Privacy Policy
This policy applies to the community board at https://community.ki-einfach-verstehen.de. It supplements the website's privacy policy and is written so you can read it on its own. Unlike the website, the Board has a backend and user accounts, so more data is processed here, and this page says which.
This English version is a translation for your convenience; the German version prevails.
Data controller
The controller within the meaning of the GDPR is Silvio Lindstedt und Maik Gräfendorf GbR, Pappelweg 27, 39576 Stendal, Germany. Email: [email protected]. Further details in the legal notice.
Principle
The Board processes only what a forum with accounts needs: your account data, your posts, technical logs for abuse prevention and the emails you receive. There is no advertising, no profiling and no sharing of your data for advertising purposes. You can read without an account.
Hosting (netcup)
The Board runs on a server of netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. The database, the application and the backups live there, and the Board's emails are sent through netcup as well. A data processing agreement under Art. 28 GDPR is in place with netcup. Legal basis for technical operation: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation) and, as far as your account is concerned, Art. 6(1)(b) GDPR.
Cloudflare (proxy and Turnstile)
All requests to the Board pass through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (represented in the EU by Cloudflare Portugal, Lda.). Cloudflare forwards requests, protects against attacks and sees your IP address and technical characteristics of your browser in the process.
On registration, password reset, the DSA report form and after failed logins, Cloudflare Turnstile is additionally loaded, a bot check without puzzles. Turnstile processes your IP address and browser characteristics for this; it sets no advertising cookies. It is not loaded on other pages.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in availability and abuse prevention). Where data reaches the USA, the transfer relies on the adequacy decision for the EU-US Data Privacy Framework, which Cloudflare has joined. See cloudflare.com/privacypolicy.
Your account
What data: handle, email address, password (only as an Argon2id hash, never in plain text), the avatar you chose from a fixed set, the optional "prior knowledge" and "context" fields, interface language, your notification settings, your TOTP secret (stored encrypted) and recovery codes (as hashes) if enabled, the "at least 16" confirmation and the accepted version of the terms with a timestamp.
Why: creating and running your account, sign-in, security, attributing your posts, notifications, proof of consent.
Legal basis: Art. 6(1)(b) GDPR (user agreement). For security features and the proof of consent additionally Art. 6(1)(f) and (c) GDPR.
Required or optional: handle, email address and password (or a sign-in provider) are required. Prior knowledge, context and TOTP are optional.
Signing in with Google or GitHub
Only if you choose to, you can sign in via Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) or GitHub (GitHub, Inc., 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA). The Board then receives from the provider only your email address and a provider-internal identifier (provider ID). The provider learns that you are signing in to the Board. No existing account is linked automatically, and the Board cannot read or write anything in your Google or GitHub account.
Legal basis: Art. 6(1)(b) GDPR. For processing at the provider itself, the provider's privacy notice applies (policies.google.com/privacy or docs.github.com/site-policy/privacy-policies/github-general-privacy-statement).
Password check against known breaches (Have I Been Pwned)
When you set a password, the Board checks whether it has appeared in known data breaches. To do this, your password is hashed locally with SHA-1 and only the first five characters of that hash are sent to the "Have I Been Pwned" service (haveibeenpwned.com). The service replies with a list of matching hash suffixes; the comparison happens on the Board's server. Your password and your full hash never leave the Board (k-anonymity). Nothing about you is transmitted. If the service is unreachable, the password is accepted without this check. Legal basis: Art. 6(1)(f) GDPR (protecting your account).
Bot protection (ALTCHA)
When you submit a post, your browser solves a small computational puzzle (ALTCHA, proof of work). This runs entirely on the Board; no data is sent to third parties and no cookies are set. Legal basis: Art. 6(1)(f) GDPR (spam prevention).
Server logs and IP addresses
On every request the server stores your IP address, the time, the address requested, your browser identifier and the status code. The Board also keeps an abuse log in which IP addresses are briefly recorded to enforce rate limits (for example on login attempts or registrations).
This data is deleted after 7 days. It is kept longer only if it is part of an open moderation or security case. Legal basis: Art. 6(1)(f) GDPR (abuse prevention, troubleshooting).
Sessions and cookies
The Board sets only the following cookies. None of them serves advertising or analytics, and none is passed to third parties.
__Host-kev_s(session): contains a random session identifier, nothing about you, and is valid only over HTTPS and only for the Board. It is set when you sign in, and already before that as soon as you open a form (for example sign-in, registration or the report form), because the protection against forged form submissions (CSRF) is tied to the session. Without an account it expires after 2 hours of inactivity and at the latest after 24 hours; for members after 30 days of inactivity and at the latest after 90 days. It is deleted when you sign out. For a signed-in session the Board stores a coarse browser and operating system description and the time of last activity, so you can see and end your sessions individually under "Account → Security".kev_lang(language): set when you switch the language with the "EN"/"DE" toggle. It contains only the language code and lasts one year. When you are signed in, the language stored in your account applies.kev_board_welcome(welcome note hidden): set when you dismiss the welcome note on the start page. It contains only the value "1" and lasts one year; "Show the welcome note again" on the rules page deletes it.kev_themeandkev_text_size(display): set when you change the colour scheme (light, dark or as in your system) or the text size. They contain only that choice, last one year and apply to the whole ki-einfach-verstehen.de domain, so the website and the Board show the same display. The Board reads them to deliver the page in your chosen display straight away.
