Privacy Policy
Information provided to users of plugins.dl-p.ch under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Articles 19 et seq. of the Swiss Federal Act on Data Protection (FADP).
Last updated:
1. Data controller
The controller of the personal data collected through this website is DL&P GmbH, registered office at Am Luchsgraben 17, 8051 Zurich, Switzerland, company identification number and VAT number CHE-130.760.530 VAT (the «Controller»).
Data Protection Officer (DPO), also acting as data protection adviser under Article 10 FADP: Achille Deodato, achille.deodato@dl-p.ch.
To exercise the rights described in section 9, or for any request concerning the processing of your personal data, write to achille.deodato@dl-p.ch.
The Controller is established in Switzerland and, since it offers its services also to data subjects located in the European Union, applies the GDPR pursuant to Article 3(2) in addition to Swiss data protection law. No representative in the Union has been designated under Article 27 GDPR, relying on the exemption in Article 27(2)(a): the processing described in this policy is occasional, does not involve large-scale processing of special categories of data and is unlikely to result in a risk to the rights and freedoms of data subjects.
2. Scope
This policy covers the pages published at plugins.dl-p.ch that present the Loop — Memo & Deadlines plugin for Moodle. Other areas reachable under the same domain, including the technical documentation published at plugins.dl-p.ch/loop-docs/, may be served by separate infrastructure and carry their own notice where their processing differs from the one described here. This policy does not apply to third-party websites reachable through links on this site, for which the Controller is not responsible.
The Loop plugin installed on a customer’s Moodle instance is a separate processing activity: there, the customer acts as controller of its own users’ data and the Controller, where it processes such data, acts as processor under a data processing agreement pursuant to Article 28 GDPR.
The plugin transmits no end-user personal data to the Controller: certification and expiry notifications are generated by the customer’s Moodle instance and delivered by email through the customer’s own mail server. On licence activation and periodic revalidation, the plugin sends the Controller’s licensing server only the data needed for that purpose: the licence key and activation identifier, a hash identifying the installation, the Moodle site address, the Moodle, plugin and PHP versions, the SHA-256 hash of the site’s main administrator email address, and the total number of active users. In respect of this data the Controller acts as an independent controller, for licence administration and prevention of unauthorised use, on the basis of Article 6(1)(b) and (f) GDPR; the data is retained for the term of the licence and for two years thereafter.
3. Data processed, purposes, legal bases and retention
The website requires no account and processes no special categories of personal data within the meaning of Article 9 GDPR. The processing activities are the following.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Contact form data: name, email address, organisation and, if filled in, the message text. | Receiving and handling the demo or information request and replying to the data subject. | Article 6(1)(b) GDPR: performance of pre-contractual steps taken at the data subject’s request. | 24 months from the last meaningful contact, unless a legal obligation requires otherwise. |
| The same contact form data. | Possible commercial follow-up regarding Loop with the organisation that submitted the request. | Article 6(1)(f) GDPR: the Controller’s legitimate interest in following up on an expression of interest in a professional (B2B) context. The data subject may object at any time. | 24 months from the last meaningful contact, or until objection if earlier. |
| Server technical logs: IP address, date and time of the request, requested URL, HTTP status code, volume of data transferred, user agent and referrer where present. | Operating and securing the website, diagnosing malfunctions, detecting and preventing abuse. | Article 6(1)(f) GDPR: legitimate interest in the security and availability of the service. | 30 days, except where longer retention is needed to investigate an abuse. |
| Anti-spam verification data collected by Cloudflare Turnstile on form submission: verification token, IP address, browser and device characteristics, page interaction signals. | Verifying that the form submission comes from a human rather than an automated system, preventing spam and abuse. | Article 6(1)(f) GDPR: legitimate interest in protecting the contact form from automated submissions. | Retained by the provider for the periods it defines; the Controller retains only the verification outcome for the duration of the submission. |
| Language preference stored in the browser (technical cookie i18n_redirected). | Remembering the selected language across visits. | Article 122(1) of Italian Legislative Decree 196/2003 (technical cookie, exempt from consent) and Article 6(1)(f) GDPR. | 12 months from the last time it was set. |
For data subjects located in Switzerland the same processing is governed by the FADP: data is processed in connection with the conclusion or performance of a contract with the data subject, or on the basis of the Controller’s overriding interest, pursuant to Articles 6 and 31 FADP.
The website uses no analytics, audience measurement or marketing tools and carries out no profiling. Fonts are served from the website’s own domain: visiting the site generates no requests to Google Fonts or other third-party content delivery networks.
