On this page
1. Who we are
Deutsch-Landia is operated by IACOB MIHAI-ALBERTO PFA (a Romanian-registered sole proprietorship; fiscal code (CUI) 54802933, Trade Register No. F2026028449007), registered office at B-dul 1 Decembrie 1918 nr. 1N, Sector 3, Bucharest, Romania. You can reach us on +40 765 759 979 or at privacy@deutsch-landia.com. We operate the educational platform available at deutsch-landia.ro and deutsch-landia.com and are the controller of personal data collected through these services. We take the privacy of our users, especially children, very seriously.
2. Data collected
We collect the following data:
- Registration data: email, first name, last name, age, role
- Progress data: completed lessons, solved exercises, XP score
- Technical security data: IP address, user-agent (browser + operating system), and the approximate country derived from the IP address. We use these for account security, fraud prevention and incident investigation (legal basis: our legitimate interest, GDPR Art. 6(1)(f)). We retain them for 24 months and they are viewable only by administrators in an internal panel whose access is itself logged. We do not use a third-party geolocation service — the country is read from a header provided by our network (Vercel), with no cookie and no script on your device, and we never determine a location more precise than the country.
- Payment data: processed exclusively by Stripe — we do not store card data
We do not store biometric data, GPS location, or social media data. One thing deserves its own paragraph, because it involves your microphone.
Pronunciation exercises and your microphone
When you practise pronunciation, we use the speech recognition your browser already has. In Chrome and Edge that means the browser sends the audio to Google's servers, and in Safari to Apple's, to turn it into text — under the browser maker's privacy policy, not ours. Neither the recording nor the recognised text reaches us: we record only that the exercise was attempted. On Firefox the feature does not exist and the exercise stays a listening one. The platform also contains a server-side transcription path via OpenAI, but it is DISABLED; if we ever switch it on, we will update this page first and add OpenAI to the recipients list in section 6.
3. Children's protection (COPPA / GDPR-K)
Deutsch-Landia is for all ages — children, teenagers and adults. Whenever an account belongs to a minor, we apply the strictest protection standards to it (COPPA 2025 Final Rule + GDPR-K + Romanian Law 190/2018), regardless of the rest of the platform.
- Below the age of consent in your country (16 in Romania and Germany, 14 in Austria, 13 in the US and the UK), the account does NOT activate on its own. We ask for a parent's email address, create the account in a locked state, and unlock it only after the parent confirms from their own inbox. Until then nothing can be learned, played or purchased. We also check that the parent address is not the child's own.
- We do not display behavioural ads to children — zero advertising tracking on educational content.
- We do not sell children's data and do not disclose it for commercial purposes. There is exactly one situation where somebody else sees anything about your child: when a school enrols them. The school then sees exactly four things — they are listed in section 4.
- We do not build voiceprints and we never identify anyone by their voice. What happens to your microphone during pronunciation exercises is described in section 2.
- We never determine a location more precise than the country.
- Parents can request access, rectification or deletion of their child's data at any time at privacy@deutsch-landia.com — we respond within 30 days.
4. When your child’s account comes from a school
Some accounts are not created by the family but by a school we work with: a teacher or the office adds the pupils to a list, we create the accounts, and each child gets their own sign-in details. If you are a parent and this is the first you are hearing of such an account, this section is written for you.
What the school sees
- Lesson progress — what they have covered and where they stopped
- XP and day streak
- Test results
- Video-session attendance
What the school does NOT see
Your child’s password, their messages, what they do on the platform outside school, and nothing at all about the family’s payments. That is it — the list above is complete, not a summary.
Who decides what
- The school decides who is enrolled, in which class, and for how long. It is also responsible for your authorisation as a parent: it warrants it to us by contract and records, pupil by pupil, how it was obtained — a register we can ask to see at any time.
- We decide how the platform works: the lessons, the points, the leaderboards, the friends, and the subscription a family can buy separately, independently of the school.
- For anything concerning you or your child, you can write to us DIRECTLY. We will not send you back to the school.
What you can do
- You can ask for access to, correction of, or deletion of your child’s data — exactly like any other parent on the platform.
- You can stop the school’s access at any time. If the school gave us your email address, we have already sent you a message with a link that does precisely that, in one click, with no explanation owed to anyone. If nothing arrived, write to us and we will handle it.
- Stopping the school’s access does NOT delete your child’s account. Their progress, points and streak stay theirs — only the link to the school is cut.
What happens when the school’s contract ends
The account stays your child’s and returns to the free version. Nothing they learned is lost. The school sees nothing from that moment on, and if the family wants to carry on with everything that was included, they can take out a separate subscription.
5. How we use data, and on what basis
Every purpose has its own legal basis — we do not process anything "in general".
