Kognita The Swiss IQ test

Privacy policy

What Kognita collects, why, for how long and who else sees it. With Google Analytics, a shortened IP address and two cookies, under the Swiss revDSG.

As of: 2026-09-13

This translation is provided for convenience. In case of discrepancy, the German version prevails.

This policy tells you which data we collect, why we do it, how long we keep it and who else gets to see it. It is written under the revised Swiss Federal Act on Data Protection, which has been in force since 1 September 2023. It is at the same time built so that it covers the requirements of the European General Data Protection Regulation, in case that regulation applies to us.

We have tried to keep it readable. If something stays unclear, ask us.

In short

What is measured on this site and what is not:

  • We measure reach with Google Analytics 4. Two cookies then sit in your browser, and your IP address is shortened. How to switch that off is set out below.
  • Alongside it we count ourselves and without a cookie, on our own server. That count recognises nobody.
  • Fonts, icons and images sit on our own server. Apart from Google’s counting code, nothing external is loaded when a page opens.
  • There are no advertising cookies, no ad networks and no social media buttons here. We do not sell data.

Until recently this passage said that the site set not a single cookie and measured nothing at all. Since reach measurement was introduced that is no longer true. We would rather write it down than hide it.

Anyone who takes an intelligence test gives away something personal. So the line that matters stays where it was: your answers and your result go to nobody. Google learns which page was opened, not how you scored.

Which law applies here, if you are used to the GDPR

Many of our readers have moved to Switzerland from an EU country or from the United Kingdom and arrive with a set of expectations from the GDPR. A short orientation, so that you know where you stand.

Switzerland is not in the EU, and the law that governs this site is Swiss. It is the revised Federal Act on Data Protection, in German the Datenschutzgesetz, usually shortened to revDSG. The revision came into force on 1 September 2023 and brought Swiss law close to the GDPR in substance: the same duty to inform, the same right to information about your data, the same rules on international disclosure, the same obligation to report serious breaches. The article numbers differ, the level of protection does not.

The fact that our servers stand in Germany does not by itself make the GDPR apply. A hosting provider is not an establishment of the provider, and a data centre in an EU country does not turn a Swiss business into an EU business. The GDPR would become applicable if we deliberately targeted people in the European Union, which we do not: we quote prices only in Swiss francs and we write about Swiss schools, Swiss cantons and Swiss procedures.

We have nevertheless built this text to cover the GDPR as well, for the case that it does apply to us. Where the two sets of rules describe the same thing under different names, we name both. And if you contact us from the European Union, we will handle your request by the same standard rather than argue about jurisdiction.

Your rights are the ones you would expect: information about what we hold, correction of anything wrong, deletion, objection to a processing operation, and a copy of the data you gave us. You exercise all of them with one e-mail to the address at the end of this page. There is no form, no fee and no account to log into. The section “Your rights” below sets out each of them.

There are two cookies, and there is still no consent banner. Both belong to the reach measurement; the site itself sets none. The banner you have clicked away on every other site is missing here because Swiss law asks something different of us than EU law does: not your consent, but our information. Art. 5(3) of the EU ePrivacy Directive, the provision the banners come from, has no counterpart in Swiss law. What the revDSG demands instead is that we tell you what happens, which is what this page does. The section “Why there is still no cookie banner” sets out the difference with the articles, because it is the honest answer to a question an EU or UK reader will have.

Who is responsible for your data

The controller within the meaning of the Data Protection Act is:

Kai Schnider Bleuenweg 4 2542 Pieterlen Switzerland

E-mail: kontakt@kognita.ch

Send all data protection matters to this address, in particular requests for information.

Which data we process

Test answers and timestamps

When you work through the test, we store the answers you select, the order in which the tasks were presented, the time you needed, and the start and end of the test. From these we calculate your result.

These data are not linked to your name at first. They hang on a randomly generated session number. Only when you order a report and give us your e-mail address does a connection arise between you as a person and your result.

