Privacy Policy
The Whiteout Exercise presents a survival scenario in which participants rank 16 items individually and then as a group, to support debriefs on team decision-making.
Controller
The controller within the meaning of Art. 4(7) GDPR is
Urs Müller, Gotenstr. 21, 10829 Berlin, Germany —
info@whiteout-exercise.org.
Who is responsible for what. For educator and administrator accounts, for security and abuse prevention, and for the retained analysis data — anonymous counters in some tools, pseudonymous rows in others; each tool's retention section says which — we are the controller. Where an institution has contracted us to run this tool for its own programme, the institution is the controller for the identifiable data of that cohort, and we process it on the institution's behalf (Art. 28 GDPR). In practice: for a request concerning your cohort's identifiable data, please approach your educator or institution first; for anything concerning accounts, security or the retained analysis data, contact us. We assist the institution in answering requests in either case (Art. 28(3)(e) GDPR).
Data protection officer: no data protection officer is appointed. § 38 BDSG has three separate triggers and we have assessed all three: headcount (at least 20 persons constantly engaged in automated processing — this service is operated by one person), processing that requires a data protection impact assessment under Art. 35 GDPR, and commercial processing for the purpose of transfer, anonymised transfer, or market or opinion research. The last two apply regardless of headcount. Our assessment is recorded in DPIA-DETERMINATION.md and is revisited whenever the scope or purpose of processing changes — in particular if cross-class research use becomes a purpose in its own right rather than support for the individual course.
What data we process
From participants
- E-mail address — required to join a session. It is stored with your ranking and is visible to your educator in the session's participant list. We send mail to it in exactly two cases: if someone tries to rejoin your session with your address from a device that is not already signed in, we send a one-time link so that only you can continue; and seven days before the class is erased we send you one notice with your personal withdrawal link. There is no newsletter and no other use.
- Your consent, as a record — that you ticked the box to take part, whether you ticked the separate research box, when, and which version of this notice and of the consent wording you were shown. We keep it because we have to be able to show that consent was actually given (Art. 7(1)).
- A pseudonymous session token in a cookie, linking your responses within one session.
- Session code — attributes your response to the correct group session.
- Your item rankings — individual and, where applicable, the group ranking.
- Submission timestamp.
- Your prediction — on the screen after your ranking you are asked, in one click, how you think it will compare with the rest of the class. It is required: the gap between what a class expected and what happened is part of what the exercise teaches. It is stored with your ranking and shown to your educator as class totals and as one unnamed point per person on a chart of predictions against results — never labelled with your name. In a small class, an educator who can see everyone's score could work out which point is yours.
- How often you are outdoors in winter — asked on that same screen and optional; "prefer not to say" is preselected. If you answer, the answer is stored with your response — on the same record as your e-mail address, like your ranking, not behind the demographics consent described below. Your educator sees it only as averages over at least five people, never next to your name, and it is not part of the data export.
- Closing questions, in sessions that include them — some sessions end a group round with two short private questions: which considerations came up in your group's discussion, and what happened to what you yourself knew. Required in those sessions, stored with your response, and shown to your educator only in combined form — per group as majority counts, and the self-descriptions only as totals over at least five people. If you gave the separate research consent, these answers are among those kept beyond the class; the group's written reason for its decision is not kept, because free text can contain anything and no consent can cover what nobody can predict.
- What your group had decided, in sessions with the optional second round — before the second round's material is shown, you are asked privately what your group had explicitly agreed to do in the situation: stay, leave, split the group, no agreement, or not discussed as a separate question. Required in those sessions, stored with your response, shown as counts per group — never next to your name. Your educator may show those counts to the class after the exercise, so a group that answers unanimously can be read off them. Deleted with the class, and not part of the research data.
- What you yourself would have done, in sessions with the optional second round — after you have read the shared update and your own recollection, and before your group talks again, you are asked privately whether you would stay with the van or try to reach help. Required in those sessions, stored with your response, shown as counts per group — never next to your name. Your educator may show those counts to the class after the exercise, so a group that leans unanimously can be read off them. Deleted with the class, and not part of the research data.
