Back to home

Privacy Policy

Last updated: August 17, 2026

1. Controller

The controller within the meaning of Article 4(7) GDPR for data processing through the diagnote web application is:

Kander Akinci
Ehrenfeldgürtel 174
50823 Köln, Germany
Email: [email protected]

For student data entered by users (teachers or schools) into the platform, the respective school or teacher is the data controller under data protection law. With respect to this student data, diagnote acts exclusively as a data processor within the meaning of Article 28 GDPR (see Sections 3.2, 7, and 12).

2. Overview

This Privacy Policy explains how diagnote ("we", "us", "our") collects, uses, stores, and protects personal data when you use the diagnote web application ("Service") at diagnote.io.

3. Data We Collect and Legal Bases

3.1 Account Data (Teachers / Users)

Provided by you during registration and use:

  • Username, email address, first and last name
  • Password (stored as a cryptographic hash; never stored in plain text)
  • Google ID (if using Google sign-in)
  • Profile image (optional)
  • System language preference (DE/EN)

Legal basis: Article 6(1)(b) GDPR — necessary for the performance of the contract for the provision of the Service.

3.2 Student Data (Data Processing)

Entered by the user (teacher or school) into the platform:

  • Student first names, last names, class assignments, or pseudonyms (recommended)
  • Student responses and exam texts (free text, multiple choice, fill-in-the-blank) as well as scanned handwritten exams (image files) processed by optical character recognition (OCR)
  • AI scoring results (fulfillment percentage, criteria analyses, rationale, pedagogical feedback)
  • Language analysis results (grammar, spelling, punctuation errors)

Legal bases in the school context:

For the processing school/teacher: Article 6(1)(e) GDPR (performance of a task carried out in the public interest / fulfilment of the educational mandate) in conjunction with § 120 School Act NRW (SchulG NRW) and the Ordinances on Data Required for School Administration (VO-DV-I / VO-DV-II NRW) or the corresponding school acts of the respective federal states, as well as the recommendations of the Conference of Ministers of Education and Cultural Affairs (KMK).

For diagnote as a service provider: Article 28 GDPR (data processing agreement).

Important note on pseudonymisation: diagnose recommends that teachers use pseudonyms or student numbers instead of real names when entering data.

3.3 Billing Data

  • Wallet balance and transaction history
  • Stripe customer ID
  • Payment method type (e.g. card brand/last 4 digits or PayPal); all payment methods are processed exclusively through our payment service provider Stripe
  • Invoice records

Legal basis: Article 6(1)(b) GDPR (contract performance) and Article 6(1)(c) GDPR (compliance with statutory retention obligations under § 147 AO, § 257 HGB). Full payment card numbers are never stored by diagnote; processing is handled by Stripe.

3.4 Task and Content Data

  • Task structures, marking schemes, instructions, and teaching materials
  • Assessment grids, criteria, and grading keys
  • Uploaded images / task sheets

Legal basis: Article 6(1)(b) GDPR — necessary for providing the core functionality.

3.5 Technical and Usage Data

  • AI model used and token consumption per scoring operation
  • Timestamps of actions and system logs
  • Error logs (via Sentry): may include IP addresses, request metadata, and in individual cases personal data and request content (including transmitted texts); processed exclusively for error diagnostics, with restricted access and subsequent deletion after the retention period
  • Product and usage analytics (PostHog): pseudonymous user identifier and teacher account master data (email, username, name) and product usage events (e.g. login, task creation). Legal basis: Article 6(1)(f) GDPR (legitimate interest in product improvement). Applies exclusively to teacher/user accounts — no student data.

Legal basis: Article 6(1)(f) GDPR — legitimate interest in IT security, maintenance, and uninterrupted provision of the Service.

4. Cookies and Authentication Tokens

4.1 Active session and analytics cookies:

Cookie / TokenPurposeTypeDuration
accessJWT authenticationHttpOnly15 minutes
refreshJWT token refreshHttpOnly7 days
csrftokenCSRF security protectionFunctionalSession
diagnote_cookie_preferencesCookie consent choiceFunctional1 year
ph_*Product analytics (PostHog) — only after opt-inAnalytics (opt-in)Up to 1 year

4.2 Strictly necessary cookies/tokens are required for secure login and service delivery. Analytics cookies (PostHog) are set only after active consent via the cookie banner. Consent can be withdrawn at any time in the settings.

Legal basis: Article 6(1)(b) and (f) GDPR; § 25(2) TDDDG.

5. Third-Party Processors and Data Transfers

5.1 Overview of service providers:

ProviderPurposeData Centre LocationSafeguard
DigitalOceanCloud hosting, database, file storageFrankfurt, Germany (FRA1)DPA
OpenAI Ireland Ltd. / OpenAIAI-assisted evaluation of student responses (API)EU / USADPA + SCCs. No model training with API data; storage up to 30 days for abuse detection, then deleted.
LanguageTooler GmbHSpelling and grammar checkingGermany / EUDPA
Stripe Payments EuropePayment processing (all payment methods, including cards and PayPal)EU / USADPA + SCCs + DPF
Google Ireland Ltd.Single Sign-On (OAuth) and AI-assisted spelling/grammar checking and OCR of handwritten exams (API)EU data centresDPA + SCCs. No model training with API data.
Sentry (Functional Software)Error monitoring / system logsUSADPA + SCCs
PostHog Inc.Product and usage analytics (server-side events for teacher accounts; additionally analytical cookies on the website only after consent)Frankfurt, EUDPA

5.2 Special guarantees when using AI interfaces (OpenAI and Google/Gemini):

When a teacher submits student responses for AI evaluation, the text and assessment criteria are transmitted to OpenAI via a secured API. For spelling and grammar checking as well as OCR of handwritten exams, response texts or scan images are transmitted to Google/Gemini via a secured API.