Purpose: calculating the result, producing the report, safeguarding the quality of the test. Basis: for taking the free test, your consent, which you give by starting the test. For the report you ordered, the overriding interest in performing the contract under Art. 31 para. 2 lit. a DSG, in the language of the GDPR the performance of a contract under its Art. 6 para. 1 lit. b. Duration: without an order we delete the session after 90 days. With an order we keep the result and the answers for as long as we have to be able to send you the report again, at most 24 months.

E-mail address

We collect your e-mail address only if you order a report. We need it to send you the report and the confirmation.

There is no registration here. You do not create an account and you do not choose a password.

Purpose: delivery of the report, order confirmation, queries about the order. Basis: performance of the contract, Art. 31 para. 2 lit. a DSG. Duration: 24 months from the order. Payment records are kept separately from this, for as long as the bookkeeping obligation requires.

We send you no advertising unless you have expressly asked for it.

Server logs and shortened IP address

Every call to a web page leaves a trace on the server. We log the date and time, the address called, the status code returned, the volume of data, and the browser and operating system reported.

We store your IP address only in shortened form. The last block is removed before it is written to the log. It can no longer be attributed to an individual person.

Purpose: operation, fault finding, defence against attacks and automated access. Basis: overriding interest in secure operation. Duration: 14 days, then automatic deletion.

Alongside Google Analytics we also count on our own server. This count existed before the measurement by Google, and it stays.

For each event we store a timestamp, the kind of event and one short detail: for a page view the address called, at the start of a test the language, on submission the result band, on a purchase the tier chosen and the amount. No IP address, no cookie, no session number and no identifier that would recognise a browser from one call to the next. The entries stand on their own and are linked neither to your session nor to your order or your e-mail address.

This count keeps running even if you switch off the measurement by Google. We keep it because it needs no outside provider and because it lets us check whether Google’s figures are plausible.

Payment data

We never see your card number or any of your other payment details. You enter those directly with our payment service provider.

From the payment we receive back: whether it succeeded, the amount, the currency, the time, a transaction number and the last digits of the card or the payment method. We need no more than that and we get no more than that.

Purpose: processing the payment, matching it to the order, refunds, bookkeeping. Basis: performance of the contract, Art. 31 para. 2 lit. a DSG. Duration: payment records ten years, in line with the commercial retention obligation.

A note on the contract itself, because expectations differ by country: what you buy, what it costs in Swiss francs and how a refund works is set out in Refunds and in the terms. Swiss law gives no statutory right of withdrawal for online orders. The Code of Obligations lists the situations in which a contract can be revoked, and buying on a website is not among them, so there is no cooling-off period here to invoke. The 14 days we offer are a voluntary commitment, binding on us because we have written it down, and not an entitlement conferred by law.

Your IP address when you place an order

When you buy something, we store your full IP address and your browser identifier together with the order. This is an exception to the shortening in the server log, and we tell you openly why.

With a digital product, someone can ask their bank for a chargeback after downloading and claim they never ordered. Without evidence, a provider loses that case almost every time. We therefore log, per order: when you agreed to the terms, from which address, when you paid and when you downloaded the report.

Purpose: evidence towards card issuers in the event of a disputed payment. Basis: overriding interest in defending against unjustified chargebacks. Duration: 180 days. After that the IP address is automatically removed from the log; the rest of the entry remains as evidence of use. The deadlines of the card networks are considerably shorter than half a year, so we do not need the address for longer.

Cookies

Two cookies sit in your browser. Both belong to the reach measurement:

  • The cookie _ga tells browsers apart. Lifetime two years by default.
  • The cookie _ga_ followed by the container id holds the state of the running measurement. Lifetime two years by default.

Both are first-party cookies. They sit under our own address rather than under that of an ad network, and no other site reads them. There is no advertising cookie among them, none for recognition on other sites and none for resale.

Beyond those, this site sets no cookie, not even a technically necessary one. Your progress through the test hangs on the address in the browser bar. When you start the test you get an address with a random string in it, and your answers sit under that address. As long as you have the address, you can reach your result. If you lose it, the result cannot be restored by us, because we link it to no person.

