Data Privacy

The English version of the Privacy Policy is for informational purposes only. Only the German version is legally binding.

Privacy Policy

for the use of the website “openbadges.education”.

1. Subject matter of the privacy policy

We appreciate your interest in our website “openbadges.education” (hereinafter referred to as “website”). The protection of your personal data (“data”) is a matter of particular importance to us. Below, we would like to inform you about what data is collected when you use the website and how we use it within the framework of the Open Educational Badges project. In the privacy policy, you will learn what personal data we collect about you, how we use it, and what rights you have. Personal data is any information that can be used to identify you, such as your name, address, date of birth, email address, or a picture of you.

Updates and changes are available on this website, so check back regularly to see what has changed. We last updated our privacy policy in August 2025.

2. Responsible body and data protection officer

The following bodies are jointly responsible for processing in accordance with Art. 26 GDPR:

mycelia gGmbH
Prinzenstr. 85C
10969 Berlin
post@mycelia.education

For fulfilling data subject requests and providing data protection information mycelia gGmbH can be contacted at datenschutz@mycelia.education.

3. About the website

Open Educational Badges is an internet-based platform for adults and young people. The platform offers a service for mapping skill acquisition through the awarding of digital badges. We offer a tool for creating, awarding, and collecting digital certificates (badges). This helps learners to keep track of the skills they have acquired, share them with others, and gives them opportunities to find further learning opportunities. Open Educational Badges also offers organizations that design learning opportunities the opportunity to create and award digital certificates (badges) to learners.

4. What we use the data for

The website enables users to find out about Open Educational Badges and to obtain, collect, share with others, and award digital badges in the role of an institution. The purpose of data processing is to properly present and offer our website and services. Specifically, your data will be processed as follows.

4.1 Purely informational use of the website

IIf you visit our website for purely informational purposes, it is generally not necessary for you to provide us with any data. In this case, we only collect and use the data that your internet browser automatically transmits to us, such as:

· Date and time of access to one of our web pages,

· Type and settings of the Internet browser you are using,

· The operating system used,

· The last website you visited (referrer URL),

· Your IP address.

We collect and use this data when you visit our website for purely informational purposes and for the purpose of enabling you to use the web pages you have accessed, improving our website, and for statistical purposes. We only store the IP address for the duration of the session. No personal evaluation takes place. The legality of this processing is based on Art. 6 (1) (f) GDPR (legitimate interest). Our legitimate interest is to ensure the functionality and security of the website.

4.2 Registration, login, and badge issuance

To use additional features of Open Educational Badges, users must register on the platform. When registering, users must provide their first and last name and an email address.

Once users have registered, they can voluntarily provide further information, e.g., as representatives of an organization, they can create an institution for the creation and awarding of badges, or as learners, they can store and collect their badges in a digital backpack. In all cases, users log in using their email address and the password they have chosen. Personal data does not necessarily have to be provided for these processes for institutions. At most, the provision of a contact email address may constitute personal data if the personal (work) email address of an employee is provided. Furthermore, members with the appropriate rights can add additional users to the institution and assign them various permissions.

The lawfulness of this processing is based on Art. 6 (1) (b) and (f) GDPR (user relationship and legitimate interest). We process this data in order to provide users with a platform after they have registered. When participating in an activity, the institution awards learners a badge and requires their first and last names and email address for direct awarding.

In other situations, badges are awarded using QR codes. Here, institutions provide learners with a specially generated QR code after an activity, which can be scanned using the camera function of the device used. Learners are then asked to enter their first and last names and email address on our website so that we can provide them with the badge. QR codes are generally used when an institution does not know the names and email addresses of the participants in advance of an event or activity.

We store and process user data using the CRM tool provided by Attio Ltd., Exmouth House Unit 120, 3-11 Pine Street, London EC1R 0JH, United Kingdom (hereinafter referred to as “Attio”). We process the first name, last name, institutional affiliation, and badge status of individual users. We have concluded a data processing agreement with Attio in accordance with Art. 28 (3) GDPR. Through this agreement, Attio assures that it will process the data in accordance with the General Data Protection Regulation and guarantee the protection of the rights of the persons concerned. Data transfers to Attio’s servers in the United Kingdom are legitimized by the adequacy decision of the EU Commission (Art. 45 GDPR).

For the creation, issuance, and management of badges, we are joint controllers with the relevant institution in accordance with Art. 26 GDPR and have concluded a corresponding agreement. The respective institution is responsible for the collection of data; the further processing steps (creation, provision, storage, modification, and deletion) are carried out under our responsibility. The rights of data subjects can be asserted both against us and against the respective institution.

Open Educational Badges generally sends learners their badges by email. The email also contains an invitation to register at www.openbadges.education in order to use additional features of the platform. However, registration on the platform is not mandatory in order to receive badges. Open Educational Badges has a legitimate interest in ensuring that users have profiles that are as meaningful as possible in order to facilitate learning content or meaningful analyses of their own competence profiles.

