Controller and contact
PLUCO GROUP SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Ksawerów 3, 02-656 Warsaw, Poland, is the controller. Privacy requests may be sent to support@desivo.de.
Privacy
This notice describes the active school-enquiry form, administration and current service providers.
PLUCO GROUP SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Ksawerów 3, 02-656 Warsaw, Poland, is the controller. Privacy requests may be sent to support@desivo.de.
The public information pages do not provide learner accounts. If a school sends the For schools request, we receive its organisation and registry details, address, representative name and role, email, optional telephone and website, requested scope, scale, notes, locale, consent timestamps and a request reference. The hosting service also processes ordinary technical request and security log data. Administrators use an email one-time code and a necessary session cookie.
We process school-request data to answer the request, prepare requested draft documents and take steps before a possible contract (GDPR Art. 6(1)(b)); to protect the service, prevent abuse and keep an auditable request record on our legitimate interests (Art. 6(1)(f)); and, where records must be kept, to comply with legal obligations (Art. 6(1)(c)). Any optional technology that requires consent will only be used after consent (Art. 6(1)(a)).
Data may be handled by Vercel (website hosting), Neon (PostgreSQL database hosting), and the configured SMTP/email provider for delivery of request notifications, solely for those purposes and under appropriate processor arrangements. We do not sell personal data. Provider hosting locations and any international-transfer safeguards must be confirmed against the production accounts before a commercial launch.
School requests are kept while the request is handled and afterwards only as needed for follow-up, evidence, legal claims or mandatory records. Admin sessions expire after seven days. No fixed automated deletion schedule is currently configured; this must be approved before commercial launch. We delete or anonymise data when no longer necessary, subject to legal retention duties, and respond to valid deletion requests.
The service uses HTTPS, input limits and validation, a hidden anti-bot field, random download tokens stored only as hashes, restricted email-code administration and HttpOnly, Secure-in-production, SameSite session cookies. Access is limited to the administration function. No internet service can promise absolute security.
No public analytics or advertising tracker is present in the reviewed version. A strictly necessary administrator session cookie is used after successful administrator login. If analytics or other optional tracking is later introduced, the notice and consent controls must be updated before activation.
Subject to the GDPR and applicable conditions, you may request access, correction, deletion, restriction, objection and portability; withdraw consent at any time without affecting earlier lawful processing; and complain to a competent data-protection authority. Contact support@desivo.de. We may need to verify your identity before acting on a request.