Security notice

This notice explains how Ace the Role protects account access, Practice Sessions, Practice Answers, Trusted Grades, billing access, and operational systems for users in Europe.

Article 1

Scope and security posture

Ace the Role is the interview-preparation app provided under the public business name QTS One. This notice summarizes how we protect account data, selected Role-Specific Paths, Practice Sessions, Practice Answers, Trusted Grades, Reference-Backed AI Feedback, billing access, support requests, and the Live Preparation Catalog. It is a public security summary, not a security certification or audit report, so it intentionally avoids disclosing sensitive implementation details.

Article 2

EU security baseline

Ace the Role is designed around EU expectations for appropriate technical and organisational measures under GDPR Article 32, including access control, confidentiality, integrity, availability, resilience, and regular review of safeguards. Our operating model is also informed by NIS2 risk-management themes such as incident handling, business continuity, supplier review, secure development, vulnerability handling, access control, and secure communications where appropriate.

Article 3

Account protection

Ace the Role uses passwordless email sign-in and authenticated sessions for account access. Protected product and support surfaces require valid account state, and administrative access is limited to authorized personnel. Sensitive account-support actions are reviewed, constrained, and recorded so misuse or mistakes can be investigated.

Article 4

Application safeguards

Ace the Role applies layered application safeguards for browser sessions, server-side integrations, deployment configuration, and stored product data. Sensitive provider and payment credentials are kept out of browser-visible code, and public pages are served with defensive browser protections appropriate for a modern web application.

Article 5

Practice data and providers

Ace the Role stores Practice Answers, Trusted Grades, feedback records, usage limits, and account access records so it can provide history, progress, quotas, support, security, and reliability features. When you request grading, Ace the Role may send the relevant question context, reference material, and Practice Answer to configured AI grading providers. Do not submit passwords, identity documents, payment card data, employer-confidential material, medical details, or other sensitive information that is not needed for interview practice.

Article 6

Payments and transactional email

Stripe handles checkout, payment methods, billing portal flows, and approved refund transactions; Ace the Role does not store full card numbers. Resend is used for transactional email such as one-time sign-in codes and Practice Data Deletion confirmations.

Article 7

Abuse prevention and operational controls

Ace the Role uses abuse-prevention controls, access limits, issue-reporting channels, operational monitoring, backups, and recovery practices to protect the service and support paid access. We review operational changes that affect account access, billing access, Practice Data Deletion, and the Live Preparation Catalog.

Article 8

Incident response and breach handling

Security incidents are triaged by containment, impact assessment, remediation, and recordkeeping. If an incident is a personal data breach that is likely to create risk for affected people, Ace the Role will assess notification to the competent supervisory authority within the GDPR 72-hour window. If the breach is likely to create a high risk for affected people, Ace the Role will also assess direct user communication without undue delay.

Article 9

Responsible disclosure

Report suspected vulnerabilities to security@acetherole.com. Include the affected URL or endpoint, reproduction steps, observed impact, timestamps, and any relevant request identifiers. Do not access, modify, delete, or extract another user's data, disrupt service availability, bypass quotas for non-testing purposes, or publish vulnerability details before we have had a reasonable opportunity to investigate. For machine-readable disclosure details, see security.txt.

Article 10

User responsibilities

Keep sign-in codes, account sessions, and billing portal links private. Contact support@acetherole.com if you believe someone else accessed your account, and contact security@acetherole.com for vulnerability reports. Personal data handling and Practice Data Deletion are explained in the privacy notice.

Security questions can be sent to security@acetherole.com. Effective date: 28 May 2026.

Ace the RoleReference-backed interview practice for role-specific paths, real interview questions, and clear next steps.

Product

  • Product
  • Pricing
  • Start preparing
  • Contact

Practice

  • Role-specific paths
  • Reference-backed AI feedback
  • Progress tracking
  • The Journey

Legal

  • Impressum
  • Security
  • Privacy
  • Terms

© 2026 QTS One. All rights reserved.