Data protection information for universities
Last updated: 3 October 2026
This sheet summarizes for International Offices and data protection officers how Permit Radar handles data and what a university sees. The full texts are in the privacy policy and the terms of use.
At a glance
The university receives only anonymous, aggregated numbers. It never sees names, email addresses, work logs, visa data or documents of individual students. Any number below 5 is hidden, and nothing is shown before at least 5 students are linked.
| Provider and controller | Akram El Basri, Huntemannstraße 2, Apt. 02/0209, 26131 Oldenburg, Germany, seasonedwebdev@gmail.com |
| Nature | Free, non-commercial student project. No ads, no selling of data. |
| Purpose | International students keep track of their work limit (for example 140 full / 280 half days), expiry dates and Ausländerbehörde appointments. |
| Not legal advice | Permit Radar is a calculator and reminder tool and provides no legal services (RDG). |
1. What the university sees
The university area shows only totals across all linked students:
- number of students using Permit Radar
- how many have set their work limit
- how many are on track, close to the limit, or over it
- how many residence permits expire within 60 days
- how many Ausländerbehörde appointments are due within 30 days
- new students per month
Protection against identification: any number from 1 to 4 is shown as "fewer than 5". If a hidden number could be worked out from the total and the other numbers, more numbers are hidden until it cannot (complementary suppression). With fewer than 5 linked students, nothing is shown at all.
2. What the university does not see
Names, email addresses, accounts, individual work days or hours, employers, visa types, individual expiry dates, documents, uploaded payslips, IP addresses, activity data. There is no feature to transfer or export these to the university.
3. How students are linked
- Voluntary: only students who sign up with a university email and confirm it, or who confirm a university email in Settings with a one-time code, are linked.
- Proof: confirming the university email ensures only real members of the university are counted.
- Reversible: students can unlink in Settings with one click.
- Not required: Permit Radar works the same without linking.
4. Roles and legal bases
- Permit Radar is the controller for student data (Art. 4(7) GDPR). Legal bases: contract (Art. 6(1)(b)), consent for analytics cookies and university linking (a), legitimate interest for security (f).
- The university receives no personal data of students, only anonymized statistics. In our assessment this creates neither processing on behalf (Art. 28) nor joint controllership (Art. 26). The final assessment rests with the university's data protection officer; we gladly provide any information needed.
- University accounts: for the people using the university dashboard we store name, email address and sign-in security data.
5. Technical and organizational measures
| Area | Measure |
|---|---|
| Location | Database at MongoDB Atlas in Frankfurt (EU). API server in the EU region. |
| Encryption | All connections over HTTPS. Passwords hashed with argon2id. One-time links stored only as hashes. |
| Access | Strict per-account isolation in code. Even the operator cannot view work logs, visa data or documents through any admin screen. |
| Sign-in | Email confirmation, lockout after failed attempts, bot protection (Cloudflare Turnstile). University and admin accounts also need a code sent by email (second factor). |
| Alerts | A sign-in from a new device triggers an immediate email to the account owner. |
| Abuse protection | Request limits per network and account, automatic blocking of suspicious networks, maintenance mode for emergencies. |
| IP addresses | Never stored in plain form, only as a keyed one-way hash. |
| Traceability | Every change to work entries, limits and documents is kept in an append-only log. |
| Payslips | Read in memory only, never stored. Only confirmed dates and hours remain. |
| Data minimization | Inactive accounts are warned after 5 months and deleted 30 days later. Unconfirmed accounts after 7 days. |
| Data subject rights | Full data export and immediate account deletion in Settings. |
| Incidents | Documented procedure for reporting personal data breaches within 72 hours (Art. 33 GDPR). |
6. Processors
MongoDB Atlas (database, Frankfurt), Railway (API server, EU), Vercel (website), Resend (email delivery), Cloudflare (bot protection). Data processing agreements are in place with all of them; transfers outside the EU rely on the EU-US Data Privacy Framework or standard contractual clauses.
7. Contact
For questions, a presentation of the project or further documents:
Akram El Basri · seasonedwebdev@gmail.com · +49 155 10951726