Privacy Policy
CINE DECIDE? — a Lappsus tool · Last updated: July 2026
This policy explains what data cinedecide.lappsus.com collects during a session, why, and how you can control it. It's written in plain language on purpose — if anything is unclear, email lapp.tudor@gmail.com and I'll clarify or fix it.
It depends on how you're taking part:
If you're a participant and unsure which applies, ask your facilitator first — they'll know which session and organisation you're part of. Lappsus can help if you can't reach them.
CINE DECIDE is built to need as little as possible. Teams are identified only by a session code (like "E1"–"E5") chosen by the facilitator — never by name.
Stored per session (shared per team, not per person):
Stored only on the participant's own device, never sent anywhere: language preference, which hat a participant personally noted for themselves, and their private notes in the verification sandbox tools.
Not collected, ever: names, emails, accounts, passwords, device identifiers, location, cookies, or any advertising/analytics tracker.
One honest caveat: the written comment and reflection fields are free text. If a participant chooses to type something personally identifying there, that text is stored as part of the session record like anything else typed into it. Facilitators are asked to remind participants not to include personal information in those fields.
| Service | Purpose | Provider's policy |
|---|---|---|
| Google Cloud — Firebase Firestore (EU region) | Stores session data described above, synced live between the facilitator, the room screen, and participants' phones | Google Cloud DPA |
No other subprocessor is used. The site itself is hosted separately (Hostinger) and doesn't add its own data collection beyond standard web server logs.
Facilitators can delete a session's data at any time from the admin panel — typically done within 30 days of the session, once any export the organisation wants has been taken. As a backstop, Lappsus deletes any session still sitting in the system after 12 months, whether or not it was manually removed first.
Session data is processed on the basis of the hosting organisation's legitimate interest in running the educational activity (GDPR Art. 6(1)(f)) and, for paid engagements, performance of the contract between Lappsus and that organisation (Art. 6(1)(b)).
Participants are typically 14–18. Because the age at which a minor can consent to a service like this on their own varies by country (from 13 up to 16 under GDPR Art. 8), CINE DECIDE doesn't rely on a participant's own click-through consent as its legal basis anywhere — it assumes the most protective standard applies by default. Instead, it relies on the hosting organisation having already secured appropriate guardian/parental consent or authorisation as part of enrolling the participant in the wider programme (camp, class, or NGO activity). If you're an organiser, make sure your own enrolment paperwork mentions this tool — ask Lappsus for a short paragraph of suggested wording.
You can, at any time, ask to know what data is held, ask for it to be corrected or deleted, or object to processing. Because sessions identify teams rather than individuals, Lappsus generally can't isolate one participant's data within a shared team record — the fastest route is asking your facilitator to delete the session (they can do this directly). You can also email lapp.tudor@gmail.com, mentioning the session name/date and organisation, and it'll be routed correctly whether Lappsus is the controller or needs to pass the request to the organisation that is.
Note: this policy is written to be accurate and clear, not as a substitute for legal advice. If you're relying on this for formal compliance purposes, have it reviewed by counsel familiar with GDPR and the data protection law of the country where it's used.