We store personal data for the duration of the user relationship. Further storage only takes place on the basis of a legal obligation or if we have an overriding legitimate interest.

4.3 Newsletter

We would like to keep you informed about the latest updates and information relating to Open Educational Badges. You can subscribe to our newsletter for this purpose. The double opt-in procedure is used to send the newsletter, which means that you will only receive a newsletter by email once you have expressly confirmed that you wish to activate the newsletter service. After you have subscribed to the newsletter on the website, you will receive a notification email with an activation link. You will only receive the newsletter after clicking on this link.

You can deactivate the newsletter at any time. To do so, either send an email to hallo@openbadges.education or use the unsubscribe link provided in each newsletter. Your data

processed in this context and exclusively for the purpose of sending the newsletter will be deleted immediately after you unsubscribe.

The permissibility of this processing is based on Art. 6 (1) (a) GDPR (consent). The provision of your data is voluntary, but necessary for receiving the newsletter. The consent given can be revoked at any time with effect for the future.

We send our newsletter using the newsletter service “Brevo” provided by Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin (hereinafter “Sendinblue”). Sendinblue uses the personal data to send the newsletter on our behalf. We have concluded a data processing agreement with Sendinblue in accordance with Art. 28 (3) GDPR. Through this agreement, Sendinblue assures that it will process the data in accordance with the General Data Protection Regulation and guarantee the protection of the rights of the persons concerned.

4.4 Collection of usage statistics (Umami)

This website uses the privacy-friendly open source system Umami from Umami Software Inc., 1362 42nd Avenue, San Francisco, CA 94122, USA (hereinafter “Umami”) for basic analysis to understand how this website is used.

This website only collects basic information provided by the browser or device you use to access our website. This includes, for example, the number of page views, server host name, browser language, referring website (referrer URL), screen dimensions, page title, page URL, and website ID. None of the information collected allows us to identify you personally or the device you are using to access this website. Umami also does not use cookies and does not track the browsing behavior of individuals across multiple websites.

The lawfulness of this processing is based on Art. 6 (1) (f) GDPR (legitimate interest). We process this data to analyze how our website is used. This information helps us to continuously improve our website and make it more user-friendly and secure.

Umami respects your browser’s ‘Do Not Track’ settings. If this feature is enabled in your browser, your visit will not be tracked.

Further information can be found in the documentation for the Umami analysis tool at https://umami.is/docs and in their privacy policy at https://umami.is/privacy.

4.5 Use of the AI Badge Assistant

When creating a badge, we offer institutions an AI Badge Assistant that helps them find suitable skills based on the course description. This serves to improve our offering and provide specialized functions that cannot be implemented internally. Institutions themselves determine which data is processed when describing the content of the course. In principle, it is not necessary to include personal data in a course description. When using the AI Badge Assistant, a small amount of personal data is collected (logs, etc.). The processing of personal data is based on your consent, which can be revoked at any time with future effect, in accordance with Art. 6 (1) (a) GDPR, by using the AI Badge Assistant in the role of the institutions. There is no obligation to provide your data. Alternatively or in addition, you can add skills manually. We provide the AI Badge Assistant with the help of Disruptive Elements GmbH, Südwestkorso 62, 12161 Berlin (hereinafter referred to as “Disruptive Elements”). Disruptive Elements uses the personal data to provide the AI Badge Assistant on our behalf. We have concluded a data processing agreement with Disruptive Elements in accordance with Art. 28 (3) GDPR. Through this agreement, Disruptive Elements assures that it will process the data in accordance with the

General Data Protection Regulation and guarantee the protection of the rights of the persons concerned. Personal data will be deleted at regular intervals and at the latest when the purpose no longer applies.

4.6 Collection of data for the issuance of badges by OEB and for sending invitations

If we meet you at an event or on a medium outside this platform/website and obtain your contact details (e.g., your email address) on this occasion, we will store and manage these using a tool. The processing is carried out either for the purpose of issuing a badge and contacting you for this purpose. The legal basis for the processing is Art. 6 (1) (b) GDPR. The processing is necessary to establish and implement the user relationship with you with regard to the badge. Without providing your email address, the badge cannot be provided to you. We may also issue badges via QR codes. The information provided in section 4.2 applies accordingly to the data processing procedure.

In other cases, we process your data to invite you to participate in surveys, request your feedback, or inform you about upcoming events and invite you to attend. The legal basis for this is your consent, which you can revoke at any time, in accordance with Art. 6 (1) (a) GDPR. You can give such consent, for example, during the registration process on our platform (see 4.2 above).

5. Duration of data processing

We store user data for as long as users are members of the platform. We then delete the data unless we are required to retain it or are obliged to store it for a longer period in accordance with Article 6(1)(c) GDPR due to tax and commercial law retention and documentation obligations (under the German Commercial Code or Fiscal Code).

The duration of a badge’s validity is determined by the issuing organization, which specifies an expiration date. Even after the expiration date, learners can still view their badges (however, these are marked as “Expired”).

