Data protection for schools, on one page.
A course on handling data carefully must not itself become a data collection. Here you can see what is stored, what is not, and where. Version as of 03.10.2026 (version 1.0).
As a PDF to pass on Data processing agreement (PDF)
1. Who is responsible?
The school is the controller within the meaning of the GDPR for the data of its pupils and teachers. It decides whether and which courses are used. secureIT UG (haftungsbeschränkt) (Patrick Ihle, Breisgau) operates the platform and processes the data exclusively on behalf of the school (Art. 28 GDPR). The data processing agreement is concluded upon registration of the school account and is available as a PDF for your records.
2. What is stored about pupils?
As little as possible. There is no pupil account, no app, no registration by email.
- To take part in lessons: the first name (freely chosen, a nickname is fine too) and a recognition cookie on the pupil’s own device. Nothing more. Answers to quiz questions, word clouds and games are assigned to the class, not graded and not reported to the teacher as individual results.
- Phishing training only in the course “Digital self-defence” and only with consent: at the end of this course (grades 8 to 10), pupils can take part in secureIT’s phishing test scenario with their parents’ consent (template in the letter to parents): three simulated, professionally made fraud attempts by email that show whether a staged fraud attempt is recognised. An email address is stored for this; it is only visible in the teacher’s Cockpit, never in the class’s course view. The certificate confirms successful participation in this training and is only issued to those who take part. Without taking part: joining in the lessons yes, data none, certificate none.
- During the phishing test: the only thing stored is whether an email was delivered, opened, clicked or reported. Passwords entered are never stored, only the fact that something was entered. Only the person themselves sees the result; the teacher does not receive a list of who clicked.
- Erasure: certificate data is deleted automatically after 60 days. The school can delete course and test data itself at any time in the Cockpit, or by simply asking me, without a form and without a waiting period.
3. What is stored about teachers?
- School Cockpit: name and work email address of the school management and of the registered teachers, password only as a hash, time of last login. Each teacher sees only their own courses.
- Training for the teaching staff (optional): name, work email address, course completion with date, simulation events as above. The school management sees participation and course completion (for the training record), never the click behaviour of individual persons. The staff council (Personalrat) must be involved before the start; a template service agreement (Dienstvereinbarung) is available.
4. Where is the data stored?
On servers of IONOS SE in Germany (ISO 27001-certified data centre). All connections are TLS-encrypted. There is no disclosure to third parties, no advertising, no tracking, no external scripts or fonts from third-party servers. The learning games also run entirely from the platform. The platform’s own page-view statistics are cookie-free and contain no personal data.
5. Legal basis
For the school: performance of its educational mandate (Art. 6(1)(e) GDPR in conjunction with the Baden-Württemberg Schools Act (Schulgesetz)). For the voluntary provision of an email address by pupils: consent (Art. 6(1)(a) GDPR); for minors, informing the parents is recommended, and the letter to parents for this is available. For teachers: employment relationship in the public service (§ 15 LDSG BW, Baden-Württemberg State Data Protection Act) and, where applicable, the service agreement with the staff council.
6. Costs and interests
For schools, everything is free of charge: courses, Cockpit, games, certificates, training for the teaching staff. There is no licence, no contract term, no advertising in lessons and no intention to sell to pupils, parents or teachers. The programme is financed by secureIT’s business customers.
7. Contact person
Patrick Ihle, secureIT UG (haftungsbeschränkt), info@secureit-online.de, +49 157 58278025. I answer questions from the data protection officer or the school authority (Schulträger) directly, usually on the same day.