Lab Privacy Policy — Supplementary
Privacy Policy — Supplement Learning Platform “Lab” — v3
1. Controller
Jaciel Antonio Acea Ruiz
Prinzenallee 38
13359 Berlin, Germany
General: kontakt@techlogia.de
Data protection: datenschutz@techlogia.de
No Data Protection Officer required per § 38(1) BDSG / Art. 37 GDPR.
2. Personal Data Processed
2.1 Individual Learner Registration
- Email address — identification + double opt-in
- Password — bcrypt hash only
- Birth year — age verification (min. 8), parental consent trigger (<16). Data minimization: year only.
- hCaptcha token — ephemeral, not stored
- Confirmation token (DOI) — 24-hour validity
2.2 During Lab Usage
- IP address — server logs, abuse prevention, quota enforcement
- VM metadata — Hetzner VM-ID, IPv4/IPv6, status, timestamps
- Learning progress — lessons started/completed with timestamps
- Validator results — JSON with check names and status, no learner input stored
- XP points — cumulative progress value (gamification)
2.3 Audit Logs
Security-relevant actions: timestamp, user ID, action type, affected entity, IP address.
2.4 Parental Consent for Minors Under 16
- Guardian email address
- Parental consent token (14-day validity)
- Consent timestamp (Art. 7(1) GDPR proof)
Auto-deletion after 14 days without confirmation.
2.5 Teachers and School Administration
- Email, display name, school role, class assignments
Legal basis: Art. 6(1)(b) GDPR + DPA per Art. 28 GDPR. School is the controller; Techlogia acts as processor.
2.6 Class-Based Students (No Email)
- Login name (assigned by teacher, pseudonym possible)
- Class code
- Learning progress and validator results
Not collected: email, password, birth year. Parental consent: school’s responsibility. Retention: 90 days after class deactivation.
2.7 OAuth Login (Google, GitHub)
- Provider ID (anonymous), email, display name, OIDC session ID
No password stored. Provider receives no lab usage data.
2.8 Forensic Snapshots (Security Incidents)
Only upon concrete suspicion of abuse (e.g. unusual load/traffic or an abuse report from our host) do we capture a technical snapshot before the lab VM is automatically deleted: process list, network connections, and system and authentication logs. This does not happen during normal use or when a session ends regularly. Purpose: incident investigation, abuse prevention, and asserting and defending legal claims (Art. 6(1)(f) GDPR). Snapshots are stored encrypted in a data centre in the EU and are automatically deleted after 90 days. Exception (legal hold): if an official or criminal-law request relates to an incident, we retain the affected data for evidentiary purposes for as long as required for the respective proceedings and delete it immediately afterwards.
3. Purpose and Legal Basis
| Processing | Purpose | Legal Basis |
|---|---|---|
| Account creation, login, DOI | Lab access | Art. 6(1)(b) GDPR |
| Birth year + parental consent | Legal obligation | Art. 6(1)(c) + Art. 8 GDPR |
| hCaptcha | Bot prevention | Art. 6(1)(a) GDPR (consent, “Functional” category) |
| IP + quota | Abuse protection | Art. 6(1)(f) GDPR |
| Lab VMs | Exercise delivery | Art. 6(1)(b) GDPR |
| Progress + XP | Progress display | Art. 6(1)(b) GDPR |
| Watchers | Mining/DDoS prevention | Art. 6(1)(f) GDPR |
| Forensic snapshots | Incident investigation | Art. 6(1)(f) GDPR |
| School-based usage | School learning platform | Art. 6(1)(b) + Art. 28 GDPR |
| OAuth | Alternative authentication | Art. 6(1)(a) + Art. 6(1)(b) GDPR |
4. Recipients / Processors
4.1 Hetzner Online GmbH — Cloud hosting, EU data centers, DPA per Art. 28 GDPR.
4.2 Intuition Machines, Inc. (hCaptcha) — Bot prevention. Loads only after consent (“Functional” cookie category). US transfer: EU-US DPF + SCCs.
4.3 Own mail server (mail.techlogia.de) — Hetzner Nürnberg, Germany. No third-country transfer.
4.4 Google Ireland Ltd — OAuth login. No lab data shared with Google.
4.5 GitHub, Inc. (Microsoft) — OAuth login. US transfer: EU-US DPF + SCCs.
5. Retention Periods
| Data | Retention |
|---|---|
| Account data | Until account deletion |
| Parental consent token | 14 days (auto-delete) |
| DOI token | 24 hours; account deleted after 48h |
| Lab session metadata | Until account deletion |
| Progress + validator + XP | Until account deletion (cascaded) |
| Class student data | 90 days after class deactivation |
| OAuth provider ID | Until account deletion |
| Forensic snapshots | 90 days |
| Audit logs | Pseudonymized after deletion; 1 year retention |
| Server logs (IP) | 7 days (DSK recommendation) |
| Push tokens | 90 days after last use |
| DPA signature events | 7 years (§ 257 HGB) |
6. Data Subject Rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17) via self-service, restriction (Art. 18), portability (Art. 20) as JSON, objection (Art. 21), consent withdrawal (Art. 7(3)) via footer “Cookie Settings” link.
