that effective prior consent is already obtained.
4. Recipients and international transfers
Providers may process data for hosting, CDN/security, email, analytics and, where active, advertising or social functions. They may include WP Engine, Cloudflare, Google, Meta and Mailgun or another email provider. Processing may occur in Sweden, elsewhere in the EEA and in the United States.
Where required, transfers rely on a recognized mechanism such as an adequacy decision, the EU-US Data Privacy Framework, current Standard Contractual Clauses and supplementary safeguards.
5. Retention
- Unfinished answers: until the current browser tab is closed.
- New result tokens: no more than 30 days.
- Ratings and selected reasons: no more than 24 months, followed by deletion or strictly anonymous aggregation.
- Older numerical result links: no fixed technical expiry; share them only with people you trust.
- Technical and security logs: normally no more than 30 days unless a specific incident, legal hold or provider setting requires longer.
- Contact correspondence: normally no more than 12 months after a matter is closed unless a contract, claim or legal duty requires longer.
- Provider cookies and events: according to the Cookie Policy and provider configuration.
6. Your rights
Depending on the law that applies, you may request confirmation and access, correction, deletion, restriction, portability, information about disclosures or object to processing based on legitimate interests. You may withdraw consent for future processing at any time. Email [email protected]; we may request proportionate information to verify the requester.
You may complain to the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.
7. Rights outside the EU/EEA
We accept privacy requests regardless of where you live. 41Q does not sell personal data for money. Some US state laws may nevertheless classify disclosures to analytics or advertising providers as “sharing” or targeted advertising. There is currently no fully functional site-wide opt-out or Global Privacy Control mechanism; browser protections and provider opt-outs may limit processing.
8. Results, age and sensitive data
41Q provides an informational self-assessment. It does not make decisions with legal or similarly significant effects and is not a medical, psychological, employment or suitability tool. The service is intended for people aged 16 or over. Do not send health data or confidential test results by email.
9. Security and changes
We use encrypted transport, access restrictions, data minimization and retention rules. No Internet service is risk-free. Material changes will be published here with a new update date.
Comparisons with others
On the English 41Q site, you can choose to create a comparison or respond to an invitation. Your profile, connections and display name are used to provide the service you request. Optional preferences and public participant cards require your separate choices. Invitations expire after 90 days; you can delete them sooner.
Read about shared data, retention periods and your rights when using comparisons.
Newsletter
If you choose to subscribe, 41Q processes your email address, selected language and market, and timestamps and technical evidence of consent and confirmation. Your name is optional. When you subscribe on a result page, your profile code and questionnaire version are also stored; the test date is stored when available. The profile is linked to the subscription. Your individual test answers are not stored as newsletter data. Delivery, bounce, complaint, click and unsubscribe events may be recorded to operate and protect the service. Open tracking is off by default.
The purposes are to send 41Q newsletters and personality insights by email, including content that may be selected or tailored to your 41Q profile, manage the subscription and demonstrate consent. Sending and the profile link are based on your explicit consent. You may withdraw consent or object to direct marketing at any time through the link in every email or the contact details in this policy. Newsletter sending stops after you unsubscribe.
Active data is kept until you unsubscribe or it is no longer needed. Identifying details and test history are then minimized after 30 days, campaign-recipient detail after 180 days, and consent evidence after three years. A keyed suppression record and limited consent history may be retained as long as necessary to respect your objection and demonstrate compliance. Data is protected using encryption and keyed hashes. The rest of this policy explains the controller, contact details, processors, transfers and your rights.