Privacy Policy
The Controversy Generator collects short survey responses to opinion statements and pairs participants with differing viewpoints, to support structured discussion in classrooms and organisations.
Controller
The controller within the meaning of Art. 4(7) GDPR is
Urs Müller, Gotenstr. 21, 10829 Berlin, Germany —
info@controversygenerator.org.
Who is responsible for what. For educator and administrator accounts, for security and abuse prevention, and for the retained analysis data — anonymous counters in some tools, pseudonymous rows in others; each tool's retention section says which — we are the controller. Where an institution has contracted us to run this tool for its own programme, the institution is the controller for the identifiable data of that cohort, and we process it on the institution's behalf (Art. 28 GDPR). In practice: for a request concerning your cohort's identifiable data, please approach your educator or institution first; for anything concerning accounts, security or the retained analysis data, contact us. We assist the institution in answering requests in either case (Art. 28(3)(e) GDPR).
Data protection officer: no data protection officer is appointed. § 38 BDSG has three separate triggers and we have assessed all three: headcount (at least 20 persons constantly engaged in automated processing — this service is operated by one person), processing that requires a data protection impact assessment under Art. 35 GDPR, and commercial processing for the purpose of transfer, anonymised transfer, or market or opinion research. The last two apply regardless of headcount. Our assessment is recorded in DPIA-DETERMINATION.md and is revisited whenever the scope or purpose of processing changes — in particular if cross-class research use becomes a purpose in its own right rather than support for the individual course.
What data we process
From survey participants
- Name or username — as entered by you; a pseudonym is fine.
- E-mail address — optional unless your educator turns it on for a particular survey, in which case it is required to submit. Each survey says which applies.
- Survey code — attributes your response to the correct survey.
- Survey responses — your answers to the opinion statements, stored as numerical values. Depending on the statements chosen by your educator, your answers can reveal personal views.
- Submission timestamp.
From educators and administrators
- E-mail address — for backoffice sign-in.
- Password — stored only as a bcrypt hash.
- Survey data — titles, items and settings of surveys you create.
Legal bases
- Running the survey and pairing discussion partners — Art. 6(1)(a) GDPR, your consent, given by ticking the required box before you submit. You can withdraw it at any time until the survey is consolidated (see Retention), using the link on your confirmation page; withdrawing does not affect processing that already happened. Every answer here is treated as data about your personal views — including political, religious or philosophical positions — whatever the statements happen to ask, so this is always explicit consent within the meaning of Art. 9(2)(a). We do not judge that statement by statement.
- Research and teaching beyond your class — Art. 6(1)(a) GDPR, a separate optional consent. Declining changes nothing about your participation, your results or your discussion pairing; it means your answers are deleted at the retention deadline rather than counted into the anonymous totals described under Retention.
- Educator and administrator accounts — Art. 6(1)(b) GDPR, performance of the arrangement under which the account was created.
- Security, rate-limiting and abuse prevention — Art. 6(1)(f) GDPR, our legitimate interest in operating the service securely.
Recipients and third-country transfers
We use no third parties for advertising, analytics or tracking, and we do not sell or share personal data for marketing purposes. The following providers process data on our behalf as processors under a data processing agreement pursuant to Art. 28 GDPR:
- IONOS SE (Germany) — hosting and outgoing e-mail.
- Microsoft Ireland Operations Ltd. (OneDrive) — storage of the weekly off-site backup copies. Those backups are encrypted before they leave the server, and the private key exists only on the operator's own machine — never at the provider. So Microsoft holds ciphertext it cannot read.
- healthchecks.io — monitoring that the backup run happened. Only status pings are sent ("run succeeded / failed"); no content and no participant data.
Transfers outside the EU/EEA: processing takes place in the EU; the servers and databases are in Germany. Two things are worth stating in full. Microsoft (OneDrive) provides for transfers outside the EEA under Art. 46 GDPR safeguards (EU standard contractual clauses) — what reaches it is only the backup copies, encrypted before they leave the server, whose key we do not hand over. And healthchecks.io runs infrastructure in the EU and the US, but receives only backup-run status pings: no participant data and no content.
What this means for erasure: when a record is deleted, a copy may remain inside backups until those expire: up to 14 days in the backups held on the server, and up to 30 days in the encrypted off-site copies. Backups are used only to restore the service after a failure, never for ordinary processing.
