Skip to main content
Techlogia — AI and Web Development Berlin

Lab Privacy Policy — Supplementary

Privacy Policy — Supplement Learning Platform “Lab” — v3

1. Controller

Jaciel Antonio Acea Ruiz
Prinzenallee 38
13359 Berlin, Germany

General: kontakt@techlogia.de
Data protection: datenschutz@techlogia.de

No Data Protection Officer required per § 38(1) BDSG / Art. 37 GDPR.

2. Personal Data Processed

2.1 Individual Learner Registration

  • Email address — identification + double opt-in
  • Password — bcrypt hash only
  • Birth year — age verification (min. 8), parental consent trigger (<16). Data minimization: year only.
  • hCaptcha token — ephemeral, not stored
  • Confirmation token (DOI) — 24-hour validity

2.2 During Lab Usage

  • IP address — server logs, abuse prevention, quota enforcement
  • VM metadata — Hetzner VM-ID, IPv4/IPv6, status, timestamps
  • Learning progress — lessons started/completed with timestamps
  • Validator results — JSON with check names and status, no learner input stored
  • XP points — cumulative progress value (gamification)

2.3 Audit Logs

Security-relevant actions: timestamp, user ID, action type, affected entity, IP address.

2.4 Parental Consent for Minors Under 16

  • Guardian email address
  • Parental consent token (14-day validity)
  • Consent timestamp (Art. 7(1) GDPR proof)

Auto-deletion after 14 days without confirmation.

2.5 Teachers and School Administration

  • Email, display name, school role, class assignments

Legal basis: Art. 6(1)(b) GDPR + DPA per Art. 28 GDPR. School is the controller; Techlogia acts as processor.

2.6 Class-Based Students (No Email)

  • Login name (assigned by teacher, pseudonym possible)
  • Class code
  • Learning progress and validator results

Not collected: email, password, birth year. Parental consent: school’s responsibility. Retention: 90 days after class deactivation.

2.7 OAuth Login (Google, GitHub)

  • Provider ID (anonymous), email, display name, OIDC session ID

No password stored. Provider receives no lab usage data.

2.8 Forensic Snapshots (Security Incidents)

Only upon concrete suspicion of abuse (e.g. unusual load/traffic or an abuse report from our host) do we capture a technical snapshot before the lab VM is automatically deleted: process list, network connections, and system and authentication logs. This does not happen during normal use or when a session ends regularly. Purpose: incident investigation, abuse prevention, and asserting and defending legal claims (Art. 6(1)(f) GDPR). Snapshots are stored encrypted in a data centre in the EU and are automatically deleted after 90 days. Exception (legal hold): if an official or criminal-law request relates to an incident, we retain the affected data for evidentiary purposes for as long as required for the respective proceedings and delete it immediately afterwards.

3. Purpose and Legal Basis

ProcessingPurposeLegal Basis
Account creation, login, DOILab accessArt. 6(1)(b) GDPR
Birth year + parental consentLegal obligationArt. 6(1)(c) + Art. 8 GDPR
hCaptchaBot preventionArt. 6(1)(a) GDPR (consent, “Functional” category)
IP + quotaAbuse protectionArt. 6(1)(f) GDPR
Lab VMsExercise deliveryArt. 6(1)(b) GDPR
Progress + XPProgress displayArt. 6(1)(b) GDPR
WatchersMining/DDoS preventionArt. 6(1)(f) GDPR
Forensic snapshotsIncident investigationArt. 6(1)(f) GDPR
School-based usageSchool learning platformArt. 6(1)(b) + Art. 28 GDPR
OAuthAlternative authenticationArt. 6(1)(a) + Art. 6(1)(b) GDPR

4. Recipients / Processors

4.1 Hetzner Online GmbH — Cloud hosting, EU data centers, DPA per Art. 28 GDPR.

4.2 Intuition Machines, Inc. (hCaptcha) — Bot prevention. Loads only after consent (“Functional” cookie category). US transfer: EU-US DPF + SCCs.

4.3 Own mail server (mail.techlogia.de) — Hetzner Nürnberg, Germany. No third-country transfer.

4.4 Google Ireland Ltd — OAuth login. No lab data shared with Google.

4.5 GitHub, Inc. (Microsoft) — OAuth login. US transfer: EU-US DPF + SCCs.

5. Retention Periods

DataRetention
Account dataUntil account deletion
Parental consent token14 days (auto-delete)
DOI token24 hours; account deleted after 48h
Lab session metadataUntil account deletion
Progress + validator + XPUntil account deletion (cascaded)
Class student data90 days after class deactivation
OAuth provider IDUntil account deletion
Forensic snapshots90 days
Audit logsPseudonymized after deletion; 1 year retention
Server logs (IP)7 days (DSK recommendation)
Push tokens90 days after last use
DPA signature events7 years (§ 257 HGB)

6. Data Subject Rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17) via self-service, restriction (Art. 18), portability (Art. 20) as JSON, objection (Art. 21), consent withdrawal (Art. 7(3)) via footer “Cookie Settings” link.

