Legal
Privacy statement
We believe privacy should be simple and transparent.
TechExplained processes as little personal data as possible and only uses it for the purpose you provide it for. This statement sets out, per processing activity, which data that is, why we need it, which legal basis under the GDPR it rests on and how long we keep it.
Minimal data
Only the information required to provide the service.
Secure by design
Encryption and secure storage protect your data.
Automatic retention
Data is removed once it is no longer needed.
Your rights
Access, export and delete your data, whenever you want.
Privacy at a glance
The key figures from this statement, in one view.
- Processing activities
- 8
- Cookies in use
- 2
- Advertising cookies
- 0
- Tracking cookies
- 0
- Processors
- 3
- Last updated
- 4 August 2026
Who is responsible
TechExplained is the controller for the data processed through this site. Questions about privacy or about this statement can be sent to info@techexplained.nl.
Which data we process, and why
For each processing activity you can see below what we record, for which purpose, on which legal basis under article 6 of the GDPR and how long we keep it.
Community Hub formAnswering your question or use case.Legitimate interestMax. 24 months
- Data
- Name, company name (optional), email address, topic and your message.
- Purpose
- Answering your question or submission. If you share a use case or topic suggestion, we may use the content as inspiration for an article, podcast or Architecture Discussion. We never publish your name, company name or contact details without your explicit consent.
- Legal basis
- Legitimate interest (art. 6(1)(f)): you got in touch yourself and expect a reply.
- Retention
- Your message arrives as an email and is not stored in a database. We keep it while the question is open and for at most 24 months after that, so we have context if you contact us again.
Newsletter and waitlistKeeping you posted or holding your waitlist spot.ConsentUntil you unsubscribe
- Data
- Your email address and which form you used.
- Purpose
- Keeping you posted, or holding your place on a waitlist.
- Legal basis
- Consent (art. 6(1)(a)): you sign up yourself.
- Retention
- Until you unsubscribe. One email is enough; after that we no longer need your address for anything.
Assessment report by emailSending the report you asked for.Consent12 months
- Data
- Your email address, optionally your name, and your scores per dimension from the Architecture Lab.
- Purpose
- Sending the report you asked for. We receive a copy so we can follow up if there is reason to. We do not use this for unsolicited marketing.
- Legal basis
- Consent (art. 6(1)(a)). The server checks that consent and refuses the request if you have not given it.
- Retention
- 12 months, after which we delete the copy.
Account and profileSigning you in and showing your profile.ContractAs long as account exists
- Data
- Email address, and if you fill them in: name, job title, company, country, short bio, interests and a profile picture.
- Purpose
- Signing you in and showing your profile. You sign in with your email address using a one-time code, so we store no password.
- Legal basis
- Performance of the contract (art. 6(1)(b)): without this data there is no account.
- Retention
- As long as your account exists. You delete it yourself on your account page; profile, preferences, progress, saved items and profile picture go with it in the same action.
Progress, library and achievementsFilling My Library and My Learning Journey.ContractAs long as account exists
- Data
- What you saved to My Library, which content you read or listened to, and which Architecture Lab exercises you completed, including your score and its spread across the eight architecture dimensions. Per item we record the type, the title, the link and the moment.
- Purpose
- Filling My Library and calculating My Learning Journey: your counters, your timeline, your progress per domain and your skill matrix. Your achievements are derived from those same rows at the moment you open the page; they are not stored separately. Certificates are not issued yet, so we store nothing for those.
- Legal basis
- Performance of the contract (art. 6(1)(b)).
- Retention
- As long as your account exists. In the database you can only read and write your own rows.
Email notificationsOnly sending what you opted into.ConsentAs long as account exists
- Data
- Your choice per category and your email address.
- Purpose
- Sending only the emails you opted into, and only when there is genuinely something new.
- Legal basis
- Consent per category (art. 6(1)(a)).
- Retention
- As long as your account exists. You can switch any category off again at any time.
Visitor statisticsSeeing what gets read and where it's slow.Legitimate interestAggregated, not traceable
- Data
- Page views, the referring page, rough device type and load times. No cookie, no profile and no recognition across sites.
- Purpose
- Seeing which topics get read and where the site is slow.
- Legal basis
- Legitimate interest (art. 6(1)(f)): the measurement stores nothing on your device and produces figures we cannot trace back to you.
- Retention
- Aggregated at Vercel. The figures cannot be traced back to a person.
