EdTechCore

The short version

No account, no newsletter, no contact form, no advertising network and no profiling. Your browser makes a request to the server, which is logged for security. Two optional items of browser storage exist and neither runs unless you switch it on. You can withdraw that agreement at any second from the footer, and withdrawing deletes what was stored.

What leaves your device on this page

You are entitled to know this before you read any further, rather than after. Here is every connection this page can make, in plain terms:

  • Fonts — nothing leaves. All type uses fonts already on your device. No font service is contacted and no request is made.
  • Analytics — nothing leaves. No analytics provider, no advertising network, no tracking pixel, no third-party script of any kind is loaded.
  • Images and code — nothing leaves. Every file this page needs is served from bobrclub.com itself.
  • Video — only if you ask. YouTube is contacted when you allow embedded video and press play, and not one moment sooner. Not even a preview image is fetched before that.
  • Other sites — only if you click. Links to TikTok, YouTube, Instagram and edtechcore.com are ordinary links. Following one hands you over to that service and its rules.
  • The server sees your request. Unavoidable, and true of every website that has ever existed: to send you this page, the host receives your IP address and logs the request. Details in section 3.

If that last point is more than you are comfortable with, close the tab now — no hard feelings. It is the honest answer: I cannot serve you a page without your device asking my host for it. Everything else on this list is either off by default or waits for you to press something.

1. Who is responsible

The controller for the processing described here, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (“GDPR”), is:

This is a personal, non-commercial site run by one individual. Email is the contact channel for everything in this policy, including any request under sections 9 and 10, and it is monitored.

No Data Protection Officer has been appointed, because none of the criteria in Article 37(1) GDPR apply to this site: there is no large-scale regular and systematic monitoring of data subjects and no large-scale processing of special categories of data. Data-protection questions go to the address above and are handled by the controller personally.

2. What this policy covers

This policy applies to bobrclub.com and its subpages. It does not apply to any other site you reach from here. Following an outbound link — to TikTok, YouTube, Instagram or edtechcore.com — takes you into a service with its own controller and its own privacy policy, and you should read theirs before using it. See also section 5.

3. Server log data

The site is delivered by a hosting and content-delivery provider (see section 5). Like every web server, it necessarily receives and records technical data with each request. This happens before any script runs and is not something a consent banner can switch off — it is the mechanism by which a page reaches you at all.

Typically recorded: the requesting IP address, date and time of the request, the page or file requested, the HTTP status returned, the volume of data transferred, the referring URL where the browser sends one, and the browser and operating-system identification string.

Purpose and legal basis. This data is processed to deliver the site, to keep it stable, and to detect and defend against abuse such as denial-of-service attacks and automated scraping. The legal basis is Article 6(1)(f) GDPR. My legitimate interest is operating a functioning and reasonably secure website; given the narrow scope, short retention and lack of any attempt to identify individuals, that interest is not overridden by your interests or fundamental rights. This data is not merged with the browser storage described in section 4 and is not used to build a profile of you.

4. Cookies and browser storage

The site sets no tracking cookies and runs no advertising network. It uses a small amount of localStorage and sessionStorage, which are not cookies in the technical sense but are treated here as equivalent because they store information on your device and are covered by the same rules (Article 5(3) of Directive 2002/58/EC as implemented nationally).

Items stored on your device, their purpose and duration
Item Type Purpose Duration Basis
bobr:consent Local storage Stores the cookie choice you made here, so you are not asked again on every page. Until you clear site data; reviewed after 12 months Strictly necessary — exempt from consent, since it exists solely to honour your choice
bobr:src Session storage Records which channel you arrived from (for example a TikTok bio link) so I can tell which videos are worth making. Holds a short channel label, not an identifier. Deleted when you close the browser tab Consent — Article 6(1)(a) GDPR
YouTube cookies Third-party Set by Google if, and only if, you allow embedded video and then play one. Nothing is set merely by visiting a page. Set and controlled by Google Consent — Article 6(1)(a) GDPR

Giving, refusing and withdrawing consent

On your first visit a banner asks about the two optional categories. Refusing is presented as prominently as accepting, and refusing is the outcome if you do nothing — nothing optional is written or loaded unless you actively agree. There is no cookie wall: the entire site works identically whether you accept or refuse.

