Privacy Policy
Reviewed on: 9/24/2026These texts are also published on slt.de: GTC · Withdrawal information · Privacy
1. Data Protection at a Glance
General Information
The following notices provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.
2. Controller and Hosting
Responsible Party
The party responsible for data processing on this website is the German civil-law partnership (GbR):
SLT-SoftwareBauer & Schmid GbR
Mittelfeldstraße 29
70806 Kornwestheim
Vertreten durch / Represented by:
Alexander Bauer, Dr. Wolfgang Schmid
Telefon: 07154-8062415
Fax: 07154-8062416
E-Mail: info@slt.de
Webseite: slt.de
We have not appointed a data protection officer, as there is no statutory obligation to do so.
Hosting
The static files of the website and the app are hosted by Fritz Managed IT GmbH, Ötterichweg 7, 90411 Nuremberg, Germany; sub-processors are Hetzner Online GmbH (data centres in Germany) and Global Switch (data centre in Frankfurt am Main). A data processing agreement (Art. 28 GDPR) is in place with the host.
We host the content of our website with the following provider:
Fritz Managed IT GmbHÖtterichweg 7
DE-90411 Nürnberg
The use of the hosting provider is based on Art. 6 (1) lit. f GDPR. We have a legitimate interest in the technically reliable and secure presentation of our website.
3. Data Collection on This Website
Local storage in your browser (no cookies)
We do not set cookies. We store technically necessary information in your browser's local storage (localStorage, sessionStorage, IndexedDB) and in the service worker cache. There is no analytics, no audience measurement and no advertising.
Depending on its purpose, this information remains only for the session or until you sign out, change the setting or clear your browser data. We store in particular:
- language and display mode (light or dark)
- cached account and learning data together with the queue of changes not yet transferred (offline use)
- the Firebase Authentication sign-in data in IndexedDB, until you sign out
- a random device identifier and a session identifier for the single-device session
- a counter of failed sign-in attempts, stored under a non-reversible short value of the e-mail address
- short-lived markers for a purchase made by a parent and for the height of the numeric keypad
- the static files of the app in the service worker cache, so they are available offline
A complete overview with category, purpose, storage location and duration is available in the Cookie Policy.
Storing this information on your device and reading it is strictly necessary for the service you have expressly requested (Section 25(2) no. 2 TDDDG). The subsequent processing is based on Art. 6(1)(b) GDPR (performance of the contract) or Art. 6(1)(f) GDPR (legitimate interest in secure, functional operation).
Server Log Files
When our pages are accessed, our host automatically collects and stores information in server log files that your browser transmits:
- Browser type and version
- Operating system used
- Referrer URL (the previously visited page)
- Hostname of the accessing computer
- Time of the server request
- IP address
The server log files contain IP addresses and are deleted by the host after 30 days at the latest.
Our server functions at Google Cloud (Frankfurt am Main) also log technical request data including the IP address. These logs are deleted after 30 days; logs of administrative operations are kept by Google Cloud for 400 days.
This data is technically required for the secure operation of the website. Processing is carried out in accordance with Art. 6 (1) lit. f GDPR.
Spam protection (ALTCHA, self-hosted)
To protect registration, password reset and the cancellation form against automated abuse, we use a self-hosted proof-of-work check (ALTCHA, open-source software). Your browser solves a small computational task that is issued and verified by our own servers in Frankfurt am Main; those servers are operated for us by Google Cloud (region europe-west3) as our processor. No cookies are set, no user profiles are created and no data is passed on to third parties; characteristics of your device and your usage behaviour are not analysed.
We do not store your IP address itself. To limit the number of requests (rate limiting) we instead store a check value of your IP address computed with a secret key (HMAC); without the separately kept key the address cannot be derived from it. This value is deleted automatically, at the latest about one day after your last request. Tasks that have already been solved are stored briefly without any personal reference so that they cannot be reused, and are also deleted automatically.
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is protecting our service and our users against spam and automated attacks.
Error logs
If a serious error occurs in the app, we store the time, the error message and technical details of the error, the page affected, the browser identifier (user agent), the online status as well as your user identifier and your e-mail address in our database in Frankfurt am Main, in order to fix the problem. Errors in child accounts are logged in the same way.
We delete error logs after 90 days.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the stable and secure operation of the service.
