Information on data processing according to Art. 13, 14 GDPR
Last updated: August 27, 2026
Kybernos is a platform for school course selection. This policy is for website visitors and schools. Technical details (encryption, logs, deletion jobs) are provided to schools and data-protection officers as an annex to the data processing agreement.
No advertising, no tracking network, no sharing of student data for marketing. Kybernos is offered exclusively to schools, school authorities and other institutional customers.
Teachers and school administrators sign in with email and password.
Controller for the public website and platform operation:
Linus Freund
trading under the business name „Seforth“
Einzelunternehmen
Mannheimer Straße 5
67117 Limburgerhof
Phone: +49 151 70635480
E-Mail: hello@kybernos.de
For school use (student accounts, elections, assignments) the school or school authority is the controller. Kybernos processes these data only as a processor. A contract under Art. 28 GDPR (DPA) is required. The school determines purposes and means and checks the school law of its German state.
Kybernos does not use school data for advertising, product profiling, training of AI models, sale of statistics or cross-school performance analysis.
For the public website and technical operation, the provider named above is itself the controller.
Purposes: Operating the website and platform, running course selection, IT security, support, responding to enquiries.
Legal bases: Art. 6(1)(b) GDPR (contract/use), (f) (operations and security); for school data Art. 28 GDPR on behalf of the school. Consent only where we expressly ask for it.
Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen. A data processing agreement is in place. Storage location: European Union.
Email sending: netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe. A data processing agreement is in place.
For HTTPS certificates we use Let’s Encrypt (ISRG, USA). Technical domain data are transmitted, not school or account data. Whether a transfer of personal data to a third country occurs depends on how those technical data are classified — not merely on the provider’s seat.
No content delivery network, no marketing trackers, no third-party login, no external error monitoring. Source code is hosted on GitHub; school production data is not processed there.
| Data | Duration |
|---|---|
| School accounts and election data | until end of contract, then export and deletion per DPA |
| Security logs | 90 days |
| Usage statistics | 180 days |
| Server logs (incl. IP) | 14 days |
| Backups | 30 days |
| Support tickets after closure | 12 months, unless longer retention is required for performing the contract or defending legal claims. Open tickets remain until closure. |
| Contact enquiries | as long as handling and follow-up require |
For sign-in we set technically necessary cookies (session, at most 12 hours, plus a security cookie). An appearance preference is stored only if you toggle it yourself. There is no advertising tracking and therefore no consent banner. Cookie names and lifetimes are in the cookie policy.
In addition we store server-side which public or signed-in pages were opened (path, optional referrer, country). This is for operations and abuse detection, not advertising and not building profiles of individuals. No user ID is stored. Hashing does not automatically make the data anonymous.
Legal basis for the statistic: Art. 6(1)(f) GDPR. We do not set cookies for it. We do not use a consent banner under Section 25 TDDDG because this statistic does not read storage or information on the end device.
Signed-in users can send requests as tickets. Attachments are only links to publicly reachable HTTPS addresses — Kybernos does not store the files itself and does not download them server-side. Whoever hosts the file processes it under their own rules.
Creators see only their own tickets. Internal staff of the provider (not of other schools) can view tickets across schools for handling; that access is logged. After closure we delete tickets automatically after the period stated above.
The platform calculates an assignment suggestion. A teacher or school administrator reviews it, can change assignments and only then releases the result. There is no solely automated decision with legal effect within the meaning of Art. 22 GDPR.
Transmission between the browser and our servers is encrypted (HTTPS/TLS). TLS protects the connection, not compromised devices, accounts or internal access-control errors.
Access is role-based and separated by school. Backups are stored encrypted. The concrete technical and organisational measures (TOMs) are an annex to the DPA.
You have the rights of access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR) and the right to withdraw consent. You may lodge a complaint with a data-protection supervisory authority.
Competent authority
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz
https://www.datenschutz.rlp.de/Contact: hello@kybernos.de — for school data please contact your school first. Platform-related access is also available via the “My Data” page.
This policy describes the documented processing. If processing changes, this policy and the internal inventory are updated. Contract terms: Terms.
Last updated: August 27, 2026