You may withdraw consent at any time with effect for the future (Article 7(3) GDPR), and it must be as easy to withdraw as it was to give. Use the button below or the Cookie settings link in the footer of every page. Withdrawing analytics consent deletes the stored value immediately; it does not make prior lawful processing unlawful.

You can also block or delete storage in your browser settings, and use “do not track” or private browsing. Deleting site data removes the record of your choice, so the banner will appear again.

5. Third parties and recipients

I do not sell personal data, and I do not disclose it for anyone else’s marketing. Data reaches the following parties only as described:

Hosting and content delivery

The site is hosted on Cloudflare’s infrastructure (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; for users in the EEA generally Cloudflare Germany GmbH). Cloudflare processes the log data in section 3 on my behalf as a processor under Article 28 GDPR, on the basis of a data processing agreement, and additionally operates security measures against attacks. Legal basis for using it: Article 6(1)(f) GDPR.

Web fonts — none

No web fonts are loaded from anywhere. All type on this site is set in fonts already installed on your own device, so your browser makes no request to any font service and no IP address is transmitted in order to render text. This is a deliberate choice: a hosted font service would otherwise see every visitor of every page, which is a lot of exposure for the sake of a typeface.

Kept here in case that ever changes

If a hosted font service — Google Fonts or any other — is ever added to this site, your browser would fetch the font files from that provider’s servers and transmit your IP address to them on every page load, before you had any chance to object. A German court has already awarded damages over precisely that (Landgericht München I, 20 January 2022, case 3 O 17493/20). Should it ever be introduced here, this policy will be updated, the provider named, and the loading placed behind consent rather than assumed. At the date at the top of this page, it is not in use.

YouTube video

Video is embedded through youtube-nocookie.com in extended data protection mode, and only ever on request. Until you allow embedded video and click play, the page contains no element that contacts Google — not even a preview image. Once you do, Google receives your IP address and may set cookies or read device storage; if you are signed in to a Google account, Google can associate the view with it. Legal basis: your consent under Article 6(1)(a) GDPR, withdrawable at any time. Provider: Google Ireland Limited, address as above.

Outbound links

Links to TikTok, YouTube, Instagram and edtechcore.com are ordinary hyperlinks. Nothing is transmitted to those services until you click, at which point the destination becomes the controller. Where a link to edtechcore.com carries utm_ parameters, those describe which link was clicked; a channel label is added to them only if you consented to analytics.

Disclosure of a material connection: edtechcore.com is my own project, so a link to it is self-promotion rather than an independent recommendation.

6. Legal bases at a glance

  • Article 6(1)(a) — consent: analytics storage, embedded video.
  • Article 6(1)(f) — legitimate interests: delivering the site, server logs, security, storing your consent choice, and consistent typography.
  • Article 6(1)(c) — legal obligation: only where I am required to retain or disclose something by law.

Where processing rests on Article 6(1)(f), I have carried out a balancing exercise in each case and you may ask me to explain the outcome for any of them.

7. Transfers outside the EEA

Cloudflare and Google are US-headquartered. Processing may therefore involve a transfer to, or access from, the United States or other third countries. Such transfers are covered by the European Commission’s adequacy decision of 10 July 2023 for the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise by Standard Contractual Clauses adopted under Article 46(2)(c) GDPR together with supplementary measures.

You should nevertheless be aware that a level of protection equivalent to the GDPR cannot be guaranteed in every respect in a third country, in particular as regards access by public authorities, and that enforcing your rights there may be harder than within the EEA. A copy of the safeguards relied on is available on request.

