Legal

Privacy Policy

DTeach is built for European classrooms, and hosted in France. This policy explains what we collect, why, and what you can ask us to do about it. Last updated 5 August 2026.

1. Who is responsible

DTeach is operated by DTeach, France. For questions about this policy or about your data, write to contact@dteach.net.

We are the controller for the data of people who visit our site, sign up on their own, or contact us. When a school, university, or company uses DTeach for its members, that organization is the controller and we act as its processor, under a data processing agreement. Requests from members of an organization are best addressed to that organization first; we forward any we receive.

2. What we collect

  • Account data — name, email address, profile picture, language, and the password hash or the Google account identifier you sign in with.
  • Organization data — the organization you belong to, your role, your groups and classes, and invitations sent or received.
  • Content — courses, documents, whiteboards, uploaded files, questions and answers, personal notes, and their revision history.
  • LMS data — when DTeach is launched from Moodle or another LMS over LTI, we receive the identifiers, name, email, and role your LMS chooses to send, plus the course context, so the right person lands in the right course.
  • Technical data — IP address, browser and device information, and timestamps, in server and application logs.
  • Billing data — the plan, billing contact, and invoice history for paying organizations. Card numbers are handled by our payment provider and never reach our servers.

3. Why we process it, and on what basis

  • To run the service — authentication, real-time collaboration, storage, and delivery of your content. Basis: performance of a contract.
  • To keep it secure and reliable — logging, abuse prevention, backups, incident investigation. Basis: legitimate interest.
  • To send service email — invitations, password resets, and notices about your account. Basis: performance of a contract.
  • To measure usage in aggregate — which pages and features are used, so we know what to improve. Basis: legitimate interest, using cookieless analytics that do not identify you.
  • To bill and to meet accounting obligations. Basis: contract and legal obligation.

We do not sell personal data, we do not run advertising, and we do not use your content to train machine learning models.

4. Cookies and analytics

We set the cookies the product needs: a session cookie to keep you signed in, and a preference cookie remembering your light or dark theme. Neither is used for tracking.

For audience measurement we use Umami, a cookieless analytics tool that records page views without a cookie and without a cross-site identifier. We also use New Relic to monitor errors and performance. Both are configured to keep data within the European Union.

5. Where your data lives

Our application, database, file storage, and backups run on Scaleway infrastructure in the fr-parregion, in France. Your content is not transferred outside the European Union. Where a sub-processor is established outside the EU, we rely on the European Commission's standard contractual clauses.

6. Who else sees it

We share personal data only with the providers we need to run DTeach:

  • Scaleway — hosting, managed database, object storage, backups (France).
  • Google — only if you choose to sign in with a Google account.
  • Our transactional email provider — to deliver invitations and account emails.
  • Our payment provider — to process subscriptions for paying organizations.

Each is bound by a contract limiting them to what we instruct. We may also disclose data where the law requires it. If we are ever involved in a merger or acquisition, we tell you before your data changes hands.

7. How long we keep it

  • Account and content data — for as long as the account or organization is active.
  • After deletion — 30 days to allow recovery from mistakes, then removal from live systems; backups roll off within 90 days.
  • Server logs — 30 days.
  • Invoices and accounting records — 10 years, as French law requires.

8. Your rights

Under the GDPR you can ask for access to your data, its correction or deletion, a portable copy, a restriction of processing, or object to processing based on legitimate interest. Write to contact@dteach.net and we answer within one month.

If our answer does not satisfy you, you can lodge a complaint with your supervisory authority — in France, the CNIL.

9. Security

Traffic is encrypted in transit with TLS, passwords are stored hashed, access to production is restricted and audited, and backups are encrypted. No system is perfect: if a breach affects your data, we notify the supervisory authority and the people concerned as the GDPR requires.

10. Children

DTeach is sold to institutions, not to children directly. Where pupils under 15 use it, the school is the controller and is responsible for the legal basis and for informing families.

11. Changes

We update this policy when the product or the law changes. The date at the top always reflects the current version, and material changes are announced by email or in the product before they take effect.