School-based usage: exercise rights against the school as controller.

Supervisory authority: Berlin Commissioner for Data Protection (BlnBDI), Alt-Moabit 59-61, 10555 Berlin.

7. Cookies

Necessary: access_token, refresh_token, cookie_consent (no opt-in). Functional: hCaptcha cookies (opt-in required). Analytics: Umami (cookieless, opt-out available). Marketing: TikTok pixel (opt-in required, no learner PII shared).

8. Automated Decision-Making (Art. 22 GDPR)

Watchers terminate VMs on threshold breach. No account bans without human review. Does not meet Art. 22(1) threshold. Objection: datenschutz@techlogia.de (5 business days).

9. Minors (Art. 8 GDPR)

Min. age 8. Under 16: parental consent required. Revocation: datenschutz@techlogia.de (full account deletion). No advertising, no profiling. School-based: school responsible.

10. Security (Art. 32 GDPR)

TLS, bcrypt, dedicated DB user, HttpOnly+Secure+SameSite cookies, JWT+refresh rotation, MFA for admins, encrypted backups, brute-force protection, CrowdSec WAF, CSP+HSTS.

11. Changes

Current version: techlogia.de/lab/datenschutz. Material changes communicated by email.

Date: 2026-05-26 — Version 3


Supplement 2026-07-12 — Sign in with Apple

Login via Apple („Sign in with Apple“)

You can alternatively sign in with your Apple account („Sign in with Apple“). From Apple we receive only: a pseudonymous user identifier („sub“), your e-mail address — optionally an Apple-generated private relay address („Hide My Email“) so we never see your real address — and, on first login only, optionally your name. There is no tracking via Apple; we receive no further profile or device data.

This data is used solely for account creation and login (legal basis Art. 6(1)(b) GDPR — performance of contract). Provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland; see Apple’s privacy policy for details. Transactional e-mails (e.g. sign-in codes or system notifications) are sent to the address provided by Apple — for relay addresses Apple forwards them to your mailbox.


Supplement 2026-07-12 — Push notifications

Push notifications of the mobile app

If you enable notifications in the Techlogia app, your device generates a device identifier (push token) which we store so we can send you targeted notifications (e.g. new lab modules or a reminder that your lab environment will shut down automatically soon). For delivery the push token is transmitted to the Apple Push service (APNs); Apple forwards the notification to your device. No account content beyond the title and body of the notification is shared with third parties in this process.

The legal basis is your consent (Art. 6(1)(a) GDPR), which you grant via the iOS permission prompt. You can withdraw it at any time — either in iOS Settings → Notifications or by logging out of the app; the push token is then deleted. The delivery service provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland.


Supplement 2026-06-13 — App usage statistics

Usage statistics of the mobile app

In the Techlogia app we measure — unless you have objected — an anonymous usage statistic to understand which areas are used and to improve the app. We collect only: the visited app area from a fixed list (e.g. „Blog“, „Lab terminal“), the session duration in seconds and a timestamp. To group related views we use a random, locally generated identifier (install_id) that is not linked to your account, e-mail or device hardware.

We transmit no personal data, no free text, no content and no precise device IDs. Processing is done as anonymous aggregate counters on our own server in Germany (retention 90 days). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in product improvement). You can object to this collection anytime in the app under Settings → Usage statistics (Art. 21 GDPR).


Supplement 2026-07-17 — Error and crash diagnostics

Error reports (website, learning platform and app)

When a technical error or crash occurs on our website, in the learning platform or in the Techlogia app, the application transmits an error report to our own, self-hosted error-analysis system (Sentry, operated on our servers in Germany — there is no transfer to third parties or third countries). An error report contains: the technical error message including the program execution path, the affected page or app area, browser or device type and operating-system version, and a timestamp.

We have technically configured the reports so that they contain no passwords, login tokens, cookies, e-mail addresses or form input — such fields are automatically removed or masked before sending; IP addresses are not stored. Reports are automatically deleted after 30 days. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable, error-free operation).


Supplement 2026-07-17 — Anonymous performance measurement

Performance data (website, learning platform and app)

In addition to error reports, our applications transmit anonymous performance metrics to the same self-hosted analysis system (servers in Germany, no third-country transfer): the name of the accessed area or operation (e.g. „app start“, „load lab overview“), the loading duration in milliseconds, device type/operating-system version and a timestamp. This lets us identify slow areas and make the application noticeably faster.

The metrics contain no personal data, no input and no account linkage; only a sample of operations is transmitted. The data is automatically deleted after 30 days. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in fast, reliable operation).

How do you like this page?