Privacy Policy

Last updated: 6 August 2026

This policy explains which personal data we process when you visit Teachlabs.app or use an academy hosted on it, why we process it, and which rights you have under the EU General Data Protection Regulation (GDPR).

1. Controller

The controller for the Teachlabs.app website and platform infrastructure is the operator of Teachlabs.app, reachable at info@philipp-bolender.com. Where a customer runs their own academy on our platform, that customer is the controller for the member data, course content and community content inside their academy, and we act as their processor.

2. Data we process

Depending on how you use the service we process:

  • Account data: email address, name or display name, password hash, profile image, authentication provider (e.g. Google sign-in), account status and timestamps.
  • Membership and role data: which academy you belong to, your roles and permissions, group memberships, invitations.
  • Learning data: course and module access, lesson progress, completion state, last viewed lesson.
  • Community data: posts, comments, reactions, bookmarks, points, levels and badges you earn.
  • Uploaded content: course cover images, media files, documents and videos you or your academy operator upload.
  • Communication data: emails you send us, support requests, invitation emails.
  • Technical log data: IP address, browser and device type, referring page, timestamps and error logs, generated automatically when you access the service.

3. Purposes and legal bases

  • Providing the platform, your account, course access and community features — performance of a contract, Art. 6(1)(b) GDPR.
  • Security, abuse prevention, fraud detection, backups and error analysis — legitimate interests, Art. 6(1)(f) GDPR.
  • Service emails such as sign-up confirmation, password reset and invitations — Art. 6(1)(b) GDPR.
  • Optional marketing emails — your consent, Art. 6(1)(a) GDPR, revocable at any time.
  • Compliance with statutory retention and accounting duties — Art. 6(1)(c) GDPR.

4. Cookies and local storage

We use strictly necessary cookies and browser local storage to keep you signed in, to remember which academy (tenant) you are visiting and to protect forms against abuse. These are required for the service to work and are set on the basis of our legitimate interest and your request to use the service. We do not use advertising cookies or cross-site tracking.

5. Processors and third-party services

We use carefully selected service providers who process data strictly on our instructions under data processing agreements pursuant to Art. 28 GDPR:

  • Cloud hosting, database, authentication and file storage — operating the application, storing your account, course and community data.
  • Vimeo — video hosting and streaming for course videos. When a lesson video is played, Vimeo receives technical connection data such as your IP address and device information. Vimeo's own privacy policy applies to that processing.
  • Email delivery provider — sending transactional emails such as confirmations, password resets and invitations.
  • Error and performance monitoring — detecting and fixing technical failures.

6. International transfers

Some of our providers process data outside the European Economic Area, in particular in the United States. In those cases the transfer is safeguarded by the EU Standard Contractual Clauses, by the provider's certification under the EU-US Data Privacy Framework, or by another legal transfer mechanism under Chapter V GDPR.

7. Retention

  • Account and membership data: for as long as your account exists, then deleted or anonymised within 90 days of deletion.
  • Learning progress and community content: for the lifetime of the academy you belong to, unless you request deletion earlier.
  • Server and security logs: normally 30 days, longer only where needed to investigate a concrete incident.
  • Invoices and accounting records: for the statutory retention periods (typically 6 to 10 years).

8. Your rights

Under the GDPR you have the right to access your data (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future.

To exercise your rights, write to info@philipp-bolender.com. If your request concerns data inside a specific academy, we will forward it to the operator of that academy, who is the controller for that data. You also have the right to lodge a complaint with a supervisory authority in your country of residence, workplace or place of the alleged infringement.

9. Data security

All traffic is encrypted in transit via TLS. Data is separated per academy at database level with row-level security so that members of one academy cannot access another academy's data. Access to production systems is restricted, passwords are stored only as salted hashes, and uploaded media is served through short-lived signed links.

10. Children

The service is not directed to children under 16. If you believe a child has provided us with personal data without the consent of a holder of parental responsibility, contact us and we will delete it.

11. Changes to this policy

We may update this policy to reflect changes to the service or to legal requirements. The current version is always available at https://teachlabs.app/legal/privacy. Material changes will be announced in the app or by email.

This document is a template provided for information purposes and does not constitute legal advice. Please have it reviewed by a qualified lawyer before relying on it.