School-based usage: exercise rights against the school as controller.
Supervisory authority: Berlin Commissioner for Data Protection (BlnBDI), Alt-Moabit 59-61, 10555 Berlin.
7. Cookies
Necessary: access_token, refresh_token, cookie_consent (no opt-in). Functional: hCaptcha cookies (opt-in required). Analytics: Umami (cookieless, opt-out available). Marketing: TikTok pixel (opt-in required, no learner PII shared).
8. Automated Decision-Making (Art. 22 GDPR)
Watchers terminate VMs on threshold breach. No account bans without human review. Does not meet Art. 22(1) threshold. Objection: datenschutz@techlogia.de (5 business days).
9. Minors (Art. 8 GDPR)
Min. age 8. Under 16: parental consent required. Revocation: datenschutz@techlogia.de (full account deletion). No advertising, no profiling. School-based: school responsible.
10. Security (Art. 32 GDPR)
TLS, bcrypt, dedicated DB user, HttpOnly+Secure+SameSite cookies, JWT+refresh rotation, MFA for admins, encrypted backups, brute-force protection, CrowdSec WAF, CSP+HSTS.
11. Changes
Current version: techlogia.de/lab/datenschutz. Material changes communicated by email.
Date: 2026-05-26 — Version 3
Supplement 2026-07-12 — Sign in with Apple
Login via Apple („Sign in with Apple“)
You can alternatively sign in with your Apple account („Sign in with Apple“). From Apple we receive only: a pseudonymous user identifier („sub“), your e-mail address — optionally an Apple-generated private relay address („Hide My Email“) so we never see your real address — and, on first login only, optionally your name. There is no tracking via Apple; we receive no further profile or device data.
This data is used solely for account creation and login (legal basis Art. 6(1)(b) GDPR — performance of contract). Provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland; see Apple’s privacy policy for details. Transactional e-mails (e.g. sign-in codes or system notifications) are sent to the address provided by Apple — for relay addresses Apple forwards them to your mailbox.
Supplement 2026-07-12 — Push notifications
Push notifications of the mobile app
If you enable notifications in the Techlogia app, your device generates a device identifier (push token) which we store so we can send you targeted notifications (e.g. new lab modules or a reminder that your lab environment will shut down automatically soon). For delivery the push token is transmitted to the Apple Push service (APNs); Apple forwards the notification to your device. No account content beyond the title and body of the notification is shared with third parties in this process.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you grant via the iOS permission prompt. You can withdraw it at any time — either in iOS Settings → Notifications or by logging out of the app; the push token is then deleted. The delivery service provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland.
Supplement 2026-06-13 — App usage statistics
Usage statistics of the mobile app
In the Techlogia app we measure — unless you have objected — an anonymous usage statistic to understand which areas are used and to improve the app. We collect only: the visited app area from a fixed list (e.g. „Blog“, „Lab terminal“), the session duration in seconds and a timestamp. To group related views we use a random, locally generated identifier (install_id) that is not linked to your account, e-mail or device hardware.
We transmit no personal data, no free text, no content and no precise device IDs. Processing is done as anonymous aggregate counters on our own server in Germany (retention 90 days). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in product improvement). You can object to this collection anytime in the app under Settings → Usage statistics (Art. 21 GDPR).
Supplement 2026-07-17 — Error and crash diagnostics
Error reports (website, learning platform and app)
When a technical error or crash occurs on our website, in the learning platform or in the Techlogia app, the application transmits an error report to our own, self-hosted error-analysis system (Sentry, operated on our servers in Germany — there is no transfer to third parties or third countries). An error report contains: the technical error message including the program execution path, the affected page or app area, browser or device type and operating-system version, and a timestamp.
We have technically configured the reports so that they contain no passwords, login tokens, cookies, e-mail addresses or form input — such fields are automatically removed or masked before sending; IP addresses are not stored. Reports are automatically deleted after 30 days. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable, error-free operation).
Supplement 2026-07-17 — Anonymous performance measurement
Performance data (website, learning platform and app)
In addition to error reports, our applications transmit anonymous performance metrics to the same self-hosted analysis system (servers in Germany, no third-country transfer): the name of the accessed area or operation (e.g. „app start“, „load lab overview“), the loading duration in milliseconds, device type/operating-system version and a timestamp. This lets us identify slow areas and make the application noticeably faster.
The metrics contain no personal data, no input and no account linkage; only a sample of operations is transmitted. The data is automatically deleted after 30 days. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in fast, reliable operation).
