Privacy Policy
The Inequality Explorer collects numerical estimates of wealth distribution and compares them with real data, to support classroom discussion of perceptions of inequality.
Controller
The controller within the meaning of Art. 4(7) GDPR is
Urs Müller, Gotenstr. 21, 10829 Berlin, Germany —
info@inequality-explorer.org.
Who is responsible for what. For educator and administrator accounts, for security and abuse prevention, and for the retained analysis data — anonymous counters in some tools, pseudonymous rows in others; each tool's retention section says which — we are the controller. Where an institution has contracted us to run this tool for its own programme, the institution is the controller for the identifiable data of that cohort, and we process it on the institution's behalf (Art. 28 GDPR). In practice: for a request concerning your cohort's identifiable data, please approach your educator or institution first; for anything concerning accounts, security or the retained analysis data, contact us. We assist the institution in answering requests in either case (Art. 28(3)(e) GDPR).
Data protection officer: no data protection officer is appointed. § 38 BDSG has three separate triggers and we have assessed all three: headcount (at least 20 persons constantly engaged in automated processing — this service is operated by one person), processing that requires a data protection impact assessment under Art. 35 GDPR, and commercial processing for the purpose of transfer, anonymised transfer, or market or opinion research. The last two apply regardless of headcount. Our assessment is recorded in DPIA-DETERMINATION.md and is revisited whenever the scope or purpose of processing changes — in particular if cross-class research use becomes a purpose in its own right rather than support for the individual course.
What data we process
From participants
- Name or pseudonym — identifies your response to the session educator.
- E-mail address — optional, only if provided.
- Session code — links your response to a specific session.
- Responses — your numerical estimates of wealth distribution.
- Optional demographics — age range, gender, income bracket.
- Two optional political-opinion questions — your level of agreement with statements on wealth redistribution and on regulating personal lifestyle choices. These reveal a political opinion, a special category of data under Art. 9(1) GDPR. They are stored only if you tick the separate box giving explicit consent; if you do not, the answers are discarded and never written to the database, even if you filled them in. Skipping them changes nothing else about your participation.
- Reflection answers — an optional page after your results asks how confident you were beforehand, what surprised you most, whether your view of an ideal distribution changed, and offers a free-text box. Only what you type is stored. Please do not put names or anything sensitive in the free-text box: unlike the other fields it can contain anything, so it is emptied for everyone at the anonymisation deadline, whatever you chose about research use.
- Your consent choices — whether you agreed to research use and to the political questions, with the date and the version of the wording you were shown. This is what makes a consent provable, and it is kept for as long as the data it covers.
- Submission timestamp.
From educators
- E-mail address — for backoffice sign-in.
- Password — stored only as a bcrypt hash.
- Session data — names, codes, configuration, responses.
Legal bases
- Running the survey and the class debrief — Art. 6(1)(f) GDPR, our legitimate interest in supporting the educational programme in which participants take part.
- The two political-opinion questions — Art. 9(2)(a) explicit consent, given by ticking the dedicated box on the demographics page. This is a separate box from the research one on purpose: you can help with research and still decline the political questions. Without that tick the answers are not stored at all.
- Keeping demographics and reflection answers past the 30-day window, and using them outside your own educator's teaching — your separate consent (Art. 6(1)(a)), also its own unticked box. Within the window and within your educator's own courses, those answers feed the session debrief and your educator's cross-session summary on Art. 6(1)(f); that is the teaching the session is part of. If you decline, they are deleted at the 30-day mark instead of being kept.
- Educator accounts — Art. 6(1)(b) GDPR.
- Security, rate-limiting and abuse prevention — Art. 6(1)(f) GDPR.
Recipients and third-country transfers
We use no third parties for advertising, analytics or tracking, and we do not sell or share personal data for marketing purposes. The following providers process data on our behalf as processors under a data processing agreement pursuant to Art. 28 GDPR:
- IONOS SE (Germany) — hosting and outgoing e-mail.
- Microsoft Ireland Operations Ltd. (OneDrive) — storage of the weekly off-site backup copies. Those backups are encrypted before they leave the server, and the private key exists only on the operator's own machine — never at the provider. So Microsoft holds ciphertext it cannot read.
- healthchecks.io — monitoring that the backup run happened. Only status pings are sent ("run succeeded / failed"); no content and no participant data.
