Data protection declaration and consent to data processing for the school
Sdui GmbH is officially commissioned by the school to process data by means of an AVV (order data processing agreement). The school remains the owner of all data - and the user consents to the school to process data.
This is a sample text for such a data protection declaration and consent to data processing for the school:
Dear parents, dear students,
The protection of the data of you and your children is very important to us. Therefore we as ________________________________________ (school) decided to use the privacy-friendly application "Sdui" from Sdui GmbH, Universitätsstr. 3, 56070 Koblenz at our school in order to be able to communicate more easily in everyday school life. In order to be able to provide you and your child with an account on "Sdui", we need your consent. A lot of data processing is associated with the use of such an app - so that you / you are able to give informed consent, we would like to show in the following section which data processing takes place if you / you decide to set up an "Sdui" account allow.
First of all: We made a conscious decision to use the provider Sdui, as they generally process the data in Germany. Sdui himself uses servers from 1 & 1 IONOS SE and LUMASERV Systems in Germany, where the data is ultimately processed. If data is processed elsewhere in exceptional cases, we will point this out again separately.
1. Information on the processing of the master data of each user: So that there is no misuse of the app and everyone knows who has carried out what actions in it, the specification and storage as well as the display of the first and last name in the app is a mandatory requirement for using the app. The name is also required for the following actions: 1. Display in the "News" menu item, so that the creator of the news (usually a teacher) can see who is on the mailing list and the users can see who the author is. Within this “news”, authors can also mention other users in order to distribute tasks, for example. 2. To display a receipt and read confirmation from the author of a “News”. 3. Display in the menu item "Cloud", provided that documents are stored there with the name given.
In order to be able to assign the students to the appropriate groups and group chats (see 4.) and to be able to display the timetable, information about their timetable is also saved for each student. In order to also assign parents to the correct groups, parents are linked to their respective children. At the end of each school year, a check is made to determine whether further storage is required in the Sdui application. Please note that storage periods in our local systems or "offline" are not affected by this.
2. Information on logging: In order to ensure security against attacks and to be able to understand changes to data, so-called logs are created in the Sdui application. These logs are intended to ensure that in the end it can be traced who entered, changed or deleted which data in the program and when. This is important so that we can clear up any discrepancies afterwards.
3. Processing of the email address (optional): You can optionally enter your e-mail in the app, which can also have a fantasy name or a nickname. It is required to reset a password and is not visible to others. Without specifying an e-mail address, the password can only be reset by submitting an application to the secretariat or the IT administrator.
4. Information about the use of the chat function: The app offers a school-specific chat function for schools that choose to do so. In particular, the advantage should be granted that pupils, parents and teachers can exchange information on organizational and / or learning-related topics at short notice. So far, this exchange has often taken place via external services such as WhatsApp, whereby adequate data protection is not guaranteed. With the chat function, Sdui offers a safe and in-school alternative that does not require a private cell phone number. So that there is no abuse, the users are visible to other users with their names when they write chat messages or by administrators (mostly teachers and possibly students in special positions such as school spokesman) in groups (class association and possibly interest groups such as e.g. Sport-AG). Students and parents are only allowed to send messages or files (photos, videos, documents, etc.) (hereinafter: "content") within a chat if an administrator has approved this. The actions taken in the chat, such as exchanged content, are saved. Specially communicated content can be deleted by the author with effect for anyone. However, it cannot be ruled out that this content has already been copied, downloaded or otherwise duplicated by other users for their own purposes. For prevention In the event of abuse, a group administrator (usually a teacher) can restrict the sharing of content. The app saves all settings made by the user for such functions. In order for the chat function to make everyday school life as easy as possible, the processing of the data mentioned is essential for the operation of the chat function.
5. Information about the video chat function: The Sdui app offers the possibility of video conferences between two or more participants. To make this possible we need to use streaming audio and video data. There is also the option of using a chat function within the web conference. In order to be able to make this available, we have to process the content as well as the associated metadata (sender, recipient, etc.). This data is not recorded, and a recording function for the video conference is not offered for data protection reasons. Text chats are also not recorded, but deleted after the conference. In order for us to be able to assign the participants correctly, a temporary participant number is generated for each conference, but this can no longer be traced back to individual users after the conference. Afterwards it can be seen that a conference took place on a certain date and time, but it is no longer possible to determine who participated in it. Before you can take part in a video conference, we also process authentication data to ensure that only authorized persons have access to the video conference room. Whether individual functions such as screen sharing can be used depends on the browser or operating system of the end device on which the video conferences are carried out. It is therefore necessary to process this information in order to provide the functions adapted to the specific terminal used.
6. Use of push notifications: You can subscribe to so-called push notifications in the mobile apps. This function is made available by the respective provider of the operating system that your devices use and is used by the app. If you use this service, it is necessary for the provider of your operating system (Apple or Google) to collect data from you in order to be able to make the service available to you. The legal basis for data processing is the consent that you give directly on your device.
7. Your other rights: According to the GDPR you have the following rights: A right to information according to Art. 15 GDPR - The right to correction according to Art. 16 GDPR - The right to erasure according to Art. 17 GDPR - The right to restriction of processing according to Art. 18 GDPR - The right to object in accordance with Art. 21 GDPR. There is also the right to complain to a data protection supervisory authority about the data processing carried out by us.
8. Information about data processing by Sdui when using the Sdui app: If you decide to use the Sdui app, data processing will also take place for which Sdui GmbH is responsible and not we as a school. In order to be transparent for you, we would like to give you an overview here:
8.1 Collection of data to provide the service: If you use our app, you can do so either via the website or directly in the Sdui app. In order to enable communication with Sdui, at least the following data is processed for technical reasons: IP address, possibly browser type and browser version, operating system used, referrer URL, host name of the accessing computer and time of the request. These logs are stored for 14 days in accordance with Sdui.
8.2 Collection of data to improve the app: So that Sdui GmbH can always improve its app and make it more user-friendly, the app saves completely anonymously and without
that there is a possibility of tracing, statistical values about the use of the functions. This happens when you accept the data transfer in the app to optimize the app. The legal basis is Article 6 (1) lit. a) GDPR. You can deactivate the function at any time in the app. For example, it is easier to see under which menu item the user frequently makes errors, so that this menu item can be revised. The storage of this statistical analysis is based on a legitimate interest in the constant improvement of the app and to enable user-friendly handling and therefore does not require consent. You can object to this statistical analysis in the app settings at any time.
Holistic consent: With a cross next to "Yes" and my signature, I confirm that I have read the data protection declaration and that I agree to all of the above data processing. I can revoke my decision at any time by phone, email or post to the school.