Fonts (Local Hosting)
We use web fonts for a uniform presentation of typefaces. These are installed locally on our web server. No connection to external servers (e.g. Google Fonts) takes place.
Inquiry by E-mail, Phone or Fax
If you contact us by e-mail, phone or fax, your inquiry, including all personal data resulting from it (name, inquiry), will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
Processing of this data is based on Art. 6 (1) lit. b GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 (1) lit. f GDPR) or on your consent (Art. 6 (1) lit. a GDPR) if it has been requested; consent can be revoked at any time.
The data you send us via contact requests will remain with us until you request its deletion, revoke your consent for storage, or the purpose for storing the data ceases to apply (e.g. after we have finished processing your inquiry). Mandatory legal provisions—in particular statutory retention periods—remain unaffected.
4. General Notices and Mandatory Information
Data Protection
We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy. Through the purely informational use of this website, only data is collected that is technically necessary for operation.
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the browser address bar changes from "http://" to "https://" and by the lock symbol in your browser bar.
Note on Data Transfer to Third Countries
To operate the application we use Google Firebase, Google Cloud, Mailjet and Stripe. This may involve transfers to third countries, in particular to the USA. The purposes, the recipients and the safeguards we rely on are set out in the following sections and in the cookie policy.
Whether you have to provide data, and automated decisions
Providing an e-mail address and a password is required for registration; without them no account can be created. A paid plan additionally requires a billing address, and a child account created by the child itself requires a parent's e-mail address. Apart from that, providing your data is neither required by law nor by contract; individual features may then not be available.
Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place. Automatic security features — such as the temporary lock after several failed sign-in attempts, the single-device session or limiting the trial to one per e-mail address — have no legal or similarly significant effect.
Your Rights
You have the right of access (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR) and to data portability (Art. 20 GDPR).
You may withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR); this does not affect the lawfulness of processing carried out before the withdrawal.
Please address requests to info@slt.de.
You may also lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular with the authority responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
Right to object (Art. 21 GDPR)
Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
An informal message to info@slt.de is enough to object.
5. Storage of Your Data in the Cloud (Firebase / Firestore)
Cloud Storage with Google Firebase
To provide learning progress across multiple devices and to synchronise parent and child accounts, we use services from the Google Cloud Platform, in particular Firebase Authentication and Cloud Firestore (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).
The following personal data is stored in Cloud Firestore:
- E-mail address, display name and account type (parent, teacher, child)
- Learning progress, completed lessons, achievements and statistics
- Language preference, display mode, learning plans and timer settings
- Child profiles created by you as a parent or teacher
Data location: Hurra Mathe's named Cloud Firestore database and Cloud Functions are configured in region "europe-west3" (Frankfurt, Germany). This regional choice does not automatically apply to every Firebase service: according to Google, Firebase Authentication runs exclusively from US data centres.
Firebase Authentication processes the sign-in data there (e-mail address or account identifier, password hash, IP address at sign-in), including that of child accounts. The transfer to the USA is based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR), under which Google LLC is certified; in addition, the EU Standard Contractual Clauses apply (Art. 46(2)(c) GDPR) as part of the Google Cloud Data Processing Terms.
We have concluded a data processing agreement with Google in accordance with Art. 28 GDPR.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) for registered users and Art. 6 (1) lit. f GDPR (legitimate interest) for providing the synchronisation functionality. For child accounts, processing is additionally based on the consent of the legal guardian (Art. 6 (1) lit. a, Art. 8 GDPR).
Payment processing (Stripe)
When you take out a paid plan we forward you to our payment service provider Stripe. Stripe processes name, e-mail address, billing address (mandatory), payment details and transaction data. We receive customer, subscription and payment status from Stripe and transmit our internal user identifier so that payment and account can be matched. We do not receive full card or account numbers.
For every transaction we log the time, type and outcome of the payment together with Stripe's transaction identifiers, so that payments can be traced and questions answered.
The controller for data processing at Stripe is Stripe Technology Company, Limited (STC), One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland, Stripe’s main establishment in Europe and controller for data processed outside the Americas. For regulated payment services, STC, Stripe Payments Europe, Limited (SPEL) and the locally regulated Stripe entity act as joint controllers; the e-money institution is Stripe Technology Europe, Limited, regulated by the Central Bank of Ireland. For transfers to third countries Stripe relies on the EU-US Data Privacy Framework and standard contractual clauses.