- Optional demographics — age band, gender, years of work experience, experience leading a team, field of study or work, and country. Every one of these is optional, the whole page can be skipped, and nothing is stored unless you tick the consent box. They are shown to your educator only as group averages, and never for a group of fewer than five people. Your country answer is also shown grouped into a world region. We record when you consented and which version of this notice and of the consent wording you saw.
From educators
- Login credentials — the password is stored only as a bcrypt hash.
- Session data — names, codes and configuration of sessions you create.
Legal bases
- Running the exercise and producing group results — Art. 6(1)(f) GDPR, our legitimate interest in supporting the educational programme in which participants take part.
- Optional demographics — Art. 6(1)(a) GDPR, your consent. You give it by ticking a box that is not ticked for you, you can skip the page entirely without any effect on the exercise, and you may withdraw it at any time by writing to us, after which the answers are deleted.
- Keeping your answers beyond the class, for research and teaching — Art. 6(1)(a) GDPR, your separate consent, with the safeguards of Art. 89(1). It is a second box, also not ticked for you, on the same screen as the first. Leaving it unticked changes nothing about taking part: you are grouped, you see your results, and everything of yours is simply erased with the rest of the class. Ticking it means one row is kept after the class is erased — see "How long we keep data" — and you can withdraw that consent at any time, with no deadline, using the link we e-mail you before the class is erased.
- Educator accounts — Art. 6(1)(b) GDPR.
- Security, rate-limiting and abuse prevention — Art. 6(1)(f) GDPR.
Recipients and third-country transfers
We use no third parties for advertising, analytics or tracking, and we do not sell or share personal data for marketing purposes. The following providers process data on our behalf as processors under a data processing agreement pursuant to Art. 28 GDPR:
- IONOS SE (Germany) — hosting and outgoing e-mail.
- Microsoft Ireland Operations Ltd. (OneDrive) — storage of the weekly off-site backup copies. Those backups are encrypted before they leave the server, and the private key exists only on the operator's own machine — never at the provider. So Microsoft holds ciphertext it cannot read.
- healthchecks.io — monitoring that the backup run happened. Only status pings are sent ("run succeeded / failed"); no content and no participant data.
Transfers outside the EU/EEA: processing takes place in the EU; the servers and databases are in Germany. Two things are worth stating in full. Microsoft (OneDrive) provides for transfers outside the EEA under Art. 46 GDPR safeguards (EU standard contractual clauses) — what reaches it is only the backup copies, encrypted before they leave the server, whose key we do not hand over. And healthchecks.io runs infrastructure in the EU and the US, but receives only backup-run status pings: no participant data and no content.
What this means for erasure: when a record is deleted, a copy may remain inside backups until those expire: up to 14 days in the backups held on the server, and up to 30 days in the encrypted off-site copies. Backups are used only to restore the service after a failure, never for ordinary processing.
How long we keep data
- Everything from a class is erased 30 days after the session finishes. That means your e-mail address, your ranking, your group, your votes, the boards, the results page and the session itself. It runs automatically, it cannot be undone, and it is the same date for everyone in the class. A session that is never finished is erased 30 days after its last submission instead; a session nobody ever joined is deleted 90 days after it was created.
- Your educator can postpone that date by 30 days, up to three times — never further, and never earlier than a date you have already been told. They are warned 14 days before, and if the date is still approaching, you are e-mailed 7 days before so you can withdraw first. That is the only such message you get for a class.
- If you gave the separate research consent, one row of yours is kept when the class is erased, and kept indefinitely: your ranking, your score, your group's result, your optional answers about yourself, your answers to the closing round in sessions that include one, and the half-year it happened in. Nothing is kept from anyone who did not tick that box — their answers are deleted with the class and never counted. It carries no e-mail address, no name, no class, no group name and no date more precise than the half-year, and the link between it and you is destroyed with the class. It is not anonymous — a ranking plus several bands can still be rare — so we treat it as personal data throughout, keep it only for research and teaching, and never publish anything that stands for fewer than five people. You can withdraw it at any time, with no time limit, using the link in that 7-day e-mail.