- Providing and personalising the educational service — performance of the contract (Art. 6(1)(b)); for minors' accounts, parental consent (Art. 8)
- Progress tracking and generating review recommendations — performance of the contract (Art. 6(1)(b))
- Communications related to account and subscription — performance of the contract (Art. 6(1)(b))
- Marketing communications (reminders, news) — your explicit consent (Art. 6(1)(a)), withdrawable with one click from any email
- Improving the platform through aggregate analysis — your consent to the "Marketing" cookie category (Art. 6(1)(a))
- Account security, fraud prevention and incident investigation — our legitimate interest (Art. 6(1)(f)), documented by a written balancing test
- Payments, invoicing and keeping accounting records — performance of the contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
6. Who we share data with
We do not sell data and we give it to nobody for advertising. We pass on strictly what is necessary, to the providers that make the platform work. The list below is complete, not an example:
- Stripe — payment processing (Irish entity)
- Vercel — website hosting and delivery (US company, served from the European data centre)
- Railway — application server and database (US company, hosted in Amsterdam)
- Resend — sending account-related email (EU region)
- Sentry — error monitoring (EU region)
- PostHog — product analytics, ONLY with your consent (EU servers, Frankfurt)
- Microsoft Clarity — anonymised page-interaction recordings, ONLY with your consent (US)
- Cloudinary — hosting images and uploaded materials (Israel and US)
- Inngest — running scheduled jobs, for example the automatic clean-up of expired data (US)
- Cloudflare — DNS and network-level protection (global)
- Google — only if you use "Continue with Google" or the Google Classroom roster import (US)
- Daily.co — only if you join a video session with a teacher (US)
- Your school, if your account was created by a school — exactly four categories, listed in section 4
Transfers outside the European Economic Area
Some of the providers above process data outside the EEA, mainly in the United States. For those transfers we rely on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914). Israel, where Cloudinary has infrastructure, is covered by a European Commission adequacy decision. You can request a copy of the applicable safeguards by writing to privacy@deutsch-landia.com.
7. How long we keep data
These are the periods we actually enforce, not the ones that would look best:
- Your account and everything about learning (progress, test results, vocabulary, XP, streaks, badges) — for as long as the account exists. Delete it and they go with it.
- Security audit log (IP address, user-agent) — 24 months, then deleted automatically by a job that runs daily.
- Country derived from your IP address — for the life of the account, because it is a fraud signal and supports age-of-consent verification; deleted with the account.
- Payment and subscription records — 7 years from the last payment, because Romanian tax law requires it.
- Authentication session — 30 days. Access token — 15 minutes.
- Unsubscribe list — 180 days; spam complaints are kept indefinitely, precisely so we never write to you again.
- Error reports and providers' technical logs — between 30 and 90 days, per each provider's policy.
8. Your rights (GDPR)
You have the right to:
- Access — receive a copy of your data
- Rectification — correct inaccurate data
- Erasure — "the right to be forgotten"
- Portability — export your data in a standard format
- Objection — to processing based on legitimate interest
- Restriction — ask us to pause processing temporarily (Art. 18)
- Withdrawal of consent — at any time, for marketing and for cookies (Art. 7(3)); withdrawal does not affect what was lawfully processed beforehand
Automated decisions
We do not make solely automated decisions that produce legal effects or similarly significantly affect you (Art. 22). The algorithm that suggests what to review is a teaching aid; it decides nothing about your account, your payment or your access.
The fastest route: if you are signed in, you can download all of your data yourself, straight away, without waiting for anyone. For anything else — or if you would rather write to us — use: gdpr@deutsch-landia.com
9. Cookies
We use four categories of cookies and similar technologies, aligned with the consent banner. (1) Necessary — httpOnly cookies for secure authentication (JWT), security, and the language preference; these are essential and cannot be disabled. This also covers error and security monitoring (Sentry), strictly necessary for platform stability — no cookies, no session recordings, and no data that identifies you (we strip it before sending), on a legitimate-interest basis. (2) Functional — stores your choices in the browser (light/dark theme, onboarding progress) for a personalised experience; it does not identify you across sites. (3) Analytics — site performance measurement, via Vercel Speed Insights and the Sentry performance (tracing) component; activated ONLY if you accept the “Analytics” category. (4) Marketing & personalisation — aggregate behavioural analytics (PostHog, EU servers in Frankfurt) and anonymised session-interaction recordings (Microsoft Clarity); activated ONLY if you accept the “Marketing” category. None of the Analytics or Marketing technologies run before your explicit acceptance. You can accept all, reject all, or choose per category, and consent can be withdrawn at any time from the section below.
10. Security
We use HTTPS/TLS 1.3, hashed passwords (bcrypt), httpOnly cookies, rate limiting, TOTP 2FA for administrative accounts, AES-256-GCM encryption for OAuth and TOTP secrets, Content-Security-Policy in enforce mode, and other standard measures. We maintain a written Information Security & Safety Program (ISSP) per COPPA § 312.8 and a Data Retention Policy, both available to supervisory authorities on request. In the event of a security breach with risk to your rights, we notify you within 72 hours (GDPR Art. 34).
11. Your rights as a California resident (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) + California Privacy Rights Act (CPRA):
- Right to know — what personal information we collect, sources, purposes, and categories of third parties we share with
- Right to delete — personal information (subject to legal exceptions — e.g., legal obligations, security)
- Right to correct — inaccurate information
- Right to opt-out — of sale or sharing of personal information
- Right to non-discrimination — for exercising your CCPA rights
- Right to data portability — receive your data in a structured, machine-readable format
NOTE: Deutsch-Landia does NOT sell or share children's or adults' data with third parties for behavioral or cross-context advertising.
To exercise these rights, email privacy@deutsch-landia.com with subject "CCPA Request". We will respond within 45 days (45-day extension permitted under CCPA § 1798.130(a)(2)).
Notice at Collection (CPRA): Categories of personal information we collect and their purposes are detailed in the "Data collected" section. Children's data (under 16) is classified as sensitive personal information under CPRA and is never sold or shared.
12. Data protection contact
For any question about your data, write to us at: gdpr@deutsch-landia.com
We have not designated a Data Protection Officer (DPO) within the meaning of Art. 37 GDPR; requests are handled directly by the controller. You can also file complaints with ANSPDCP (the Romanian National Supervisory Authority for Personal Data Processing).