The session cookie is technically necessary; the others store a setting you choose explicitly. None of them requires consent (§ 25(2) no. 2 TDDDG, German Telecommunications Digital Services Data Protection Act). Legal basis: Art. 6(1)(b) GDPR, for the setting cookies Art. 6(1)(f) GDPR (legitimate interest in keeping your chosen display).
Emails
For now the Board sends only account and security emails to your registered address: address verification, the password reset link, sign-in from a new device, changed password, confirmation and undo link for a changed address, and the confirmation that your account was deleted. These cannot be switched off while your account exists, because they protect your account.
Notifications (for example about answers to your question or @mentions) and a weekly digest are not sent yet. Under "Account → Notifications" you can already choose which of them you would like; only your choice is stored. Before such emails start, this policy will be extended, including how to unsubscribe from them.
Emails are sent through netcup's mail server (see Hosting). Outgoing emails are logged in a queue for up to 30 days. Legal basis: Art. 6(1)(b) GDPR; for the security emails also Art. 6(1)(f) GDPR.
Web analytics (Matomo)
The Board uses the same self-hosted Matomo instance as the website (matomo.silvio-und-maik.de) to evaluate, in aggregate, how the Board is used, for example how many questions are asked about a lesson. The analysis is cookie-free, the IP address is truncated to 2 bytes before storage, and no user identifier is passed on; Matomo does not know which account made a request. It records the technical characteristics described on the website, plus anonymous event counters ("question asked", "answer given", "marked as helpful", each with the lesson key).
Because no cookie is set and no information is stored on your device, no consent is required under § 25 TDDDG. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in needs-driven development). You may object (Art. 21 GDPR): tick the opt-out option in the field below.
Error monitoring (Sentry)
If a technical error occurs in the Board, an error report is sent to Sentry (Functional Software, Inc., 45 Fremont Street, San Francisco, CA 94105, USA) so the error can be fixed. The report contains the error type, the code path affected and technical environment data. Personal data is removed beforehand: no IP address, no email address, no handle, no cookies, no post content. Legal basis: Art. 6(1)(f) GDPR (stable operation). Sentry is certified under the EU-US Data Privacy Framework.
Public nature of your posts and profile
The Board is public. Everything you write can be read without signing in and found by search engines, including your edit history after the first ten minutes. Your public profile shows your handle, avatar, prior knowledge and context (if provided), the month you joined, how many people your answers have helped, and your posts. Your handle, avatar, prior knowledge and context also appear next to each of your posts. Not public are your email address, your last activity and your linked sign-in providers.
So think about what you publish. Questions without an answer are marked noindex so search engines do not pick them up. Posts are licensed under CC BY-SA 4.0 (see the terms of use) and may be redistributed by others.
Reports and moderation
When you report a post, the Board stores your report with the reason, the time and your account. If you use the report form at /melden without an account, it stores the details you enter there (URL, explanation, optionally name and email). Moderation decisions and the statements of reasons sent are recorded in a log visible only to the operators. Legal basis: Art. 6(1)(c) GDPR (obligations under the Digital Services Act) and (f) (defence of legal claims).
Retention periods
| Data | Purpose | Retention |
|---|---|---|
| Email address, password hash, provider ID | Account | until the account is deleted |
| Handle, avatar, prior knowledge/context, posts, reactions, votes | Community function | posts: anonymised on account deletion, otherwise as long as the Board exists |
| Sessions (hash, coarse browser info, last activity) | Sign-in | until expiry + 7 days |
| IP addresses (server log, abuse log) | Abuse prevention, rate limits | 7 days, then deleted; longer only in an open moderation case |
| Notifications | Function | 90 days |
| Outgoing emails (queue) | Delivery | 30 days |
| Reports, DSA notices, moderation log | Legal obligation, defence | 1 year after the case is closed |
| Backups | Recovery | 14 daily + 8 weekly; deletions reach backups only through rotation |
Backups are encrypted; the key is not stored on the server.
Account deletion and data export
Data export: under "Account", after re-authentication, you can download at any time a JSON file with your profile, all posts and revisions, reactions, votes and subscriptions (Art. 20 GDPR).
Account deletion: also under "Account". This deletes your email address, password hash, provider links, TOTP, sessions, subscriptions and notifications. Your profile becomes "Deleted member"; your posts remain under the CC BY-SA licence, without any link to you. @mentions of your handle in other people's posts remain as text and no longer link. Your handle becomes available again after 90 days. You receive a confirmation by email. In backups the data remains until rotation (at most about two months).
Your rights
Towards the controller you have the right to
- access your stored data (Art. 15 GDPR), for most data directly via the export under "Account";
- rectification (Art. 16), for example via the profile settings;
- erasure (Art. 17), via account deletion or by email;
- restriction of processing (Art. 18);
- data portability (Art. 20), via the export;
- object to processing based on legitimate interests (Art. 21), for example to web analytics.
For requests, write to [email protected]. You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for the controller is the State Commissioner for Data Protection of Saxony-Anhalt (Landesbeauftragter für den Datenschutz Sachsen-Anhalt), Leiterstraße 9, 39104 Magdeburg, Germany, datenschutz.sachsen-anhalt.de.
Automated decisions
The Board makes no automated decisions with legal effect for you (Art. 22 GDPR). One technical exception: if a post is reported by three different established accounts, the Board hides it automatically and provisionally until a human has reviewed it. The decision whether the post stays or is removed is always made by a human; you are informed with a statement of reasons and can object.
Minors
The Board is intended for people aged 16 and over. Younger people may read but may not create an account. If the operator learns that an account was created by a person under 16, it is deleted.
Changes
This policy is updated when the Board or the legal situation changes. The current version is always available at this address; the date at the top shows its status.