Cookie settings

We use optional analytics and monitoring only with your consent. You can accept all, reject all, or review the details.

Essential cookies stay active because they are required for core website functionality and storing your privacy choices.

eDoer logo
Legal

Privacy Policy

Effective Date: 27.08.2026

eDoer is the learning platform and related services operated by Education4All GmbH. In this Privacy Policy, references to eDoer describe the Platform and, where legal responsibility is concerned, Education4All GmbH as its operator.

1. Controller

Where eDoer acts as data controller (see Section 4), the controller is:

***Education4All GmbH***  
  

Angoulemepl. 2,
31134 Hildesheim
Germany

*Email: [[email protected]](mailto:[email protected])*

For educational data processed on behalf of organizations, the respective organization is the data controller.
The responsible Organization and its privacy contact are identified in the Organization’s own privacy information. Users should consult that notice for the lawful bases and retention instructions applicable to Organization-controlled processing.

2. Structure of Data Processing Roles

eDoer operates as a multi-tenant learning platform.

Depending on the processing activity:

  • Educational data is processed on behalf of organizations (Art. 28 GDPR).
  • Certain technical, security, analytics, organization-subscription, payment-administration, and legally required service-delivery data is processed by eDoer as an independent controller.

3. Processing on Behalf of Organizations

Organizations using eDoer act as independent data controllers for:

  • Learner registration and enrollment
  • Learning progress and assessment results
  • Certificates and grading
  • Educational communication
  • Discussions, direct conversations, moderation, and activity notifications
  • Course and content management
  • AI configuration and reference materials, including organization knowledge base files and learner background documents where enabled
  • Optional document-source integrations initiated by authorized users where enabled
  • AI conversations, prompts, generated responses, citations, and reviewable actions
  • Live-session scheduling, participation, and attendance where enabled
  • YouTube playlist and video imports initiated by authorized users where enabled

eDoer processes this data strictly on documented instructions under Data Processing Agreements.

3.1. Categories of Data

  • Account data (name, email, role, organization)
  • Learning progress and assessment results
  • Submitted answers and uploaded files
  • Organization knowledge base files and related reference materials where enabled
  • Learner background documents where enabled
  • Optional third-party document-source connection and import data for authorized users where enabled (e.g., Roxtra username, encrypted credential material, imported files)
  • Certificates (name, grade, issue date)
  • Discussion and messaging data, including topic scope and participants’ data, messages, replies, mentions, reactions, attachments, read status, reports, reporter identity, shared-thread choice, moderation status and actions, and related timestamps
  • AI interaction data, including conversation and message identifiers, prompts, attachments, generated responses, citations, suggested actions, relevant page or editor context, processing status, error information, and token-usage metadata
  • Live-session data, including session identifiers, scheduled times, participant roles, attendance status, room links, and lifecycle events where enabled
  • Public source URLs or identifiers, requested language, and retrieved public metadata or transcript content for authorized YouTube imports where enabled

3.2. Legal Basis

The respective Organization determines and documents the lawful basis for this processing. Depending on the Organization and context, this may include Article 6(1)(b), 6(1)(c), 6(1)(e), or 6(1)(f) GDPR and, where special-category data is involved, an applicable Article 9 condition. The Organization’s privacy information identifies the basis that applies to its Users.

4. Processing as Independent Controller

eDoer processes certain data as an independent controller for the following purposes:

4.1. Platform Security and Stability

  • System logs
  • Error reports
  • Access metadata (IP address, timestamps)
  • Fraud prevention

Legal basis: Art. 6(1)(f) GDPR – legitimate interest.
The legitimate interests are protecting accounts and tenants, detecting misuse and fraud, maintaining availability, diagnosing faults, defending legal claims, and documenting security events. Security and access metadata is required for secure Platform operation; refusal may prevent account access or use of affected functions.