Stripe acts partly as our processor and partly on its own account. For the technical transmission and settlement of payments, Stripe processes the data on our behalf and on our instructions (Art. 28 GDPR); the data processing agreement incorporated into the Stripe user agreement applies. Where Stripe fulfils its own statutory duties — identity verification (Know Your Customer), anti-money-laundering, network-wide fraud prevention and its own business relationship with you — Stripe is an independent controller and decides on purposes and means alone. There is no joint controllership under Art. 26 GDPR; Stripe excludes it contractually. You can exercise your rights as a data subject towards us and towards Stripe; Stripe informs you itself about the data it processes on its own account.
We keep invoices and payment records for up to 10 years. The payment log also contains accounting records and is therefore kept for up to 10 years as well; the purely technical webhook log is deleted after 90 days.
The legal basis is Art. 6(1)(b) GDPR (performance of the contract); for accounting records Art. 6(1)(c) GDPR in conjunction with Section 147 AO and Section 257 HGB.
Single-device session and activity
So that an account is used on only one device at a time, we store a random device identifier and a session identifier in your browser, and in our database the user identifier, the device identifier and the expiry time of the session (about five minutes after the last activity). If the same account signs in on a second device, the older session is ended.
We also store the date of your last activity so that free accounts can be deleted after 24 months of complete inactivity.
The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR (legitimate interest in protection against unauthorised parallel use). Storing and reading the device identifier on your device is strictly necessary for the service you requested (Section 25(2) no. 2 TDDDG).
Child accounts invited by parents or teachers
When parents or teachers create a child account or import several children from a CSV file, we process the child's first name, last name, e-mail address and group assignment in order to send the invitation and manage the account. The source of this data is the inviting account; we do not collect it from the child. This policy is how we inform the child and the parents about that processing (Art. 14 GDPR).
Invitations that are not accepted are deleted once they expire. We are the controller for this processing — including when a teacher sends the invitation: they act like a parent adding their own children, not as a representative of a school. Because the child’s details do not come from the child, the invitation e-mail contains the information required by Art. 14 GDPR, in particular who issued the invitation. The legal basis is Art. 6(1)(b) and (f) GDPR.
The legal basis is Art. 6(1)(b) GDPR towards the inviting account and Art. 6(1)(f) GDPR for setting up and managing the child account.
Conclusion of contract, cancellation and records
When you place an order we store the version and time of the terms accepted, the plan booked, the price, the language version and Stripe's transaction identifier. On a cancellation — including one submitted through the public cancellation form without signing in — we store the name, the account and confirmation e-mail addresses, the type and scope of the cancellation, any reason given and both the requested and the actual end date.
The purpose is performing the contract, meeting the statutory confirmation duties (Sections 312f and 312k BGB) and proving how the order and the cancellation came about.
We keep these records until 31 December of the third year after the contract ends or the account is deleted.
The legal basis is Art. 6(1)(b), (c) and (f) GDPR.
E-mail delivery
We send transactional e-mails via the processor Mailjet (Sinch group), German branch: Mailjet GmbH, Alt-Moabit 2, 10557 Berlin. E-mail address, name, message content and sending/delivery data are processed; e-mails are sent from servers in the EU. The data processing agreement (Art. 28 GDPR) is concluded via Mailjet’s terms of use (Data Processing Agreement).
Sinch uses sub-processors that may also process data outside the EU/EEA. Those transfers are covered by the EU Standard Contractual Clauses under Implementing Decision (EU) 2021/914 of 4 June 2021, and for the "Sinch Email" service additionally by the EU-US Data Privacy Framework including its UK extension as well as the UK Addendum. Supplementary technical and organisational measures have been agreed, in particular encryption, aggregation, separated access controls and data minimisation. Sinch publishes the current list of sub-processors at https://sinch.com/legal/data-protection-agreement-sub-processors/ and announces changes 30 days in advance.
We send in particular:
- verification of the e-mail address and password reset e-mails
- requests to parents to consent to a child account, and reminders about them
- invitations to child accounts
- contract confirmations and cancellation confirmations
- payment notices and payment reminders
- notices before deletion for inactivity and notices about frozen child accounts
- confirmation codes for deleting the account and other security notices
For every message we log the time, the type and the delivery status without the recipient in clear text; this log is deleted after 90 days. To prevent abuse we limit the number of messages per account, e-mail address or request and briefly store counters under a check value of the identifier concerned.
