Privacy Policy
Version 2026-09-22Only the German version is legally binding. This language version is provided for information only. Go to the German version
1. Data Protection at a Glance
General Information
The following notices provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.
2. Controller and Hosting
Responsible Party
The party responsible for data processing on this website is the German civil-law partnership (GbR):
SLT-Software
Bauer & Schmid GbR
Mittelfeldstraße 29
70806 Kornwestheim
Represented by:
Alexander Bauer, Dr. Wolfgang Schmid
Contact:
Phone: 07154-8062415
Fax: 07154-8062416
E-mail: info@slt.de
Website: slt.de
Hosting
The static files of the website and the app are hosted by Fritz Managed IT GmbH, Ötterichweg 7, 90411 Nuremberg, Germany; sub-processors are Hetzner Online GmbH (data centres in Germany) and Global Switch (data centre in Frankfurt am Main). A data processing agreement (Art. 28 GDPR) is in place with the host.
We host the content of our website with the following provider:
Fritz Managed IT GmbH
Ötterichweg 7
DE-90411 Nürnberg
The use of the hosting provider is based on Art. 6 (1) lit. f GDPR. We have a legitimate interest in the technically reliable and secure presentation of our website.
3. Data Collection on This Website
Server Log Files
The provider of the pages collects and stores information automatically in so-called server log files, which your browser transmits to us:
- Browser type and version
- Operating system used
- Referrer URL (the previously visited page)
- Hostname of the accessing computer
- Time of the server request
- IP address
The server log files contain IP addresses and are deleted by the host after 30 days at the latest.
This data is technically required for the secure operation of the website. Processing is carried out in accordance with Art. 6 (1) lit. f GDPR.
Fonts (Local Hosting)
We use web fonts for a uniform presentation of typefaces. These are installed locally on our web server. No connection to external servers (e.g. Google Fonts) takes place.
Inquiry by E-mail, Phone or Fax
If you contact us by e-mail, phone or fax, your inquiry, including all personal data resulting from it (name, inquiry), will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
Processing of this data is based on Art. 6 (1) lit. b GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 (1) lit. f GDPR) or on your consent (Art. 6 (1) lit. a GDPR) if it has been requested; consent can be revoked at any time.
The data you send us via contact requests will remain with us until you request its deletion, revoke your consent for storage, or the purpose for storing the data ceases to apply (e.g. after we have finished processing your inquiry). Mandatory legal provisions—in particular statutory retention periods—remain unaffected.
4. General Notices and Mandatory Information
Data Protection
We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy. Through the purely informational use of this website, only data is collected that is technically necessary for operation.
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the browser address bar changes from "http://" to "https://" and by the lock symbol in your browser bar.
Note on Data Transfer to Third Countries
The application uses services including Google Firebase, hCaptcha and Stripe. These services may transfer data to third countries. The controller for data processing at Stripe is Stripe Technology Company, Limited (STC), One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland, Stripe’s main establishment in Europe and controller for data processed outside the Americas. For regulated payment services, STC, Stripe Payments Europe, Limited (SPEL) and the locally regulated Stripe entity act as joint controllers; the e-money institution is Stripe Technology Europe, Limited, regulated by the Central Bank of Ireland. For transfers to third countries Stripe relies on the EU-US Data Privacy Framework and standard contractual clauses. Details about each service, its purpose and safeguards appear in the following sections and in the cookie policy.
Your Rights (Information, Deletion, Complaint)
You have the right at any time to receive free information about the origin, recipients and purpose of your stored personal data. You also have the right to lodge a complaint with the responsible supervisory authority.
5. Storage of Your Data in the Cloud (Firebase / Firestore)
Cloud Storage with Google Firebase
To provide learning progress across multiple devices and to synchronise parent and child accounts, we use services from the Google Cloud Platform, in particular Firebase Authentication and Cloud Firestore (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).
The following personal data is stored in Cloud Firestore:
- E-mail address, display name and account type (parent, teacher, child)
- Learning progress, completed lessons, achievements and statistics
- Language preference, display mode, learning plans and timer settings
- Child profiles created by you as a parent or teacher
Data location: Hurra Mathe's named Cloud Firestore database and Cloud Functions are configured in region "europe-west3" (Frankfurt, Germany). This regional choice does not automatically apply to every Firebase service: according to Google, Firebase Authentication runs exclusively from US data centres, while Firebase App Check uses global infrastructure.
We have concluded a data processing agreement with Google in accordance with Art. 28 GDPR. Where data is transferred outside the EU/EEA, the provider states that suitable safeguards include EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) for registered users and Art. 6 (1) lit. f GDPR (legitimate interest) for providing the synchronisation functionality. For child accounts, processing is additionally based on the consent of the legal guardian (Art. 6 (1) lit. a, Art. 8 GDPR).
E-mail delivery
We send transactional e-mails (e.g. verification, invitation, contract and cancellation confirmations) via the processor Mailjet (Sinch group), German branch: Mailjet GmbH, Alt-Moabit 2, 10557 Berlin. E-mail address, name, message content and sending/delivery data are processed; e-mails are sent from servers in the EU. The data processing agreement (Art. 28 GDPR) is concluded via Mailjet’s terms of use (Data Processing Agreement).
The legal basis is Art. 6(1)(b) GDPR (performance of the contract) or Art. 6(1)(f) GDPR (reliable delivery).
One-time trial (check register)
So that the free 7-day trial can be used only once per e-mail address, when a trial starts we store in a check register only a pseudonymised check value of your e-mail address (HMAC-SHA256 with a secret key over the normalised address) together with the start and expiry date of the entry. The e-mail address itself is not stored there; it cannot be derived without the separately kept key. When someone registers again with the same e-mail address, we only check whether an entry exists.
The entry is kept even after the account has been deleted and is deleted automatically 36 months after the trial started.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to prevent the free trial from being used more than once. You may object to the processing on grounds relating to your particular situation (Art. 21 GDPR).
Offline Mode and Local Storage
The application also works without an internet connection. In this case, your entries are first stored in your browser's local storage and are automatically synchronised with Cloud Firestore the next time you go online. Locally stored data does not leave your device until synchronisation.
In demo mode (without signing up), your practice progress is stored solely in this browser's local storage and is never uploaded to the cloud. If the demo is not used for more than seven days, this local progress is automatically deleted the next time you open it. Before deletion we offer to preserve it by creating an account; the transfer then happens entirely within this browser into your account.
Retention Period and Deletion
We store your data for as long as your account exists. You can delete your account and thus all associated data at any time in the settings; all personal data in Cloud Firestore will then be removed immediately. Mandatory statutory retention obligations remain unaffected.
If a child registers on their own, the confirmation request to the parents is valid for 14 days. If the parents decline or do not confirm within 14 days, we delete the child account with all its data. As proof (Art. 6(1)(c) and (f) GDPR) we only store the outcome, timestamps, the identifier of the deleted account and check values (hashes) of the parents’ e-mail address and – for a refusal – of the IP address, but no plain e-mail address and no name; this proof is deleted at the end of the third calendar year following the event.
Retention periods at a glance: free accounts are deleted after 24 months of complete inactivity (e-mail notice four weeks beforehand). Child accounts frozen after a downgrade are deleted after 12 months (e-mail notice 30 days beforehand). Records of the conclusion of contracts, cancellations and consents are kept after an account has been deleted until 31 December of the third following year. The check value for the one-time trial is deleted after 36 months, server log files after 30 days at the latest.