6. Recipients of data and transfer to third countries

The data collected when you visit and use the website and the information you provide individually will be transmitted to our servers (which may be hosted by third parties) and stored there. In addition, your data may be passed on to persons at the responsible bodies who are involved in processing. Other potential recipients are processors or contractual partners. The transfer to these recipients is either based on a legal obligation to which we are subject (Art. 6 (1) (c) GDPR) or within the scope of order processing. Parts of the data collected via the platform are stored and hosted at our external data center, Hetzner Online GmbH.

In particular, data will be passed on to other controllers or third parties to the extent permitted by law and necessary for the performance of contractual relationships with users of the platform in accordance with Art. 6 (1) (b) GDPR. Data is exchanged during the creation and awarding of badges, e.g., between us and the organizations/institutions (see above).

Beyond that, we only share your data with third parties if users have given their consent in accordance with Art. 6 (1) (a) GDPR or if the transfer is necessary in accordance with Art. 6 (1) (f) GDPR for the assertion, exercise, or defense of legal claims and there is no reason to assume that there is an overriding interest worthy of protection in not disclosing the data.

We do not transfer data to third countries, except in the cases expressly described.

7. Third-party content

7.1 OpenStreetMap

We use OpenStreetMap on this website to integrate map material. This service is provided by the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom (hereinafter “OpenStreetMap”). This is a collaborative open source project that aims to create and provide freely usable geographic data, such as road maps.

When using the maps, a connection is established to the OpenStreetMap servers and the IP address is transmitted. No cookies are used to track website visitors, but only those that are limited to the functionality of the website.

The legal basis for processing is Art. 6 (1) (f) GDPR and § 25 (2) No. 2 TDDDG. We have a legitimate interest in displaying locations or providing geographical information in order to improve the functionality, user-friendliness, and range of services offered by the website.

Data transfers to OpenStreetMap servers in the United Kingdom are legitimized by the adequacy decision of the EU Commission (Art. 45 GDPR).

Further information on data processing within the framework of OpenStreetMap can be found at https://wiki.osmfoundation.org/wiki/Privacy_Policy .

7.2 Altcha

To protect our forms and registration screens from spam and unwanted behavior, we use the open-source captcha service “Altcha” (hereinafter “Altcha”). Altcha is provided by BAU Software s.r.o., Lidicka 700/19, Brno 602 00, Czech Republic. We use the option of integrating the Captcha service locally on our website. Altcha uses a proof-of-work mechanism and does not require the use of cookies or fingerprinting technologies. Altcha processes browser and device information, IP addresses, and approximate geographic location.

The legal basis for processing is Art. 6 (1) (f) GDPR and § 25 (2) No. 2 TDDDG. We have a legitimate interest in protecting our website from spam and unwanted behavior and in preventing and filtering out such activities.

Further information can be found at https://altcha.org/privacy-policy/.

7.3 Tally

We use the service Tally to provide our forms (e.g., for newsletter registration or webinars). The provider is Tally BV, August Van Lokerenstraat 71, 9050 Ghent, Belgium.

Tally processes technical metadata to ensure the technical provision of the service and to prevent misuse. The processed data includes, in particular, the information you provide in the form (e.g., name, email address, survey responses) as well as technical metadata (e.g., IP address, time of submission). Tally processes this data on our behalf to enable us to evaluate the form entries. By default, Tally stores data on servers within the European Union.

Further information can be found at https://tally.so/help/terms-and-privacy

8. Your data protection rights

You have the following rights:

· pursuant to Art. 7 (3) GDPR, to revoke your consent at any time. As a result, we will no longer be permitted to continue processing data based on this consent in the future;

· pursuant to Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can obtain information about the purposes of processing, the category of personal data, the categories of recipients to whom your personal data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing, or objection, the existence of a right to lodge a complaint, the origin of your personal data if it was not collected by us, and the existence of automated decision-making, including profiling and, where applicable, meaningful information about its details;

· pursuant to Art. 16 GDPR, to request the immediate correction of inaccurate or incomplete personal data stored by us.

· pursuant to Art. 17 GDPR, to request the erasure of your personal data stored by us, unless processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims;

· pursuant to Art. 18 GDPR, to request the restriction of the processing of your personal data if you dispute the accuracy of the personal data, the processing is unlawful, but you refuse to have it deleted and we no longer need the personal data, but you need it to assert, exercise, or defend legal claims, or you have objected to the processing pursuant to Art. 21 GDPR;

· pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format or to request its transfer to another controller; and

· in accordance with Art. 77 GDPR, to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose.

If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) (f) GDPR, you have the right to object to the processing of your personal data pursuant to Art. 21 GDPR, provided that there are reasons for this arising from your particular situation or the objection is directed against direct marketing. In the latter case, you have a general right to object, which we will implement without you having to specify a particular situation. If you wish to exercise your right to object, simply send an email to datenschutz@mycelia.education.