4. Whether providing data is mandatory
Providing the fields marked as required in the contact form (name, email, organisation) is necessary to handle the request: without them no reply can be given. The «message» field is optional. Completing the anti-spam check is necessary in order to submit the form.
Browsing the website requires no voluntary provision of data beyond the technical data inherent to transmitting requests over the network.
5. Recipients
Data is processed by the Controller’s authorised personnel, instructed pursuant to Article 29 GDPR, and may be disclosed to the following parties, acting as processors under Article 28 GDPR or as independent controllers where the law so provides.
| Party | Role and activity | Place of processing |
|---|---|---|
| Infomaniak Network SA | Processor: website hosting on a virtual server and storage of server technical logs. | Switzerland. |
| MailerSend (MailerLite group) | Processor: delivery of the email messages generated by the contact form. | European Union, with possible use of sub-processors in third countries (see section 6). |
| Cloudflare, Inc. and Cloudflare Ireland Ltd | Processor: Turnstile anti-bot verification of the contact form. | European Union and United States (see section 6). |
| Professional service providers (legal, tax and IT advisers) | Processors or independent controllers, within the limits of their respective activities. | European Union. |
| Public authorities and supervisory bodies | Independent controllers, only where disclosure is required by law or needed to assert a right in legal proceedings. | European Union. |
Personal data is not disseminated, nor sold or transferred to third parties for their own marketing purposes.
6. Transfers to third countries
The Controller is based in Switzerland and the website is hosted on a virtual server located in Switzerland, so data collected through the website, including technical logs, is processed there. Switzerland is recognised by the European Commission as providing an adequate level of protection (Decision 2000/518/EC, confirmed by the Commission’s periodic review), and transfers from the European Union therefore require no additional safeguards under Article 45 GDPR. Switzerland in turn recognises the Member States of the European Union as providing adequate protection under Article 16 FADP and Annex 1 to the FADP Ordinance.
Use of Cloudflare Turnstile may involve transferring data (in particular the IP address and technical browser signals) to the United States. Such transfers rely on the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, in the version also recognised by the Swiss Federal Data Protection and Information Commissioner, and, where applicable, on the adequacy decisions concerning the EU-U.S. Data Privacy Framework and its Swiss extension (Swiss-U.S. Data Privacy Framework), supplemented by the provider’s additional technical and organisational measures.
Equivalent safeguards apply to any sub-processors of the email delivery provider located in third countries. A copy of the safeguards in place can be requested at achille.deodato@dl-p.ch.
7. Security measures
The Controller applies technical and organisational measures appropriate under Article 32 GDPR, including: HTTPS transmission of pages and forms, input validation and sanitisation, anti-bot protection of the contact form, least-privilege access to mailboxes and hosting systems, and maintenance of software dependencies.
No security measure makes transmission over the Internet entirely free of risk. Please do not include in the «message» field any data that is not necessary to assess the request, in particular data concerning health, criminal convictions or other special categories.
8. No automated decision-making
The Controller carries out no automated decision-making, including profiling, within the meaning of Article 22(1) and (4) GDPR. The anti-spam check only determines whether the form submission is accepted and produces no legal effects concerning the data subject.
9. Data subject rights
Subject to the conditions set out in the GDPR, you may at any time exercise the following rights:
- access to your personal data and to information about the processing (Article 15);
- rectification of inaccurate data and completion of incomplete data (Article 16);
- erasure of data, where the conditions are met (Article 17);
- restriction of processing (Article 18);
- portability of the data you provided, for processing based on contract or consent and carried out by automated means (Article 20);
- objection to processing based on legitimate interest, including commercial follow-up (Article 21).
Data subjects located in Switzerland have the corresponding rights of access, rectification, erasure and handing over or transfer of data under Articles 25 et seq. FADP.
Requests should be addressed to achille.deodato@dl-p.ch. The Controller replies without undue delay and in any case within one month of receipt; that period may be extended by two further months for particularly complex requests, with notice to the data subject. Exercising these rights is free of charge, except for manifestly unfounded or excessive requests.
10. Complaint to a supervisory authority
If you are located in the European Union and consider the processing of your data unlawful, you may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy; garante@gpdp.it; www.garanteprivacy.it) or with the supervisory authority of your habitual residence or place of work.
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern; www.edoeb.admin.ch). In either case, you may also bring proceedings before the competent court.
11. Minors
The website is aimed at professionals and organisations and is not intended for minors. The Controller does not knowingly collect data relating to minors; should it become aware of such data, it will delete it without undue delay.
13. Changes to this policy
This policy may be updated to reflect legal, technical or organisational changes. The version in force is always published on this page together with its last-updated date. Material changes are communicated to data subjects by appropriate means where required by applicable law.