Because Swiss law asks for something other than what EU law asks for: not your consent, but our information.

The banners you know from other sites go back to Art. 5(3) of Directive 2002/58/EC, as amended by Directive 2009/136/EC. That provision requires consent before anything is stored on your device or read from it, whether or not personal data are involved. The click-through in front of the first sentence of text comes from there.

The revised Swiss Data Protection Act has no such provision. It does not attach to storage on the device but to the processing of personal data, and what it demands for that is, first of all, transparency. Art. 19 DSG obliges us to inform you adequately about the collection, as a minimum about our identity, the purpose of the processing and the recipients, and, where data are disclosed abroad, also about the country and where applicable the safeguards. That duty is precisely what the text you are reading discharges.

Consent would be a different matter. Art. 6 para. 6 DSG determines when a consent is valid at all, and para. 7 requires it to be explicit for the processing of particularly sensitive personal data and for high-risk profiling. Measuring reach with a shortened IP address is neither. It tells us which page was read, not who you are.

So we put the measurement on the record and show you two ways to switch it off further down, rather than putting a window in front of the text. A banner you click away in order to keep reading is not a choice.

Where your data goes

We do not sell data. We pass it on only where the operation requires it. That is four places.

Hetzner Online GmbH, Germany

Our servers are with Hetzner Online GmbH at the Falkenstein site in Germany. Hetzner runs the machines on which the website and the database operate, and acts as a processor under Art. 9 DSG. Hetzner does not look at your data and does not use it for its own purposes.

Germany stands first among the states with adequate data protection in Annex 1 of the Data Protection Ordinance. The disclosure is therefore permitted under Art. 16 para. 1 DSG without additional safeguards.

Google, measuring reach

For measuring reach we use Google Analytics 4, measurement id G-HB4ZNY0QDR. When a page opens, your browser loads the counting code from a Google server. Google thereby learns your IP address, the address called, details of your browser and device, and the two cookies named above.

anonymize_ip is explicitly set in the counting code. In Google Analytics 4 the IP address is shortened and not stored in any case, and that cannot even be switched off there. We set the flag regardless, so that it does not depend on a default that could change.

Our contracting party is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Ireland is listed in Annex 1 of the Data Protection Ordinance among the states with adequate data protection. The disclosure is therefore permitted under Art. 16 para. 1 DSG without additional safeguards.

Google Ireland passes data on to Google LLC in the United States. The United States appear in Annex 1 of the Data Protection Ordinance only for organisations certified under the Swiss-US Data Privacy Framework. We looked this up on 13 September 2026 in the official participant list at dataprivacyframework.gov: Google LLC in Mountain View is listed there with a certification for the Swiss-US Data Privacy Framework, shown as active, with its re-certification under review. The entry names the Swiss Federal Data Protection and Information Commissioner as the recourse body. The disclosure rests on that entry.

Purpose: measuring reach, improving the content. Basis: overriding interest in knowing which content is read. Duration: the two cookies run for two years unless you delete them earlier. How long Google keeps the measured data depends on the retention setting of the property and on Google’s own periods.

Your test answers and your result are not passed to Google. The counting code reports page views. The scoring of the test runs on our own server, and there is no point at which a result is handed to Google.

How to switch the measurement off. Two ways, both effective immediately:

  • Google’s browser add-on. It switches Google Analytics off for every site you visit, and is available at https://tools.google.com/dlpage/gaoptout for the common desktop browsers.
  • Your browser settings. You can block cookies for this site or delete the ones already there. Note that a block aimed only at third-party cookies does not catch the two counting cookies, because they are first-party cookies. The tracking protection built into several browsers already blocks the counting code itself.

Stripe, payment processing

We process the payment through Stripe, whichever payment method you choose. Stripe receives from us the amount, the currency and an order number. You enter your payment details directly with Stripe.

Stripe does not receive your test result. Nor does it receive your answers. Payment and evaluation are separate in our system.