4.2. Behavioral Analytics (Consent-Based)

Only after the relevant optional consent is given, eDoer initializes browser telemetry through the configured eDoer collection endpoint. Depending on the selected category, telemetry may include sanitized route paths, page-view and view-lifecycle events, Core Web Vitals, pseudonymous in-memory session identifiers, unhandled errors and promise rejections, fetch/XHR traces, selected warning or error console events, allowlisted interface actions, browser and device context, timestamps, and—only for consented monitoring of signed-in Users—the internal User identifier. The purposes are to:

  • Improve product features
  • Analyze usability
  • Ensure performance and reliability

Legal basis: Art. 6(1)(a) GDPR – consent.

Users may withdraw consent at any time.

Analytics processing:

  • Is optional

  • Does not affect educational functionality

  • Is stopped immediately upon withdrawal

  • Recipients are authorized eDoer product, operations, and security personnel and the infrastructure processors operating the configured collection and log systems. Telemetry is not used for advertising or unrelated profiling.

  • Telemetry records are retained for no more than 90 days unless a shorter production configuration applies, and are then deleted or anonymized. The in-memory session identifier expires after 30 minutes of inactivity and is not stored in cookies or local storage.

4.3. Consent Management

Consent audit records include the User identifier or anonymous identifier, previous and new consent-category states, source, consent-schema and policy version, Organization, timestamp, user agent, and hashed IP address. They are processed under Article 6(1)(c) GDPR to demonstrate compliance and Article 6(1)(f) GDPR to establish and defend legal claims, and are retained for 730 days unless a longer period is required for an active legal dispute.

4.4. Marketplace and Payment Processing

Where Marketplace Services are enabled, an Organization may offer a learning path for one-time purchase by eligible users in that Organization. The selling Organization is presented as the seller and merchant of record. eDoer operates the marketplace, facilitates checkout, receives the disclosed platform commission, reconciles transaction status, and administers refunds, disputes, and purchase-derived access.
eDoer stores marketplace data such as buyer account identifiers, username and email snapshots, purchased learning path and offer details, price, currency, commission, seller net amount, provider account and transaction identifiers, checkout/payment/refund/dispute/fulfillment status, reconciliation records, seller-account readiness information, and security and audit records.
Stripe-hosted checkout and onboarding surfaces may collect payment-card, billing, identity-verification, and bank-account information directly. eDoer does not intentionally store full card details, bank-account details, or seller verification documents. Stripe may process transaction, device, and identifying data under its own privacy documentation and applicable agreements.
The legal bases are performance of the marketplace transaction and related User Terms (Article 6(1)(b) GDPR), compliance with tax, accounting, and other legal obligations (Article 6(1)(c) GDPR), and the legitimate interests in platform security, fraud and loss prevention, accurate reconciliation, dispute handling, service enforcement, and legal claims (Article 6(1)(f) GDPR). Required checkout and account information must be provided to complete a purchase; otherwise checkout or purchase-derived access cannot be provided. Data may be disclosed to the selling Organization, Stripe and its service providers, payment-system participants, professional advisers, and competent authorities where necessary. Stripe’s role is determined separately for each payment, onboarding, fraud, compliance, and platform service under the applicable Stripe agreements and privacy information.
Marketplace financial, transaction, refund, dispute, reconciliation, and audit records are retained for the period required by applicable tax, accounting, payment-services, and limitation laws. After operational use ends, direct identifiers should be deleted or pseudonymized where legally and technically permissible.

4.5. Platform Notifications and Transactional Email

The Platform creates recipient-specific in-app notifications from discussion, learning, certificate, live-session, system, moderation, and similar service events. Records may include the recipient and Organization, event type and category, activity-derived payload and context, destination link, and creation, update, read, seen, and deletion timestamps.
Users may configure optional notification-email categories. eDoer also records preference status and email-delivery metadata such as scheduling, attempts, status, skip reason, provider message identifiers, reconciliation keys and events, timestamps, and error information. Required operational, security, billing, account, or moderation messages may be sent independently of optional preferences where necessary.
Transactional and notification email is delivered through Amazon Simple Email Service (Amazon SES), operated for the German production account by Amazon Web Services EMEA SARL in the Europe (Frankfurt) Region. Depending on the email, Amazon SES receives the sender and recipient addresses, subject, text and HTML body, attachments where applicable, and delivery metadata. Under the AWS service terms, SES may store or scan email and its content to prevent spam, phishing, malware, abuse, and delivery failures.
The role and legal basis follow the underlying event: Organization-directed educational notifications are processed on the Organization’s documented instructions; eDoer relies on Article 6(1)(b), 6(1)(c), or 6(1)(f) GDPR as applicable for its own account, security, billing, mandatory service, fraud-prevention, abuse handling, and moderation communications. The legitimate interests are reliable delivery, account and service protection, misuse prevention, reconciliation, and legal claims. Optional notification email may be disabled; required operational communications are necessary to administer or protect the account and service.

