Inequality Explorer

Privacy Policy

The Inequality Explorer collects numerical estimates of wealth distribution and compares them with real data, to support classroom discussion of perceptions of inequality.

Controller

The controller within the meaning of Art. 4(7) GDPR is
Urs Müller, Gotenstr. 21, 10829 Berlin, Germany — info@inequality-explorer.org.

Who is responsible for what. For educator and administrator accounts, for security and abuse prevention, and for the retained analysis data — anonymous counters in some tools, pseudonymous rows in others; each tool's retention section says which — we are the controller. Where an institution has contracted us to run this tool for its own programme, the institution is the controller for the identifiable data of that cohort, and we process it on the institution's behalf (Art. 28 GDPR). In practice: for a request concerning your cohort's identifiable data, please approach your educator or institution first; for anything concerning accounts, security or the retained analysis data, contact us. We assist the institution in answering requests in either case (Art. 28(3)(e) GDPR).

Data protection officer: no data protection officer is appointed. § 38 BDSG has three separate triggers and we have assessed all three: headcount (at least 20 persons constantly engaged in automated processing — this service is operated by one person), processing that requires a data protection impact assessment under Art. 35 GDPR, and commercial processing for the purpose of transfer, anonymised transfer, or market or opinion research. The last two apply regardless of headcount. Our assessment is recorded in DPIA-DETERMINATION.md and is revisited whenever the scope or purpose of processing changes — in particular if cross-session research use becomes a purpose in its own right rather than support for the individual course.

What data we process

From participants

From educators

Legal bases

Recipients and third-country transfers

We use no third parties for advertising, analytics or tracking, and we do not sell or share personal data for marketing purposes. The following providers process data on our behalf as processors under a data processing agreement pursuant to Art. 28 GDPR:

Transfers outside the EU/EEA: processing takes place in the EU; the servers and databases are in Germany. Two things are worth stating in full. Microsoft (OneDrive) provides for transfers outside the EEA under Art. 46 GDPR safeguards (EU standard contractual clauses) — what reaches it is only the backup copies, encrypted before they leave the server, whose key we do not hand over. And healthchecks.io runs infrastructure in the EU and the US, but receives only backup-run status pings: no participant data and no content.

What this means for erasure: when a record is deleted, a copy may remain inside backups until those expire: up to 14 days in the backups held on the server, and up to 30 days in the encrypted off-site copies. Backups are used only to restore the service after a failure, never for ordinary processing.

How long we keep data

Who can see your data

Data security

Server log files

Our web server records standard access log entries: IP address, date and time, the resource requested, HTTP status, referrer and browser identifier. These logs are used solely to operate and secure the service, are not combined with other data, are not used to identify individuals or build profiles, and are rotated and deleted after 14 days. IP addresses processed for rate-limiting are held in memory only and never written to the database.

Administrative audit trail. If you use an educator account, we record security-relevant actions — successful and failed sign-ins, password changes and resets, creating, changing and deleting accounts, and deleting or anonymising session data — each with the time, the account's e-mail address and the IP address. The basis is our legitimate interest (Art. 6(1)(f) GDPR) in being able to reconstruct unauthorised access to an account. These entries are deleted after 12 months. Participants are not affected.

Your rights

You have the following rights:

Your right to object. Where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to that processing at any time, for reasons arising from your particular situation. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests. To object, write to info@inequality-explorer.org.

Response time. We aim to respond to enquiries promptly. Requests concerning your personal data are answered within the period required by Art. 12(3) GDPR (one month at the latest).

Erasure and withdrawal on this tool

You can delete your own response. Every response gets a personal deletion link, shown once when you finish. Opening it shows what would be removed and asks you to type a word to confirm; nothing happens until you do.

If you no longer have your deletion link, ask for a new one at /withdrawal-link with the session code and the e-mail address you took part with. We send it to that address and nowhere else, and we answer the same way whether or not we hold it, so the page cannot be used to find out who took part. The new link replaces any earlier one, which stops working at that moment. We keep only a one-way fingerprint of these links, never the link itself, so a copy of our database gives nobody the power to delete your data — which is also why we cannot re-send the one you had.

What happens at the session's deadline depends on one answer you gave. If you did not agree to research use, your whole response is deleted at the deadline — there is nothing left to withdraw and nothing left to count. If you agreed, the pseudonymous research record remains, cut loose from your session, and the link keeps working on it for as long as it exists. What we cannot do after the deadline is find that record for you, because nothing then connects it to your name or address. You can still write to us or to your educator before that date.

If you gave no e-mail address, the link shown when you finished is the only one you will get, and we cannot send you another.

Whether you must provide data

Providing data is neither a statutory nor a contractual requirement. A name or pseudonym is needed so your educator can see who has responded. Everything on the demographics page is voluntary: every field offers “prefer not to say”, the whole page can be skipped, and neither consent box has to be ticked. Declining any of it does not affect your results, the session debrief, or anything else.

Supervisory authority

You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for our location is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
www.datenschutz-berlin.de

Automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.