Transparency
Compliance dossier
The privacy notice says what we do with personal data. This document sets out how the site is actually built, so that those statements can be checked rather than merely believed.
Last updated 2026-09-19.
1. Who is responsible
The controller is the Ecole Internationale de Genève. This site is run by the Mathematics Department at Campus des Nations. The department's operational contact is Katherine Northcott (katherine.northcott@ecolint.ch). Data protection questions and rights requests go to privacy@ecolint.ch.
2. What this site is
The public site is a set of static files — pre-built HTML, images and PDFs — served from Google Firebase Hosting. There is no database behind the public pages, no login, no forms and no code running per request. This matters for privacy: a page you read here cannot look you up, because there is nothing for it to look you up in.
A separate, sign-in-only staff area lets the department record which pages need reviewing and leave notes on them. It is reachable only with an @ecolint.ch Google account that has been added to a staff list.
3. Systems and processors
One processor: Google. There is no analytics provider, no email provider, no AI provider, no support-desk tool and no third-party database.
- Firebase Hosting — serves the public pages. Part of Google Cloud, in a project belonging to the school's own Google Cloud organisation (
ecolint.ch) rather than to an individual. - Cloud Firestore — holds the staff area's data. Located in
europe-west6(Zurich), so that data is stored in Switzerland. - Firebase Authentication — verifies staff Google sign-ins.
- Google Workspace — the school's existing tenancy, under its existing agreement, for documents and files linked from the site.
4. Personal data held
| What | Where | Who it concerns |
|---|---|---|
| Name, role, title, biography, photo, contact address, professional links | Firestore (teachers), published on the Teachers page | Department staff |
| Staff list and role (teacher / head of department / admin) | Firestore (staff) | Department staff |
| Review notes, with the author's email and the page they refer to | Firestore (notes) | Department staff |
| Server request logs (IP address, page, time, browser) | Google, as hosting provider | Any visitor |
No student data is held. The practice quizzes keep their state in the student's own browser and send nothing to us. No student signs in, and there are no student accounts.
5. Access control
Access to the staff area requires three things at once: a Google sign-in, an @ecolint.ch address, and an active entry in the staff list. These are enforced by Firestore security rules on Google's servers, not by the website — the staff page is a static file that anyone can fetch, so it is deliberately not trusted to protect anything. It contains no data of its own.
- Any staff member may read the page list and leave notes.
- A staff member may edit their own profile, but not their own role.
- Only the Head of Department or an admin may publish or hide a page, assign reviewers, or resolve someone else's note.
- Only an admin may add or remove staff.
A note's author is taken from the verified sign-in token rather than from the form, so a note cannot be filed under someone else's name.
6. Retention
- Staff profiles — kept while the person works in the department, and removed on request or on leaving.
- Review notes — kept while they are useful to the department's editorial work. They concern web pages, not people.
- Server request logs — retained by Google under its logging defaults for this project. We keep no copy.
7. International transfers
Firestore data is stored in Zurich. Firebase Hosting serves pages from Google's global content-delivery network, so a request may be served from, and logged at, an edge location outside Switzerland. Google acts as processor under the Google Cloud data-processing terms, which incorporate the European Commission's Standard Contractual Clauses.
8. Security measures
- HTTPS with modern TLS on every request.
- No writable surface on the public site: no database, no login, no forms, no server-side code.
- Staff access via Google sign-in; no shared passwords anywhere.
- Authorisation enforced server-side by security rules, written down and version controlled alongside the site's source.
- Staff biographies are sanitised before display, to prevent stored scripting.
- The site is rebuilt from version-controlled source, so any previous version can be restored.
9. Your rights
You may ask what personal data is held about you, ask for it to be corrected or erased, object to its processing, or complain to a supervisory authority. Contact privacy@ecolint.ch. Because this site holds so little — staff profiles, staff review notes, and server logs held by Google — most requests can be answered quickly.
10. What changed in September 2026
The site was rebuilt. It previously ran on Vercel with a Supabase database, and staff signed in with a single shared department password. Now:
- Two external processors were removed. Everything is Google, under school-owned projects.
- The shared password is gone, replaced by individual Google sign-in with roles, so actions are attributable to a person.
- The public site became static, so it no longer reads a database when someone visits it.
- Quiz answer keys are no longer sent to the browser in the version used for assessed practice.
11. Open items
Listed rather than glossed over, because a compliance document that claims everything is settled is not worth reading.
- The statements of lawful basis in the privacy notice were written for the previous architecture and should be confirmed by the school's data protection lead.
- No formal retention period is yet set for review notes.
- Whether student practice results should ever be stored server-side is an open decision. Today they are not.
- This dossier has not yet been reviewed by the school's data protection lead.