4.6. Organization Subscriptions and Mollie Payments

For organization subscriptions purchased or administered through Mollie, eDoer processes the organization purchaser and administrative contact, Mollie customer, mandate, payment and subscription identifiers, amount and Billing Interval, transaction and subscription status, payment history, failure, grace, suspension, cancellation and paid-through information, and operational reconciliation records.
For public or electronic organization registration, eDoer also records the selected package, legal-document identifiers, language and content hashes, acceptance timestamp, user agent, hashed IP address, checkout status, and related idempotency and fulfillment information.
The legal bases are contract performance (Article 6(1)(b) GDPR), tax, accounting, and other legal obligations (Article 6(1)(c) GDPR), and the legitimate interests in accurate payment reconciliation, service security, fraud and loss prevention, dispute handling, enforcement, and legal claims (Article 6(1)(f) GDPR). Required purchaser, mandate, and payment information must be provided to establish or administer a Mollie subscription; otherwise recurring checkout or continued paid access cannot be provided. Mollie determines purposes and means for regulated payment services, legal compliance, and its own fraud controls as an independent controller. Any processing Mollie performs solely on eDoer’s documented instructions remains governed by the applicable contractual role rather than this general controller description.

4.7. Account Authentication and Legal Acceptance

eDoer processes authentication, account-security, and legal-acceptance data necessary to establish and protect access to the Platform. Depending on the registration method, this may include an email address or username, password hash, authentication-provider identifiers, Organization, role, login and verification events, legal-document version and content hash, acceptance timestamp, user agent, and hashed IP address.

Users may sign in with Platform credentials or, where offered, Google sign-in. When Google sign-in is selected, Google receives the authentication request and processes account, device, network, and security data under Google’s own privacy information. eDoer receives the identity attributes released for the sign-in, normally including the Google account identifier, name, email address, and profile information authorized by the User.

The legal bases are performance of the account and Platform relationship (Article 6(1)(b) GDPR), compliance evidence where legally required (Article 6(1)(c) GDPR), and the legitimate interests in secure authentication, fraud prevention, tenant isolation, account recovery, and legal claims (Article 6(1)(f) GDPR). Google sign-in is optional where another authentication method is available.

5. AI-Based Processing, Voice, and Optional Source Integrations

Certain features may use AI services (e.g., large language models) to support:

  • Educational assistance
  • Educational content and metadata generation
  • Retrieval and grounding based on organization knowledge base files and, where enabled, learner background documents

When AI features are enabled, data sent to AI services may include:

  • Educational content and learning path metadata
  • Organization-designated knowledge base files
  • Learner background documents uploaded by users where learner AI is enabled
  • User-submitted prompts and attachments
  • Relevant current-page or editor context submitted with the request, such as titles, descriptions, learning outcomes, selected modules, and unsaved editor content
  • Assigned-learning-path and learner-visible source metadata necessary to identify permitted grounding sources
  • Existing conversation messages necessary to provide conversational continuity
  • Voice recordings submitted for transcription and completed assistant text submitted for spoken playback

When AI processes organization-related educational data:

  • eDoer acts as processor
  • AI providers act as sub-processors under contractual safeguards
  • Data is minimized and pseudonymized where possible
  • eDoer does not intentionally add unrelated learner performance data or platform account identifiers as separate AI input fields, unless such information is contained in content, files, prompts, or attachments intentionally submitted for AI processing

AI providers are contractually prohibited from using submitted data for independent purposes where enterprise agreements apply.