8. How long data is kept

  • Server logs: kept only as long as needed for security and diagnostics, and deleted or anonymised thereafter in line with the provider’s standard retention period.
  • bobr:src: deleted automatically when you close the tab, and immediately if you withdraw analytics consent.
  • bobr:consent: kept on your device until you clear site data; the choice is re-requested if the categories change materially.
  • Email correspondence: kept as long as needed to deal with your enquiry and any follow-up, then deleted, subject to any statutory retention period.

9. Your rights

Where I process your personal data, you have the following rights:

  • Access (Article 15) — confirmation of whether I process data about you, a copy of it, and the information in this policy.
  • Rectification (Article 16) — correction of inaccurate data and completion of incomplete data.
  • Erasure (Article 17) — deletion where one of the listed grounds applies.
  • Restriction (Article 18) — processing limited to storage while, for example, a dispute over accuracy is resolved.
  • Portability (Article 20) — data you provided, in a structured, commonly used, machine-readable format, where processing rests on consent or contract and is automated.
  • Objection (Article 21) — see section 10.
  • Withdrawal of consent (Article 7(3)) — at any time, without affecting the lawfulness of processing before withdrawal.
  • Complaint (Article 77) — to a supervisory authority, without prejudice to any other remedy. You may lodge it with the authority in the EU or EEA Member State of your habitual residence, your place of work, or the place of the alleged infringement, whichever suits you; you do not need to use one of my choosing.

Exercise any of these by writing to admin@edtechcore.com. I answer without undue delay and in any event within one month of receipt, extendable by two further months where the request is complex, in which case I will tell you within the first month. Exercising your rights is free of charge; a reasonable fee may be charged, or the request refused, only where it is manifestly unfounded or excessive, in particular because it is repetitive (Article 12(5) GDPR).

I may need to ask for information to satisfy myself of your identity before acting (Article 12(6) GDPR). That is a safeguard for you, not an obstacle: it stops someone else obtaining your data by pretending to be you. Note that because this site holds no account and no identifier, I am usually unable to link log data to a named person, and Article 11(2) GDPR then applies — if you can supply information enabling identification, please include it.

10. Your right to object

Where processing is based on Article 6(1)(f) GDPR — legitimate interests — you have the right to object at any time, on grounds relating to your particular situation, to that processing. If you object, I will stop processing the data concerned unless I can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

This site does not process personal data for direct marketing purposes. If that ever changes, you would have an unconditional right to object under Article 21(2) GDPR, after which the data could no longer be used for that purpose.

An objection is informal and free. Send it to admin@edtechcore.com.

11. Nothing you are obliged to provide

You are under no statutory or contractual obligation to provide any personal data here. There is no form to fill in and no account to create. The only unavoidable processing is the technical data in section 3, which arises from the act of requesting a page. Declining the optional categories has no consequence: no feature is withheld and no content is hidden.

12. No automated decision-making

No automated decision-making producing legal effects concerning you or similarly significantly affecting you takes place, within the meaning of Article 22(1) and (4) GDPR. No profiling and no scoring is carried out. The analytics described above counts channels, not people.

13. Children

This site is aimed at a general adult audience and is not directed at children. No data is knowingly collected from children, and none of the processing described here relies on consent given by a child within the meaning of Article 8 GDPR. If you believe a child has provided personal data, contact me and I will delete it.

14. Security

The site is served exclusively over TLS (HTTPS); you can check this by the padlock in the address bar. Appropriate technical and organisational measures under Article 32 GDPR are in place, proportionate to a static site holding no account data. No transmission over the internet can be guaranteed absolutely secure, and no such guarantee is given here.

15. Changes to this policy

This policy is updated when the site or the law changes; the current version always applies to your present visit. The version number and date at the top tell you which one you are reading. If a change materially widens the optional categories, your stored choice is invalidated and you will be asked again rather than silently carried over.

16. Contact

For anything in this policy, including requests under sections 9 and 10, write to admin@edtechcore.com. Please say what you are asking for, so I can deal with it inside the time limit above.

See also the Legal Notice & Disclaimer for the terms on which this site is provided, third-party trademarks, and liability.