Stripe processes the payment data in part as an independent controller, for example for fraud prevention and because financial market law requires it. To that extent Stripe’s own privacy policy applies. Depending on the contracting company, a disclosure to the USA takes place. It is then permitted on the basis of Annex 1 of the Data Protection Ordinance, which names the USA for organisations certified under the Swiss-US Data Privacy Framework, or on the basis of standard data protection clauses under Art. 16 para. 2 lit. d DSG.

Sending the e-mails

For sending the confirmations and the reports we use a dispatch service. It receives your e-mail address and the content of the message, which includes your report where the report is attached to it. It acts as a processor and may use the data only for the dispatch.

Where data arises, and where it does not

It helps to look at this once from the other side. These are the things we do not do:

  • We run no advertising and embed no ad network.
  • We set no advertising cookies and no counting pixels belonging to third parties.
  • We embed no maps, videos, fonts or icon sets from external servers.
  • We run no social media buttons that transmit data as soon as a page loads.
  • We do not join the data measured at Google to your order, your e-mail address or your result.
  • We do not match your data against external data holdings.
  • We transmit your result to nobody except you.
  • We do not sell data.

Automated evaluation

Your result is calculated by software, not by a person. That is the point of the exercise.

This calculation is not an automated individual decision within the meaning of Art. 21 DSG. It carries no legal consequence for you and does not significantly affect you. Nobody decides on this basis about your education, your job or your health. The result is an orientation value that you ordered yourself and that stays with you. What it says and what it does not say is set out in the disclaimer.

If you have the impression that the evaluation went wrong in your case, write to us. We will look at it.

Your rights

You have the following rights under the Data Protection Act. We grant them regardless of whether you live in Switzerland or in another country. Where the GDPR uses a different name for the same right, we have added it.

Information (GDPR: access). You can demand at any time that we tell you whether and which data we process about you. The information is free of charge. We normally provide it within 30 days, as Art. 25 DSG requires. You cannot waive this right in advance.

Correction (rectification). If data are wrong, we correct them.

Deletion (erasure). You can demand the deletion of your data. We comply, in so far as we are not still required to keep the data, for example payment records for the bookkeeping.

Objection. You can object to a processing operation. While the test is running, that means we delete the session.

Release of data (portability). You can demand that we hand over the data you gave us in a common electronic format.

Complaint. You can turn to the Federal Data Protection and Information Commissioner. If the GDPR applies to you, the route to your national supervisory authority is additionally open.

All of these run through one e-mail to the address at the end of this page. So that we can give information without handing data to the wrong person, we need something to match you by. Give us your order number or the e-mail address you ordered with. For mere test sessions without an order we often cannot identify you at all, for want of any identifying feature. That is not an evasion, it is the consequence of deliberately collecting little.

Data security

We take the technical and organisational measures that Art. 8 DSG requires. These include encrypted transmission of all pages, restricted access to the database, regular updates of the software in use, and collecting data sparingly.

A residual risk remains with every transmission over the internet. We cannot promise that away.

If a breach of data security occurs that entails a high risk for you, we report it under Art. 24 DSG to the Federal Data Protection and Information Commissioner as quickly as possible and inform you, in so far as that is necessary for your protection.

Relationship to the European General Data Protection Regulation

Kognita is aimed at an audience in Switzerland. Prices are quoted in Swiss francs, and the examples and classifications refer to Swiss circumstances.

The fact that our servers stand in Germany does not, in itself, make the GDPR applicable. A data centre is not an establishment of the provider. The GDPR would become applicable if we deliberately addressed people in the European Union.

We have nevertheless written this policy so that it satisfies the substantive requirements of both sets of rules. The duty to inform under Art. 19 DSG and the one under Art. 13 GDPR overlap to a large extent. Should you access the site from the European Union, we will handle your requests by the same standard. We will not invoke questions of jurisdiction in doing so.

Changes

We adjust this policy when the technology or the legal position changes. The version published at the time of your visit is the one that applies. You will find the date of the last change at the top of this page.

Contact for requests for information

Please address all data protection matters to:

Kai Schnider Bleuenweg 4 2542 Pieterlen kontakt@kognita.ch

Getting in touch with us costs you nothing, and it does you no harm.