AI conversations and their messages are stored by eDoer so that the User can access conversation history. Completed AI responses may contain structured citations and reviewable actions. Actionable changes are not inferred from ordinary assistant text: the User must select an explicit action and, where applicable, save the resulting Platform content.

Learner background documents are optional evidence for an individual message. The Use my background control is off by default. When the learner enables it for a message, the AI service validates the authenticated learner and trusted document catalogue before making the authorized background documents available to the AI request. When it is off, those documents are excluded from preparation and generation.

Voice recordings are processed only to return an editable transcript. They are not stored as chat attachments and are not indexed. Spoken playback is generated from an already completed assistant message, is identified in the interface as an AI-generated voice, and is cached only for the current browser session.

Temporary generated images are held by the AI service only for the period stated in Section 8. If an authorized User accepts a generated image, eDoer stores the resulting image as an Organization library file under the Organization’s instructions; depending on the selected library location and use, that accepted file may be publicly accessible.

AI-Assisted Features do not make decisions based solely on automated processing that produce legal or similarly significant effects. Outputs may be incomplete, inaccurate, or unsuitable and are suggestions that require review by an authorized User or the Organization. AI interaction is identified as such in the Platform. Where AI-generated or manipulated content is used or published, eDoer and the responsible User or Organization must preserve and provide AI-origin disclosures or metadata where required by applicable law.

If approved document-source integrations such as Roxtra are enabled by platform-level administration and the organization, eDoer may process the connecting user’s integration credentials to authenticate with the third-party service, search documents, and import user-selected files into eDoer. Imported files are thereafter processed like other platform files under the Organization’s instructions.

For certain enabled YouTube playlist, video-metadata, or transcript imports, eDoer may use Decodo’s Web Scraping API on demand. The request is limited to the relevant public source URL or identifier, requested language or retrieval parameters, and the public response needed for the import. eDoer does not intentionally send the importing User’s account identifier to Decodo. Decodo is not used for general AI chat.

When authorized Users add links or embedded media, the linked provider may receive the User’s IP address, device and browser information, referrer information, requested URL, and interaction data when the external resource is loaded or opened. This applies in particular to YouTube content provided by Google. The external provider processes that data under its own privacy information and settings.

5.1. Children

Organizations determine whether minors may participate and must provide an appropriate lawful basis, age-appropriate information, permissions, and safeguards for Organization-controlled processing. Where eDoer relies on consent for an information-society service offered directly to a child, eDoer applies Article 8 GDPR and the applicable national age threshold. In Germany, consent by a child under 16 generally requires authorization from the holder of parental responsibility.

Optional analytics and monitoring remain disabled for a known child unless valid consent or authorization has been obtained. Information directed specifically to children is provided in clear, age-appropriate language. Organizations should not enable unnecessary profiling, sensitive-data processing, or unrestricted communication features for minors.

6. Administrative Access

In limited cases, authorized eDoer personnel may access organization data for:

  • Technical troubleshooting
  • Security investigations
  • Support requests

Such access:

  • Is restricted to authorized staff
  • Is logged
  • Is limited in duration
  • Requires documented purpose
  • Is subject to confidentiality obligations

7. Recipients, Service Providers, and International Data Transfers

Personal data may be disclosed, strictly as necessary for the relevant feature, to authorized personnel of eDoer and the responsible Organization; other authorized Users participating in a learning, communication, marketplace, or live-session workflow; professional advisers and competent authorities where legally required; and the following service providers or external recipients:

