Privacy policy
This English version is a translation for your convenience. Only the German version is legally binding.
1. Controller
The controller responsible for data processing in Accelerando is:
Accelerando is run by a private individual. No data protection officer has been appointed because there is no legal obligation to do so. Please send questions about data protection to the email address above.
2. Overview
Accelerando is a practice tracker for the members of the orchestra. Access is by invitation only. I only process the data needed for signing in and for recording your practice sessions.
There is no advertising, no tracking, no audience measurement and no embedded content from other providers. Fonts, images and all other files come from our own server.
3. Visiting the website and server log files
Every time the website and the app are accessed, the host processes the following data in log files for technical reasons: IP address, date and time, requested address, amount of data transferred, status code, browser and operating system (user agent) and the previously visited page (referrer).
If an error occurs on the server, the application writes a technical message to the host’s error log. If sending an email fails, this message contains the recipient address, never the content of the email. The error log is kept for the same period as the access logs.
Purpose: delivering the website, secure operation, error analysis and defence against attacks. Legal basis: Art. 6(1)(f) GDPR; my legitimate interest is secure and stable operation.
4. Invitation
The orchestra’s administration can invite you with your email address and your name and add an instrument (optional) and a role. This information comes from the running of the orchestra.
You receive an email with an invitation link. It is valid for 7 days and can be used once; if the administration sends the invitation again, only the newest link is valid. If you do not accept the invitation, your entry remains with the status “invited” until the administration deletes it.
Legal basis: Art. 6(1)(f) GDPR. My legitimate interest is offering the members of the orchestra a tool for practising.
5. Account and signing in by email link
For your account I store: email address, name, instrument (if given), role (member, librarian or administration), account status (invited, active or deactivated), language and whether you chose it yourself, the time of your last sign-in and the times the account was created and last changed.
Accelerando does not use passwords. To sign in, you enter your email address and receive a link that is valid for 15 minutes and can be used once. Only a cryptographic hash of the link is stored, not the link itself, together with its expiry and time of use. After you sign in, all other open links become invalid. A nightly clean-up deletes used and expired links once they are more than a day old.
When you sign in for the first time, Accelerando adopts your browser’s language unless you have chosen one. If you choose a language in your profile, it is stored in your account and also applies to emails.
Purpose: providing your account and secure sign-in. The administration sees the time of your last sign-in in order to recognise inactive accounts. Legal basis: Art. 6(1)(b) GDPR (use of Accelerando); for the time of the last sign-in Art. 6(1)(f) GDPR, my legitimate interest being the secure management of accounts.
Email address and name are required to use Accelerando; the instrument is optional.
Retention: until the administration deletes your account. A deactivated account remains with all practice data until the administration deletes it; you can no longer sign in with it. There is no automatic deletion. If you want your account to be deleted, contact the administration or me (section 1).
6. Sending emails
Invitations and sign-in links are sent to your address as plain-text emails via the host’s mail server. They contain no tracking pixels and no redirected links. The connection to the host’s mail server is encrypted; further on, transmission is usually encrypted (TLS) if your email provider’s mail server supports it.
Legal basis: as for the invitation and the account (sections 4 and 5).
7. Protecting sign-in against misuse
To prevent anyone from requesting sign-in links in bulk, the number of requests is limited: to five links per hour per account, counted via the stored links, and per connection regardless of the address. For the count per connection I do not store the IP address in plain text, only as a check value (HMAC with a secret key; for IPv6 per /64 network), together with the time of the request. The nightly clean-up deletes entries older than one hour.
Legal basis: Art. 6(1)(f) GDPR. My legitimate interest is protecting your account and the service against misuse.
8. Practice sessions and entries
When you practise, I store your practice sessions with start, end and an optional note, and your entries: passage, tempo with note value, rating (unsteady, clean or secure), optional note and time. A practice session that has been open for more than 4 hours is ended automatically. From your entries Accelerando calculates your statistics and the suggestion “Practise next”.
Your practice data is private. Only you see it; the administration and the librarians have no access either. The server checks this on every request.
Please do not enter information about your health or other sensitive information in notes.
Legal basis: Art. 6(1)(b) GDPR. Retention: until you delete the entries or the administration deletes your account.
9. Visibility within the app
To manage accounts, the administration sees name, email address, instrument, role, status and the time of the last sign-in. It can deactivate and delete accounts; deleting an account permanently removes all of its practice sessions and entries.
The librarians maintain the catalog of pieces and see no practice data. When they delete a piece or a passage, they only learn whether anyone has entries for it (the item is then archived instead of deleted), not who.
10. Cookies and local storage
Only after you sign in does Accelerando set a single cookie that keeps you signed in. It contains a random identifier, cannot be read by scripts (HttpOnly), is only transmitted encrypted over HTTPS and expires 30 days after you last used Accelerando, at the latest 90 days after signing in. The server only stores a hash of the identifier together with a value that protects against forged requests and the times of the session. The session ends when you have not been active for 30 days, at the latest 90 days after signing in, and immediately when you sign out; a nightly clean-up deletes expired sessions.
When you open the start page, the web server only checks whether this cookie is present and then takes you directly to “Practice”. If the cookie no longer belongs to a valid session, the server deletes it with the next request. No further cookie is used for this.
Accelerando only stores something in your browser’s local storage (localStorage) when you choose a setting yourself: “accelerando.theme” with the value “light” or “dark” when you tap the appearance switch (resetting to the system setting removes the entry), and “accelerando.locale” with “de” or “en” when you choose a language. These values contain no identifier and are not sent to the server.
When the administration uses “View as”, the browser remembers the chosen role until the tab is closed (sessionStorage, “accelerando.viewAs”). The app sends it with every request so that the server restricts the permissions accordingly.
The cookie and these entries are strictly necessary to provide the service you requested; consent is therefore not required under § 25(2) no. 2 TDDDG. I process the session on the basis of Art. 6(1)(b) GDPR. The public start page, the legal notice and this page set no cookies.
11. Recipients and hosting
The host is ALL-INKL.COM, Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. It runs the web server, database and mail server on my behalf; a data processing agreement under Art. 28 GDPR is in place.
Beyond that, I do not pass on any data. The data is stored on servers in Germany; there is no transfer to third countries. The emails themselves are delivered by the email provider of your address.
I use GitHub to develop and deliver the program code. No data of users is processed in the process. The nightly clean-up is triggered by a GitHub service; the server only reports counts back, such as the number of deleted entries, no personal data.
12. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Please use the email address in section 1.
You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
13. Right to object under Art. 21 GDPR
Where I process data on the basis of Art. 6(1)(f) GDPR (sections 3, 4, 5 for the time of the last sign-in and 7), you may object at any time on grounds relating to your particular situation. I will then no longer process the data unless I can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
14. No automated decisions
There are no automated decisions within the meaning of Art. 22 GDPR and no profiling. The suggestion “Practise next” is calculated only from your own entries, is visible only to you and has no effect other than being displayed.
15. Security
The connection is encrypted with HTTPS throughout. Sign-in and invitation links as well as session identifiers are stored only as hashes in the database, IP addresses only as check values. The server checks roles and access rights on every request.
16. Changes
If the processing changes, I will update this policy.