- Educator accounts — retained until deactivated or deleted by an administrator.
Who can see your data
- Educators see, for their own sessions, the participant list including each participant's e-mail address, alongside the individual and group rankings. Demographics are shown to them only as averages over at least five people — never next to a name. Answers given by fewer than five people are not shown separately; they are either withheld or combined with other rare answers into a single "everyone else" figure that also covers at least five people.
- Your class may be shown those same demographic averages during the debrief, and they may be included in a written summary your educator hands out afterwards. That is part of the discussion the answers are collected for. The five-person floor and the "everyone else" pooling apply exactly as above, so nothing is shown that stands for fewer than five people — but be aware that five people in a room where everyone knows each other are not anonymous in the way five strangers would be. If you would rather your answers were not part of that, skip the questions, or ask your educator to delete them.
- The administrator has technical access for maintenance and security only.
Data security
- The server is located in Germany.
- All transmission is encrypted using HTTPS/TLS.
- Passwords are stored only as bcrypt hashes, never in plain text.
- Session cookies are signed and HTTP-only.
- Web fonts are served from our own server — no third-party CDNs, so no data flows to third parties when fonts load.
- IP addresses processed for rate-limiting are held in memory only and never written to the database.
Server log files
Our web server records standard access log entries: IP address, date and time, the resource requested, HTTP status, referrer and browser identifier. These logs are used solely to operate and secure the service, are not combined with other data, are not used to identify individuals or build profiles, and are rotated and deleted after 14 days. IP addresses processed for rate-limiting are held in memory only and never written to the database.
Administrative audit trail. If you use an educator account, we record security-relevant actions — successful and failed sign-ins, password changes and resets, creating, changing and deleting accounts, and deleting or anonymising class data — each with the time, the account's e-mail address and the IP address. The basis is our legitimate interest (Art. 6(1)(f) GDPR) in being able to reconstruct unauthorised access to an account. These entries are deleted after 12 months. Participants are not affected.
Your rights
You have the following rights:
- Access (Art. 15 GDPR) — what data we hold about you.
- Rectification (Art. 16 GDPR) — correction of inaccurate data.
- Erasure (Art. 17 GDPR) — deletion of your personal data.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) — your data in a structured, machine-readable format.
- Withdrawal of consent (Art. 7(3) GDPR) — at any time, with effect for the future, as easily as it was given.
Your right to object. Where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to that processing at any time, for reasons arising from your particular situation. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests. To object, write to info@whiteout-exercise.org.
Response time. We aim to respond to enquiries promptly. Requests concerning your personal data are answered within the period required by Art. 12(3) GDPR (one month at the latest).
Erasure and withdrawal on this tool
While the class still exists your e-mail address identifies your submission, so we can always find and delete it: write to us, or ask your educator, naming the session code and the address you joined with. Educators can delete a single participant's response, or a whole session, at any time. If you gave optional demographics, withdrawing that consent deletes those answers and nothing else — the exercise results are unaffected.
After the class is erased there is nothing of yours left to find unless you gave the separate research consent. That row we cannot find either — by design, it carries no address and nothing linking it to you — so it can only be reached with the personal link in the e-mail we send you seven days before the class is erased. Keep that e-mail. Opening the link shows you what would be removed and removes nothing until you confirm; use it before the deadline and it deletes your class answers as well. There is no time limit on it.
Whether you must provide data
Providing data is neither a statutory nor a contractual requirement, but an e-mail address is technically required to join a session — without it a submission cannot be recorded.
Supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for our location is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
www.datenschutz-berlin.de
Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
Diese Datenschutzerklärung ist auch auf Deutsch verfügbar.