The legal basis is Art. 6(1)(b) GDPR (performance of the contract) or Art. 6(1)(f) GDPR (reliable delivery and protection against abuse).
One-time trial (check register)
So that the free 7-day trial can be used only once per e-mail address, when a trial starts we store in a check register only a pseudonymised check value of your e-mail address (HMAC-SHA256 with a secret key over the normalised address) together with the start and expiry date of the entry. The e-mail address itself is not stored there; it cannot be derived without the separately kept key. When someone registers again with the same e-mail address, we only check whether an entry exists.
The entry is kept even after the account has been deleted and is deleted automatically 36 months after the trial started.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to prevent the free trial from being used more than once. You may object to the processing on grounds relating to your particular situation (Art. 21 GDPR).
Offline Mode and Local Storage
The application also works without an internet connection. In this case, your entries are first stored in your browser's local storage and are automatically synchronised with Cloud Firestore the next time you go online. Locally stored data does not leave your device until synchronisation.
In demo mode (without signing up), your practice progress is stored solely in this browser's local storage and is never uploaded to the cloud. If the demo is not used for more than seven days, this local progress is automatically deleted the next time you open it. Before deletion we offer to preserve it by creating an account; the transfer then happens entirely within this browser into your account.
Retention Period and Deletion
We store your data for as long as your account exists. You can delete your account and thus all associated data at any time in the settings; your account and learning data are then removed immediately. Excluded from this are:
- records of the conclusion of contracts, cancellations and consents — until 31 December of the third year after the contract ends
- records that must be kept under tax and commercial law, in particular invoices — up to 10 years
- the record of the parents' decision and the consent log — 3 years
- a pseudonymised deletion note (user identifier and check value of the e-mail address) — 3 years
- technical logs (error, e-mail, webhook and lifecycle log) — 90 days
- the check value for the one-time trial — 36 months
Until they are deleted, we use this data only for the purpose for which we keep it. Mandatory statutory retention obligations remain unaffected.
If a child registers on their own, the confirmation request to the parents is valid for 7 days. If the parents decline or do not confirm within 7 days, we delete the child account with all its data. As proof (Art. 6(1)(c) and (f) GDPR) we only store the outcome, timestamps, the identifier of the deleted account and check values (hashes) of the parents’ e-mail address and – for a refusal – of the IP address, but no plain e-mail address and no name; this proof is deleted at the end of the third calendar year following the event.
Retention periods at a glance: free accounts are deleted after 24 months of complete inactivity (e-mail notice four weeks beforehand). Child accounts frozen after a downgrade are deleted after 12 months (e-mail notice 30 days beforehand). Records of the conclusion of contracts, cancellations and consents are kept after an account has been deleted until 31 December of the third following year. The check value for the one-time trial is deleted after 36 months, server log files after 30 days at the latest.
6. Children's privacy
Child accounts and parental consent
Our service is designed for children. Parents, guardians and teachers can create and manage child accounts themselves.
If a child registers on their own, we obtain a parent's consent by e-mail. Until that decision, data is already held in the cloud: an account for signing in exists at Firebase Authentication (processed in the USA, see above), and in our database in Frankfurt am Main we store the child's name and sign-in e-mail address, the parents' e-mail address, the language version and a random confirmation code. The request to the parents is composed and sent by our server; neither recipient nor content is determined by the child's device.
The app stays locked until consent is given. Practice data is created in that period only if the child uses demo mode; it then stays exclusively in this browser.
If no consent is given within 7 days, we delete the child account with all its data; if a parent declines, we delete it immediately. The details stored solely for the request are deleted with the decision, at the latest after 7 days.
Use by schools is only offered through a separate school solution on request.
The legal basis for processing until the parents decide is Art. 6(1)(f) GDPR. Our legitimate interest is being able to obtain the consent required by Art. 8(2) GDPR in the first place.
Explained for children
Hello! So that you can practise with Hurra Mathe, we remember your name, your sign-in e-mail and what you have practised. Only you and your parents or your teacher can see this. We show you no adverts and we sell nothing about you. Your parents can have your data deleted at any time. If you have questions, ask your parents – they can write to us.