Privacy Policy
The Drawbridge Drama presents a short illustrated narrative and asks participants to attribute responsibility, to support classroom discussion of moral judgment and framing effects.
Controller
The controller within the meaning of Art. 4(7) GDPR is
Urs Müller, Gotenstr. 21, 10829 Berlin, Germany —
info@drawbridge-drama.org.
Who is responsible for what. For educator and administrator accounts, for security and abuse prevention, and for the retained analysis data — anonymous counters in some tools, pseudonymous rows in others; each tool's retention section says which — we are the controller. Where an institution has contracted us to run this tool for its own programme, the institution is the controller for the identifiable data of that cohort, and we process it on the institution's behalf (Art. 28 GDPR). In practice: for a request concerning your cohort's identifiable data, please approach your educator or institution first; for anything concerning accounts, security or the retained analysis data, contact us. We assist the institution in answering requests in either case (Art. 28(3)(e) GDPR).
Data protection officer: no data protection officer is appointed. § 38 BDSG has three separate triggers and we have assessed all three: headcount (at least 20 persons constantly engaged in automated processing — this service is operated by one person), processing that requires a data protection impact assessment under Art. 35 GDPR, and commercial processing for the purpose of transfer, anonymised transfer, or market or opinion research. The last two apply regardless of headcount. Our assessment is recorded in DPIA-DETERMINATION.md and is revisited whenever the scope or purpose of processing changes — in particular if cross-class research use becomes a purpose in its own right rather than support for the individual course.
What data we process
From class participants
We do not ask for your name, e-mail address, phone number or any account. The data we store is pseudonymous, per submission:
- Class code — attributes the response to the correct class; it is not linked to you personally.
- Story-path code — which version of the story flow was shown.
- Your responses — your responsibility attribution, certainty rating and optional follow-ups; a free-text explanation if you choose "Other". Your answers can reveal your moral views. The free-text box is the one field we cannot check for you: please do not type your name or anything that identifies you or another person, and we ask you not to on the page itself.
- Optional demographics — age bracket, gender, childhood country/region, prior familiarity. All optional.
- Submission timestamp.
- A deletion code — shown to you once when you submit, and stored so that entering it later finds your response. It is the only thing that can, since no name or address is collected. Keep it if you might want your answers removed; we cannot re-send it.
- Your answer to the optional research question, with the date and the version of the wording you were shown — this is how we can demonstrate what you agreed to.
- Short one-way hashes of your session cookie and browser identifier — checked before a response is accepted, so that one browser session cannot submit twice. The original cookie and browser string are not retained in these fields, but the hashes can still single out the same browser session; clearing your cookies starts a new session, so this prevents accidental double submission rather than a determined one. Because such a key exists, the data is pseudonymous rather than anonymous.
From baseline (Prolific) participants
- Prolific participant ID — a quasi-identifier used to deduplicate responses and to honour withdrawal via Prolific.
From educators and administrators
- E-mail address, display name — for backoffice sign-in.
- Password — stored only as a bcrypt hash.
- Class data — names, codes and configuration of classes you create.
Legal bases
- Running the study and aggregate visualisations — Art. 6(1)(f) GDPR, our legitimate interest in supporting the educational programme in which participants take part.
- Keeping a stripped research row after the class is erased — Art. 6(1)(a) GDPR, your separate, optional consent. The box is not pre-selected, declining changes nothing about the exercise, and you can withdraw at any time with your deletion code.
- Educator and administrator accounts — Art. 6(1)(b) GDPR.
- Security, rate-limiting and abuse prevention — Art. 6(1)(f) GDPR.
Recipients and third-country transfers
We use no third parties for advertising, analytics or tracking, and we do not sell or share personal data for marketing purposes. The following providers process data on our behalf as processors under a data processing agreement pursuant to Art. 28 GDPR:
- IONOS SE (Germany) — hosting and outgoing e-mail.
- Microsoft Ireland Operations Ltd. (OneDrive) — storage of the weekly off-site backup copies. Those backups are encrypted before they leave the server, and the private key exists only on the operator's own machine — never at the provider. So Microsoft holds ciphertext it cannot read.
- healthchecks.io — monitoring that the backup run happened. Only status pings are sent ("run succeeded / failed"); no content and no participant data.
Transfers outside the EU/EEA: processing takes place in the EU; the servers and databases are in Germany. Two things are worth stating in full. Microsoft (OneDrive) provides for transfers outside the EEA under Art. 46 GDPR safeguards (EU standard contractual clauses) — what reaches it is only the backup copies, encrypted before they leave the server, whose key we do not hand over. And healthchecks.io runs infrastructure in the EU and the US, but receives only backup-run status pings: no participant data and no content.
