Privacy Statement

We respect your privacy and are committed to protecting your personal and academic data in full compliance with the General Data Protection Regulation (GDPR).

Last Updated: October 5, 2026

1. Introduction and Controller Information

Welcome to our Student Learning Management System (referred to herein as "The Learning Mindset Platform"). We respect your privacy and are committed to protecting your personal data.

As a platform operating from The Netherlands, we fully adhere to the strict data protection standards set forth by the General Data Protection Regulation (GDPR) and other applicable European Union privacy laws.

Data Controller: Leiden University

Location: Rapenburg 70, 2311 EZ, Leiden, The Netherlands

2. What Personal and Academic Information Is Collected?

To provide you with a seamless educational and administrative experience, we collect and process specific categories of information:

  • Personal Information: User ID, full name, email address, date of birth, physical address, account password (securely stored as a Bcrypt hash), profile photo, email verification PIN, and verification status.
  • Academic Information: Educational details including your university, program, program level, academic year, and faculty.

3. What Student-Generated Content Is Stored?

During your active learning journey on the platform, we store content created and uploaded by you, which includes:

  • Academic and learning progress data.
  • Student-generated learning journals, tool inputs, media files, and downloaded PDF materials.

4. Why the Information Is Collected (Legal Basis under GDPR)

We collect and process your information strictly for legitimate educational, operational, and administrative purposes in accordance with GDPR Article 6:

  • Performance of a Contract: To create and manage your user account, verify your identity via email, and grant you access to educational tools and learning management features.
  • Legitimate Interests: To maintain platform security, conduct educational research and analysis, and ensure proper academic administration.

5. Who Can Access Your Data?

Access to your personal and academic data is strictly controlled on a need-to-know basis:

  • Platform Administrator: Has full administrative panel access to manage user accounts and system integrity.
  • Platform Developers: May occasionally access the administrative panel strictly for development, technical maintenance, and debugging needs.
  • You (The Student): You have continuous access to your own personal profile, learning journals, interactive tools, and exported PDFs.
  • Third Parties: No unauthorized external parties have access to your data.

6. Data Retention Policy (How Long It Is Retained)

We retain your data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Active Records: System data is automatically managed to purge student records and content older than one year from the database.
  • Student Exports: Prior to automated data deletion, students are encouraged and permitted to save and export their historical learning journals as PDF files for long-term personal archiving.
  • Backups: Full hosting account backups are managed via an automated plugin schedule consisting of 6 daily backups (kept for 6 days), 3 weekly backups (kept for 3 weeks), and 5 monthly backups (kept for 5 months), after which they are systematically overwritten.

7. Which Third Parties Process Your Data?

We minimize data sharing with external entities to protect your privacy:

  • Hosting Provider: The platform and its Progressive Web App (PWA) are hosted via NameCheap Shared Web Hosting, with servers physically located in a US data center (RadiusDC: Phoenix). Appropriate safeguards are implemented for international data transfers under EU law.
  • Email Service: We utilize the hosting environment's built-in SMTP service exclusively for essential operational communications, such as email address verification, password-reset PINs, and contact-form submissions.
  • No AI or Tracking APIs: The platform does not utilize external AI/LLM models, external advertising trackers, or third-party analytics APIs.

8. Data Security and Incident Management

We implement robust technical and organizational measures to ensure the security of your data:

  • Encryption in Transit: The live platform operates exclusively over HTTPS/TLS, ensuring that all data transmitted between your web browser and our server is encrypted and protected.
  • Encryption at Rest: User passwords are never stored in plain text; instead, they are securely salted and stored using Bcrypt hashing.
  • Security Incidents & Breaches: In the unlikely event of a personal data breach that poses a high risk to your rights and freedoms, the Data Controller will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours and inform affected users without undue delay, in compliance with GDPR Articles 33 and 34.

9. How Students Can Request Access, Export, or Deletion

Under the GDPR, you hold specific rights regarding your personal data. You can exercise these rights by contacting our privacy team:

  • Access & Rectification: You can request a summary of the personal and academic data we hold about you and ask for corrections if information is inaccurate.
  • Data Export: While comprehensive CSV/JSON export tools for entire courses are not currently built directly into the interface, you can independently export your learning journals as PDF documents at any time. Administrators may also download student PDFs when strictly necessary for authorized research and analysis.
  • Erasure & Deletion: You have the right to request the early deletion of your account and associated records ahead of our standard one-year automated purge cycle.

10. Questions and Privacy Contact

If you have any questions regarding this privacy statement, wish to exercise your data protection rights, or need to report a privacy concern, please contact our designated privacy contact: