Privacy Policy
phronon.org is the umbrella site for the Phronon classroom simulations. Each simulation runs on its own domain and carries its own legal pages covering the participant data it processes; this site collects no participant data itself.
Controller
The controller within the meaning of Art. 4(7) GDPR is
Urs Müller, Gotenstr. 21, 10829 Berlin, Germany —
info@phronon.org.
Data protection officer: no data protection officer is appointed. § 38 BDSG has three separate triggers and we have assessed all three: headcount (at least 20 persons constantly engaged in automated processing — this service is operated by one person), processing that requires a data protection impact assessment under Art. 35 GDPR, and commercial processing for the purpose of transfer, anonymised transfer, or market or opinion research. The last two apply regardless of headcount. Our assessment is recorded in DPIA-DETERMINATION.md and is revisited whenever the scope or purpose of processing changes — in particular if cross-class research use becomes a purpose in its own right rather than support for the individual course.
What data we process
- Server log files — see the server-log section below; nothing beyond it.
- E-mail contact — if you write to us, the details you provide are stored to handle your enquiry and are not passed on.
- Administrator credentials — for the private administration area; the password is stored only as a bcrypt hash.
- Fleet overview (administration area only) — when a signed-in administrator opens the overview, this site queries each tool over the server's own loopback interface and displays that tool's class/session titles, join codes, the educator e-mail address that owns each one, its status, response count and last activity. This data is read live and shown on screen; the hub does not store it.
This umbrella site does not collect questionnaire responses or participant demographics — that processing happens inside the individual tools, each of which has its own privacy notice describing it.
Legal bases
- Operating and securing the site, answering enquiries — Art. 6(1)(f) GDPR, our legitimate interest in providing and securing the service.
- The fleet overview — Art. 6(1)(f) GDPR, our legitimate interest in operating the nine tools as one service: seeing which sessions are running, and where, is what makes support and capacity planning possible.
- Administrator accounts — Art. 6(1)(b) GDPR.
Recipients and third-country transfers
We use no third parties for advertising, analytics or tracking, and we do not sell or share personal data for marketing purposes. The following providers process data on our behalf as processors under a data processing agreement pursuant to Art. 28 GDPR:
- IONOS SE (Germany) — hosting and outgoing e-mail.
- Microsoft Ireland Operations Ltd. (OneDrive) — storage of the weekly off-site backup copies. Those backups are encrypted before they leave the server, and the private key exists only on the operator's own machine — never at the provider. So Microsoft holds ciphertext it cannot read.
- healthchecks.io — monitoring that the backup run happened. Only status pings are sent ("run succeeded / failed"); no content and no participant data.
Transfers outside the EU/EEA: processing takes place in the EU; the servers and databases are in Germany. Two things are worth stating in full. Microsoft (OneDrive) provides for transfers outside the EEA under Art. 46 GDPR safeguards (EU standard contractual clauses) — what reaches it is only the backup copies, encrypted before they leave the server, whose key we do not hand over. And healthchecks.io runs infrastructure in the EU and the US, but receives only backup-run status pings: no participant data and no content.
What this means for erasure: when a record is deleted, a copy may remain inside backups until those expire: up to 14 days in the backups held on the server, and up to 30 days in the encrypted off-site copies. Backups are used only to restore the service after a failure, never for ordinary processing.
How long we keep data
- Server logs — rotated and deleted per the server-log section below.
- E-mail correspondence — kept as long as needed to handle the enquiry.
Who can see your data
Only the administrator has access to the administration area, including the fleet overview described above. No participant responses are shown there — class titles, join codes, counts and the owning educator's e-mail address are.
Data security
- The server is located in Germany.
- All transmission is encrypted using HTTPS/TLS.
- Passwords are stored only as bcrypt hashes, never in plain text.
- Session cookies are signed and HTTP-only.
- Web fonts are served from our own server — no third-party CDNs, so no data flows to third parties when fonts load.
- IP addresses processed for rate-limiting are held in memory only and never written to the database.
Server log files
Our web server records standard access log entries: IP address, date and time, the resource requested, HTTP status, referrer and browser identifier. These logs are used solely to operate and secure the service, are not combined with other data, are not used to identify individuals or build profiles, and are rotated and deleted after 14 days. IP addresses processed for rate-limiting are held in memory only and never written to the database.
Your rights
You have the following rights:
- Access (Art. 15 GDPR) — what data we hold about you.
- Rectification (Art. 16 GDPR) — correction of inaccurate data.
- Erasure (Art. 17 GDPR) — deletion of your personal data.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) — your data in a structured, machine-readable format.
- Withdrawal of consent (Art. 7(3) GDPR) — at any time, with effect for the future, as easily as it was given.
Your right to object. Where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to that processing at any time, for reasons arising from your particular situation. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests. To object, write to info@phronon.org.
Response time. We aim to respond to enquiries promptly. Requests concerning your personal data are answered within the period required by Art. 12(3) GDPR (one month at the latest).
Erasure and withdrawal on this tool
Write to us; correspondence and any stored contact details are deleted on request.
Whether you must provide data
Providing data is neither a statutory nor a contractual requirement; the public pages can be read without providing any data at all.
Supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for our location is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
www.datenschutz-berlin.de
Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.