Your information
Privacy Policy
This policy explains how RulesLab handles personal data when you browse the site, practise as a guest, create an account, or sign in through Officials.Zone.
Effective:
Who is responsible for your data?
Quietly Capable ApS is the data controller for RulesLab.
Quietly Capable ApSCVR no. 46783158
Amager Landevej 150D
2770 Kastrup
Denmark
Email: admin@officials.zone
What data we process
When you use an account
- Your email address and a securely hashed password if you create a RulesLab login.
- A stable Officials.Zone account identifier if you choose to sign in with or connect Officials.Zone. RulesLab does not receive your Officials.Zone password, email address, or permissions through this connection.
- Your RulesLab account ID, role, account status, chosen time zone, sign-in security records, and account-deletion status.
- Your practice sessions, questions shown, submitted answers or self-ratings, skips, scores, progress, achievements, and learning history.
- Question reports you submit and any outcome shown to you.
- For content editors and administrators, content changes, imports, moderation decisions, and administrative actions recorded in the audit history.
When you use RulesLab as a guest
We store a random guest identifier in your session, the practice settings and questions presented to you, and your answers, reveals, or skips. Guest activity contributes to anonymous question-level training statistics, including which incorrect options are selected.
Technical and security data
We process session identifiers and a protected representation of your network address for authentication, request limits, fraud prevention, and service security. The web server may also record ordinary access information such as time, requested page, network address, browser information, and response status in protected operational logs.
Verification and password-reset requests include your email address and a short-lived, one-use token. Email delivery necessarily discloses the recipient address and message-routing information to the mail service involved in delivery.
Why we process data
| Purpose | Legal basis |
|---|---|
| Provide accounts, saved practice, progress, achievements, reports, and requested account functions. | Performance of our service agreement with you (GDPR Article 6(1)(b)). |
| Provide guest practice and maintain anonymous question-level statistics that improve training content. | Our legitimate interests in providing and improving RulesLab (Article 6(1)(f)). |
| Secure the service, enforce request limits, prevent misuse, diagnose faults, and preserve an accountable content and administration history. | Our legitimate interests in operating a secure and reliable service (Article 6(1)(f)). |
| Respond to privacy requests and comply with binding legal requirements. | Compliance with legal obligations (Article 6(1)(c)). |
You do not have to create an account to use public practice lists. If you want saved progress, we need the account and practice data described above. Without it, we cannot provide persistent account features.
Personalised practice and automated processing
If you enable previous performance, RulesLab uses your earlier answers to choose questions that may be most useful to practise. It also uses overall anonymous answer patterns to select plausible incorrect options. RulesLab awards achievements automatically when their published conditions are met.
These features support learning only. They do not produce legal or similarly significant effects, rank users publicly, or make employment, examination, or eligibility decisions.
Who receives data
Personal data is available only where needed to operate RulesLab. It may be processed by:
- hosting, database, security, and email-delivery providers acting for Quietly Capable ApS;
- authorised RulesLab administrators and service operators;
- Officials.Zone when you deliberately start its sign-in or account-connection flow; and
- public authorities or other recipients when disclosure is legally required.
Super Users and Administrators can view aggregate question-level performance to plan training, but RulesLab does not provide them with named learner-result rosters. Question reports identify the reporter to authorised reviewers until account deletion pseudonymises that reference.
We do not sell personal data and do not use third-party advertising or behavioural-analytics services. If a service provider processes personal data outside the European Economic Area, we use a lawful transfer mechanism where required, such as an adequacy decision or the European Commission’s standard contractual clauses. You may contact us for information about applicable safeguards.
Cookies and local storage
RulesLab uses a first-party session cookie that is necessary for sign-in, security, guest sessions, preferences, and keeping a practice session consistent. It is host-only, unavailable to browser scripts, and normally expires when the browser session ends. The selected light, dark, or automatic colour theme may be saved in your browser.
We do not use optional advertising or third-party analytics cookies. Because current browser storage is used only for requested functions and security, RulesLab does not show a cookie-consent banner.
How long we keep data
- Active accounts and personal learning history: until the account is deleted.
- Account deletion: you have 14 days to cancel a request. After that, login identities and personal progress are removed. Anonymous training counts remain, and audit or report references needed for integrity are pseudonymised.
- Completed guest attempts: 90 days.
- Inactive or abandoned guest attempts: 30 days.
- Anonymous aggregate response facts: retained without a set end date because they do not contain account, email, or guest identifiers.
- Resolved or dismissed question reports: 3 years after resolution.
- Content revisions and audit history: 7 years.
- CSV import source details and unreferenced uploads: 30 days; remaining import records and errors are kept for 2 years.
- Expired verification and password-reset tokens: removed by scheduled cleanup.
- Expired rate-limit and related network-security records: up to 30 days after expiry.
We may retain limited information longer where required to establish, exercise, or defend legal claims or comply with law.
Your rights
Depending on the circumstances, you may ask us to:
- give you access to your personal data;
- correct inaccurate or incomplete data;
- delete data;
- restrict how data is used;
- provide data you supplied in a portable format; or
- stop processing based on our legitimate interests.
These rights are not absolute. We may need to verify your identity and may retain information where the law permits or requires it. You can request deletion from My account. For other requests, email admin@officials.zone or write to the address above.
You may lodge a complaint with the Danish Data Protection Agency (Datatilsynet). We would appreciate the opportunity to address your concern first.
Security and changes to this policy
We use access controls, isolated application data, encrypted transport, password hashing, short-lived tokens, request limits, and audit records to protect RulesLab. No system can guarantee absolute security.
We may update this policy when RulesLab or its data handling changes. The effective date at the top will show the latest version. Material changes will be communicated in an appropriate way within the service.