Privacy notice
Last updated: 23 September 2026 · 2026-09-23
Protecting personal data — especially children's data — is central to us. Pursuant to Art. 13 and 14 GDPR, this notice explains which data we process in this application, for what purpose and on which legal basis.
1. Controller
The controller is the organization named in the imprint.
Bayan Kulturzentrum (BKZ) e.V., Im Liefeld 51, 40227 Düsseldorf
Please send data protection requests to: bayan.kontakt@gmail.com
2. Data we process
- Students: first and last name, date of birth, gender, class, lesson records (attendance, memorized and reviewed passages, grades, homework, teachers' notes). With their own read-only account, additionally email address and sign-in data.
- Parents/guardians and emergency contacts: name, relationship to the child, phone number and/or email address, and date and version of the consent. With their own account, additionally sign-in data (email address, the password only as an irreversible hash, language) and the confirmation that a homework assignment has been seen.
- Teachers and administration: name, email address, role, sign-in data (the password only as an irreversible hash).
- Technical data: IP address and time at sign-in and at every change to or access of student data (audit log), session identifier.
3. Purposes and legal bases
Accompanying Qur'an lessons and learning progress and informing parents — based on the parents' consent (Art. 6(1)(a) GDPR) and to perform the teaching relationship (Art. 6(1)(b) GDPR).
Enrollment of new students: processing the details submitted by parents to review the enrollment and place the children in a class — to take steps at the parents' request prior to the teaching relationship (Art. 6(1)(b) GDPR) and based on their consent (Art. 6(1)(a) GDPR).
Security and accountability: the log of all changes and accesses serves data security and accountability (Art. 5(2), Art. 32, Art. 6(1)(c) and (f) GDPR).
We use no advertising, no analytics or tracking services, and load no fonts or scripts from third-party servers.
4. Recipients
Only authorized people within the respective school have access: teachers see only the students in their classes, parents only their own children. Hosting and database providers support us technically as processors under Art. 28 GDPR; the data is stored in data centres in the European Union (Frankfurt am Main). No data is passed to other third parties.
5. Processors and where the data is kept
The application runs on Netlify (Netlify, Inc., San Francisco, USA) and the database on Neon (Neon, Inc., USA) in the Frankfurt am Main data centre. Both process the data on our instructions only; a data processing agreement under Art. 28 GDPR is in place with each of them.
The data is stored in the European Union. Access by the providers from the United States cannot be ruled out entirely; it rests on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR). Connections are encrypted throughout.
6. Retention
Lesson records are kept for as long as the student attends the school, so the whole learning journey remains traceable. When a student leaves, the data is archived and deleted on request; a requested deletion is carried out irreversibly after 30 days, and personal content in the audit log is redacted. Sign-in sessions, including IP address and browser details, are deleted 30 days after they end. Enrollment applications are kept until the school decides; afterwards only the decision and the record of consent remain. Backups are kept for 30 days.
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.
Competent supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Postfach 20 04 44, 40102 Düsseldorf, Telefon +49 211 38424-0, poststelle@ldi.nrw.de
8. Consent and withdrawal
For photographs and for messages over WhatsApp or SMS we ask for your consent (Art. 6(1)(a) GDPR). Both are optional and no condition of enrollment. You may withdraw a consent at any time under Profile; the lawfulness of the processing carried out until then is unaffected (Art. 7(3) GDPR).
9. Cookies and local storage
We only set technically necessary cookies: a session cookie for sign-in and cookies for your chosen language and appearance. Entries captured without an internet connection stay on the device until they are sent and are removed at sign-out. No consent is required for this (§ 25(2) TDDDG).
10. Children's data
Students can receive their own read-only account with which they see only their own page. Children's data is stored only with the consent of their parents or guardians — given in writing to the school or when enrolling through this application; the date and version of the consent are documented.
11. Enrollment by invitation
The school can hand parents a personal invitation link for a class, for example via WhatsApp, email or as a QR code. With this link, parents create their own account (name, email address, password), submit their children's details themselves (first and last name, date of birth, gender) and, if they wish, emergency contacts, and give their consent. The school reviews the enrollment; only once it is confirmed are the children created as students and placed in a class. If an enrollment is rejected, the children's details submitted are deleted. The link is valid for 14 days and can be used once; only an irreversible check value (hash) of the link is stored.
12. Contact via WhatsApp
Teachers can message parents directly in WhatsApp via a link. The application itself sends no data to WhatsApp; only when tapped does WhatsApp open on the teacher's device and receive the phone number. WhatsApp (WhatsApp Ireland Ltd.) is responsible for any further processing.
13. Videos
An announcement may carry a video. Our server fetches the preview picture from YouTube and serves it from our own address, so reading the page creates no connection to Google. Only when you press play is the player loaded from youtube-nocookie.com, and your IP address and details of your device are then sent to Google Ireland Ltd. The legal basis is the consent you give with that click (Art. 6(1)(a) GDPR).
14. Prayer times
Our server fetches the prayer times from mawaqit.net every six hours. Your browser never connects there — the people running that site do not learn who is reading ours.
15. Providing the data, and automated decisions
To enroll a child we need its name and date of birth and a way of reaching a parent or guardian. Without those we cannot carry out the teaching agreement; everything else is optional.
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.
16. Security
Transmission is encrypted (TLS). Access rights are enforced on the server and additionally in the database, every change is logged, and student data cannot be deleted by accident.
17. Changes
We update this notice when the processing changes. The version published here is authoritative.
Note for the administration: this privacy notice was prepared for the application and must be reviewed legally and completed with the specific processors before use.
