Legal
Privacy notice
This privacy notice transparently explains which personal data is processed on the public website, in customer portals and during platform operation.
1. Responsibilities
Philipp Senn, t-api, 8037 Zurich, Switzerland, info@t-api.app, is responsible for the public website and t-api's own platform operations.
The respective education provider is generally the controller for business data about people, events, attendance and grades in a customer portal. t-api processes technical portal data on its behalf and under an individual agreement.
2. Public website
When the information site is accessed, the hosting infrastructure processes technically necessary request data such as time, resource, status and, where applicable, the IP address. A contact request processes name, email address, optional organisation, topic, language and message.
Cloudflare Turnstile processes technical browser and request signals to detect bots and abuse. The site uses no marketing tracking; language and display remain local browser preferences.
3. Customer portals
The Tocco username, the related email address as the delivery channel, hashed one-time-code records, rate-limit data, session metadata, technical Tocco keys and audit events are processed for sign-in and portal operation.
Business data is read live from Tocco or written back there and is not stored as a second business dataset in the t-api database. Value details in necessary audit evidence are additionally encrypted.
4. Purposes and legal bases
Processing supports provision and security of the service, responses to contact requests, authentication, authorisation checks, contract performance, support, troubleshooting and evidence of authorised write operations.
Bases include contract performance, statutory duties, overriding legitimate interests in secure operations and, where needed, separate consent or a customer-specific legal basis.
5. Recipients and service providers
Recipients are limited to parties required for operations: the relevant education provider and its Tocco instance, Vercel for web delivery and serverless runtime, Neon for PostgreSQL, the configured SMTP service and Cloudflare Turnstile for contact-form abuse prevention.
Contact details are not sent to Tocco or an education provider. Cloudflare does not receive the form message; Siteverify receives only the short-lived CAPTCHA token with technical request details.
6. Data location and international transfers
t-api serverless functions are configured on Vercel in fra1 and the PostgreSQL database on Neon in eu-central-1. Vercel and Neon are US providers; DPAs and Standard Contractual Clauses are in place.
If another service processes personal data outside Switzerland or a country with adequate protection, the destination and safeguards are stated in the applicable contract or register.
7. Retention
Standard periods are: OTP records no more than 24 hours, session records 30 days after invalidation, technical rate counters no more than 24 hours after expiry and monitoring aggregates 90 days. Contact content is not stored in the portal database and is processed only in the email system.
Contact emails follow the operationally and legally required mailbox periods. Security-relevant audit core records are retained for 10 years by default; encrypted business value details are redacted after 24 months.
8. Data subject rights
Within applicable law, data subjects may request access, correction, deletion, restriction or disclosure and may object to processing. Requests about the website or t-api operational data go to info@t-api.app.
For business data or a specific customer portal, contact the relevant education provider first. It coordinates the request with t-api and Tocco. The right to complain to the competent data protection authority remains unaffected.
9. Security
t-api protects data through measures including TLS, host-bound secure cookies, separated customer-portal and operator sessions, server-side authorisation checks, encryption of credentials and audit value details, and data-minimising logs.
No technical system is entirely risk-free. Security reports are accepted at info@t-api.app and handled under the documented incident process.
10. Changes
This notice is updated when data flows, service providers, legal requirements or product functions change materially. The update date shown above identifies the current public version.
Contractually relevant changes are communicated to the named contacts of affected education providers through agreed channels.