What this means for erasure: when a record is deleted, a copy may remain inside backups until those expire: up to 14 days in the backups held on the server, and up to 30 days in the encrypted off-site copies. Backups are used only to restore the service after a failure, never for ordinary processing.
How long we keep data
- Class responses — erased automatically 30 days after the class is closed, or 30 days after the last response if it is never closed. A class nobody ever joined is removed 90 days after it was created. Erasure removes the whole class: every response, the free-text answers, the optional demographics and the browser hashes. Educators are warned 14 days beforehand and may postpone up to three times by 30 days. The latest possible date is 120 days after the class closed or the last response — 90 days beyond the original deletion date.
- If you tick the optional research box — one row of yours is kept after that date: the experimental story version and factor levels, your choice, certainty, optional closed-choice follow-up, and any demographics you gave. Your free-text explanation is never copied. The row has no class code or class name and no date finer than the half-year. It does carry a new random cohort key shared by people who answered in the same class, so co-membership can be analysed without retaining which class it was. Those rows are pseudonymous, not anonymous: the deletion code you were given still matches yours, which is exactly what lets you withdraw it. If you do not tick it, nothing of yours survives the deadline.
- Baseline (Prolific) responses — a one-time benchmark sample, collected as research from the outset with consent given through Prolific and retained as part of that dataset. It is not on the class clock above. The Prolific ID is held only for deduplication and for withdrawal through Prolific.
- Educator accounts — retained until deactivated or deleted by an administrator.
Who can see your data
- Educators see aggregate counts and the pseudonymous response-level data for their own classes, plus aggregated comparison figures from the baseline sample. No stored field identifies a participant directly.
- The administrator has technical access for maintenance, backups and security only, and is the only role that can open or export the raw baseline (Prolific) sample.
Data security
- The server is located in Germany.
- All transmission is encrypted using HTTPS/TLS.
- Passwords are stored only as bcrypt hashes, never in plain text.
- Session cookies are signed and HTTP-only.
- Web fonts are served from our own server — no third-party CDNs, so no data flows to third parties when fonts load.
- IP addresses processed for rate-limiting are held in memory only and never written to the database.
Server log files
Our web server records standard access log entries: IP address, date and time, the resource requested, HTTP status, referrer and browser identifier. These logs are used solely to operate and secure the service, are not combined with other data, are not used to identify individuals or build profiles, and are rotated and deleted after 14 days. IP addresses processed for rate-limiting are held in memory only and never written to the database.
Administrative audit trail. If you use an educator account, we record security-relevant actions — successful and failed sign-ins, password changes and resets, creating, changing and deleting accounts, and deleting or anonymising class data — each with the time, the account's e-mail address and the IP address. The basis is our legitimate interest (Art. 6(1)(f) GDPR) in being able to reconstruct unauthorised access to an account. These entries are deleted after 12 months. Participants are not affected.
Your rights
You have the following rights:
- Access (Art. 15 GDPR) — what data we hold about you.
- Rectification (Art. 16 GDPR) — correction of inaccurate data.
- Erasure (Art. 17 GDPR) — deletion of your personal data.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) — your data in a structured, machine-readable format.
- Withdrawal of consent (Art. 7(3) GDPR) — at any time, with effect for the future, as easily as it was given.
Your right to object. Where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to that processing at any time, for reasons arising from your particular situation. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests. To object, write to info@drawbridge-drama.org.
Response time. We aim to respond to enquiries promptly. Requests concerning your personal data are answered within the period required by Art. 12(3) GDPR (one month at the latest).
Erasure and withdrawal on this tool
Use the deletion code you were shown when you submitted. Enter it at /withdraw and your response is erased immediately — before or after the 30-day deadline, and including the research row if you kept one. That code is the only thing that identifies your response as yours: we store no name and no e-mail address, so we cannot look it up for you, and we cannot send you another.
If you did not keep it, we cannot identify which response is yours: the duplicate-prevention hashes are not exposed as a lookup code and sending us a message from the same browser does not transmit them. Baseline (Prolific) participants can request deletion via their Prolific ID.
Whether you must provide data
Providing data is neither a statutory nor a contractual requirement. No identifying information is required at all; the demographic questions are optional and skipping them has no consequence.
Supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for our location is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
www.datenschutz-berlin.de
Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.