No model training: Under OpenAI's contractual API data usage policies, API inputs and outputs are expressly not used to train or improve public or commercial AI models.

Privacy in the school context: The data processing serves exclusively the temporary generation of scoring suggestions for the respective teacher.

6. Purpose of Data Processing & Use as a Marking Assistant

6.1 We process personal data exclusively for the following purposes:

  • Providing and operating the diagnote platform (account management, task creation, AI-assisted criteria analysis, generation of feedback drafts);
  • Processing payments and fulfilling statutory obligations;
  • Ensuring IT system stability and resolving errors.

6.2 Pedagogical final responsibility ("Human-in-the-Loop"):

diagnote is designed as a marking assistant and decision-support system in accordance with the recommendations of the Conference of Ministers of Education and Cultural Affairs (KMK, 10 October 2024) and the requirements of the Ministry of School and Education NRW (MSB NRW). The platform does not make fully automated individual decisions within the meaning of Article 22 GDPR. Grading authority, professional review, and the assignment of marks remain 100% with the responsible teacher.

6.3 We do not sell data to third parties and do not create user profiles for marketing purposes.

7. Student Data — Data Processing Relationship (DPA)

7.1 When a teacher or school enters student data into diagnote, the role of data controller (Article 4(7) GDPR) remains entirely with the school/teacher.

7.2 diagnote acts as a data processor within the meaning of Article 28 GDPR, processing student data strictly under instruction within the framework of the Data Processing Agreement (DPA) to be concluded.

7.3 The controller (school/teacher) ensures that the conditions under school and data protection law are met (in particular compliance with state school acts such as § 120 SchulG NRW and the Ordinances VO-DV-I / VO-DV-II NRW or the corresponding state school acts and the KMK recommendations).

7.4 A ready-made Data Processing Agreement (DPA) meeting the requirements of school authorities, including Technical and Organisational Measures (TOMs), is available for download on the platform or can be requested at [email protected].

8. Data Usage for Model Training (Exclusion for School Data)

8.1 To continuously improve and quality-assure our own algorithms, diagnote may analyse anonymised system usage data.

8.2 Strict exclusion for school users:

All data, free texts, exams, student responses, and assessment criteria processed under a Data Processing Agreement (DPA) or via school licences are completely excluded from use for model training or development purposes.

8.3 No use of school data for training purposes takes place with the integrated third-party APIs (OpenAI, Google/Gemini); these providers do not use data transmitted via the API for training purposes according to their API terms of use.

9. Data Retention and Deletion Periods

9.1 Student data and tasks: Retained for the duration of the active user account. Users may delete individual student work, classes, or tasks at any time manually.

9.2 Account deletion: Upon deletion of a user account, all associated data (student data, tasks, assessments, wallet references) is immediately and permanently deleted from the active databases.

9.3 Tax data: Billing records and invoices are retained for up to 10 years in accordance with statutory retention periods (§ 147 AO, § 257 HGB).

9.4 Backups: Data in encrypted system backups is automatically and permanently overwritten within a maximum of 30 days in the course of the regular backup rotation.

10. Your Rights as a Data Subject (Articles 15–21 GDPR)

You have the following rights regarding the data we hold about you:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure / "right to be forgotten" (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

To exercise your rights, please contact us at [email protected].

Note for students and parents/guardians: Since student data is managed by the school or teacher as the controller, data subject rights regarding marks and exam texts must be directed to the respective school. diagnote supports the school in fulfilling such requests upon instruction.

Right to lodge a complaint with a supervisory authority:

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for our registered office is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
https://www.ldi.nrw.de

11. Data Security (TOMs pursuant to Article 32 GDPR)

We implement comprehensive technical and organisational measures:

  • Encryption: End-to-end transport encryption (TLS/HTTPS) and server-side encryption of data at rest in the Frankfurt data centre (DigitalOcean).
  • Password protection: Cryptographic hashing to modern standards (no plain-text storage).
  • Access controls: Role-based permissions and logical user separation (multi-tenancy — teachers have access exclusively to their own data).
  • Short-lived tokens: Authentication via 15-minute JWTs and HttpOnly cookies against client-side attacks.

12. Special Provisions for Data of Minors

12.1 diagnote's contractual partners are exclusively adults (teachers, schools, educational institutions).

12.2 Where student data relating to minors is entered in the course of school operations, the user (school) ensures that the school law requirements of the respective federal state are met. In North Rhine-Westphalia, this is done on the basis of § 120 SchulG NRW in conjunction with the Ordinances VO-DV-I / VO-DV-II. diagnote does not directly contact minor students.

13. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy to reflect changes in the legal situation or extensions of our platform. Registered users will be notified of material changes in advance by email.

14. Contact

For questions about data protection or to request our school DPA package:

diagnote
Kander Akinci
Ehrenfeldgürtel 174
50823 Köln, Germany
Email: [email protected]