Technical logs and abuse preventionKeeping the site running and forms protected.Legitimate interest60 seconds, not stored
- Data
- IP address, timestamp and the page requested.
- Purpose
- Keeping the site running and protecting the forms against automated submissions. Per IP address we accept a limited number of submissions per minute.
- Legal basis
- Legitimate interest (art. 6(1)(f)): security and availability.
- Retention
- The IP address used for that limit sits in memory for 60 seconds and is not stored. Hosting logs are kept briefly by Vercel as part of the service.
Once a period has passed we delete the data or make it untraceable. If you ask for deletion earlier, we handle that request as described below.
How your data moves through the system
A simplified view of what happens between a visit to the site and the moment data disappears again.
Local storage
Podcast Knowledge Checks work without an account: your result then stays only in your own browser storage and disappears once you clear it. The rest of the Architecture Lab, meaning challenges, simulations, assessments and builds, requires you to be signed in. Your completed exercises then go into the database, so My Learning Journey shows the same thing on every device.
Who else processes the data
We rely on these parties. They process data solely on our behalf and for the purposes stated above.
Vercel
- Role
- Hosting, running the server code and the visitor statistics.
- Data
- Technical request data and IP address, and the contents of a form at the moment it is submitted.
- Region
- Requests arrive at a node in Frankfurt. The server code currently runs in the United States, Washington region.
Supabase
- Role
- Authentication, the database behind your account and storage of your profile picture.
- Data
- Email address, profile, notification preferences, progress, saved items and profile picture.
- Region
- Ireland, inside the European Union.
Resend
- Role
- Email delivery: your message from the form, your assessment report and the notifications you opted into.
- Data
- Name, email address and the contents of the message or report.
- Region
- United States.
Transfers outside the European Union
Your account and your profile sit inside the European Union. Running the server code and delivering email currently go through the United States. Data you enter in a form is therefore briefly processed there before the email goes out. For that transfer we rely on the European Commission's standard contractual clauses from the data processing agreement with the party concerned.
Our privacy principles
The principles behind this statement, summarised.
- We process as little personal data as possible
- We never sell personal data
- We avoid tracking technology
- We actively limit retention periods
- We design privacy in from the start, not after the fact
- We are transparent about what we do and why
What we do not do
- We do not sell personal data and do not share it with third parties for their own purposes.
- We show no ads.
- We use no advertising tracking, no fingerprinting and no cross-site profiles.
- We make no automated decisions with legal or similarly significant effects (art. 22). A score from the Architecture Lab is feedback on an exercise, not a judgement about you.
Your rights
The GDPR gives you a number of rights. They all apply, whether or not you have an account.
Access (art. 15).
You may ask which data we process about you and receive a copy of it.
Rectification (art. 16).
If something is wrong, we correct it. You can change your profile details yourself on your account page.
Erasure (art. 17).
You may ask us to delete your data. You can delete your account yourself, immediately and completely, on your account page.
Restriction (art. 18).
If there is a dispute about accuracy or legal basis, you can ask us to pause the processing in the meantime.
Portability (art. 20).
For the data you provided yourself, you can get a copy in a commonly used file format.
Objection (art. 21).
You can object to processing based on legitimate interest, such as the statistics.
Withdrawing consent (art. 7(3)).
Where we asked for consent, you may withdraw it at any time. What happened before that stays lawful.
To make a request, email info@techexplained.nl. We respond within one month. If a request is complex we may extend that by two months, and we will tell you within the first month. We may ask for additional details if we cannot establish that it is really you.
How we protect the data
All traffic runs over TLS and is enforced with HSTS, backed by security headers that constrain what the browser is allowed to load. Signing in works without a password: you receive a one-time code by email, so there is no password to leak either. The database uses row level security: every row belongs to a user and you can only read and write your own. If you do find a vulnerability, report it to info@techexplained.nl.
- TLS and HSTS enforced on all traffic
- Security headers that constrain what the browser can load
- Passwordless sign-in with a one-time code
- Row level security: only your own rows are visible
- Responsible disclosure for vulnerabilities
- No advertising tracking or fingerprinting
External links and embedded content
Some pages carry an embedded Spotify player. It loads content from Spotify, and Spotify may process data itself in doing so; their terms apply to that. Links to LinkedIn, TikTok and Instagram are plain links: nothing is loaded from those parties until you click through yourself.
Changes
If what we process changes, we update this statement and the date at the top.
Contact
Questions about this statement or about your data? Email
info@techexplained.nl