  • Hetzner Online GmbH / Hetzner Finland Oy: EU application, database, object-storage, and AI/RAG infrastructure used for the Services.
  • Cloudflare, Inc.: reverse proxy, content delivery, TLS termination, DNS, traffic filtering, and DDoS protection.
  • Amazon Web Services EMEA SARL: transactional and notification email through Amazon SES in the Europe (Frankfurt) Region.
  • OpenAI Ireland Ltd.: enabled AI text and image generation, transcription, spoken playback, and provider-native retrieval or search functions.
  • Google Ireland Ltd. / Google LLC: enabled Gemini AI functions, Google sign-in, and YouTube-hosted or YouTube-derived content. The role and data involved depend on the selected function.
  • Decodo (UAB “Data troops”): on-demand retrieval of certain public YouTube metadata or transcripts where the import feature is enabled.
  • Whereby AS: hosted video rooms and related live-session lifecycle processing where live sessions are enabled.
  • Stripe entities: Marketplace seller onboarding, hosted checkout, payments, refunds, disputes, fraud prevention, and compliance where Marketplace Services are enabled.
  • Mollie B.V.: Organization-subscription checkout, mandates, recurring payments, payment status, and regulated payment services where Mollie billing is used.

External document sources selected by an Organization or User, such as Roxtra, receive authentication and search requests as directed by that User. Such a source is not a sub-processor appointed by eDoer merely because the Platform enables a connection to it. Imported copies are thereafter processed within eDoer under the role allocation described above.

eDoer maintains a provider- and activity-specific transfer register. Primary Amazon SES processing is configured for the Europe (Frankfurt) Region through Amazon Web Services EMEA SARL and is not itself a third-country transfer. OpenAI, Google Cloud, Cloudflare, Stripe, Mollie, AWS, or their subprocessors may involve third-country access or transfers depending on the contracted entity, service, support model, and current processing chain. Before relying on a transfer, eDoer verifies the exact recipient and applies an adequacy decision, valid EU-US Data Privacy Framework participation, the applicable 2021 Standard Contractual Clauses, or another lawful Chapter V mechanism, together with supplementary measures where required. Information about the applicable safeguard or a copy of it may be requested using the contact above.

  • Standard Contractual Clauses apply where required for an onward third-country transfer.
  • The EU-US Data Privacy Framework may be used where available and legally applicable.

8. Data Retention

eDoer applies the following standard retention schedule unless the responsible Organization gives a lawful documented instruction requiring earlier deletion, or applicable law requires longer storage:

  • Educational and Organization data: retained while the relevant account, Organization, or Service Agreement remains active and as instructed by the Organization. It is deleted after the applicable account or Organization is deleted or the Service Agreement ends, subject to statutory exceptions and the backup lifecycle below.
  • AI conversations and messages: retained until the User deletes the conversation or the relevant User account or Organization is deleted. A soft-deleted conversation and its associated messages, generation jobs, and usage records are permanently removed by scheduled cleanup after a recovery period of up to 30 days.
  • Completed AI generation-job and per-call token-usage records: retained for 90 days. These operational records are separate from visible conversation content.
  • Temporary generated-image output: expires after 1 hour and is removed with its temporary job record by scheduled cleanup. An accepted image becomes an Organization library file and follows the retention instructions for that file.
  • Derived AI indexes and necessary source mappings: retained while the underlying source remains available. Source deletion triggers removal from the retrieval system; failed or delayed removal is remediated so deletion is completed within 30 days. Completed removal-job metadata is retained for 90 days.
  • AI service file logs: rotated files are retained for no more than 14 days and may be removed sooner through size-based rotation.
  • Security, access, error, and consent-based browser telemetry logs: retained for no more than 90 days unless a shorter operational period applies. The in-memory browser-telemetry session identifier expires after 30 minutes of inactivity.
  • Verification tokens: expired tokens are removed 30 days after expiry.
  • Notifications: read or seen notifications are retained for 90 days; unread and unseen notifications are retained for 180 days. Terminal sent, skipped, or failed notification-email delivery records are retained for 180 days; pending or non-terminal records remain while delivery or reconciliation is active.
  • Consent audit records and the minimal completed User-erasure audit ledger: retained for 730 days to demonstrate compliance and handle legal claims. Expired one-use erasure challenges are removed by the next scheduled cleanup.
  • Optional integration credentials: retained only while the integration remains connected or as necessary for security and troubleshooting. They are deleted or overwritten after disconnection or replacement, subject to the backup lifecycle.
  • Discussion, moderation, and ordinary educational messages: retained according to the responsible Organization’s instructions and account lifecycle. Restricted or soft-deleted content and closed moderation records are retained only as necessary for moderation, security, legal obligations, or legal claims and are then deleted or anonymized.
  • Organization-subscription, Marketplace, and payment records: retained for applicable contractual, tax, accounting, payment-services, limitation, fraud-prevention, and legal-claims periods. Identifiers are deleted or pseudonymized where lawful and technically feasible after those purposes end.
  • Encrypted database backups: created daily and retained for 7 days on a rolling basis. Data deleted from live systems may remain in an isolated backup until that backup expires. If a backup is restored, applicable deletion records are reapplied before normal processing resumes.
  • Provider-side records: retention by an independent recipient, including Stripe, Mollie, Google, or a User-selected external source, is governed by that recipient’s own legal obligations and privacy information. Sub-processor retention is governed by the applicable data-processing terms; eDoer does not state a fixed provider-side period where none is contractually established.