How long we keep data
- One deadline, set when your survey closes. Thirty days after your educator closes a survey, it is consolidated: the individual responses are erased — names, e-mail addresses, submission times and the record of who was paired with whom. Answers from participants who ticked the optional research box are first counted into anonymous per-statement totals; everyone else's are deleted without being counted. A daily job enforces this.
- If a survey is never closed, it is consolidated 30 days after the last response instead, so nothing can stay open indefinitely.
- If a survey never receives a response, it is simply deleted 90 days after it was created.
- Postponement: the educator is warned 14 days before the date and can push it back by 30 days, at most three times — no later than 120 days after the survey closed or the last response, which is 90 days beyond the original deletion date. If you gave an e-mail address, you are warned 7 days before.
- After consolidation only anonymous totals remain, and they are kept indefinitely. They cannot be traced back to you, to your class or to a date, which is also why a response cannot be withdrawn once that day has passed.
- Manual deletion: educators and administrators can delete whole surveys or individual submissions at any time before then.
Who can see your data
- Educators see participant names, e-mail addresses (where provided) and individual responses for their own surveys only.
- Anonymous statement statistics are shared between educators. Once a survey is consolidated, what remains is a count of how many people chose each point on the scale for each statement, per half-year. Those totals are pooled across all classes and are visible to every educator using the same statement from the shared library. They are shown only where at least two different surveys and at least five responses stand behind the figure, so no single class can be read out of them, and they contain nothing that identifies a person, a class or a date.
- The administrator has technical access for maintenance and security purposes only.
Data security
- The server is located in Germany.
- All transmission is encrypted using HTTPS/TLS.
- Passwords are stored only as bcrypt hashes, never in plain text.
- Session cookies are signed and HTTP-only.
- Web fonts are served from our own server — no third-party CDNs, so no data flows to third parties when fonts load.
- IP addresses processed for rate-limiting are held in memory only and never written to the database.
Server log files
Our web server records standard access log entries: IP address, date and time, the resource requested, HTTP status, referrer and browser identifier. These logs are used solely to operate and secure the service, are not combined with other data, are not used to identify individuals or build profiles, and are rotated and deleted after 14 days. IP addresses processed for rate-limiting are held in memory only and never written to the database.
Administrative audit trail. If you use an educator account, we record security-relevant actions — successful and failed sign-ins, password changes and resets, creating, changing and deleting accounts, and deleting or anonymising class data — each with the time, the account's e-mail address and the IP address. The basis is our legitimate interest (Art. 6(1)(f) GDPR) in being able to reconstruct unauthorised access to an account. These entries are deleted after 12 months. Participants are not affected.
Your rights
You have the following rights:
- Access (Art. 15 GDPR) — what data we hold about you.
- Rectification (Art. 16 GDPR) — correction of inaccurate data.
- Erasure (Art. 17 GDPR) — deletion of your personal data.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) — your data in a structured, machine-readable format.
- Withdrawal of consent (Art. 7(3) GDPR) — at any time, with effect for the future, as easily as it was given.
Your right to object. Where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to that processing at any time, for reasons arising from your particular situation. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests. To object, write to info@controversygenerator.org.
Response time. We aim to respond to enquiries promptly. Requests concerning your personal data are answered within the period required by Art. 12(3) GDPR (one month at the latest).
Erasure and withdrawal on this tool
Until your survey is consolidated you can withdraw your response yourself, using the withdrawal link on your confirmation page, or ask your educator (who can delete individual submissions) or us. The date is shown to you before you submit, and if you gave an e-mail address you are reminded seven days beforehand.
After that date we cannot do it, and neither can anyone else. Consolidation erases the individual responses and leaves only anonymous totals, so there is nothing left that could be identified as yours and removed. This is a deliberate design: it is what makes the remaining figures genuinely anonymous rather than merely stripped of a name.
Whether you must provide data
Providing data is neither a statutory nor a contractual requirement. A name (which may be a pseudonym) is needed to take part so that your educator can attribute responses. The e-mail address is optional by default; an educator can make it required for their own survey, and where they have, you cannot submit without it.
Supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for our location is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
www.datenschutz-berlin.de
Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.