Transfers outside the EU/EEA: processing takes place in the EU; the servers and databases are in Germany. Two things are worth stating in full. Microsoft (OneDrive) provides for transfers outside the EEA under Art. 46 GDPR safeguards (EU standard contractual clauses) — what reaches it is only the backup copies, encrypted before they leave the server, whose key we do not hand over. And healthchecks.io runs infrastructure in the EU and the US, but receives only backup-run status pings: no participant data and no content.
What this means for erasure: when a record is deleted, a copy may remain inside backups until those expire: up to 14 days in the backups held on the server, and up to 30 days in the encrypted off-site copies. Backups are used only to restore the service after a failure, never for ordinary processing.
How long we keep data
- After 30 days, what happens depends on your consent. In every case your name and e-mail address are removed, and the free-text reflection box is emptied for everyone. If you did not consent to research use, your demographic and reflection answers are deleted outright at the same moment. If you did consent, they are kept — but the record is cut loose from your class: the link to the session is removed and the timestamp is reduced to the month, so the answers sit in a large cross-class pool instead of a group of twenty where a combination of age, gender and income could point at one person.
- What that means for you: once the 30 days have passed we can no longer find your individual response, so a withdrawal request has to reach us before then. Until then, write to us and we will delete it.
- This routine had been broken since the feature was written — the database rejected the deletion every time, and it only ran at start-up — and was repaired on 2026-07-30/31. A test now executes the deletion itself on every deploy rather than merely checking that the code exists.
- Manual anonymisation: educators can anonymise or archive a session at any time before the 30-day window ends. Doing so applies exactly the steps described above, immediately — it is the same routine, not a lighter version of it.
Who can see your data
- Educators see who responded (names or pseudonyms) but not individual response values linked to a person; responses are shown in aggregate or anonymised form. The session summary does quote reflection notes back to the educator, without a name attached — so please write nothing there you would not want the room to read. Educators can delete erroneous entries in their own sessions, and see a summary across their own sessions.
- The administrator has technical access for maintenance and security only.
Data security
- The server is located in Germany.
- All transmission is encrypted using HTTPS/TLS.
- Passwords are stored only as bcrypt hashes, never in plain text.
- Session cookies are signed and HTTP-only.
- Web fonts are served from our own server — no third-party CDNs, so no data flows to third parties when fonts load.
- IP addresses processed for rate-limiting are held in memory only and never written to the database.
Server log files
Our web server records standard access log entries: IP address, date and time, the resource requested, HTTP status, referrer and browser identifier. These logs are used solely to operate and secure the service, are not combined with other data, are not used to identify individuals or build profiles, and are rotated and deleted after 14 days. IP addresses processed for rate-limiting are held in memory only and never written to the database.
Administrative audit trail. If you use an educator account, we record security-relevant actions — successful and failed sign-ins, password changes and resets, creating, changing and deleting accounts, and deleting or anonymising class data — each with the time, the account's e-mail address and the IP address. The basis is our legitimate interest (Art. 6(1)(f) GDPR) in being able to reconstruct unauthorised access to an account. These entries are deleted after 12 months. Participants are not affected.
Your rights
You have the following rights:
- Access (Art. 15 GDPR) — what data we hold about you.
- Rectification (Art. 16 GDPR) — correction of inaccurate data.
- Erasure (Art. 17 GDPR) — deletion of your personal data.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) — your data in a structured, machine-readable format.
- Withdrawal of consent (Art. 7(3) GDPR) — at any time, with effect for the future, as easily as it was given.
Your right to object. Where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to that processing at any time, for reasons arising from your particular situation. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests. To object, write to info@inequality-explorer.org.
Response time. We aim to respond to enquiries promptly. Requests concerning your personal data are answered within the period required by Art. 12(3) GDPR (one month at the latest).
Erasure and withdrawal on this tool
Within the first 30 days, ask your educator (who can delete individual entries) or write to us naming the session and the name you used — your entry can be found and removed. After 30 days the record has been anonymised and, if you consented to research use, detached from your class, so we genuinely cannot identify which row was yours. You can also withdraw a consent you gave at any time by writing to us; that stops any further use, though it cannot reach a record we can no longer locate.
Whether you must provide data
Providing data is neither a statutory nor a contractual requirement. A name or pseudonym is needed so your educator can see who has responded. Everything on the demographics page is voluntary: every field offers “prefer not to say”, the whole page can be skipped, and neither consent box has to be ticked. Declining any of it does not affect your results, the class discussion, or anything else.
Supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for our location is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
www.datenschutz-berlin.de
Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.