The database retention process runs once per day and whenever the privacy worker starts. AI-service cleanup runs at shorter intervals to enforce temporary-image and AI-record expiry. Valid erasure requests do not wait for the ordinary schedule where earlier deletion is required and technically possible. A documented legal hold or statutory obligation may suspend deletion only for the affected data and required period; access remains restricted during that time.

8.1. Sources of Data and Whether Provision Is Required

Personal data is obtained from Users, authorized Organization representatives, the User’s interaction with the Platform, connected services selected by authorized Users, payment and email providers, and system-generated security, delivery, consent, and audit events. Where eDoer receives contact or account data from an Organization, that Organization is the source.

Fields identified as required at registration, invitation, checkout, security verification, or billing are necessary for the relevant account, contract, legal obligation, or service. If required data is not provided, the relevant registration, access, purchase, subscription, or protected function may not be available. Optional profile information, analytics, monitoring, and notification-email categories may be declined without loss of core educational functionality, except where a communication is operationally or legally required.

9. Data Subject Rights

Subject to the conditions and exceptions in the GDPR, Users may exercise the following rights:

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction (Art. 18)
  • Portability (Art. 20)
  • Objection (Art. 21)
  • Withdrawal of consent (Art. 7)
  • Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22). eDoer does not currently perform such decision-making in the processing described by this Policy.
  • Where processing is based on Article 6(1)(f) GDPR, Users may object on grounds relating to their particular situation. eDoer will stop that processing unless compelling legitimate grounds override the User’s interests, rights, and freedoms or processing remains necessary for legal claims. Direct-marketing objections, if applicable, are honored without balancing.

For educational, discussion, and organization-directed notification data, requests should generally be directed to the respective Organization. For analytics, organization-subscription, payment-administration, security, or other platform-level processing for which eDoer is controller, requests may be directed to eDoer. Mollie handles requests relating to its independent payment-services processing under its own privacy information.

Requests may be submitted to the contact in Section 1. eDoer may request information reasonably necessary to verify identity. Requests are answered without undue delay and ordinarily within one month; the period may be extended by up to two further months where permitted by Article 12 GDPR, with notice of the reasons for delay.

10. Security Measures

eDoer implements appropriate technical and organizational measures, including:

  • Encrypted transmission (TLS)
  • Password hashing
  • Encrypted storage of third-party integration credentials
  • Role-based access control
  • Organization-level data isolation
  • Logged administrative access
  • Incident response procedures
  • Scheduled retention and erasure controls
  • Encrypted daily backups with a 7-day rolling lifecycle and deletion replay before restored data returns to service

11. Complaints

Users may lodge a complaint with a supervisory authority, particularly in the Member State of habitual residence, place of work, or place of the alleged infringement. The supervisory authority responsible for eDoer’s establishment is Der Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany; email: [email protected]; telephone: +49 511 120-4500.

12. Updates to This Policy

This Privacy Policy may be updated to reflect legal, regulatory, contractual, or technical changes. The current effective date is shown above. Where required by law or where a change materially affects Users, eDoer or the responsible Organization will provide appropriate notice before the change takes effect.